• Title/Summary/Keyword: 서명체계

Search Result 118, Processing Time 0.027 seconds

The Secure Key Store to prevent leakage accident of a Private Key and a Certificate (인증서와 개인키 유출 방지를 위한 보안키 저장소 Secure Key Store)

  • Park, Young-Jin;Kim, Seon-Jong;Lee, Dong-Hoon
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.24 no.1
    • /
    • pp.31-40
    • /
    • 2014
  • In Korea, the Public Key Infrastructure (PKI) has been introduced. For secure information transmission and identification, the electronic signature authorization system of a certificate-based is built, and then the service provide.The certificate is stored in location what users can easily access and copy. Thus, there is a risk that can be stolen by malware or web account hacking. In addition, private key passwords can be exposed by the logging tool, after keyboard security features are disabled. Each of these security weaknesses is a potential conduit for identity theft, property/asset theft, and theft of the actual certificates. The present study proposes a method to prevent the private key file access illegally. When a certificate is stored, the private key is encrypted by the dependent element of the device, and it is stored securely. If private key leakage occurs, the retrieved key could not be used on other devices.

Design and Implementation of DHCP Supporting Network Attack Prevention (네트워크 공격 방지를 지원하는 DHCP의 설계 및 구현에 관한 연구)

  • Yoo, Kwon-joeong;Kim, Eun-gi
    • Journal of the Korea Institute of Information and Communication Engineering
    • /
    • v.20 no.4
    • /
    • pp.747-754
    • /
    • 2016
  • DHCP(Dynamic Host Configuration Protocol) is a protocol for efficiency and convenience of the IP address management. DHCP automatically assigns an IP address and configuration information needed to run the TCP/IP communication to individual host in the network. However, existing DHCP is vulnerable for network attack such as DHCP spoofing, release attack because there is no mutual authentication systems between server and client. To solve this problem, we have designed a new DHCP protocol supporting the following features: First, ECDH(Elliptic Curve Diffie-Hellman) is used to create session key and ECDSA(Elliptic Curve Digital Signature Algorithm) is used for mutual authentication between server and client. Also this protocol ensures integrity of message by adding a HMAC(Hash-based Message Authentication Code) on the message. And replay attacks can be prevented by using a Nonce. As a result, The receiver can prevent the network attack by discarding the received message from unauthorized host.

A study on the capability of acceptance in utilization of TradeCard as new foreign trade payment practice (국제결제관습상(國際決濟慣習上) TradeCard의 수용가능성(受容可能性)에 관한 연구(硏究))

  • Ahn, Byung-Soo
    • International Commerce and Information Review
    • /
    • v.2 no.2
    • /
    • pp.171-188
    • /
    • 2000
  • 지속적으로 변화하는 무역관습의 흐름은 결제관습에 있어서도 새로운 변화를 초래하고 있는데 최근의 국제결제시스템중 가장 두드러진 변화는 전자적 방법에 의한 결제시스템의 대두이다. TradeCard는 이러한 전자결제시스템으로서 가장 대표적인 예로서 1994년 처음 사업이 시작된 이후 10년도 되지 않아 새로운 무역결제관습으로 정착되기 위한 상업적 활동에 나서고 있다. 본 논문은 이러한 TradeCard의 상업적 활동이 과연 순조롭게 추진되어 신용장을 비롯한 기존의 무역결제시스템에 추가 또는 대체되는 새로운 무역관습이 탄생할 수 있을지를 검토하고 있다. 이를 위해 본 논문은 먼저 TradeCard가 갖고 있는 특징을 몇 가지로 분류하여 살펴보았다. 즉, 무역절차의 전자화 과정에서 기능적 접근방법을 채택하였다는 점, 타 기관이나 조직과의 활발한 제휴, 비용과 시간을 절감시킬 수 있는 방법의 제시 등이 그것이다. 이러한 특징을 통해 TradeCard는 새로운 무역관습으로 자리잡을 수 있는 충분한 가능성을 갖고 있다는 것이 논자의 생각이다. 그러나 다음의 몇 가지 문제점 역시 갖고 있기 때문에 이를 해결하는 것이 그러한 가능성의 전제조건이 된다. 첫째, TradeCard를 통한 거래의 법적 안정성 확보이다. 이는 모든 전자거래가 공통으로 갖는 문제점이지만 TradeCard의 경우 거래조건의 이행여부에 대한 전자적 판단이라는 요소를 지니고 있어 이를 어떻게 법적으로 수용할 것인가의 문제가 제기된다. 둘째, TradeCard를 통한 거래에서 발생되는 피해에 대한 구제방법의 제시이다. 이는 아마도 보험을 통해서 해결할 수 있으리라 생각되지만 현재 TradeCard는 이부분에 대한 명확한 입장이 명시되지 않은 것 같다. 셋째, 국제적 전자거래를 안전하게 할 수 있는 방안으로 전자서명의 활용이 절실한데 이에 대한 상호인정의 해결이 필요하다는 점이다. 물론 이는 TradeCard의 역할이라기 보다는 우리 정부를 비롯한 각국의 정부당국의 몫이다. 그러나 이러한 모든 문제는 결국 얼마나 빨리 많은 사용자를 확보하여 시장의 힘을 통해 국제상관습으로 정착시킬 수 있는가의 문제로 귀착된다고 본다. 따라서 TradeCard는 처렴한 요금체계 및 사용자에 대한 인센티브의 제공 등을 통해 조기에 다수 사용자를 확보하는 것이 시급한 것으로 생각한다.

  • PDF

Study on a System Reliability Calculation Method Using Failure Enumeration of Reliability Path (신뢰도 경로의 고장열거를 이용한 시스템 신뢰도 계산방법 연구)

  • Lee, Jang-Il;Park, Kee-Jun;Chun, Hwan-Kyu;Jeong, Choong-Min;Shin, Dong-Jun;Suh, Myung-Won
    • Transactions of the Korean Society of Mechanical Engineers A
    • /
    • v.35 no.6
    • /
    • pp.629-633
    • /
    • 2011
  • Recently, systems such as aircraft, trains and ships have become larger more complex. Therefore, the reliability calculation of these systems is more difficult. This paper presents a reliability calculation algorithm for a complex system with a solution that is difficult to analyze. When the system has a very complex structure, it is very difficult to find an analytical solution. In this case, we can assess system reliability using the failure enumeration method of the reliability path. In this research, we represent the reliability block diagram by an adjacent matrix and define the reliability path. We can find any system status by the failure enumeration of the reliability path, and thus we can calculate any kind of system reliability through this process. This result can be applied to RCM (Reliability-Centered Maintenance) and reliability information-management systems, in which the system reliability is composed of the reliabilities of individual parts.

Optimum Design Based on Sequential Design of Experiments and Artificial Neural Network for Enhancing Occupant Head Protection in B-Pillar Trim (센터 필라트림의 FMH 충격성능 향상을 위한 순차적 실험계획법과 인공신경망 기반의 최적설계)

  • Lee, Jung Hwan;Suh, Myung Won
    • Transactions of the Korean Society of Mechanical Engineers A
    • /
    • v.37 no.11
    • /
    • pp.1397-1405
    • /
    • 2013
  • The optimal rib pattern design of B-pillar trim considering occupant head protection can be determined by two methods. One is the conventional approximate optimization method that uses the statistical design of experiments (DOE) and response surface method (RSM). Generally, approximated optimum results are obtained through the iterative process by trial-and-error. The quality of results strongly depends on the factors and levels assigned by a designer. The other is a methodology derived from previous work by the authors, called the sequential design of experiments (SDOE), to reduce the trial-and-error procedure and to find an appropriate condition for using artificial neural network (ANN) systematically. An appropriate condition is determined from the iterative process based on the analysis of means. With this new technique and ANN, it is possible to find an optimum design accurately and efficiently.

Development of a Underground Facility Management System based on Sensor and Object Data (센서 및 객체 정보 기반의 도시 지하시설물 관리시스템 구축 방안)

  • Kang, Joon-Mook;Lee, Jae-Wook;Seo, Myung-Woo;Baik, Song-Hoon
    • Journal of the Korean Society of Surveying, Geodesy, Photogrammetry and Cartography
    • /
    • v.27 no.5
    • /
    • pp.607-617
    • /
    • 2009
  • With the promotion of the u-City project in recent years, the need for the systematic and efficient management of ground and underground facilities comprising the urban infrastructure has been increased. Considering that the diverse services provided in the u-City are closely related to the physical environment of the city itself, including its location and condition, the core of such management must be to continuously maintain these facilities in a normal state, based on accurate data collection from the facilities. This paper discusses a method of collecting the sensor and the object data that are needed to accurately understand the state of the underground facilities, and presents a plan to build an Underground Facility Management System on this basis. This plan is then verified using a scenario test performed by a prototype system.

Securing the Private Key in the Digital Certificate Using a Graphic Password (그래픽 비밀번호를 활용한 공인인증서 개인키 보호방법에 관한 연구)

  • Kang, Byung-Hoon;Kim, Beom-Soo;Kim, Kyung-Kyu
    • The Journal of Society for e-Business Studies
    • /
    • v.16 no.4
    • /
    • pp.1-16
    • /
    • 2011
  • A digital certificate mandated by the Electronic Signature Act has become familiar in our daily lives as 95% of the economically active population hold certificates. Due to upgrades to 256 bit level security that have become effective recently, the security and reliability of digital certificates are expected to increase. Digital certificates based on Public Key Infrastructure (PKI) have been known as "no big problem," but the possibility of password exposure in cases of leaked digital certificates still exists. To minimize this vulnerability, various existing studies have introduced alternative password methods, expansion of certificate storage media, and multiple certification methods. These methods perform enhanced functions but also have limitations including the fact that the secureness of passwords is not guaranteed. This study suggests an alternative method for enhancing the level of password secureness as a way to improve password security. This new method improves security management and enhances the convenience of using digital technologies. The results may be used for developing digital certificate related security technologies and research in the future.

A Study on the Durability Analysis of Underground parking lot and User Awareness on apartment -Focusing on the Bundang New Town- (공동주택 건축물의 지하주차장 내구성 분석 및 사용자 인식 연구 - 분당 신도시를 중심으로 -)

  • Suhr, Myong-Suk
    • The Journal of the Convergence on Culture Technology
    • /
    • v.7 no.4
    • /
    • pp.727-734
    • /
    • 2021
  • The purpose of this study is to analyze the perception of the residents of the new city by examining the consciousness of the occupants to understand the characteristics of the residents of the city of Bundang. As a result of evaluating and analyzing the durability by visual inspection and some equipment tests at the site of the on-site investigation, it was found that there is a problem with the quality, and continuous maintenance is required to improve the durability and usability of the apartment house. In particular, many cracks appearing in the rapidly deteriorated part should be repaired promptly, and a systematic plan should be formulated and carried out. In the apartment housing perception survey of Bundang new city residents, about 93.4% showed above-average satisfaction, and 43.4% showed a favorable preference toward the residential area.

Integrity Guarantee System in IoT Virtual Environment Platform: Through Hyperedfger Indy and MQTT (IoT 가상환경 플랫폼에서의 무결성 보장 시스템:Hyperledger Indy와 MQTT를 통하여)

  • Yoosung Hong;Geun-Hyung Kim
    • Smart Media Journal
    • /
    • v.13 no.4
    • /
    • pp.76-85
    • /
    • 2024
  • In this paper, we propose a system that improves the data integrity of IoT(Internet of Things) devices in the virtual environment by combining Hyperledger Indy and MQTT(Message Queuing Telemetry Transport). The system complements the limitations of the centralized system by realizing a DPKI(Decentralized Public Key Infrastructure) structure that utilizes a distributed network in publish-subscribe(pub/sub) pattern communication. Digital signature technology was applied to ensure the data integrity of IoT devices and communication scenarios between the four core components of the client, IoT device, broker, and blockchain, as well as a topic structure using a decentralized identifier to ensure safety in the virtual environment. We present a systematic method for transparent data exchange. To prove the performance of the proposed system, this paper conducted experiments on four scenarios and evaluated communication performance in a virtual environment. The experimental results confirmed that the proposed system provides a reliable IoT data communication structure in a virtual environment.

Morphological Classification of Unit Basin based on Soil & Geo-morphological Characteristics in the yeongsangang Basin (토양 및 지형학적 특성에 따른 영산강유역의 소유역 분류)

  • Sonn, Yeon-Kyu;Hyun, Byung-Keun;Jung, Suk-Jae;Hur, Seong-Oh;Jung, Kang-Ho;Seo, Myung-Chul;Ha, Sang-Keun
    • Korean Journal of Soil Science and Fertilizer
    • /
    • v.40 no.4
    • /
    • pp.262-268
    • /
    • 2007
  • To characterize morphological classification of the basins, four major basin characteristics of the unit basins, including sinuosity, ratio of forest, ratio of flat area, and tributary existence were selected for cluster analysis. The analysis was carried out using soil map, topographic map, water course map, and basin map of the fifty unit basins in the Yeongsangang Basin. The unit basins could be categorized to five basin groups. The fitness by the Mantel test showed good fit of which r was 0.830. These grouping based on comprehensive soil and topographic characteristics provides best management practices, water quality management according to pollutants, increased water related model application and reasonable availability of water management. For agricultural management of water resources and conservation of water quality from agricultural non-point pollutants, therefore, comprehensive systematic classification of soil characteristics on unit basin might be an useful tool.