• Title/Summary/Keyword: Authorization System

Search Result 240, Processing Time 0.025 seconds

Risk Management-Based Application of Anti-Tampering Methods in Weapon Systems Development (무기 시스템 개발에서 기술보호를 위한 위험관리 기반의 Anti-Tampering 적용 기법)

  • Lee, Min-Woo;Lee, Jae-Chon
    • Journal of the Korea Academia-Industrial cooperation Society
    • /
    • v.19 no.12
    • /
    • pp.99-109
    • /
    • 2018
  • Tampering involves illegally removing technologies from a protected system through reverse engineering or developing a system without proper authorization. As tampering of a weapon system is a threat to national security, anti-tampering measures are required. Precedent studies on anti-tampering have discussed the necessity, related trends, application cases, and recent cybersecurity-based or other protection methods. In a domestic situation, the Defense Technology Protection Act focuses on how to prevent technology leakage occurring in related organizations through personnel, facilities and information systems. Anti-tampering design needs to determine which technologies are protected while considering the effects of development cost and schedule. The objective of our study is to develop methods of how to select target technologies and determine counter-measures to protect these technologies. Specifically, an evaluation matrix was derived based on the risk analysis concept to select the protection of target technologies. Also, based on the concept of risk mitigation, the classification of anti-tampering techniques was performed according to its applicability and determination of application levels. Results of the case study revealed that the methods proposed can be systematically applied for anti-tampering in weapon system development.

The Design and Implementation of User Authorization Module based on Zigbee for Automotive Smart-key System (차량용 스마트키 시스템을 위한 지그비 기반의 사용자 인증 모듈 설계 및 구현)

  • Kim, Kyeong-Seob;Lee, Yun-Seob;Yun, Hyun-Min;Choi, Sang-Bang
    • Journal of the Korea Institute of Information and Communication Engineering
    • /
    • v.14 no.11
    • /
    • pp.2442-2450
    • /
    • 2010
  • Using sensor devices applied to various objects will be needed wireless network that it is easy to install in them. Tiny devices configured to processor that bas comparatively low computing ability are inappropriate to use devices that are wireless LAN, etc. In result, network devices needed to not only have simple communication protocol, but have Plug and Play function that it works as soon as it connects without installing any device driver. it also will industrially have both low power and low cost because of mobility of it. From IEEE 802.11 standard, WPAN(Wireless Personal Area Network) included in LAN is being developed by WPAN WG(Working Group) on area with low power consumption and low complexity. In addition to, it is standardizing MAC and PRY of the standard that is expected to wirelessly communicate within 10m. WPAN will be used generally in the more near future because of both low power and low cost of Zigbee. In this paper we designed zigbee based user authentication module for a automotive smart-key system.

Development of the Model for Evaluation of Medical device manufacturer's Quality Management System against international standards and industry environment's change (국제기준 및 산업환경 변화에 대응한 의료기기 제조기업 품질경영 평가모델 개발)

  • Yoon, Do-Sik
    • Journal of the Korea Academia-Industrial cooperation Society
    • /
    • v.19 no.6
    • /
    • pp.382-390
    • /
    • 2018
  • This study developed a model to evaluate the quality management system of a medical device manufacturing company, and applied it to medical device manufacturers to understand the impact on business performance in response to international regulations and industry's change. This study prepared preliminary items, defined four (4) major factors (Plan-Do-Check-Act) that consist of the evaluation layers and items per category according to prior research review and expert interview, and calculated the weight and importance using AHP. The study results showed that responsibility & authority and quality objective in Planning Category, product-related requirement and R&D in Doing Category, Measuring and monitoring in Check Category, and review of meeting Regulatory and regulation in Action Category are relatively more important factors. The evaluation model developed based on the calculated weight and importance to business performance was applied to medical device manufacturers to investigate and analyze the implementation level of QMS and its impact on business performance according to each category. Most medical device manufacturers to be studied showed a reasonable level of QMS and effective business performance. Almost all the evaluation layers and items in the four (4) factors had a significant influence on business performance. Although the medical device quality management system is aimed mainly at license acquisition, it is important that management environment factors not related directly to licensing and authorization are important to business performance, and it is effective when these factors are integrated and operated within and outside the manufacturer.

The Meaning and the Legislative Suggestion about Data Manipulation of Pharmaceutical Companies in the Aspect of the Medicine Approval System (의약품 품목허가 제도에서 제약기업 자료조작의 의미와 입법 개선 방안-대법원 2008. 11. 13. 선고 2008두8628 판결을 중심으로-)

  • Park, Sungmin;Shin, Youngkee
    • The Korean Society of Law and Medicine
    • /
    • v.22 no.4
    • /
    • pp.59-88
    • /
    • 2021
  • The National Assembly of the Republic of Korea recently enacted laws to fortify sanctions about data manipulation of pharmaceutical companies. The medicine approval system is the result of legislative efforts to prevent accidents that caused damages to patients' life and health. The medicine approval system is based on the trust that the data submitted by pharmaceutical companies is not manipulated. The Supreme Court of Korea clarified that strict standard shoud be required to secure the medicine safety in Supreme Court Decision 2008Du8628 decided November 13, 2008. We agree. This paper suggest legislation to weaken the economic incentives for pharmaceutical companies to choose data manipulation by minimizing the expected profit. In addition to revoking the marketing authorization of the medicine, the 'unfair' profits the pharmaceutical company has earned must be recovered. In addition, in order to increase the possibility to discover data manipulation, it is necessary to strengthen the review capacity and to activate the whistle-blowing.

A Study on the Method and System for Organization's Name Authorization of Korean Science and Technology Contents (국내 과학기술콘텐츠 전거데이터 구축을 위한 소속기관명 식별 방법과 시스템에 관한 연구)

  • Kim, Jinyoung;Lee, Seok-Hyong;Suh, Dongjun;Kim, Kwang-Young
    • Journal of Digital Contents Society
    • /
    • v.17 no.6
    • /
    • pp.555-563
    • /
    • 2016
  • Science and technology contents (research papers, patents, reports) are the most common reference material for researchers involved in research and development in the fields of science and technology. Based on various search elements (title, abstract, keyword, year of publication, name of journal, name of author, publisher, etc.), many services are available for users to search science and technology contents and bibliographic information owned by libraries. Authority data on organization name can be useful as an element for author identification and as an element to search for results produced by specific organizations. However, organization name is not taken into account by current search services for domestic academic information and bibliographic records. This study analyzes organization name data contained in the metadata of science and technology contents, which are the basis of the establishment of authority data, and proposes a method and system based on string containment and exact string matching.

A Study on the Importance of the Assessment of Records Management Metadata Elements Related to the Electronic Medical Records Management System for Medical Records Managers (전자의무기록 관리시스템 관련 기록관리 메타데이터 요소들에 대한 의무기록 관리자의 중요도 평가 연구)

  • Lee, Eun-Mi;Kim, Myeong;Yim, Jin Hee
    • Journal of Korean Society of Archives and Records Management
    • /
    • v.13 no.3
    • /
    • pp.151-171
    • /
    • 2013
  • To comprehend the importance and necessity of record management metadata standard implemented in an electronic medical records system, a survey was undertaken to 50 medical records managers in charge of 5 major hospitals in Seoul. Analysis of the survey results was performed by averaging the responses given by those who answered the survey. SPSS was utilized for statistical analysis. Managers of medical records placed importance on metadata that are related to security of records, such as "levels of security", "types of access to medical records", "levels of authorization granted to personnel", and "users accessing medical records". It shows that these managers need the functions of privacy protection in ERMS. Metadata on "external disclosure" had the lowest level but those surveyed with more than 7 years of experience placed greater importance in this area more those surveyed with less than 7 years of experience in a hospital. This shows that managers need the functions of external disclosure to meet the needs of third partiesfor medical research and medical education.

Token-Based IoT Access Control Using Distributed Ledger (분산 원장을 이용한 토큰 기반 사물 인터넷 접근 제어 기술)

  • Park, Hwan;Kim, Mi-sun;Seo, Jae-hyun
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.29 no.2
    • /
    • pp.377-391
    • /
    • 2019
  • Recently, system studies using tokens and block chains for authentication, access control, etc in IoT environment have been going on at home and abroad. However, existing token-based systems are not suitable for IoT environments in terms of security, reliability, and scalability because they have centralized characteristics. In addition, the system using the block chain has to overload the IoT device because it has to repeatedly perform the calculation of the hash et to hold the block chain and store all the blocks. In this paper, we intend to manage the access rights through tokens for proper access control in the IoT. In addition, we apply the Tangle to configure the P2P distributed ledger network environment to solve the problem of the centralized structure and to manage the token. The authentication process and the access right grant process are performed to issue a token and share a transaction for issuing the token so that all the nodes can verify the validity of the token. And we intent to reduce the access control process by reducing the repeated authentication process and the access authorization process by reusing the already issued token.

Analysis of the Organization System and Learning Objectives of Middle School Informatics Textbooks (중학교 정보 교과서의 구성체계 및 학습목표 분석)

  • Kang, Oh-Han
    • The Journal of Korean Association of Computer Education
    • /
    • v.22 no.2
    • /
    • pp.1-9
    • /
    • 2019
  • In order to improve the quality of textbooks, this study analyzed seven informatics textbooks published based on the 2015 revised curriculum. Content analysis was used to analyze the organization system of these textbooks. Learning objectives of the textbooks were also analyzed according to Anderson's taxonomy of educational objectives. Furthermore, a textbook satisfaction survey, in which textbook selection criteria were applied, was given out to preliminary teachers. The results showed that the textbooks were similarly organized, centered on practice, activities, differentiated learning, and small group learning. However, the number of pages varies considerably for each chapter. After analyzing learning objectives of the textbooks, it was found that in terms of cognitive processes, 'understanding' (53%) was the highest item and 'analyzing' (16%) the second highest; in terms of type of knowledge, 'conceptual' (42%) and 'procedural' (31%) accounted for the two highest categories; in terms of cognitive domains, there has been a significant increase in 'analyzing' and 'creating' facets for learning objectives of these new versions of textbooks as compared to those of previously existed textbooks. In the satisfaction survey on a 5-point Likert scale, 'the accuracy and fairness of the content' had the highest points at 4.21 among four scale items. In this study, the improvement of the textbook is proposed based on the findings from this analysis.

A Study on Proving RMF A&A in Real World for Weapon System Development (무기체계 개발을 위한 RMF A&A의 실증에 관한 연구)

  • Cho, Kwangsoo;Kim, Seungjoo
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.31 no.4
    • /
    • pp.817-839
    • /
    • 2021
  • To manage software safely, the military acquires and manages products in accordance with the RMF A&A. RMF A&A is standard for acquiring IT products used in the military. And it covers the requirements, acquisition through evaluation and maintenance of products. According to the RMF A&A, product development activities should reflect the risks of the military. In other words, developers have mitigated the risks through security by design and supply chain security. And they submit evidence proving that they have properly comply with RMF A&A's security requirements, and the military will evaluate the evidence to determine whether to acquire IT product. Previously, case study of RMF A&A have been already conducted. But it is difficult to apply in real-world, because it only address part of RMF A&A and detailed information is confidential. In this paper, we propose the evidence fulfilling method that can satisfy the requirements of the RMF A&A. Furthermore, we apply the proposed method to real-world drone system for verifying our method meets the RMF A&A.

Development of Rapid Antibody-based Therapeutic Platform Correspondence for New Viruses Using Antigen-specific Single Cell Memory B Cell Sorting Technology (항원 특이적 단일 기억 B 세포 분리를 이용한 신종 바이러스 대응 신속 항체 플랫폼 개발)

  • Jiyoon Seok;Suhan Jung;Ye Gi Han;Arum Park;Jung Eun Kim;Young Jo Song;Chi Ho Yu;Hyeongseok Yun;Se Hun Gu;Seung-Ho Lee;Yong Han Lee;Gyeunghaeng Hur;Woong Choi
    • Journal of the Korea Institute of Military Science and Technology
    • /
    • v.27 no.1
    • /
    • pp.116-125
    • /
    • 2024
  • The COVID-19 pandemic is not over despite the emergency use authorization as can see recent COVID-19 daily confirmed cases. The viruses are not only difficult to diagnose and treat due to random mutations, but also pose threat human being because they have the potential to be exploited as biochemical weapons by genetic manipulation. Therefore, it is inevitable to the rapid antibody-based therapeutic platform to quickly respond to future pandemics by new/re-emerging viruses. Although numerous researches have been conducted for the fast development of antibody-based therapeutics, it is sometimes hard to respond rapidly to new viruses because of complicated expression or purification processes for antibody production. In this study, a novel rapid antibody-based therapeutic platform using single B cell sorting method and mRNA-antibody. High immunogenicity was caused to produce antibodies in vivo through mRNA-antigen inoculation. Subsequently, antigen-specific antibody candidates were selected and obtained using isolation of B cells containing antibody at the single cell level. Using the antibody-based therapeutic platform system in this study, it was confirmed that novel antigen-specific antibodies could be obtained in about 40 days, and suggested that the possibility of rapid response to new variant viruses.