• Title/Summary/Keyword: Certificate Status Management

Search Result 34, Processing Time 0.021 seconds

Improvement of Performance for Online Certificate Status Validation (실시간 인증서 상태검증의 성능개선)

  • Jung, Jai-Dong;Oh, Hae-Seok
    • The KIPS Transactions:PartC
    • /
    • v.10C no.4
    • /
    • pp.433-440
    • /
    • 2003
  • According as the real economic activities are carried out in the cyber world and the identity problem of a trade counterpart emerges, digital signature has been diffused. Due to the weakness for real-time validation using the validation method of digital signature, Certificate Revocation List, On-line Certificate Status Protocol was introduced. In this case, every transaction workload requested to verify digital signature is concentrated of a validation server node. Currently this method has been utilized on domestic financial transactions, but sooner or later the limitation will be revealed. In this paper, the validation method will be introduced which not only it can guarantee real-time validation but also the requesting node of certificate validation can maintain real-time certificate status information. This method makes the revocation management node update the certificate status information in real-time to the validation node while revoking certificate. The characteristic of this method is that the revocation management node should memorize the validation nodes which a certificate holder uses. If a certificate holder connects a validation node for the first time, the validation node should request its certificate status information to the above revocation management node and the revocation management node memorizes the validation node at the time. After that, the revocation management node inform the revocation information in real-time to all the validation node registered when a request of revocation happens. The benefits of this method are the fact that we can reduce the validation time because the certificate validation can be completed at the validation node and that we can avoid the concentration of requesting certificate status information to a revocation node.

A Study on Efficient CRI managing for Certificate Status Validate in Distributed OCSP (분산 OCSP에서 인증서 상태 검증을 위한 효율적인 CRI 운영에 관한 연구)

  • Kim, Young-Ja;Chang, Tae-Mu
    • Journal of the Korea Society of Computer and Information
    • /
    • v.13 no.3
    • /
    • pp.91-97
    • /
    • 2008
  • The conventional CA(Certificate Authority) has problems in dealing with certificates whose valid time is expired and in managing CRI (Certificate Revocation Information) produced by clients. Many researches are conducted to solve them, but they have limitations in providing real-time verifications of certificates' status for clients. In this paper, we propose a new CRI management model to address these limitations in distributed OCSP(On-line Certificate Status Protocol) environments. CRL(Certificate Revocation List) is divided into two parts: one part that is recent is replicated over several OCSP servers, the other part is replicated and distributed over servers. Our methods can help to break the bottleneck of CA, and effectively reduce the size of CRL transferred. Therefore, with our methods, clients can verify the state of certificates in real time.

  • PDF

An Efficient Signing and Certificate Status Management Scheme in Personal PKI (Personal PKI에서 효율적인 서명 및 인증서 상태 검증 기법)

  • Sur Chul;Shin Weon;Lee Kyung-Hyune
    • Proceedings of the Korea Contents Association Conference
    • /
    • 2005.05a
    • /
    • pp.91-96
    • /
    • 2005
  • Recetly, the term Personal Public Key Infrastructure (PKI) was introduced to supprot reliable and authenticated service in a Personal Area Network (PAN). However, traditional public key signature schemes and certificate status management are not suitable for a PAN environment since mobile devices that constitute the PAN have limited computing capability. In this paper, we propose a new scheme that efficiently provides signature generation and certificate status management for mobile devices. Based on hash chain technique, we intend to reduce computational overhead on signature generation, and further, to minimize communication overhead for managing certificate status.

  • PDF

Efficient Protocol for Authentication and Certificate Status Management in PAN (PAN에서 인증 및 인증서 상태 관리를 위한 효율적인 프로토콜)

  • Jang, Hwa-Sik;Rhee, Kyung-Hyune
    • Journal of Korea Multimedia Society
    • /
    • v.10 no.3
    • /
    • pp.373-380
    • /
    • 2007
  • In this paper we propose a new efficient authentication protocol that reduces overheads of computation for digital signature generation/verification on mobile devices in the Personal Area Network (PAN). In particular, we focus on eliminating the traditional public key operations on mobile devices without any assistance of a signature server. Moreover, the proposed protocol provides a simplified procedure for certificate status management to alleviate communication and computational costs on mobile devices in the PAN.

  • PDF

A Study on operational issues and status of Certificate of Basic OSH Training in Construction (건설업 기초안전보건교육의 운용적 문제점과 실태에 관한 연구)

  • Park, Hyun-Geon;Kang, Kyung-Sik
    • Journal of the Korea Safety Management & Science
    • /
    • v.19 no.1
    • /
    • pp.53-62
    • /
    • 2017
  • Full embroidery industrial accidents in recent years has shown a declining trend. But disaster embroidery of domestic construction industry were more than 20,000 deaths per year is about 500 people. The government has introduced a construction site often changing the recruitment of new construction based on health and safety as an alternative to road safety education training yisuje of construction workers, daily work periods short. Certificate of Basic OSH Training in Constructions had also been evaluated as successful by reducing the accident rate problem. It is conducted in private educational institutions has occurred on the friction between workers and employers and training costs are difficult to approach workers in the education standards for such facilities due to the superintendent. Educational institutions are institutions that have been caused by excessive competition lowered levels of education. There is also a lack of evaluation that the training is limited to the basic safety knowledge. These details are brought formal safety education purposes only and is introducing the results of other self jyeotgi difficult to reap the proceeds to good effect. In this study, we propose a plan for improving operational problems and enemy status based on research data presented after the Certificate of Basic OSH Training in Construction.

Certification Status Verification System Implementation for Communication of Domain with CSMS (CSMS와 도메인과의 통신을 이용한 인증서 상태 검증 시스템 구현)

  • Lee, Chong-Ho;Lee, Yong-Jun;Kim, Hyun-Chul;Oh, Hae-Seok
    • Proceedings of the Korea Information Processing Society Conference
    • /
    • 2003.05c
    • /
    • pp.2077-2080
    • /
    • 2003
  • 일반적으로 기존의 도메인으로부터 인증서를 검증하는 방법은 CRL(Certificate Revocation List), OCSP(Online Certificate Status Protocol), Freshest CRL, Delta CRL등이 있으나 CRL 검증 방식에 대해서 여러 단점이 부각되었다. 현재 CRL 검증 방법에 대해서 효율적으로 검증하기 위한 방안이 OCSP, Delta CRL등이 제시하여 서비스를 하고 있는 실정이다. 피러나 이런 검증 서비스 시스템에도 한계성이 드러나게 되었고 그 단점을 보완하기 위한 검증 시스템을 채택하여 기존의 인증서 검증 서비스보다 효율적이고 안정적인 시스템을 구현하기 위해 CSMS(Certificate Status Management Server)를 제시한다. CSMS는 OCSP와 같이 실시간으로 검증과 빠른 서비스로 USER에게로의 응답을 위한 서비스를 제공함으로써 전자상거래를 통한 트랜젝션에 적합한 시스템을 위한 것이다.

  • PDF

A Study of PMI based on Established Certificate (기존 인증서를 통한 PMI 연구)

  • 김건배;배두현;박세현;송오영
    • Proceedings of the Korea Institutes of Information Security and Cryptology Conference
    • /
    • 2002.11a
    • /
    • pp.548-550
    • /
    • 2002
  • 본 논문은 PKC(Public Key Certificate)를 이용하여 Privilege Management를 제공하는 모델에 대해 다룬다. 권한관리는 PKC와 AC(Attribute Certificate)를 이용한 PMI가 제시되고 있으나, PMI를 구축하기 위한 비용이 들게 된다. 본 논문에서는 현재 구성되고 있는 PMI 모델과 본 논문에서 제시한 PSL(Privilege Status List)를 이용한 권한 관리모델을 비교, 분석한다.

  • PDF

ISO 900G Quality System Application Status of Small & Medium Size Industrial Companies (중소기업체의 ISO 9000품질시스템 운영실태)

  • 김복만;박종화
    • Journal of Korean Society of Industrial and Systems Engineering
    • /
    • v.24 no.66
    • /
    • pp.59-67
    • /
    • 2001
  • This thesis is to research for analysis of ISO 9000 Quality Management System application status of small & medium-sized Industrial Companies. For this research, 10 companies certified by ISO 9000 standard were selected. By using an evaluation method and a software for analysis of application, this thesis compared, analyzed and evaluated the application status before and after certificate of ISO 9000, and identified the performance and difficulty of QMS application, and then proposed improvement methodology for ISO 9000 effective application.

  • PDF

A Secure Switch Migration for SDN with Role-based IBC

  • Lam, JunHuy;Lee, Sang-Gon;Andrianto, Vincentius Christian
    • Journal of the Korea Society of Computer and Information
    • /
    • v.22 no.9
    • /
    • pp.49-55
    • /
    • 2017
  • Despite the Openflow's switch migration occurs after the channel was established in secure manner (optional), the current cryptography protocol cannot prevent the insider attack as the attacker possesses a valid public/private key pair. There are methods such as the certificate revocation list (CRL) or the online certificate status protocol (OCSP) that tries to revoke the compromised certificate. However, these methods require a management system or server that introduce additional overhead for the communication. Furthermore, these methods are not able to mitigate power abuse of an insider. In this paper, we propose a role-based identity-based cryptography (RB-IBC) that integrate the identity of the node along with its role so the nodes within the network can easily mitigate any role abuse of the nodes. Besides that, by combining with IBC, it will eliminate the need of exchanging certificates and hence improve the performance in a secure channel.

Food Allergy-related Awareness and Performance of Dietitians at Children's Hospitals in Korea: Comparison of Certificate Possession among Clinical Dietitians (전국 아동병원 영양사의 식품알레르기 관련 인식도 및 수행도: 임상영양사 자격증 유무에 따른 비교)

  • Shin, Hye-Ran;Kim, Sook-Bae
    • Korean Journal of Community Nutrition
    • /
    • v.24 no.6
    • /
    • pp.512-524
    • /
    • 2019
  • Objectives: The purpose of this study was to examine the food allergy-related knowledge, awareness, and performance of dietitians at children's hospitals, depending on whether or not they have a clinical dietitian certificate. Methods: A questionnaire survey was administered to 41 dieticians at children's hospitals registered as a part of the Korean Hospital Association. The survey consisted of questionnaires examining general characteristics, nutritional counseling-related characteristics, and food allergy-related characteristics (food allergy-related knowledge, awareness, and performance). We examined differences according to the status of clinical dietitian certification. Results: The proportion of subjects who were holders of clinical dietitian certificates was 48.8%. There were differences between holders of clinical dietitian certificates and non-holders as follows. Regarding nutritional awareness and performance, 'needs to provide nutrition counseling in children's hospitals', 'providing nutrition counseling services in working hospitals', and 'whether there is a nutrition counseling room' scored higher among holders of clinical dietitian certificates than non-holders. Holders of clinical dietitian certificates showed higher scores for knowledge of food allergy symptoms and food allergy management than non-holders. For food allergy awareness and performance, 'self-assessment of food allergy knowledge understanding level', 'awareness of open oral food challenge (OFC)', 'recognition of the need for education and counseling on food allergy for patients / guardians', and 'food allergy related educational experience' scored higher among holders of clinical dietitians certificates than in non-holders. Conclusions: Children's hospital dietitians with a clinical dietitian certificate showed high knowledge, awareness, and performance related to food allergies. It is thus necessary to employ a clinical dietitian for food allergy management in children's hospitals. In addition, training and conservative education are necessary for the management of food allergies for children's hospital dietitians.