• Title/Summary/Keyword: SSO

Search Result 142, Processing Time 0.025 seconds

Security Architecture for OSGi Service Platform Environment (OSGi 서비스 플랫폼 환경을 위한 보안 아키텍처)

  • 박대하;김영갑;문창주;백두권
    • Journal of KIISE:Computing Practices and Letters
    • /
    • v.10 no.3
    • /
    • pp.259-272
    • /
    • 2004
  • This paper suggests a new security architecture for facilitating secure OSGi service platform environment. The security architecture includes 1) user authentication mechanism, 2) bundle authentication mechanism, 3) key sharing mechanism, and 4) authorization mechanism. The user authentication mechanism supplies SSO(single sign-on) functions which are useful for safe and easy user authentications. The bundle authentication mechanism utilizes both PKI-based and MAC-based digital signatures for efficiently authenticating service bundles. The key sharing mechanism, which is performed during bootstrapping phase of a service gateway, supplies a safe way for sharing secret keys that are required for authentication mechanisms. Finally, the authorization mechanism suggests distributed authorization among service providers and an operator by establishing their own security policies. The main contributions of the parer are twofold. First, we examine several security requirements of current OSGi specification when its security functions can be applied in real OSGi environments. Second, we describe the ways to resolve the problems by means of designing and implementing concrete security mechanisms.

Effect of Dietary Conjugated Linoleic Acid on Lipid Characteristics of Egg Yolk

  • Hur, Sun-Jin;Kang, Geun-Ho;Jeong, Jin-Yeun;Yang, Han-Sul;Ha, Yeong-Lae;Park, Gu-Boo;Joo, Seon-Tea
    • Asian-Australasian Journal of Animal Sciences
    • /
    • v.16 no.8
    • /
    • pp.1165-1170
    • /
    • 2003
  • A total of 250 laying hens were fed a diet containing 0, 1, 2.5 or 5% conjugated linoleic acid (CLA), and 5% Safflower seed oil (SSO) for 5 weeks, and eggs were collected by week to analyse lipid characteristics of egg yolk. Egg yolk from CLA-fed groups showed significant increase in CLA content with increased CLA in the diet. Dietary CLA also increased the ratio of saturated fatty acids and decreased unsaturated fatty acids in the egg yolk. The proportion of myristic, palmitic, stearic and CLA were increased, while those of oleic, linoleic, linolenic and arachidonic acid were decreased. The cholesterol content in egg yolk was significantly decreased by dietary CLA for 5 weeks feeding. After 7 days of feeding, 5% CLA-fed group showed the lowest cholesterol content in egg yolk. CLAfed groups showed significantly lower 2-thiobarbituric acid-reactive substances (TBARS) values compared to control and SSO-fed group after 14 days of storage. No significant differences in TBARS values among CLA-fed groups were observed at the 28 days of storage. Results suggested that lipid oxidation of egg yolk during cold storage could be inhibited by dietary CLA due not only to changes in fatty acid composition but also to the high concentration of CLA in egg yolk.

Implementation of Accessibility and Usability Enhancement Scheme for a WebRTC VC Application (WebRTC VC응용의 접근성 및 편의성 향상기술 구현)

  • Lee, KyoungMin;Jo, Jinyong;Kong, JongUk
    • Journal of the Korea Institute of Information and Communication Engineering
    • /
    • v.20 no.8
    • /
    • pp.1478-1486
    • /
    • 2016
  • This paper introduces technical methods to improve the accessibility and usability of a WebRTC video conference (VC) application. Simplified login is essential, by applying such as single sign-on (SSO) to improve the accessibility of VC applications. High usability and manageability are also necessary to attract more users, enhance user experiences, and save service management cost. The proposed VC application leverages SAML-based federated identity management (FIM) to enable higher service accessibility. Users can access the application with their organizational ID and SSO authentication. The FIM eases user ID management and indirectly strengthens privacy information protection. Proposed web application has high usability and manageability because users and/or administrators can easily create, join, monitor, or tear down VC sessions through RESTful web service (REST API). We verify the feasibility of the VC application after illustrating the SAML-based identity federation and the designed REST API.

Certificate-based SSO Protocol Complying with Web Standard (웹 표준을 준수하는 인증서기반 통합 인증 프로토콜)

  • Yun, Jong Pil;Kim, Jonghyun;Lee, Kwangsu
    • Journal of the Korea Institute of Information and Communication Engineering
    • /
    • v.20 no.8
    • /
    • pp.1466-1477
    • /
    • 2016
  • Public key infrastructure(PKI), principle technology of the certificate, is a security technology providing functions such as identification, non-repudiation, and anti-forgery of electronic documents on the Internet. Our government and financial organizations use PKI authentication using ActiveX to prevent security accident on the Internet service. However, like ActiveX, plug-in technology is vulnerable to security and inconvenience since it is only serviceable to certain browser. Therefore, the research on HTML5 authentication system has been conducted actively. Recently, domestic bank introduced PKI authentication complying with web standard for the first time. However, it still has inconvenience to register a certification on each website because of same origin policy of web storage. This paper proposes the certificate based SSO protocol that complying with web standard to provide user authentication using certificate on several sites by going around same origin policy and its security proof.

Effect of Conjugated Linoleic Acid on Fatty Acid Composition and Lipid Oxidation of Egg Yolk (난황내 Conjugated Linoleic Acid가 지방산 조성과 지방산화에 미치는 효과)

  • Park, Gu-Boo;Lee, Jeong-Il;Ha, Yeong-Lae;Kang,Seuck-Joong;Jin, Sang-Keun;Joo, Seon-Tea
    • Food Science of Animal Resources
    • /
    • v.18 no.4
    • /
    • pp.339-347
    • /
    • 1998
  • The effects of conjugated linoleic acid (CLA) in egg yolk on fatty acid composition and lipid oxidation during chilled storage (4$^{\circ}C$) were investigated. CLA was synthesized according to the method of alkali isomerization using safflower seed oil (SSO). A total of 250 hens (200 days of age) were fed control diet (commercial formula feed for han) or CLA-supplemented diet (1%, 2.5% and 5% CLA) or 5% SSO supplemented diet for 6 weeks, and eggs were collected for analysis of CLA, fatty acid compositons and lipid oxidation. Eggs from CLA-supplemented diets groups showed significantly (p<0.05) higher CLA content compared to those of control group. The contents of linoleic, palmitic, and myristic acid were increased as well as CLA content by feeding a CLA-supplemented diet. However, the contents of oleic and arachidonic acids in egg yolks were decreased by dietary CLA supplementation. The pH of egg yolk increased by the levels of CLA during storage. The contents of CLA were not significantly (p<0.05) changed during chilled storage for 28 days, whereas TBARS were significantly (p<0.05) increased. It is suggested that lipid oxidation of egg yolk might be affected by the levels of CLA in egg yolk due to changes in fatty acid compositions.

  • PDF

DEEP: KMTNet DEep Ecliptic Patrol

  • Moon, Hong-Kyu;Choi, Young-Jun;Kim, Myung-Jin;Ishiguro, Masateru;Thuillot, William
    • The Bulletin of The Korean Astronomical Society
    • /
    • v.36 no.2
    • /
    • pp.122.2-122.2
    • /
    • 2011
  • For more than a decade, NEA (Near-Earth Asteroid) survey teams equipped with 1 meter-class telescopes discovered thousands of NEAs in the northern sky. As of August 2011, some 8,200 NEAs have been cataloged, yet only five percent of them has been investigated for their physical and chemical properties. In order to improve current situation, we propose a deep ecliptic survey utilizing KMTNet, for detection and characterization of NEAs in the southern sky. Thanks to the wide-field capability (four square degrees) of the telescopes, we will be able to considerably expand the search volume carrying out precision photometry down to 21.5th magnitude. We plan to focus our survey on opposition and two "sweet spots" in the ecliptic belt. Since SDSS colors characterize mineralogical properties of NEAs, g', r', i', z' filters will be employed. Based on the round-the-clock observation, we will study their rotational properties; for multiple systems, mass, density and other physical parameters can be obtained. We plan to maintain a dedicated database of the physical and mineralogical properties of NEAs. With this archive, it is expected that our understanding on the population will see a drastic change. We also plan to participate in the GAIA Follow-Up Network for ground based observation of the Solar System Objects (GAIA-FUN-SSO). The follow- up astrometry will be performed upon alerts issued by the GAIA-FUN-SSO Central Node in France.

  • PDF

A Converged Profile and Authentication Control Scheme for Supporting Converged Media Service (융합 미디어 서비스 제공을 위한 통합 프로파일 및 인증제어 기술 연구)

  • Lee, Hyun-Woo;Kim, Kwi-Hoon;Ryu, Won
    • The Journal of Korean Institute of Communications and Information Sciences
    • /
    • v.35 no.3B
    • /
    • pp.503-516
    • /
    • 2010
  • In this paper, we propose the converged profile and authentication scheme for supporting converged media services of broadcasting & communications convergence in fixed mobile convergence networks. The proposed scheme supports the management of access, service, mobility and IPTV profiles on subscriber and a function of open API(Application Program Interface) for providing the subscriber profile for the third party service provider with the PUSH/PULL method. The open API is based on a web service and a REST(Representational State Transfer) and provides various services for the third party service provider with ease. In addition, the proposed scheme supports a function of SSO(Single Sign-on). After user succeeded in establishing an access connection, user can sustain the same authentication state with this function although connected access network is changed or IMS(IP Multimedia Subsystem) service network is attached. We evaluate and analyze the performance of the proposed scheme through the implementation of CUPS(Converged User Profile Server) system test-bed.

Development of SAML Software for JAVA Web Applications in Korea (국내 자바 웹 응용을 위한 SAML 소프트웨어의 개발)

  • Jo, Jinyong;Chae, Yeonghun;Kong, JongUk
    • Journal of the Korea Institute of Information and Communication Engineering
    • /
    • v.23 no.9
    • /
    • pp.1160-1172
    • /
    • 2019
  • Federated authentication is a user authentication and authorization infrastructure that spans multiple security domains. Many overseas Web applications have been adopting SAML-based federated authentication. However, in Korea, it is difficult to apply the authentication because of the high market share of a specific Web (application) server, which is hard to use open-source SAML software and the high adoption of Java-based standard framework which is not easy to integrate with SAML library. This paper proposes the SAML4J, which is developed in order to have Web applications easily and safely integrated with the Java-based framework. SAML4J has a developer-friendly advantage of using a session storage independent of the framework and processing Web SSO flows through simple API. We evaluate the functionality, performance, and security of the SAML4J to demonstrate the high feasibility of it.

A Study on Access Control Technique for Provision of Cloud Service in SSO-based Environment

  • Eun-Gyeom Jang
    • Journal of the Korea Society of Computer and Information
    • /
    • v.28 no.11
    • /
    • pp.73-80
    • /
    • 2023
  • In this paper, a technology to protect important information from access in order to revitalize the cloud service market. A technology is proposed to solve the risk of leakage of important confidential and personal information stored in cloud systems, which is one of the various obstacles to the cloud service market. To protect important information, access control rights to cloud resources are granted to cloud service providers and general users. The system administrator has superuser authority to maintain and manage the system. Client computing services are managed by an external cloud service provider, and information is also stored in an external system. To protect important in-house information within the company, all users, it was designed to provide access authority with users including cloud service providers, only after they are authenticated. It is expected that the confidentiality of cloud computing resources and service reliability achieved through the proposed access control technology will contribute to revitalizing the cloud service market.

New Mechanism for the Reaction of Thianthrene Cation Radical Perchlorate with tert-Butyl Peroxide

  • Park, Bo-Kyung;Sohn, Chang-Kook;Lee, Wang-Keun
    • Bulletin of the Korean Chemical Society
    • /
    • v.23 no.1
    • /
    • pp.103-106
    • /
    • 2002
  • A new reaction mechanism is proposed for the reaction of thianthrene cation radical perchlorate $(Th^{+{\cdot}}CIO_4^-}$ and tert-butyl peroxide in acetonitrile at room temperature on the basis of experimental and theoretical results. Rapid C-O bond rupture instead of O-O bond cleavage was observed by a good peroxy radical trapping agent, thianthrene cation radical. Products were N-tert-butyl acetamide, thianthrene 5-oxide (ThO), thianthrene 5,5-dioxide $(SSO_2)$, and thianthrene (Th). Thianthrene 5,10-dioxide (SOSO) was not obtained. A comparative computational study of the cation radical of tert-butyl peroxide is made by using B3LYP and CBS-4. The computational results are helpful to explain the reaction mechanism.