• 제목/요약/키워드: certificate systems

검색결과 180건 처리시간 0.03초

공인인증서의 암호학 활용에 관한 연구 (On the application of authorized certificate for cryptology)

  • 김대학
    • Journal of the Korean Data and Information Science Society
    • /
    • 제28권1호
    • /
    • pp.163-171
    • /
    • 2017
  • 인터넷 뿐만 아니라 휴대용 컴퓨터라고도 불리고 있는 스마트폰의 기능이 향상되면서 인터넷상거래나 금융기관거래에서 인터넷이나 스마트폰을 이용한 거래가 활성화 되고 있다. 인터넷이나 스마트폰을 이용한 상거래나 금융기관 거래 (banking)에는 공인인증서 (authorized certificate, certificate)가 반드시 필요하다. 공인인증서는 지금도 중요시 되지만 미래사회에도 계속 중요하게 다루어질 중요한 안전장치이다. 공인인증서는 2015년 3월 현재 우리나라 국민 2,841만명이 이용할 정도로 생활 필수품에 가까운 위치를 점했다. 그러나 공인인증서의 사용자들이 상상이상으로 공인인증서에 대해 알고 있지 못하다는 점을 파악하여 본 논문에서는 공인인증서에 대한 중요사항들을 정리하고 암호학과 관련된 내용들을 설명하고자 한다. 각종 논문과 인터넷 자료 및 신문기사, 그리고 서적을 통하여 공인인증서의 본질적인 모습과 공인인증서가 어떤 암호체계를 기반으로 발전해 왔는지, 또 과거의 모습부터 근래의 모습에는 어떤 변화를 거쳐왔는지 살펴보고 다양하게 쓰이는 공인인증서의 장점과 그 속에 공존하는 단점, 그리고 취약점들에 대하여 언급하였다. 또한 앞으로 공인인증서가 어떻게 발전해 나갈지에 대해 비모수적 통계적 방법으로 예측하였다.

국제표준기반의 철도 RAMS와 인증 프로세스 소개 및 그 적용사례 (Introduction of RAMS and Certificate Process for Railway System based on International Standard and Practices)

  • 최요철
    • 시스템엔지니어링학술지
    • /
    • 제11권1호
    • /
    • pp.49-54
    • /
    • 2015
  • The RAMS Process is the Internationally required activity to secure Reliability, Availability, Maintainability, and Safety of system which will be acquired as customer requirements. The importance are situations that have been growing gradually. Specially, When developing railway system, the needs of customer about RAMS Process has been being proposed in a variety of railroad business. Through this paper, It introduces the international standards described the RAMS Process and also presents the requirements that should have to comply with it. Furthermore, the necessary activities to get certificate of a Railway system are suggested and not only the various acquisition cases of certificate but also lessons learned by cases in the field of railway signalling system are presented.

Certificate-Based Encryption Scheme without Pairing

  • Yao, Ji;Li, Jiguo;Zhang, Yichen
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • 제7권6호
    • /
    • pp.1480-1491
    • /
    • 2013
  • Certificate-based cryptography is a new cryptographic primitive which eliminates the necessity of certificates in the traditional public key cryptography and simultaneously overcomes the inherent key escrow problem suffered in identity-based cryptography. However, to the best of our knowledge, all existed constructions of certificate-based encryption so far have to be based on the bilinear pairings. The pairing calculation is perceived to be expensive compared with normal operations such as modular exponentiations in finite fields. The costly pairing computation prevents it from wide application, especially for the computation limited wireless sensor networks. In order to improve efficiency, we propose a new certificate-based encryption scheme that does not depend on the pairing computation. Based on the decision Diffie-Hellman problem assumption, the scheme's security is proved to be against the chosen ciphertext attack in the random oracle. Performance comparisons show that our scheme outperforms the existing schemes.

HyperCerts : 개인정보를 고려한 OTP 기반 디지털 졸업장 블록체인 시스템 (HyperCerts : Privacy-Enhanced OTP-Based Educational Certificate Blockchian System)

  • 정승욱
    • 정보보호학회논문지
    • /
    • 제28권4호
    • /
    • pp.987-997
    • /
    • 2018
  • 블록체인의 tamper-free 특성으로 많은 응용들이 개발되고 있다. MIT Media Lab 등은 기존 학력 증명의 진본 여부를 확인하는 절차의 복잡한 문제를 해결하기 위해서 블록체인 기반 디지털 졸업장 시스템을 개발하였다. 기존의 연구는 public blockchain 기반으로 원칙적으로 누구나 디지털 졸업장을 발급자가 될 수 있으나 이를 해결하기 위한 방법을 명확히 제시하고 있지 않다. 기존의 학력 증명 블록체인 시스템은 블록체인의 무결성을 활용하지만 개인정보가 다수 들어 있는 졸업장의 기밀성 문제를 해결하지 못하고 있다. 본 논문에서는 최초로 private blockchain 기반으로 HyperCerts라 명명된 디지털 졸업장 시스템을 제안한다. Private blockchain 기반이므로 신원이 확인된 신뢰할 수 있는 자만이 디지털 졸업장을 발급할 수 있으며 practical byzantine fault tolerance를 합의 알고리즘으로 이용하여 작은 컴퓨팅 파워를 필요로 하며 합의에 따른 지연이 매우 적은 장점이 있다. 디지털 졸업장은 민감한 개인정보를 포함한다. 따라서 디지털 졸업장의 privacy는 보장되어야 한다. HyperCerts는 디지털 졸업장의 hash값만 분산 원장에 저장하므로 악의적 노드의 참여로 인한 개인정보 유출 문제를 원천적으로 차단한다. 또한 디지털 졸업장은 암호화되고 OTP와 함께 제공되어 복호화 횟수 제한 등으로 디지털졸업장이 유출되었을 때 무분별한 복호화를 방지하도록 하였다.

철도제품 국제인증관련 정부 정책 및 인증획득 사례 분석을 통한 실효적 정책 개선안에 관한 제언 (Suggestions for effective policy improvement through analysis of government policies and certification acquisition cases related to international certification of railway domain products.)

  • 최요철
    • 시스템엔지니어링학술지
    • /
    • 제17권2호
    • /
    • pp.106-113
    • /
    • 2021
  • Today, the market and customer requirements for safety-related products in the Railway industry are continuously increasing, and companies that supply these products continue to make related efforts. However, the international standard requirements for making safety-related products are high, so small and medium-sized business companies are having difficulty developing them due to problems in time and cost to achieve them. This study examined government-centered international certificate policies and cases and suggested improvement measures based on the research results. In addition to supporting international certification costs, the government needs to expand technical consulting and expert training for them to solve problems in obtaining an international certificate.

차량간 인증 기반 메시지 집계 프로토콜 관리시스템 설계 (A Design of Protocol Management System for Aggregating Messages based on Certification between Vehicles)

  • 이병관;정은희
    • 한국산업정보학회논문지
    • /
    • 제18권4호
    • /
    • pp.43-51
    • /
    • 2013
  • 본 논문에서는 차량 간의 메시지 전송 시에 차량 메시지를 인증함으로서 Sybil 공격에 의해 메시지가 위 변조되는 것을 막고, 동시에 전송 시에 빈번하게 발생하는 중복되는 차량 메시지를 집계하여 효율적인 통신을 제공하는 차량간 인증 기반 메시지 집계 프로토콜 관리시스템 설계를 제안한다. 이를 위하여 제안 시스템은 첫째, 세션 키 기반 로컬인증서인 SKLC(Session Key based Local Certificate)를 설계하고, 둘째, 중복되는 차량 메시지를 집계하는 MAP(Message Aggregation Protocol) 설계를 제안한다. 따라서 제안 시스템은 차량의 인증서를 확인할 때, 해시함수 연산으로 메시지 무결성을 검증하여 신뢰성이 높은 정보를 안전하게 제공할 뿐만 아니라, 연산 처리 시간을 줄여 통신 효율도 향상시킨다.

Efficient Certificate-Based Proxy Re-encryption Scheme for Data Sharing in Public Clouds

  • Lu, Yang
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • 제9권7호
    • /
    • pp.2703-2718
    • /
    • 2015
  • Nowadays, public cloud storage is gaining popularity and a growing number of users are beginning to use the public cloud storage for online data storing and sharing. However, how the encrypted data stored in public clouds can be effectively shared becomes a new challenge. Proxy re-encryption is a public-key primitive that can delegate the decryption right from one user to another. In a proxy re-encryption system, a semi-trusted proxy authorized by a data owner is allowed to transform an encrypted data under the data owner's public key into a re-encrypted data under an authorized recipient's public key without seeing the underlying plaintext. Hence, the paradigm of proxy re-encryption provides a promising solution to effectively share encrypted data. In this paper, we propose a new certificate-based proxy re-encryption scheme for encrypted data sharing in public clouds. In the random oracle model, we formally prove that the proposed scheme achieves chosen-ciphertext security. The simulation results show that it is more efficient than the previous certificate-based proxy re-encryption schemes.

건설현장 물체에 맞음 사고 저감을 위한 줄걸이 작업 전문 자격제도 도입에 관한 연구 (A Study on the Introduction of a Rigging and Slinging Certificate System to Reduce a Struck by Object Accidents)

  • 염춘호;이진호;박현
    • 한국안전학회지
    • /
    • 제33권5호
    • /
    • pp.92-100
    • /
    • 2018
  • According to 'The Analysis of Industrial Accidents in 2016' by Ministry of Employment and Labor, the number of deaths caused by accidents in the construction field is 391, accounting for 47% of 826 industrial fatalities in all industries. The breakdown of the 391 fatalities of the construction industry shows that 'struck by an object' accident had 30 fatalities, the 3rd in frequency following falling (235) and crashing (32) accidents. This study aims to explore ways to reduce the 'struck by an object' accident with emphasis on safety education and certificate system for rigging and slinging works. This study reviews literature on rigging and slinging works and analyzes 'struck by an object' accidents. The rules and regulation on the rigging and slinging works are also reviewed both for Korea and other countries with best practices in construction safety such as Singapore, Japan, U.K., and U.S. The rigging and slinging certificate systems of those countries are also reviewed to find any advantage in the construction safety management. In addition, a pilot rigging and slinging certificate system was executed in one of domestic construction site followed by two surveys: one on the riggers who participated in the pilot operation and the other on general managers in domestic construction sites. Based on the analysis of the 'struck by an object' accidents and pilot operation, this study proposes a rigging and slinging certificate system to reduce accidents, enhancing safety condition of construction sites. The certificate system was proposed in a way to accommodate working practice of construction sites. Depending on rigging careers and a crane load capacity, riggers are eligible to apply either basic or master certificate which makes difference in the level of rigging works. The safety condition of rigging and slinging work could be substantially enhanced if workers, managers, supervisors, administrators, and policy makers work together consistently.

BCM(재해경감활동관리)산업 활성화를 위한 법·제도 개선 방안 연구 (A study on the improvement of BCM industry through legal systems)

  • 한종우
    • 방재&안전
    • /
    • 제5권1호
    • /
    • pp.93-100
    • /
    • 2015
  • Although many years passed since 'The Legislative bill on the support of voluntary activities of enterprises for disaster reduction'(hereinafter referred to as 'enterprise disaster reduction act') has been first enacted in 2007, BCMS is still not activated in our society. In contrast, after 911 Terror, importance of BCM is getting magnified and standardization research & institutionalization i s a lso proceeding i all over world. Lately, Disaster preventing activities is urgently needed like the sinking of 'Sewol ferry'. So the purpose of this paper is proposed for establishment of 'BCMS' and activation of the certificate system for Best-Run Business by analyzing the problem of 'enterprise disaster reduction act' and weak of activation as following. First, propel changing the policy of self-regulated participation to mandatory about the certificate system for Best-Run Business from public entity to government ministry and it is able to activate by propelling demo business of the certificate system for Best-Run Business. Second, public entity that has been given the certificate system for Best-Run Business by affiliating with Disaster Management Assessment of government management can be exempted from Disaster Management Assessment or those entity can arrange for connectivity acquisition method of 'Excellent rate'. Third, to publicize the activation of the law mentioned above, makes public entity r ecognizable by incorporating 'BCMS' into National safety management plan and establishment of National critical infrastructures security plan. Fourth, it should be reviewed to improving the related act regarding to inclusion of public organizations as well as private enterprises.

  • PDF

컴퓨터 관련 사무자동화 자격증취득을 위한 효율화 방안 (A Study on Efficient Plans for Acquisition of Office Automation Certificate of Qualification Relating to Computer)

  • 이경오
    • 경영과정보연구
    • /
    • 제15권
    • /
    • pp.165-186
    • /
    • 2004
  • When certificates of qualification relating to computer have shown up like dam water and meeting the age of office automation (OA) utilizing computer throughout the community, and at the point of time when the promotion of efficiency of duty is attempted by utilizing internet, the improvement plans should be groped for to expect to cultivate the national industrial manpower efficiently and by easily approaching the related OA certificates of qualification related to computer so that everyone can acauire the additional points for recognition of credit, entering company and promotion by the dimension of public trust, recognition degree, practial using level in actual affairs, reliability of problems and after manpower management of the certificates of qualification less expensively and saving time. the concrete plans are as follows: First, in the standard of making questions for the examination of 'Computer Utilizing Ability' executed by the chamber of commerce and Industry, there is the independent examination, but by inserting the presentation portion in the higher grade and middle grade, it should be contributed to improve office efficiency both in mane and reality. Second, though the internet retriever's examination is executed by the nongovernment specialized examination, since it is actually widely utilized in the office activities due to universality of using internet, it is now the time to newly establish and accommodate it as the national examination of 'internet Utilizing Ability', not the interest specialized retriever. Third, the applicants, shall take examination for the nongoverment certificate of qualification or enterprise's certificate of qualification at the date and place designated by the applicant, but there are much restrictions for the national certificate of qualification, so the date of examination shall be decided flexibly and efficiently to give chances to students by adjusting to the semesters of the students. Fourth, in this rapidly changing age of the informationalization community, the acquisition of the certificates of qualification through the university and the designated and entrusted educational institutes should be increased the proportion of activation to become officially recognized, and the extent of special treatment for obtainers of the certificate of qualification should be expanded to equip manpower competitive power in the age of informationalization.

  • PDF