• Title/Summary/Keyword: single sign-on

Search Result 198, Processing Time 0.024 seconds

A Study on the design of broker and agent based Single Sign-On system (브로커 및 에이전트 기반의 통합 단일 인증 시스템 설계에 관하 연구)

  • 최홍민;손태식;서정택;채송화;유승화;김동규
    • Proceedings of the Korean Information Science Society Conference
    • /
    • 2001.04a
    • /
    • pp.829-831
    • /
    • 2001
  • 현재의 정보통신 사회에서 널리 사용되는 인터넷 서비스는 기본적으로 ID/PW(PassWord) 기반의 인증을 사용한다. 이때 사용자는 여러 웹 서비스에 대해서 각각 다양한 ID/PW를 기억해야 한다는 어려움을 가진다. 마찬가지로 웹 서비스 관리자 역시 여러 사용자들의 ID/PW를 관리하는데 많은 비용 및 노력을 소모해야 한다. 따라서 한 번의 안전한 인증 과정을 통해 사용자 및 관리자의 편리를 도모할 수 있는 SSO(Single Sign-On) 시스템의 적용이 필수적으로 요구되고 있다. 본 연구에서는 기존의 SSO 시스템을 분석하여 새롭게 모든 인터넷 환경에서 보다 안전하게 사용자에게 서비스를 제공하며, 관리자에게는 편리성을 제공하는 브로커와 에이전트의 기능을 포함한 통합 SSO 시스템을 설계하며, 추후 연구과제로서 실제 브로커 및 에이전트 기반 통합 SSO 시스템 구현 및 적용에 대하여 연구 할 것이다.

  • PDF

A Study on the Improved Broker-based Single Sign-On Model (개선된 브로커 기반 SSO 모델 연구)

  • Kim, Hyun-Jin;Lee, Im-Yeong
    • Proceedings of the Korea Information Processing Society Conference
    • /
    • 2014.04a
    • /
    • pp.401-403
    • /
    • 2014
  • 초고속 인터넷 망이 발달함에 따라 다양한 서비스들에 대한 사용자의 요구가 증가되었다. 보통 사용자들은 여러 서비스 사이트를 이용함에 있어 여러 개의 아이디와 패스워드를 기억하여 사용한다. 이러한 불편함을 해결하고 관리측면에서 효과적인 방법으로 제안된 인증 시스템이 SSO(Single Sign-On)이다. SSO 인증 모델 중 브로커 기반의 경우 중앙집중식 시스템 관리를 사용하여 인증 연산처리의 효율성을 증가시키는 장점을 가지고 있으며, 대표적으로 Kerberos 인증이 있다. 하지만 전통적인 Kerberos 인증은 패스워드 공격 및 재전송 공격에 비교적 심각한 위험성을 가지고 있어 그에 대한 연구가 활발히 진행되었다. 이에 본 논문에서는 기존방식의 문제점을 해결하여 보다 개선된 브로커 기반 SSO 인증 모델을 제안하였다.

A Study on Single Sign-On Authentication Model using Multi Agent (멀티 에이전트를 이용한 Single Sign-On 인증 모델에 관한 연구)

  • 서대희;이임영
    • The Journal of Korean Institute of Communications and Information Sciences
    • /
    • v.29 no.7C
    • /
    • pp.997-1006
    • /
    • 2004
  • The rapid expansion of the Internet has provided users with a diverse range of services. Most Internet users create many different IDs and passwords to subscribe to various Internet services. Thus, the SSO system has been proposed to supplement vulnerable security that may arise from inefficient management system where administrators and users manage a number of ms. The SSO system can provide heightened efficiency and security to users and administrators. Recently commercialized SSO systems integrate a single agent with the broker authentication model. However, this hybrid authentication system cannot resolve problems such as those involving user pre-registration and anonymous users. It likewise cannot provide non-repudiation service between joining objects. Consequently, the hybrid system causes considerable security vulnerability. Since it cannot provide security service for the agent itself, the user's private information and SSO system may have significant security vulnerability. This paper proposed an authentication model that integrates a broker authentication model, out of various authentication models of the SSO system, with a multi-agent system. The proposed method adopts a secure multi-agent system that supplements the security vulnerability of an agent applied to the existing hybrid authentication system. The method proposes an SSO authentication model that satisfies various security requirements not provided by existing broker authentication models and hybrid authentication systems.

Implementation of the SSO model applying the SAML authentication (SAML인증을 적용한 SSO (Single Sign On)모델의 구현)

  • Jeong, Jong-Il;Sung, Baek-Ho;Park, Byung-Chul;Shin, Dong-Kyoo;Shin, Dong-Il
    • Proceedings of the Korea Information Processing Society Conference
    • /
    • 2003.05c
    • /
    • pp.2053-2056
    • /
    • 2003
  • 인터넷 사용자들의 다양한 요구에 따라 존재하는 많은 자원들에 접근하기 위해 이용되었던 기존의 개별적인 인증절차는 패스워드 관리와 보관 피리고 공개된 네트워크를 통해 빈번히 전송되어지는 보안상의 취약점이 노출되어있다. 단일인증을 통해 보다 효율적이고 안전하게 필요한 자원에 접근하는 방법으로 SAML인증을 적용한 Single Sign On모델을 구현하였다.

  • PDF

A Study on Secure and Improved Single Sign-On Authentication System against Replay Attack (재전송 공격에 안전하고 개선된 Single Sign-On 인증 시스템에 관한 연구)

  • Kim, Hyun-Jin;Lee, Im-Yeong
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.24 no.5
    • /
    • pp.769-780
    • /
    • 2014
  • In general, internet users need to remember several IDs and passwords when they use diverse web sites. From an effective management perspective, SSO system was suggested to reduce user inconvenience. Kerberos authentication, which uses centralized system management, is a typical example of a broker-based SSO authentication model. However, further research is required, because the existing Kerberos authentication system has security vulnerability problems of password and replay attacks. In SSO authentication systems, a major security vulnerability is the replay attack. When user credentials are seized by attackers, an authorized session can be obtained through a replay attack. In this paper, an improved SSO authentication model based on the broker-based model and a secure lightweight SSO mechanism against credential replay attack is proposed.

An User Authentication Mechanism in the OSGi Service Platform Environment (OSGi서비스 플랫폼 환경에서의 사용자 인증 메커니즘)

  • 전경석;문창주;박대하;백두권
    • Journal of KIISE:Computing Practices and Letters
    • /
    • v.9 no.2
    • /
    • pp.191-204
    • /
    • 2003
  • In the home gateway environment, several characteristics for the user authentication mechanism should be reflected separately from the existing distributed service environment. First, the platform of a home gateway is a component based system that its services are installed dynamically. Second, the convenience that user can use several services by authentication of once should be offered. Finally, the system resources of a home gateway are restricted. However, a user authentication mechanism that reflected these characteristics is not shown at the user admin service specification of the OSGi service platform.(OSGi is the representative standardization organization of hone gateway.) Also, there is no existing authentication protocol that satisfies these qualities at the same time. In this paper, we propose a new user authentication mechanism considering those characteristics for the home gateway environment. We also design and implement an independent authentication service bundle based on the OSGi service platform so that it can perform user authentication operations for each bundle service. We supplement and extend the Kerberos Protocol that can apply.

Synchronization of the LDAP(Lightweigth Directory Access Protocol) information with web site member informal ion for a SSO(Single Sign-On) setup (SSO(Single Sign-On)체제 구축을 위한 웹 사이트 회원정보와 LDAP(Lightweight Directory Access Protocol)정보 동기화)

  • Cheon inhyeuk;Yi T.S.;Lee S.H.;Kim N.G.;Shin Kijeong
    • Proceedings of the Korean Information Science Society Conference
    • /
    • 2005.07b
    • /
    • pp.103-105
    • /
    • 2005
  • 공공 부문이나 대기업에서 운영하는 웹 사이트의 규모가 커지면서 분야별로 사이트가 나누어지게 되는데, 사이트를 이동할 때 마다 로그인을 다시 해야 하는 불편이 있다. 따라서 최근 이용자들의 불편을 줄이기 위하여 SSO (Single Sing-On) 통합인증 체제를 도입하는 사례가 늘고 있다. 통합 인증 시스템을 구축하면서 다수 웹 사이트의 회원을 통합하고 이에 대한 회원 정보 DB를 구축하여야 하는데, 빠른 인증서비스를 위해서 LDAP(Lightweight Directory Access Protocol)를 사용하는 것이 일반적이다. 이때 회원정보 DB와 LDAP의 정보에 대한 동기화 문제와 웹 사이트를 통한 회원가입과 동시에 적용되어야 하는 요구사항을 만족시키기 위해 본 논문에서는 회원 정보 DB와 LDAP의 정보 사이의 동기화 방법을 제안하고 구현하여 그 성능을 분석하였다.

  • PDF

Design and Implementation of Data Acquisition and Storage Systems for Multi-view Points Sign Language (다시점 수어 데이터 획득 및 저장 시스템 설계 및 구현)

  • Kim, Geunmo;Kim, Bongjae
    • The Journal of the Institute of Internet, Broadcasting and Communication
    • /
    • v.22 no.3
    • /
    • pp.63-68
    • /
    • 2022
  • There are 395,789 people with hearing impairment in Korea, according to the 2021 Disability Statistics Annual Report by the Korea Institute for the Development of Disabled Persons. These people are experiencing a lot of inconvenience through hearing impairment, and many studies related to recognition and translation of Korean sign language are being conducted to solve this problem. In sign language recognition and translation research, collecting sign language data has many difficulties because few people use sign language professionally. In addition, most of the existed data is sign language data taken from the front of the speaker. To solve this problem, in this paper, we designed and developed a storage system that can collect sign language data based on multi-view points in real-time, rather than a single point, and store and manage it with high usability.

Single-molecule Detection of Fluorescence Resonance Energy Transfer Using Confocal Microscopy

  • Kim, Sung-Hyun;Choi, Don-Seong;Kim, Do-Seok
    • Journal of the Optical Society of Korea
    • /
    • v.12 no.2
    • /
    • pp.107-111
    • /
    • 2008
  • We demonstrated single-molecule fluorescence resonance energy transfer (FRET) from single donor-acceptor dye pair attached to a DNA with a setup based on a confocal microscope. Singlestrand DNAs were immobilized on a glass surface with suitable inter-dye distance. Energy transfer efficiency between the donor and the acceptor dyes attached to the DNA was measured with different lengths of DNA. Photobleaching of single dye molecule was observed and used as a sign of single-molecule detection. We could achieve high enough signal-to-noise ratio to detect the fluorescence from a single-molecule, which allows real-time observation of the distance change between single dye pairs in nanometer scale.

The Usefulness of the Ivy Sign on Fluid-Attenuated Intensity Recovery Images in Improved Brain Hemodynamic Changes after Superficial Temporal Artery-Middle Cerebral Artery Anastomosis in Adult Patients with Moyamoya Disease

  • Lee, Jung Keun;Yoon, Byul Hee;Chung, Seung Young;Park, Moon Sun;Kim, Seong Min;Lee, Do Sung
    • Journal of Korean Neurosurgical Society
    • /
    • v.54 no.4
    • /
    • pp.302-308
    • /
    • 2013
  • Objective : MR perfusion and single photon emission computerized tomography (SPECT) are well known imaging studies to evaluate hemodynamic change between prior to and following superficial temporal artery (STA)-middle cerebral artery (MCA) anastomosis in moyamoya disease. But their side effects and invasiveness make discomfort to patients. We evaluated the ivy sign on MR fluid attenuated inversion recovery (FLAIR) images in adult patients with moyamoya disease and compared it with result of SPECT and MR perfusion images. Methods : We enrolled twelve patients (thirteen cases) who were diagnosed with moyamoya disease and underwent STA-MCA anastomosis at our medical institution during a period ranging from September of 2010 to December of 2012. The presence of the ivy sign on MR FLAIR images was classified as Negative (0), Minimal (1), and Positive (2). Regions were classified into four territories: the anterior cerebral artery (ACA), the anterior MCA, the posterior MCA and the posterior cerebral artery. Results : Ivy signs on preoperative and postoperative MR FLAIR were improved (8 and 4 in the ACA regions, 13 and 4 in the anterior MCA regions and 19 and 9 in the posterior MCA regions). Like this result, the cerebrovascular reserve (CVR) on SPECT was significantly increased in the sum of CVR in same regions after STA-MCA anastomosis. Conclusion : After STA-MCA anastomosis, ivy signs were decreased in the cerebral hemisphere. As compared with conventional diagnostic modalities such as SPECT and MR perfusion images, the ivy sign on MR FLAIR is considered as a useful indicator in detecting brain hemodynamic changes between preoperatively and postoperatively in adult moyamoya patients.