Abstract:
The present invention relates to an information protection technology for web mashup contents right management, a method for authenticating a user to use web multi contents according to the present invention includes: a step of confirming preparation for right information of a user for at least one contents and requesting for user right verification to a domain which supplies the contents; a step of performing authentication for the user who wants to use the contents; a step of verifying if the request of the user for the contents is within the authenticated right or not; and a step of decoding and providing the contents. According to the present invention, the access control for data convergence in a web service environment which use one protocol according to the same origin policy. Also, the alternation or the theft for contents (data and code) in the web convergence service environment can be prevented. [Reference numerals] (AA) Start; (BB) End; (S100) Requesting for user right verification; (S200) Authenticating a user; (S300) Authenticating user right; (S38) Data to be transmitted exists?; (S40) At least 256 byte?; (S400) Providing contents; (S42) Separating into 256 byte; (S44) Transmitting in 256 byte-unit; (S46) Corresponding event ended?; (S48,S56) Transmitting a doorbell; (S50) Event of the corresponding symbol ended?; (S52) Writing operation interrupt generated?; (S54) Transmitting the corresponding data; (S58) Executing the entire event table?
Abstract:
PURPOSE: A method for generating security labels for distributing scalable contents and a device thereof are provided to apply a differentiated security policy which is evaluated by performance indexes to a service in consideration of requirements and service conditions which are different for each scalable unit. CONSTITUTION: A scalable content transmitting unit(1100) generates a security label and an encoded scalable unit. A scalable content receiving unit(1200) receives the encoded scalable unit and the security label. The scalable content receiving unit decodes, reproduces, modifies, stores, or redistributes the encoded scalable unit according to the security label. A scalable content storage(1000) searches scalable content and metadata corresponding to a request of the scalable content transmitting unit.
Abstract:
PURPOSE: A group generating method of multicast network and participating method thereof are provided to supply high security. CONSTITUTION: A second node(D43) requests generation of a group to a third node(D49) which is a root candidate node based on a research result. The third node received from generated of the group provides their ID to a first node(D6A).
Abstract:
PURPOSE: A data encryption apparatus and a method thereof, a data decoding apparatus, a data searching method are provided to stably encode and store data by configuring a column of a table inside a database. CONSTITUTION: A conversion unit(120) searches a range interval corresponding to first unit character of input data at a domain interval, and divides the searched range interval through an interval division method. The conversion unit searches a range interval for the final character of input data, and an encryption unit(140) generates an encryption value of the input data by using the searched range interval for the final character. The encryption unit calculates the character length of the input data.
Abstract:
A method for generating indirect trust binding between peers in a P2P network is provided to enable a source peer to be aware of trust of the destination peer using a trust binding generation result since the indirect trust binding is not broken down by an attacker. A method for generating indirect trust binding between peers comprises the following steps. A source peer P1 generates an initialization request message of a destination peer P2 for receiving a session identifier of the destination peer P2 to transmit the same to the destination peer P2(S1). The destination peer P2 receives and analyzes the initialization request message to generate a response message including a session identifier of itself, and transmits the same to the source peer P1(S2). The source peer P1 selects one of a plurality of peers on the P2P network as a relay peer P3(S3). The source peer P1 generates an indirect trust binding request message encrypted using the session identifier of itself, a session identifier of the destination peer, and a session identifier of a relay peer according to an IBC(Identity Based Cryptography) mechanism to transmit the same to the relay peer P3(S4). The relay peer P3 receives and analyzes the indirect trust binding request message to detect the destination peer P2, and delivers the received indirect trust binding request message to the detected destination peer P2(S5). The destination peer P2 forms indirect trust binding to the source peer P1 in response to the indirect trust binding request message, and generates an indirect trust binding checking message encrypted using the session identifier of itself, and a session identifier of the source peer to transmit the same to the source peer P1(S6). The source peer P1 receives and analyzes the indirect trust binding checking message to check an indirect trust binding generation result, and measures trust of the destination peer P2(S7).
Abstract:
A method for providing a VPN(Virtual Private Network) service to a mobile node in an IPv6 network and a gateway for the same are provided to offer IP mobility in a VPN service and support the mobility of a mobile node inside and outside a VPN domain by executing a function corresponding to a mobile IPv6 HA(Home Agent). An MVPN gateway executes an IKE(Internet Key Exchange) negotiation with a mobile node which has executed handover, acquires a SA(Security Association), and authenticates the mobile node(S301). The MVPN gateway receives a BU(Binding Update) message from the mobile node, verifies it, stores new location information of the mobile node, transmits a BA(Binding Acknowledge) message, and executes mobility processing(S303). Then, the MVPN executes IPsec(IP security) processing for a packet to be transmitted to a CN(Correspondent Node) from the mobile node and delivers it to the CN(S305). For a packet transmitted to home address of the mobile node from the CN, the MVPN reconfigures it so that it can be delivered to the CoA(Care of Address) of the mobile node(S307).
Abstract:
IPv6 로컬 네트워크에서 이웃 발견 서비스 거부 공격을 방지하기 위한 장치 및 방법이 개시된다. 본 발명에 따른 장치는 내부 호스트의 IP 주소를 저장하는 IP 주소 저장부; 저장되어 있는 IP 주소인지 검색하는 외부 목적지 IP 주소 검색부; 목적지 IP 주소가 IP 주소 저장부에 저장된 IP 주소인 경우에는 높은 품질의 이웃 발견(ND: Neighbor Discovery) 서비스를 제공하고, IP 주소 저장부에 등록되지 않은 IP 주소인 경우에는 낮은 품질의 이웃 발견 서비스를 제공하는 차등 서비스 제공부; 및 이웃 발견 프로토콜을 수행하는 이웃 발견 확인부;를 포함한다. 본 발명에 따르면, 로컬 네트워크의 IPv6 주소 구성 방식과 상관없이 정상 패킷이 차단되는 문제를 최소화하면서 IPV6 로컬 네트워크에서 발생하는 이웃 발견 서비스 거부 공격을 방지할 수 있다. 이웃 발견 프로토콜, NDP, 거부 공격, IPv6 로컬 네트워크, 차등 서비스
Abstract:
이동 IPv6 환경에서 AAA(Authentication Authorization Accounting) 기반 구조를 통한 IPSec 보안 연계 분배 방법 및 시스템이 개시되어 있다. 본 발명은 AAA 기반 구조와 연동된 모바일 IPv6환경에서 이동 노드와 홈에이전트간에 IPSec 보안 연계를 분배하는 IPSec 보안 연계 분배 방법에 있어서, 이동 노드가 상기 AAA기반구조로 보안 연계 분배를 요청하면 소정의 인증 절차를 거쳐 상기 홈에이전트에 보안 연계 분배에 필요한 정보를 요청하는 과정, 홈에이전트로부터 보안 연계 분배 요청의 정책 정보와 일치하는 정책의 존재 여부와 알고리듬 선택 메시지를 수신하면 그 메시지를 바탕으로 보안 연계 구성 정보를 생성하는 과정, 생성된 보안 연계 정보 메시지를 상기 이동 노드 및 상기 홈 에이전트로 분배하는 과정을 포함한다.