Abstract:
본 발명은 전자 금융 거래 시스템에서 사용자에 대한 인증을 하기 위한 OTP발생기에 관한 것으로, OTP발생기는 외부 서버로부터 챌린지값(C 0 )을 수신하고, PUF(Physically Unclonable Fuction)모듈이 상기 챌린지값(C 0 )에 대응하는 응답값(R 0 )을 생성하면, 시간 동기 정보 및 상기 응답값(R 0 )을 이용하여 OTP비밀번호를 생성한다. 이러한 OTP발생기는 원하는 정보를 PUF의 응답값을 비밀키로 이용하여 암호화하여 보호하므로 공격자들이 어떤 정보도 복원할 수 없도록 하는 효과를 갖는다.
Abstract:
A system for managing wireless LAN security in a mobile terminal according to the present invention comprises a reception unit for receiving wireless LAN AP information; a reliability calculation unit for calculating reliability based on the wireless LAN AP information; a management unit for managing the access of the wireless LAN AP based on a threshold value for the calculated reliability; a storage unit for storing an AP list in which the threshold value for the reliability and the stored AP list exceeds; and an update unit for updating the AP list stored in the storage unit. The management unit connects to the wireless LAN AP included in the wireless LAN AP information received by the reception unit when the calculated reliability exceeds the threshold value. The management unit connects to a virtual private gateway when the calculated reliability does not exceed the threshold value.
Abstract:
A radio frequency identification (RFID) tag using a physically unclonable function (PUF) generates a response value corresponding to a challenge value, receives an ID of an RFID reader from the RFID reader, generates a first message authentication code for the ID of the RFID reader, the ID of the RFID tag, and time information by using the first response value corresponding to the first challenge value as a secrete key, and if the ID of the RFID reader is received, sends the first challenge value, the first message authentication code, and the time information of the RFID tag, which are tag identifying elements, to the RFID reader. The RFID tag shares the same message authentication code generation function as the RFID tag authentication server, the ID of the RFID tag, the first challenge value, and the first response value generated from the PUF module.
Abstract:
Disclosed is a device authenticating apparatus which authenticates a plurality of devices with physical unclonable function (PUF) circuits via an authentication server. An authentication requesting part transmits a first ID of a first device to the authentication server to authenticate the first device and requests the server to authenticate the first device. A first authentication information part receives first set authentication information, using a first response value corresponding to an arbitrary first challenge value on the first ID as a private key, from the authentication server. A second authentication information part generates a second response value in the PUF circuit based on the first challenge value extracted from the first authentication information and transmits second set authentication information including the second response value to the authentication server. An authentication checking part receives data on whether the first response value is identical to the second response value from the authentication server and authenticates the first device. The present invention authenticates a device by using a challenge-response value which plays a role like a fingerprint of a device in various fields, thereby may defense sham attacks from a malicious device and effectively cope with various security attacks which may occur afterwards.
Abstract:
ARP스푸핑 감지단말은 서버로부터 인가된 호스트의 ARP정보를 수신하고, ARP정보로부터 맥 주소 및 아이피 주소를 수집하고, ARP테이블에 인가된 호스트의 맥 주소 및 아이피 주소를 정적 할당하고, 인가된 호스트와 동일한 아이피 주소에 대한 ARP응답 패킷을 수신한 경우, ARP스푸핑 공격으로 감지한다.
Abstract:
A radio frequency identification (RFID) tag generates a random number, stores a private key, ID of the RFID tag and a first random number generated in a random number generator in advance, receives ID of an RFID reader from the RFID reader, generates a first message authentication code with respect to the RFID reader ID and time information by using the RFID tag ID as a private key, and encrypts first and second random numbers using the private key. If the RFID tag receives the ID of the RFID reader, the RFID tag transmits the first random number, first message authentication code, ID of the RFID reader, time information, first and second random numbers encrypted with the private key, which are tag identification elements, to the RFID reader. In this case, the RFID tag shares the same message authentication code generating function, private key, RFID tag ID and first random number with the RFID tag authentication server.
Abstract:
Disclosed is an apparatus for authenticating secure sockets layer/transport layer security (SSL/TLS). A private key generator generates a plurality of private keys associated with each other using SSL/TLS private keys to separately store the private keys in a first cloud and a second cloud. A protocol unit receives an SSL/TLS generation request message from a web browser to start an SSL/TLS handshake protocol. A private key operating unit enables the first cloud to transmit a private key operation request message to the second cloud, and the second cloud receives the private key operation request message to transmit a private key operation result message to the first cloud. An SSL/TLS channel forming unit shares a private key with the web browser based on the private key operation result message received by the first cloud to form an SSL/TLS channel. The present invention may stably protect the private key from malicious access of a public cloud in a cloud environment and form a stable SSL/TLS channel to stably protect a web user and a web server.