차량용 네트워크의 침입 탐지 시스템(IDS) 및 그 제어방법
    22.
    发明授权
    차량용 네트워크의 침입 탐지 시스템(IDS) 및 그 제어방법 有权
    车内网络侵入检测系统及其控制方法

    公开(公告)号:KR101638613B1

    公开(公告)日:2016-07-11

    申请号:KR1020150054404

    申请日:2015-04-17

    Abstract: 본발명은차량내부네트워크에대한공격시도를사전에차단하는침입탐지시스템(IDS) 및그 제어방법에관한것이다. 상기와같은과제를해결하기위해본 발명의일 실시예에따른차량의공격탐지시스템(IDS)에서네트워크공격을탐지하는방법은, 기설정된주기동안네트워크의메시지들을입력받는단계; 상기입력된각 메시지별로현재발생빈도값을구하는단계; 상기주기가시작될때 차량의동작상태정보를입력받는단계; 상기동작상태정보에대응되는메시지별정상발생빈도값을호출하는단계; 상기현재발생빈도값 및상기정상발생빈도값을이용하여메시지별로선형근사화한상대거리함수연산을수행하는단계; 및상기선형근사화한상대거리함수연산의결과를기 설정된임계값과비교하여상기각 메시지별로공격상태여부를판단하는단계를포함할수 있다.

    Abstract translation: 入侵检测系统(IDS)及其控制方法技术领域本发明涉及一种先前阻止企图攻击车载网络的入侵检测系统(IDS)及其控制方法。 为此,根据本发明的实施例的用于检测在车辆的攻击检测系统(或IDS)中的网络的攻击的方法可以包括以下步骤:在预设时段内接收网络的消息; 获得每个接收到的消息的当前重复率; 在该周期的起始点接收车辆的操作状态信息; 为每个消息调用对应于操作状态信息的正常重复率; 通过使用当前重复率和正常重复率来计算每个消息的线性近似相对距离函数; 以及通过将所述线性近似相对距离函数的计算结果与预设阈值进行比较来确定是否存在针对每个消息的攻击状态。

    차량 네트워크 공격 탐지 장치 및 그 방법
    23.
    发明授权
    차량 네트워크 공격 탐지 장치 및 그 방법 有权
    用于检测车辆网络的装置及其方法

    公开(公告)号:KR101371902B1

    公开(公告)日:2014-03-10

    申请号:KR1020120144900

    申请日:2012-12-12

    CPC classification number: H04L63/1425 H04L67/12

    Abstract: The present invention relates to a device for detecting an attack on a vehicle network and a method thereof and is to provide to a device for detecting an attack on a vehicle network and a method thereof which accumulatively counts packets by each device (ID) connected to a vehicle network bus, calculates the accumulated value by accumulating an inspected value (S) whenever accumulatively counting packets and determines that an attack is occurred if the average accumulated value calculated by dividing the accumulated value by the accumulated counting does not exceed a first threshold value. For the purpose, in a vehicle network environment in which devices, having a priority for packet transmission, connected to a vehicle network bus include: a packet collection unit for collecting packets transmitted through the vehicle network bus; a packet counting unit for accumulatively counting the number of packets collected by the packet collection unit; an inspected value calculation unit for calculating an inspected value based on a time difference between packets having the same ID; an accumulated value calculation unit for calculating an accumulated value by adding the inspected value which is calculated by the inspected value calculation unit to the previous inspected value; an average accumulated value calculation unit for calculating the average accumulated value by dividing the accumulated value calculated by the accumulated value calculation unit by accumulated counting value by the packet counting unit; and an attack determination unit for determining the existence of attack based on the average accumulated value calculated by the average accumulated value calculation unit. [Reference numerals] (10) Packet collection unit; (20) Packet counting unit; (30) Inspected value calculation unit; (40) Accumulated value calculation unit; (50) Average accumulated value calculation unit; (60) Attack determination unit; (70) Control unit

    Abstract translation: 本发明涉及一种用于检测车辆网络攻击的装置及其方法,并提供给用于检测对车辆网络的攻击的装置及其方法,其中每个装置(ID)对连接到车辆网络的数据进行累积计数 车辆网络总线,每当累积计数分组时累积检查值(S)来计算累积值,并且如果通过将累加值除以累加计数而计算的平均累积值不超过第一阈值,则确定发生攻击 。 为此,在车辆网络环境中,具有连接到车辆网络总线的分组传输优先级的设备包括:分组收集单元,用于收集通过车辆网络总线传送的分组; 分组计数单元,用于累积计数由所述分组收集单元收集的分组的数量; 检查值计算单元,用于基于具有相同ID的分组之间的时间差计算检查值; 累积值计算单元,用于通过将由检查值计算单元计算的检查值与先前检查值相加来计算累积值; 平均累计值计算单元,用于通过将由累积值计算单元计算出的累积值除以累积计数值来计算平均累积值; 以及攻击确定单元,用于基于由平均累积值计算单元计算的平均累积值来确定攻击的存在。 (附图标记)(10)分组收集单元; (20)分组计数单元; (30)检验价值计算单位; (40)累计值计算单位; (50)平均累计值计算单位; (60)攻击判定单元; (70)控制单元

    데이터 보안이 강화된 전자 서명 장치 및 방법

    公开(公告)号:KR101873881B1

    公开(公告)日:2018-07-03

    申请号:KR1020160160261

    申请日:2016-11-29

    Abstract: 데이터보안이강화된전자서명장치및 방법이개시된다. 본발명은 "1"과 "0"의코드값을임의의성분들로포함하는 (n-k) x k 크기의제1 부분행렬(submatrix) R과 (n-k) x (n-k)의크기를갖는단위행렬인제2 부분행렬 I가열 방향으로조합된제1 행렬 H를생성하고, "1"과 "0"의코드값을성분으로포함하는 (n-k) x (n-k) 크기의스크램블링행렬 Q와 "1"과 "0"의코드값을성분으로포함하는 n x n 크기의순열행렬 P를생성한후 상기제1 행렬 H, 상기스크램블링행렬 Q 및상기순열행렬 P를개인키로활용하여전자서명값을생성하고, 상기스크램블링행렬 Q, 상기제1 행렬 H 및상기순열행렬 P가곱해진 QHP를공개키로사용하여상기전자서명값을검증하는새로운방식의전자서명생성및 검증과관련된알고리즘을제공할수 있다.

    데이터 보안이 강화된 전자 서명 장치 및 방법

    公开(公告)号:KR1020180060588A

    公开(公告)日:2018-06-07

    申请号:KR1020160160261

    申请日:2016-11-29

    CPC classification number: G06F21/33 H04L9/30 H04L9/3247

    Abstract: 데이터보안이강화된전자서명장치및 방법이개시된다. 본발명은 "1"과 "0"의코드값을임의의성분들로포함하는 (n-k) x k 크기의제1 부분행렬(submatrix) R과 (n-k) x (n-k)의크기를갖는단위행렬인제2 부분행렬 I가열 방향으로조합된제1 행렬 H를생성하고, "1"과 "0"의코드값을성분으로포함하는 (n-k) x (n-k) 크기의스크램블링행렬 Q와 "1"과 "0"의코드값을성분으로포함하는 n x n 크기의순열행렬 P를생성한후 상기제1 행렬 H, 상기스크램블링행렬 Q 및상기순열행렬 P를개인키로활용하여전자서명값을생성하고, 상기스크램블링행렬 Q, 상기제1 행렬 H 및상기순열행렬 P가곱해진 QHP를공개키로사용하여상기전자서명값을검증하는새로운방식의전자서명생성및 검증과관련된알고리즘을제공할수 있다.

Patent Agency Ranking