Abstract:
PURPOSE: A runtime providing apparatus and a method for application service sealing execution provide a security virtualization interface layer for application service data requiring security consumption, and thereby maximize security of application service execution or application service data consumption. CONSTITUTION: A security virtualization interface layer (310) has an application service received through a user space (300) use hardware resources (450) and kernel services (432) of the lower part of a kernel space (340). A container parser (410) separates a virtualization security code and an application service from a service container received from a service providing server (100). A security virtualization interface generator (412) uses the virtualization security code and service policy to produce security virtualization interface. A virtualization service injector (414) stacks the application service in a VM (Virtual Machine) (420) through the security virtualization interface layer according to a policy in the security virtualization interface. [Reference numerals] (AA) Start; (BB) End; (S500) Receive a service container; (S502) Classification by Information in the service container; (S504) Deliver a virtualization security code and relevant information to an SVIF generator; (S506) Deliver a service(service data) to a VS injector; (S508) Generate a virtual interface after requesting and receiving a service policy; (S510) Separate application for the service required?; (S512) Request and receive the application; (S514) Inject the application service(application) to a virtual machine using a security virtualization interface; (S516) Is the security virtualization interface using code verification abnormal?; (S518) Request the implement or consumption of the application service(application); (S520) Stop the application service(application)
Abstract:
PURPOSE: A method and apparatus for preventing leakage and misuse for the client's derivative personal information are provided to protect the client's derivative information from the leakage and misuse by the internal operator by automatically analyzing the work action of a service operator according to the security policy of the service provider and detecting the abnormal action of the service operator in real-time. CONSTITUTION: An method for preventing leakage and misuse for the client's derivative personal information includes the steps of: monitoring the Internet service operator's information search, the combination of the searched information with other information, and the usage of the derivative personal information derived from the searched information; and, if the matters on the violation of work by an operator is detected, executing handling of the violation of work for the individual Internet service operator(320). The range of using the client's information is different depending on the level of the client registered to the service and the level of the service operator.
Abstract:
PURPOSE: A method and apparatus for providing data freshness check of media data are provided to configure an SVC(Scalable Video Coding) and conversion information as a message digest with a feature and control information by layer. CONSTITUTION: A scalable media transmitter(100) transmits feature information and control information which are extracted from the encoded and converted scalable media data. A scalable media receiver(300) verifies the integrity of the scalable media. A secure directory(400) stores the characteristic information and control information. A scalable media reuse device(500) requests the retransmission of the scalable media to the scalable media receiver.
Abstract:
PURPOSE: A real time content service method and an apparatus for the same are provided to secure a safety for whole service section by regulating security intensity based on a single security mechanism. CONSTITUTION: A secure memory generator(114) creates security message which recognizes encryption information of a media content. The media content is extracted by layers through an SVC(Scalable Video Coding) content layer extracting unit(112). A bit stream transmitter(116) transmits the security message and a media content extracted by the layers into a bit stream type. An interconnector(400) changes the media content into a reusable content.
Abstract:
PURPOSE: An SVC encryption device and a method thereof are provided to proceed safe media conversion in the network node by performing per-condition data encryption additionally about the NAL data of the bit stream. CONSTITUTION: An encoding and an encrypting unit(102a) performs the SVC encoding of the inputted contents. An NAL data analyzer(102b) extracts the NAL data corresponding to the second encoding condition by the NAL data analysis of the generated SVC bit stream. A per-condition NAL data encryption unit(102c) encodes the extracted NAL data according to the second encoding condition. A bit stream transmitter(102d) transmits the encrypted SVC bit stream.
Abstract:
A key management method for providing secure communication on a P2P network and an apparatus for managing the key are provided to authenticate ownership of a public key safely by using an authentication method using a PK1-based structure. A message receiving process is performed to receive a file search request message transmitted from a first peer of a P2P network. A search process is performed to search the presence of the file requested in the message receiving process. A file search response message composition process is performed to compose a file search response message including internet protocol address and public key data of a second peer for storing the corresponding file when the file is searched in the search process. A transmission process is performed to transmit the composed response message to the first peer.
Abstract:
본 발명에 의한 IPv6 네트워크에서 이동노드에게 VPN 서비스를 제공하는 방법 및 이를 위한 게이트웨이는 핸드오버를 수행한 이동노드와 IKE 협상을 수행하고 보안연관(SA; Security Association)을 획득한 후 상기 이동단말을 인증하는 단계; 이동노드로부터 BU(Binding Update)메시지를 수신하여 검증한 후 이동노드의 새로운 위치정보를 저장하고 BA(Binding Acknowledge)메시지를 송신하여 이동성 처리를 수행하는 단계; 상기 이동성 처리가 완료된 후 이동노드가 대응노드(CN)로 송신하는 패킷에 대하여는 인터넷 보안 프로토콜(IP security protocol, IPsec) 처리를 하여 전달하는 단계; 및 대응노드가 이동노드의 홈 주소로 송신하는 패킷에 대하여는 상기 이동노드의 보조주소로 전달될 수 있도록 패킷을 재구성하여 전달하는 단계;를 포함하는 것을 특징으로 하며, Mobile IPv6의 홈에이전트(HA : Home Agent)에서 수행하는 기능을 수행하여 VPN 서비스에서 IP 이동성을 제공할 수 있으며, MN의 VPN 도메인 내부에서의 이동성뿐만 아니라 그 외부에서의 이동성도 지원할 수 있다. IPv6, VPN Gateway, Mobile Node, Home Agent, MIPv6, reverse tunneling
Abstract:
본 발명은 평가규칙표기언어를 이용한 IPv6 네트워크 계층의 보안성 평가 시스템 및 방법에 관한 것으로서, 사용자 인터페이스를 이용하여 평가규칙표기언어의 문법에 맞게 보안성 평가규칙을 기술할 수 있도록 지원하며, 평가실행 요구명령을 발생시키고, 평가결과를 조회하고, 평가규칙처리 모듈을 이용하여 상기 평가실행 요구명령에 대응하여 평가규칙을 해석하고, 평가대상 시스템의 패킷 수집기로부터 패킷을 수집하여 분석 및 가공하며, 평가결과를 출력시키며, DBMS에 상기 평가결과를 저장하며, 평가결과 조회요구에 대응하여 해당 데이터를 사용자 인터페이스로 전달하여, 평가대상 시스템의 보안 위협요소를 도출함으로 더욱 안전성을 보장하는 시스템을 개발할 수 있는 많은 장점을 제공할 수 있다. 평가규칙표기언어, IPv6, 보안, 평가
Abstract:
본 발명은 네트워크 보안관리 시스템에 관한 것으로 특히, 그래픽 사용자 인터페이스(Graphical User Interface, 이하 GUI)를 이용하여 네트워크 보안관리의 편리성을 꾀할 수 있는 네트워크 보안관리 시스템에 관한 것이다. 본 발명이 제공하는 네트워크 보안관리 시스템은 네트워크상에 있는 노드의 보안이벤트 발생을 감지하거나, 사용자로부터 상기 노드의 보안관련 처리 요청을 받아 상기 노드의 보안을 관리하는 보안관리 모듈; 및 상기 보안관리 모듈로부터 상기 보안이벤트 발생을 통지받아 사용자에게 실시간으로 디스플레이하거나, 상기 보안관련 처리 요청시에 그 요청의 입력을 위한 화면을 디스플레이하는 그래픽 사용자 인터페이스(GUI) 모듈을 포함하여 본 발명의 목적 및 기술적 과제를 달성한다.