• Title/Summary/Keyword: ID-Based System

Search Result 488, Processing Time 0.029 seconds

Blockchain-Based Access Control Audit System for Next Generation Learning Management (차세대학습관리를 위한 블록체인 기반의 접근제어 감사시스템)

  • Chun, Ji Young;Noh, Geontae
    • KIPS Transactions on Software and Data Engineering
    • /
    • v.9 no.11
    • /
    • pp.351-356
    • /
    • 2020
  • With the spread of COVID-19 infections, the need for next-generation learning management system for undact education is rapidly increasing, and the Ministry of Education is planning future education through the establishment of fourth-generation NEIS. If the fourth-generation NEIS System is well utilized, there are advantages such as providing personalized education services and activating the use of educational data, but a solution to the illegal access problem in an access control environment where strict authorization is difficult due to various user rights. In this paper, we propose a blockchain-based access control audit system for next-generation learning management. Sensitive personal information is encrypted and stored using the proposed system, and when the auditor performs an audit later, a secret key for decryption is issued to ensure auditing. In addition, in order to prevent modification and deletion of stored log information, log information was stored in the blockchain to ensure stability. In this paper, a hierarchical ID-based encryption and a private blockchain are used so that higher-level institutions such as the Ministry of Education can hierarchically manage the access rights of each institution.

Role-Based Network Access Control System on Open Network Two-Factor Authentication (네트워크 이중 인증을 통한 역할 기반 개방형 네트워크 접근 통제 시스템의 구현)

  • Lee, Chun-Jae;Cho, Ki-Ryang
    • The Journal of Korean Institute of Communications and Information Sciences
    • /
    • v.32 no.8B
    • /
    • pp.502-508
    • /
    • 2007
  • This paper proposes a method to shut out all of the not certified network access packet by embodying the two-factor(MAC ADDRESS, ID/PASSWORD) authentication system. The Authenticating Gateway System takes over central server's policy and permit or hold up the packet by inherited policy. And checks the whether or not patched the OS version and getting influenced from computer virus. And takes the information about client's resources(H/W, S/W) without Agent in the client. That makes more stability of network operating circumstance and fast facing the attack from hackers. In the fixed mobile network circumstance, This method provides more simplicity and less expenses than IEEE802.1x authentication system(cisco nac).

Development of a System Security Unit using RFID (RFID를 이용한 시스템 보안 장치 개발)

  • Jang, Jae-Hyuk;Sim, Gab-Sig
    • Journal of the Korea Society of Computer and Information
    • /
    • v.16 no.1
    • /
    • pp.11-18
    • /
    • 2011
  • This study developed a digital security device which power is on/off by the RFID card. This device is based on the wireless data transmit/receive circuits, built in RS-232C chip and applied to computer and other digital devices. We can check whether this device is operated or not by connecting the LED. In this system, 13.56MHz frequency circuit supplies power with ID card, and DC inputs check the proximity operating distance of the card field for verifying the existence of a card. The security level of this system is much stronger than that of a compared system[13]. Anyone cannot use the system without RFID card. All illegal access is prevented except for authorized path.

Embedded System Implementation of Tree Routing Structure for Ubiquitous Sensor Network (유비쿼터스 센서 네트워크를 위한 트리 라우팅 구조의 임베디드 시스템 구현)

  • Park, Hyoung-Keun;Lee, Cheul-Hee
    • Journal of the Korea Academia-Industrial cooperation Society
    • /
    • v.12 no.10
    • /
    • pp.4531-4535
    • /
    • 2011
  • In this paper, USN(Ubiquitous Sensor Network) is used in the structure of the tree routing was implemented in embedded systems. Tree Routing in the USN to the sink node to transmit sensor data is one of the techniques. When routing, sensor data is transmitted based on pre-defined ID according hop number. In order to have optimal routing path, the current state of the wireless sector and the sensor node informations were used. Also, received sensor data and the results of the tree routing by implementing an embedded system. This embedded system can be applied to a portable sensor information collecting system.

Workplace Response System Against Infectious Disasters based on the MERS Outbreak in Korea (사업장의 감염성재난 대응체계: 2015년 메르스 유행을 중심으로)

  • Jeong, Ihn Sook;Yu, Jungok;Ha, Mi Jeong
    • Korean Journal of Occupational Health Nursing
    • /
    • v.26 no.4
    • /
    • pp.207-217
    • /
    • 2017
  • Purpose: This study aimed to evaluate the workplace response system (WRS) against infectious disasters (IDs) based on the response attitudes and capacity of occupational health nurses (OHNs) who worked during the 2015 Middle East Respiratory Syndrome (MERS) outbreak in South Korea. Methods: Fifty-one participants who had worked as OHNs at the time of the 2015 MERS outbreak were surveyed from November 20 to December 10, 2016. Data were collected using a self-report questionnaire and analyzed using descriptive statistics and McNemaer's test. Results: According to the survey results, the following were lacking in the WRS: a dedicated ID-response team, manuals, related education programs for OHNs, and health education programs for workers. Results also confirmed that workers were vulnerable to new infectious diseases because of the lack of health checkups and support for workers before and after business trips abroad. Among the respondents, 98.0% answered affirmatively that an ID was important for health management in the workplace, but 64.7% answered that it was difficult to manage an ID. The perceived capacity items to respond to IDs ranged from 3.0 points to 3.3 points. This scores were generally high. Conclusion: As the WRS is currently insufficient, it is necessary to develop an adequate WRS to IDs by addressing the identified problems.

A Study on a Location Determination System using Infrastructure Information of a WLAN Network (무선랜 네트워크의 인프라 정보를 이용한 위치측위 시스템에 관한 연구)

  • Lim, Joong-Seon;Choi, Gyung-Hyun
    • The Journal of The Korea Institute of Intelligent Transport Systems
    • /
    • v.10 no.6
    • /
    • pp.98-107
    • /
    • 2011
  • In this paper, we propose the location determination system of an agent mobile device using the information provided by the WLAN(Wireless LAN) infrastructure. This system is configured as a typical ESS(Extended Service Set)-type WLAN structure with real-time location positioning engine and thru AP(Access Point) controller. The positioning engine collects the information of agent devices using SNMP(Small Network Management Protocol) thru AP controller and utilize those information as Cell ID. for LBS(Location Based Service). In the result of a real office environment implementation, the average success rate of inter-AP roaming is measured to 62.5% and the duration time of the device information update within the AP is average of 11 second of time, which means this system is adaptable to the location based service of above average accuracy but somewhat less urgency.

The method of making Rule Cases to build Rule-Based System (규칙기반시스템의 구축에 필요한 규칙 발생 기법)

  • Zheng, BaoWei;Yeo, Jeongmo
    • Proceedings of the Korea Information Processing Society Conference
    • /
    • 2010.04a
    • /
    • pp.852-855
    • /
    • 2010
  • Tree type of Rule Case will be processed by the method that provide practical Rule Case to Rule Engine that is made with procedural language beforehand, then the Rule Engine according to the condition of the special Rule Case to return result in current Rule-Based System. There are two disadvantages in the method; the first is according to specific business rule after construct the Rule Engine when the business rule changing the Rule Engine also must be changed. The second is when Rule have many conditions the Rule Engine will become very complex and the speed of processing Rule Case will become very slow. In this paper, we will propose a simplified algorithm that according to the theory of ID Tree to produce Rules which be used in Rule-Based System. The algorithm can not only produce Rules but also make sure of satisfying change of business rule by execute the algorithm. Because it is not necessary to make a Rule Engine, we will anticipate effect of increasing speed and reducing cost from Rule-Based System of applying the algorithm.

Behavioural Analysis of Password Authentication and Countermeasure to Phishing Attacks - from User Experience and HCI Perspectives (사용자의 패스워드 인증 행위 분석 및 피싱 공격시 대응방안 - 사용자 경험 및 HCI의 관점에서)

  • Ryu, Hong Ryeol;Hong, Moses;Kwon, Taekyoung
    • Journal of Internet Computing and Services
    • /
    • v.15 no.3
    • /
    • pp.79-90
    • /
    • 2014
  • User authentication based on ID and PW has been widely used. As the Internet has become a growing part of people' lives, input times of ID/PW have been increased for a variety of services. People have already learned enough to perform the authentication procedure and have entered ID/PW while ones are unconscious. This is referred to as the adaptive unconscious, a set of mental processes incoming information and producing judgements and behaviors without our conscious awareness and within a second. Most people have joined up for various websites with a small number of IDs/PWs, because they relied on their memory for managing IDs/PWs. Human memory decays with the passing of time and knowledges in human memory tend to interfere with each other. For that reason, there is the potential for people to enter an invalid ID/PW. Therefore, these characteristics above mentioned regarding of user authentication with ID/PW can lead to human vulnerabilities: people use a few PWs for various websites, manage IDs/PWs depending on their memory, and enter ID/PW unconsciously. Based on the vulnerability of human factors, a variety of information leakage attacks such as phishing and pharming attacks have been increasing exponentially. In the past, information leakage attacks exploited vulnerabilities of hardware, operating system, software and so on. However, most of current attacks tend to exploit the vulnerabilities of the human factors. These attacks based on the vulnerability of the human factor are called social-engineering attacks. Recently, malicious social-engineering technique such as phishing and pharming attacks is one of the biggest security problems. Phishing is an attack of attempting to obtain valuable information such as ID/PW and pharming is an attack intended to steal personal data by redirecting a website's traffic to a fraudulent copy of a legitimate website. Screens of fraudulent copies used for both phishing and pharming attacks are almost identical to those of legitimate websites, and even the pharming can include the deceptive URL address. Therefore, without the supports of prevention and detection techniques such as vaccines and reputation system, it is difficult for users to determine intuitively whether the site is the phishing and pharming sites or legitimate site. The previous researches in terms of phishing and pharming attacks have mainly studied on technical solutions. In this paper, we focus on human behaviour when users are confronted by phishing and pharming attacks without knowing them. We conducted an attack experiment in order to find out how many IDs/PWs are leaked from pharming and phishing attack. We firstly configured the experimental settings in the same condition of phishing and pharming attacks and build a phishing site for the experiment. We then recruited 64 voluntary participants and asked them to log in our experimental site. For each participant, we conducted a questionnaire survey with regard to the experiment. Through the attack experiment and survey, we observed whether their password are leaked out when logging in the experimental phishing site, and how many different passwords are leaked among the total number of passwords of each participant. Consequently, we found out that most participants unconsciously logged in the site and the ID/PW management dependent on human memory caused the leakage of multiple passwords. The user should actively utilize repudiation systems and the service provider with online site should support prevention techniques that the user can intuitively determined whether the site is phishing.

An Accuracy Assessment Scheme through Entropy Analysis in BLE-based Indoor Positioning Systems (BLE 기반 실내 측위 시스템에서 엔트로피 분석을 통한 정확도 평가 기법)

  • Pi, Kyung-Joon;Min, Hong;Han, Kyoungho
    • The Journal of the Institute of Internet, Broadcasting and Communication
    • /
    • v.22 no.3
    • /
    • pp.117-123
    • /
    • 2022
  • Unlike the satellite-based outdoor positioning system, the indoor positioning system utilizes various wireless technologies such as BLE, Wi-Fi, and UWB. BLE-based beacon technology can measure the user's location by periodically broadcasting predefined device ID and location information and using RSSI from the receiving device. Existing BLE-based indoor positioning system studies have many studies comparing the error between the user's actual location and the estimated location at a single point. In this paper, we propose a technique to evaluate the positioning accuracy according to the movement path or area by applying the entropy analysis model. In addition, simulation results show that calculated entropy results for different paths can be compared to assess which path is more accurate.

Development of a Prototype for the Digitalized Nuclear Power Plant's Main Control Room (원자력발전소 디지털형 주제어실 모형 개발)

  • Jung, Yeon-Sub;Cho, Sung-Jae
    • The Journal of the Institute of Internet, Broadcasting and Communication
    • /
    • v.9 no.4
    • /
    • pp.145-152
    • /
    • 2009
  • Domestic Kori-1 MCR was partially modified in 2007 and will be renovated entirely in 2013. Digital devices partially replacing original analog devices have been introduced and standard alone computer systems such as SPDS have been integrated into the plant computer. Upgrading KSNP's MCR based on the ditalization is planned for 2015. However, the site engineers and operators are reluctant to the advanced systems. Therefore, a prototype for the KSNP's advanced MCR has been developed to increase the acceptance level of the operators and field engineers and also, to evaluate user interfaces and I&C architecture. For enhancing support of the operators' work, a P&ID based display system composed of multi-layers, which are linked through a context sensitive menu each other, has been adopted. The $1^{st}$ layer displays a simplified P&ID, the $2^{nd}$ layer control related diagrams such as controllers and logic diagrams, the $3^{rd}$ layer trends, etc. The end point view of MCR for KSNP is also suggested considering reliability and operability of the digital systems. Additionally, modernization strategies over the overhaul periods, that do not have much impact on operation and configuration efforts are suggested.

  • PDF