• Title/Summary/Keyword: Identity Threat

Search Result 58, Processing Time 0.06 seconds

Resident-Driven Rural Village Plan Based on Ecological Rural Amenity: Focused on Busu Area, Boeun-gun, South Korea (생태적 농촌어메니티 기반 주민주도형 농촌마을종합계획 -보은군 회인면 부수권역 '하얀민들레 생태마을'을 중심으로-)

  • Ban, Yong-Un;Youn, Joong-Shuk;Woo, Hye-Mi;Han, Kyung-Min;Baek, Jong-In
    • Journal of Korean Society of Rural Planning
    • /
    • v.16 no.4
    • /
    • pp.157-169
    • /
    • 2010
  • This study has intended to devise a comprehensive rural planning, driven by residents based on ecological rural amenity paradigm for Busu area, Boeun-gun, South Korea. To reach the goal, this study has performed the following processes. First, we have analyzed the elements of threat, opportunity, weakness, and strength in both inside and outside village through 'SWOT analysis. Second, through strategic analysis and consultation, we have proposed developmental directions of Busu area. Third, based on an ecological rural amenity planning system composed of ecological economy system, ecological environment system, ecological history-culture system, ecological image system, and ecological society system, we have suggested research projects of each system Fourth, we selected projects through a general meeting with all stakeholders. Fifth, the selected projects were applied to Busu area by village residents and experts. Finally, the projects, which were appraised and revised by experts, residents, and governmental officers, were composed of ecological scenic agriculture center, resident's site for city dweller, energy independent village, eco-road, eco-pond, ecological park and parking lot, restoration of traditional culture, zone of ecological scenic agriculture, eco-tunnel, eco-fence, landmark, corporate identity, community center, forum and seminar, and education for residents' empowerment.

Mutual Authentication and Secure Session Termination Scheme in iATA Protocol

  • Ong, Ivy;Lee, Shirly;Lee, Hoon-Jae;Lim, Hyo-Taek
    • Journal of information and communication convergence engineering
    • /
    • v.8 no.4
    • /
    • pp.437-442
    • /
    • 2010
  • Ubiquitous mobile computing is becoming easier and more attractive in this ambient technological Internet world. However, some portable devices such as Personal Digital Assistant (PDAs) and smart phones are still encountering inherent constraints of limited storages and computing resources. To alleviate this problem, we develop a cost-effective protocol, iATA to transfer ATA commands and data over TCP/IP network between mobile appliances and stationary servers. It provides mobile users a virtual storage platform which is physically resided at remote home or office. As communications are made through insecure Internet connections, security risks of adopting this service become a concern. There are many reported cases in the history where attackers masquerade as legitimate users, illegally access to network-based applications or systems by breaking through the poor authentication gates. In this paper, we propose a mutual authentication and secure session termination scheme as the first and last defense steps to combat identity thief and fraud threat in particular for iATA services. Random validation factors, large prime numbers, current timestamps, one-way hash functions and one-time session key are deployed accordingly in the scheme. Moreover, we employ the concept of hard factorization problem (HFP) in the termination phase to against fraud termination requests. Theoretical security analysis discussed in later section indicates the scheme supports mutual authentication and is robust against several attacks such as verifiers' impersonation, replay attack, denial-of-services (DoS) attack and so on.

A Study of a Secure Smart Car System using Attribute-based Delegation Method (속성 기반 권한위임 관리 기법을 사용한 스마트 자동차 안전성 검토에 관한 연구)

  • Kim, Jin-Mook;Moon, Jeong-Kyung;Hwang, Deuk-Young
    • Convergence Security Journal
    • /
    • v.19 no.3
    • /
    • pp.71-79
    • /
    • 2019
  • The demand of smart cars is increasing rapidly. International stand organize such as 3GPP and 5GAA are proposing standard communication protocvols for connected-car, and automotive network infrastructure. But Smart car network have many security threats and more dangerous against the existed wire communication network. Typically, peripheral devices of a smart car may disguise their identity and steal location information and personal information about the vehicle. In addition, the infrastructure elements around smart cars can conspire and put driving cars in danger, threatening lives. This is a very serious security threat. Therefore, in order to solve these problems, we proposed a system that is secure from collusion and tampering attacks using attribute-based authorize delegation method and threshold encryption algorithms. We have demonstrated using a semantic safety model that the proposed system can be safe from collusion attack.

Development of a Standardized Framework for Domestic Information Security Education; Focusing on a Two-Track Curriculum Customized by Age and Job (국내 정보보호 교육 표준 프레임워크 개발; 연령 및 직무 맞춤의 이원화(Two-track) 교육과정을 중심으로)

  • Park, Minjung;Lee, GI Hyouk;Chai, Sangmi
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.31 no.5
    • /
    • pp.1083-1095
    • /
    • 2021
  • With the recent increase in users' dependence on the Internet and the spread of various IT devices, the influence of information security on the users' has expanded compared to the past. Therefore, it is expected to have an increased influence on information security in personal life. In addition, as the intrusion factors that threaten security continue to become more advanced and diversified (eg., fake news, cyberbullying, identity theft), the need for nurturing information security experts is increasing. Furthermore, not only corporate information security workers, but also all individuals, cannot be free from the threat of information security. Therefore, it is necessary to prepare various information security education to improve information security awareness and induce proactive information security behaviors. In this study, characteristics of domestic and foreign information security education courses are analyzed and provide a standardized framework for information security education applicable to the domestic environment.

Modeling Technology on Free-form Surface of a New Military Personal Head using Quick Surface Method (퀵서피스기법을 이용한 신장병 두상의 자유곡면 모델링 기술)

  • Lee, Yong-Moon;Hwang, Tae-Son;Kim, Hun;Nam, Hee-Tae;Lee, Kee-Hwan;Kang, Myungchang
    • Journal of the Korean Society of Manufacturing Process Engineers
    • /
    • v.17 no.6
    • /
    • pp.170-176
    • /
    • 2018
  • Recently, weapon system requires personal protection products due to the explosion of rapid-fire explosion, which is considered to be multi threat in modernization, complication and war against terrorism. However, the conventional Korean military bullet protection helmets are not suitable for wearing convenience and combatant interoperability in terms of ergonomic. In this paper, we propose a suitable 3D Scanning method for the head, and compare the measured 3D dimension with the existing 2D measurement value to identity the reliability. Reverse engineered soldier head using the quick surface method was realized with a perfect free-form surface and satisfactory tolerance range (${\pm}0.2mm$). Through the comparison of 3D and 2D measured head dimensions, the absolute error value was 0.73 mm on average and relative error was 0.35 %, confirming the high accuracy of the 3D scan modeling. Also, quick surface method using 3D scanner is suggested a fast and accurate skill for ergonomics in obtaining the head modeling needed for military's personal bullet protection helmet design.

A Study on Situations and Response Methods for Pirate Incidents in the Seas Southwest of the Philippines (필리핀 남서부 해적사고 현황과 대응방안 연구)

  • Na, Song-Jin
    • Journal of the Korean Society of Marine Environment & Safety
    • /
    • v.23 no.7
    • /
    • pp.829-833
    • /
    • 2017
  • Recently, pirate incidents involving passing ships have been continuously occurring in the seas southwest of the Philippines, the Sulu Sea and the Celebes Sea. Pirates in these areas are members of the "Abu Sayyaf Group", which consists of Islamic armed rebels. They have abducted and confined 59 ship crews over the last 13 months to obtain money for group operations. The activities of these pirates, abducting and killing crews, have became a significant threat for marine security in the Sulu and Celebes Seas and for logistic activities in Asia. This study examines and analyzes 22 recent incidents in terms of ships gross tonnage, kind, nationality, incident time, location, etc. The identity of the Abu Sayyaf Group, which has been committing this piracy and represents the de facto power behind the actors responsible, is also unpacked, along with current challenges to resolving these conflicts. Finally, responses passing ships, shipping companies, related countries and the international community should make are proposed.

An Implementation of the Security Service on Internet Mail System (인터넷 메일 시스템에서의 정보보호 서비스 구현)

  • 강명희;신효영;유황빈
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.7 no.2
    • /
    • pp.107-122
    • /
    • 1997
  • Most of the currently used electronic mail system has the threat of security such as illegal leak of message, forgery, uncertain identity, denial of sending and receiving, and so forth. The security for this system is not satisfied yet, thus we explore these problems. In this thesis, we implement the security services for internet mail system which cover the weakness for traditional mail system. This system provides not only security services which PEM and PGP provides (i.e message confidentiality, message integrity, originator authentication, non-repudiation of origin), but also message replay prevention. and non-denial of recipient using certification of contents. In addition, this system increases security of the digital signature by signing with signature block formatting on the creation of it. And it increases security of the digital enveloping by encrypting with encryption block formatting of message encryption key.

Design of DID-based Verification Protocol for Strengthening Copyright Holders' Sovereignty (저작권자의 주권 강화를 위한 DID 기반 검증 프로토콜 설계)

  • Kim, Ho-Yoon;Shin, Seung-Soo
    • Journal of Industrial Convergence
    • /
    • v.20 no.9
    • /
    • pp.47-58
    • /
    • 2022
  • Digital content is difficult to distinguish between the original and the replica due to its nature. For this reason, NFT technology using blockchain technology is attracting attention because it can guarantee the proof and scarcity of the original digital content. However, the NFT buyer does not own the copyright to the digital content, but the ownership. In particular, since the minting process of issuing NFTs is possible for anyone, there is a copyright threat to the copyright holder. In this study, we propose a verification protocol based on DID for the process of issuing and transacting NFTs for copyright protection of copyright holders' digital contents. As a research method, the problems of research cases related to digital contents were analyzed and the safety was comparatively analyzed. NFT issuance can only be issued by copyright holders whose identity has been verified through DID, and only users who have completed authentication can participate in the transaction to prevent indiscriminate theft and use of digital content and form a safe and transparent transaction market.

Cloud security authentication platform design to prevent user authority theft and abnormal operation during remote control of smart home Internet of Things (IoT) devices (스마트 홈 사물인터넷 기기(IoT)의 원격제어 시 사용자 권한 탈취 및 이상조작 방지를 위한 클라우드 보안인증 플랫폼 설계)

  • Yoo Young Hwan
    • Convergence Security Journal
    • /
    • v.22 no.4
    • /
    • pp.99-107
    • /
    • 2022
  • The use of smart home appliances and Internet of Things (IoT) devices is growing, enabling new interactions and automation in the home. This technology relies heavily on mobile services which leaves it vulnerable to the increasing threat of hacking, identity theft, information leakage, serious infringement of personal privacy, abnormal access, and erroneous operation. Confirming or proving such security breaches have occurred is also currently insufficient. Furthermore, due to the restricted nature of IoT devices, such as their specifications and operating environments, it is difficult to provide the same level of internet security as personal computers. Therefore, to increase the security on smart home IoT devices, attention is needed on (1) preventing hacking and user authority theft; (2) disabling abnormal manipulation; and (3) strengthening audit records for device operation. In response to this, we present a plan to build a cloud security authentication platform which features security authentication management functionality between mobile terminals and IoT devices.

A Scheme Reconfiguration of Whitelisting and Hyperledger Fabric for Cryptocurrency Integrity Transactions (암호화폐 무결성 거래를 위한 Whitelisting과 Hyperledger Fabric 재구성 기법)

  • Su-An Jang;Keun-Ho Lee
    • Journal of Internet of Things and Convergence
    • /
    • v.10 no.1
    • /
    • pp.7-12
    • /
    • 2024
  • To trade cryptocurrency, traders require a personal cryptocurrency wallet. Cryptocurrency itself using blockchain technology is guaranteed excellent security and reliability, so the threat of blockchain hacking is almost impossible, but the exchange environment used by traders for transactions is most subject to hacking threats. Even if transactions are made safely through blockchain during the transaction process, if the trader's wallet information itself is hacked, security cannot be secured in these processes. Exchange hacking is mainly done by stealing a trader's wallet information, giving the hacker access to the victim's wallet assets. In this paper, to prevent this, we would like to reconstruct the existing Hyperledger Fabric structure and propose a system that verifies the identity integrity of traders during the transaction process using whitelisting. The advantage is that through this process, damage to cryptocurrency assets caused by hackers can be prevented and recognized. In addition, we aim to point out and correct problems in the transaction process that may occur if the victim's wallet information is stolen from the existing Hyperledger Fabric.