Lately, there has been a notable surge in the defense industry's efforts to develop highly advanced intelligent systems. These systems encompass sophisticated computing platforms that boast an impressive level of autonomy. However, it's important to acknowledge that these very systems are not impervious to vulnerabilities stemming from both hardware and software tampering. Within the context of this discourse, our focus of the survey is directed towards the hardware security module. This component stands out for its capability to offer a significantly heightened level of protection when compared to conventional software-based techniques. Through the lens of this paper, we embark on a comprehensive survey of Trusted Platform Module (TPM), a hardware security module, shedding light on its potential to fortify the defense against threats that emerge from various vectors of attack.
This paper presents the design and the verification of an efficient image protection method based on the QR code, which is a type of two-dimensional barcode widely used in various fields. For this purpose, we design a new image protection system consisting of a secure image generator and a secure image recognizer. One adds a new pre-processing block to the typical QR code generator and the other combines the existing QR code reader with a new post-processing block. The new architecture provides image de-identification. It is also flexible, allowing the use of text-based compression and encryption. We have implemented prototype applications for verifying the functions of the secure image generator and those of the secure image recognizer. As a result, it is shown that the proposed architecture can be used as a good solution for image privacy protection, especially in offline environments.
The necessity of protecting personal information contained in off-line documents (e.g., identification cards, driver's licenses, passports, and delivery invoices) is increasing as the subject of privacy is expanding to various objects in the physical world from the existing security perspective, which was limited only to on-line services. In this paper, we propose off-line document protection technology that can safely protect ID cards and important confidential documents released with personal information exposed on the website, and prevent cases where personal information (name, address, phone number, etc.) on delivery and mail is leaked and abused in the crime. The proposed method consists of masking and unmasking process using two-dimensional bar codes and a user's secret keys. Through the experimental results using the proposed method, we confirmed that personal information in off-line documents can be changed as an unreadable form and that only authorized user can restore the unrecognizable area to prevent the leakage of personal information.
Recently smart services, which are a global issue, aims to provide convenience, instructiveness, and safety to users by sharing data through communication between various devices connected to the internet and analyzing and processing collected data to provide useful information to users. However, in order to securely provide a variety of services to users by interconnecting a large number of devices, important key management function as well as mutual authentication between devices must be applied to the smart service environments. In this paper, we propose a secret key updating method based on devices using dynamic session key. This method can be applied to secure services on smart city such as authentication and key update between repeaters and street lights or between CCTV cameras and various sensors and also applicable to secure services on smart home such as authentication and key update between gas detector and gas breaker.
Smart IoT and wearable devices have been presenting through many companies lately. Most devices are interacted with a variety of sensors and they have feature to connect the Internet. For this reason, those devices provide a wide range of IoT services, such as smart home, smart car and smart city, to users. However, if you do not consider the proper security features needed for safe service operation, the extent of damage will be expanded widely with increased security threats. Therefore, we propose a lightweight mutual authentication and dynamic session key scheme for IoT devices in this paper.
In this paper, we present the implementation of a secure OTP(One Time Password) generator for IoT(Internet of Things) devices. Basically, MTM(Mobile Trusted Module) is used and expanded considering secure IoT services. We combine the MTM architecture with a new hardware-based OTP generation engine. The new architecture is more secure, offering not only the security of devices but also that of the OTP service. We have implemented and verified the MTM-based OTP generator on a real mobile platform embedded with the MTM chip. The proposed method can be used as a solution for enhancing security of IoT devices and services.
Recently, smart home appliances and wearable devices have been developed through many companies. Most devices can be interacted with various sensors, have communication function to connect the internet by themselves. Those devices will provide a wide range of services to users through a mutual exchange of information. However, due to the nature of the IoT environment, the appropriate security functions for secure and trustworthy smart home service should be applied extensively because the security threats will be increased and impact of security threats is likely to be expanded. Therefore, in this paper, we describe specifically the security requirements of the components that make up the smart home system.
In mobile environments, application authentication is necessarily requested for providing secure service and managing transparently the source of application. In this paper, we propose an application authentication and key management for application using a Mobile Trusted Module (MTM). After application is normally authenticated using the expected value stored in MTM, we generate a Storage Root Key (SRK) to independently operate key management system for each application. SRK for each application is created as similar as take ownership process of a Trusted Platform Module (TPM) by using two hash values. Proposed scheme will solve the performance problem of a conventional MTM key management scheme and provide more secure environment as a consequence of key isolation between applications.
This paper presents the design and requirements of effective video encryption for intelligent surveillance systems. For this purpose, we design a new video encryption system and derive requirements for it in order to protect privacy and harm in surveillance videos.
Our implementation is aimed at estimating the possibility of employing TCG-based trusted computing mechanisms, such as verifying the code-integrity of executables and libraries at load-time and remote attestation, in mobile devices. Considering the restrained resource in mobile device, the experimentation shows promising results, thereby enabling these mechanisms to be used as a basic building block for a more secured mobile service. To this end; we add a new feature of integrity measurement and verification to Wombat Linux kernel and Iguana embedded OS. We also implement attestation agents, Privacy CA, and TCG Software Stack.
TCG (Trusted Computing Group) has defined a set of standards. The main features of the standards are protection against theft of secrets held on the platform and a mechanism for the platform to prove that it is in a trusted state, called attestation. However, the attestation mechanism is vulnerable to relay attack because of the lack of linkage between the endpoint identity and attestation message. We show here how to defeat the attack by employing a new agent, called Network Interface Monitoring Agent (NIMA). In addition, we show that the NIMA-based approach can render DRM more robust and efficient, especially in case of protecting a company's sensitive data.
3G 이동통신, 무선랜은 각기 다른 장단점을 가지고 무선 통신 서비스를 제공하고 있다. 현재 이들 서비스의 단점들을 보완하도록 설계한 WiBro 서비스가 개발되었으며. 3중-모드로 작동하는 단말기를 이용하는 사용자가 세 개 망을 편리하게 사용할 수 있도록 하기 위한 3G-WLAN-WiBro 연동 시스템이 제안되었다. 각 망은 보안과 과금을 위하여 사용자와 네트워크간의 상호 인증 절차를 도입하고 있으나, 서로 다른 인증 프로토콜을 사용하고 있다. 본 논문에서는 3G-WLAN-WiBro 연동 네트워크상에서, 사용자가 동일 사업자의 이종 망으로 이동할 때 이전망에서 사용하던 인증 정보를 활용하면서 새로운 망으로 안전하게 로밍할 수 있도록 지원하기 위한 통합된 인증 및 키 관리 프로토콜을 제안하였다. 3G telecommunication and wireless LAN provide various wireless communication services with their own native advantages and disadvantages. Currently WiBro service was developed to make up for the disadvantages of those services, and 3G-WLAN-WiBro underworking system which enables a user who uses triple-mode terminals to use those three networks was proposed. Even though each network adopts mutual authentication process between users and networks to provide security and accounting, they use different authentication protocols. In this paper, integrated authentication and key management protocol is proposed which makes use of previously used authentication information and supports safe roaming when a user moves from one network to another one under a same service provider on the 3G-WLAN-WiBro interworking network.
3GPP makes efforts to enable usage of 3GPP system functionalities such as SIP calls between mobile terminals and 3GPP systems via the WLAN and to utilize 3GPP system functionalities to complement the functionalities such as charging means, authentication, authorization, and accounting functions available in the WLAN. And an interworking framework to integrate the services of 3G, WLAN and WiBro networks is proposed by Electronics and Communications Research Institute. Since each network adopts deferent protocols for mutual authentication and key agreement between users and networks, unified authentication for the integrated system is not simple problem when a user moves from one network to another. In this paper, a secure and efficient key management protocol for roaming among different networks is proposed.
This paper describes integrated testing and debugging environment for Java Card. An integrated testing and debugging environment is based on J-JCRE (Java Card Runtime Environment) and Java Card APIs (Application Programming Interface). And also, developed tool supports two kinds of cryptographic algorithms, automatic generation of client/server applet stub/skeleton, script execution, and source level debugging of system class etc. Therefore, by using development environment, application can be debugged and tested before being downloaded onto the Java Card. Key-Words: Java Card, Simulator, Testing, Debugging, Development tool