Remote user authentication scheme is a kind of way to authenticate the communication parties who transmit messages through an insecure channel. Researchers in this area have proposed some approaches during the last couple of decades. Unfortunately, most of them are proved to be insecure against various attacks. In 2009, Kim and Chung improved Yoon and Yoo's scheme, and claimed that their scheme can prevent masquerading attack as well as resist to other malicious attacks. However, we found that Kim and Chung's scheme is still not secure enough, especially in preventing off-line password guessing attack. In this study, we proposed a more secure and practical remote user authentication scheme to resolve all of the aforementioned security vulnerabilities while preserving the merits of Kim-Chung's scheme.
In 2009, Tseng et al. proposed a key agreement protocol based on chaotic maps. Tseng et al. claimed that their protocol preserve user anonymity. However, Tseng et al.’s protocol is insecure against the insider attack. Nui et al. proposed a new anonymous key agreement protocol in 2011. Unfortunately, Nui et al.’s protocol cannot provide user anonymity and has computational efficiency problem. We introduce a new key agreement protocol based on Chebyshev chaotic map. Our protocol overcomes these security problems and provides user anonymity.
The current DRM system has been focusing on restricting the content usage and limiting user rights for the content. Thus, the concept of AD (Authorized Domain) was proposed to remove such inconvenience and limitations. However, the previous works on AD have two problems. The first is that it requires a rather expensive revocation mechanism. The second is that the content obtained in AD can still be played, even if it is outside AD. To solve these problems, we propose a secure and efficient content management scheme without revocation list.
In 2011, Li and Lee proposed a novel user authentication scheme with anonymity for wireless communications. In particular, Li and Lee defined two more session keys and adopted Diffie-Hellman key agreement method for their scheme to establish two more session keys. However, since modular exponential computation demands plenty of resources, their scheme is very inefficient. Thus, in this paper, we address the drawbacks of Li and Lee's scheme and propose an efficient user authentication scheme for wireless communications with same functionality and security.
User authentication is highly necessary technology in a variety of services. Many researchers have proposed a two-factor authentication scheme using certificate and OTP, smartcard and password, and so on. Two-factor authentication requires an additional factor rather than one-factor authentication. Therefore, loss or exposure can occur, since users always must carry and manage the additional device or factor. For this reason, biometric authentication, used in many services, needs a verification method of the user without an additional factor. Fingerprinting is widely used in service due to excellent recognition, low cost device, and less user-hostile. However, fingerprint recognition always uses the same fingerprint template, due to the inalterability. This causes a problem of reusable fingerprint by a malicious attacker. Therefore, we proposed a secure two-factor user authentication system using fingerprint information and password to solve the existing two-factor problem. The proposed scheme is secure against reuse of a fingerprint. It does not need an extra device, so efficiency and accessibility are improved.
In 1981, Lamport proposed a password authentication scheme to provide authentication between single user and single remote server. In a smart card based password authentication scheme, the smart card takes password as input, makes a login message and sends it to the server. Many smart card based password authentication schemes with a single server have already been constructed. However it is impossible to apply the authentication methods in single server environment to multi-server environment. Therefore, some smart card based password authentication schemes for the multi-server environment are proposed. In 2010, Yoon et al. proposed a robust biometrics-based multi-server authentication with key agreement scheme for smart cards on elliptic curve cryptosystem. In this paper, however, we show that scheme of Yoon et al. is vulnerable to off-line password guessing attack and propose an improved scheme to prevent the attack.
2011년, C.-T. Li et al.은 Kim et al. 스킴의 문제점인 오프라인 패스워드 추측 공격과 신분 위장 공격을 해결한 향상된 안전한 사용자 인증 스킴을 제안하였다. C.-T. Li et al.은 그들이 제안하는 방식이 패스워드 추측 공격과 신분 위장 공격 등의 스마트카드 보안 관련 공격들을 막을 수 있다고 주장하였다. 또한 상호 인증과 세션 키 생성을 제공한다는 장점을 가지고 있었다. 하지만, 본 논문에서 분석한 결과, C.-T. Li et al.의 스킴은 패스워드 변경 단계에서의 패스워드 추측 공격이나 스마트카드 위조 공격, 훔친 검증자 공격(stolen verifier attack)에 취약함이 발견되었다. 본 논문에서는 C.-T. Li et al.의 스킴이 패스워드 추측 공격에 대해 안전하지 않으며, 실용적이지 않다는 것을 지적하고자 한다. In 2011, C.-T. Li et al. proposed a secure user authentication scheme, which is an improvement over Kim et al.'s scheme to resolve several security flaws such as off-line password guessing attack and masquerading attack. C.-T. Li et al. claimed that their scheme prevents smart card security related attacks. Moreover, it provides mutual authentication and session key establishment. However, we found that their scheme is vulnerable to password guessing attack through password change phase, smart card forgery attack and stolen verifier attack. Moreover, C.-T. Li et al.'s scheme is not secure against password guessing attack as they claimed. In this paper, we also point out that their scheme is not practical to use.
Protocols for group key establishment enable a group of parties to build a secure multicast channel over insecure public networks. In this paper, we present a group key transfer protocol designed for use in the model where a trusted key generation center shares a long-term secret with each of its registered users. Our protocol is an improved version of the group key transfer protocol proposed recently by Harn and Lin. Improvement is made in three different aspects: security, efficiency and correctness. Our main contribution is in showing that Harn and Lin's protocol does not achieve implicit key authentication but can be fixed without causing any efficiency degradation.
Recently, there has been increased interest in home healthcare service due to prosperity of information technology and distribution of developed medical devices. Home healthcare service is a service that enables patients to receive medical service at home, without visiting a hospital. However, since the insecurely processed information can directly affect patients' health and lives, security must be taken into consideration. In this paper, we discuss the vulnerabilities and threats to consolidate security and reliability of home healthcare service, and propose a protection profile for home healthcare medical devices based on Common Criteria.
IT products developed without due consideration of security issues have caused many security accidents over the last ten years. As a result, the importance of security in software development is increasing. It is important to ensure that no known vulnerabilities remain in the design, development, and test stage, in order to develop secure IT products. Even when an IT product is designed securely, various security vulnerabilities can occur, such as buffer overflow, if the general coding technique is used at the development stage. Therefore, the introduction of secure coding rules becomes most critical in developing a robust information security product. This paper proposes a method of applying a secure coding standard in the CC evaluation process. The proposed method is expected to contribute to improving the security of IT products in the CC evaluation process.
A group key exchange (GKE) protocol is designed to allow a group of parties communicating over a public network to establish a common secret key called a session key. As group-oriented applications gain popularity over the Internet, a number of GKE protocols have been suggested to provide those applications with a secure multicast channel. Among the many protocols is the GKE protocol presented by Dutta and Dowling for mobile ad hoc networks. In this paper, we are concerned with the security of the Dutta-Dowling protocol. Their protocol carries a proof of security in the standard adversarial model which captures unknown key-share attacks. But unlike the claim of provable security, the Dutta-Dowling protocol fails to achieve unknown key-share resilience. We here reveal this security vulnerability of the protocol and show how to address it.
MFP (Multi-Function Peripheral) is an embedded system that serves several functions including printing, copying, scanning, faxing, document storing, and etc. Recently, MFP is becoming a popular option for office workers due to its multi-functionality and economic efficiency. Furthermore, MFP is able to perform several functions such as USB printing, private job printing, stored job printing, and scan-to-server. Due to the rapid growth of MFP market, MFP is widely used in many workspaces. Therefore, if we can extract meaningful information from MFP's storage devices, it may be valuable evidences in digital forensic investigation. However, systematic forensic investigation about MFP has never been studied so far. In this paper, we describe a process for digital forensic examination of MFP and analyze the acquired data and effectively trace the use of MFP in the crime scene.
Recently, the number of incidents by malicious codes designed to suspend services and abuse personal information has grown rapidly, and the installation of applications on smart phones has emerged as one of the most common ways by which such malicious codes are spread. Anti-virus programs can be used to curb the spread of such codes, but these have limitations in terms of speed and efficiency. Accordingly, we need to strengthen the safety of application distribution and verification procedures in order to prevent the spread of malicious codes. To this end, this paper examines the problems of existing application distribution procedures, and suggests an enhanced code-signing scheme using the public key infrastructure (PKI) certificate for an application distribution method. It offers improved reliability and security by using code signing technology to secure the integrity of software and developer authentication functions.
We propose a secure framework for mobile-phone based RFID service using personal privacy policy based access control for personalized ultra-high frequency (UHF) tags employing the Electronic Product Code (EPC). The framework, called mobile RPS, has dynamic capabilities that extend upon extent trust-building service mechanisms for RFID systems. This new technology aims to provide absolute confidentiality with only basic tags.
Multifunction peripherals, capable of networking and equipped with several hardcopy functions with various security functions, are taking place of printers and other printing devices in office workplaces. However, the security functions within a multifunction peripheral and its IT environments may have vulnerabilities. The information transmitted in multifunction peripherals includes very sensitive data since the device is networked to transmit data including confidential information. There have been international efforts to mitigate this anxiety of consumers through common criteria. In 2009, a series of standards for multifunction peripherals were developed. These protection profiles are classified in accordance to four different operational environments. However, though multifunction peripherals treat confidential information, network separation issue is not regarded in classifying the operational environments. Thus, in this paper, we present an operational environment and propose a protection profile that is appropriate for the new environment.
Recently, major portal sites are suffering from a number of attacks and it is growing exponentially. July 2009, there has been system failure on government sites and some of the major portal sites due to the DDoS (Distributed Denial of Service) attack. Moreover, portal sites are exploited by a cross-site scripting vulnerability in 2010. To solve these problems, each portal site made an effort to eliminate the security vulnerability of the website and to protect personal information such as ID and password. However, portal sites still have the security vulnerabilities against ARP (Address Resolution Protocol) poisoning attack and the certificate spoofing attack. In this paper, we show the results of our penetration test and present the countermeasures on the ARP (Address Resolution Protocol) poisoning attack and the certificate spoofing attack.
Radio Frequency Identification (RFID) is taking place of barcodes in our lives, thanks to its remote identification capability. However, being transmitted via radio waves, the information is exposed to many possible attacks, which may endanger the security and privacy of relevant individuals and organizations. Fortunately, there have been efforts to construct an efficient and secure protocol in conformance with EPC Class 1 Generation 2 Standard (Gen 2), the most popular standard for RFID passive tags. Yeh et al. proposed a mutual authentication protocol conforming Gen 2. However, the proposed protocol is found to be vulnerable to an attack. Thus, in this paper, we show the vulnerability of Yeh et al.’s protocol and propose countermeasures to secure the protocol.
Recently, there has been an increased interest in wireless security equipment because of the proliferation of distributed wireless networks and wireless equipment. The security functions of wireless security equipment being used by organizations and companies provide remote users with access to a system after performing user identification and authentication, and allow encrypted data to be exchanged. However, since a consistent methodology for evaluating the vulnerability of wireless equipment has not yet been developed, it is difficult for evaluators and developers to properly evaluate the security of wireless equipment. To solve these problems, we propose an environment for vulnerability testing and outline trends in the development of wireless security equipment and security functions.