
http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
보안이 적용된 VoIP 시스템의 합법적 감청을 위한 미디어 키 분배 기법
노효선,정수환,Roh Hyo-Sun,Jung Sou-Hwan 한국통신학회 2006 한국통신학회논문지 Vol.31 No.8B
본 논문에서는 보안이 적용된 VoIP 시스템에서 합법적 감청 지원을 위한 미디어 키 분배 기법을 제안하였다. 현재 제정되고 있는 미국과 유럽의 감청 표준은 양단간에 보안이 적용된 VoIP 시스템의 경우, 보안이 적용된 키정보를 수집하는 메커니즘이 정의되어 있지 않아 감청에 어려움이 예상된다. 제안된 기법은 미디어 트래픽의 암호화를 위해 사용한 미디어 키를 ISP AAA 서버, TSP 등록 서버와 UA 간의 대칭키로 이중 암호화하여 각 서버에 보관하였다가 합법적 감청 기관으로부터 승인된 감청 요청이 있을 경우 각 서버에서 미디어 키를 합법적 감청 기관으로 전달하여 암호화된 미디어 트래픽을 감청 할 수 있는 방법을 제안하였다. 이 방법은 이중으로 암호화된 미디어 키를 어느 한쪽 서버에서 임의로 확인할 수 없으며, 합법적 감청 승인을 받은 감청 기관에 의해서만 미디어 키를 확인할 수 있기 때문에 무분별한 감청 시도를 방지할 수 있어 개인의 사생활을 보호할 수 있다. This paper proposes a media key distribution scheme for lawful interception in secured VoIP systems. A problem of the current US or EU standards for lawful interception is that they do not provide a mechanism for collecting keys used for encrypting media streams between two end points. In the proposed scheme, dual encryption was applied on the media keys using two shared secrets: one between the ISP AAA server and user agent, and the other between the TSP registrar and user agent. Only the lawful agency with court warrant can collect both keys from the service providers. This scheme can still provide a privacy by preventing the misusage of the keys by the service providers.
홍기훈(Ki-Hun Hong),정수환(Sou-Hwan Jung),유현경(Hyun-Kyung Yoo),김도영(Do-Young Kim) 한국통신학회 2003 한국통신학회논문지 Vol.28 No.10B
본 논문에서는 VoIP의 보안을 위하여 적용된 암호화와 보안 적용 방식이 실시간 통신에 미치는 영향을 알아보기 위해 암호화에 주로 사용되는 DES, 3DES, SEED, AES 등의 암호 알고리즘을 VoIP에 적용한 후 지터나 RTT, 패킷 손실률 등의 여러 가지 QoS 요소를 측정하여 보았다. 또한 각 알고리즘별 암ㆍ복호화 전과 후의 패킷 처리 시간 간격을 측정하여 암호화로 인한 시간 간격의 변화를 알아보았고, 음성으로 재생되기 직전의 처리 시간 간격을 측정하여 각 패킷이 어느 정도 주기적으로 공급되는지 여부와 실제 음질을 비교하여 보았다. 또한 대표적인 실시간 멀티미디어 보안 프로토콜인 H.235와 SRTP에서의 RTP 보안 적용 방식을 비교하여 키 교환 및 보안성과 공격 방어 측면 그리고 RTP 보안 적용의 효율성 등을 분석하였다.
Open IPTV 환경에서 재암호화 과정 없는 댁내 컨텐츠 분배를 위한 키관리 기법
정서현(Seo-Hyun Jung),노효선(Hyo-Sun Roh),이현우(Hyun-Woo Lee),이정현(Jeong-Hyun Yi),정수환(Sou-Hwan Jung) 한국컴퓨터정보학회 2010 한국컴퓨터정보학회논문지 Vol.15 No.7
Due to the advancement of IPTV technologies, open IPTV services are a step closer to becoming reality. In such service environment, users are able to enjoy IPTV services using a variety of devices available at their home domain. However, it is impossible to get such flexible services at their convenience unless each of devices is individually connected to Set-Top-Box (STB) because of Conditional Access System (CAS) or service providers otherwise allow STB to freely distribute decoded contents to every user devices attached to STB. In this paper, we propose a key management scheme for securely distributing contents from STB to multiple user devices at home domain. The proposed scheme also makes the service providers be able to control the access rights to each of user devices without installing individual STBs. It is achieved by computationally dividing a private key of RSA signature scheme into three parts and thus makes possible to distribute the contents scrambled through a underlying CAS mechanism without re-encrypting them that the existing scheme should employ. It improves significantly computation and communication complexities, maintaining it as secure as the existing schemes. Additionally, it prevents misbehaving users from illegally distributing the contents from STB to their devices available at home domain.
RSA 공개키 분할 전송을 이용한 SRTP 키 교환 기법
채강석(Kang-Suk Chae),정수환(Sou-Hwan Jung) 한국컴퓨터정보학회 2009 한국컴퓨터정보학회논문지 Vol.14 No.12
This paper proposes a SRTP key exchange scheme using split transfer of divided RSA public key in SIP-based VoIP environment without PKI. The existing schemes are hard to apply to real VoIP environment, because they require a PKI and certificates in the end devices. But in case of ZRTP. which is one of existing schemes, it's able to exchange SRTP Key securely without PKI, but it is inconvenient since it needs user's involvement. To solve these problems, the proposed scheme will split RSA public key and transmit them to SIP signaling secession and media secession respectively. It can defend effectively possible Man-in-The-Middle attacks, and it is also able to exchange the SRTP key without the user's involvement. Besides, it meets the requirements for security of SRTP key exchange. Therefore, it's easy to apply to real VoIP environment that is not available to construct PKL.
SIP 기반의 VoIP 서비스 환경에서 스팸 방지를 위한 인증 기법
장유정,문형권,최재덕,원유재,조영덕,정수환,Jang, Yu-Jung,Moon, Hyung-Kwon,Choi, Jae-Duck,Won, Yoo-Jae,Cho, Young-Duk,Jung, Sou-Hwan 한국통신학회 2007 韓國通信學會論文誌 Vol.32 No.8b
This paper proposes a message authentication scheme to resist potential spam threats in SIP-based VoIP services. Our scheme applies the extended HTTP digest authentication mechanism between the inbound proxy and the UAS to verify that a service request is coming through the valid inbound proxy. The proposed scheme is simple and requires minimal modification the current SIP standards, and effective to filter invalid peer-to-peer spam calls. In this paper, an experimental spam attack using modified open source was tested on a commercial VoIP networks to exploit the possibility of spam attacks in real environment. 본 논문에서는 SIP 기반의 VoIP상에서 스팸 위협에 대해 분석하고 이를 차단하기 위해 UAS에서 inbound proxy 서버를 인증할 수 있는 발신자 인증 기법을 제안하였다. 제안된 기법은 UAS로 들어오는 메시지가 inbound proxy를 통해 전송됐는지 여부를 검증하기 위해 inbound proxy 서버와 UAS 간 사전에 공유하고 있는 패스워드를 기반으로 HTTP Digest 인증을 적용하였다. 이는 SIP 표준의 큰 수정 없이 쉽게 적용이 가능하고 peer-to-peer로 발생되는 스팸을 효과적으로 차단할 수 있다. 본 논문에서는 상용 망에서 peer-to-peer로 스팸을 발송해보고 제안된 기법을 이용해 스팸이 차단되는 것을 검증하기 위해 오픈 소스를 이용해 구현해 보았다.
커뮤니티 기반 유비쿼터스 네트워크 환경에서 사용자 테이블을 이용한 효율적인 그룹키 관리 기법
홍철화 ( Chul-wha Hong ),김성일,정수환 ( Sou-hwan Jung ) 한국정보처리학회 2011 한국정보처리학회 학술대회논문집 Vol.18 No.1
커뮤니티 기반 유비쿼터스 네트워크 환경에서 커뮤니티 사용자는 응용 서비스 및 네트워크 서비스를 제공받기 위해 자유롭게 커뮤니티에 참여하고 탈퇴할 수 있다. 이런 서비스가 안전하게 제공되기 위해서는 그룹키가 필요하다. 커뮤니티 사용자의 참여 및 탈퇴는 그룹키의 순방향, 역방향 안정성에 영향을 주고 갱신된 그룹키는 효율적인 분배가 이루어져야 한다. 기존 그룹키 관리 기법은 사용자 수에 따라 그룹키를 교환하는데 사용되는 메시지 수가 증가하는 확장서 문제를 가지고 있다. 본 논문에서는 사용자 테이블을 이용하여 커뮤니티 내에 사용자 수에 영향을 받지 않는 그룹키 관리 기법을 제안한다.