RISS 학술연구정보서비스

검색
다국어 입력

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

변환된 중국어를 복사하여 사용하시면 됩니다.

예시)
  • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
  • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
닫기
    인기검색어 순위 펼치기

    RISS 인기검색어

      次世代 移動 네트워크 環境에서 信念論理를 利用한 信賴모델 基盤 認證 프로토콜 分析에 관한 硏究 = (A) study on authentication protocol analysis based on trust model using belief logic in next generation mobile network environments

      한글로보기

      https://www.riss.kr/link?id=T11730501

      • 0

        상세조회
      • 0

        다운로드
      서지정보 열기
      • 내보내기
      • 내책장담기
      • 공유하기
      • 오류접수

      부가정보

      다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

      This paper proposes an authentication service and an authentication protocol analysis using belief logic in mobile networks. An authentication protocol can be formalized as a kind of trust theory, which can be used to reason about the trust of agents. Reasoning about trust actually involves reasoning about beliefs, therefore a theory of trust may need to be based on a kind of belief logic.
      rom the point of view of mobility signaling owner, the mobility support protocols are divided into two categories: host-based and network-based mobility management protocols. Mobile IPv6 (MIPv6) and its extensions such as Fast MIPv6 and Hierarchical MIPv6 are classified into the host-based mobility management protocol and Proxy MIPv6 (PMIPv6) is the network-based mobility management protocol that has been recently developed by the IETF.
      In PMIPv6, it is possible to support mobility for IPv6 nodes without host involvement. The mobile access gateway (MAG) sends the proxy binding update (PBU) message on behalf of the MN when the MN moves to its coverage or boots up within its coverage. The local mobility anchor (LMA) acts as the home agent (HA) of the MN in the PMIPv6 domain and is responsible for maintaining the MN’s reachability by receiving the proxy binding update (PBU) from the MAG. Thus, MN does not need the MIPv6 stack in the PMIPv6 domain.
      Designing a correct protocol specification that satisfies certain security properties is an important task. BAN logic is a well-known authentication logic that remains popular with many protocol designers. Analyzing a cipher protocol through BAN Logic, we must perform the reconfiguration process to protocol idealization and induce an assumption of initial status of protocol in BAN Logic notation.
      To date, there has been no research analyzing the authentication method of EAP-TLS using BAN Logic in the PMIPv6 environment. Specifically, a designer who requires a high strength authentication system, such as online banking or e-marketing, needs a mutual authentication mechanism in a distributed environment. To this end, our research provides a basis for analyzing the certificate through the EAP-TLS authentication mechanism in PMIPv6.
      In ad-hoc environments, all nodes have function to set themselves a route and build a network. It is important how trustable each node is in the environment. This study proposes the cluster-based trust model, and uses the model to discuss how you can solve some possible problems occurred in the network. The reputation from a neighboring node is applied to the calculation of the trust value. If the trust value of a truster is used as a weight, more sophisticated calculation of the trust value is available. When you create a cluster, all nodes in the cluster can fully trust the selected head, if entire nodes in the cluster participate in the head competition. And then, the head node issues the certificate that shows the trust level of each member node. If a node moves from one cluster to another, the trust level of the node is determined by the certificate issued by the previous cluster-head. The model proposed by this study can monitor the selfish behavior of nodes in the network and isolate the selfish nodes from the network to enhance the effectiveness throughout the network.
      Trust plays an important role when any decision is made based on unstable, uncertain information. This functionality has recently been introduced in e-commerce and virtual communities, where trust represents the subjective degree of belief. In a conventional network environment, trust is set and recognized through the access control procedure. The nodes, to which fixed roles are allocated, can be replaced by various decisions in an open network environment. In this setting, reputation is an important element affecting decisions. Reputation represents a positive prediction level for an object's future behaviors, and greatly affects the decision to trust. There are two ways to obtain information regarding reputation: the subject's own experience with an agent and a recommendation from objects around a subject.
      Trust affects certain decisions, i.e., access control and the selection of a public key in the Public Key Infrastructure (PKI). Trust is available to supplement the PKI when an object decides whether to receive a public key, based on the other object's trust level. The cluster-head, which has the highest trust value, and which is elected as a head in the group, should not be a trusted third party (TTP), but should operate the same as the other nodes in the same group. Basically, the cluster-head has a role to keep the cluster’s information and to broadcast information to members. Also, all nodes may issue a certificate binding the agent’s key and identity.
      It is impossible to obtain an appropriate trust value if there is a lack of interaction among the nodes, as in the existing trust models. However, the proposed cluster-based trust model can quickly determine the trust values, even in situations where no experience data is available with the help of neighboring nodes or “introducers”.
      In this study proposes a cluster-based network model, and trust model, using fuzzy control, that can evaluate the trust value in order to provide an authentication service in ad-hoc environments where there is no centrally controlled server. This model is then used to discuss methods of effectively and correctly calculating the trust value of a node newly entering the cluster, methods to identify the selfish nodes in the cluster, and methods to protect against other possible attacks.
      번역하기

      This paper proposes an authentication service and an authentication protocol analysis using belief logic in mobile networks. An authentication protocol can be formalized as a kind of trust theory, which can be used to reason about the trust of agents....

      This paper proposes an authentication service and an authentication protocol analysis using belief logic in mobile networks. An authentication protocol can be formalized as a kind of trust theory, which can be used to reason about the trust of agents. Reasoning about trust actually involves reasoning about beliefs, therefore a theory of trust may need to be based on a kind of belief logic.
      rom the point of view of mobility signaling owner, the mobility support protocols are divided into two categories: host-based and network-based mobility management protocols. Mobile IPv6 (MIPv6) and its extensions such as Fast MIPv6 and Hierarchical MIPv6 are classified into the host-based mobility management protocol and Proxy MIPv6 (PMIPv6) is the network-based mobility management protocol that has been recently developed by the IETF.
      In PMIPv6, it is possible to support mobility for IPv6 nodes without host involvement. The mobile access gateway (MAG) sends the proxy binding update (PBU) message on behalf of the MN when the MN moves to its coverage or boots up within its coverage. The local mobility anchor (LMA) acts as the home agent (HA) of the MN in the PMIPv6 domain and is responsible for maintaining the MN’s reachability by receiving the proxy binding update (PBU) from the MAG. Thus, MN does not need the MIPv6 stack in the PMIPv6 domain.
      Designing a correct protocol specification that satisfies certain security properties is an important task. BAN logic is a well-known authentication logic that remains popular with many protocol designers. Analyzing a cipher protocol through BAN Logic, we must perform the reconfiguration process to protocol idealization and induce an assumption of initial status of protocol in BAN Logic notation.
      To date, there has been no research analyzing the authentication method of EAP-TLS using BAN Logic in the PMIPv6 environment. Specifically, a designer who requires a high strength authentication system, such as online banking or e-marketing, needs a mutual authentication mechanism in a distributed environment. To this end, our research provides a basis for analyzing the certificate through the EAP-TLS authentication mechanism in PMIPv6.
      In ad-hoc environments, all nodes have function to set themselves a route and build a network. It is important how trustable each node is in the environment. This study proposes the cluster-based trust model, and uses the model to discuss how you can solve some possible problems occurred in the network. The reputation from a neighboring node is applied to the calculation of the trust value. If the trust value of a truster is used as a weight, more sophisticated calculation of the trust value is available. When you create a cluster, all nodes in the cluster can fully trust the selected head, if entire nodes in the cluster participate in the head competition. And then, the head node issues the certificate that shows the trust level of each member node. If a node moves from one cluster to another, the trust level of the node is determined by the certificate issued by the previous cluster-head. The model proposed by this study can monitor the selfish behavior of nodes in the network and isolate the selfish nodes from the network to enhance the effectiveness throughout the network.
      Trust plays an important role when any decision is made based on unstable, uncertain information. This functionality has recently been introduced in e-commerce and virtual communities, where trust represents the subjective degree of belief. In a conventional network environment, trust is set and recognized through the access control procedure. The nodes, to which fixed roles are allocated, can be replaced by various decisions in an open network environment. In this setting, reputation is an important element affecting decisions. Reputation represents a positive prediction level for an object's future behaviors, and greatly affects the decision to trust. There are two ways to obtain information regarding reputation: the subject's own experience with an agent and a recommendation from objects around a subject.
      Trust affects certain decisions, i.e., access control and the selection of a public key in the Public Key Infrastructure (PKI). Trust is available to supplement the PKI when an object decides whether to receive a public key, based on the other object's trust level. The cluster-head, which has the highest trust value, and which is elected as a head in the group, should not be a trusted third party (TTP), but should operate the same as the other nodes in the same group. Basically, the cluster-head has a role to keep the cluster’s information and to broadcast information to members. Also, all nodes may issue a certificate binding the agent’s key and identity.
      It is impossible to obtain an appropriate trust value if there is a lack of interaction among the nodes, as in the existing trust models. However, the proposed cluster-based trust model can quickly determine the trust values, even in situations where no experience data is available with the help of neighboring nodes or “introducers”.
      In this study proposes a cluster-based network model, and trust model, using fuzzy control, that can evaluate the trust value in order to provide an authentication service in ad-hoc environments where there is no centrally controlled server. This model is then used to discuss methods of effectively and correctly calculating the trust value of a node newly entering the cluster, methods to identify the selfish nodes in the cluster, and methods to protect against other possible attacks.

      더보기

      국문 초록 (Abstract) kakao i 다국어 번역

      차세대 네트워크 환경에서 개체의 인증은 네트워크 보안 분야에서 중요한 요소이다. 본 연구를 통해서 전통적인 네트워크 환경에서 사용되던 인증 개념을 차세대 네트워크 환경에서 적용 가능한 신뢰 개념으로 확장하여 정의하였다. 이는 전통적인 환경에서 0과 1로 대변 되는 인증의 결과를 실수의 범위로 확장하여 (0, 1)의 범위에서 어느 정도 인증 할 것인지에 대한 개념이다. 이러한 연구는 시시각각 변화하는 미래형 네트워크 환경에서 인증을 위한 중요한 연구가 될 것이다.
      본 연구에서는 차세대 네트워크 환경은 이동노드가 자유롭게 접근점을 옮겨가며 네트워크 자원을 활용하는 핸드오버가 빈번하게 발생하게 된다. 이러한 핸드오버가 발생하는 환경에서 인증강도가 높은 EAP-TLS 프로토콜이 안전하게 동작하는지 검증하는 작업은 중요한 작업이 될 것이다. 또한, 최근 연구가 진행되고 있거나 표준화된 인증프로토콜이 안전하게 동작하는지 검증하는 작업이 필요하게 되었다. 따라서 본 연구에서는 인증프로토콜을 분석하여 검증하기 위한 신념논리 도구를 이용하여 인증서-기반 상호인증 프로토콜을 검증하였다.
      차세대 이동 네트워크 환경에서 적용 가능한 인증구조를 개발하여 제안 하고자 한다. 인증구조는 4계층으로 이루어져 있다. 1계층은 이동호스트들이 존재하는 네트워크 환경이고, 2계층은 이러한 네트워크를 일정한 크기의 그룹으로 나누기 위해서 클러스터링-기반 모델이 활용된다. 3계층은 같은 그룹 혹은 서로 다른 그룹의 노드들을 인증하기 위한 신뢰 모델이 활용된다. 신뢰관리를 위해서 전문가의 경험이 활용되는 퍼지제어 개념이 적용된다. 4계층에서는 보안기능으로 네트워크 전체에 악영향을 주는 노드를 식별하여 네트워크 내에서 격리시키는 동작을 수행한다. 이러한 구조에 의해 개발된 인증서비스는 기존에 개발된 인증서비스와 성능평가를 통해 비교한다.
      차후 연구과제로는 EAP-기반의 키 유도 방법을 적용하여 핸드오버를 지원하기 위하여 새롭게 제안되는 인증프로토콜을 본 연구에서 활용한 신념논리를 이용하여 안전하게 동작하는지 검증하는 연구가 될 것이다.
      번역하기

      차세대 네트워크 환경에서 개체의 인증은 네트워크 보안 분야에서 중요한 요소이다. 본 연구를 통해서 전통적인 네트워크 환경에서 사용되던 인증 개념을 차세대 네트워크 환경에서 적용 ...

      차세대 네트워크 환경에서 개체의 인증은 네트워크 보안 분야에서 중요한 요소이다. 본 연구를 통해서 전통적인 네트워크 환경에서 사용되던 인증 개념을 차세대 네트워크 환경에서 적용 가능한 신뢰 개념으로 확장하여 정의하였다. 이는 전통적인 환경에서 0과 1로 대변 되는 인증의 결과를 실수의 범위로 확장하여 (0, 1)의 범위에서 어느 정도 인증 할 것인지에 대한 개념이다. 이러한 연구는 시시각각 변화하는 미래형 네트워크 환경에서 인증을 위한 중요한 연구가 될 것이다.
      본 연구에서는 차세대 네트워크 환경은 이동노드가 자유롭게 접근점을 옮겨가며 네트워크 자원을 활용하는 핸드오버가 빈번하게 발생하게 된다. 이러한 핸드오버가 발생하는 환경에서 인증강도가 높은 EAP-TLS 프로토콜이 안전하게 동작하는지 검증하는 작업은 중요한 작업이 될 것이다. 또한, 최근 연구가 진행되고 있거나 표준화된 인증프로토콜이 안전하게 동작하는지 검증하는 작업이 필요하게 되었다. 따라서 본 연구에서는 인증프로토콜을 분석하여 검증하기 위한 신념논리 도구를 이용하여 인증서-기반 상호인증 프로토콜을 검증하였다.
      차세대 이동 네트워크 환경에서 적용 가능한 인증구조를 개발하여 제안 하고자 한다. 인증구조는 4계층으로 이루어져 있다. 1계층은 이동호스트들이 존재하는 네트워크 환경이고, 2계층은 이러한 네트워크를 일정한 크기의 그룹으로 나누기 위해서 클러스터링-기반 모델이 활용된다. 3계층은 같은 그룹 혹은 서로 다른 그룹의 노드들을 인증하기 위한 신뢰 모델이 활용된다. 신뢰관리를 위해서 전문가의 경험이 활용되는 퍼지제어 개념이 적용된다. 4계층에서는 보안기능으로 네트워크 전체에 악영향을 주는 노드를 식별하여 네트워크 내에서 격리시키는 동작을 수행한다. 이러한 구조에 의해 개발된 인증서비스는 기존에 개발된 인증서비스와 성능평가를 통해 비교한다.
      차후 연구과제로는 EAP-기반의 키 유도 방법을 적용하여 핸드오버를 지원하기 위하여 새롭게 제안되는 인증프로토콜을 본 연구에서 활용한 신념논리를 이용하여 안전하게 동작하는지 검증하는 연구가 될 것이다.

      더보기

      목차 (Table of Contents)

      • 제 1 장 서 론 1
      • 제 1 절 연구의 동기와 목적 1
      • 제 2 절 연구 내용 및 범위 3
      • 제 3 절 논문의 구성 5
      • 제 2 장 인증 및 권한 구조 7
      • 제 1 장 서 론 1
      • 제 1 절 연구의 동기와 목적 1
      • 제 2 절 연구 내용 및 범위 3
      • 제 3 절 논문의 구성 5
      • 제 2 장 인증 및 권한 구조 7
      • 제 1 절 전통적 인증 및 권한 구조 7
      • 1. 인증 10
      • 2. 권한 17
      • 3. 접근제어절차 17
      • 제 2 절 유비쿼터스 네트워크-기반 AAA 시나리오 19
      • 1. 애드 혹 네트워크 20
      • 2. 이동 네트워크 25
      • 3. 센서 네트워크 29
      • 제 3 절 이동 네트워크 환경에서 인증 및 권한 구조 33
      • 1. 이동 IP 의 AAA 구조 33
      • 2. PANA 프레임워크 35
      • 3. NEMO AAA의 기본 구조 37
      • 4. 중첩 환경에서의 NEMO AAA 구조 38
      • 5. 애드 혹과 NEMO 네트워크 특징 비교 40
      • 6. 애드 혹과 전통적 라우팅 프로토콜의 비교 43
      • 제 3 장 인증서-기반 상호인증 방법 분석 47
      • 제 1 절 서 론 47
      • 제 2 절 PMIPv6 네트워크 환경 49
      • 1. PMIPv6 네트워크 49
      • 2. PMIPv6 환경에서의 동작 50
      • 3. PMIPv6 환경의 핸드오버 기술 52
      • 4. PMIPv6 환경의 이동 시나리오 54
      • 제 3 절 EAP-TLS 인증프로토콜 56
      • 1. 공개키 인증서-기반 EAP-TLS 인증절차 56
      • 2. EAP 57
      • 3. EAP-TLS를 PMIPv6 환경에 적용 61
      • 제 4 절 BAN 로직과 인증서를 위한 확장 로직 63
      • 1. 암호 프로토콜의 안전성 검증의 필요성 및 방법 63
      • 2. BAN 로직 64
      • 3. BAN 로직의 표현과 확장 로직 65
      • 4. 인증서의 개념화 66
      • 5. BAN 로직 추론 규칙 67
      • 제 5 절 인증서-기반 상호인증 70
      • 1. 분석을 위한 가정 71
      • 2. 분석에 필요한 표현 71
      • 3. 초기인증 표현 72
      • 4. 핸드오프인증 표현 72
      • 제 6 절 검증의 증명 73
      • 1. 초기인증의 목표 73
      • 2. 초기인증의 가정 74
      • 3. 초기인증 메시지의 BAN 로직 표현 74
      • 4. 초기인증 메시지의 분석 75
      • 5. 핸드오프인증의 목표 77
      • 6. 핸드오프인증의 가정 77
      • 7. 핸드오프인증 메시지의 BAN 로직 표현 77
      • 8. 핸드오프인증 메시지의 분석 78
      • 제 7 절 결론 및 향후 연구과제 79
      • 제 4 장 신뢰-기반 접근제어 81
      • 제 1 절 서 론 82
      • 제 2 절 신뢰모델 84
      • 1. 신뢰 개념 85
      • 2. 신뢰와 평판모델과의 상관성 85
      • 3. 신뢰 측정기준 86
      • 4. 신뢰와 리스크 상관성 88
      • 제 3 절 신뢰관리 89
      • 1. 신뢰의 생성 및 진화 89
      • 2. 신뢰 계산 91
      • 3. 신뢰시스템 고려사항 94
      • 4. 시스템 위협요인 96
      • 제 4 절 신뢰모델 평가 97
      • 1. 평판서버가 없는 경우 97
      • 2. 네트워크 내의 클러스터 구성모형 100
      • 3. 평판서버가 있는 경우 104
      • 제 5 절 신뢰 모델 성능평가 분석 106
      • 1. 시스템 구성 106
      • 2. 평판서버가 없는 경우의 분석 107
      • 3. 평판서버가 있는 경우의 분석 108
      • 제 6 절 결론 및 향후 연구과제 110
      • 제 5 장 신뢰-기반과 클러스터-기반 인증서비스 112
      • 제 1 절 서 론 112
      • 제 2 절 신뢰시스템 114
      • 1. 신뢰관계 114
      • 2. 신뢰의 역할 115
      • 3. 클러스터 형성 방법 116
      • 4. 악의적인 노드의 행동 116
      • 5. 신뢰시스템의 고려사항 117
      • 6. 퍼지 제어와 평판시스템 118
      • 제 3 절 인증시스템구조와 모델 118
      • 1. 제안된 인증시스템의 구조 119
      • 2. 네트워크 모델 121
      • 3. 신뢰모델 122
      • 4. 보안동작 123
      • 제 4 절 클러스터링-기반 신뢰평가모델 124
      • 1. 그룹 내 신뢰형성 시나리오 125
      • 2. 그룹 간 신뢰형성 시나리오 127
      • 제 5 절 퍼지 제어 127
      • 1. 신뢰 관리를 위한 퍼지 제어 127
      • 2. 신뢰 값의 다른 단계를 위한 소속함수 128
      • 3. 신뢰 값 통합 130
      • 제 6 절 성능 분석 130
      • 1. 성능 분석 매개변수 131
      • 2. 총 오버헤드 계산 132
      • 3. 악의적인 노드의 탐지비율 133
      • 제 7 절 결론과 논의 135
      • 1. 신뢰관리를 위한 퍼지제어의 장점 135
      • 2. 인증서 기반의 클러스터링과 인증 135
      • 3. 공격들에 유연한 모델과 향후 연구과제 136
      • 제 6 장 결 론 138
      • 참고문헌 140
      • ABSTRACT 151
      더보기

      분석정보

      View

      상세정보조회

      0

      Usage

      원문다운로드

      0

      대출신청

      0

      복사신청

      0

      EDDS신청

      0

      동일 주제 내 활용도 TOP

      더보기

      주제

      연도별 연구동향

      연도별 활용동향

      연관논문

      연구자 네트워크맵

      공동연구자 (7)

      유사연구자 (20) 활용도상위20명

      이 자료와 함께 이용한 RISS 자료

      나만을 위한 추천자료

      해외이동버튼