Abstract:
Disclosed herein is an apparatus for enhancing network security, which includes an information collection unit for collecting information about states of hosts that form a network and information about connectivity in the network; an attack surface analysis unit for analyzing attack surfaces by creating an attack graph using the information about the states and the information about connectivity; a security-enhancing strategy establishment unit for establishing a security-enhancing strategy based on the attack graph; and a security-enhancing strategy implementation unit for delivering a measure based on the security-enhancing strategy to a corresponding host, thereby taking a security-enhancing measure.
Abstract:
Disclosed herein are an apparatus and method for managing personal information. The method includes a step in which a user terminal device registers the decentralized identification information of a user in a blockchain, receives the personal information of the user, stores the same in an endpoint for managing the personal information, and registers a personal information access policy for the personal information in a first server; a step in which the apparatus receives the decentralized identifier of the user, retrieves the decentralized identification information of the user, corresponding to the decentralized identifier, from the blockchain, and requests a personal information access token for accessing the personal information from the first server using the decentralized identification information; and a step in which the apparatus identifies the endpoint from the personal information access token, which is generated based on the personal information access policy, and retrieves the personal information from the endpoint.
Abstract:
There are provided a method and device for providing a security assistant service. In an embodiment of the invention, there is provided a device for providing a security assistant service in which a first terminal and a second terminal are included. The device includes the first terminal configured to generate information for requesting verification of an original plaintext to be signed (here, the information for requesting verification of the original plaintext to be signed refers to the original plaintext to be signed or a hash value of the original plaintext to be signed) and transmit an encrypted value in which the information for requesting verification of the original plaintext to be signed is encrypted and the original plaintext to be signed to the second terminal, and the second terminal configured to receive the original plaintext to be signed and the encrypted value, decrypt the information for requesting verification of the original plaintext to be signed by decrypting the encrypted value, display the original plaintext to be signed when the original plaintext to be signed or a hash value of the original plaintext to be signed matches the decrypted information for requesting verification of the original plaintext to be signed, receive a verification signal from a user, generate an original verification message (here, the original verification message refers to information indicating that the original plaintext to be signed is verified by the user and the information can be proved using a key held by the second terminal and verified using the key held by the first terminal) and transmit the original verification message to the first terminal.
Abstract:
Disclosed herein are a terminal apparatus, a server apparatus, and a method for FIDO universal authentication using a blockchain. The method includes sending, by the terminal apparatus, a FIDO service request for any one of FIDO registration, FIDO authentication, and FIDO deregistration for an application service provided by the server apparatus to the server apparatus; verifying, by the blockchain, a FIDO service response message, which is created as a result of local authentication of a user in the terminal apparatus in response to the FIDO service request; and processing, by the server apparatus, the FIDO service request based on whether the FIDO service response message is successfully verified by the blockchain.
Abstract:
Disclosed herein are an apparatus and method for authenticated key exchange using a password and an identity-based signature, by which robustness is provided in order to prevent a server impersonation attack when a password is exposed, and by which a client may be provided with convenient authentication using an ID and a password.
Abstract:
Disclosed are an apparatus and method for providing a digital signature. The apparatus includes a certificate unit, an input unit receives a selection input for a certificate related to signature content received from a signature-requesting terminal, and a control unit for determining whether the certificate unit is capable of performing a digital signature function corresponding to a selected certificate. If the certificate unit is capable of performing the digital signature function, the certificate unit creates a digital signature based on a private key corresponding to the selected certificate when the control unit commands the certificate unit to create a digital signature. Further, if the certificate unit is not capable of performing the digital signature function, the control unit creates a digital signature based on a private key corresponding to a certificate selected from the certificate unit. The control unit transmits the digital signature to the signature-requesting terminal.