논문 상세보기

사이버-물리 시스템 기반 IoT 환경에서 ECC 삼중 인증 프로토콜의 보안 취약점 모델링과 보안 개선 설계 KCI 등재

Improvements for ECC-Based Three-Factor Authentication Protocols in IoT-Enabled e-Health Cloud Systems

변해원
  • 언어KOR
  • URLhttps://db.koreascholar.com/Article/Detail/451678
구독 기관 인증 시 무료 이용이 가능합니다. 4,000원
한국기계항공기술학회지(구 한국기계기술학회지) (Journal of the Korean Society of Mechanical and Aviation Technology)
한국기계항공기술학회(구 한국기계기술학회) (Korean Society of Mechanical Technology)
초록

This study critically analyzed a lightweight ECC-based three-factor authentication protocol designed for IoT-enabled e-Health cloud systems. Through adversarial modeling and formal verification, three core vulnerabilities were identified: static identity inference via XOR-cancellation across sessions, ephemeral key reuse leading to session key replay, and insufficient biometric template binding enabling cross-system correlation. Countermeasures proposed include dual-nonce ephemeral key diversification, salted fuzzy extractor-based biometric binding, dual-ephemeral Diffie–Hellman key exchange for forward secrecy, and a permissioned blockchain audit layer. Simulation results on Raspberry Pi 4 and Intel i5 demonstrate 100% replay detection, per-session forward secrecy, eliminated biometric linkability, and end-to-end latency increase within 6.7%, confirming suitability for resource-constrained IoT healthcare deployments.

키워드
타원곡선 암호IoT 인증세션키취약점 분석e-Health 클라우드 ECCAuthentication ProtocolSession KeyVulnerability Analysise-Health Cloud
목차
Abstract
1. 서 론
2. 관련 연구
3. 연구 방법
4. 프로토콜 분석
    4.1 기존 ECC 기반 삼중 인증 프로토콜
    4.2 취약점 분석
5. 프로토콜 개선 방안 제안
    5.1 이중 난수 기반 에피머럴 키 신선성 강화
    5.2 솔팅된 퍼지 추출기 기반 생체정보 바인딩
    5.3 이중 에피머럴 디피-헬만 교환을 통한 전방비밀성 확보
    5.4 허가형 블록체인 감사 로그 및 스마트카드 저장 보안 강화
6. 모의 실험 결과
7. 결 론
References
저자
  • 변해원(Dept. of Future Technology, Korea University of Technology and Education, South Korea) | Haewon Byeon Corresponding author