J1Yun
ZU-TECHLOG
J1Yun
์ „์ฒด ๋ฐฉ๋ฌธ์ž
์˜ค๋Š˜
์–ด์ œ
  • ๐Ÿ“‘ Category (135)
    • Algorithm (61)
      • ๐Ÿ“š Concept (6)
      • ๐Ÿ“˜ Baekjoon Judge (53)
      • ๐Ÿ“— Programmers (2)
    • Computer Science (42)
      • ๐Ÿ”’ Operating System (14)
      • ๐Ÿ“ก Network (15)
      • ๐Ÿ’พ Database (8)
      • ๐Ÿงฉ Design Pattern (4)
      • ๐Ÿ”‘ Security (1)
    • Activities (12)
      • ๐Ÿฆ ๋ฉ‹์Ÿ์ด์‚ฌ์ž์ฒ˜๋Ÿผ 9๊ธฐ (6)
      • ๐Ÿ’ป SW๋งˆ์—์ŠคํŠธ๋กœ 13๊ธฐ (6)
    • Infra (1)
      • โ˜๏ธ AWS (1)
    • Languages (1)
      • ๐Ÿ’™ Python (1)
    • Backend (7)
      • ๐Ÿ”ต Django (4)
      • ๐ŸŸข Node.js (3)
    • Ect. (8)
      • ๐Ÿ’ฌ Talk (0)
      • ๐Ÿ—‚๏ธ ๊ฐœ๋ฐœ์ง๊ตฐ ์ทจ์—… ์ค€๋น„์ž๋ฃŒ (8)

๋ธ”๋กœ๊ทธ ๋ฉ”๋‰ด

  • ํ™ˆ
  • ํƒœ๊ทธ
  • ๋ฐฉ๋ช…๋ก

๊ณต์ง€์‚ฌํ•ญ

์ธ๊ธฐ ๊ธ€

์ตœ๊ทผ ๋Œ“๊ธ€

์ตœ๊ทผ ๊ธ€

ํ‹ฐ์Šคํ† ๋ฆฌ

250x250
hELLO ยท Designed By ์ •์ƒ์šฐ.
J1Yun

ZU-TECHLOG

[๋ณด์•ˆ] ๋Œ€์นญํ‚ค์™€ ๋น„๋Œ€์นญํ‚ค(๊ณต๊ฐœํ‚ค) ์•”ํ˜ธํ™” + ๋””์ง€ํ„ธ ์ธ์ฆ์„œ
Computer Science/๐Ÿ”‘ Security

[๋ณด์•ˆ] ๋Œ€์นญํ‚ค์™€ ๋น„๋Œ€์นญํ‚ค(๊ณต๊ฐœํ‚ค) ์•”ํ˜ธํ™” + ๋””์ง€ํ„ธ ์ธ์ฆ์„œ

728x90

๋Œ€์นญํ‚ค ์•”ํ˜ธํ™”

  • ์•”๋ณตํ˜ธํ™”์— ์‚ฌ์šฉ๋˜๋Š” ํ‚ค๊ฐ€ ๋™์ผํ•œ ๋ฐฉ์‹
  • ์žฅ์ : ์•”ํ˜ธํ™” ์†๋„ ๋น ๋ฆ„, ๋Œ€์šฉ๋Ÿ‰ ๋ฐ์ดํ„ฐ ์•”ํ˜ธํ™”์— ์ ํ•ฉ, ๊ธฐ๋ฐ€์„ฑ ์ œ๊ณต
  • ๋‹จ์ : ํ‚ค ๋ฐฐ์†ก ๋ฌธ์ œ ๋ฐœ์ƒ - ํ‚ค ๊ตํ™˜ ์‹œ ํƒˆ์ทจ ์œ„ํ—˜, ์‚ฌ๋žŒ์ด ์ฆ๊ฐ€ํ• ์ˆ˜๋ก ํ‚ค ๊ด€๋ฆฌ ์–ด๋ ค์›€, ๋‚ฎ์€ ํ™•์žฅ์„ฑ, ๋ฌด๊ฒฐ์„ฑ/์ธ์ฆ/๋ถ€์ธ๋ฐฉ์ง€ ์ œ๊ณต X
  • Session Key(์„ธ์…˜ํ‚ค), Secret Key(๋น„๋ฐ€ํ‚ค), Shared Key(๊ณต์œ ํ‚ค), ๋‹จ์šฉํ‚ค๋ผ๊ณ ๋„ ํ•จ
  • ๋Œ€ํ‘œ์  ์•Œ๊ณ ๋ฆฌ์ฆ˜ : ๊ณต์ธ์ธ์ฆ์„œ์˜ ์•”ํ˜ธํ™”๋ฐฉ์‹์œผ๋กœ ์œ ๋ช…ํ•œ SEED, DES, 3DES, AES, ARIA, ์ตœ๊ทผ ์ฃผ๋ชฉ๋ฐ›๊ณ  ์žˆ๋Š” ์•”ํ˜ธ์ธ ChaCha20

 

 

๋น„๋Œ€์นญํ‚ค ์•”ํ˜ธํ™”

  • ์•”๋ณตํ˜ธํ™”์— ์‚ฌ์šฉ๋˜๋Š” ํ‚ค๊ฐ€ ์„œ๋กœ ๋‹ค๋ฅธ ๋ฐฉ์‹ (๊ณต๊ฐœํ‚ค์™€ ๊ฐœ์ธํ‚ค)
  • ์žฅ์ : ํ‚ค ๋ถ„๋ฐฐ ํ•„์š” X, ๊ธฐ๋ฐ€์„ฑ/์ธ์ฆ/๋ถ€์ธ๋ฐฉ์ง€ ๊ธฐ๋Šฅ ์ œ๊ณต
  • ๋‹จ์ : ์•”ํ˜ธํ™” ์†๋„ ๋А๋ฆผ, ๋ฌด๊ฒฐ์„ฑ ์ œ๊ณต X
  • ์•”ํ˜ธ ๋ชจ๋“œ: ๊ณต๊ฐœํ‚ค๋กœ ์•”ํ˜ธํ™” -> ๊ฐœ์ธํ‚ค๋กœ ๋ณตํ˜ธํ™”
    • ์†Œ๋Ÿ‰์˜ ๋ฉ”์‹œ์ง€ ์•”ํ˜ธํ™” ๋ชฉ์ 
    • ์ฃผ๋กœ ํ‚ค ๊ตํ™˜์˜ ์šฉ๋„๋กœ ์‚ฌ์šฉ
  • ์ธ์ฆ ๋ชจ๋“œ: ๊ฐœ์ธํ‚ค๋กœ ์•”ํ˜ธํ™” -> ๊ณต๊ฐœํ‚ค๋กœ ๋ณตํ˜ธํ™”
    • ๋ฉ”์‹œ์ง€๋ฅผ ์ธ์ฆ ๋ฐ ๋ถ€์ธ ๋ฐฉ์ง€ํ•˜๋Š” ๋ชฉ์ 
  • ๋Œ€ํ‘œ์  ์•Œ๊ณ ๋ฆฌ์ฆ˜: RSA, Diffie Hellman, ECC ๋“ฑ

 

๋Œ€์นญํ‚ค VS ๋น„๋Œ€์นญํ‚ค(๊ณต๊ฐœํ‚ค) ์ •๋ฆฌ

 
๋Œ€์นญํ‚ค
๋น„๋Œ€์นญํ‚ค
ํ‚ค ๊ด€๊ณ„
์•”ํ˜ธํ™” ํ‚ค = ๋ณตํ˜ธํ™”ํ‚ค
์•”ํ˜ธํ™” ํ‚ค ≠ ๋ณตํ˜ธํ™” ํ‚ค
์•”ํ˜ธํ™” ํ‚ค
๋น„๋ฐ€ํ‚ค
๊ณต๊ฐœํ‚ค
๋ณตํ˜ธํ™” ํ‚ค
๋น„๋ฐ€ํ‚ค
๊ฐœ์ธํ‚ค
๋น„๋ฐ€ํ‚ค ์ „์†ก
ํ•„์š”
๋ถˆํ•„์š”
ํ‚ค ๊ธธ์ด
์งง๋‹ค
๊ธธ๋‹ค
์ธ์ฆ
๊ณค๋ž€
์šฉ์ด
์•”๋ณตํ™” ์†๋„
๋น ๋ฅด๋‹ค
๋А๋ฆฌ๋‹ค
๊ฒฝ์ œ์„ฑ
๋†’๋‹ค
๋‚ฎ๋‹ค
์ „์ž์„œ๋ช…
๋ณต์žก
๊ฐ„๋‹จ
์ฃผ ์šฉ๋„
๊ณ ์šฉ๋Ÿ‰ ๋ฐ์ดํ„ฐ ์•”ํ˜ธํ™”(๊ธฐ๋ฐ€์„ฑ)
ํ‚ค ๊ตํ™˜ ๋ฐ ๋ถ„๋ฐฐ, ์ธ์ฆ, ๋ถ€์ธ๋ฐฉ์ง€
์žฅ์ 
- ์•”๋ณตํ˜ธํ™” ํ‚ค ๊ธธ์ด๊ฐ€ ์งง์Œ
- ๊ตฌํ˜„์ด ์šฉ์ดํ•˜๊ณ , ์•”๋ณตํ˜ธํ™”๊ฐ€ ๋น ๋ฆ„
- ์•”ํ˜ธํ™” ๊ฐ•๋„ ์ „ํ™˜์ด ์šฉ์ด
- ์•”ํ˜ธํ™” ๊ธฐ๋Šฅ์ด ์šฐ์ˆ˜
- ๊ฐ์ข… ์•”ํ˜ธ ์‹œ์Šคํ…œ์˜ ๊ธฐ๋ณธ์œผ๋กœ ํ™œ์šฉ
- ์‚ฌ์šฉ์ž๊ฐ€ ์ฆ๊ฐ€ํ•˜๋”๋ผ๋„ ๊ด€๋ฆฌํ•ด์•ผ ํ•  ํ‚ค์˜ ๊ฐœ์ˆ˜๊ฐ€ ์ƒ๋Œ€์ ์œผ๋กœ ์ ์Œ
- Key ์ „๋‹ฌ์ด๋‚˜ ๊ตํ™˜์— ์ ํ•ฉ
- ์ธ์ฆ๊ณผ ์ „์ž ์„œ๋ช…์— ์ด์šฉ
- ๋Œ€์นญํ‚ค ๋ณด๋‹ค ํ™•์žฅ์„ฑ์ด ์ข‹์Œ
- ์—ฌ๋Ÿฌ๊ฐ€์ง€ ๋ถ„์•ผ์—์„œ ์‘์šฉ์ด ๊ฐ€๋Šฅ
- ํ‚ค ๋ณ€ํ™”์˜ ๋นˆ๋„๊ฐ€ ์ ์Œ
๋‹จ์ 
- ํ‚ค ๊ตํ™˜ ์›๋ฆฌ๊ฐ€ ๋ช…์‹œ๋˜์ง€ ์•Š์•„ ํ‚ค ๋ถ„๋ฐฐ๊ฐ€ ์–ด๋ ค์›€
- ๊ด€๋ฆฌํ•  ์•”๋ณตํ˜ธํ™” ํ‚ค๊ฐ€ ๋งŽ์Œ
- ํ™•์žฅ์„ฑ์ด ๋‚ฎ์Œ
- ์ „์ž์„œ๋ช…(๋””์ง€ํ„ธ์„œ๋ช…)์ด ๋ถˆ๊ฐ€๋Šฅ
- ๋ถ€์ธ๋ฐฉ์ง€ ๊ธฐ๋Šฅ์ด ์—†์Œ
- ํ‚ค ๊ธธ์ด๊ฐ€ ๊น€
- ๋ณต์žกํ•œ ์ˆ˜ํ•™์  ์—ฐ์‚ฐ์„ ์ด์šฉํ•จ์œผ๋กœ ์•”๋ณตํ˜ธํ™” ์†๋„๊ฐ€ ๋А๋ฆผ
- ์ค‘๊ฐ„์— ์ธ์ฆ๊ณผ์ •์ด ์—†์œผ๋ฏ€๋กœ ์ค‘๊ฐ„์ž ๊ณต๊ฒฉ์— ์ทจ์•ฝ (์ „์ž์„œ๋ช…,์ธ์ฆ์„œ ๋“ฑ์œผ๋กœ ํ•ด๊ฒฐ)
์˜ˆ
[Feistel] : SEED, DES
[SPN] : ARIA, AES, IDEA
๋ฉ”์‹œ์ง€ ์ธ์ฆ์ฝ”๋“œ(MAC)
Diff-Hellman, RSA, ECC, DAS
[Block chain]
[TPM]

 

โ€ป ์ฐธ๊ณ 

  • ๊ธฐ๋ฐ€์„ฑ(Confidentiality): ์ธ๊ฐ€๋˜์ง€ ์•Š์€ ์ž๋Š” ์ •๋ณด๋ฅผ ํ™•์ธํ•˜์ง€ ๋ชปํ•˜๋„๋ก ํ•˜๋ฉฐ ์ •๋ณด๊ฐ€ ์œ ์ถœ๋˜๋”๋ผ๋„ ํ‰๋ฌธ์œผ๋กœ ํ•ด๋…ํ•  ์ˆ˜ ์—†๊ณ  ๋ณ€์กฐ๋‚˜ ์œ„์กฐ๋˜์ง€ ๋ชปํ•˜๋„๋ก ๊ธฐ๋ฐ€์„ ์œ ์ง€
  • ๋ฌด๊ฒฐ์„ฑ(Integrity): ์ธ๊ฐ€๋˜์ง€ ์•Š์€ ์ž๋กœ๋ถ€ํ„ฐ ์œ„์กฐ๋‚˜ ๋ณ€์กฐ๊ฐ€ ๋ฐœ์ƒํ•˜์ง€ ์•Š์•˜๋Š”์ง€ ํ™•์ธ
  • ์ธ์ฆ(Authentication): ์ˆ˜์‹ ๋ฐ›์€ ๋ฉ”์‹œ์ง€๊ฐ€ ์†ก์‹ ์ž ๋ณธ์ธ์ด๋ผ๋Š” ๊ฒƒ์„ ํ™•์ธํ•˜๊ณ  ์ฆ๋ช…
  • ๋ถ€์ธ ๋ฐฉ์ง€(Non-Repudiation): ๋ฉ”์‹œ์ง€๋ฅผ ๋ณด๋‚ธ ์‚ฌ๋žŒ์ด ๋ณด๋‚ธ ์‚ฌ์‹ค์„ ๋ถ€์ธํ•˜๊ฑฐ๋‚˜, ๋ฐ›๋Š” ์‚ฌ๋žŒ์ด ๋ฐ›์€ ์‚ฌ์‹ค์„ ๋ถ€์ธํ•˜์ง€ ์•Š๋„๋ก ์ฆ๋ช…
๐Ÿ’ก ๋ฌด๊ฒฐ์„ฑ์€ ๋Œ€์นญํ‚ค์™€ ๋น„๋Œ€์นญํ‚ค(๊ณต๊ฐœํ‚ค) ์•Œ๊ณ ๋ฆฌ์ฆ˜ ๋ชจ๋‘์—์„œ ์„ฑ๋ฆฝํ•˜์ง€ ์•Š์œผ๋ฉฐ, ๋น„๋Œ€์นญํ‚ค ์•”ํ˜ธํ™” ๋ฐฉ์‹์—์„œ๋Š” ์ „์ž ์„œ๋ช…(์ธ์ฆ์„œ)๋ฅผ ์ถ”๊ฐ€ํ•จ์œผ๋กœ์จ ๋ฌด๊ฒฐ์„ฑ ๋ณด์žฅ ๊ฐ€๋Šฅ (๋Œ€์นญํ‚ค๋Š” ์ „์ž์„œ๋ช… ์–ด๋ ค์›€)

 

 

๋””์ง€ํ„ธ ์ธ์ฆ์„œ

  • ๋ณด์•ˆ์ด ํ•„์š”ํ•œ ํ†ต์‹ ์—์„œ ์ƒ๋Œ€๋ฐฉ์ด ํ†ต์‹ ํ•˜๊ณ ์ž ํ•˜๋Š” ๋Œ€์ƒ์ด ๋งž์Œ์„ ํ™•์ธํ•ด ์ฃผ๋Š” ์—ญํ• 
  • ์ธ์ฆ์„œ ์†Œ์œ ์ฃผ์˜ ์‹ ๋ถ„์„ ๋ณด์ฆํ•˜๊ณ , ์ธ์ฆ์„œ์— ํฌํ•จ๋œ ๊ณต๊ฐœํ‚ค(public key)๊ฐ€ ๊ทธ ์†Œ์œ ์ฃผ ๊ฒƒ์ด ๋งž์Œ์„ ์ฆ๋ช…
  • ์„œ๋กœ๊ฐ€ ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ์ œ์‚ผ์ž ์ธ์ฆ ๊ธฐ๊ด€์ธ CA(Certificate Authority)์™€ ๋น„๋Œ€์นญ ์•”ํ˜ธํ™” ํ•„์š”
  • CA๊ฐ€ ์ธ์ฆ์„œ๋ฅผ ์š”์ฒญํ•œ ์‚ฌ๋žŒ์ด๋‚˜ ๊ธฐ๊ด€์— ๋Œ€ํ•œ ์‹ ๋ถ„๊ณผ ๋ณด์œ ํ•œ ๊ณต๊ฐœํ‚ค๋ฅผ ๋˜ ๋‹ค๋ฅธ ๊ด€๊ณ„์ž์—๊ฒŒ ๋ณด์ฆ์„ ํ•ด์ฃผ๋Š” ๋ฐฉ์‹

 

๋””์ง€ํ„ธ ์ธ์ฆ์„œ ๋ฐœ๊ธ‰ ๊ณผ์ •

  1. User B๋Š” CA์—๊ฒŒ ์ž์‹ ์ด B์ž„์„ ์ฆ๋ช…ํ•˜๊ธฐ ์œ„ํ•ด ์ž์‹ ์˜ ๊ณต๊ฐœํ‚ค๋ฅผ ๋ณด๋‚ด๊ณ , CA์—๊ฒŒ B์˜ ๊ณต๊ฐœํ‚ค๊ฐ€ ๋งž์Œ์„ ์ธ์ฆํ•˜๋Š” ์ธ์ฆ์„œ ๋ฐœ๊ธ‰๋ฐ›์Œ
  2. User A๋Š” User B์—๊ฒŒ B์˜ ๊ณต๊ฐœํ‚ค๊ฐ€ ํฌํ•จ๋œ ์ธ์ฆ์„œ๋ฅผ ๋ฐ›์Œ
  3. User A๋Š” ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ์ธ์ฆ๊ธฐ๊ด€ CA์—๊ฒŒ ์ง„์งœ๋กœ CA์—์„œ ๋ฐœ๊ธ‰๋œ ์ธ์ฆ์„œ๊ฐ€ ๋งž๋Š”์ง€ ํ™•์ธ
  4. User A๋Š” ์ธ์ฆ์„œ์— ํฌํ•จ๋œ ๊ณต๊ฐœํ‚ค๋กœ ๋ฉ”์‹œ์ง€๋ฅผ ์•”ํ˜ธํ™”ํ•ด์„œ User B์—๊ฒŒ ์ „๋‹ฌ
  5. User B๋Š” ๋ณธ์ธ์˜ ๊ฐœ์ธํ‚ค๋กœ ํ•ด๋‹น ๋ฉ”์‹œ์ง€๋ฅผ ๋ณตํ˜ธํ™”

 

728x90
์ €์ž‘์žํ‘œ์‹œ (์ƒˆ์ฐฝ์—ด๋ฆผ)
    J1Yun
    J1Yun
    ๊ฐœ๋ฐœ ๊ด€๋ จ ๊ธฐ์ˆ  ๋ฐ ๊ณต๋ถ€ ๋‚ด์šฉ ๊ธฐ๋ก์žฅ

    ํ‹ฐ์Šคํ† ๋ฆฌํˆด๋ฐ”