DOI QR코드

DOI QR Code

Blockchain-based new identification system

블록체인 기반 새로운 신원확인 체계

  • Received : 2020.11.10
  • Accepted : 2021.02.05
  • Published : 2021.02.28

Abstract

The value and importance of personal information are increasing due to the increasing number of fields where the Internet environment and computing environment are used, and user authentication technology is also changing. Until now, accredited certificates, which are mainly used in the financial sector, are being replaced with biometric authentication technology due to the problem of revocation. However, another problem is that biometric information cannot be modified once it is leaked. Recently, with the advent of blockchain technology, research on user authentication methods has actively progressed. In this paper, both public certificate and blockchain-based user authentication can be used without system change, and a new DID issuance and reissuance method that can replace the resident registration number is presented. The proposed system can be used without restrictions in a blockchain. However, the currently used DID requires installation of an application at the Interworking Support Center for verification. Since a DID can be authenticated without registering as a member, indiscriminate information collection can be prevented. Security, convenience, and determinism are compared with the existing system, and excellence is proven based on various attack methods, its portability, and proxy use.

인터넷 환경과 컴퓨팅 환경이 활용되는 분야 증가로 개인정보의 활용가치와 중요성이 높아지고 있으며, 사용자 인증 기술 또한 변화하고 있다. 현재까지 금융권 위주로 사용되고 있는 공인인증서는 폐지 문제로 생체인증 기술로 교체되고 있다. 하지만 생체정보는 한번 유출되면 수정할 수 없다는 문제점을 내포하고 있다. 최근 블록체인 기술의 등장으로 사용자 인증 방식에 대한 연구가 활발하게 진행되고 있다. 본 논문에서는 공인인증서와 블록체인 기반 사용자 인증 방법 모두를 시스템 변경 없이 사용할 수 있도록 설계하였으며, 주민등록번호를 대체할 수 있는 새로운 분산 ID(DID) 발급 및 재발급, 검증, 위임 방법을 제안한다. 제안하는 시스템에서는 블록체인에 제한 없이 사용이 가능하다. 단 현재 사용되고 있는 분산 ID는 검증을 위해 상호연동지원센터에 응용프로그램 설치가 필요하다. 분산 ID는 별도의 회원가입 없이 인증할 수 있으므로 무분별한 정보 수집을 방지할 수 있다. 기존 시스템과 보안성, 편의성, 확정성을 비교하였으며, 다양한 공격방법과 휴대성, 대리 사용 등을 통해 우수함을 입증하였다.

Keywords

References

  1. Kim Jai-Yong, Jung Yong-hoon, Jun Moon-Suk, Lee Sang-Beon, "User Integrated Authentication System using EID in Blockchain Environment", Journal of the Korea Academia-Industrial cooperation Society, Vol.21, No.3, pp.24-31, Mar. 2020. DOI : http://dx.doi.org/10.5762/KAIS.2020.21.3.24
  2. S. G. Moon, M. S. Kim, H. J. Kim, "Design of an Integrated University Information Service Model Based on Block Chain", Journal of the Korea Academia-Industrial cooperation Society Vol. 20, No.2 pp. 43-50, 2019. DOI : https://doi.org/10.5762/KAIS.2019.20.2.43
  3. S. D. Yoo, "A Study on Consensus Algorithm based on Blockchain", The Journal of The Institute of Internet, Broadcasting and Communication , Vol.19, No.3, pp.25-32, 2019. DOI : https://doi.org/10.7236/JIIBC.2019.19.3.25
  4. S. J. Han, S. T. Kim, S. Y. park, "A GDPR based Approach to Enhancing Blockchain Privacy", The Journal of The Institute of Internet, Broadcasting and Communication , Vol.19, No.5, pp.33-38, 2019. DOI : https://doi.org/10.7236/JIIBC.2019.19.5.33
  5. Sang-Il Choi, "Implementation of Service Model for Data-Driven Integrated Urban Management Service Operation Using Blockchain Technology", The Journal of The Korea Academia Industrial, Vol.20, No.10, pp.503-514, 2019. DOI : https://doi.org/10.5762/KAIS.2019.20.10.503
  6. Korea Certification Authority Centrol, KISA(Korea Internet Security Agency), http://rootca.or.kr/kor/main.jsp
  7. FIDO Alliance, https://fidoalliance.org/specifications/?lang=ko
  8. W3C Working Draft "Decentralized Identifiers (DIDs) v1.0", 14 July 2020, https://www.w3.org/TR/did-core/
  9. Security Technology Research Team, "Overseas Research Trends Related to Blockchain Interworking" FINANCIAL SECURITY INSTITUTE, Korea
  10. FINANCIAL SECURITY INSTITUTE, "Electronic Finance and Financial Security No. 22", Periodicals, FINANCIAL SECURITY INSTITUTE, Korea, pp97-110