Security management method and apparatus using hardware security module
The security management method employing a hardware security module addresses the challenge of data security by ensuring secure key management and encryption through identification code generation and interval encryption channel formation, effectively preventing military secret leakage and enhancing overall security.
Patent Information
- Application Number
- PCT/KR2023/018754
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-14
- Filing Date
- 2023-11-21
- Publication Date
- 2025-05-22
AI Technical Summary
The increasing importance of data security in online and Internet work environments necessitates dedicated hardware encryption equipment for safe storage, management, and high-speed encryption processing of encryption keys. Existing technologies face challenges in securely managing and protecting sensitive information, particularly in military contexts where leakage of military secrets is a concern.
A security management method utilizing a hardware security module that includes steps such as transmitting terminal identification information, activating wireless communication and authentication clients, generating identification codes, and forming an interval encryption channel based on secret information from the hardware security module. This method enhances security by ensuring only authorized access and communication.
The proposed method effectively prevents the leakage of military secrets and enhances security by ensuring that only authorized access and communication occur, leveraging the hardware security module's capabilities for secure key management and encryption processes.
Smart Images

Figure KR2023018754_22052025_PF_FP_ABST
Abstract
Description
Security management method and device using hardware security module
[0001] The present disclosure relates to a security management method and device using a hardware security module, and more specifically, to a security management method for applying a security policy based on whether a hardware security module is mounted or removed and an authentication result.
[0002] This patent was prepared with the support of the Information and Communication Technology Evaluation and Planning Institute with funding from the government (Ministry of National Defense).
[0003] Assignment ID: 1711193732
[0004] Assignment Number: 2022-0-00701
[0005] Ministry Name: Ministry of National Defense
[0006] Project Management (Professional) Agency Name: Information and Communications Technology Planning and Evaluation Institute
[0007] Research Project Name: Defense ICT Convergence (Informatization)
[0008] Research Project Name: Development of Security Technology for Linking the Defense Information and Communication Network and Commercial Network (5G)
[0009] Contribution rate: 1 / 1
[0010] Project implementation organization name: Electronics and Telecommunications Research Institute
[0011] Research period: April 1, 2022 - December 31, 2025
[0012] With the expansion of online and internet-based work environments, the importance of data security is growing. This has led to a growing need for dedicated hardware encryption equipment capable of securely storing, managing, and performing high-speed encryption processing of the encryption keys that protect data. Accordingly, hardware security modules (HSMs) are being utilized not only to manage and protect the private keys of servers, which are crucial for system operation, but also to reduce server load and enhance encryption or decryption performance when performing cryptographic tasks such as certificate issuance, electronic signatures, and signature verification.
[0013] Hardware security modules can securely store and safeguard confidential information, such as private keys. They also feature built-in processing and cryptographic processing units, enabling the generation and verification of electronic signature keys. Furthermore, security tokens, which incorporate built-in processing and processing units for encryption, decryption, and electronic signatures, can manage, generate, and store encryption keys. These hardware security modules are removable.
[0014] The present disclosure has been devised in response to the aforementioned background technology, and aims to provide a security management method using a hardware security module with enhanced security and to prevent leaks of military secrets.
[0015] The technical problems of the present disclosure are not limited to the technical problems mentioned above, and other technical problems not mentioned will be clearly understood by those skilled in the art from the description below.
[0016] According to one embodiment of the present disclosure for solving the above-described problem, a security management method performed by a terminal including at least one processor may include the steps of: when a mounting event of a designated hardware security module is detected, transmitting terminal identification information to the hardware security module; when approval of the terminal identification information is obtained from the hardware security module, activating a wireless communication function and an authentication client of the terminal; generating a first identification code based on user authentication information and the identification information of the terminal by executing the authentication client; inputting the first identification code into a predetermined hash function and transmitting the outputted second identification code to a server; when approval of the second identification code is obtained from the server, activating an interval encryption client; and forming an interval encryption channel with the server based on secret information obtained from the hardware security module using the interval encryption client.
[0017] According to one embodiment, the security management method of the present invention may include a step of performing authentication on the user authentication information by executing the authentication client.
[0018] The step of performing authentication for the above user authentication information may include a step of receiving user identification information and a password from the user using the authentication client, and a step of authenticating the user by determining whether the user identification information and the password match.
[0019] The above first identification code may be generated by any one of the multiple generation options.
[0020] The plurality of generation options may include a first option for generating the first identification code based on a combination of at least a portion of a bit string representing the user identification information and at least a portion of a bit string representing the terminal identification information, and a second option for generating the second identification code based on a combination of at least a portion of a bit string representing the user identification information, at least a portion of a bit string representing the terminal identification information, and at least a portion of a bit string representing the serial number of the hardware security module.
[0021] If the generation option for generating the above first identification code is changed, an indicator indicating the changed generation option among the plurality of generation options can be transmitted to the server.
[0022] The step of creating an interval encryption channel with the server according to a control signal transmitted from the interval encryption client may include a step of receiving key setting information derived from a pre-shared shared key from the server, a step of sharing the key setting information with the hardware security module, a step of transmitting a first message generated by using the key setting information by the hardware security module to the server, a step of receiving a second message generated from the server based on whether the first message can be decrypted, a step of obtaining a session key generated by decrypting the second message based on a key obtained from the hardware security module, and a step of creating an interval encryption channel using the session key.
[0023] The method may further include a step of disabling the wireless communication function and the section encryption client when the hardware encryption module removal event is detected, and a step of activating the wireless communication function and the section encryption client when the hardware encryption module mounting event is detected within a pre-specified time slot range.
[0024] According to one embodiment, when obtaining approval for the terminal identification information from the hardware security module, the method may include the steps of receiving at least one of a user's application execution command and an application installation command, checking whether the application is an application classified into a preset whitelist from metadata of the application related to at least one of the application execution command and the application installation command, and allowing at least one of installation and execution of the application if the application is an application classified into a preset whitelist.
[0025] If the hardware encryption module removal event is detected, the step of restricting installation and execution of the application, regardless of the type of the application, may be included.
[0026] When the above-mentioned section encryption channel is formed, data stored and transmitted / received by the execution of an application classified in the above-mentioned whitelist can be encrypted or decrypted by the above-mentioned hardware security module.
[0027] In one embodiment, when the terminal is rebooted, it can be determined whether an available hardware security module is mounted on the terminal.
[0028] In one embodiment, if the available hardware security module is not mounted on the terminal, the function of the terminal may be restricted until a mounting event of the available hardware security module is detected.
[0029] According to one embodiment, when the available hardware security module is mounted on the terminal, a user authentication process of the terminal may be initiated, and when the user authentication process is completed, use of at least some of the functions of the terminal may be permitted.
[0030] The technical solutions obtainable in the present disclosure are not limited to the solutions mentioned above, and other solutions not mentioned will be clearly understood by a person having ordinary skill in the art to which the present disclosure pertains from the description below.
[0031] The present disclosure, conceived in response to the aforementioned background technology, provides a security management method utilizing a hardware security module. This can prevent the leakage of military secrets and enhance security.
[0032] The effects that can be obtained from the present disclosure are not limited to the effects mentioned above, and other effects that are not mentioned will be clearly understood by a person having ordinary skill in the art to which the present disclosure pertains from the description below.
[0033] Various aspects are now described with reference to the drawings, wherein like reference numerals are used to refer to similar elements generally. In the following examples, for purposes of explanation, numerous specific details are set forth to provide a thorough understanding of one or more aspects. However, it will be apparent that such aspects may be practiced without these specific details. In other instances, well-known structures and devices are shown in block diagram form to facilitate the description of one or more aspects.
[0034] FIG. 1 illustrates an exemplary system for performing a security management method according to some embodiments of the present disclosure.
[0035] FIG. 2 is an exemplary diagram illustrating a hardware security module authentication operation according to some embodiments of the present disclosure.
[0036] FIG. 3 is a flowchart illustrating a security management method according to one embodiment of the present disclosure.
[0037] FIG. 4 is a flowchart illustrating an example of a security management method according to some embodiments of the present disclosure.
[0038] FIG. 5 is a flowchart illustrating a security management method according to one embodiment of the present disclosure.
[0039] Figure 6 is a flowchart exemplarily showing the process of performing step S560 shown in Figure 5.
[0040] FIG. 7 is a flowchart illustrating a user authentication step according to one embodiment of the present disclosure.
[0041] FIG. 8 is a flowchart for explaining the operation of a terminal according to an application execution or installation command according to one embodiment of the present disclosure.
[0042] The present invention is susceptible to various modifications and embodiments. Specific embodiments are illustrated in the drawings and described in detail in the detailed description. However, this is not intended to limit the present invention to specific embodiments, but rather to encompass all modifications, equivalents, and alternatives falling within the spirit and technical scope of the present invention. Throughout the description of each drawing, similar reference numerals have been used to designate similar components.
[0043] Terms such as first, second, A, and B may be used to describe various components, but these components should not be limited by these terms. These terms are used solely to distinguish one component from another. For example, without departing from the scope of the present invention, a first component may be referred to as a second component, and similarly, a second component may also be referred to as a first component. The term "and / or" includes a combination of multiple related items described herein or any of multiple related items described herein.
[0044] When a component is referred to as being "connected" or "connected" to another component, it should be understood that it may be directly connected or connected to that other component, but that there may be other components intervening. Conversely, when a component is referred to as being "directly connected" or "connected" to another component, it should be understood that there are no other components intervening.
[0045] The terminology used in this application is only used to describe specific embodiments and is not intended to limit the present invention. The singular expression includes the plural expression unless the context clearly indicates otherwise. In this application, it should be understood that the terms "comprise" or "have" indicate the presence of a feature, number, step, operation, component, part, or combination thereof described in the specification, but do not exclude in advance the possibility of the presence or addition of one or more other features, numbers, steps, operations, components, parts, or combinations thereof.
[0046] Unless otherwise defined, all terms used herein, including technical or scientific terms, have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. Terms defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant technology, and will not be interpreted in an idealized or overly formal sense unless explicitly defined herein.
[0047] The present disclosure relates to a security management method and device utilizing a hardware security module. Specifically, the present disclosure relates to a security management method that provides a secure environment by authenticating a terminal by installing a hardware security module, using a hardware security module that includes block ciphers, electronic signatures, key derivation, public key encryption, random number generation, message authentication, hash function provision, and key setting functions.
[0048] That is, the present disclosure relates to a security management method for creating a section encryption channel based on information matching a hardware security module, a terminal, and the user information of each terminal. Specifically, a database storing terminal identification information matched to the hardware security module and user information matched to each terminal can be utilized. Furthermore, the server and terminal of the present disclosure can share information agreed upon in advance regarding the identification code generation method.
[0049] During this authentication process, hardware security modules can perform tasks such as key generation, message authentication, and hash function provision. Authentication using hardware security modules can establish a section-encrypted channel, providing a secure communication environment with servers such as power grids and defense systems.
[0050] FIG. 1 illustrates an exemplary system for performing a security management method according to some embodiments of the present disclosure.
[0051] Referring to FIG. 1, a system for performing the security management method of the present disclosure may include a terminal (100), a hardware security module (200), a section encryption channel formation network (300), and a server (400). A terminal (100) equipped with a hardware security module (200) may be connected to a server (400) via the section encryption channel formation network (300).
[0052] The terminal (100) may refer to a device that proactively performs a security management method according to one embodiment of the present invention. The terminal (100) may refer to a portable communication device such as a smartphone. The terminal (100) may refer to communication equipment issued to individuals in military units.
[0053] Referring to FIG. 1, a terminal (100) may include an authentication client (110) and an interval encryption client (120). The authentication client (110) may refer to a client that is included in the terminal and generates a control signal to perform authentication based on a hardware encryption module (200). The interval encryption client (120) may refer to a client that controls an operation of forming an interval encryption channel based on the authentication result performed by the authentication client (110).
[0054] In one embodiment, the terminal (100) may refer to a commercially available smartphone. The terminal (100) may be a device having security software installed on a commercial smartphone.
[0055] A terminal (100) may refer to a personal communication device. The terminal (100) may be a communication device issued to an individual after being set up by an administrator of a military unit. The terminal (100) may include a personal computer (PC), a notebook, a mobile terminal, a smart phone, a tablet PC, and may include any type of terminal capable of connecting to a wired / wireless network.
[0056] A hardware security module (200) may refer to a dedicated device that generates and stores encryption keys. The hardware security module (200) may refer to a dedicated device that generates and stores relevant keys for various applications that require encryption keys. In particular, the internal information contained in the hardware security module (200) cannot be copied or recreated externally.
[0057] According to one embodiment, the hardware security module (200) can generate random numbers using an algorithm. The hardware security module (200) can provide a defense function against the following attacks for stealing encryption keys. The hardware security module (200) can use a dedicated OS and SW to prevent attacks using a network. The hardware security module (200) can provide a defense function against physical attacks. If the hardware security module (200) is attacked from the outside, it can be configured to automatically destroy the encryption key being stored.
[0058] A hardware security module (200) according to one embodiment of the present invention may be a device that has obtained KCMVP certification. KCMVP is a system that certifies the security of hardware security solutions that meet government security requirements, such as cryptographic module stability and implementation suitability. The hardware security module (200) may be a device that complies with the corresponding verification standards.
[0059] The hardware security module (200) can provide higher security than a security device that installs a cryptographic library within a conventional server and performs operations. Conventional technologies perform cryptographic functions based on algorithms received from a cryptographic library in an application program, and information and passwords can be passed as variables. Conventional technologies store such generated data and keys in a storage device (a hard disk within the server, an external dedicated storage device, or a storage device mounted on an external server), which can result in low security.
[0060] In one embodiment, the hardware security module (200) may provide an operation for generating or transmitting a message based on a provided encryption key. Furthermore, the hardware security module may provide an operation for extracting a session key based on a message generated by the server.
[0061] According to one embodiment, a hardware security module (200) may be mounted on a terminal (100). The terminal (100) may operate when the hardware security module (200) is mounted. Before the hardware security module (200) is mounted, the terminal (100) may have limited functionality.
[0062] According to one embodiment, a hardware security module (200) may be a quantum entropy-based hardware encryption module. Specifically, it may be a hardware encryption module that applies a quantum random number entropy generation method. This provides sufficient randomness compared to existing random number generation methods, thereby further enhancing security.
[0063] In one embodiment, the terminal (100) and hardware security module (200) may be paired and provided to the user. For example, a military unit administrator may provide the terminal (100) and hardware security module (200) as a set to the user. The administrator may receive a commercial smartphone, register the terminal identification information on the military network, and register the user who is authorized to use the terminal. The administrator may register the hardware security module for the authorized user and proceed with the authorization process. The authorization process may be a separate process that must be performed to enable the use of a specific hardware security module on the paired terminal. The administrator may need to separately install security software on the terminal. After all procedures, the administrator may perform a test and verification process to confirm whether the function is operational.
[0064] The section encryption channel forming network (300) may include wired Internet, wireless Internet, mobile communication network, satellite communication network, etc. including dedicated lines, etc. The section encryption channel forming network (300) may be a closed network such as a Local Area Network (LAN), a Wide Area Network (WAN), or an open network such as the Internet. The Internet refers to a global open computer network structure that provides various services existing in the TCP / IP protocol and its upper layer, namely Hyper Text Transfer Protocol (HTTP), Telnet, File Transfer Protocol (FTP), Domain Name System (DNS), Simple Mail Transfer Protocol (SMTP), Simple Network Management Protocol (SNMP), Network File Service (NFS), and Network Information Service (NIS).
[0065] In one embodiment, the segment encryption channel formation network (300) may be a 5G communication network. The segment encryption channel formation network (300) may vary depending on the security policy applied to the terminal (100).
[0066] According to one embodiment, the interval encryption channel formation network (300) may be a network in which an interval encryption channel is formed according to a security policy applied by a terminal (100) equipped with a hardware security module (200). The terminal (100) may communicate only through the interval encryption channel formation network (300) based on an interval encryption communication function according to the security policy.
[0067] The server (400) may be a service-related server authorized according to the security policy applied to the terminal (100). The server (400) may include a section encryption server (410), a service server (420), and a terminal management server (430). In FIG. 1, the server (400) is shown divided into a section encryption server (410), a service server (420), and a terminal management server (430) according to the functions performed. However, the section encryption server (410), the service server (420), and the terminal management server (430) may not be strictly separated physically or logically and may be implemented by a single device.
[0068] In one embodiment, the server (400) may be linked to the Defense Broadband Integrated Network. The server (400) may establish a communication channel between terminals owned by soldiers and maintain the security of the communication channel. However, the embodiment is not limited thereto. The server (400) may be linked to a private network used by a facility or organization requiring security, and may perform the function of maintaining the security of the communication channel between members of the facility or organization.
[0069] The terminal (100), the hardware security module (200), and the user information of the terminal (100) may be mapped and managed with respect to each other. For example, the terminal (100) and the hardware security module (200) may be mapped on a 1:1 basis. However, the embodiment is not limited thereto. As another example, there may be multiple hardware security modules (200) mapped to the terminal (100), or there may be multiple terminals (100) mapped to the hardware security module (200).
[0070] Terminal (100) and user information can be mapped on a 1:1 basis. However, in another example, multiple user information can be mapped to one terminal (100), and one user can be mapped to multiple terminals (100).
[0071] The server (400) may pre-store information about the identifier of the terminal (100) and the serial number of the hardware security module (200) mapped to the terminal (100). In addition, the server (400) may pre-store information about the identifier of the terminal (100) and the user's information (e.g., user ID and password) mapped to the terminal (100). The user identification information may be the user's military number.
[0072] The hardware security module (200) can obtain identification information of the terminal (100) to which it is mapped in advance before being distributed. The hardware security module (200) can store identification information of the terminal (100) to which it is mapped in advance.
[0073] The terminal (100) can obtain information about the user of the terminal (100) in advance from the server (400). The authentication client can manage and store information about at least one user authorized to use the terminal (100). The user information may include an ID and password. The user information may be the user's military number.
[0074] FIG. 2 is an exemplary diagram illustrating a hardware security module authentication operation according to some embodiments of the present disclosure.
[0075] Referring to FIG. 2, when a terminal (100) detects a mounting event of a hardware security module (200), it transmits terminal identification information to the hardware security module (200) to activate a wireless communication function and an authentication client (110). The wireless communication function of the terminal can be deactivated when the hardware security module (200) is detached. This reduces the possibility of security threats occurring when the hardware security module (200) is detached, thereby enhancing the security stability of the terminal.
[0076] Additionally, the wireless communication function of the terminal (200) may be activated within a limited range when a hardware security module (200) mounting event is detected. For example, when the authentication client (110) performs authentication, the wireless communication function of the terminal may be activated only to the extent necessary to transmit and receive messages required for authentication. After authentication is completed, the authentication client (110) may be fully activated. Different security policies may be applied to the authentication client (110) when it is partially activated and when it is fully activated. This may enhance security efficiency.
[0077] When a terminal (100) transmits terminal identification information to a hardware security module (200), the hardware security module (200) can compare the terminal identification information of the terminal (100) with pre-stored information. The terminal (100) can obtain approval for the terminal identification information from the hardware security module (200). The hardware security module (200) can be used in a manner that is matched to each terminal (100). The terminal (100) can obtain approval if the terminal identification information matches the identification information of the equipped hardware security module.
[0078] In one embodiment, if the hardware security module (200) deviates from the pre-approved mapping relationship, authentication may fail. If authentication fails, the authentication client (110) may not initiate additional authentication procedures. By not initiating additional authentication procedures based on the pre-approved mapping relationship, communication efficiency can be improved and security can be enhanced.
[0079] For example, the identification information of the terminal (100) may include an International Mobile Equipment Identity (IMEI).
[0080] According to one embodiment, the identification information of the terminal (100) may include a carrier code, manufacturing date, warranty information, serial number, etc.
[0081] According to one embodiment, the terminal (100) may have a physical structure capable of mounting an external device. For example, the terminal (100) may include a configuration such as a USB connector, a smart connector (such as a pogo pin), and a Lightning 8-pin.
[0082] The terminal (100) can obtain identification information (e.g., UUID, MAC, SERIAL) of the equipped hardware security module and identify the equipped hardware security module based on this.
[0083] In one embodiment, when the authentication client (110) is activated, the authentication client (110) may generate a pop-up message, such as an authentication window. Through this, the authentication client (110) can obtain user identification information and a password from the user. The user identification number may correspond to the user's military ID, but the embodiment is not limited thereto.
[0084] In one embodiment, the terminal (100) can be controlled based on authenticated user input by authenticating only the matched user. That is, the next authentication procedure can be performed only when the user identification information obtained through the user input matches the terminal (100).
[0085] In another embodiment, the terminal (100) may be configured for automatic login. Specifically, when automatic login is configured, the terminal (100) may be capable of user authentication by obtaining separately stored user identification information.
[0086] FIG. 3 is a flowchart illustrating a security management method according to one embodiment of the present disclosure.
[0087] In step (S310), the terminal (100) can detect a hardware security module removal / removal event.
[0088] When the hardware security module (100) detects a mounting event, the terminal (100) can execute the operation of step (S320). In step (S320), the terminal (100) can transmit terminal identification information to the hardware security module (200). When the terminal (100) transmits terminal identification information to the hardware security module (200), the hardware security module (200) can perform authentication by comparing it with pre-mapped terminal identification information.
[0089] According to one embodiment, when approval for terminal identification information is obtained from the hardware security module (200), a user authentication process may be executed in step (S330).
[0090] That is, FIG. 3 discloses an embodiment in which a user authentication process is executed after forming an interval encryption channel, and FIG. 4 may disclose an embodiment in which an interval encryption channel is formed after user authentication. In addition, various embodiments, such as an automatic login mode, may exist.
[0091] Referring to FIG. 3, when a user is authenticated in step (S330), a first identification code can be generated based on user authentication information and terminal identification information in step (S340). In step (S340), the terminal (100) can input the first identification code into a predetermined hash function and transmit the output second identification code to the server.
[0092] Specifically, in step (S340), a first identification code can be generated based on user authentication information and terminal identification information. For example, the first identification code can be generated using any one of multiple generation options. The terminal (100) and server (400) can share information regarding the generation options for the first identification code in advance.
[0093] According to one embodiment, the first option may be a method of generating the first identification code based on a combination of at least a portion of a bit string representing user identification information and at least a portion of a bit string representing identification information of the terminal.
[0094] The authentication client (110) can generate a first identification code by combining and listing a bit string of IMEI and a bit string representing a user ID in an order predetermined by the first option.
[0095] According to another embodiment, the second option may be a method of generating the first identification code based on a combination of at least a portion of a bit string representing user identification information, at least a portion of a bit string representing identification information of the terminal, and at least a portion of a bit string representing a serial number of the hardware security module.
[0096] That is, the authentication client (110) can generate a first identification code by combining terminal identification information and user identification information and performing a padding process. According to another embodiment, the authentication client (110) can generate a first identification code by combining terminal identification information, user identification information, and a hardware security module serial number and performing a padding process.
[0097] In one embodiment, the terminal (100) may input a first identification code into a predetermined hash function and transmit the resulting second identification code to the server. At this time, the terminal (100) may also transmit its own identification information (e.g., IMEI).
[0098] The server (400) knows the identification information (e.g., IMEI) of the terminal (100) in advance and can check the serial number of the hardware security module mapped to the terminal (100) and the identification information (e.g., user ID) of the user mapped to the terminal (100) in the DB.
[0099] The server (400) may generate a first identification code based on at least one of the generation option of the first identification code shared with the terminal (100), the identification information of the terminal (100) acquired in step SXXXX, the serial number of the hardware encryption module corresponding to the identification information of the terminal (100), and the user information corresponding to the identification information of the terminal (100). In addition, a hash function may be applied to the first identification code to generate a second identification code. The server (400) may compare the second identification code generated by itself with the second identification code acquired from the terminal (100). If the comparison results match, the server (400) may transmit approval for the second identification code to the authentication client (110).
[0100] Through this, even if the first identification code or user identification information is stolen, authentication can be performed stably.
[0101] When approval for the second identification code is completed in step (S350), the interval encryption client (120) may be activated. The authentication client (110) may request the interval encryption client (120) to form an interval encryption channel.
[0102] In step (S360), the interval encryption client (120) can form an interval encryption channel with the server based on secret information obtained from the hardware security module (200).
[0103] In another embodiment, when a removal event of the hardware security module (200) is detected in step (S310), the wireless communication function and the section encryption client may be disabled.
[0104] According to another embodiment, if the hardware security module (200) detected in step (S320) does not match the terminal (100), the function of the terminal (100) may be limited and a warning message may be sent to the terminal (100).
[0105] According to one embodiment, when a hardware encryption module (200) removal event is detected, the wireless communication function and the section encryption client of the terminal (100) can be disabled.
[0106] After this, if a hardware encryption module (200) mounting event is detected within a pre-designated time slot range, the wireless communication function and the section encryption client of the terminal (100) can be activated. That is, even if the hardware encryption module (200) is removed from the terminal (100), if it is re-mounted within a designated time range, the wireless communication function and the section encryption client can be maintained without a re-authentication procedure. This reduces the risk of communication being disconnected and having to restart the task when a task that must be performed quickly while maintaining security.
[0107] Even if user authentication fails in step (S330), the function of the terminal (100) may be limited and a warning message may be sent to the terminal (100). In step (S430), authentication may fail if the user identification information and the terminal identification information do not match or the user identification information and the password do not match.
[0108] Additionally, when the terminal is rebooted, it can be determined whether an available hardware security module is mounted on the terminal. If the available hardware security module is not mounted on the terminal, the terminal's functions can be restricted until an event of mounting the available hardware security module is detected.
[0109] Specifically, the terminal (100) runs a security management process in the background and waits in the background state. When a request is received, a new process can be created for the request. In other words, the security management process can continue to run in the background even when rebooting.
[0110] In another embodiment, if the available hardware security module is installed in the terminal, a user authentication process for the terminal may be initiated. Upon completion of the user authentication process, use of at least some of the terminal's functions may be permitted.
[0111] FIG. 4 is a flowchart illustrating an example of a security management method according to some embodiments of the present disclosure.
[0112] The security management methods disclosed in FIGS. 3 and 4 may differ in the order in which the user authentication process is performed.
[0113] In step (S410), the terminal (100) can detect a hardware security module removal / removal event.
[0114] When the hardware security module (100) detects a mounting event, the terminal (100) can execute the operation of step (S420). In step (S420), the terminal (100) can transmit terminal identification information to the hardware security module (200). When the terminal (100) transmits terminal identification information to the hardware security module (200), the hardware security module (200) can perform authentication by comparing it with pre-mapped terminal identification information.
[0115] In step (S430), the terminal (100) can generate a first identification code using terminal identification information and the serial number of the hardware security module (200).
[0116] According to another embodiment, if the automatic login mode is set and there is pre-registered user identification information, the first identification code can be generated according to the second option even in step (S430).
[0117] In step (S430), the terminal (100) can input the first identification code into a predetermined hash function and transmit the output second identification code to the server.
[0118] Upon obtaining approval for the second identification code from the server in step (S440), the interval encryption client (120) may be activated.
[0119] In step (S440), the interval encryption client (120) can share the key setting information derived based on the shared key with the hardware security module (200) and transmit the generated first message to the interval encryption server (410).
[0120] In step (S440), the interval encryption server (410) can decrypt the first message to generate the first message. The interval encryption client (120) can receive the second message. The interval encryption client (120) can decrypt the second message using the key obtained from the hardware security module. The interval encryption client (120) can decrypt the second message to obtain a session key to be used in interval encryption communication.
[0121] In step (S450), an interval encryption channel can be formed using the session key obtained in step (S440).
[0122] In step (S460), the authentication client (110) can authenticate the user by transmitting user identification information and a password to the terminal management server. If user authentication is successful, the terminal (100) can encrypt data during transmission.
[0123] In one embodiment, when user authentication is approved, data can be transmitted to a service server using the service app of the terminal (100). The service app may refer to an application classified as whitelisted.
[0124] In one embodiment, the service server may transmit data to the terminal (100). The transmitted and received data may be encrypted and decrypted based on a session key. That is, when a segment encryption channel is established, the stored and transmitted and received data resulting from the execution of an application classified in the whitelist may be encrypted or decrypted based on a session key extracted using the hardware security module (200).
[0125] If user authentication fails in step (S460), the terminal's functions may be limited and a warning message may be transmitted.
[0126] FIG. 5 is a flowchart illustrating a security management method according to one embodiment of the present disclosure.
[0127] Referring to FIG. 5, the security management method may include a step of transmitting terminal identification information to the hardware security module when a mounting event of a designated hardware security module (200) is detected (S510), a step of activating a wireless communication function and an authentication client (11) of the terminal when approval of the terminal identification information is obtained from the hardware security module (200) (S520), a step of generating a first identification code based on user authentication information and the terminal identification information by executing the authentication client (110) (S530), a step of inputting the first identification code into a predetermined hash function and transmitting the output second identification code to the server (S540), a step of activating an interval encryption client (120) when approval of the second identification code is obtained from the server (S550), and a step of forming an interval encryption channel with the server based on secret information obtained from the hardware security module using the interval encryption client (120) (S560).
[0128] In step (S510), when a mounting event of a designated hardware security module (200) is detected, the terminal (100) can transmit terminal identification information to the hardware security module (200).
[0129] According to one embodiment, since a hardware security module is matched to each terminal, the terminal (100) can transmit terminal identification information to the hardware security module (200) to confirm whether the equipped hardware security module (200) is a hardware security module (200) that matches the terminal (100).
[0130] In step (S520), the terminal (100) can obtain approval for terminal identification information from the hardware security module (200). If the hardware security module (200) and the terminal (100) are matched, the terminal (100) can activate the terminal's wireless communication function and authentication client.
[0131] In step (S530), the authentication client (110) can generate a first identification code based on user authentication information and terminal identification information.
[0132] In step (S530), the authentication client (110) can generate a first identification code based on one of multiple generation options.
[0133] In one embodiment, when a generation option for generating a first identification code is changed, the authentication client (110) may transmit to the server an indicator indicating the changed generation option among a plurality of generation options.
[0134] That is, if the generation option for generating the first identification code is changed, agreement between the server and the identification code generation option for the pre-stored generation option may be necessary.
[0135] In step (S540), a second identification code can be generated by inputting the first identification code generated in step (S530) into a predetermined hash function. The second identification code may be a value output by inputting the first identification code into a hash function.
[0136] Specifically, in step (S540), the terminal (100) can receive a hash function from the hardware security module (200) and output a second identification code.
[0137] In step (S550), the terminal (100) can obtain approval for the second identification code from the server. Upon approval for the second identification code, the interval encryption client (120) can be activated.
[0138] In step (S560), the interval encryption client (120) can form an interval encryption channel with the server based on the secret information obtained from the hardware security module (200). Specifically, the interval encryption client (120) can generate a message based on a shared key from the hardware security module (200). Through this, a session key required for transmitting and receiving interval encryption data can be derived using the hardware security module (200).
[0139] According to one embodiment, when a section encryption channel is formed in step (S560), the terminal (100) can automatically encrypt transmission data and communicate with the service app server without a separate encryption setting. For example, the terminal (100) can perform mutual authentication with the server (400) based on a shared key based on the EAP-PSK protocol (RFC4764). The terminal (100) and the server (400) each generate random values, and the terminal (100) can share the encrypted value with the server (400) using the encryption key of the hardware security module (200).
[0140] Figure 6 is a flowchart exemplarily showing the process of performing step S560 shown in Figure 5.
[0141] Referring to FIG. 6, step (S560) may include a step (S561) of receiving key setting information derived from a pre-shared shared key from a server, a step (S562) of sharing the key setting information with the hardware security module and transmitting a first message generated based on the key setting information by the hardware security module to the server, a step (S563) of receiving a second message generated based on whether the first message can be decrypted from the server, a step (S564) of obtaining a session key generated by decrypting the second message based on the key obtained from the hardware security module, and a step (S564) of creating an interval encryption channel using the session key.
[0142] According to one embodiment, in step (S561), the interval encryption client (120) may receive key setting information derived from a pre-shared shared key from the server. Specifically, the server and the interval encryption client may include mutually agreed-upon shared key information. More specifically, the interval encryption client (120) may receive the shared key from the hardware encryption module (200).
[0143] That is, in step (S561), the interval encryption client (120) can extract a shared key matching the first identification code from the hardware encryption module (200).
[0144] In step (S562), the interval encryption client (120) can share key setting information with the hardware security module (200). The hardware security module (200) can generate a first message based on the key setting information. The interval encryption client (120) can transmit the first message received from the hardware security module (200) to the server.
[0145] In step (S563), the interval encryption client (120) can receive a second message generated from the server based on whether the first message can be decrypted. Specifically, the first message can be decrypted based on a shared key. That is, the second message can be generated using the key generated by decrypting the first message.
[0146] In step (S563), the server can send a second message to the interval encryption client (120).
[0147] In step (S564), the interval encryption client (120) can obtain a session key generated by decrypting the second message based on the key obtained from the hardware security module (200).
[0148] In step (S565), the interval encryption client (120) can create an interval encryption channel using a session key.
[0149] FIG. 7 is a flowchart illustrating a user authentication step according to one embodiment of the present disclosure.
[0150] Referring to FIG. 7, a security management method according to one embodiment may perform user authentication when an authentication client (110) is activated.
[0151] Specifically, in step (S610), the authentication client (110) can obtain user identification information and a password through user input.
[0152] In step (S620), the authentication client (110) can authenticate the user by determining whether the user identification information and password match.
[0153] FIG. 8 is a flowchart for explaining the operation of a terminal according to an application execution or installation command according to one embodiment of the present disclosure.
[0154] Referring to FIG. 8, a security management method according to one embodiment may include a step of receiving at least one of a user's application execution command and an application installation command when obtaining approval for the terminal identification information from a hardware security module (200) (S810), a step of checking whether the application is an application classified into a preset whitelist from metadata of an application related to at least one of the application execution command and the application installation command (S820), and a step of allowing at least one of installation and execution of the application if the application is an application classified into a preset whitelist (S830).
[0155] In step (S810), the user can input a command for application execution and installation into the terminal (100).
[0156] In step (S820), the terminal (100) can check whether the application entered in step (S810) belongs to the whitelist classification by comparing it with the acquired whitelist.
[0157] In step (S830), if the application is included in the whitelist, the terminal (100) can allow the execution and installation of the application by encrypting or decrypting the data stored and transmitted and received by executing the application classified as whitelisted by the hardware security module.
[0158] According to one embodiment, when a hardware encryption module (200) removal event is detected, the terminal (100) may restrict the installation and execution of the application regardless of the type of the application.
[0159] The description of the disclosed embodiments is provided to enable any person skilled in the art to make or use the present disclosure. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other embodiments without departing from the scope of the present disclosure. Therefore, the present disclosure is not intended to be limited to the embodiments disclosed herein, but is to be construed in the broadest scope consistent with the principles and novel features disclosed herein.
Claims
1. A security management method performed by a terminal including at least one processor, A step of transmitting terminal identification information to the hardware security module when a mounting event of a designated hardware security module is detected; Upon obtaining approval for the terminal identification information from the hardware security module, a step of activating the wireless communication function and authentication client of the terminal; A step of generating a first identification code based on user authentication information and terminal identification information by executing the above authentication client; A step of inputting the first identification code into a predetermined hash function and transmitting the output second identification code to the server; Upon obtaining approval for the second identification code from the server, a step of activating the interval encryption client; and A security management method comprising a step of forming an interval encryption channel with the server based on secret information obtained from the hardware security module using the interval encryption client.
2. In paragraph 1, A step of performing authentication on the user authentication information by executing the above authentication client, The steps for performing authentication for the above user authentication information are: A step of receiving user identification information and password from the user using the above authentication client; Includes a step of authenticating a user by determining whether the above user identification information and password match, A security management method wherein the above first identification code is generated by any one of a plurality of generation options.
3. In paragraph 2, The above multiple creation options are: A first option for generating the first identification code based on a combination of at least a portion of a bit string representing the user identification information and at least a portion of a bit string representing the terminal identification information; A security management method comprising a second option for generating the first identification code based on a combination of at least a portion of a bit string representing the user identification information, at least a portion of a bit string representing the terminal identification information, and at least a portion of a bit string representing the serial number of the hardware security module.
4. In paragraph 3, A security management method further comprising the step of transmitting to the server an indicator indicating a changed generation option among the plurality of generation options when the generation option for generating the first identification code is changed.
5. In paragraph 4, The step of creating an interval encryption channel with the server according to a control signal transmitted from the above interval encryption client A step of receiving key setting information derived based on a pre-shared shared key from a server; A step of sharing key setting information with the hardware security module and transmitting a first message generated based on the key setting information by the hardware security module to a server; A step of receiving a second message generated based on whether the first message can be decrypted from the server; A step of obtaining a session key generated by decrypting a second message based on a key obtained from the above hardware security module; and A security management method comprising a step of creating an interval encryption channel using the above session key.
6. In paragraph 1, When the hardware encryption module removal event is detected, a step of disabling the wireless communication function and the section encryption client; and A security management method further comprising the step of activating the wireless communication function and the interval encryption client when the hardware encryption module mounting event is detected within a pre-designated time slot range.
7. In paragraph 2, Upon obtaining approval for the terminal identification information from the hardware security module, a step of receiving at least one of a user's application execution command and an application installation command; A step of determining whether the application is an application classified into a preset whitelist from metadata of the application related to at least one of the application execution command and the application installation command; A security management method further comprising a step of allowing at least one of installation and execution of the application, if the application is classified as an application in a preset whitelist.
8. In paragraph 7, A security management method comprising the step of restricting installation and execution of the application regardless of the type of the application when the hardware encryption module removal event is detected.
9. In paragraph 7, A security management method characterized in that when the above-mentioned section encryption channel is formed, the storage and transmission / reception data by the execution of the application classified into the above-mentioned whitelist is encrypted or decrypted by the above-mentioned hardware security module.
10. In paragraph 7, When the above terminal is rebooted, check whether an available hardware security module is mounted on the terminal, If the above available hardware security module is not mounted on the terminal, the function of the terminal is restricted until the mounting event of the above available hardware security module is detected. A security management method for initiating a user authentication process of the terminal when the available hardware security module is mounted on the terminal and allowing use of at least a portion of the functions of the terminal when the user authentication process is completed.
Citation Information
Patent Citations
User authentication method and system using software-based HSM without password exposure
KR101745919B1
Providing integrity verification and attestation in a hidden execution environment
KR1020120093439A
Blockchain-based multi-security authentication system and method between mobile terminals and IoT devices
KR102265788B1
Seawater evaporation device
KR102344981B1
Systems and methods for managing wireless communications by a vehicle
US20200029209A1