|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
¾Æ·¡
µÎ°¡Áö¸¦ ÀÌ¿ëÇÏ¿© ÀÎÁõÇÑ´Ù´Â ÀǹÌ
1. What you Know
: Password, PIN
2. What you have
: Key, Card, Token, Fingerprint, Vocal Pattern
|
|
|
|
- Single-Factor
ÀÎÁõ¹æ½ÄÀÇ ¹®Á¦Á¡ ÇØ°á
- ÀÎÁõµÇÁö ¾ÊÀº »ç¿ëÀÚ¿¡ ´ëÇÑ ¿Ïº®ÇÑ Á¢±Ù±ÝÁö
- »ç¿ëÀÚÀÇ ÆíÀǼº
- ÀÎÁõÀ» ÅëÇÑ Á¢¼Ó ÈÄ ÇàÀ§¿¡ ´ëÇÑ ºÎÀιæÁö
- »ç¿ëÀÚ °ü¸®ÀÇ ¿ëÀ̼º
|
|
¢Ã
Challenge/Response
Challenge/Response ¹æ½ÄÀ̶õ ¼¹ö¿¡¼ º¸³»¿Â ³¼ö¿Í Ŭ¶óÀ̾ðÆ®ÀÇ Á¤º¸¸¦
HashÇÑ
°ªÀ» ¼¹öÀÇ ±â´ë°ª°ú ºñ±³ÇØ ÀÎÁõÇÏ´Â ¹æ½Ä
Challenge : Á¢¼ÓÇÒ ¶§ ¸¶´Ù ¼¹ö¿¡¼ ¸Å¹ø »õ·Î¿î ³¼ö¸¦ »ý¼ºÇؼ Ŭ¶óÀ̾ðÆ®·Î
Àü¼Û
Response : ¼¹ö¿¡¼ ¹ÞÀº ³¼ö¸¦ ÀÌ¿ëÇÏ¿© ¸Å¹ø »õ·Î¿î ÀÀ´äÀ» ¼¹ö·Î Àü¼Û
¢Ã OTP (One Time Password)
One Time Password¶õ ¸» ±×´ë·Î ÇÑ ¹ø ¾²°í ¹ö¸®´Â ÀÏȸ¿ë Æнº¿öµåÀ̹ǷÎ
±âÁ¸ÀÇ
Æнº¿öµå°¡ ÇØÅ·µÇ¾îµµ »õ·Î »ý¼ºµÈ Æнº¿öµå¸¦ »ç¿ëÇϹǷΠ¾ÈÀü¼º º¸Àå
|
|
|
|
1.
Client´Â ÀÎÁõÀ» ¹Þ±â À§ÇØ ¼¹ö¿¡ Á¢¼ÓÇÑ´Ù.
2. ¼¹ö´Â RandomÇÏ°Ô ¹ß»ýµÈ ³¼ö¸¦ Client¿¡°Ô º¸³½´Ù. (Challenge)
3. Client´Â ¼¹öÀÇ Challenge¿Í ÀÚ½ÅÀÇ °³ÀÎ Á¤º¸¸¦ ƯÁ¤ÇÑ Mechanism(MD5
Hash)À»
ÀÌ¿ëÇÏ¿© ¼¹ö·Î µÇµ¹·ÁÁØ´Ù. (Response)
4. ¼¹ö´Â Client°¡ º¸³»¿Â Response¸¦ ¹Ì¸® °è»êÇØ ³õÀº ±â´ë°ª°ú ºñ±³ÇÏ¿©
»ç¿ëÀÚÀÇ
ÀÎÁõ ¿©ºÎ¸¦ °áÁ¤ÇÑ´Ù.
|
|
|
|
|
|