์ธ์ฆ์„œ์™€ ์ „์ž ์„œ๋ช…(๋””์ง€ํ„ธ ์„œ๋ช…) ๐Ÿ”’ ๐Ÿ”‘
Security

์ธ์ฆ์„œ์™€ ์ „์ž ์„œ๋ช…(๋””์ง€ํ„ธ ์„œ๋ช…) ๐Ÿ”’ ๐Ÿ”‘

1. ์ธ์ฆ์„œ ์ „๋‹ฌ ๊ณผ์ •

โ‘  ์ „์ž ์„œ๋ช…๋œ ์ธ์ฆ์„œ(์ธ์ฆ์„œ ์ •๋ณด๋ฅผ Hash ์•Œ๊ณ ๋ฆฌ์ฆ˜์œผ๋กœ ์•”ํ˜ธํ™” ํ›„ CA ๋น„๊ณต๊ฐœํ‚ค๋กœ ์•”ํ˜ธํ™”ํ•œ Signature๋ฅผ ํฌํ•จ)ํ•˜์—ฌ Server -> Client๋กœ ๋ณด๋‚ธ๋‹ค.

โ‘ก Client๋Š” ์ „์ž ์„œ๋ช…๋œ ์ธ์ฆ์„œ๋ฅผ ๋ฐ›๊ณ  ๋ธŒ๋ผ์šฐ์ €์—์„œ ๋ณด๊ด€์ค‘์ธ CA List์˜ ๊ณต๊ฐœํ‚ค๋กœ ๋ณตํ˜ธํ™”ํ•˜์—ฌ ํ•ด๋‹น ์ธ์ฆ์„œ๊ฐ€ CA๋กœ๋ถ€ํ„ฐ ๋ฐ›์€ ์ธ์ฆ์„œ์ž„์„ ์‹ ๋ขฐํ•œ๋‹ค.

โ‘ข Client๋Š” ์ „๋‹ฌ ๋ฐ›์€ ์ธ์ฆ์„œ๋ฅผ Hash ์•Œ๊ณ ๋ฆฌ์ฆ˜์œผ๋กœ ์•”ํ˜ธํ™”ํ•œ Signature๊ณผ Server๋กœ๋ถ€ํ„ฐ ์ „๋‹ฌ ๋ฐ›์€ Signature๋ฅผ ๋น„๊ตํ•˜์—ฌ ์ธ์ฆ์„œ์˜ ๋ฌด๊ฒฐ์„ฑ์„ ๊ฒ€์ฆํ•œ๋‹ค.

 

2. ์ธ์ฆ์„œ ํ™•์ธ

www.naver.com ์ธ์ฆ์„œ

- ์„œ๋ช… ์•Œ๊ณ ๋ฆฌ์ฆ˜(Signature) : SHA-256(RSA ์•”ํ˜ธํ™”)

- ๊ณต๊ฐœํ‚ค ์•Œ๊ณ ๋ฆฌ์ฆ˜ : RSA ์•”ํ˜ธํ™”

 

3. ๋น„๋Œ€์นญํ‚ค ์•”ํ˜ธํ™”

๋น„๊ณต๊ฐœํ‚ค ์•”ํ˜ธํ™”๋ž€?

- ๊ณต๊ฐœํ‚ค/๋น„๊ณต๊ฐœํ‚ค ๋‘๊ฐœ์˜ ์Œ์ด ์ƒ๊น€

- ๋Œ€์นญํ‚ค์˜ ํ‚ค ๋ฐฐ๋‹ฌ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐ

- ๊ณต๊ฐœํ‚ค๋กœ ์•”ํ˜ธํ™”ํ•˜๊ณ  ๋น„๊ณต๊ฐœํ‚ค๋กœ ๋ณตํ˜ธํ™” ํ•  ๊ฒฝ์šฐ ๋ฐ์ดํ„ฐ๊ฐ€ ์ค‘์š”

- ๋น„๊ณต๊ฐœํ‚ค๋กœ ์•”ํ˜ธํ™”ํ•˜๊ณ  ๊ณต๊ฐœํ‚ค๋กœ ๋ณตํ˜ธํ™” ํ•  ๊ฒฝ์šฐ ์•”ํ˜ธํ™”ํ•œ ์ฃผ์ฒด๊ฐ€ ์ค‘์š”(์ „์ž์„œ๋ช…)

 

๋น„๊ณต๊ฐœํ‚ค ์•”ํ˜ธํ™” ์ข…๋ฅ˜

- RSA << ๊ถŒ์žฅ

- DSE(SEED)

- DH

- ECDH << ๊ถŒ์žฅ

 

https://ko.wikipedia.org/wiki/%EA%B3%B5%EA%B0%9C_%ED%82%A4_%EC%95%94%ED%98%B8_%EB%B0%A9%EC%8B%9D

 

๊ณต๊ฐœ ํ‚ค ์•”ํ˜ธ ๋ฐฉ์‹ - ์œ„ํ‚ค๋ฐฑ๊ณผ, ์šฐ๋ฆฌ ๋ชจ๋‘์˜ ๋ฐฑ๊ณผ์‚ฌ์ „

์œ„ํ‚ค๋ฐฑ๊ณผ, ์šฐ๋ฆฌ ๋ชจ๋‘์˜ ๋ฐฑ๊ณผ์‚ฌ์ „. ๊ณต๊ฐœ ํ‚ค ์•”ํ˜ธ ๋ฐฉ์‹(ๅ…ฌ้–‹ - ๆš—่™Ÿ ๆ–นๅผ, public-key cryptography)์€ ์•”ํ˜ธ ๋ฐฉ์‹์˜ ํ•œ ์ข…๋ฅ˜๋กœ ์‚ฌ์ „์— ๋น„๋ฐ€ ํ‚ค๋ฅผ ๋‚˜๋ˆ ๊ฐ€์ง€์ง€ ์•Š์€ ์‚ฌ์šฉ์ž๋“ค์ด ์•ˆ์ „ํ•˜๊ฒŒ ํ†ต์‹ ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•œ

ko.wikipedia.org

 

4. Hash ์•”ํ˜ธํ™”

Hash ์•Œ๊ณ ๋ฆฌ์ฆ˜์ด๋ž€?

- ๋‹จ๋ฐฉํ–ฅ ์•Œ๊ณ ๋ฆฌ์ฆ˜

- ์•”ํ˜ธ๋ฌธ ๊ธธ์ด๋ฅผ ๊ณ ์ •ํ•  ์ˆ˜ ์žˆ์Œ

- ํ‰๋ฌธ์ด ์กฐ๊ธˆ์ด๋ผ๋„ ๋‹ฌ๋ผ์ง€๋ฉด ์•”ํ˜ธ๋ฌธ์ด ๋ฐ”๋€Œ์–ด ํ‰๋ฌธ์˜ ๋ฌด๊ฒฐ์„ฑ์„ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉ

 

Hash ์•Œ๊ณ ๋ฆฌ์ฆ˜ ์ข…๋ฅ˜

- MD4/5

- SHA 0/1

- SHA 256/512 << ๊ถŒ์žฅ

 

https://ko.wikipedia.org/wiki/%EC%95%94%ED%98%B8%ED%99%94_%ED%95%B4%EC%8B%9C_%ED%95%A8%EC%88%98

 

์•”ํ˜ธํ™” ํ•ด์‹œ ํ•จ์ˆ˜ - ์œ„ํ‚ค๋ฐฑ๊ณผ, ์šฐ๋ฆฌ ๋ชจ๋‘์˜ ๋ฐฑ๊ณผ์‚ฌ์ „

์œ„ํ‚ค๋ฐฑ๊ณผ, ์šฐ๋ฆฌ ๋ชจ๋‘์˜ ๋ฐฑ๊ณผ์‚ฌ์ „. ์•”ํ˜ธํ™” ํ•ด์‹œ ํ•จ์ˆ˜(cryptographic hash function)์€ ํ•ด์‹œ ํ•จ์ˆ˜์˜ ์ผ์ข…์œผ๋กœ, ํ•ด์‹œ ๊ฐ’์œผ๋กœ๋ถ€ํ„ฐ ์›๋ž˜์˜ ์ž…๋ ฅ๊ฐ’๊ณผ์˜ ๊ด€๊ณ„๋ฅผ ์ฐพ๊ธฐ ์–ด๋ ค์šด ์„ฑ์งˆ์„ ๊ฐ€์ง€๋Š” ๊ฒฝ์šฐ๋ฅผ ์˜๋ฏธํ•œ๋‹ค. ์•”

ko.wikipedia.org