- From: yslee <yslee@pentasecurity.com>
- Date: Fri, 09 Aug 2013 17:17:05 +0900
- To: Wonsuk Lee <wonsuk73@gmail.com>
- CC: public-html-ig-ko@w3.org
¾È³çÇϼ¼¿ä. Áö³ ¹ø Çà»ç¶§ óÀ½ ¸¸³ª¼ µÇÁöµµ ¾Ê´Â ÀÌ·± Àú·± Áú¹®µéÀ» Çß¾ú´Âµ¥.. Ȥ ½Ã ±â¾ïÇÏ½Ç Áö ¸ð¸£°Ú½À´Ï´Ù. À̹ø ±³À° ¶§ session I, II °¡ ÁøÇàµÇÁö ¾Ê¾Æ ¸Å¿ì ¾Æ½¬¿ü½À´Ï´Ù. Àú´Â º¸¾È °ü·Ã ¾÷ü¿¡¼ °³¹ßÀ» ÇÏ°í Àִµ¥¿ä. À¥¿¡ ´ëÇÑ ÀÌÇØ°¡ ª¾Æ¼ Áú¹®ÀÌ ÀÌ»óÇÏ´õ¶óµµ »ì¦ ÀÌÇØÇØ ÁÖ½Ã±æ ºÎŹµå¸³´Ï´Ù. HTML 5¿¡ º¸¸é CryptoAPI °¡ Á¦°øµÇ´Âµ¥¿ä. Á¦°¡ ±Ã±ÝÇÑ °ÍÀº ³¼ö ºÎºÐÀÔ´Ï´Ù. ³¼ö´Â º¸Åë Block cipher¿¡¼ key¸¦ ¸¸µé°Å³ª, °ø°³Å° ƯÈ÷ RSA¿¡¼ short message attackÀ» ¹æÁöÇϱâ À§ÇÑ de facto standardÀÎ RSA-OAEP(ÇöÀç´Â RSAES)¿¡¼ »ç¿ëµÇ±â ¶§¹®¿¡ Çʼö¶ó°í ÇÒ ¼ö ÀÖ½À´Ï´Ù. ¾Æ½Ã°ÚÁö¸¸, ³¼ö´Â entropy È®º¸¸¦ À§ÇÏ¿© ³¼ö¸¦ »ý¼ºÇÏ´Â seed(block cipherÀÇ ÇÑ Á¾·ùÀÎ SEED°¡ ¾Æ´Ï¶ó ³¼ö¸¦ »ý¼ºÇϱâ À§ÇÑ ¾¾¾Ñ °ªÀ» ¸»ÇÕ´Ï ´Ù.)°¡ ¸Å¿ì Áß¿äÇÕ´Ï´Ù. ÇöÀç ¿ì¸®³ª¶ó¿¡¼ ÀÎÁ¤Çϴ ǥÁØÀº ISO/IEC 18033-2:2006ÀÔ´Ï´Ù.(±âÁ¸¿¡´Â "FIPS PUB 186-2 Addendix 3¿¡ ¸í½ÃµÈ ³¼ö¹ß»ý±âÀÇ º¯Çü ¸ðµ¨ Áß SHA-1À» ÀÌ ¿ëÇÑ GÇÔ¼ö »ç¿ë ¸ðµ¨"À̾ú½À´Ï´Ù.) ±¹Á¤¿ø¿¡¼´Â ÃÖ¼Ò 256ÀÇ entropy¸¦ È®º¸Çϵµ·Ï ÇÏ°í Àִµ¥, À̸¦ À§Çؼ CPU Clock, PID, TID, memory address, mouse pointer À§Ä¡ µîÀÇ °ªµéÀ» °¡Á® ¿É´Ï´Ù. Á¦ Áú¹®ÀÇ ¿äÁö´Â HTML 5¿¡¼ Àú·± systemÀÇ °ªµéÀ» °¡Á®¿Ã ¼ö ÀÖ´À³Ä´Â °ÍÀÔ ´Ï´Ù. °¡Á®¿Ã ¼ö ¾ø´Ù¸é ¿ì¸®°¡ "³¼ö"¶ó°í ºÎ¸¦ ¼ö ÀÖ´Â °ÍµéÀ» »ý¼ºÇϱ⠾î·Æ±â ¶§¹®ÀÔ´Ï´Ù. ±âÁ¸¿¡ Javascript µîÀ¸·Î ¾ÏÈ£ ¾Ë°í¸®ÁòÀ» ±¸ÇöÇÏ°í ½Í¾îµµ ÇÒ ¼ö ¾ø¾ú´ø ÀÌ À¯°¡ ³¼ö¸¦ Á¦´ë·Î ¸¸µé ¼ö ¾ø¾î¼¿´½À´Ï´Ù. HTML 5¿¡¼ ÀÌ ¹®Á¦¸¦ ¾î¶»°Ô ÇØ°áÇÏ°í ÀÖ´ÂÁö ±Ã±ÝÇÕ´Ï´Ù. ¾Æ½Ã´Â ºÐµé ÀÖÀ¸½Ã¸é ´äº¯ ºÎŹµå¸±²²¿ä. °¨»çÇÕ´Ï´Ù. ³¡. --
Received on Friday, 9 August 2013 08:17:35 UTC