Il Kwon Sohn

dblp:225/0477 · DBLP profile ↗
← Back
3ranked-venue papers
0as first author
3since 2021 · last 2022
0000-0001-5321-2427ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 2 · 2 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2022 Design and Validation of Quantum Key Management System for Construction of KREONET Quantum Cryptography Communication
abstract
As it has been recently proven that the public key-based RSA algorithms that are currently used in encryption can be unlocked by Shor’s algorithm of quantum computers in a short time, conventional security systems are facing new threats, and accordingly, studies have been actively conducted on new security systems. They are classified into two typical methods: Post Quantum Cryptography (PQC) and Quantum Key Distribution (QKD). PQC aims to design conventional cryptography systems in a more robust way so that they will not be decrypted by a quantum computer in a short time whereas QKD aims to make data tapping and interception physically impossible by using quantum mechanical characteristics. In this paper, we design a quantum key management system, which is most crucial for constructing a QKD network and analyze the design requirements to apply them to Korea Research Environment Open NETwork (KREONET). The quantum key management system not only manages the lifecycle, such as storage, management, derivation, allocation, and deletion of the symmetric key generated in QKD but also enables many-to-many communication in QKD communication based on the key relay function and P2P communication to overcome the limitation of distance, which is a disadvantage of QKD. We have validated the designed quantum key management system through simulations to supplement the parts that were not considered during the initial design.
Kyu-Seok Shim, Il Kwon Sohn, Eunjoo Lee, Kwang-il Bae, Wonhyuk Lee
J. Web Eng.3
2022 Eavesdropping Detection in BB84 Quantum Key Distribution Protocols
abstract
The nature of quantum mechanics provides us with an opportunity to statistically detect eavesdropping in quantum key distribution (QKD) protocols, which is unimaginable in classical digital communications. By utilizing Hoeffding’s inequality, this study analyzes the upper bounds of the false-positive ratio (FPR) and false-negative ratio (FNR) of eavesdropping detection in the Bennett–Brassard-84 (BB84) QKD protocol, where eavesdropping is detected if the measured quantum bit error rate (QBER) is equal to or higher than a threshold. The analysis clarifies the trade-off between the accuracy of eavesdropping detection and the economy of quantum resources in the BB84 protocol. Owing to the central limit theorem, the QBER measured by 300 quantum bits (qubits) is sufficient to guarantee lower than 0.009% of the FPR and FNR of eavesdropping detection. To deal with rapidly varying quantum channel conditions, this study further introduces grouped BB84 protocol and combinatory eavesdropping detection algorithms. A polarization basis is changeable for a group of qubits, and eavesdropping is judged by a combination of criteria between QBER and group-QBER in the proposed protocol and algorithms. In our extensive simulation study, the grouped BB84 protocol with 300 qubits comparison guarantees at least 99.92% accuracy in eavesdropping detection under rapidly varying quantum channel conditions.
Chan-Kyun Lee, Il Kwon Sohn, Wonhyuk Lee
IEEE Trans. Netw. Serv. Manag.2
2021 Enhance the ICS Network Security Using the Whitelist-based Network Monitoring Through Protocol Analysis
abstract
In our present technological age, most manual and semi-automated tasks are being automated for efficient productivity or convenience. In particular, industrial sites are rapidly being automated to increase productivity and improve work efficiency. However, while networks are increasingly deployed as an integral part of the automation of industrial processes, there are also many resultant dangers such as security threats, malfunctions, and interruption of industrial processes. In particular, while the security of business networks is reinforced and their information is not easily accessible, intruders are now targeting industrial networks whose security is relatively poor, wherein attacks could directly lead to physical damage. Therefore, numerous studies have been conducted to counter security threats through network traffic monitoring, and to minimize physical loss through the detection of malfunctions. In the case of industrial processes, such as in nuclear facilities and petroleum facilities, thorough monitoring is required as security issues can lead to significant danger to humans and damage to property. Most network traffic in industrial facilities uses proprietary protocols for efficient data transmission, and these protocols are kept confidential because of intellectual property and security reasons. Protocol reverse engineering is a preparatory step to monitor network traffic and achieve more accurate traffic analysis. The field extraction method proposed in this study is a method for identifying the structure of proprietary protocols used in industrial sites. From the extracted fields, the structure of commands and protocols used in the industrial environment can be derived. To evaluate the feasibility of the proposed concept, an experiment was conducted using the Modbus/TCP protocol and Ethernet/IP protocol used in actual industrial sites, and an additional experiment was conducted to examine the results of the analysis of conventional protocols using the file transfer protocol.
Kyu-Seok Shim, Il Kwon Sohn, Eunjoo Lee, Woojin Seok, Wonhyuk Lee
J. Web Eng.2