What is Hackers' Pub?

Hackers' Pub is a place for software engineers to share their knowledge and experience with each other. It's also an ActivityPub-enabled social network, so you can follow your favorite hackers in the fediverse and get their latest posts in your feed.

0
2

ๆดช ๆฐ‘ๆ†™ (Hong Minhee) shared the below article:

๋„์ปค๋กœ ๊ตฌ์ถ•ํ•œ ๋žฉ์—์„œ ํ˜ผ์ž ์‹ค์Šตํ•˜๋ฉฐ ๋ฐฐ์šฐ๋Š” ๋„คํŠธ์›Œํฌ ํ”„๋กœํ† ์ฝœ ์ž…๋ฌธ #5-1 TLS

์ž์†ํ‚ด @jasonkim@hackers.pub

L7 ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜

์ „์†ก ๊ณ„์ธต์€ ์ „์†ก ์ œ์–ด๋ฅผ ํ•˜๊ณ  ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜๋ณ„๋กœ ํŒจํ‚ท์„ ๋ถ„๋ฅ˜ํ•˜๋Š” ๊ฒƒ ๊นŒ์ง€๋งŒ ๋‹ด๋‹นํ•œ๋‹ค. ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๊ณ„์ธต์€ ํŒจํ‚ท์„ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์œผ๋กœ ์ฒ˜๋ฆฌํ•˜๊ณ  ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜๊ณผ ์‚ฌ์šฉ์ž๋ฅผ ์—ฐ๊ฒฐํ•˜๋Š” ๊ณ„์ธต์ด๋‹ค.

OSI 7๊ณ„์ธต์˜ L5, L6์„ ๋‹ค๋ฃจ์ง€ ์•Š๋Š” ์ด์œ 

OSI 7๊ณ„์ธต ๋ชจ๋ธ์—์„œ๋Š” ์„ธ์…˜ ๊ณ„์ธต(L5)๊ณผ ํ”„๋ ˆ์  ํ…Œ์ด์…˜ ๊ณ„์ธต(L6)์ด ๋ณ„๋„๋กœ ์ •์˜๋˜์–ด ์žˆ๋‹ค. ์„ธ์…˜ ๊ณ„์ธต์€ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๊ฐ„์˜ ์„ธ์…˜(์—ฐ๊ฒฐ) ์„ค์ •, ๊ด€๋ฆฌ, ์ข…๋ฃŒ๋ฅผ ๋‹ด๋‹นํ•˜๊ณ , ํ”„๋ ˆ์  ํ…Œ์ด์…˜ ๊ณ„์ธต์€ ๋ฐ์ดํ„ฐ์˜ ํ˜•์‹ ๋ณ€ํ™˜, ์•”ํ˜ธํ™”, ์••์ถ•์„ ๋‹ด๋‹นํ•œ๋‹ค.

ํ•˜์ง€๋งŒ ํ˜„๋Œ€ ์ธํ„ฐ๋„ท์˜ ๊ทผ๊ฐ„์ธ TCP/IP ๋ชจ๋ธ์—์„œ๋Š” ์ด ๋‘ ๊ณ„์ธต์„ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๊ณ„์ธต๊ณผ ๋ถ„๋ฆฌํ•˜์ง€ ์•Š๋Š”๋‹ค. TCP/IP ๋ชจ๋ธ์€ OSI์˜ L5~L7์„ ํ•˜๋‚˜์˜ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๊ณ„์ธต์œผ๋กœ ํ†ตํ•ฉํ•˜๋ฉฐ ์„ธ์…˜ ๊ด€๋ฆฌ๋‚˜ ๋ฐ์ดํ„ฐ ํ‘œํ˜„ ๋ฐฉ์‹์€ ๊ฐ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ํ”„๋กœํ† ์ฝœ์ด ์ž์ฒด์ ์œผ๋กœ ์ฒ˜๋ฆฌํ•œ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด TCP๋Š” ์ด๋ฏธ ์ „์†ก ๊ณ„์ธต์—์„œ ์—ฐ๊ฒฐ์˜ ์„ค์ •๊ณผ ํ•ด์ œ(3-way handshake, 4-way handshake)๋ฅผ ๊ด€๋ฆฌํ•˜๊ณ  TLS๋Š” ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ํ”„๋กœํ† ์ฝœ ์ˆ˜์ค€์—์„œ ์•”ํ˜ธํ™”์™€ ๋ฐ์ดํ„ฐ ๋ฌด๊ฒฐ์„ฑ์„ ์ฒ˜๋ฆฌํ•œ๋‹ค.

์‹ค์ œ๋กœ RFC 3439์—๋Š” "Layering considered harmful"์ด๋ผ๋Š” ์„น์…˜์ด ์žˆ์„ ์ •๋„๋กœ ์—„๊ฒฉํ•œ ๊ณ„์ธต ๋ถ„๋ฆฌ๋ณด๋‹ค๋Š” ์‹ค์šฉ์ ์ธ ํ”„๋กœํ† ์ฝœ ์„ค๊ณ„๊ฐ€ ์ค‘์‹œ๋œ๋‹ค. ์ด๋Ÿฌํ•œ ์ด์œ ๋กœ ์ด ์ฑ…์—์„œ๋„ L5, L6์„ ๋ณ„๋„๋กœ ๋‹ค๋ฃจ์ง€ ์•Š๊ณ  ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ํ”„๋กœํ† ์ฝœ๋กœ ํ†ตํ•ฉํ•˜์—ฌ ์„ค๋ช…ํ•œ๋‹ค.

๋‹ค์–‘ํ•œ ํ”„๋กœํ† ์ฝœ

์ด ์ฑ…์—์„œ๋Š” HTTP, SSL/TLS, DNS, DHCP์— ๋Œ€ํ•ด์„œ ๋‹ค๋ฃฌ๋‹ค.

  • HTTP(Hypertext Transfer Protocol): ์›น ๋ธŒ๋ผ์šฐ์ €์™€ ์›น ์„œ๋ฒ„ ๊ฐ„์˜ ํ†ต์‹ ์„ ์œ„ํ•œ ํ”„๋กœํ† ์ฝœ์ด๋‹ค. ์š”์ฒญ-์‘๋‹ต ๋ฐฉ์‹์œผ๋กœ ๋™์ž‘ํ•˜๋ฉฐ, ์›น ํŽ˜์ด์ง€, ์ด๋ฏธ์ง€, API ๋ฐ์ดํ„ฐ ๋“ฑ ๋‹ค์–‘ํ•œ ๋ฆฌ์†Œ์Šค๋ฅผ ์ „์†กํ•œ๋‹ค.

  • SSL/TLS(Secure Sockets Layer/Transport Layer Security): ๋„คํŠธ์›Œํฌ ํ†ต์‹ ์„ ์•”ํ˜ธํ™”ํ•˜์—ฌ ๋ณด์•ˆ์„ ์ œ๊ณตํ•˜๋Š” ํ”„๋กœํ† ์ฝœ์ด๋‹ค. HTTPS๋Š” HTTP์— TLS๋ฅผ ๊ฒฐํ•ฉํ•œ ๊ฒƒ์œผ๋กœ ์›น์—์„œ ๊ฐ€์žฅ ๋„๋ฆฌ ์‚ฌ์šฉ๋˜๋Š” ๋ณด์•ˆ ํ†ต์‹  ๋ฐฉ์‹์ด๋‹ค.

  • DNS(Domain Name System): ๋„๋ฉ”์ธ ์ด๋ฆ„(์˜ˆ: www.example.com)์„ IP ์ฃผ์†Œ๋กœ ๋ณ€ํ™˜ํ•˜๋Š” ์‹œ์Šคํ…œ์ด๋‹ค. ์‚ฌ์šฉ์ž๊ฐ€ ๊ธฐ์–ตํ•˜๊ธฐ ์‰ฌ์šด ๋„๋ฉ”์ธ ์ด๋ฆ„์„ ์‚ฌ์šฉํ•˜์—ฌ ์›น์‚ฌ์ดํŠธ์— ์ ‘์†ํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ด์ค€๋‹ค.

  • DHCP(Dynamic Host Configuration Protocol): ๋„คํŠธ์›Œํฌ์— ์—ฐ๊ฒฐ๋œ ์žฅ์น˜์—๊ฒŒ IP ์ฃผ์†Œ, ์„œ๋ธŒ๋„ท ๋งˆ์Šคํฌ, ๊ธฐ๋ณธ ๊ฒŒ์ดํŠธ์›จ์ด, DNS ์„œ๋ฒ„ ๋“ฑ์˜ ๋„คํŠธ์›Œํฌ ์„ค์ •์„ ์ž๋™์œผ๋กœ ํ• ๋‹นํ•˜๋Š” ํ”„๋กœํ† ์ฝœ์ด๋‹ค.

HTTP๋Š” ๋”ฐ๋กœ ์ •๋ฆฌํ•˜์ง€ ์•Š์„ ๊ฒƒ์ด๊ณ , TLS, DNS, DHCP์— ๋Œ€ํ•ด์„œ๋งŒ ์ •๋ฆฌ ํ•  ๊ฒƒ์ด๋‹ค.

TLS

TLS(SSL)์€ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ์•”ํ˜ธํ™”ํ•˜๋Š” ํ”„๋กœํ† ์ฝœ์ด๋‹ค.

SSL์—์„œ TLS๋กœ์˜ ์ „ํ™˜

SSL์€ 1995๋…„ Netscape๊ฐ€ ์›น ํ†ต์‹  ๋ณด์•ˆ์„ ์œ„ํ•ด ๊ฐœ๋ฐœํ•œ ํ”„๋กœํ† ์ฝœ์ด๋‹ค. SSL 2.0์ด ์ตœ์ดˆ๋กœ ๊ณต๊ฐœ๋˜์—ˆ์ง€๋งŒ ์‹ฌ๊ฐํ•œ ๋ณด์•ˆ ์ทจ์•ฝ์ ์ด ๋ฐœ๊ฒฌ๋˜์–ด 1996๋…„ SSL 3.0์œผ๋กœ ๋Œ€์ฒด๋˜์—ˆ๋‹ค. ์ดํ›„ IETF(Internet Engineering Task Force)๊ฐ€ SSL์„ ํ‘œ์ค€ํ™”ํ•˜๋Š” ๊ณผ์ •์—์„œ ํ”„๋กœํ† ์ฝœ ์ด๋ฆ„์ด TLS(Transport Layer Security)๋กœ ๋ณ€๊ฒฝ๋˜์—ˆ๋‹ค. 1999๋…„ TLS 1.0์ด RFC 2246์œผ๋กœ ๋ฐœํ‘œ๋˜์—ˆ๋Š”๋ฐ ์ด๋Š” SSL 3.0์„ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•˜๋˜ ์ƒํ˜ธ ์šด์šฉ์„ฑ์ด ์—†์„ ์ •๋„๋กœ ์ถฉ๋ถ„ํ•œ ์ฐจ์ด๊ฐ€ ์žˆ์—ˆ๋‹ค.

SSL 3.0์€ 2014๋…„ POODLE(Padding Oracle On Downgraded Legacy Encryption) ๊ณต๊ฒฉ ์ทจ์•ฝ์ ์ด ๋ฐœ๊ฒฌ๋œ ํ›„ 2015๋…„ ๊ณต์‹์ ์œผ๋กœ ํ๊ธฐ๋˜์—ˆ๋‹ค. TLS 1.0๊ณผ 1.1๋„ 2020๋…„ ์ฃผ์š” ๋ธŒ๋ผ์šฐ์ €๋“ค์— ์˜ํ•ด ์ง€์›์ด ์ค‘๋‹จ๋˜์—ˆ๊ณ  2021๋…„ RFC 8996์„ ํ†ตํ•ด ๊ณต์‹ ํ๊ธฐ๋˜์—ˆ๋‹ค.

ํ˜„์žฌ๋Š” TLS 1.2(2008๋…„ ์ถœ์‹œ)์™€ TLS 1.3(2018๋…„ ์ถœ์‹œ)์ด ์‚ฌ์šฉ๋˜๋ฉฐ TLS 1.3์ด ๊ถŒ์žฅ๋œ๋‹ค.

์ฑ…์—์„œ๋Š” TLS 1.2์™€ RSA๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ์„ค๋ช…ํ•˜๊ณ  ์žˆ์ง€๋งŒ ์ด ํฌ์ŠคํŒ…์—์„œ๋Š” TLS 1.3๊ณผ Ed25519, X25519๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ์ •๋ฆฌ ํ•  ๊ฒƒ์ด๋‹ค.

TLS๋กœ ๋ง‰์„ ์ˆ˜ ์žˆ๋Š” ์œ„ํ˜‘

TLS๋Š” ์Šคํ‘ธํ•‘, ๋ณ€์กฐ, ๋„์ฒญ์ด๋ผ๋Š” ์„ธ ๊ฐ€์ง€ ์ฃผ์š” ๋ณด์•ˆ ์œ„ํ˜‘์„ ๋ฐฉ์ง€ํ•œ๋‹ค.

์•”ํ˜ธํ™”๋กœ ๋„์ฒญ ๋ฐฉ์ง€

๋„์ฒญ์€ ํ†ต์‹  ๋‹น์‚ฌ์ž๊ฐ€ ์•„๋‹Œ ์ œ3์ž๊ฐ€ ๋„คํŠธ์›Œํฌ๋ฅผ ํ๋ฅด๋Š” ๋ฐ์ดํ„ฐ๋ฅผ ๋ชฐ๋ž˜ ๊ฐ€๋กœ์ฑ„ ์ฝ๋Š” ํ–‰์œ„์ด๋‹ค. ๊ณต๊ณต ์™€์ดํŒŒ์ด์—์„œ ๋กœ๊ทธ์ธ ์ •๋ณด๋ฅผ ํ›”์น˜๊ฑฐ๋‚˜ ๋„คํŠธ์›Œํฌ ํŒจํ‚ท์„ ์บก์ฒ˜ํ•˜์—ฌ ๋ฏผ๊ฐํ•œ ์ •๋ณด๋ฅผ ํƒˆ์ทจํ•˜๋Š” ๊ฒƒ์ด ๋Œ€ํ‘œ์ ์ธ ์˜ˆ๋‹ค.

์•”ํ˜ธํ™”๋Š” ์ •ํ•ด์ง„ ๊ทœ์น™(์•”ํ˜ธํ™” ์•Œ๊ณ ๋ฆฌ์ฆ˜)์— ๋”ฐ๋ผ ๋ฐ์ดํ„ฐ๋ฅผ ๋ณ€ํ™˜ํ•˜๋Š” ๊ธฐ์ˆ ์ด๋‹ค. TLS๋Š” ๋Œ€์นญํ‚ค ์•”ํ˜ธํ™”๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํ†ต์‹  ๋‚ด์šฉ์„ ์•”ํ˜ธ๋ฌธ์œผ๋กœ ๋ณ€ํ™˜ํ•œ๋‹ค. ๋„์ฒญ์ž๊ฐ€ ์•”ํ˜ธํ™”๋œ ํŒจํ‚ท์„ ๊ฐ€๋กœ์ฑ„๋”๋ผ๋„ ๋ณตํ˜ธํ™” ํ‚ค ์—†์ด๋Š” ์›๋ณธ ๋ฐ์ดํ„ฐ๋ฅผ ์•Œ ์ˆ˜ ์—†๋‹ค.

ํ•ด์‹ฑ์œผ๋กœ ๋ณ€์กฐ ๋ฐฉ์ง€

๋ณ€์กฐ(Tampering)๋Š” ํ†ต์‹  ์ค‘์ธ ๋ฐ์ดํ„ฐ๋ฅผ ์ œ3์ž๊ฐ€ ์ค‘๊ฐ„์—์„œ ๊ฐ€๋กœ์ฑ„์–ด ๋‚ด์šฉ์„ ๋ฐ”๊พธ๋Š” ํ–‰์œ„์ด๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด ์€ํ–‰ ์†ก๊ธˆ ์š”์ฒญ์—์„œ ์ˆ˜์‹ ์ž ๊ณ„์ขŒ๋ฒˆํ˜ธ๋‚˜ ๊ธˆ์•ก์„ ๋ณ€๊ฒฝํ•˜๋Š” ์ค‘๊ฐ„์ž ๊ณต๊ฒฉ(Man-in-the-Middle Attack)์ด ์žˆ๋‹ค.

ํ•ด์‹ฑ์€ ๋ถˆ๊ทœ์น™ํ•œ ๊ธธ์ด์˜ ๋ฐ์ดํ„ฐ์—์„œ ์ •ํ•ด์ง„ ๊ณ„์‚ฐ(ํ•ด์‹ฑ ์•Œ๊ณ ๋ฆฌ์ฆ˜)์— ๋”ฐ๋ผ ๊ณ ์ •๋œ ๊ธธ์ด์˜ ๋ฐ์ดํ„ฐ(ํ•ด์‹œ๊ฐ’)๋ฅผ ์ƒ์„ฑํ•˜๋Š” ๊ธฐ์ˆ ์ด๋‹ค. TLS๋Š” ๋ฉ”์‹œ์ง€ ์ธ์ฆ ์ฝ”๋“œ(MAC)๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๊ฐ ๋ฉ”์‹œ์ง€์— ํ•ด์‹œ ๊ธฐ๋ฐ˜ ํƒœ๊ทธ๋ฅผ ๋ถ™์ธ๋‹ค. ์ˆ˜์‹ ์ž๋Š” ๋ฐ›์€ ๋ฐ์ดํ„ฐ๋กœ ๋™์ผํ•œ ํ•ด์‹œ๋ฅผ ๊ณ„์‚ฐํ•˜๊ณ  ์†ก์‹ ์ž๊ฐ€ ๋ณด๋‚ธ MAC ํƒœ๊ทธ์™€ ๋น„๊ตํ•œ๋‹ค. ๋งŒ์•ฝ ๋ฐ์ดํ„ฐ๊ฐ€ ์กฐ๊ธˆ์ด๋ผ๋„ ๋ณ€๊ฒฝ๋˜์—ˆ๋‹ค๋ฉด ํ•ด์‹œ๊ฐ’์ด ์™„์ „ํžˆ ๋‹ฌ๋ผ์ง€๋ฏ€๋กœ ๋ณ€์กฐ๋ฅผ ์ฆ‰์‹œ ํƒ์ง€ํ•  ์ˆ˜ ์žˆ๋‹ค.

๋””์ง€ํ„ธ ์ธ์ฆ์„œ๋กœ ์Šคํ‘ธํ•‘ ๋ฐฉ์ง€

์Šคํ‘ธํ•‘(Spoofing)์€ ๊ณต๊ฒฉ์ž๊ฐ€ ๋‹ค๋ฅธ ์„œ๋ฒ„๋‚˜ ์‚ฌ์šฉ์ž๋กœ ์œ„์žฅํ•˜์—ฌ ํ†ต์‹  ์ƒ๋Œ€๋ฐฉ์„ ์†์ด๋Š” ํ–‰์œ„์ด๋‹ค. ๊ฐ€์งœ ์€ํ–‰ ์›น์‚ฌ์ดํŠธ๋ฅผ ๋งŒ๋“ค์–ด ์‚ฌ์šฉ์ž์˜ ๋กœ๊ทธ์ธ ์ •๋ณด๋ฅผ ํƒˆ์ทจํ•˜๋Š” ํ”ผ์‹ฑ ๊ณต๊ฒฉ์ด ๋Œ€ํ‘œ์ ์ด๋‹ค.

๋””์ง€ํ„ธ ์ธ์ฆ์„œ๋Š” ์ธํ„ฐ๋„ท์— ์žˆ๋Š” ๋‹ค๋ฅธ ๋‹จ๋ง์— "๋‚˜๋Š” ์ง„์งœ์ž…๋‹ˆ๋‹ค!"๋ผ๊ณ  ์ฆ๋ช…ํ•˜๋Š” ํŒŒ์ผ์ด๋‹ค. TLS๋Š” ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ์ธ์ฆ ๊ธฐ๊ด€(CA, Certificate Authority)์ด ๋ฐœ๊ธ‰ํ•œ ๋””์ง€ํ„ธ ์ธ์ฆ์„œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์„œ๋ฒ„์˜ ์‹ ์›์„ ๊ฒ€์ฆํ•œ๋‹ค. ํด๋ผ์ด์–ธํŠธ๋Š” ์„œ๋ฒ„๊ฐ€ ์ œ์‹œํ•œ ์ธ์ฆ์„œ๊ฐ€ ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” CA์— ์˜ํ•ด ์„œ๋ช…๋˜์—ˆ๋Š”์ง€ ์ธ์ฆ์„œ์˜ ๋„๋ฉ”์ธ์ด ์ ‘์†ํ•˜๋ ค๋Š” ๋„๋ฉ”์ธ๊ณผ ์ผ์น˜ํ•˜๋Š”์ง€ ํ™•์ธํ•œ๋‹ค. ์ด ๊ฒ€์ฆ์„ ํ†ตํ•ด ๊ฐ€์งœ ์„œ๋ฒ„์— ์—ฐ๊ฒฐ๋˜๋Š” ๊ฒƒ์„ ๋ฐฉ์ง€ํ•œ๋‹ค.

TLS๋ฅผ ์ง€ํƒฑํ•˜๋Š” ๊ธฐ์ˆ 

TLS๋Š” ์•”ํ˜ธํ™” ์•Œ๊ณ ๋ฆฌ์ฆ˜, ํ‚ค ๊ตํ™˜ ์•Œ๊ณ ๋ฆฌ์ฆ˜, ๋””์ง€์ปฌ ์„œ๋ช… ์•Œ๊ณ ๋ฆฌ์ฆ˜, ๋ฉ”์‹œ์ง€ ์ธ์ฆ ์•Œ๊ณ ๋ฆฌ์ฆ˜ 4๊ฐ€์ง€ ๊ธฐ์ˆ ์„ ์กฐํ•ฉํ•˜์—ฌ ์‚ฌ์šฉํ•œ๋‹ค.

์•”ํ˜ธํ™” ์•Œ๊ณ ๋ฆฌ์ฆ˜

์•”ํ˜ธํ™”๋Š” ํ‰๋ฌธ(์›๋ณธ ๋ฐ์ดํ„ฐ)์„ ์•”ํ˜ธ๋ฌธ(์ฝ์„ ์ˆ˜ ์—†๋Š” ํ˜•ํƒœ)์œผ๋กœ ๋ณ€ํ™˜ํ•˜๋Š” ๊ณผ์ •์ด๋ฉฐ ๋ณตํ˜ธํ™”๋Š” ์•”ํ˜ธ๋ฌธ์„ ๋‹ค์‹œ ํ‰๋ฌธ์œผ๋กœ ๋˜๋Œ๋ฆฌ๋Š” ๊ณผ์ •์ด๋‹ค. TLS์—์„œ ์‹ค์ œ ๋ฐ์ดํ„ฐ ์•”ํ˜ธํ™”์—๋Š” ๋Œ€์นญํ‚ค(๊ณตํ†ตํ‚ค) ์•”ํ˜ธํ™” ๋ฐฉ์‹์„ ์‚ฌ์šฉํ•œ๋‹ค.

๋Œ€์นญํ‚ค ์•”ํ˜ธํ™”๋Š” ์•”ํ˜ธํ™”์™€ ๋ณตํ˜ธํ™”์— ๋™์ผํ•œ ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๋ฐฉ์‹์ด๋‹ค. AES-GCM์ด๋‚˜ ChaCha20-Poly1305 ๊ฐ™์€ ์•Œ๊ณ ๋ฆฌ์ฆ˜์ด ๋Œ€ํ‘œ์ ์ด๋ฉฐ ์ฒ˜๋ฆฌ ์†๋„๊ฐ€ ๋นจ๋ผ ๋Œ€์šฉ๋Ÿ‰ ๋ฐ์ดํ„ฐ ์•”ํ˜ธํ™”์— ์ ํ•ฉํ•˜๋‹ค.

ํ•˜์ง€๋งŒ ๋Œ€์นญํ‚ค ์•”ํ˜ธํ™”์—๋Š” ๊ทผ๋ณธ์ ์ธ ๋ฌธ์ œ๊ฐ€ ์žˆ๋‹ค. ํ†ต์‹ ์„ ์‹œ์ž‘ํ•˜๊ธฐ ์ „์— ์–‘์ธก์ด ๋™์ผํ•œ ํ‚ค๋ฅผ ๊ฐ€์ง€๊ณ  ์žˆ์–ด์•ผ ํ•˜๋Š”๋ฐ ์ด ํ‚ค๋ฅผ ์–ด๋–ป๊ฒŒ ์•ˆ์ „ํ•˜๊ฒŒ ์ „๋‹ฌํ•  ๊ฒƒ์ธ๊ฐ€? ํ‚ค๋ฅผ ํ‰๋ฌธ์œผ๋กœ ๋„คํŠธ์›Œํฌ์— ์ „์†กํ•˜๋ฉด ๋„์ฒญ์ž์—๊ฒŒ ํƒˆ์ทจ๋‹นํ•  ์ˆ˜ ์žˆ๋‹ค. ํ‚ค๊ฐ€ ํƒˆ์ทจ๋˜๋ฉด ํ•ด๋‹น ํ‚ค๋กœ ์•”ํ˜ธํ™”๋œ ๋ชจ๋“  ํ†ต์‹  ๋‚ด์šฉ์ด ๋…ธ์ถœ๋œ๋‹ค. ์ด๊ฒƒ์ด ๋ฐ”๋กœ 'ํ‚ค ์ „๋‹ฌ ๋ฌธ์ œ'์ด๋ฉฐ ์ด๋ฅผ ํ•ด๊ฒฐํ•˜๊ธฐ ์œ„ํ•ด ํ‚ค ๊ตํ™˜ ์•Œ๊ณ ๋ฆฌ์ฆ˜์ด ํ•„์š”ํ•˜๋‹ค.

ํ‚ค ๊ตํ™˜ ์•Œ๊ณ ๋ฆฌ์ฆ˜

๊ณตํ†ตํ‚ค ์•”ํ˜ธ ๋ฐฉ์‹์„ ์‚ฌ์šฉํ•˜๋ฉด ํ‚ค ์ „๋‹ฌ์‹œ ๋ณด์•ˆ ๋ฌธ์ œ๋ฅผ ํ”ผํ•  ์ˆ˜ ์—†๋‹ค. ํ‚ค ๊ตํ™˜ ์•Œ๊ณ ๋ฆฌ์ฆ˜์€ ๋„์ฒญ์ž๊ฐ€ ์ง€์ผœ๋ณด๋Š” ๊ณต๊ฐœ ์ฑ„๋„์„ ํ†ตํ•ด์„œ๋„ ์–‘์ธก์ด ์•ˆ์ „ํ•˜๊ฒŒ ๊ณต์œ  ๋น„๋ฐ€(Shared Secret)์„ ์ƒ์„ฑํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ด์ฃผ๋Š” ๊ธฐ์ˆ ์ด๋‹ค.

RSA์˜ ๋ฌธ์ œ์ 

์ด์ „์—๋Š” RSA ํ‚ค ๊ตํ™˜์„ ์‚ฌ์šฉํ–ˆ๋‹ค. ํด๋ผ์ด์–ธํŠธ๊ฐ€ ๋ฌด์ž‘์œ„ ๋น„๋ฐ€๊ฐ’์„ ์ƒ์„ฑํ•˜๊ณ  ์„œ๋ฒ„์˜ RSA ๊ณต๊ฐœํ‚ค๋กœ ์•”ํ˜ธํ™”ํ•˜์—ฌ ์ „์†กํ•˜๋ฉด ์„œ๋ฒ„๊ฐ€ ์ž์‹ ์˜ ๊ฐœ์ธํ‚ค๋กœ ๋ณตํ˜ธํ™”ํ•˜๋Š” ๋ฐฉ์‹์ด๋‹ค. ํ•˜์ง€๋งŒ ์ด ๋ฐฉ์‹์—๋Š” ์‹ฌ๊ฐํ•œ ๋ฌธ์ œ๊ฐ€ ์žˆ๋‹ค.

๋งŒ์•ฝ ๊ณต๊ฒฉ์ž๊ฐ€ ์•”ํ˜ธํ™”๋œ ํ†ต์‹ ์„ ๋ชจ๋‘ ์ €์žฅํ•ด๋‘์—ˆ๋‹ค๊ฐ€, ๋‚˜์ค‘์— ์„œ๋ฒ„์˜ RSA ๊ฐœ์ธํ‚ค๊ฐ€ ์œ ์ถœ๋˜๋ฉด ๊ณผ๊ฑฐ์˜ ๋ชจ๋“  ํ†ต์‹ ์„ ๋ณตํ˜ธํ™”ํ•  ์ˆ˜ ์žˆ๋‹ค. ์ด๋ฅผ '์ „๋ฐฉ ๋น„๋ฐ€์„ฑ(Forward Secrecy)'์ด ์—†๋‹ค๊ณ  ํ•œ๋‹ค.

X25519๋กœ์˜ ์ „ํ™˜

TLS 1.3์—์„œ๋Š” RSA ํ‚ค ๊ตํ™˜์ด ์™„์ „ํžˆ ์ œ๊ฑฐ๋˜๊ณ , X25519(๋˜๋Š” ECDHE) ๊ฐ™์€ ์ž„์‹œ(Ephemeral) Diffie-Hellman ํ‚ค ๊ตํ™˜๋งŒ ์‚ฌ์šฉํ•œ๋‹ค. X25519๋Š” Curve25519 ํƒ€์› ๊ณก์„ ์„ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•œ ECDH(Elliptic Curve Diffie-Hellman) ํ‚ค ๊ตํ™˜ ํ•จ์ˆ˜๋กœ Daniel J. Bernstein์ด 2006๋…„์— ์„ค๊ณ„ํ–ˆ๋‹ค.

X25519์˜ ์žฅ์ ์€ ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค:

  • ์™„์ „ ์ˆœ๋ฐฉํ–ฅ ๋น„๋ฐ€์„ฑ(Perfect Forward Secrecy): ๋งค ์„ธ์…˜๋งˆ๋‹ค ์ƒˆ๋กœ์šด ์ž„์‹œ ํ‚ค ์Œ์„ ์ƒ์„ฑํ•˜๋ฏ€๋กœ ์„œ๋ฒ„์˜ ์ธ์ฆ์„œ ๊ฐœ์ธํ‚ค๊ฐ€ ์œ ์ถœ๋˜์–ด๋„ ๊ณผ๊ฑฐ ์„ธ์…˜์˜ ํ†ต์‹  ๋‚ด์šฉ์„ ๋ณตํ˜ธํ™”ํ•  ์ˆ˜ ์—†๋‹ค.
  • ๋†’์€ ์„ฑ๋Šฅ: 256๋น„ํŠธ ํ‚ค๋กœ 128๋น„ํŠธ ๋ณด์•ˆ ์ˆ˜์ค€์„ ์ œ๊ณตํ•˜๋ฉด์„œ๋„ ๊ธฐ์กด ์•Œ๊ณ ๋ฆฌ์ฆ˜๋ณด๋‹ค ํ›จ์”ฌ ๋น ๋ฅด๋‹ค.
  • ๊ตฌํ˜„ ์•ˆ์ „์„ฑ: ํƒ€์ด๋ฐ ๊ณต๊ฒฉ ๋“ฑ ๋ถ€์ฑ„๋„ ๊ณต๊ฒฉ์— ๊ฐ•ํ•˜๋„๋ก ์„ค๊ณ„๋˜์—ˆ๋‹ค.

X25519 ํ‚ค ๊ตํ™˜ ๋™์ž‘ ์›๋ฆฌ

  1. ํ‚ค ์Œ ์ƒ์„ฑ: ์˜ํฌ์™€ ์ฒ ์ˆ˜๋Š” ๊ฐ๊ฐ 32๋ฐ”์ดํŠธ์˜ ๋ฌด์ž‘์œ„ ๊ฐœ์ธํ‚ค(a, b)๋ฅผ ์ƒ์„ฑํ•œ๋‹ค.
  2. ๊ณต๊ฐœํ‚ค ๊ณ„์‚ฐ: ๊ฐ์ž ์ž์‹ ์˜ ๊ฐœ์ธํ‚ค์™€ ํƒ€์› ๊ณก์„ ์˜ ๊ธฐ์ค€์ (G)์„ ๊ณฑํ•˜์—ฌ ๊ณต๊ฐœํ‚ค๋ฅผ ๊ณ„์‚ฐํ•œ๋‹ค. ์˜ํฌ์˜ ๊ณต๊ฐœํ‚ค = a ร— G, ์ฒ ์ˆ˜์˜ ๊ณต๊ฐœํ‚ค = b ร— G
  3. ๊ณต๊ฐœํ‚ค ๊ตํ™˜: ์˜ํฌ์™€ ์ฒ ์ˆ˜๋Š” ์ž์‹ ์˜ ๊ณต๊ฐœํ‚ค๋ฅผ ์ƒ๋Œ€๋ฐฉ์—๊ฒŒ ์ „์†กํ•œ๋‹ค. ์ด ๊ณต๊ฐœํ‚ค๋Š” ๋„์ฒญ์ž๊ฐ€ ๋ณผ ์ˆ˜ ์žˆ์–ด๋„ ์•ˆ์ „ํ•˜๋‹ค.
  4. ๊ณต์œ  ๋น„๋ฐ€ ๊ณ„์‚ฐ: ์˜ํฌ๋Š” ์ž์‹ ์˜ ๊ฐœ์ธํ‚ค(a)์™€ ์ฒ ์ˆ˜์˜ ๊ณต๊ฐœํ‚ค(b ร— G)๋ฅผ ๊ณฑํ•˜์—ฌ ๊ณต์œ  ๋น„๋ฐ€์„ ๊ณ„์‚ฐํ•œ๋‹ค. ์ฒ ์ˆ˜๋Š” ์ž์‹ ์˜ ๊ฐœ์ธํ‚ค(b)์™€ ์˜ํฌ์˜ ๊ณต๊ฐœํ‚ค(a ร— G)๋ฅผ ๊ณฑํ•œ๋‹ค. ํƒ€์› ๊ณก์„ ์˜ ์ˆ˜ํ•™์  ํŠน์„ฑ์— ์˜ํ•ด a ร— (b ร— G) = b ร— (a ร— G)๊ฐ€ ์„ฑ๋ฆฝํ•˜๋ฏ€๋กœ, ์–‘์ธก์€ ๋™์ผํ•œ ๊ณต์œ  ๋น„๋ฐ€์„ ์–ป๋Š”๋‹ค.
  5. ์„ธ์…˜ ํ‚ค ์œ ๋„: ๊ณต์œ  ๋น„๋ฐ€์€ HKDF(HMAC-based Key Derivation Function)๋ฅผ ํ†ตํ•ด ์‹ค์ œ ์•”ํ˜ธํ™”์— ์‚ฌ์šฉํ•  ์„ธ์…˜ ํ‚ค๋กœ ๋ณ€ํ™˜๋œ๋‹ค.

๋„์ฒญ์ž๋Š” ๊ณต๊ฐœํ‚ค(a ร— G, b ร— G)๋งŒ ๋ณผ ์ˆ˜ ์žˆ๋Š”๋ฐ ์—ฌ๊ธฐ์„œ ๊ฐœ์ธํ‚ค(a, b)๋ฅผ ์•Œ์•„๋‚ด๋Š” ๊ฒƒ์€ ํƒ€์› ๊ณก์„  ์ด์‚ฐ ๋กœ๊ทธ ๋ฌธ์ œ(ECDLP)๋ฅผ ํ‘ธ๋Š” ๊ฒƒ์œผ๋กœ ํ˜„์žฌ ๊ธฐ์ˆ ๋กœ๋Š” ๊ณ„์‚ฐ์ ์œผ๋กœ ๋ถˆ๊ฐ€๋Šฅํ•˜๋‹ค.

๋””์ง€ํ„ธ ์„œ๋ช… ์•Œ๊ณ ๋ฆฌ์ฆ˜

์•ž์„œ ์–ธ๊ธ‰ํ–ˆ๋“ฏ์ด TLS๋Š” ๋””์ง€ํ„ธ ์ธ์ฆ์„œ์— ํฌํ•จ๋œ ๋””์ง€ํ„ธ ์„œ๋ช…์„ ํ†ตํ•ด ์ƒ๋Œ€๋ฐฉ์ด ์ œ3์ž๊ฐ€ ์‹ ๋ขฐ ํ•  ์ˆ˜์žˆ๋Š” ์ƒ๋Œ€์ธ์ง€ ์—ฌ๋ถ€๋ฅผ ํŒ๋‹จํ•œ๋‹ค.

RSA์—์„œ Ed25519๋กœ

์˜ˆ์ „์—๋Š” RSA๊ฐ€ ๋””์ง€ํ„ธ ์„œ๋ช…์— ๋„๋ฆฌ ์‚ฌ์šฉ๋˜์—ˆ์ง€๋งŒ ๋ช‡ ๊ฐ€์ง€ ํ•œ๊ณ„๊ฐ€ ์žˆ๋‹ค. ๋™๋“ฑํ•œ ๋ณด์•ˆ ์ˆ˜์ค€์„ ์œ„ํ•ด ํ›จ์”ฌ ํฐ ํ‚ค ํฌ๊ธฐ๊ฐ€ ํ•„์š”ํ•˜๊ณ (RSA 3072๋น„ํŠธ โ‰ˆ Ed25519 256๋น„ํŠธ) ์„œ๋ช… ์ƒ์„ฑ ์†๋„๊ฐ€ ์ƒ๋Œ€์ ์œผ๋กœ ๋А๋ฆฌ๋ฉฐ ๊ตฌํ˜„ ์‹œ ํŒจ๋”ฉ ์˜ค๋ผํด ๊ณต๊ฒฉ ๋“ฑ์— ์ทจ์•ฝํ•  ์ˆ˜ ์žˆ๋‹ค.

Ed25519๋Š” ์ด๋Ÿฌํ•œ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•œ ํ˜„๋Œ€์ ์ธ ๋””์ง€ํ„ธ ์„œ๋ช… ์•Œ๊ณ ๋ฆฌ์ฆ˜์ด๋‹ค. Edwards ๊ณก์„  ๊ธฐ๋ฐ˜์˜ EdDSA(Edwards-curve Digital Signature Algorithm) ๊ตฌํ˜„์ฒด๋กœ, Daniel J. Bernstein ํŒ€์ด ์„ค๊ณ„ํ–ˆ๋‹ค. 2023๋…„ FIPS 186-5์— ๊ณต์‹ ํฌํ•จ๋˜์–ด ๋ฏธ๊ตญ ์—ฐ๋ฐฉ ์ •๋ถ€ ์‹œ์Šคํ…œ์—์„œ๋„ ์Šน์ธ๋œ ์„œ๋ช… ์•Œ๊ณ ๋ฆฌ์ฆ˜์ด ๋˜์—ˆ๋‹ค.

Ed25519์˜ ํŠน์ง•

  • ์ž‘์€ ํ‚ค์™€ ์„œ๋ช… ํฌ๊ธฐ: ๊ณต๊ฐœํ‚ค 32๋ฐ”์ดํŠธ, ์„œ๋ช… 64๋ฐ”์ดํŠธ๋กœ ๋งค์šฐ ์ปดํŒฉํŠธํ•˜๋‹ค.
  • ๋น ๋ฅธ ์„ฑ๋Šฅ: ์„œ๋ช… ์ƒ์„ฑ์ด RSA๋ณด๋‹ค ์•ฝ 33๋ฐฐ ๋น ๋ฅด๋‹ค.
  • ๋†’์€ ๋ณด์•ˆ์„ฑ: 128๋น„ํŠธ ๋ณด์•ˆ ์ˆ˜์ค€์„ ์ œ๊ณตํ•˜๋ฉฐ, ๋ถ€์ฑ„๋„ ๊ณต๊ฒฉ์— ๊ฐ•ํ•˜๋„๋ก ์„ค๊ณ„๋˜์—ˆ๋‹ค.
  • ๊ฒฐ์ •์  ์„œ๋ช…: ๋‚œ์ˆ˜ ์ƒ์„ฑ๊ธฐ์— ์˜์กดํ•˜์ง€ ์•Š์•„ ๊ตฌํ˜„ ์˜ค๋ฅ˜๋กœ ์ธํ•œ ๊ฐœ์ธํ‚ค ๋…ธ์ถœ ์œ„ํ—˜์ด ์—†๋‹ค. (Sony PlayStation 3 ํŽŒ์›จ์–ด ์„œ๋ช…ํ‚ค ์œ ์ถœ ์‚ฌ๊ฑด์€ ECDSA์˜ ์ž˜๋ชป๋œ ๋‚œ์ˆ˜ ์‚ฌ์šฉ์œผ๋กœ ๋ฐœ์ƒํ–ˆ๋‹ค.)

๋””์ง€ํ„ธ ์„œ๋ช… ์ƒ์„ฑ๊ณผ ๊ฒ€์ฆ ๊ณผ์ •

์„œ๋ช… ์ƒ์„ฑ (์„œ๋ฒ„/๋ฐœ๊ธ‰์ž ์ธก):

  1. ์„œ๋ช…ํ•  ๋ฉ”์‹œ์ง€(์˜ˆ: ์ธ์ฆ์„œ ๋‚ด์šฉ)๋ฅผ ์ค€๋น„ํ•œ๋‹ค.
  2. ๊ฐœ์ธํ‚ค์™€ ๋ฉ”์‹œ์ง€๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํ•ด์‹œ๋ฅผ ๊ณ„์‚ฐํ•œ๋‹ค.
  3. ์ด ํ•ด์‹œ์™€ ๊ฐœ์ธํ‚ค๋ฅผ ํƒ€์› ๊ณก์„  ์—ฐ์‚ฐ์— ์‚ฌ์šฉํ•˜์—ฌ ์„œ๋ช…๊ฐ’(R, s)์„ ์ƒ์„ฑํ•œ๋‹ค.
  4. ์„œ๋ช…์„ ๋ฉ”์‹œ์ง€(์ธ์ฆ์„œ)์— ์ฒจ๋ถ€ํ•œ๋‹ค.

์„œ๋ช… ๊ฒ€์ฆ (ํด๋ผ์ด์–ธํŠธ ์ธก):

  1. ์„œ๋ฒ„๋กœ๋ถ€ํ„ฐ ์ธ์ฆ์„œ์™€ ์„œ๋ช…์„ ๋ฐ›๋Š”๋‹ค.
  2. ์ธ์ฆ์„œ์— ํฌํ•จ๋œ ๊ณต๊ฐœํ‚ค๋ฅผ ์ถ”์ถœํ•œ๋‹ค.
  3. ๊ณต๊ฐœํ‚ค, ๋ฉ”์‹œ์ง€, ์„œ๋ช…์„ ์‚ฌ์šฉํ•˜์—ฌ ํƒ€์› ๊ณก์„  ๋ฐฉ์ •์‹์„ ๊ฒ€์ฆํ•œ๋‹ค.
  4. ๋ฐฉ์ •์‹์ด ์„ฑ๋ฆฝํ•˜๋ฉด ์„œ๋ช…์ด ์œ ํšจํ•˜๊ณ , ์ธ์ฆ์„œ๊ฐ€ ํ•ด๋‹น ๊ฐœ์ธํ‚ค ์†Œ์œ ์ž์— ์˜ํ•ด ์„œ๋ช…๋˜์—ˆ์Œ์ด ์ฆ๋ช…๋œ๋‹ค.

ํ†ต์‹  ์ƒ๋Œ€๋ฐฉ ์ธ์ฆ:

  1. ํด๋ผ์ด์–ธํŠธ๊ฐ€ ์„œ๋ฒ„์— ์—ฐ๊ฒฐํ•˜๋ฉด ์„œ๋ฒ„๋Š” ์ž์‹ ์˜ ๋””์ง€ํ„ธ ์ธ์ฆ์„œ๋ฅผ ์ œ์‹œํ•œ๋‹ค.
  2. ์ธ์ฆ์„œ์—๋Š” ์„œ๋ฒ„์˜ ๊ณต๊ฐœํ‚ค์™€ CA(์ธ์ฆ ๊ธฐ๊ด€)์˜ ๋””์ง€ํ„ธ ์„œ๋ช…์ด ํฌํ•จ๋˜์–ด ์žˆ๋‹ค.
  3. ํด๋ผ์ด์–ธํŠธ๋Š” ์ด๋ฏธ ์‹ ๋ขฐํ•˜๊ณ  ์žˆ๋Š” CA์˜ ๊ณต๊ฐœํ‚ค๋กœ ์ธ์ฆ์„œ์˜ ์„œ๋ช…์„ ๊ฒ€์ฆํ•œ๋‹ค.
  4. ๊ฒ€์ฆ์ด ์„ฑ๊ณตํ•˜๋ฉด ์ธ์ฆ์„œ์— ์žˆ๋Š” ์„œ๋ฒ„ ๊ณต๊ฐœํ‚ค๊ฐ€ ์ง„์งœ ํ•ด๋‹น ์„œ๋ฒ„์˜ ๊ฒƒ์ž„์ด ๋ณด์žฅ๋œ๋‹ค.

๋ฉ”์‹œ์ง€ ์ธ์ฆ ์•Œ๊ณ ๋ฆฌ์ฆ˜

TLS์—์„œ ์•ž์„œ ์–ธ๊ธ‰ํ•œ ๋””์ง€ํ„ธ ์„œ๋ช… ์•Œ๊ณ ๋ฆฌ์ฆ˜์€ ํ†ต์‹  ์ƒ๋Œ€๋ฐฉ์„ ์ธ์ฆํ•˜๋Š” ๊ฒƒ์ผ ๋ฟ ์ดํ›„ ์ฃผ๊ณ ๋ฐ›๋Š” ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ฐ์ดํ„ฐ(๋ฉ”์‹œ์ง€)๋ฅผ ์ธ์ฆํ•˜๋Š” ๊ฒƒ์€ ์•„๋‹ˆ๋‹ค.

๋””์ง€ํ„ธ ์„œ๋ช…์€ ๋น„๋Œ€์นญํ‚ค ์•”ํ˜ธํ™”๋ฅผ ์‚ฌ์šฉํ•˜๋ฏ€๋กœ ์—ฐ์‚ฐ ๋น„์šฉ์ด ๋†’๋‹ค. ๋งค ๋ฉ”์‹œ์ง€๋งˆ๋‹ค ์„œ๋ช…์„ ์ƒ์„ฑํ•˜๊ณ  ๊ฒ€์ฆํ•˜๋Š” ๊ฒƒ์€ ์„ฑ๋Šฅ์ƒ ๋น„ํšจ์œจ์ ์ด๋‹ค. ๋”ฐ๋ผ์„œ TLS๋Š” ํ•ธ๋“œ์…ฐ์ดํฌ ๊ณผ์ •์—์„œ ํ•ฉ์˜ํ•œ ๋Œ€์นญํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜๋Š” MAC(Message Authentication Code)์œผ๋กœ ๊ฐ ๋ฉ”์‹œ์ง€์˜ ๋ฌด๊ฒฐ์„ฑ๊ณผ ์ธ์ฆ์„ ๋ณด์žฅํ•œ๋‹ค.

MAC์ด๋ž€?

MAC์€ ๋ฉ”์‹œ์ง€์™€ ๊ณต์œ  ๋น„๋ฐ€ํ‚ค๋ฅผ ์ž…๋ ฅ์œผ๋กœ ๋ฐ›์•„ ๊ณ ์ • ๊ธธ์ด์˜ ์ธ์ฆ ํƒœ๊ทธ๋ฅผ ์ƒ์„ฑํ•˜๋Š” ์•Œ๊ณ ๋ฆฌ์ฆ˜์ด๋‹ค. ๋‹จ์ˆœํ•œ ํ•ด์‹œ์™€ ๋‹ฌ๋ฆฌ, ๋น„๋ฐ€ํ‚ค๊ฐ€ ์—†์œผ๋ฉด ์˜ฌ๋ฐ”๋ฅธ MAC ํƒœ๊ทธ๋ฅผ ์ƒ์„ฑํ•  ์ˆ˜ ์—†๋‹ค. ๋”ฐ๋ผ์„œ MAC์€ ๋ฉ”์‹œ์ง€ ๋ฌด๊ฒฐ์„ฑ(๋ณ€์กฐ ์—ฌ๋ถ€)๊ณผ ๋ฉ”์‹œ์ง€ ์ธ์ฆ(๋ฐœ์‹ ์ž ํ™•์ธ)์„ ๋™์‹œ์— ์ œ๊ณตํ•œ๋‹ค.

TLS์—์„œ๋Š” ์ฃผ๋กœ HMAC(Hash-based MAC)์„ ์‚ฌ์šฉํ•œ๋‹ค. HMAC์€ SHA-256 ๊ฐ™์€ ํ•ด์‹œ ํ•จ์ˆ˜์™€ ๋น„๋ฐ€ํ‚ค๋ฅผ ๊ฒฐํ•ฉํ•˜์—ฌ MAC ํƒœ๊ทธ๋ฅผ ์ƒ์„ฑํ•œ๋‹ค. TLS 1.3์—์„œ๋Š” AEAD(Authenticated Encryption with Associated Data) ๋ชจ๋“œ์ธ AES-GCM์ด๋‚˜ ChaCha20-Poly1305๋ฅผ ์‚ฌ์šฉํ•˜๋Š”๋ฐ, ์ด๋“ค์€ ์•”ํ˜ธํ™”์™€ ๋ฉ”์‹œ์ง€ ์ธ์ฆ์„ ๋™์‹œ์— ์ˆ˜ํ–‰ํ•œ๋‹ค.

MAC์œผ๋กœ ๋ณ€์กฐ ๊ฒ€์ฆํ•˜๋Š” ๊ณผ์ •

  1. ์†ก์‹ ์ž: ์•”ํ˜ธํ™”๋œ ๋ฉ”์‹œ์ง€์™€ ๊ณต์œ  ๋น„๋ฐ€ํ‚ค๋ฅผ MAC ์•Œ๊ณ ๋ฆฌ์ฆ˜์— ์ž…๋ ฅํ•˜์—ฌ MAC ํƒœ๊ทธ๋ฅผ ์ƒ์„ฑํ•œ๋‹ค.
  2. ์ „์†ก: ์•”ํ˜ธํ™”๋œ ๋ฉ”์‹œ์ง€์™€ MAC ํƒœ๊ทธ๋ฅผ ํ•จ๊ป˜ ์ „์†กํ•œ๋‹ค.
  3. ์ˆ˜์‹ ์ž: ๋ฐ›์€ ๋ฉ”์‹œ์ง€์™€ ๋™์ผํ•œ ๊ณต์œ  ๋น„๋ฐ€ํ‚ค๋กœ MAC์„ ์ง์ ‘ ๊ณ„์‚ฐํ•œ๋‹ค.
  4. ๋น„๊ต: ๊ณ„์‚ฐํ•œ MAC๊ณผ ๋ฐ›์€ MAC ํƒœ๊ทธ๋ฅผ ๋น„๊ตํ•œ๋‹ค.
  5. ํŒ์ •: ๋‘ ๊ฐ’์ด ์ผ์น˜ํ•˜๋ฉด ๋ฉ”์‹œ์ง€๊ฐ€ ๋ณ€์กฐ๋˜์ง€ ์•Š์•˜์Œ์ด ๋ณด์žฅ๋œ๋‹ค. ์ผ์น˜ํ•˜์ง€ ์•Š์œผ๋ฉด ๋ฉ”์‹œ์ง€๊ฐ€ ์ „์†ก ์ค‘์— ๋ณ€์กฐ๋˜์—ˆ๊ฑฐ๋‚˜ ์˜ฌ๋ฐ”๋ฅธ ํ‚ค๋ฅผ ๊ฐ€์ง„ ๋ฐœ์‹ ์ž๊ฐ€ ๋ณด๋‚ธ ๊ฒƒ์ด ์•„๋‹ˆ๋ฏ€๋กœ ๋ฉ”์‹œ์ง€๋ฅผ ํ๊ธฐํ•œ๋‹ค.

์ด ๊ณผ์ •์—์„œ ๊ณต๊ฒฉ์ž๊ฐ€ ๋ฉ”์‹œ์ง€ ๋‚ด์šฉ์„ ์กฐ๊ธˆ์ด๋ผ๋„ ๋ฐ”๊พธ๋ฉด ํ•ด์‹œ๊ฐ’์ด ์™„์ „ํžˆ ๋‹ฌ๋ผ์ง€๋ฏ€๋กœ ์˜ฌ๋ฐ”๋ฅธ MAC ํƒœ๊ทธ๋ฅผ ์ƒ์„ฑํ•  ์ˆ˜ ์—†๋‹ค. ๋˜ํ•œ ๊ณต์œ  ๋น„๋ฐ€ํ‚ค ์—†์ด๋Š” ์œ„์กฐ๋œ ๋ฉ”์‹œ์ง€์— ๋Œ€ํ•œ ์œ ํšจํ•œ MAC์„ ๋งŒ๋“ค ์ˆ˜ ์—†์–ด ๋ฉ”์‹œ์ง€์˜ ์ถœ์ฒ˜๋„ ๊ฒ€์ฆ๋œ๋‹ค.

Read more โ†’
6

Here's the document release you were waiting for today!

The UNIX V4 tape!

archive.org/details/utah_unix_

Credits:

* Jay Lepreau for holding on to this tape
* Aleksander Maricq for finding it
* Jon Duerig for driving it to the Computer History Museum
* Thalia Archibald for doing a huge amount of research into the tape, its history, and file formats, and the upload
* Al Kossow for the tape-reading equipment and doing the actual read
* Len Shustek for the lab where the read was done and the software used to decode it

0
0
0
0

๊น€ ์ด๋ฆฌ, ํŽ˜์ด์ปค์™€ ๋Œ€๋‹ด..."๊ตญ๊ฐ€ยท์‚ฌํšŒ์— ์ข‹์€ ์—ญํ•  ํ•ด๋‹ฌ๋ผ" 2025.12.20. ์˜คํ›„ 5:32. ๊น€๋ฏผ์„ ๊ตญ๋ฌด์ด๋ฆฌ๊ฐ€ ํ”„๋กœ๊ฒŒ์ด๋จธ 'ํŽ˜์ด์ปค' ์ด์ƒํ˜ ์„ ์ˆ˜์™€ K-๊ฒŒ์ž„ ์‚ฐ์—…์˜ ๋ฐœ์ „ ๋ฐฉํ–ฅ ๋“ฑ์— ๋Œ€ํ•ด ์˜๊ฒฌ์„ ๋‚˜๋ˆด๋‹ค๊ณ  ๊ตญ๋ฌด์ด๋ฆฌ์‹ค์ด ๋ฐํ˜”์Šต๋‹ˆ๋‹ค. www.ytn.co.kr/_ln/0101_202...

๊น€ ์ด๋ฆฌ, ํŽ˜์ด์ปค์™€ ๋Œ€๋‹ด..."๊ตญ๊ฐ€ยท์‚ฌํšŒ์— ์ข‹์€ ์—ญํ•  ...

1
0
0

I don't think I'll stop using Firefox anytime soon.
Yes, their management are fucking idiots and it's annoying that I'll have to disable new AI features whenever they release them..

But the alternative is to use something Chromium-based, which would make Google's domination of web technology absolute - and Google is 100x more evil than Mozilla ever could be.

I hope this fucking bubble pops before Mozilla fucks up Firefox so badly that it becomes completely unusable

0
0
1
0
0
0

fluent-emojisใ‚‚twemojiใ‚‚ใฉใกใ‚‰ใ‚‚ๅŒใ˜ๅ‘ฝๅ่ฆๅ‰‡ใซๅค‰ๆ›ใ™ใ‚‹ใฎใง็ตฑไธ€็š„ใซๅ‚็…งใงใใ‚‹ใ‚ˆใ†ใซใชใฃใฆใ‚‹

1
0
2

่ฆ‹้€ƒใ—่ฆ–่ดๆœŸ้–“ใŒ้ŽใŽใŸใฎใงใ€12/2ใซ200ไบบ่ฟ‘ใ„ไบบใŒใ‚ชใƒณใƒฉใ‚คใƒณใงๅŠ็ฌ‘ใ„ใง่žใ„ใฆใ„ใŸใจใ„ใ†็งใฎRSJใ‚ปใƒŸใƒŠใƒผใฎใ‚นใƒฉใ‚คใƒ‰๏ผˆใ„ใ‚‰ใ™ใจใ‚„ใ•ใ‚“ใ‚ใ‚ŠใŒใจใ†๏ผ‰ใ‚’ๅ…ฌ้–‹ใ—ใพใ—ใŸใ€‚

ๅพŒใ‚ใฎใฟใชใ•ใพใซๅคšๅคงใชใ”่ฟทๆƒ‘ใ‚’ใŠใ‹ใ‘ใ—ใพใ—ใŸใ€‚

https://www.docswell.com/s/ryuichiueda/K37XMM-2025-12-02-rsj-seminar

1
0
0
1
0
0
0
0
2
0

ใ€BUILT-IN PRO ้›ปๅ™จๅฐˆ้–€ๅบ—็‰น็ด„ใ€‘้‡Ž็”Ÿๅ‹•็‰ฉๆ”ๅฝฑๅธซ Elio Della Ferrera ่ฟ‘ๆ—ฅๅœจๆ„ๅคงๅˆฉๅŒ—้ƒจ็š„ๆ–ฏ็‰น็ˆพ็ถญๅฅงๅœ‹ๅฎถๅ…ฌๅœ’๏ผˆStelvio National Park๏ผ‰ๅ…ง๏ผŒๆ„ๅค–็™ผ็พ่ฆๆจก้พๅคง็š„ๆ้พ่…ณๅฐๅŒ–็Ÿณ็พคใ€‚่ฉฒๅœฐ้ปž้„ฐ่ฟ‘2026ๅนด็ฑณ่˜ญโ€”็ง‘็ˆพ่’‚็ดๅ†ฌๅฅงๆœƒ่ณฝๅ€๏ผŒๅˆๆญฅ็ตฑ่จˆๅทฒ็™ผ็พๆ•ธไปฅๅƒ่จˆ็š„ๆ้พ่ถณ่ทก๏ผŒๅฐˆๅฎถไผฐ่จˆๅœจ็ด„3่‹ฑ้‡Œใ€ๅณ็ด„4.8ๅ…ฌ้‡Œ็ฏ„ๅœๅ…ง๏ผŒ่…ณๅฐๆ•ธ้‡ๆˆ–ๅคš้”2่ฌๅ€‹๏ผŒๆˆ็‚บๆ„ๅคงๅˆฉๆญทไพ†ไฟๅญ˜ๆœ€ๅฎŒๆ•ดใ€่ฆๆจกๆœ€ๅคง็š„ๆ้พ่ถณ่ทก็พคไน‹ไธ€ใ€‚

ๆœ‰้—œๅŒ–็Ÿณ็ถ“็ฑณ่˜ญ่‡ช็„ถๆญทๅฒๅš็‰ฉ้คจๅค็”Ÿ็‰ฉๅญธๅฎถ Cristiano Dal Sasso ้‘‘ๅฎš๏ผŒๅนดไปฃๅฏ่ฟฝๆบฏ่‡ณ็ด„2.1ๅ„„ๅนดๅ‰็š„ไธ‰็–Š็ด€ใ€‚่ถณ่ทก็›ธไฟกๅฑฌๆ–ผไธ€็จฎ้•ท้ ธใ€ๆค้ฃŸๆ€ง็š„้›™่ถณๆ้พ๏ผŒ้ซ”้•ทๅฏ้”10็ฑณใ€้ซ”้‡็ด„4ๅ™ธ๏ผŒๅ…ถๅฝขๆ…‹็‰นๅพต่ˆ‡ๆฟ้พ๏ผˆPlateosaurus๏ผ‰็›ธ่ฟ‘ใ€‚้ƒจๅˆ†่…ณๅฐ้—Šๅบฆ้”40ๅŽ˜็ฑณ๏ผŒ็ˆช็—•่ผชๅป“ๆธ…ๆ™ฐ๏ผŒไฟๅญ˜็‹€ๆณ่‰ฏๅฅฝใ€‚

May be an image of climbing, outdoors and text that says 'ๆ„ๅคงๅˆฉ่ฟ‘ ๆ„ๅคงๅˆฉ่ฟ‘ๅ†ฌๅฅง่ณฝๅ€ KN KCHD ็พๆ•ธๅƒๆ่ƒŒ่…ณๅฐ ๆˆ–ๅฑฌ2.1ๅ„„ๅนดๅ‰็พค้ซ”้ท่ƒฝ้บ่ทก BUILT-IN PRO SIEMENS F BOSCH LG Whirlpool SAMSUNG ritmass ่–่ช• ๅคงๆŠ˜ๆ—ฅ 12FI7ๆ—ฅ-2M8Iๆ—ฅ ๅ…จๅ ด้Žๅƒไปถ็”ขๅ“ ไฝŽ่‡ณ ไฝŽ่‡ณ1ๆŠ˜'
0
0
0
0
0
0
0
2
0

์ผ๋‹จ์€... ๋‚ด๋…„์— ์‚ด๊ฒŒ ๋  ๊ณณ์€ ์น˜๋ฐ” ๋ฐ ๋„์ฟ„๊ณ 
์—ฌํ–‰ ๊ฐ€๊ณ  ์‹ถ์€ ๊ณณ์€ ๋„์ฟ„ ์—ฌํ–‰์„ ์ œ์™ธํ•˜๋ฉด

2์›” - ์˜ค์‚ฌ์นด ๋ฐ ๊ตํ†  ๋ฐ ์‹œ๊ฐ€ํ˜„
3์›” - ๋Œ€๋งŒ ๋ฐ ํ™์ฝฉ ๋ฐ ๋ฒ ํŠธ๋‚จ(ํ˜ธ์น˜๋ฏผ)
5์›” - ์‹œ์ฆˆ์˜ค์นด ๋ฐ ํ›„์ง€์‚ฐ ๋ฐ ๋‚˜๊ณ ์•ผ
8์›” - ์„ผ๋‹ค์ด ๋ฐ ํ™‹์นด์ด๋„

ํ˜ธ์ฃผ๋Š”... ๊ฒฐ๋ก ์ ์œผ๋กœ ๋นผ๊ธฐ๋กœ
๊ฐ€์„์— ํ›„์ฟ ์˜ค์นด๋„ ๊ฐˆ๊นŒ...

2

I am pleased that I switched from to @Vivaldi but the one thing I canโ€™t quite understand is if Mozilla is building AI themselves, offering an open source alternative for developers, why on earth are they not building it into the browser?

I appreciate some people might say, they would be pushing their own models on users, but not if it was just an option. It might do something to steer the โ€œhateโ€ away since Mozilla AI seems to be based on open and diverse inclusion,

Perhaps their AI Window will feature this as an option, I just find it a bit odd.

I do use AI for work, but not beyond that, so serves me well.

0
2
1
1
0

์œผ ...... ์กฐ๋ช…์ด ์—ด์•…ํ•œ ๊ณณ์—์„œ๋„ 1/500์— ์กฐ๋ฆฌ๊ฐœ ๋” ๋‹ซ๊ณ  ์ฐ๊ณ ์‹ถ์€๋ฐ ๊ทธ๋ ‡๋‹ค๊ณ  M๋ชจ๋“œ ๊ฐ€๋ฉด ๊นŒ๋งŒ ์‚ฌ์ง„๋งŒ ์ฐํžํ…Œ๊ณ  ๊ทธ๋ ‡๋‹ค๊ณ  ์…”ํ„ฐ์Šคํ”ผ๋“œ๋ฅผ ์–‘๋ณดํ•˜๋ฉด ๊ณ ์–‘์ด๊ฐ€ ๋‹ค ํ๋ ค์ง€๋‹ˆ S๋ชจ๋“œ๋†“๊ณ  ์ฐ์œผ๋ฉด ์กฐ๋ฆฌ๊ฐœ๊ฐ€ ์•Œ์•„์„œ ๋นจ๋ผ์ ธ ์ดˆ์ ์ด ์กฐ๊ธˆ๋งŒ ํ‹€์–ด์ง€๋ฉด ๊ณ ์–‘์ด์— ์ดˆ์ ์ด ์ž˜ ์•ˆ ๋งž๊ฒŒ ๋œ๋‹ค. ...... ์•„๋‹ˆ ๊ฑฐ ์•„์ดํฐ์€ ์ด๋Ÿฐ๊ฑฐ ์ž˜ํ•˜๋“œ๋งŒ ์ด๋Ÿฌ๋‹ˆ๊นŒ ์นด๋ฉ”๋ผ๊ฐ€ ๋งํ•˜์ง€ ใ… _ใ… 

0
1

I don't think I'll stop using Firefox anytime soon.
Yes, their management are fucking idiots and it's annoying that I'll have to disable new AI features whenever they release them..

But the alternative is to use something Chromium-based, which would make Google's domination of web technology absolute - and Google is 100x more evil than Mozilla ever could be.

I hope this fucking bubble pops before Mozilla fucks up Firefox so badly that it becomes completely unusable

0
0
1
0
0

ๅคšๅˆ†ๆ™ฎ้€šใซๅ‹•ใใ‘ใฉHDDใŒ้…ทไฝฟใ•ใ‚Œใ™ใŽใฆใ‚ธใƒฃใƒณใ‚ฏใซใชใฃใฆใŸใƒ‡ใ‚นใ‚ฏใƒˆใƒƒใƒ—PCๆฌฒใ—ใ‹ใฃใŸ (ๆŒใฃใฆๅธฐใ‚Œใชใ„ใฎใง่ฒทใฃใฆใชใ„)

0
0
1
0
0
0
0
0
0