Towards a secure human-and-computer mutual authentication protocol

  • Authors:
  • Kenneth Radke;Colin Boyd;Juan Gonzalez Nieto;Margot Brereton

  • Affiliations:
  • Information Security Institute and Queensland University of Technology;Information Security Institute;Information Security Institute;Queensland University of Technology

  • Venue:
  • AISC '12 Proceedings of the Tenth Australasian Information Security Conference - Volume 125
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

We blend research from human-computer interface (HCI) design with computational based cryptographic provable security. We explore the notion of practice-oriented provable security (POPS), moving the focus to a higher level of abstraction (POPS+) for use in providing provable security for security ceremonies involving humans. In doing so we highlight some challenges and paradigm shifts required to achieve meaningful provable security for a protocol which includes a human. We move the focus of security ceremonies from being protocols in their context of use, to the protocols being cryptographic building blocks in a higher level protocol (the security ceremony), which POPS can be applied to. In order to illustrate the need for our approach, we analyse both a protocol proven secure in theory, and a similar protocol implemented by a financial institution, from both HCI and cryptographic perspectives.