Decryptable to Your Eyes: Visualization of Security Protocols at the User Interface

DaeHun Nyang,Abedelaziz Mohaisen,Taekyoung Kwon,Brent Kang,Angelos Stavrou
DOI: https://doi.org/10.48550/arXiv.1112.2245
2011-12-10
Abstract:The design of authentication protocols, for online banking services in particular and any service that is of sensitive nature in general, is quite challenging. Indeed, enforcing security guarantees has overhead thus imposing additional computation and design considerations that do not always meet usability and user requirements. On the other hand, relaxing assumptions and rigorous security design to improve the user experience can lead to security breaches that can harm the users' trust in the system. In this paper, we demonstrate how careful visualization design can enhance not only the security but also the usability of the authentication process. To that end, we propose a family of visualized authentication protocols, a visualized transaction verification, and a "decryptable to your eyes only" protocol. Through rigorous analysis, we verify that our protocols are immune to many of the challenging authentication attacks applicable in the literature. Furthermore, using an extensive case study on a prototype of our protocols, we highlight the potential of our approach for real-world deployment: we were able to achieve a high level of usability while satisfying stringent security requirements.
Cryptography and Security
What problem does this paper attempt to address?