The WHO Hardware Token Security Model (Position Paper)

lucas c k hui,joe c k yau,eric ke wang,s m yiu,zoe l jiang
2006-01-01
Abstract:Existing Internet applications usually rely on a secure communication channel (such as SSL) or users’ passwords to provide a secure communication. And usually we assume that the browser and the computer we are using are trustworthy. However, these assumptions are obviously unrealistic. In this paper, we try to address these issues, in particular, we describe a trust model, call the WHO model, which does not rely on a trusted computer to communicate with the server. The key ideas of the model rely on a carefully designed hardware material accessing module as well as an open-source in-house developed trusted browser. Prototype systems are currently implemented. Preliminary results show that the systems are secure, convenient to use, and are flexible for incorporating different secure protocols.
What problem does this paper attempt to address?