• DocumentCode
    1944495
  • Title

    A Survey to Guide Group Key Protocol Development

  • Author

    Studer, Ahren ; Johns, Christina ; Kase, Jaanus ; Meara, Kyle O. ; Cranor, Lorrie

  • Author_Institution
    Dept. of Electr. & Comput. Eng., Carnegie Mellon Univ., Pittsburgh, PA
  • fYear
    2008
  • fDate
    8-12 Dec. 2008
  • Firstpage
    475
  • Lastpage
    484
  • Abstract
    A large number of papers have proposed cryptographic protocols for establishing secure group communication. These protocols allow a set of group members to exchange or establish keys to encrypt and authenticate messages within the group. At the same time, individuals outside of the group cannot eavesdrop on group communication or inject messages. There have even been usability studies, demonstrating an average user can successfully complete some of these protocols. However, group protocols are rarely used in the real world. In this work, we conduct a survey to help uncover why the general population ignores such mechanisms for group communication. We also try to determine what protocols would best match respondents´ current expectations for group protocols and methods for establishing trust. Survey results indicate that a group protocol that leverages location-limited channels, PKI, or Web-of-Trust authenticated public keys and allows addition and deletion of members fulfills the majority of users´ expectations.
  • Keywords
    cryptographic protocols; message authentication; public key cryptography; PKI; Web-of-trust authenticated public keys; authenticate messages; cryptographic protocols; encrypt messages; group key protocol development; group protocols; location-limited channels; secure group communication; Application software; Collaborative work; Computer security; Cryptographic protocols; Human computer interaction; Internet; Public key; Public key cryptography; Public policy; Usability; Group Key Protocols; Trust Establishment; Usability;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications Conference, 2008. ACSAC 2008. Annual
  • Conference_Location
    Anaheim, CA
  • ISSN
    1063-9527
  • Print_ISBN
    978-0-7695-3447-3
  • Type

    conf

  • DOI
    10.1109/ACSAC.2008.28
  • Filename
    4721582