DocumentCode
2353537
Title
Uni-directional trusted path: Transaction confirmation on just one device
Author
Filyanov, Atanas ; McCuney, Jonathan M. ; Sadeghiz, Ahmad-Reza ; Winandy, Marcel
Author_Institution
Horst Gortz Inst. for IT-Security, Ruhr-Univ. Bochum, Bochum, Germany
fYear
2011
fDate
27-30 June 2011
Firstpage
1
Lastpage
12
Abstract
Commodity computer systems today do not include a full trusted path capability. Consequently, malware can control the user´s input and output in order to reveal sensitive information to malicious parties or to generate manipulated transaction requests to service providers. Recent hardware offers compelling features for remote attestation and isolated code execution, however, these mechanisms are not widely used in deployed systems to date. We show how to leverage these mechanisms to establish a “one-way” trusted path allowing service providers to gain assurance that users´ transactions were indeed submitted by a human operating the computer, instead of by malware such as transaction generators. We design, implement, and evaluate our solution, and argue that it is practical and offers immediate value in e-commerce, as a replacement for captchas, and in other Internet scenarios.
Keywords
Internet; electronic commerce; invasive software; transaction processing; Internet; e-commerce; isolated code execution; malicious parties; malware; remote attestation; service providers; transaction confirmation; unidirectional trusted path; Authentication; Hardware; Humans; Malware; Servers; Software; security; transaction confirmation; trusted computing; trusted path;
fLanguage
English
Publisher
ieee
Conference_Titel
Dependable Systems & Networks (DSN), 2011 IEEE/IFIP 41st International Conference on
Conference_Location
Hong Kong
ISSN
1530-0889
Print_ISBN
978-1-4244-9232-9
Electronic_ISBN
1530-0889
Type
conf
DOI
10.1109/DSN.2011.5958202
Filename
5958202
Link To Document