首页> 外文会议>2013 12th IEEE International Conference on Trust, Security and Privacy in Computing and Communications >Studies in Socio-technical Security Analysis: Authentication of Identities with TLS Certificates
【24h】

Studies in Socio-technical Security Analysis: Authentication of Identities with TLS Certificates

机译:社会技术安全分析研究:使用TLS证书对身份进行身份验证

获取原文
获取原文并翻译 | 示例

摘要

Authenticating web identities with TLS certificates is a typical problem whose security depends on both technical and human aspects, and that needs, to be fully grasped, a socio-technical analysis. We performed such an analysis, and in this paper we comment on the tools and methodology we found appropriate. We first analysed the interaction ceremonies between users and the most used browsers in the market. Then we looked at user's understanding of those interactions. Our tools and our methodology depend on whether the user model has a non-deterministic or a realistic behaviour. We successfully applied formal methods in the first case. In the second, we had to define a security framework consistent with research methods of experimental cognitive science.
机译:使用TLS证书对Web身份进行身份验证是一个典型的问题,其安全性取决于技术和人员方面,因此需要进行全面的社会技术分析。我们进行了这样的分析,在本文中,我们对我们认为合适的工具和方法进行了评论。我们首先分析了用户与市场上最常用的浏览器之间的交互仪式。然后,我们研究了用户对这些交互的理解。我们的工具和方法取决于用户模型是不确定的还是现实的行为。我们在第一种情况下成功应用了形式化方法。第二,我们必须定义与实验认知科学的研究方法一致的安全框架。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号