Alphacodes: Usable, Secure Transactions with Untrusted Providers using Human Computable Puzzles

Ashlesh Sharma, Varun Chandrasekaran, F. Amjad, D. Shasha, L. Subramanian
{"title":"Alphacodes: Usable, Secure Transactions with Untrusted Providers using Human Computable Puzzles","authors":"Ashlesh Sharma, Varun Chandrasekaran, F. Amjad, D. Shasha, L. Subramanian","doi":"10.1145/3001913.3001924","DOIUrl":null,"url":null,"abstract":"Many banking and commerce payment systems in developing regions require users to share private or sensitive information in clear-text with untrusted providers, exposing them to different forms of man-in-the-middle attacks. In this paper, we introduce Alphacodes, a new paradigm that enables users to secure transactions with untrusted parties using the notion of human-computable visual puzzles. We describe how Alphacodes can be applied in different use cases and also explain two simple applications that we have built using this framework. We motivate our solution using security vulnerabilities in existing systems, and show how our protocol overcomes them. We demonstrate the ease of use of Alphacodes with minimal training using two simple crowdsourcing studies. Using another simple real world user study involving 10 users who speak Kannada (a regional Indian language), we show that the Alphacodes paradigm can be easily extended to languages beyond English.","PeriodicalId":204042,"journal":{"name":"Proceedings of the 7th Annual Symposium on Computing for Development","volume":"41 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-11-18","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 7th Annual Symposium on Computing for Development","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3001913.3001924","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

Many banking and commerce payment systems in developing regions require users to share private or sensitive information in clear-text with untrusted providers, exposing them to different forms of man-in-the-middle attacks. In this paper, we introduce Alphacodes, a new paradigm that enables users to secure transactions with untrusted parties using the notion of human-computable visual puzzles. We describe how Alphacodes can be applied in different use cases and also explain two simple applications that we have built using this framework. We motivate our solution using security vulnerabilities in existing systems, and show how our protocol overcomes them. We demonstrate the ease of use of Alphacodes with minimal training using two simple crowdsourcing studies. Using another simple real world user study involving 10 users who speak Kannada (a regional Indian language), we show that the Alphacodes paradigm can be easily extended to languages beyond English.
字母表:使用人类可计算谜题与不受信任的提供者进行可用的、安全的交易
发展中地区的许多银行和商业支付系统要求用户以明文形式与不受信任的提供商共享私人或敏感信息,这使他们容易受到不同形式的中间人攻击。在本文中,我们介绍了Alphacodes,这是一种新的范例,使用户能够使用人类可计算的视觉谜题的概念来保护与不受信任方的交易。我们描述了如何在不同的用例中应用Alphacodes,并解释了我们使用该框架构建的两个简单应用程序。我们使用现有系统中的安全漏洞来激励我们的解决方案,并展示我们的协议如何克服它们。我们用两个简单的众包研究演示了字母编码的易用性和最少的训练。使用另一个简单的真实世界用户研究,涉及10个说卡纳达语(一种印度地区语言)的用户,我们表明Alphacodes范式可以很容易地扩展到英语以外的语言。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信