Usable security for QR code

被引:34
|
作者
Focardi, Riccardo [1 ]
Luccio, Flaminia L. [1 ]
Wahsheh, Heider [1 ]
机构
[1] Univ Ca Foscari Venezia, DAIS, Avia Torino 155, I-30170 Venice, Italy
关键词
QR Codes; Usable security; Cryptography; Digital signature; HMAC;
D O I
10.1016/j.jisa.2019.102369
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
QR codes are widely used in various settings such as consumer advertising, commercial tracking, ticketing and marketing. People tend to scan QR codes and trust their content, but there exists no standard mechanism for providing authenticity and confidentiality of the code content. Attacks such as the redirection to a malicious website or the infection of a smartphone with a malware are realistic and feasible in practice. In this paper, we present the first systematic study of usable state-of-the-art cryptographic primitives inside QR codes. We select standard, popular cryptographic schemes and we compare them based on performance, size and security. We conduct tests that show how different usability factors impact on the QR code scanning performance and we evaluate the usability/security trade-off-of the considered cryptographic schemes. Interestingly, we find out that in some cases security breaks usability and we provide recommendations for the choice of secure and usable cryptographic schemes. (C) 2019 Elsevier Ltd. All rights reserved.
引用
收藏
页数:9
相关论文
共 50 条
  • [1] QR Code Security - How Secure and Usable Apps Can Protect Users Against Malicious QR Codes
    Krombholz, Katharina
    Fruehwirt, Peter
    Rieder, Thomas
    Kapsalis, Ioannis
    Ullrich, Johanna
    Weippl, Edgar
    PROCEEDINGS 10TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY ARES 2015, 2015, : 230 - 237
  • [2] Communication Security of Microwave QR Code
    Du, Yanan
    Xu, Sai
    Yu, Kuaikuai
    Wang, Jiangzhou
    IEEE WIRELESS COMMUNICATIONS LETTERS, 2023, 12 (04) : 635 - 639
  • [3] QR Code Antenna for Wireless and Security Applications
    Numan-Al-Mobin, Abu Md.
    Meruga, Jeevan M.
    Cross, William M.
    Kellar, Jon J.
    Anagnostou, Dimitris E.
    2013 IEEE ANTENNAS AND PROPAGATION SOCIETY INTERNATIONAL SYMPOSIUM (APSURSI), 2013, : 1728 - 1729
  • [4] Modern Applications of QR-Code for Security
    Saranya, K.
    Reminaa, R. S.
    Subhitsha, S.
    PROCEEDINGS OF 2ND IEEE INTERNATIONAL CONFERENCE ON ENGINEERING & TECHNOLOGY ICETECH-2016, 2016, : 173 - 177
  • [5] Redesigning QR Code Ecosystem with Improved Mobile Security
    Yin, L. Roger
    Zhou, Jiazhen
    Hsu, Maxwell K.
    IEEE 39TH ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE WORKSHOPS (COMPSAC 2015), VOL 3, 2015, : 678 - 679
  • [6] Beautified QR Code with Security Based on Data Hiding
    Cai, Huili
    Liu, Xiaofeng
    Yan, Bin
    ADVANCES IN COMPUTATIONAL INTELLIGENCE SYSTEMS (UKCI 2019), 2020, 1043 : 423 - 432
  • [7] A Desktop Application of QR Code for Data Security and Authentication
    Mittra, Partiksha
    Rakesh, Nitin
    2016 INTERNATIONAL CONFERENCE ON INVENTIVE COMPUTATION TECHNOLOGIES (ICICT), VOL 2, 2016, : 62 - 66
  • [8] Usable Cryptographic QR Codes
    Focardi, Riccardo
    Luccio, Flaminia L.
    Wahsheh, Heider Ahmad
    2018 IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL TECHNOLOGY (ICIT), 2018, : 1664 - 1669
  • [9] Multiple security anti-counterfeit applications to QR code payment based on visual secret sharing and QR code
    Wan, Song
    Yang, Guozheng
    Qi, Lanlan
    Li, Longlong
    Yan, Xuehu
    Lu, Yuliang
    MATHEMATICAL BIOSCIENCES AND ENGINEERING, 2019, 16 (06) : 6367 - 6385
  • [10] Evaluating Security, Privacy and Usability Features of QR Code Readers
    Wahsheh, Heider A. M.
    Luccio, Flaminia L.
    PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY (ICISSP), 2019, : 266 - 273