A Pattern for Secure Graphical User Interface Systems

被引:6
|
作者
Fischer, Thomas [1 ]
Sadeghi, Ahmad-Reza [1 ]
Winandy, Marcel [1 ]
机构
[1] Ruhr Univ Bochum, Horst Gortz Inst IT Secur, Bochum, Germany
关键词
security pattern; secure GUI; secure windowing system;
D O I
10.1109/DEXA.2009.76
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Several aspects of secure operating systems have been analyzed and described as security patterns. However, existing patterns do not cover explicitly the secure interaction of users with the user interface of applications. Especially graphical user interfaces tend to get complex and vulnerable to spoofing and eavesdropping, e.g., due to key loggers or fake dialog windows. A secure user interface system has to provide a trusted path between the user and the application the user intends to use. The trusted path must be able to ensure integrity and confidentiality of the transmitted data, and must allow for the verification of the authenticity of the end points. We present a pattern for secure graphical user interface systems and evaluate its use in different implementations. This pattern shows how to fulfill the security requirements of a trusted path while preserving, in a policy-driven way, the flexibility that graphical user interfaces generally demand.
引用
收藏
页码:186 / 190
页数:5
相关论文
共 50 条
  • [1] Secure graphical user interface for Geant4
    Yoshida, H
    Minamimoto, K
    2003 IEEE NUCLEAR SCIENCE SYMPOSIUM, CONFERENCE RECORD, VOLS 1-5, 2004, : 1614 - 1616
  • [2] Secure graphical user interface for geant4
    Naruto University of Education, Japan
    1600, 1614-1616 (2003):
  • [3] Graphical user interface
    Woolls-King, Andrew
    1997, (26):
  • [4] Photovoltaic systems sizing using graphical user interface
    Vega-Carranza, Kenneth
    Francisco Piedra-Segura, Juan
    Richmond-Navarro, Gustavo
    TECNOLOGIA EN MARCHA, 2019, 32 (03): : 66 - 78
  • [5] An Initial Characterization of Industrial Graphical User Interface Systems
    Brooks, Penelope
    Robinson, Brian
    Memon, Atif M.
    SECOND INTERNATIONAL CONFERENCE ON SOFTWARE TESTING, VERIFICATION, AND VALIDATION, PROCEEDINGS, 2009, : 11 - +
  • [6] Graphical user interface for next generation power systems
    Lavergne, M
    INTELEC(R): TWENTY-SECOND INTERNATIONAL TELECOMMUNICATIONS ENERGY CONFERENCE, 2000, : 109 - 112
  • [7] Graphical User Interface definition processes in the frame of Systems-of-Systems
    Arnould, Vincent
    2018 13TH ANNUAL CONFERENCE ON SYSTEM OF SYSTEMS ENGINEERING (SOSE), 2018, : 297 - 302
  • [8] A command line interface versus a graphical user interface in coding VR systems
    Fellmann, Tom
    Kavakli, Manolya
    PROCEEDINGS OF THE SECOND IASTED INTERNATIONAL CONFERENCE ON HUMAN-COMPUTER INTERACTION, 2007, : 142 - 147
  • [9] Interactive modular graphical user interface development for telesensation systems
    DeRossi, V
    Batsomboon, P
    Tosunoglu, S
    Repperger, DW
    SMC '97 CONFERENCE PROCEEDINGS - 1997 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS, VOLS 1-5: CONFERENCE THEME: COMPUTATIONAL CYBERNETICS AND SIMULATION, 1997, : 1604 - 1608
  • [10] AN OBJECT BASED GRAPHICAL USER INTERFACE FOR POWER-SYSTEMS
    FOLEY, M
    BOSE, A
    MITCHELL, W
    FAUSTINI, A
    CHAINEY, WE
    HUSCH, CR
    KRUGER, KH
    IEEE TRANSACTIONS ON POWER SYSTEMS, 1993, 8 (01) : 97 - 104