A Pattern for Secure Graphical User Interface Systems

被引:6
|
作者
Fischer, Thomas [1 ]
Sadeghi, Ahmad-Reza [1 ]
Winandy, Marcel [1 ]
机构
[1] Ruhr Univ Bochum, Horst Gortz Inst IT Secur, Bochum, Germany
关键词
security pattern; secure GUI; secure windowing system;
D O I
10.1109/DEXA.2009.76
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Several aspects of secure operating systems have been analyzed and described as security patterns. However, existing patterns do not cover explicitly the secure interaction of users with the user interface of applications. Especially graphical user interfaces tend to get complex and vulnerable to spoofing and eavesdropping, e.g., due to key loggers or fake dialog windows. A secure user interface system has to provide a trusted path between the user and the application the user intends to use. The trusted path must be able to ensure integrity and confidentiality of the transmitted data, and must allow for the verification of the authenticity of the end points. We present a pattern for secure graphical user interface systems and evaluate its use in different implementations. This pattern shows how to fulfill the security requirements of a trusted path while preserving, in a policy-driven way, the flexibility that graphical user interfaces generally demand.
引用
收藏
页码:186 / 190
页数:5
相关论文
共 50 条
  • [21] On the usability assessment of the graphical user interface related to a digital pattern software tool
    Patalano S.
    Lanzotti A.
    Del Giudice D.M.
    Vitolo F.
    Gerbino S.
    International Journal on Interactive Design and Manufacturing (IJIDeM), 2017, 11 (3): : 457 - 469
  • [22] User-centred Design and Development of a Graphical User Interface for Learning Classifier Systems
    Babu, Sooraj K.
    Schneider, Tim
    von Mammen, Sebastian
    PROCEEDINGS OF THE 2023 GENETIC AND EVOLUTIONARY COMPUTATION CONFERENCE COMPANION, GECCO 2023 COMPANION, 2023, : 1830 - 1837
  • [23] Graphical User Interface for Electrical Engineering Systems using Wolfram Language
    Lutovac, Miroslav D.
    Mladenovic, Vladimir
    Lutovac-Banduka, Maja
    2016 24TH TELECOMMUNICATIONS FORUM (TELFOR), 2016, : 909 - 912
  • [24] A technique to specify the graphical user interface for supervisory-control systems
    Suzuki, H
    Tanikoshi, K
    Tani, M
    INTELLIGENT COMPONENTS AND INSTRUMENTS FOR CONTROL APPLICATIONS 1997 (SICICA'97), 1997, : 165 - 169
  • [25] Secure User Authentication with Graphical Passwords and PassText
    Mohd, Raj Mohammed
    Bindu, C. Shoba
    Vasumathi, D.
    PROCEEDINGS OF THE FIRST INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND INFORMATICS, ICCII 2016, 2017, 507 : 523 - 533
  • [26] The missing graphical user interface for genomics
    Schatz, Michael C.
    GENOME BIOLOGY, 2010, 11 (08):
  • [27] Inspector: the GTC graphical user interface
    Macias, R.
    Filgueira, J. M.
    ADVANCED SOFTWARE AND CONTROL FOR ASTRONOMY II, PTS 1 & 2, 2008, 7019
  • [28] Graphical user interface for the program FraGen
    Wang, Chao
    Wei, Yueju
    Yang, Bing
    Li, Yi
    JOURNAL OF APPLIED CRYSTALLOGRAPHY, 2019, 52 (1455-1459) : 1455 - 1459
  • [29] Graphical User Interface for Blackbody Control
    Weeks, Kaitlin L.
    Weeks, Kirk L.
    Bakhoum, Ezzat
    PROCEEDINGS OF THE IEEE SOUTHEASTCON 2009, TECHNICAL PROCEEDINGS, 2009, : 115 - +
  • [30] MacMolPlt: A graphical user interface for GAMESS
    Bode, BM
    Gordon, MS
    JOURNAL OF MOLECULAR GRAPHICS & MODELLING, 1998, 16 (03): : 133 - +