A Pattern for Secure Graphical User Interface Systems

被引:6
|
作者
Fischer, Thomas [1 ]
Sadeghi, Ahmad-Reza [1 ]
Winandy, Marcel [1 ]
机构
[1] Ruhr Univ Bochum, Horst Gortz Inst IT Secur, Bochum, Germany
关键词
security pattern; secure GUI; secure windowing system;
D O I
10.1109/DEXA.2009.76
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Several aspects of secure operating systems have been analyzed and described as security patterns. However, existing patterns do not cover explicitly the secure interaction of users with the user interface of applications. Especially graphical user interfaces tend to get complex and vulnerable to spoofing and eavesdropping, e.g., due to key loggers or fake dialog windows. A secure user interface system has to provide a trusted path between the user and the application the user intends to use. The trusted path must be able to ensure integrity and confidentiality of the transmitted data, and must allow for the verification of the authenticity of the end points. We present a pattern for secure graphical user interface systems and evaluate its use in different implementations. This pattern shows how to fulfill the security requirements of a trusted path while preserving, in a policy-driven way, the flexibility that graphical user interfaces generally demand.
引用
收藏
页码:186 / 190
页数:5
相关论文
共 50 条
  • [31] MacMolPlt: A graphical user interface for GAMESS
    Department of Chemistry, Iowa State University, Ames, IA, United States
    不详
    J. Mol. Graph. Model., 3 (133-138):
  • [32] A Graphical User Interface of Pylinac Library
    Garrigo, E.
    Aon, E.
    Descamps, C.
    Falco, E.
    Franco, D.
    Sansogne, R.
    Arbiser, S.
    MEDICAL PHYSICS, 2020, 47 (06) : E498 - E498
  • [33] KERNEL FOR A RESPONSIVE AND GRAPHICAL USER INTERFACE
    STRUBBE, HJ
    SOFTWARE-PRACTICE & EXPERIENCE, 1983, 13 (11): : 1033 - 1042
  • [34] AUTOMATION TESTING OF GRAPHICAL USER INTERFACE
    Miljkovic, Dorde
    Bojic, Sasa
    Dukic, Miodrag
    Jovanovic, Miladin
    2012 20TH TELECOMMUNICATIONS FORUM (TELFOR), 2012, : 1609 - 1612
  • [35] A graphical user interface for PC GAMESS
    Anderson, WP
    JOURNAL OF CHEMICAL EDUCATION, 2003, 80 (08) : 968 - 968
  • [36] Inspector: The GTC graphical user interface
    GTC Project, Instituto de Astrofísica de Canarias , 38200 La Laguna , Spain
    Proc SPIE Int Soc Opt Eng, 1600,
  • [37] A graphical user interface (GUI) for OpenMx
    Carey, Gregory
    BEHAVIOR GENETICS, 2010, 40 (06) : 788 - 788
  • [38] EXPGUI, a graphical user interface for GSAS
    Toby, BH
    JOURNAL OF APPLIED CRYSTALLOGRAPHY, 2001, 34 : 210 - 213
  • [39] Design Trend of Graphical User Interface
    Chang, Eva
    Wang, Ming-Tang
    Chen, Rain
    Tan, Su-Ping
    Shen, Sung-Yun
    2014 INTERNATIONAL SYMPOSIUM ON COMPUTER, CONSUMER AND CONTROL (IS3C 2014), 2014, : 962 - 965
  • [40] A GRAPHICAL USER INTERFACE SERVER FOR UNIX
    HUDSON, SE
    MOHAMED, SP
    SOFTWARE-PRACTICE & EXPERIENCE, 1990, 20 (12): : 1227 - 1239