A Pattern for Secure Graphical User Interface Systems

被引:6
|
作者
Fischer, Thomas [1 ]
Sadeghi, Ahmad-Reza [1 ]
Winandy, Marcel [1 ]
机构
[1] Ruhr Univ Bochum, Horst Gortz Inst IT Secur, Bochum, Germany
关键词
security pattern; secure GUI; secure windowing system;
D O I
10.1109/DEXA.2009.76
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Several aspects of secure operating systems have been analyzed and described as security patterns. However, existing patterns do not cover explicitly the secure interaction of users with the user interface of applications. Especially graphical user interfaces tend to get complex and vulnerable to spoofing and eavesdropping, e.g., due to key loggers or fake dialog windows. A secure user interface system has to provide a trusted path between the user and the application the user intends to use. The trusted path must be able to ensure integrity and confidentiality of the transmitted data, and must allow for the verification of the authenticity of the end points. We present a pattern for secure graphical user interface systems and evaluate its use in different implementations. This pattern shows how to fulfill the security requirements of a trusted path while preserving, in a policy-driven way, the flexibility that graphical user interfaces generally demand.
引用
收藏
页码:186 / 190
页数:5
相关论文
共 50 条
  • [41] The graphical user interface layer for BALI
    Lim, W
    MOBILE ROBOTS XI AND AUTOMATED VEHICLE CONTROL SYSTEMS, 1997, 2903 : 34 - 43
  • [42] Informal user interface for graphical computing
    Sun, ZX
    Liu, J
    AFFECTIVE COMPUTING AND INTELLIGENT INTERACTION, PROCEEDINGS, 2005, 3784 : 675 - 682
  • [43] A graphical user interface for screening securities
    Abdelrahman, NM
    Zargham, MR
    IKE'03: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON INFORMATION AND KNOWLEDGE ENGINEERING, VOLS 1 AND 2, 2003, : 482 - 487
  • [44] Measure the usability of graphical user interface
    Sharipbay, Altynbek
    Barlybayev, Alibek
    Sabyrov, Talgat
    NEW ADVANCES IN INFORMATION SYSTEMS AND TECHNOLOGIES, VOL 1, 2016, 444 : 1037 - 1045
  • [45] THE PROCESS OF UPDATING THE GRAPHICAL USER INTERFACE
    Cherniltsev, Andrey
    INFORMATICS, GEOINFORMATICS AND REMOTE SENSING CONFERENCE PROCEEDINGS, SGEM 2016, VOL I, 2016, : 483 - 488
  • [46] The missing graphical user interface for genomics
    Michael C Schatz
    Genome Biology, 11
  • [47] pamlX: A Graphical User Interface for PAML
    Xu, Bo
    Yang, Ziheng
    MOLECULAR BIOLOGY AND EVOLUTION, 2013, 30 (12) : 2723 - 2724
  • [48] MVPANI: A Toolkit With Friendly Graphical User Interface for Multivariate Pattern Analysis of Neuroimaging Data
    Peng, Yanmin
    Zhang, Xi
    Li, Yifan
    Su, Qian
    Wang, Sijia
    Liu, Feng
    Yu, Chunshui
    Liang, Meng
    FRONTIERS IN NEUROSCIENCE, 2020, 14
  • [49] Adaptive Graphical User Interface Solution for Modern User Devices
    Behan, Miroslav
    Krejcar, Ondrej
    INTELLIGENT INFORMATION AND DATABASE SYSTEMS (ACIIDS 2012), PT II, 2012, 7197 : 411 - 420
  • [50] User evaluation of a graphical user interface for biomedical literature search
    Wiesman, F
    MEDICAL INFORMATICS EUROPE '97: PARTS A & B, 1997, 43 : 796 - 800