Most traditional cryptosystems assume that secret information, such as decryption and signing keys, is kept secure from attackers and that the machine executing the algorithm is trustworthy. In reality, however, security is not always guaranteed, as machines may be infected with malware that leaks secret information or executes computations differently from the intended algorithms. To address this, Ogata et al. introduced the concept of a “server-aided in-brain signature,” a cryptographic protocol to sign a message securely even if the user’s device and servers are not completely trusted, and its concrete scheme that combines a one-time pad and multi-party computation (MPC). In this study, we first design the user interface for the Ogata et al.’s in-brain signature scheme using two terminals: a laptop and a smartphone. In this scheme, the signer must process characters in their brain using a one-time pad, raising concerns about its feasibility. To facilitate this process, we introduce an addition table to significantly reduce cognitive processing in the brain. We then implement the interface and evaluated it through user experiments. As a result, in the objective evaluation, all experimental participants successfully performed one-time pad operations in their brains. In the subjective evaluation, although the in-brain signature imposed a high cognitive load, its potential acceptability is confirmed for transactions requiring a high level of security.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Design and Evaluation of User Interface for Server-Aided In-Brain Signature

  • Ryunosuke Harada,
  • Wataru Hatakeyama,
  • Sena Enomoto,
  • Kakeru Hasegawa,
  • Toi Tomita,
  • Kenta Takahashi,
  • Wakaha Ogata,
  • Masakatsu Nishigaki

摘要

Most traditional cryptosystems assume that secret information, such as decryption and signing keys, is kept secure from attackers and that the machine executing the algorithm is trustworthy. In reality, however, security is not always guaranteed, as machines may be infected with malware that leaks secret information or executes computations differently from the intended algorithms. To address this, Ogata et al. introduced the concept of a “server-aided in-brain signature,” a cryptographic protocol to sign a message securely even if the user’s device and servers are not completely trusted, and its concrete scheme that combines a one-time pad and multi-party computation (MPC). In this study, we first design the user interface for the Ogata et al.’s in-brain signature scheme using two terminals: a laptop and a smartphone. In this scheme, the signer must process characters in their brain using a one-time pad, raising concerns about its feasibility. To facilitate this process, we introduce an addition table to significantly reduce cognitive processing in the brain. We then implement the interface and evaluated it through user experiments. As a result, in the objective evaluation, all experimental participants successfully performed one-time pad operations in their brains. In the subjective evaluation, although the in-brain signature imposed a high cognitive load, its potential acceptability is confirmed for transactions requiring a high level of security.