In the quest to protect users from {Side-Channel} attacks–a {User-Centred} design space to mitigate thermal attacks on public payment terminals

K Marky, S Macdonald, Y Abdrabou… - 32nd usenix security …, 2023 - usenix.org
32nd usenix security symposium (usenix security 23), 2023usenix.org
Thermal attacks are an emerging threat that enables the reconstruction of user input after
interaction with a device by analysing heat traces. There are several ways to protect users
from thermal attacks that require different degrees of user involvement. In this paper, we first
present a structured literature review to identify 15 protection strategies. Then, we
investigate user perceptions of these strategies in an online study (N= 306). Our results
show that users intuitively use protection strategies that also work against other side …
Abstract
Thermal attacks are an emerging threat that enables the reconstruction of user input after interaction with a device by analysing heat traces. There are several ways to protect users from thermal attacks that require different degrees of user involvement. In this paper, we first present a structured literature review to identify 15 protection strategies. Then, we investigate user perceptions of these strategies in an online study (N= 306). Our results show that users intuitively use protection strategies that also work against other side-channel attacks. Further, users are willing to sacrifice convenience for the sake of verifying a strategy's efficacy. Yet, an ideal holistic defence from thermal attacks is one that is readily integrated into user interfaces by manufacturers in a way that the user can verify it. Further, users like resourceless strategies that fit their habits. We use the literature review and study results to identify a user-centred design space for thermal attack protection. We conclude the paper with specific recommendations for users, device manufacturers and interface providers to better protect individuals from thermal attacks.
usenix.org
以上显示的是最相近的搜索结果。 查看全部搜索结果