TWC: Medium: Collaborative: Neuroscience Meets Computer Security: Designing Systems Secure Against Coercion Attacks
TWC: Medium: Collaborative: Neuroscience Meets Computer Security: Designing Systems Secure Against Coercion Attacks
批准号:
1228460
负责人:
Patrick Lincoln
金额:
$34.98万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2012
资助国家:
美国
项目状态:
已结题
起止时间:
2012-10-01 至 2016-09-30
中文摘要
强制攻击迫使授权用户透露他或她的秘密身份验证凭据,可以使攻击者访问受限系统。 PI正在开发一种新的方法来防止胁迫攻击,使用认知心理学中的内隐学习概念。 内隐学习是指在没有任何有意识的知识的情况下学习模式。使用一个精心制作的基于键盘的电脑游戏,PI在参与者的大脑中植入一个秘密密码,而参与者对训练的密码没有任何意识知识。 这个植入的秘密可以用于身份验证,但参与者不能被迫透露他们的秘密,因为他们没有意识到这一点。 这个项目探讨了在计算机安全中使用内隐学习的三个方向。 首先,PI正在开发旨在用于挑战-响应身份验证的隐式学习任务。第二,PI正在试验通过使用现成的EEG设备测量头皮沿着的电活动来展示内隐知识的方法。 第三,PI正在进行用户实验,以证明参与者能够正确地进行身份验证,但不能有意识地识别训练的秘密。 该项目是计算机安全研究人员和认知心理学家之间的合作。 最终,该项目旨在了解大脑如何表示内隐知识。 这反过来又会为高安全性应用程序带来新的抗强制安全机制。
英文摘要
Coercion attacks that compel an authorized user to reveal his or her secret authentication credentials can give attackers access to restricted systems. The PIs are developing a new approach to preventing coercion attacks using the concept of implicit learning from cognitive psychology. Implicit learning refers to learning of patterns without any conscious knowledge of the learned pattern. Using a carefully crafted keyboard-based computer game the PIs plant a secret password in the participant's brain without the participant having any conscious knowledge of the trained password. This planted secret can be used for authentication, but participants cannot be coerced into revealing their secret since they have no conscious knowledge of it. This project explores three directions for using implicit learning in computer security. First, the PIs are developing implicit learning tasks designed to be used in challenge-response authentication. Second, the PIs are experimenting with methods to demonstrate implicit knowledge by measuring electrical activity along the scalp using off the shelf EEG devices. Third, the PIs are conducting user experiments to demonstrate that participants are able to properly authenticate, but cannot consciously recognize the trained secret. This project is a collaboration between computer security researchers and cognitive psychologists. Ultimately, the project aims to understand how the brain represents implicit knowledge. This in turn will lead to new coercion resistant security mechanisms for high-security applications.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SGER: SCIF: Securing the Computing and Information Future: Principled Foundations and New Cryptographic Abstractions
-
批准号:0749931
-
项目类别:Continuing Grant
-
资助金额:$0.0万
-
财政年份:2007
-
负责人:Patrick Lincoln
-
依托单位:
Computational Aspects of Linear Logic
-
批准号:9224858
-
项目类别:Standard Grant
-
资助金额:$11.35万
-
财政年份:1993
-
负责人:Patrick Lincoln
-
依托单位:
海外基金