Title:
Mandatory Human Participation: A New Scheme for Building Secure Systems

dc.contributor.author Essa, Irfan
dc.contributor.author Sung, Min-Ho
dc.contributor.author Lipton, Richard J.
dc.contributor.author Xu, Jun en_US
dc.date.accessioned 2005-06-17T17:42:56Z
dc.date.available 2005-06-17T17:42:56Z
dc.date.issued 2001 en_US
dc.description.abstract Mandatory Human Participation (MHP) is a novel authentication scheme that asks the question "are you human?" (instead of "who are you?"), and upon the correct answer to this question, can prove a principal to be a human being instead of a computer program. MHP helps solve old and new problems in computer security that existing security measures can not address properly, including password (or PIN number) guessing attacks, automated service and information theft, and denial of service. A key component of this `are you human?'' authentication process is a character morphing algorithm that transforms a character string into its graphical form in such a way that a human being won't have any problem recognizing the original string, while a computer program (e.g., an Optical Character Recognition program), will not be able to decipher it or make a correct guess with non-negligible probability. The basic idea of the MHP scheme is to ask an agent to recognize the string before its login attempts or transaction requests can be honored. Here a protocol is needed to send a puzzle to an agent, check if the answer supplied by the agent is correct, and most importantly make sure that the agent can not cheat in the process. A number of system and security issues that relate to the protocol need to be addressed for the protocol to be secure, efficient, robust, and user-friendly. The MHP scheme contributes to the foundation of the computer security by faithfully implementing a novel security semantics, "human," which existing cryptographic measures can not express accurately. As many real-world security applications involve the interaction between a human and a computer, which naturally contains "human" as a part of its protocol semantics, we believe that the MHP scheme will find many new applications in the future. en_US
dc.format.extent 231894 bytes
dc.format.mimetype application/pdf
dc.identifier.uri http://hdl.handle.net/1853/6564
dc.language.iso en_US
dc.publisher Georgia Institute of Technology en_US
dc.relation.ispartofseries CC Technical Report; GIT-CC-01-09 en_US
dc.subject Authentication
dc.subject Computer security
dc.subject Mandatory Human Participation (MHP)
dc.subject Humanizer
dc.title Mandatory Human Participation: A New Scheme for Building Secure Systems en_US
dc.type Text
dc.type.genre Technical Report
dspace.entity.type Publication
local.contributor.author Essa, Irfan
local.contributor.corporatename College of Computing
local.relation.ispartofseries College of Computing Technical Report Series
relation.isAuthorOfPublication 84ae0044-6f5b-4733-8388-4f6427a0f817
relation.isOrgUnitOfPublication c8892b3c-8db6-4b7b-a33a-1b67f7db2021
relation.isSeriesOfPublication 35c9e8fc-dd67-4201-b1d5-016381ef65b8
Files
Original bundle
Now showing 1 - 1 of 1
Thumbnail Image
Name:
GIT-CC-01-09.pdf
Size:
226.46 KB
Format:
Adobe Portable Document Format
Description: