Establishing trust between a group of individuals remains a difficult problem. Prior works assume trusted infrastructure, require an individual to trust unknown entities, or provide relatively low probabilistic guarantees of authenticity (95% for realistic settings). The first part of this dissertation presents a primitive (called SPATE for short) that allows users to establish trust via device mobility and physical interaction. Once SPATE protocol runs to completion, its participants' mobile devices have authentic data that their applications can use to interact securely (i.e., the probability of a successful attack is 2^−24). For second part of this dissertation, we leverage SPATE protocol as part of a larger system to facilitate efficient, secure, and user-friendly collaboration via email, file-sharing, and text messaging services. The implementation of SPATE on Nokia smartphones (Nokia S60 serials, including N70 and E51) allows users to establish trust in small groups of up to eight users in less than one minute. To be widespread, SPATE is also ported to iPhone platform (early result is given). Three example SPATE applications provide increased security with minor overhead noticeable to users once keys are established.
在群體人群間建立信賴關係仍然是一個很難的問題。以往的研究都會假設已經存在至少一個信賴的基礎建設,如需要使用者信任一些未必可信任之單位,或是提供相對低的信任程度(95%的實際設定)。該論文提出SPATE機制,允許使用者透過行動運算裝置與實體接觸來進行建立信賴關係。當SPATE交換程序完成之後,參與者的行動裝置可取得群體內所交換的認證資訊(攻擊者的成功機率僅有2−24)。 基於該機制,我們利用SPATE建制後的信任基礎以建置三種有效、便 利、安全的實際應用,包含電子郵件、檔案分享與簡訊服務。該系統被完整的實作於諾基亞S60系列智慧型手機(包含N70與E51)。系統效能相當卓越,八位以下使用者僅需一分鐘內便可建制完成,使用方法也簡單易懂。透過該設計的機 制,人們可以更簡單與便利的建置信賴關係與相關安全應用。