User Identification Procedures with Human Mutations: Formal Analysis and Pilot Study (Extended Version)

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Quamara, Megha, Vigano, Luca
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915143241170944
author Quamara, Megha
Vigano, Luca
author_facet Quamara, Megha
Vigano, Luca
contents User identification procedures, essential to the information security of systems, enable system-user interactions by exchanging data through communication links and interfaces to validate and confirm user authenticity. However, human errors can introduce vulnerabilities that may disrupt the intended identification workflow and thus impact system behavior. Therefore, ensuring the integrity of these procedures requires accounting for such erroneous behaviors. We follow a formal, human-centric approach to analyze user identification procedures by modeling them as security ceremonies and apply proven techniques for automatically analyzing such ceremonies. The approach relies on mutation rules to model potential human errors that deviate from expected interactions during the identification process, and is implemented as the X-Men tool, an extension of the Tamarin prover, which automatically generates models with human mutations and implements matching mutations to other ceremony participants for analysis. As a proof-of-concept, we consider a real-life pilot study involving an AI-driven, virtual receptionist kiosk for authenticating visitors.
format Preprint
id arxiv_https___arxiv_org_abs_2502_05530
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle User Identification Procedures with Human Mutations: Formal Analysis and Pilot Study (Extended Version)
Quamara, Megha
Vigano, Luca
Cryptography and Security
User identification procedures, essential to the information security of systems, enable system-user interactions by exchanging data through communication links and interfaces to validate and confirm user authenticity. However, human errors can introduce vulnerabilities that may disrupt the intended identification workflow and thus impact system behavior. Therefore, ensuring the integrity of these procedures requires accounting for such erroneous behaviors. We follow a formal, human-centric approach to analyze user identification procedures by modeling them as security ceremonies and apply proven techniques for automatically analyzing such ceremonies. The approach relies on mutation rules to model potential human errors that deviate from expected interactions during the identification process, and is implemented as the X-Men tool, an extension of the Tamarin prover, which automatically generates models with human mutations and implements matching mutations to other ceremony participants for analysis. As a proof-of-concept, we consider a real-life pilot study involving an AI-driven, virtual receptionist kiosk for authenticating visitors.
title User Identification Procedures with Human Mutations: Formal Analysis and Pilot Study (Extended Version)
topic Cryptography and Security
url https://arxiv.org/abs/2502.05530