Zur Kurzanzeige

Human Aspects in Secure Messaging

dc.contributor.advisorSmith, Matthew
dc.contributor.authorDechand, Sergej
dc.date.accessioned2025-06-05T13:00:06Z
dc.date.available2025-06-05T13:00:06Z
dc.date.issued05.06.2025
dc.identifier.urihttps://hdl.handle.net/20.500.11811/13121
dc.description.abstractThe widespread adoption of digital communication demands robust security and privacy protections, particularly through secure messaging systems that can protect personal and sensitive information. Despite advancements in end-to-end security, encryption, and anonymity, significant gaps remain in usability and user trust, limiting widespread adoption. This cumulative dissertation examines the human aspects of secure messaging systems through four peer-reviewed studies, addressing fundamental challenges in usability, trust establishment, and practical implementations.
Diverse methodological approaches drive the research, including systematic protocol analysis with a focus on human aspects, large-scale empirical studies, and qualitative investigations, alongside the proposal and evaluation of improved technical implementations. First, a comprehensive systematization of knowledge establishes a unified framework for evaluating secure messaging protocols and “in-the-wild” tools, investigating critical gaps in current approaches. Second, an empirical study with 1047 participants examines fingerprint representation approaches for trust establishment. Third, qualitative research explores potential misconceptions in user mental models and trust for end-to-end security in general. Finally, a novel hardware-based approach utilizing NFC-enabled wearables demonstrates practical solutions for simplifying cryptographic key management while maintaining security.
Key findings indicate that (1) trust establishment remains the cornerstone of secure messaging, as it requires user interaction and underpins the entire security guarantees; failure in this area compromises the system entirely. (2) traditional hex-based fingerprint representations significantly underperform in both attack detection and perceived usability compared to the proposed sentence-based representation, but also numeric representation, as commonly used outside cryptographic contexts, also proving more effective; (3) users mistrust messaging platforms and security features in general and substantially overestimate attackers while underestimating cryptographic capabilities; and (4) less invasive security mechanisms as with using wearables show promise for broader adoption. The findings align with current developments in secure messaging applications, where similar verification approaches are used.
This work advances the field of usable security by bridging theoretical understanding with practical implementation, contributing to the development of more effective and accessible secure communication systems. The findings provide guidance for designing next-generation secure messaging solutions that balance robust security with user needs and capabilities.
en
dc.language.isoeng
dc.rightsIn Copyright
dc.rights.urihttp://rightsstatements.org/vocab/InC/1.0/
dc.subjectsecure messaging
dc.subjectusable security
dc.subject.ddc004 Informatik
dc.titleHuman Aspects in Secure Messaging
dc.typeDissertation oder Habilitation
dc.publisher.nameUniversitäts- und Landesbibliothek Bonn
dc.publisher.locationBonn
dc.rights.accessRightsopenAccess
dc.identifier.urnhttps://nbn-resolving.org/urn:nbn:de:hbz:5-82661
dc.relation.doihttps://doi.org/10.1109/EuroSP.2019.00037
dc.relation.doihttps://doi.org/10.1109/SP.2015.22
dc.relation.doihttps://doi.org/10.1145/3130964
dc.relation.urlhttps://www.usenix.org/conference/usenixsecurity16/technical-sessions/presentation/dechand
ulbbn.pubtypeErstveröffentlichung
ulbbnediss.affiliation.nameRheinische Friedrich-Wilhelms-Universität Bonn
ulbbnediss.affiliation.locationBonn
ulbbnediss.thesis.levelDissertation
ulbbnediss.dissID8266
ulbbnediss.date.accepted29.04.2025
ulbbnediss.dissNotes.externIn reference to IEEE copyrighted material which is used with permission in this thesis, the IEEE does not endorse any of University of Bonn's products or services. Internal or personal use of this material is permitted. If interested in reprinting/republishing IEEE copyrighted material for advertising or promotional purposes or for creating new collective works for resale or redistribution, please go to http://www.ieee.org/publications_standards/publications/rights/rights_link.html to learn how to obtain a License from RightsLink.
ulbbnediss.instituteMathematisch-Naturwissenschaftliche Fakultät : Fachgruppe Informatik / Institut für Informatik
ulbbnediss.fakultaetMathematisch-Naturwissenschaftliche Fakultät
dc.contributor.coRefereeMeier, Michael
ulbbnediss.contributor.orcidhttps://orcid.org/0009-0005-1376-2631


Dateien zu dieser Ressource

Thumbnail

Das Dokument erscheint in:

Zur Kurzanzeige

Die folgenden Nutzungsbestimmungen sind mit dieser Ressource verbunden:

InCopyright