USENIX Security2021Top-tier venue
CACTI: Captcha Avoidance via Client-side TEE Integration
Yoshimichi Nakatsuka, Ercan Ozturk, Andrew Paverd, Gene Tsudik
Abstract
Preventing abuse of web services by bots is an increasingly important problem, as abusive activities grow in both volume and variety. CAPTCHAs are the most common way for thwarting bot activities. However, they are often ineffective against bots and frustrating for humans. In addition, some recent CAPTCHA techniques diminish user privacy. Meanwhile, client-side Trusted Execution Environments (TEEs) are becoming increasingly widespread (notably, ARM TrustZone and Intel SGX), allowing establishment of trust in a small part (trust anchor or TCB) of client-side hardware. This prompts the question: can a TEE help reduce (or remove entirely) user burden of solving CAPTCHAs? In this paper, we design CACTI: CAPTCHA Avoidance via Client-side TEE Integration. Using client-side TEEs, CACTI allows legitimate clients to generate unforgeable rate-proofs demonstrating how frequently they have performed specific actions. These rate-proofs can be sent to web servers in lieu of solving CAPTCHAs. CACTI provides strong client privacy guarantees, since the information is only sent to the visited website and authenticated using a group signature scheme. Our evaluations show that overall latency of generating and verifying a CACTI rate-proof is less than 0.25 sec, while CACTI's bandwidth overhead is over 98% lower than that of current CAPTCHA systems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 23eaa084-639e-4d69-856d-9aecd22afd32Cited by top-tier papers3
- Scrappy: SeCure Rate Assuring Protocol with PrivacYKosei Akama, Yoshimichi Nakatsuka, Masaaki Sato, Keisuke UeharaNDSS 2024
- Are CAPTCHAs Still Bot-hard? Generalized Visual CAPTCHA Solving with Agentic Vision Language ModelXiwen Teoh, Yun Lin, Siqi Li, Ruofan Liu et al.USENIX Security 2025
- VICEROY: GDPR-/CCPA-compliant Enforcement of Verifiable Accountless Consumer RequestsScott Jordan, Yoshimichi Nakatsuka, Ercan Ozturk, Andrew Paverd et al.NDSS 2023
Builds on4
- EnclaveDB: A Secure Database Using SGXChristian Priebe, Kapil Vaswani, Manuel CostaS&P 2018 · 329 citations
- EverCrypt: A Fast, Verified, Cross-Platform Cryptographic ProviderJonathan Protzenko, Bryan Parno, Aymeric Fromherz, Chris Hawblitzel et al.S&P 2020 · 114 citations
- Fidelius: Protecting User Secrets from Compromised BrowsersSaba Eskandarian, Jonathan Cogan, Sawyer Birnbaum, Peh Chang Wei Brandon et al.S&P 2019 · 55 citations
- Presence Attestation: The Missing Link in Dynamic Trust BootstrappingZhangkai Zhang, Xuhua Ding, Gene Tsudik, Jinhua Cui et al.CCS 2017 · 16 citations
Related papers
- BITE: Bitcoin Lightweight Client Privacy using Trusted ExecutionSinisa Matetic, Karl Wüst, Moritz Schneider, Kari Kostiainen et al.USENIX Security 2019 · 109 citations
- Horizontal Privilege Escalation in Trusted ApplicationsDarius Suciu, Stephen E. McLaughlin, Laurent Simon, Radu SionUSENIX Security 2020
- ACAI: Protecting Accelerator Execution with Arm Confidential Computing ArchitectureSupraja Sridhara, Andrin Bertschi, Benedict Schlüter, Mark Kuhne et al.USENIX Security 2024 · 36 citations
- Hardware-Backed Heist: Extracting ECDSA Keys from Qualcomm's TrustZoneKeegan RyanCCS 2019 · 90 citations
- SoK: Analysis of Accelerator TEE DesignsChenxu Wang, Junjie Huang, Yujun Liang, Xuanyao Peng et al.NDSS 2026 · 2 citations
