CACTI: Captcha Avoidance via Client-side TEE Integration
Yoshimichi Nakatsuka, Ercan Ozturk, Andrew Paverd, Gene Tsudik
摘要
Preventing abuse of web services by bots is an increasingly important problem, as abusive activities grow in both volume and variety. CAPTCHAs are the most common way for thwarting bot activities. However, they are often ineffective against bots and frustrating for humans. In addition, some recent CAPTCHA techniques diminish user privacy. Meanwhile, client-side Trusted Execution Environments (TEEs) are becoming increasingly widespread (notably, ARM TrustZone and Intel SGX), allowing establishment of trust in a small part (trust anchor or TCB) of client-side hardware. This prompts the question: can a TEE help reduce (or remove entirely) user burden of solving CAPTCHAs? In this paper, we design CACTI: CAPTCHA Avoidance via Client-side TEE Integration. Using client-side TEEs, CACTI allows legitimate clients to generate unforgeable rate-proofs demonstrating how frequently they have performed specific actions. These rate-proofs can be sent to web servers in lieu of solving CAPTCHAs. CACTI provides strong client privacy guarantees, since the information is only sent to the visited website and authenticated using a group signature scheme. Our evaluations show that overall latency of generating and verifying a CACTI rate-proof is less than 0.25 sec, while CACTI's bandwidth overhead is over 98% lower than that of current CAPTCHA systems.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Scrappy: SeCure Rate Assuring Protocol with PrivacYKosei Akama, Yoshimichi Nakatsuka, Masaaki Sato, Keisuke UeharaNDSS 2024
- Are CAPTCHAs Still Bot-hard? Generalized Visual CAPTCHA Solving with Agentic Vision Language ModelXiwen Teoh, Yun Lin, Siqi Li, Ruofan Liu 等USENIX Security 2025
- VICEROY: GDPR-/CCPA-compliant Enforcement of Verifiable Accountless Consumer RequestsScott Jordan, Yoshimichi Nakatsuka, Ercan Ozturk, Andrew Paverd 等NDSS 2023
它引用的顶会 Paper4
- EnclaveDB: A Secure Database Using SGXChristian Priebe, Kapil Vaswani, Manuel CostaS&P 2018 · 被引用 329 次
- EverCrypt: A Fast, Verified, Cross-Platform Cryptographic ProviderJonathan Protzenko, Bryan Parno, Aymeric Fromherz, Chris Hawblitzel 等S&P 2020 · 被引用 114 次
- Fidelius: Protecting User Secrets from Compromised BrowsersSaba Eskandarian, Jonathan Cogan, Sawyer Birnbaum, Peh Chang Wei Brandon 等S&P 2019 · 被引用 55 次
- Presence Attestation: The Missing Link in Dynamic Trust BootstrappingZhangkai Zhang, Xuhua Ding, Gene Tsudik, Jinhua Cui 等CCS 2017 · 被引用 16 次
相关 Paper
- BITE: Bitcoin Lightweight Client Privacy using Trusted ExecutionSinisa Matetic, Karl Wüst, Moritz Schneider, Kari Kostiainen 等USENIX Security 2019 · 被引用 109 次
- Horizontal Privilege Escalation in Trusted ApplicationsDarius Suciu, Stephen E. McLaughlin, Laurent Simon, Radu SionUSENIX Security 2020
- ACAI: Protecting Accelerator Execution with Arm Confidential Computing ArchitectureSupraja Sridhara, Andrin Bertschi, Benedict Schlüter, Mark Kuhne 等USENIX Security 2024 · 被引用 36 次
- Hardware-Backed Heist: Extracting ECDSA Keys from Qualcomm's TrustZoneKeegan RyanCCS 2019 · 被引用 90 次
- SoK: Analysis of Accelerator TEE DesignsChenxu Wang, Junjie Huang, Yujun Liang, Xuanyao Peng 等NDSS 2026 · 被引用 2 次
