SeQR: A User-Friendly and Secure-by-Design Configurator for Enterprise Wi-Fi
S. Mahmudul Hasan, Che Wei Tu, Md. Endadul Hoque, Omar Chowdhury, Sze Yiu Chau
摘要
A classic problem in enterprise Wi-Fi is client-side misconfiguration, which enables credential theft via "Evil Twin" (ET) attacks. To mitigate this, we design, develop, and evaluate a new configurator, SeQR, which allows users to effortlessly and securely set up an enterprise Wi-Fi connection. Utilizing existing authenticated channels, SeQR fully automates the client-side enterprise Wi-Fi configuration process with a simple scan, leaving no room for misconfigurations. Specifically, SeQR thwarts ET by making it impossible for users to opt-out from the security-critical certificate validation. We evaluate the efficacy of SeQR on two fronts. First, we implement a prototype of SeQR in Android, and test its functionality and runtime performance. Next, we compare the usability of SeQR against two existing Wi-Fi configuration interfaces of Android in an in-person user study (n=41) with real devices. Our evaluation shows that SeQR achieves noticeable usability improvements over existing designs, and prevents users from misconfiguring.
• Security and privacy → Usability in security and privacy; • Human-centered computing → User interface programming; Empirical studies in HCI .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper13
- Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2Mathy Vanhoef, Frank PiessensCCS 2017 · 被引用 437 次
- HVLearn: Automated Black-Box Analysis of Hostname Verification in SSL/TLS ImplementationsSuphannee Sivakorn, George Argyros, Kexin Pei, Angelos D. Keromytis 等S&P 2017 · 被引用 88 次
- Release the Kraken: New KRACKs in the 802.11 StandardMathy Vanhoef, Frank PiessensCCS 2018 · 被引用 69 次
- SymCerts: Practical Symbolic Execution for Exposing Noncompliance in X.509 Certificate Validation ImplementationsSze Yiu Chau, Omar Chowdhury, Md. Endadul Hoque, Huangyi Ge 等S&P 2017 · 被引用 67 次
- Informing the Design of Privacy-Empowering Tools for the Connected HomeWilliam Seymour, Martin J. Kraemer, Reuben Binns, Max Van KleekCHI 2020 · 被引用 38 次
相关 Paper
- Assessing certificate validation user interfaces of WPA supplicantsKailong Wang, Yuwei Zheng, Qing Zhang, Guangdong Bai 等MobiCom 2022 · 被引用 10 次
- All your Credentials are Belong to Us: On Insecure WPA2-Enterprise ConfigurationsMan Hong Hue, Joyanta Debnath, Kin Man Leung, Li Li 等CCS 2021 · 被引用 14 次
- Development, Evaluation, and Implementation of SEQR - a Usable Secure QR Code ScannerMattia Mossano, Maxime Fabian Veit, Tobias Länge, Benjamin Maximilian Berens 等CHI 2026 · 被引用 1 次
- AirSnitch: Demystifying and Breaking Client Isolation in Wi-Fi NetworksXin'an Zhou, Juefei Pu, Zhutian Liu, Zhiyun Qian 等NDSS 2026 · 被引用 1 次
- Man-in-the-Middle Attacks without Rogue AP: When WPAs Meet ICMP RedirectsXuewei Feng, Qi Li, Kun Sun, Yuxiang Yang 等S&P 2023
