Ładowanie...

Aplikacja zasad Design Thinking w kryptografii

dc.contributor.authorKuraś, Paweł
dc.contributor.authorTurek, Anna
dc.contributor.authorGacek, Maciej
dc.contributor.editorLizak, Jadwiga (red.)
dc.contributor.editorSidor, Maria Wanda (red.)
dc.date.accessioned2026-08-25T12:47:12Z
dc.date.issued2025
dc.description.abstractWspółczesne systemy kryptograficzne, mimo wysokiego poziomu zaawansowania matematycznego, często zawodzą na płaszczyźnie interakcji z użytkownikiem końcowym (Human-Computer Interaction). Celem niniejszego artykułu jest analiza możliwości zastosowania metodologii Design Thinking w procesie projektowania bezpiecznych narzędzi cyfrowych. W pracy postawiono tezę, że uwzględnienie perspektywy użytkownika na wczesnym etapie projektowania (security by design) przy użyciu narzędzi empatyzacji i prototypowania, znacząco podnosi realny poziom bezpieczeństwa systemów IT. W części badawczej przeprowadzono eksperyment z udziałem grupy testowej (N=30), mający na celu zaprojektowanie interfejsu zarządzania kluczami kryptograficznymi zgodnie z pięcioetapowym procesem Design Thinking. Wyniki wskazują, że podejście zorientowane na człowieka redukuje liczbę błędów krytycznych popełnianych przez użytkowników oraz zwiększa zrozumienie mechanizmów zabezpieczeń. Artykuł omawia również bariery we wdrażaniu interdyscyplinarnego podejścia łączącego inżynierię bezpieczeństwa z projektowaniem User Experience (UX).pl
dc.description.abstractModern cryptographic systems, despite their high level of mathematical sophistication, often fail in terms of Human-Computer Interaction (HCI). The aim of this paper is to analyze the applicability of Design Thinking methodology in the process of designing secure digital tools. The paper posits that incorporating the user’s perspective at an early design stage (security by design) using empathizing and prototyping tools significantly increases the real security level of IT systems. The research section describes an experiment involving a test group aimed at designing a cryptographic key management interface following the five-stage Design Thinking process. The results indicate that a human-centric approach reduces the number of critical errors made by users and enhances the understanding of security mechanisms. The article also discusses barriers to implementing an interdisciplinary approach combining security engineering with User Experience (UX) design.en_US
dc.identifier.citationKuraś, P., Turek, A., Gacek, M. (2025). Aplikacja zasad Design Thinking w kryptografii. W: J. Lizak, M. W. Sidor (red.), Nowe wyzwania w naukach społecznych i technicznych: podejście interdyscyplinarne (t. 2) (s. 1-). Wydawnictwo WSB-NLU.
dc.identifier.doi10.66935/978-83-65926-17-3.21
dc.identifier.isbn978-83-65926-17-3
dc.identifier.urihttps://repozytorium.wsb-nlu.edu.pl/handle/11199/11424
dc.language.isopl
dc.publisherWydawnictwo WSB-NLU
dc.relation.ispartofNowe wyzwania w naukach społecznych i technicznych: podejście interdyscyplinarne
dc.relation.referencesAcquisti, A., Grossklags, J. (2005). Privacy and Rationality in Individual Decision Making. IEEE Security & Privacy, 3(1), 26-33. https://doi.org/10.1109/MSP.2005.22
dc.relation.referencesAdams, A., Sasse, M. A. (1999). Users Are Not the Enemy. Communications of the ACM, 42(12), 40-46. https://doi.org/10.1145/322796.322806
dc.relation.referencesAnderson, R. (2001). Why Information Security is Hard – An Economic Perspective. Annual Computer Security Applications Conference (ACSAC), 358-365. https://doi.org/10.1109/ACSAC.2001.991552
dc.relation.referencesBonneau, J., Herley, C., van Oorschot P. C., Stajano, F. (2012). The Quest to Replace Passwords: A Framework for Comparative Evaluation of Web Authentication Schemes, IEEE Symposium on Security and Privacy, 553-567. https://doi.org/10.1109/SP.2012.44
dc.relation.referencesCohn-Gordon, K., Cremers, C., Dowling, B., Garratt, L., Stebila, D. (2017). A Formal Security Analysis of the Signal Messaging Protocol. IEEE European
dc.relation.referencesDhamija, R., Tygar, J. D., Hearst, M. A. (2006). Why Phishing Works. Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, 581-590. https://doi.org/10.1145/1124772.1124861
dc.relation.referencesDiffie, W., Hellman, M. E. (1976). New Directions in Cryptography. IEEE Transactions on Information Theory, 22(6), 644-654. https://doi.org/10.1109/TIT.1976.1055638
dc.relation.referencesFahl, S., Harbach, M., Muders, T., Baumgartner, L., Freisleben, B., Smith, M. (2012). Why Eve and Mallory Love Android: An Analysis of Android SSL (In)Security. Proceedings of the 2012 ACM conference on Computer and communications security, 50-61. https://doi.org/10.1145/2382196.2382205
dc.relation.referencesGarfinkel, S. L., Miller, R. C. (2005). Johnny 2: A User Test of Key Continuity Management with S/MIME and Outlook Express. Proceedings of the 2005 symposium on Usable privacy and security, 13-24. https://doi.org/10.1145/1073001.1073003
dc.relation.referencesHerley, C. (2009). So Long, And No Thanks for the Externalities: The Rational Rejection of Security Advice by Users. Proceedings of the 2009 workshop on New security paradigms workshop, 133-144. https://doi.org/10.1145/1719030.1719050
dc.relation.referencesKahneman, D. (2012). Thinking, Fast and Slow. Penguin Books.
dc.relation.referencesKerckhoffs, A. (1883). La Cryptographie Militaire. Journal des Sciences Militaires, 9, 5-38. https://petitcolas.net/kerckhoffs/crypto_militaire_1.pdf
dc.relation.referencesMiller, G. A. (1956). The Magical Number Seven, Plus or Minus Two: Some Limits on Our Capacity for Processing Information. Psychological Review, 63(2), 81-97. http://dx.doi.org/10.1037/h0043158
dc.relation.referencesNorman, D. A. (1988). The Design of Everyday Things. Basic Books.
dc.relation.referencesRivest, R. L., Shamir, A., Adleman, L. (1978). A Method for Obtaining Digital Signatures and Public-Key Cryptosystems. Communications of the ACM, 21(2), 120-126. https://doi.org/10.1145/359340.359342
dc.relation.referencesSchneier, B. (2004). Secrets and Lies: Digital Security in a Networked World. Wiley.
dc.relation.referencesShannon, C. E. (1948). A Mathematical Theory of Communication. Bell System Technical Journal, 27, 379-423. http://dx.doi.org/10.1002/j.1538-7305.1948.tb01338.x
dc.relation.referencesWhitten, A., Tygar, J. D. (1999). Why Johnny Can't Encrypt: A Usability Evaluation of PGP 5.0. Proceedings of the 8th USENIX Security Symposium, 169-184 https://people.eecs.berkeley.edu/~tygar/papers/Why_Johnny_Cant_Encrypt/OReilly.pdf
dc.relation.referencesYee, K.-P. (2002). User Interaction Design for Secure Systems. Proceedings of the 4th. International Conference on Information and Communications Security, 278-290. https://doi.org/10.1007/3-540-36159-6_24
dc.rightshttp://purl.org/coar/access_right/c_abf2
dc.subjectDesign Thinkingpl
dc.subjectkryptografiapl
dc.subjectużytecznośćpl
dc.subjectUser Experiencepl
dc.subjectbezpieczeństwo informacjipl
dc.subjectDesign Thinkingen_US
dc.subjectcryptographyen_US
dc.subjectusabilityen_US
dc.subjectUser Experienceen_US
dc.subjectinformation securityen_US
dc.titleAplikacja zasad Design Thinking w kryptografii
dc.title.alternativeApplication of Design Thinking principles in Cryptographyen_US
dc.typeBook chapter

Pliki

Oryginalne pliki

Teraz wyświetlane 1 - 1 z 1
Ładowanie...
Nazwa:
P. Kuraś, A. Turek, M. Gacek, Aplikacja zasad Design Thinking w kryptografii.pdf
Rozmiar:
942.63 KB
Format:
Adobe Portable Document Format

Licencja

Teraz wyświetlane 1 - 1 z 1
Ładowanie...
Nazwa:
license.txt
Rozmiar:
3.52 KB
Format:
Item-specific license agreed upon to submission
Opis: