Aplikacja zasad Design Thinking w kryptografii
| dc.contributor.author | Kuraś, Paweł | |
| dc.contributor.author | Turek, Anna | |
| dc.contributor.author | Gacek, Maciej | |
| dc.contributor.editor | Lizak, Jadwiga (red.) | |
| dc.contributor.editor | Sidor, Maria Wanda (red.) | |
| dc.date.accessioned | 2026-08-25T12:47:12Z | |
| dc.date.issued | 2025 | |
| dc.description.abstract | Współczesne systemy kryptograficzne, mimo wysokiego poziomu zaawansowania matematycznego, często zawodzą na płaszczyźnie interakcji z użytkownikiem końcowym (Human-Computer Interaction). Celem niniejszego artykułu jest analiza możliwości zastosowania metodologii Design Thinking w procesie projektowania bezpiecznych narzędzi cyfrowych. W pracy postawiono tezę, że uwzględnienie perspektywy użytkownika na wczesnym etapie projektowania (security by design) przy użyciu narzędzi empatyzacji i prototypowania, znacząco podnosi realny poziom bezpieczeństwa systemów IT. W części badawczej przeprowadzono eksperyment z udziałem grupy testowej (N=30), mający na celu zaprojektowanie interfejsu zarządzania kluczami kryptograficznymi zgodnie z pięcioetapowym procesem Design Thinking. Wyniki wskazują, że podejście zorientowane na człowieka redukuje liczbę błędów krytycznych popełnianych przez użytkowników oraz zwiększa zrozumienie mechanizmów zabezpieczeń. Artykuł omawia również bariery we wdrażaniu interdyscyplinarnego podejścia łączącego inżynierię bezpieczeństwa z projektowaniem User Experience (UX). | pl |
| dc.description.abstract | Modern cryptographic systems, despite their high level of mathematical sophistication, often fail in terms of Human-Computer Interaction (HCI). The aim of this paper is to analyze the applicability of Design Thinking methodology in the process of designing secure digital tools. The paper posits that incorporating the user’s perspective at an early design stage (security by design) using empathizing and prototyping tools significantly increases the real security level of IT systems. The research section describes an experiment involving a test group aimed at designing a cryptographic key management interface following the five-stage Design Thinking process. The results indicate that a human-centric approach reduces the number of critical errors made by users and enhances the understanding of security mechanisms. The article also discusses barriers to implementing an interdisciplinary approach combining security engineering with User Experience (UX) design. | en_US |
| dc.identifier.citation | Kuraś, P., Turek, A., Gacek, M. (2025). Aplikacja zasad Design Thinking w kryptografii. W: J. Lizak, M. W. Sidor (red.), Nowe wyzwania w naukach społecznych i technicznych: podejście interdyscyplinarne (t. 2) (s. 1-). Wydawnictwo WSB-NLU. | |
| dc.identifier.doi | 10.66935/978-83-65926-17-3.21 | |
| dc.identifier.isbn | 978-83-65926-17-3 | |
| dc.identifier.uri | https://repozytorium.wsb-nlu.edu.pl/handle/11199/11424 | |
| dc.language.iso | pl | |
| dc.publisher | Wydawnictwo WSB-NLU | |
| dc.relation.ispartof | Nowe wyzwania w naukach społecznych i technicznych: podejście interdyscyplinarne | |
| dc.relation.references | Acquisti, A., Grossklags, J. (2005). Privacy and Rationality in Individual Decision Making. IEEE Security & Privacy, 3(1), 26-33. https://doi.org/10.1109/MSP.2005.22 | |
| dc.relation.references | Adams, A., Sasse, M. A. (1999). Users Are Not the Enemy. Communications of the ACM, 42(12), 40-46. https://doi.org/10.1145/322796.322806 | |
| dc.relation.references | Anderson, R. (2001). Why Information Security is Hard – An Economic Perspective. Annual Computer Security Applications Conference (ACSAC), 358-365. https://doi.org/10.1109/ACSAC.2001.991552 | |
| dc.relation.references | Bonneau, J., Herley, C., van Oorschot P. C., Stajano, F. (2012). The Quest to Replace Passwords: A Framework for Comparative Evaluation of Web Authentication Schemes, IEEE Symposium on Security and Privacy, 553-567. https://doi.org/10.1109/SP.2012.44 | |
| dc.relation.references | Cohn-Gordon, K., Cremers, C., Dowling, B., Garratt, L., Stebila, D. (2017). A Formal Security Analysis of the Signal Messaging Protocol. IEEE European | |
| dc.relation.references | Dhamija, R., Tygar, J. D., Hearst, M. A. (2006). Why Phishing Works. Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, 581-590. https://doi.org/10.1145/1124772.1124861 | |
| dc.relation.references | Diffie, W., Hellman, M. E. (1976). New Directions in Cryptography. IEEE Transactions on Information Theory, 22(6), 644-654. https://doi.org/10.1109/TIT.1976.1055638 | |
| dc.relation.references | Fahl, S., Harbach, M., Muders, T., Baumgartner, L., Freisleben, B., Smith, M. (2012). Why Eve and Mallory Love Android: An Analysis of Android SSL (In)Security. Proceedings of the 2012 ACM conference on Computer and communications security, 50-61. https://doi.org/10.1145/2382196.2382205 | |
| dc.relation.references | Garfinkel, S. L., Miller, R. C. (2005). Johnny 2: A User Test of Key Continuity Management with S/MIME and Outlook Express. Proceedings of the 2005 symposium on Usable privacy and security, 13-24. https://doi.org/10.1145/1073001.1073003 | |
| dc.relation.references | Herley, C. (2009). So Long, And No Thanks for the Externalities: The Rational Rejection of Security Advice by Users. Proceedings of the 2009 workshop on New security paradigms workshop, 133-144. https://doi.org/10.1145/1719030.1719050 | |
| dc.relation.references | Kahneman, D. (2012). Thinking, Fast and Slow. Penguin Books. | |
| dc.relation.references | Kerckhoffs, A. (1883). La Cryptographie Militaire. Journal des Sciences Militaires, 9, 5-38. https://petitcolas.net/kerckhoffs/crypto_militaire_1.pdf | |
| dc.relation.references | Miller, G. A. (1956). The Magical Number Seven, Plus or Minus Two: Some Limits on Our Capacity for Processing Information. Psychological Review, 63(2), 81-97. http://dx.doi.org/10.1037/h0043158 | |
| dc.relation.references | Norman, D. A. (1988). The Design of Everyday Things. Basic Books. | |
| dc.relation.references | Rivest, R. L., Shamir, A., Adleman, L. (1978). A Method for Obtaining Digital Signatures and Public-Key Cryptosystems. Communications of the ACM, 21(2), 120-126. https://doi.org/10.1145/359340.359342 | |
| dc.relation.references | Schneier, B. (2004). Secrets and Lies: Digital Security in a Networked World. Wiley. | |
| dc.relation.references | Shannon, C. E. (1948). A Mathematical Theory of Communication. Bell System Technical Journal, 27, 379-423. http://dx.doi.org/10.1002/j.1538-7305.1948.tb01338.x | |
| dc.relation.references | Whitten, A., Tygar, J. D. (1999). Why Johnny Can't Encrypt: A Usability Evaluation of PGP 5.0. Proceedings of the 8th USENIX Security Symposium, 169-184 https://people.eecs.berkeley.edu/~tygar/papers/Why_Johnny_Cant_Encrypt/OReilly.pdf | |
| dc.relation.references | Yee, K.-P. (2002). User Interaction Design for Secure Systems. Proceedings of the 4th. International Conference on Information and Communications Security, 278-290. https://doi.org/10.1007/3-540-36159-6_24 | |
| dc.rights | http://purl.org/coar/access_right/c_abf2 | |
| dc.subject | Design Thinking | pl |
| dc.subject | kryptografia | pl |
| dc.subject | użyteczność | pl |
| dc.subject | User Experience | pl |
| dc.subject | bezpieczeństwo informacji | pl |
| dc.subject | Design Thinking | en_US |
| dc.subject | cryptography | en_US |
| dc.subject | usability | en_US |
| dc.subject | User Experience | en_US |
| dc.subject | information security | en_US |
| dc.title | Aplikacja zasad Design Thinking w kryptografii | |
| dc.title.alternative | Application of Design Thinking principles in Cryptography | en_US |
| dc.type | Book chapter |
Pliki
Oryginalne pliki
1 - 1 z 1
Ładowanie...
- Nazwa:
- P. Kuraś, A. Turek, M. Gacek, Aplikacja zasad Design Thinking w kryptografii.pdf
- Rozmiar:
- 942.63 KB
- Format:
- Adobe Portable Document Format
Licencja
1 - 1 z 1
Ładowanie...
- Nazwa:
- license.txt
- Rozmiar:
- 3.52 KB
- Format:
- Item-specific license agreed upon to submission
- Opis:
