Skip to search boxSkip to navigationSkip to main content

Trustworthy exams without trusted parties

  • Giampaolo Bella
    ,
  • Rosario Giustolisi
    ,
  • Gabriele Lenzini
    ,
  • Peter Yvain Anthony Ryan
  • University of Catania
    ,
  • Swedish Institute of Computer Science
    ,
  • University of Luxembourg
Research Output:
Journal Article or Conference Article in Journal
Journal article
Peer-review

Publication Information

Output type

Research Output:
Journal Article or Conference Article in Journal
Journal article
Peer-review

Original language

English

Pages from-to (Number of pages)

Pages 291-307

Journal (Volume, Issue Number)

Computers & Security (Volume 67)

Publication milestones

  • Published - 2017

Publication status

Published - 2017

ISSN

0167-4048

Publication IDs

  • Scopus: 85028234699

Abstract

Historically, exam security has mainly focused on threats ascribed to candidate cheating. Such threats have been normally mitigated by invigilation and anti-plagiarism methods. However, as recent exam scandals confirm, also invigilators and authorities may pose security threats. The introduction of computers into the different phases of an exam, such as candidate registration, brings new security issues that should be addressed with the care normally devoted to security protocols.

This paper proposes a protocol that meets a wide set of security requirements and resists threats that may originate from candidates as well as from exam administrators. By relying on a combination of oblivious transfer and visual cryptography schemes, the protocol does not need to rely on any trusted third party. We analyse the protocol formally in ProVerif and prove that it verifies all the stated security requirements.

Publication metrics

PlumX, opens in new tab

Captures
20
Citations
8