Verifiable one-way file transfer across air gaps with screens, paper and serial cables
Laboratory instrument PCs, industrial workstations and other isolated computers still exchange files through USB storage, a route that security programmes try to close and that leaves no record of what moved. We describe a browser-based system that moves a file from such a machine over channels that are one-way by construction — a screen read by a camera, printed pages read later by any camera, and a serial cable with only the transmit line connected — and that produces a dispatch record signed by the sender and a delivery receipt signed by the receiver, verifiable offline by an open-source tool. The handshake and the two one-way modes are modelled in ProVerif; secrecy, authentication and receipt soundness hold under stated assumptions, and sanity variants that remove each assumption yield the expected attacks. For printed pages, where whole codes are lost to smudges and tears, we show that choosing the spare fountain-coded symbols so that each covers about a third of the source blocks, combined with Gaussian elimination when the peeling decoder stalls, raises recovery of a 30 KB file with 8 of its 48 codes missing from 3% to 91% of trials at about 30% overhead, and of a 150 KB file with 12 codes missing from 4% to 100%. For live camera reading, restricting decoding to the region around the last decoded code reduced delivery time of a 200 KB transfer by about a quarter on a processor slowed to phone speed. We report the limits: the measurements come from one phone and synthetic benchmarks, and the system has had no independent security audit.
Authors
- Taha Bayar (ORCID: https://orcid.org/0009-0009-6247-4985)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-30
- DOI
- https://doi.org/10.5281/zenodo.23064776
- Primary Topic
- User Authentication and Security Systems
- Type
- preprint