Usable Security of Authentication Process: New Approach and Practical Assessment

被引:0
|
作者
Althobaiti, Maha M. [1 ]
Mayhew, Pam [1 ]
机构
[1] Univ East Anglia, Sch Comp Sci, Norwich, England
关键词
authentication; security; usability; HCI; E-banking;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Authentication mechanisms are considered the typical method to secure financial websites. Context authentication has become increasingly important in the arena of online banking, which involves sensitive data that belong to users who trust their banks. Multifactor authentication is the most commonly used method of strengthening the log-in process in e-banking. Developing a usable and secure authentication approach and method is the most challenging area for researchers in the fields of security and Human-Computer Interaction (HCI). This paper describes a work-in-progress towards a new approach for authenticating users when access online banking by giving them the opportunity to choose their preferred method to log into e-banking. In our complex experiment with 100 online banking customers, we simulate an original online banking platform based on the proposed approach; then, we evaluate the usability and security of three different methods and assess user awareness of the most visible security design flaws. The initial result shows that the new system model was able to assess the usability and security of different multifactor authentication methods and it is considered a first attempt towards a usable and secure authentication approach.
引用
收藏
页码:179 / 180
页数:2
相关论文
共 50 条
  • [21] Security analysis of a practical "on the fly" authentication and signature generation
    Poupard, G
    Stern, J
    ADVANCES IN CRYPTOLOGY - EUROCRYPT '98, 1998, 1403 : 422 - 436
  • [22] Practical anonymous user authentication scheme with security proof
    Chien, Hung-Yu
    COMPUTERS & SECURITY, 2008, 27 (5-6) : 216 - 223
  • [23] Computer Security Issues in Online Banking: An Assessment from the Context of Usable Security
    Mahmadi, F. N.
    Zaaba, Z. F.
    Osman, A.
    INTERNATIONAL ENGINEERING RESEARCH AND INNOVATION SYMPOSIUM (IRIS), 2016, 160
  • [24] Towards a New Security Approach Based on Heartbeat Authentication to Ensure Security of Cloud Data Access
    Hammami, Hamza
    Brahmi, Hanen
    Ben Yahia, Sadok
    2018 32ND INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING (ICOIN), 2018, : 37 - 43
  • [25] Design and Security Assessment of Usable Multi-factor Authentication and Single Sign-On Solutions for Mobile Applications A Workshop Experience Report
    Carbone, Roberto
    Ranise, Silvio
    Sciarretta, Giada
    PRIVACY AND IDENTITY MANAGEMENT: FAIRNESS, ACCOUNTABILITY, AND TRANSPARENCY IN THE AGE OF BIG DATA, 2019, 547 : 51 - 66
  • [26] Security Enhancement of Pairing and Authentication Process of Bluetooth
    Alam, Md Ariful
    Khan, Mohammad Ibrahim
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2010, 10 (06): : 243 - 249
  • [27] A practical approach to enterprise IT security
    Liu, S.
    Sullivan, J.
    Ormaner, J.
    IT Professional, 2001, 3 (05) : 35 - 42
  • [28] INFORMATION SECURITY - A PRACTICAL APPROACH
    STAPLES, E
    OFFICE ADMINISTRATION AND AUTOMATION, 1985, 46 (01): : 79 - 79
  • [29] PRACTICAL REALIZATIONS IN PROCESS MODELING .1. NEW APPROACH TO PRACTICAL REALIZATION
    JAYARAMAN, K
    LAPIDUS, L
    AICHE JOURNAL, 1976, 22 (02) : 298 - 309
  • [30] Affective Design Approach to Mobile Security Authentication
    Park, Daehee
    Lee, Jaeyong
    Lee, Yenah
    Song, Scott
    HUMAN SYSTEMS ENGINEERING AND DESIGN, IHSED2018, 2019, 876 : 553 - 558