Exploring User-Centered Security Design for Usable Authentication Ceremonies

被引:11
|
作者
Fassl, Matthias [1 ,2 ]
Grober, Lea Theresa [1 ,2 ]
Krombholz, Katharina [1 ]
机构
[1] CISPA Helmholtz Ctr Informat Secur, Saarbrucken, Germany
[2] Saarland Univ, Saarbrucken, Germany
关键词
Instant Messaging; Man-in-the-Middle (MitM); Authentication; Usability; User-Centered Design;
D O I
10.1145/3411764.3445164
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Security technology often follows a systems design approach that focuses on components instead of users. As a result, the users' needs and values are not sufficiently addressed, which has implications on security usability. In this paper, we report our lessons learned from applying a user-centered security design process to a well-understood security usability challenge, namely key authentication in secure instant messaging. Users rarely perform these key authentication ceremonies, which makes their end-to-end encrypted communication vulnerable. Our approach includes collaborative design workshops, an expert evaluation, iterative storyboard prototyping, and an online evaluation. While we could not demonstrate that our design approach resulted in improved usability or user experience, we found that user-centered prototypes can increase the users' comprehension of security implications. Hence, prototypes based on users' intuitions, needs, and values are useful starting points for approaching long-standing security challenges. Applying complementary design approaches may improve usability and user experience further.
引用
收藏
页数:15
相关论文
共 50 条
  • [21] User-centered design for a voice portal
    Marasek, Krzysztof
    Brocki, Lukasz
    Koržinek, Danijel
    Szklanny, Krzysztof
    Gubrynowicz, Ryszard
    Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2009, 5070 LNCS : 273 - 293
  • [22] User-centered design in universal design resources?
    Chris M. Law
    Paul T. Jaeger
    Elspeth McKay
    Universal Access in the Information Society, 2010, 9 : 327 - 335
  • [23] User-centered design in universal design resources?
    Law, Chris M.
    Jaeger, Paul T.
    McKay, Elspeth
    UNIVERSAL ACCESS IN THE INFORMATION SOCIETY, 2010, 9 (04) : 327 - 335
  • [24] Intergram, an User-centered Design Process
    Losada, Begona
    Martinez, Jabier
    Lopez, David
    CHALLENGES FOR ASSISTIVE TECHNOLOGY, 2007, 20 : 786 - 790
  • [25] User-centered design: Principles to live by
    Trachtman, L
    ASSISTIVE TECHNOLOGY, 1998, 10 (01) : 1 - 2
  • [26] Building a team for user-centered design
    Barnum, CM
    IEEE PROFESSIONAL COMMUNICATION SOCIETY INTERNATIONAL PROFESSIONAL COMMUNICATION CONFERENCE AND ACM SPECIAL INTEREST GROUP ON DOCUMENTATION CONFERENCE, 2000, : 325 - 332
  • [27] Evolving the scope of user-centered design
    Karat, J
    COMMUNICATIONS OF THE ACM, 1997, 40 (07) : 33 - 38
  • [28] User-centered design of web pages
    Yeh, Chung-Hsing
    Lin, Yang-Cheng
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2008, PT 2, PROCEEDINGS, 2008, 5073 : 129 - +
  • [29] User-centered Design Consultation Research
    Liu Ruifen
    PROCEEDINGS OF THE 2008 INTERNATIONAL CONFERENCE ON INDUSTRIAL DESIGN, VOL 2/2, 2008, : 214 - 218
  • [30] USER-CENTERED DESIGN - FOR USERS OR BY USERS
    EASON, KD
    ERGONOMICS, 1995, 38 (08) : 1667 - 1673