论文标题

不仅仅是好密码吗?关于基于风险的身份验证的可用性和安全性看法的研究

More Than Just Good Passwords? A Study on Usability and Security Perceptions of Risk-based Authentication

论文作者

Wiefling, Stephan, Dürmuth, Markus, Iacono, Luigi Lo

论文摘要

基于风险的身份验证(RBA)是一种适应性的安全措施,可增强基于密码的身份验证。 RBA在登录过程中监视其他功能,并且当观察到的特征值与以前所见的特征值显着不同时,用户必须提供其他身份验证因素,例如验证代码。 RBA有可能提供更多可用的身份验证,但是对RBA的可用性和安全看法却没有很好地研究。 我们介绍了一项组间实验室研究(n = 65)的结果,以评估两个RBA变体的可用性和安全感知,一个2FA变体和仅密码的身份验证。我们的研究表明,结果表明,RBA被认为比研究的2FA变体更可用,而它比一般的纯密码身份验证更安全,并且在各种应用程序类型中对2FA的安全性更高。我们还观察到了RBA可用性问题,并提供了缓解建议。我们的贡献提供了对用户对RBA的看法的更深入的了解,并有助于改善RBA实施,以获得更广泛的用户接受。

Risk-based Authentication (RBA) is an adaptive security measure to strengthen password-based authentication. RBA monitors additional features during login, and when observed feature values differ significantly from previously seen ones, users have to provide additional authentication factors such as a verification code. RBA has the potential to offer more usable authentication, but the usability and the security perceptions of RBA are not studied well. We present the results of a between-group lab study (n=65) to evaluate usability and security perceptions of two RBA variants, one 2FA variant, and password-only authentication. Our study shows with significant results that RBA is considered to be more usable than the studied 2FA variants, while it is perceived as more secure than password-only authentication in general and comparably secure to 2FA in a variety of application types. We also observed RBA usability problems and provide recommendations for mitigation. Our contribution provides a first deeper understanding of the users' perception of RBA and helps to improve RBA implementations for a broader user acceptance.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源