Designing Usable, Yet Secure Authentication Services: A User-Centric Protocol
Abstract
User authentication is a vital and critical service in many modern interactive applications including online banking, commerce, government as well as critical infrastructures protection. Such critical software systems should provide highly secure services for establishing if user access should be granted or not. As it will be highlighted in this paper, there is an intrinsic conflict between creating user authentication services that are secure, yet easy to use by the end-users. Our main goal is to adopt a human-centric approach which consists to study the intimate relationship between usability and security before the user authentication service has been implemented and deployed. We propose a framework that models the usability and security symmetry meaning the security consequences of usability issues. It suggests a novel usable security protocol through an inspection method named Usable Security Symmetry for dealing with usable security of user authentication methods that in turns will guide the development of truly secure and usable user authentication systems. The framework uses NGOMSL (Natural Goals, Methods, and Selection Language) to understand the user cognitive processes involved in user authentication while helping to identify and model the diverse situations of conflict between usability and security attributes.
Keywords: Security Usability, User Authentication, Information Security, Human Computer Interaction.
DOI: 10.54941/ahfe100257
Cite this paper
More from this volume
- Variability Handling in Multi-Mode Service Composition
- A Semi-Automatic Approach for the Integration of Structural Karlstad Enterprise Modeling Schemata
- Model Synchronization in Sociotechnical Service Systems
- Storage in the Cloud: What You Need to Know and Why
- Attitudes and Use of Mobile Phones in Tweens
- User Experience as Service at Social Networking
- UX as a Service
- Social Influence Tagging as a Service for Brand Marketing
- Exploring the Servicelization of Mobile User Interface Evaluation
- Shopping Experience as a Service for On-line Group Purchasing
- A Journey Recommender System Using Crowd Attention Monitoring for Facilitating a Collaborative Visiting Experience
- Group Work: Does It Work?


AHFE Open Access