A conceptual framework for evaluating usable security in authentication mechanisms - usability perspectives

A conceptual framework for evaluating usable security in authentication mechanisms - usability perspectives
复制标题

用于评估身份验证机制中可用安全性的概念框架 - 可用性视角

DOI:
--
复制
发表时间:
2011
期刊:
International Conference on Network and System Security
影响因子:
--
通讯作者:
B. Jerman
B. Jerman
中科院分区:
--
文献类型:
--
作者:
M. Mihajlov;Saso Josimovski;B. Jerman

文献摘要

被引文献

相似文献

在评估这些系统的有效性时,很少有研究关注身份验证机制中的可用性和安全性之间的平衡。当前的大多数身份验证机制都依赖于基于字符的密码,并且有许多替代建议声称可以提高身份验证机制概念的某些可用性。本文提出了一个概念性框架,用于评估认证机制中的可用安全性,目的是通过平衡质量度量来指导给定环境中的可用性和安全性评估过程。该框架定义了质量标准,并根据两个原则进行量化:参与和分类。在之前工作的基础上,我们更详细地关注可用性视角。最后,我们提出了一种数学方法来推导安全系统中可用安全性的总质量分数。
Little research has been focused on the balance between usability and security in authentication mechanisms when evaluating the effectiveness of these systems. Most of the current authentication mechanisms rely on character-based passwords with a number of alternative suggestions claiming to improve some usability aspects of the authentication mechanism concept. This paper presents a conceptual framework for assessing usable security in authentication mechanisms with the purpose of guiding the usability and security evaluation process in a given environment by balancing quality metrics. The framework defines quality criteria which are quantified according to two principles: participation and categorization. Building on previous works we focus on usability perspectives in more detail. To conclude we present a mathematical approach that derives a total quality score for usable security in a security system.