Gamifying authentication

Gamifying authentication
复制标题

游戏化认证

DOI:
10.1109/issa.2012.6320439
复制
发表时间:
2012
期刊:
2012 Information Security for South Africa
影响因子:
--
通讯作者:
M. Olivier
M. Olivier
中科院分区:
--
文献类型:
--
作者:
Christien Kroeze;M. Olivier

文献摘要

参考文献

被引文献

相似文献

安全性和可用性领域经常相互冲突。安全性的重点是使系统难以被攻击者破坏。然而,这样做也增加了用户的难度。安全中的用户通常被视为一个障碍-他们是系统的最薄弱点,愿意绕过安全策略,以便更快地访问他们的工作。安全性的很大一部分是身份验证:知道系统的用户是谁,并拒绝未经身份验证的用户访问。身份验证通常是用户与安全系统交互的起点。不幸的是,身份验证仍然是最常用的基于文本的密码。这通常是最容易和最便宜的系统来实现。大多数网站和服务都建议用户选择独特、复杂和冗长的密码。这些密码对用户来说很难记住,并且经常导致不负责任的行为,例如写下或重复使用密码。严肃游戏是为与纯粹娱乐不同的主要目的而设计的游戏。这个领域包括游戏化,其中非游戏环境通过使用游戏原理来增强。例子包括经验点、成就、进度指标和排行榜。游戏化使用这些工具来说服用户改变他们的行为。如果游戏化可以应用于安全,它可能有助于说服用户采取更安全的行动。本文讨论了将游戏化应用于身份验证的可能性,这是一种提高可用性和安全性的新方法。
The fields of security and usability often conflict with each other. Security focuses on making systems difficult for attackers to compromise. However, doing this also increases difficulty for the user. Users in security are often seen as an obstacle - they are the weakest point of the system, willing to circumvent security policies in order to access their work faster. A large part of security is authentication: knowing who a user of a system is and denying access to unauthenticated users. Authentication is very often the starting point of user interaction with security systems. Unfortunately, authentication is still most commonly achieved using text-based passwords. This is often the easiest and cheapest system to implement. Most websites and services advise users to select unique, complex and lengthy passwords. These passwords are difficult for users to remember and often lead to irresponsible behaviour such as writing down or reusing passwords. Serious games are games that are designed for a different primary purpose than pure entertainment. This field includes gamification, where non-gaming contexts are enhanced by using principles from gaming. Examples include experience points, achievements, progress indicators and leader boards. Gamification uses these tools to persuade users to change their behaviour. If gamification can be applied to security, it may aid in convincing users to act more securely. This paper discusses the possibilities of applying gamification to authentication as a new approach to usability and security.
DOI: 10.1016/j.jrp.2008.09.001
发表时间: 2009-06
影响因子: 3.3
作者:
Niemiec CP;Ryan RM;Deci EL
通讯作者: Deci EL