User-centered security

User-centered security
复制标题

以用户为中心的安全

DOI:
--
复制
发表时间:
1996
期刊:
New Security Paradigms Workshop
影响因子:
--
通讯作者:
M. Zurko
M. Zurko
中科院分区:
--
文献类型:
--
作者:
M. Zurko

文献摘要

被引文献

相似文献

我们引入以用户为中心的安全性这个术语,指的是以可用性为主要动机或目标的安全模型、机制、系统和软件。我们讨论了可用的安全系统的历史,引用过去的问题和目前的研究。我们开发了三个类别的工作在用户友好的安全:应用可用性测试和技术,以安全系统,开发安全模型和用户友好的系统机制,并考虑用户需求作为一个主要的设计目标,在安全系统开发的开始。我们讨论了我们在以用户为中心的授权方面的工作,这是从基于规则的授权引擎(MAP)开始的,并将继续使用Adage。我们概述了我们迄今为止所吸取的经验教训,以及如何将其应用于我们今后的工作。我们评估的优点和缺点,这方面的努力,作为进一步工作的先驱,在这方面,包括我们目前的工作在以用户为中心的授权的简要描述。正如我们的结论所指出的那样,我们希望在未来看到更多以用户为中心的安全工作;使用户能够选择和使用他们想要的保护,符合他们对安全和隐私的直觉,并支持团队和组织需要的策略并使用它们来完成工作。二.安全软件中的可用性关键字以用户为中心,安全性,授权
We introduce the term user-centered security to refer to security models, mechanisms, systems, and software that have usability as a primary motivation or goal. We discuss the history of usable secure systems, citing both past problems and present studies. We develop three categories for work in user-friendly security: applying usability testing and techniques to secure systems, developing security models and mechanisms for user-friendly systems, and considering user needs as a primary design goal at the start of secure system development. We discuss our work on user-centered authorization, which started with a rules-based authorization engine (MAP) and will continue with Adage. We outline the lessons we have learned to date and how they apply to our future work. We evaluate the pros and cons of this effort, as a precursor to further work in this area, and include a brief description of our current work in user-centered authorization. As our conclusion points out, we hope to see more work in user-centered security in the future; work that enables users to choose and use the protection they want, that matches their intuitions about security and privacy, and that supports the policies that teams and organizations need and use to get their work done. II. USABILITY IN SECURE SOFTWARE Keywordsuser-centered, security, authorization