Challenging Challenge Questions: An Experimental Analysis of Authentication Technologies and User Behaviour

Challenging Challenge Questions: An Experimental Analysis of Authentication Technologies and User Behaviour
复制标题

DOI:
10.2202/1944-2866.1013
复制
发表时间:
2010-04-01
影响因子:
4.9
通讯作者:
Aspinall, David
Aspinall, David
中科院分区:
人文科学2区
文献类型:
--
作者:
Just, Mike;Aspinall, David

文献摘要

被引文献

相似文献

为了向系统认证人类用户,通常使用基于个人信息的质询问题,通常是在忘记诸如密码之类的主要认证凭证时。这应该是一个值得信赖的机制,既可靠又准确:个人信息应该是固有的难忘的,不为他人所知。然而,最近有人对这些假设提出了关切:例如,一些常用的问题可能是基于公开的信息。因此,一个可能的改进是允许用户选择自己的问题。在这里,我们报告一个实验,收集用户选择的问题和随后的安全性和可用性分析。我们的实验本身遵循一种新颖的方法,旨在产生参与者的信任,因此他们诚实地参与。这一方法创新表明,在不必从用户那里收集敏感信息的情况下,进行道德认证实验是可能的。我们的实验揭示了一些令人惊讶的结果。虽然受试者有时似乎意识到安全的必要性,但他们往往“错过了标记”的一个很大的差距;同样,有严重的关注自由选择的问题与自由形式的答案的可用性。这些结果应该提出一些严重的问题,为那些制定政策议程,无论是测试或构建互联网应用程序的身份验证解决方案。
To authenticate human users to systems, challenge questions based on personal information are often used, typically when a primary authentication credential, such as a password, is forgotten. This ought to be a trustworthy mechanism, that is both reliable and accurate: personal information should be inherently memorable and not known to others. However, concerns have been raised recently about these assumptions: for example, some commonly used questions may be based on information that is available publicly. A possible improvement, then, is to allow users to choose their own questions. Here we report on an experiment which gathered user chosen questions and a subsequent security and usability analysis of them. Our experiment itself follows a novel method which is designed to engender the trust of participants, so they participate honestly. This methodological innovation demonstrates that it is possible to perform ethical authentication experiments where sensitive information does not have to be collected from users. Our experiments revealed some surprising results. Although subjects sometimes seemed aware of the need for security, they often 'missed the mark' by a wide margin; similarly, there are serious concerns over the usability of freely chosen questions with free-form answers. These results should raise some serious questions for those setting the policy agenda for either testing or building authentication solutions for Internet applications.