"Too Taxing on the Mind!" Authentication Grids are not for Everyone

"Too Taxing on the Mind!" Authentication Grids are not for Everyone
复制标题

“太费脑子了!”

DOI:
--
复制
发表时间:
2015
期刊:
Interacción
影响因子:
--
通讯作者:
Angela Sasse
Angela Sasse
中科院分区:
--
文献类型:
--
作者:
Kat Krol;C. Papanicolaou;A. Vernitski;Angela Sasse

文献摘要

被引文献

相似文献

与密码相关的安全性和可用性问题鼓励了大量替代身份验证方案的开发。这些方案旨在提供更强大和/或更可用的身份验证,但开发人员很难预测用户将如何使用这些方案并对其做出反应。我们介绍了一个一次性密码输入方法的案例研究,该方法称为Vernitski身份验证网格VAG,它要求用户通过查找包含字符的行和列的交点并从该交点输入字符,从而以字符对的形式输入密码。我们进行了一个实验室用户评估ni¾* * =i¾ź36,发现认证平均花费88.6i¾źs,登录时间随着实践而减少。参与者在平板电脑上的身份验证速度比在个人电脑上快。总的来说,参与者发现使用网格复杂且耗时。他们表示愿意使用它取决于使用的背景,大多数参与者认为它适合访问不经常使用和高风险的帐户和系统。在使用网格时,36名参与者中有31人用手指或鼠标指向字符、行和列,这破坏了VAG旨在提供的肩部冲浪保护。我们的研究结果表明,不可能有一刀切的密码替代品——可用性和安全性只能通过设计适合特定使用环境的方案来实现。
The security and usability issues associated with passwords have encouraged the development of a plethora of alternative authentication schemes. These aim to provide stronger and/or more usable authentication, but it is hard for the developers to anticipate how users will perform with and react to such schemes. We present a case study of a one-time password entry method called the Vernitski Authentication Grid VAG, which requires users to enter their password in pairs of characters by finding where the row and the column containing the characters intersect and entering the character from this intersection. We conducted a laboratory user evaluation ni¾ź=i¾ź36 and found that authentication took 88.6i¾źs on average, with login times decreasing with practice. Participants were faster authenticating on a tablet than on a PC. Overall, participants found using the grid complex and time-consuming. Their stated willingness to use it depended on the context of use, with most participants considering it suitable for accessing infrequently used and high-stakes accounts and systems. While using the grid, 31 out of 36 participants pointed at the characters, rows and columns with their fingers or mouse, which undermines the shoulder-surfing protection that the VAG is meant to offer. Our results demonstrate there cannot be a one-size-fits-all replacement for passwords --- usability and security can only be achieved through schemes designed to fit a specific context of use.