A user study of policy creation in a flexible access-control system

A user study of policy creation in a flexible access-control system
复制标题

灵活访问控制系统中策略创建的用户研究

DOI:
10.1145/1357054.1357143
复制
发表时间:
2008
期刊:
Proceedings of the SIGCHI Conference on Human Factors in Computing Systems
影响因子:
--
通讯作者:
Kami Vaniea
Kami Vaniea
中科院分区:
--
文献类型:
--
作者:
Lujo Bauer;L. Cranor;R. Reeder;M. Reiter;Kami Vaniea

文献摘要

被引文献

相似文献

在开发富有表现力和灵活的访问控制语言和系统方面投入了大量精力。然而,几乎没有做过评估这些系统在实际情况下与真实的用户,和一些尝试已经发现和分析的访问控制策略,用户实际上想要实现。我们报告的用户研究中,我们得到理想的访问策略所需的一组用户在办公室环境中的物理安全。我们比较这些理想的政策,用户实际上实现的密钥和基于智能手机的分布式访问控制系统的政策。我们开发了一种方法,使我们能够定量地表明,智能手机系统允许我们的用户更准确,更安全地实现他们的理想政策比他们可以与密钥,我们描述了每个系统的不足之处。
Significant effort has been invested in developing expressive and flexible access-control languages and systems. However, little has been done to evaluate these systems in practical situations with real users, and few attempts have been made to discover and analyze the access-control policies that users actually want to implement. We report on a user study in which we derive the ideal access policies desired by a group of users for physical security in an office environment. We compare these ideal policies to the policies the users actually implemented with keys and with a smartphone-based distributed access-control system. We develop a methodology that allows us to show quantitatively that the smartphone system allowed our users to implement their ideal policies more accurately and securely than they could with keys, and we describe where each system fell short.