A Qualitative Study of Adoption Barriers and Challenges for Passwordless Authentication in German Public Administrations
Authors
Research Background and Issues
What problems or challenges did the authors identify?
- Public administration departments handle sensitive citizen data, making them targets for cyberattacks such as phishing and data breaches.
- Despite national investments in digital infrastructure, the public sector faces unique organizational and technical challenges, such as hierarchical structures and lack of technical resources.
- The insecurity of password-based authentication methods urgently calls for advanced alternatives, yet the application of passwordless authentication in public administration remains limited, with insufficient research on its applicability and demand in this domain.
Why is this issue important?
- The digital security of the public sector impacts not only individual institutions but also the security of national infrastructure.
- Phishing attacks and human errors are primary causes of security incidents in the public sector, and existing security frameworks are inadequate to address these challenges.
- Passwordless authentication (e.g., FIDO2) has potential in preventing phishing attacks and password leaks, but its acceptance and implementation effectiveness in the public sector remain unclear.
Research Motivation and Related Work
- The motivation for this research is to explore the feasibility, barriers, and potential benefits of deploying passwordless authentication in the unique environment of the public sector.
- Related work indicates high acceptance of passwordless authentication in enterprises and the private sector, but the public sector has not been thoroughly investigated.
Solutions
What methods or solutions did the authors propose?
- Employing a mixed research approach, including online surveys and field experiments.
- Assessing public sector employees' perceptions and experiences with passwordless authentication through surveys.
- Observing user behavior in real work environments using FIDO2 and TOTP methods during experiments.
What are the innovative aspects of this solution?
- Focusing the research specifically on the public administration sector, addressing a gap in existing studies.
- Offering a comprehensive data collection approach, including user experiments and follow-up interviews, to deeply understand psychological and practical barriers to technology adoption.
What are the implementation steps? What key technologies were used?
- Online Survey: Distributing questionnaires to 108 employees in the German public sector to gather insights into their perceptions and experiences with passwordless authentication.
- Field Experiment:
- Providing FIDO2 hardware tokens (e.g., YubiKey) and authentication methods (e.g., Windows Hello and TOTP).
- Conducting a two-week test in actual work scenarios to observe user performance during authentication processes.
- Collecting login metadata to measure habituation effects.
- Interviews: Conducting semi-structured interviews post-experiment to gather detailed feedback on users' experiences and opinions regarding passwordless methods.
Research Outcomes
What specific results were achieved?
- Survey Findings:
- Only 35% of survey participants had used passwordless authentication at work, with TOTP being the most commonly known method.
- Most participants were knowledgeable about malware and phishing but lacked awareness of advanced security mechanisms like Windows Hello or challenge-response authentication.
- Experimental Results:
- FIDO2 methods received high overall evaluations, particularly the ease of use of hardware tokens like YubiKey.
- Despite misunderstandings, such as mistaking YubiKey's touch sensor for fingerprint recognition, users generally considered these methods more secure.
- Login times showed significant habituation effects, with average login times decreasing from 10 seconds to 6 seconds.
What advantages does it have compared to existing solutions?
- Passwordless authentication eliminates the need to remember passwords, enhancing both convenience and security in authentication processes.
- FIDO2's phishing resistance and security performance were positively evaluated by participants.
- The study directly observed the psychological models and workflows of public sector employees, uncovering deployment challenges.
Limitations and Future Directions
- Limitations:
- Voluntary participation introduced selection bias, making the sample not fully representative of the German public sector.
- Recruitment involved extensive organizational procedures, affecting participant numbers.
- Technical constraints (e.g., outdated devices and software policies) limited the use of certain methods like TOTP and Windows Hello.
- Future Directions:
- Investigating how policymakers can improve regulations to support passwordless authentication technologies.
- Conducting comparative studies with countries that have higher levels of digitalization to gain cross-national perspectives.
- Performing direct comparative experiments between public and private sectors.
Conclusion
This study is the first to focus on the experiences and acceptance of passwordless authentication among employees in the German public sector, uncovering unique technical and organizational challenges. The findings demonstrate that these methods offer strong security and user experience but are constrained by policy and technical limitations. Future research should explore how to optimize policy and technical environments to better support the application of passwordless authentication technologies in the public sector.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- What are limitations of password authentication in public sector environments?Category: Authentication and Identity SecuritySimilar questionsarrow_forward
- How do public sector employees perceive and accept passwordless authentication methods such as FIDO2?Category: Authentication and Identity SecuritySimilar questionsarrow_forward
- What practical deployment barriers and advantages do passwordless authentication have in real work scenarios?Category: Authentication and Identity SecuritySimilar questionsarrow_forward
Practical Problems
1- The public sector is vulnerable to phishing and password leakage, and existing authentication methods are insufficiently secure.Category: Authentication and Identity SecuritySimilar questionsarrow_forward
- 60%
Field Evidence of the Effects of Privacy, Data Transparency, and Pro-social Appeals on COVID-19 App Attractiveness
CHI '22· Privacy by Design & User Control +1
- 60%
Tips, Tricks, and Training: Supporting Anti-Phishing Awareness among Mid-Career Office Workers Based on Employees' Current Practices
CHI '23· Privacy Perception & Decision-Making +1
- 60%
Understanding and Improving User Adoption and Security Awareness in Password Checkup Services
CHI '25· Passwords & Authentication +1
Based on Jaccard similarity of research subtopics & professions (≥60%)