A Qualitative Study of Adoption Barriers and Challenges for Passwordless Authentication in German Public Administrations

Passwords & AuthenticationPrivacy Perception & Decision-MakingGovernment Officials & Civil ServantsPrivacy Policy Makers

Research Background and Issues

What problems or challenges did the authors identify?

  • Public administration departments handle sensitive citizen data, making them targets for cyberattacks such as phishing and data breaches.
  • Despite national investments in digital infrastructure, the public sector faces unique organizational and technical challenges, such as hierarchical structures and lack of technical resources.
  • The insecurity of password-based authentication methods urgently calls for advanced alternatives, yet the application of passwordless authentication in public administration remains limited, with insufficient research on its applicability and demand in this domain.

Why is this issue important?

  • The digital security of the public sector impacts not only individual institutions but also the security of national infrastructure.
  • Phishing attacks and human errors are primary causes of security incidents in the public sector, and existing security frameworks are inadequate to address these challenges.
  • Passwordless authentication (e.g., FIDO2) has potential in preventing phishing attacks and password leaks, but its acceptance and implementation effectiveness in the public sector remain unclear.

Research Motivation and Related Work

  • The motivation for this research is to explore the feasibility, barriers, and potential benefits of deploying passwordless authentication in the unique environment of the public sector.
  • Related work indicates high acceptance of passwordless authentication in enterprises and the private sector, but the public sector has not been thoroughly investigated.

Solutions

What methods or solutions did the authors propose?

  • Employing a mixed research approach, including online surveys and field experiments.
  • Assessing public sector employees' perceptions and experiences with passwordless authentication through surveys.
  • Observing user behavior in real work environments using FIDO2 and TOTP methods during experiments.

What are the innovative aspects of this solution?

  • Focusing the research specifically on the public administration sector, addressing a gap in existing studies.
  • Offering a comprehensive data collection approach, including user experiments and follow-up interviews, to deeply understand psychological and practical barriers to technology adoption.

What are the implementation steps? What key technologies were used?

  1. Online Survey: Distributing questionnaires to 108 employees in the German public sector to gather insights into their perceptions and experiences with passwordless authentication.
  2. Field Experiment:
    • Providing FIDO2 hardware tokens (e.g., YubiKey) and authentication methods (e.g., Windows Hello and TOTP).
    • Conducting a two-week test in actual work scenarios to observe user performance during authentication processes.
    • Collecting login metadata to measure habituation effects.
  3. Interviews: Conducting semi-structured interviews post-experiment to gather detailed feedback on users' experiences and opinions regarding passwordless methods.

Research Outcomes

What specific results were achieved?

  • Survey Findings:
    • Only 35% of survey participants had used passwordless authentication at work, with TOTP being the most commonly known method.
    • Most participants were knowledgeable about malware and phishing but lacked awareness of advanced security mechanisms like Windows Hello or challenge-response authentication.
  • Experimental Results:
    • FIDO2 methods received high overall evaluations, particularly the ease of use of hardware tokens like YubiKey.
    • Despite misunderstandings, such as mistaking YubiKey's touch sensor for fingerprint recognition, users generally considered these methods more secure.
    • Login times showed significant habituation effects, with average login times decreasing from 10 seconds to 6 seconds.

What advantages does it have compared to existing solutions?

  • Passwordless authentication eliminates the need to remember passwords, enhancing both convenience and security in authentication processes.
  • FIDO2's phishing resistance and security performance were positively evaluated by participants.
  • The study directly observed the psychological models and workflows of public sector employees, uncovering deployment challenges.

Limitations and Future Directions

  • Limitations:
    • Voluntary participation introduced selection bias, making the sample not fully representative of the German public sector.
    • Recruitment involved extensive organizational procedures, affecting participant numbers.
    • Technical constraints (e.g., outdated devices and software policies) limited the use of certain methods like TOTP and Windows Hello.
  • Future Directions:
    • Investigating how policymakers can improve regulations to support passwordless authentication technologies.
    • Conducting comparative studies with countries that have higher levels of digitalization to gain cross-national perspectives.
    • Performing direct comparative experiments between public and private sectors.

Conclusion

This study is the first to focus on the experiences and acceptance of passwordless authentication among employees in the German public sector, uncovering unique technical and organizational challenges. The findings demonstrate that these methods offer strong security and user experience but are constrained by policy and technical limitations. Future research should explore how to optimize policy and technical environments to better support the application of passwordless authentication technologies in the public sector.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/188703/2025

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://dl.acm.org/doi/10.1145/3706598.3713252
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2025
emoji_events
Award
No award tagged
group
Authors
4 authors
sell
Subtopics
Passwords & Authentication, Privacy Perception & Decision-Making
work
Professions
Government Officials & Civil Servants, Privacy Policy Makers
article
Content Status
Full text indexed
hub
Related Papers
3 related papers