The TaPSI Research Framework - A Systematization of Knowledge on Tangible Privacy and Security Interfaces
Authors
Research Background and Problem
-
Problem and Challenges: This paper highlights the lack of a systematic review of research on Tangible Privacy and Security Interfaces (TaPSI). Despite the significant potential of these interfaces to enhance privacy and security management due to their intuitive and physical interaction characteristics, the field lacks unified terminology and definitions. Furthermore, existing studies often focus on specific subfields, lacking cross-domain insights and formalized frameworks, and fail to fully explore the design possibilities and challenges of these interfaces.
-
Significance: The use cases for privacy and security interfaces span multiple domains, including authentication, access control, privacy choice mechanisms, and education, all of which are critical to user privacy and security experiences. Without a systematic review and framework, researchers face difficulties in effectively integrating knowledge or designing innovative solutions.
-
Research Motivation and Related Work: Although there have been individual studies on such interfaces (e.g., smart locks and physical authentication devices), a comprehensive body of knowledge has not yet been established. Additionally, Systematization of Knowledge (SoK) studies related to Human-Computer Interaction (HCI) and Usable Privacy and Security (UPS) provide methodological and thematic references for this research. The literature also emphasizes the need for user-centered privacy and security design to ensure transparency, intuitiveness, and high usability.
Solution
-
Proposed Method and Framework: The paper introduces the first systematic knowledge framework (SoK) for TaPSI, defining unified terminology, research directions, and design space for TaPSI. The framework aims to help researchers identify relevant literature, establish clear research objectives, and design and evaluate TaPSI-based solutions more efficiently.
-
Innovations:
- Introduced the term "TaPSI" and provided a unified definition: "Interfaces existing in physical space and perceivable through tactile and other sensory modalities, designed to help users manage, protect, and understand information privacy and/or security."
- Proposed the "TaPSI Research Framework," which includes conceptual design steps for clarifying research objectives and technical design steps for implementing research projects.
- Mapped out the TaPSI design space, including form factors, materials, interaction modalities, and metaphors.
-
Implementation Steps:
- Conceptualization of Research Objectives: Identify the UPS problem to be addressed, assess the suitability of tangible interfaces, and consult relevant literature to understand existing research.
- Technical Research Design: Design and implement TaPSI based on research objectives, including interface realization, experimental evaluation, and the extraction of theoretical contributions.
- Research Evaluation: Evaluate the effectiveness, design, and functionality of TaPSI through experiments and user studies.
-
Key Techniques: Employ mixed thematic analysis to extract concepts and patterns from existing datasets and summarize hierarchical elements of research, such as technological maturity, form factors, and user group differentiation.
Research Outcomes
-
Specific Outcomes:
- Defined and unified the terminology and definition of TaPSI, clarifying its intersection with privacy and security topics.
- Proposed a design framework detailing how to design, implement, and evaluate TaPSI, including core aspects such as appearance design, user interaction, and metaphor selection.
- Summarized current practices, existing issues, and potential future directions in the field through the analysis of 80 papers.
-
Advantages Over Existing Solutions:
- Provides a cross-domain perspective and systematic approach, integrating fragmented research findings from different privacy and security domains.
- Offers practical design guidelines and evaluation tools, such as a clear design space and recommendations for research method selection.
-
Experimental and Evaluation Results:
- Analysis of 80 papers revealed that most studies lack formalized research objectives, with research designs being predominantly descriptive and lacking experimental and comparative studies.
- Identified various TaPSI applications in UPS domains (e.g., authentication, access control, and user education) and highlighted their potential advantages in intuitiveness, cognitive support, and social interaction.
- Investigated interface implementations based on physical materials and electronic components, uncovering significant diversity in metaphors, shapes, sizes, and interaction modalities.
-
Limitations and Future Research Directions:
-
Limitations:
- The generalizability and granularity of the overall framework require further empirical validation.
- Limited comparative studies between TaPSI and purely digital interfaces, especially outside the UPS domain.
- Insufficient quantitative and causal research in certain areas, such as the relationship between user characteristics and interface preferences.
-
Future Directions:
- Conduct comparative studies of TaPSI and digital solutions across various UPS scenarios.
- Explore the impact of design on cognitive model construction, including usability and user understanding.
- Extend research to hybrid interfaces that combine physical and digital interaction attributes to meet diverse user needs and tasks.
-
Overall, this study provides a formalized framework to guide the research and development of tangible privacy and security interfaces, broadening the research horizon in the field of usable privacy and security.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- How can the concept and terminology of Tangible Privacy and Security Interfaces (TaPSI) be defined and unified?Category: Privacy Experience, Control, and Workflow DesignSimilar questionsarrow_forward
- What key elements does the TaPSI design space include?Category: Privacy Experience, Control, and Workflow DesignSimilar questionsarrow_forward
- How can TaPSI be systematically designed, implemented, and evaluated to improve privacy and security user experience?Category: Privacy Experience, Control, and Workflow DesignSimilar questionsarrow_forward
Practical Problems
1- Users struggle to intuitively manage and understand information privacy and security.Category: Privacy Experience, Control, and Workflow DesignSimilar questionsarrow_forward
- 100%
A Promise Is A Promise: The Effect of Commitment Devices on Computer Security Intentions
CHI '19· Privacy by Design & User Control +2
- 83%
"I'm Surprised So Much is Connected": A Study on Users' Online Account Security Connections
CHI '22· Privacy by Design & User Control +2
- 80%
Leveraging Semantic Transformation to Investigate Password Habits and Their Causes
CHI '18· Privacy by Design & User Control +1
- 80%
A Field Study of Computer-Security Perceptions Using Anti-Virus Customer-Support Chats
CHI '19· Privacy by Design & User Control +1
- 80%
I Don't Even Have to Bother Them!: Using Social Media to Automate the Authentication Ceremony in Secure Messaging
CHI '19· Privacy by Design & User Control +1
- 80%
Understanding and Improving User Adoption and Security Awareness in Password Checkup Services
CHI '25· Passwords & Authentication +1
- 80%
Judging Phishing Under Uncertainty: How Do Users Handle Inaccurate Automated Advice?
CHI '25· Privacy by Design & User Control +1
- 80%
A Visual Exploration of Cybersecurity Concepts
C&C '22· Privacy by Design & User Control +1
- 71%
Development, Evaluation, and Implementation of SEQR -- a Usable Secure QR Code Scanner
CHI '26· Privacy by Design & User Control +2
- 67%
Security During Application Development: an Application Security Expert Perspective
CHI '18· Privacy by Design & User Control +1
Based on Jaccard similarity of research subtopics & professions (≥60%)