Exploring User-Centered Security Design for Usable Authentication Ceremonies

Privacy by Design & User ControlPasswords & AuthenticationCybersecurity EngineersAI/ML Researchers & EngineersHCI Researchers

Document Title

Exploring User-Centered Security Design: Usable Authentication Ceremonies

Document Information

  • Subject Area: User Experience Design, Privacy and Security, Cryptographic Authentication
  • Keywords: Instant Messaging, Man-in-the-Middle Attack (MitM), Authentication, Usability, User-Centered Design
  • Conference Published: CHI Conference on Human Factors in Computing Systems (CHI '21)
  • Publication Date: 2021
  • DOI: https://doi.org/10.1145/3411764.3445164

Research Background and Problem

  • Problem Description: Many current security technologies (e.g., key authentication in encrypted messaging apps) require users to actively perform complex and difficult-to-understand tasks, leading to these tasks being ignored or improperly executed, thereby exposing communications to the risk of Man-in-the-Middle (MitM) attacks.
  • Importance: Security authentication ceremonies (e.g., verifying encryption keys) are crucial for ensuring the privacy of end-to-end encrypted communication. However, these ceremonies are often difficult for users to accept and perform, impacting the actual adoption of security tools.
  • Challenges:
    1. Authentication ceremonies lack user-friendliness, being time-consuming and complex.
    2. Users face social and psychological resistance to security technologies (e.g., feelings of awkwardness when asked to authenticate by others).
    3. Most existing designs focus on system components rather than user needs, making it difficult to foster user trust and understanding.
  • Related Work: Previous research has primarily focused on two areas of improvement:
    1. Simplifying the execution of authentication tasks for users.
    2. Removing user involvement through automation. However, this may lead to insufficient user trust in security.

Solution

  • Research Objective: Evaluate the potential of User-Centered Design (UCD) in addressing usability issues in security authentication ceremonies.
  • Core Methodology: A four-stage design process based on UCD:
    1. Collaborative Design Workshops: Gather user ideas about authentication ceremonies, including their goals and needs.
    2. Narrowing the Design Space: Combine user input with security technologies to transform user concepts into feasible design prototypes.
    3. Iterative Prototype Design: Present user interface prototypes through storyboards and collect user feedback for improvement.
    4. Online Evaluation: Conduct randomized online experiments to compare the performance of design prototypes in terms of user experience and security perception.
  • Key Technologies:
    • Employ cryptographic protocols such as the Socialist Millionaire Protocol (SMP) to enhance security.
    • Utilize human-computer interaction techniques, such as participatory design methods, to collect user feedback and improve prototype acceptance.

Research Outcomes

  • Specific Results:
    1. Proposed three novel authentication ceremony prototypes:
      • A "Password Lock Prototype" based on shared knowledge.
      • A "Selfie Prototype" using selfie-based authentication.
      • A "ID Card Prototype" setting up virtual identification cards.
    2. Online evaluation findings:
      • The Password Lock Prototype improved user understanding of security (especially regarding different types of attacks).
      • The Selfie Prototype somewhat reduced the accuracy of security assessments against threat models.
    3. Experiments revealed conservative user evaluations of the overall user experience (UX) of these prototypes.
  • Experimental Statistics:
    • System Usability Scale (SUS) and User Experience Questionnaire Short Version (UEQ-S): The new design prototypes did not show significant improvements in these dimensions.
    • However, the Password Lock Prototype significantly enhanced user comprehension of threat models.
  • Advantages and Disadvantages:
    • Advantages: The UCD design approach helped identify authentication methods that users intuitively understand and trust, making them more appealing than existing ceremonies.
    • Limitations: Failed to significantly improve usability, with limited enhancements to user experience.

Limitations and Future Directions

  • Limitations:
    1. The study primarily focused on users from developed countries, whose security needs and threat perceptions may differ from those in other regions.
    2. The design process did not sufficiently address the social and cultural barriers to widespread adoption of authentication ceremonies, such as feelings of embarrassment or reluctance to ask for help.
    3. Current online experiments limited the realism of user interactions with prototypes.
  • Future Directions:
    • Develop more attractive user incentive mechanisms to enhance the discoverability, usability, and adoption rates of authentication ceremonies.
    • Conduct tests with high-fidelity prototypes in real-world application environments, while incorporating Activity-Centered Design to further optimize usability.
    • Design customized solutions for users with specific threat models (e.g., journalists, activists).

Summary and Insights

  • The study highlights the value of user-centered design methods in addressing challenges related to security ceremonies while emphasizing the need for collaboration between technical and user experience experts.
  • Improving the usability of security tools requires not only enhancing absolute performance but also addressing social and cultural issues.
  • The applicability of UCD methods in complex security problems warrants further exploration.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/47437/2021

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3411764.3445164
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2021
emoji_events
Award
No award tagged
group
Authors
3 authors
sell
Subtopics
Privacy by Design & User Control, Passwords & Authentication
work
Professions
Cybersecurity Engineers, AI/ML Researchers & Engineers, HCI Researchers
article
Content Status
Full text indexed
hub
Related Papers
1 related papers