FIDO2 the Rescue? Platform vs. Roaming Authentication on Smartphones

Best Paper
Explainable AI (XAI)AI-Assisted Decision-Making & AutomationPasswords & AuthenticationCybersecurity EngineersPrivacy Policy Makers

Document Title

FIDO2 the Rescue? Platform vs. Roaming Authentication on Smartphones

Document Information

  • Subject Area: User Authentication, Password Replacement Technologies, Human-Computer Interaction
  • Keywords: Usability, Security, Passwordless, User Authentication, Biometrics, Accounts

Research Background and Problem

  • Problems and Challenges:

    • Since the 1970s, text passwords have been widely used for user authentication but suffer from issues such as being hard to remember, password reuse, and susceptibility to phishing attacks.
    • Existing password replacement technologies often face difficulties in large-scale adoption, primarily due to insufficient deployability and usability.
  • Significance:

    • Password-related issues have become a critical bottleneck in internet security, and the promotion of new technologies (e.g., FIDO2) is essential for improving user experience and ensuring information security.
  • Research Motivation and Related Work:

    • The FIDO2 standard primarily achieves passwordless authentication through public-key cryptography and biometric technologies and is already compatible with mainstream browsers. However, user attitudes and acceptance of this new authentication method remain underexplored, particularly in smartphone usage scenarios.

Solution

  • Methods and Innovations:

    • This study examines user authentication experiences on smartphones by comparing FIDO2 platform authentication (relying on built-in biometric modules like Apple Touch ID) and roaming authentication (relying on external hardware devices such as YubiKey).
    • The study is the first to conduct a large-scale laboratory comparison in this field, focusing on usability preferences, technology acceptance, and application scenarios.
  • Implementation Steps and Techniques:

    1. Experiment Design: 87 participants were divided into two groups, using platform authentication and roaming authentication, respectively, to complete multiple online authentication tasks in a laboratory environment.
    2. Questionnaire Survey: Participants provided feedback on usability, acceptance, and the likelihood of adopting FIDO2 in different application scenarios. This included open-ended questions and quantitative metrics (e.g., SUS scores and five-point Likert scales).
    3. Data Analysis: Quantitative and qualitative data were analyzed using statistical methods and coding techniques to reveal user attitudes.

Research Findings

  • Specific Results:

    • Usability: Both platform and roaming authentication received high SUS scores (median scores of 95 and 90, respectively), indicating high user satisfaction with daily operations. Platform authentication showed higher acceptance compared to roaming authentication.
    • Advantages and Disadvantages:
      • Key advantages include enhanced security, elimination of password management burdens, and ease of use.
      • Key disadvantages include difficulties in account recovery, challenges in revoking authentication after device loss, and limited multi-device support for platform authentication.
    • Application Preferences: Users preferred using roaming authentication for sensitive accounts (e.g., banking accounts) and platform authentication for non-sensitive or frequently used accounts.
  • Comparison with Existing Solutions:

    • Compared to traditional passwords, FIDO2 offers resistance to phishing attacks.
    • Roaming authentication is more suitable for low-frequency use and high-security scenarios, while platform authentication is more acceptable for frequently used accounts or device-specific scenarios.
  • Limitations and Future Directions:

    • Limitations:
      • The current learning curve of FIDO2 limits its quick adoption by general users, and its overall adoption rate remains low.
      • Platform authentication does not fully address issues in multi-device scenarios.
    • Future Directions:
      • Emphasize user education to promote understanding of FIDO2.
      • Improve the standard to address existing issues such as account recovery, authentication revocation, and account delegation.
      • Foster collaboration among vendors to develop cross-platform open-source solutions (e.g., Apple's Passkeys mechanism).

Conclusion

Through detailed experiments and surveys, this study reveals the specific advantages, disadvantages, and user acceptance of FIDO2 authentication methods on smartphones. Despite existing technical limitations, FIDO2 has the potential to replace passwords. With user education and technological improvements, it can better meet authentication needs across different scenarios. The study recommends further optimization of platform authentication and enhanced cross-device compatibility to improve user experience and security.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/96561/2023

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3544548.3580993
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2023
emoji_events
Award
Best Paper
group
Authors
4 authors
sell
Subtopics
Explainable AI (XAI), AI-Assisted Decision-Making & Automation, Passwords & Authentication
work
Professions
Cybersecurity Engineers, Privacy Policy Makers
article
Content Status
Full text indexed
hub
Related Papers
0 related papers