FIDO2 the Rescue? Platform vs. Roaming Authentication on Smartphones
Best PaperAuthors
Document Title
FIDO2 the Rescue? Platform vs. Roaming Authentication on Smartphones
Document Information
- Subject Area: User Authentication, Password Replacement Technologies, Human-Computer Interaction
- Keywords: Usability, Security, Passwordless, User Authentication, Biometrics, Accounts
Research Background and Problem
-
Problems and Challenges:
- Since the 1970s, text passwords have been widely used for user authentication but suffer from issues such as being hard to remember, password reuse, and susceptibility to phishing attacks.
- Existing password replacement technologies often face difficulties in large-scale adoption, primarily due to insufficient deployability and usability.
-
Significance:
- Password-related issues have become a critical bottleneck in internet security, and the promotion of new technologies (e.g., FIDO2) is essential for improving user experience and ensuring information security.
-
Research Motivation and Related Work:
- The FIDO2 standard primarily achieves passwordless authentication through public-key cryptography and biometric technologies and is already compatible with mainstream browsers. However, user attitudes and acceptance of this new authentication method remain underexplored, particularly in smartphone usage scenarios.
Solution
-
Methods and Innovations:
- This study examines user authentication experiences on smartphones by comparing FIDO2 platform authentication (relying on built-in biometric modules like Apple Touch ID) and roaming authentication (relying on external hardware devices such as YubiKey).
- The study is the first to conduct a large-scale laboratory comparison in this field, focusing on usability preferences, technology acceptance, and application scenarios.
-
Implementation Steps and Techniques:
- Experiment Design: 87 participants were divided into two groups, using platform authentication and roaming authentication, respectively, to complete multiple online authentication tasks in a laboratory environment.
- Questionnaire Survey: Participants provided feedback on usability, acceptance, and the likelihood of adopting FIDO2 in different application scenarios. This included open-ended questions and quantitative metrics (e.g., SUS scores and five-point Likert scales).
- Data Analysis: Quantitative and qualitative data were analyzed using statistical methods and coding techniques to reveal user attitudes.
Research Findings
-
Specific Results:
- Usability: Both platform and roaming authentication received high SUS scores (median scores of 95 and 90, respectively), indicating high user satisfaction with daily operations. Platform authentication showed higher acceptance compared to roaming authentication.
- Advantages and Disadvantages:
- Key advantages include enhanced security, elimination of password management burdens, and ease of use.
- Key disadvantages include difficulties in account recovery, challenges in revoking authentication after device loss, and limited multi-device support for platform authentication.
- Application Preferences: Users preferred using roaming authentication for sensitive accounts (e.g., banking accounts) and platform authentication for non-sensitive or frequently used accounts.
-
Comparison with Existing Solutions:
- Compared to traditional passwords, FIDO2 offers resistance to phishing attacks.
- Roaming authentication is more suitable for low-frequency use and high-security scenarios, while platform authentication is more acceptable for frequently used accounts or device-specific scenarios.
-
Limitations and Future Directions:
- Limitations:
- The current learning curve of FIDO2 limits its quick adoption by general users, and its overall adoption rate remains low.
- Platform authentication does not fully address issues in multi-device scenarios.
- Future Directions:
- Emphasize user education to promote understanding of FIDO2.
- Improve the standard to address existing issues such as account recovery, authentication revocation, and account delegation.
- Foster collaboration among vendors to develop cross-platform open-source solutions (e.g., Apple's Passkeys mechanism).
- Limitations:
Conclusion
Through detailed experiments and surveys, this study reveals the specific advantages, disadvantages, and user acceptance of FIDO2 authentication methods on smartphones. Despite existing technical limitations, FIDO2 has the potential to replace passwords. With user education and technological improvements, it can better meet authentication needs across different scenarios. The study recommends further optimization of platform authentication and enhanced cross-device compatibility to improve user experience and security.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- Which FIDO2 authentication method do users prefer on smartphones: platform authentication or roaming authentication?Category: Biometric Identification, Authentication, and PrivacySimilar questionsarrow_forward
- What are the respective advantages and disadvantages of platform and roaming authentication across different scenarios?Category: Biometric Identification, Authentication, and PrivacySimilar questionsarrow_forward
- How can FIDO2 authentication methods improve users' usability and security experience?Category: Biometric Identification, Authentication, and PrivacySimilar questionsarrow_forward
Practical Problems
1- Users struggle to manage passwords across multiple devices and avoid phishing risks.Category: Biometric Identification, Authentication, and PrivacySimilar questionsarrow_forward
No related papers with ≥60% similarity
Based on Jaccard similarity of research subtopics & professions (≥60%)