More Than Just Good Passwords? A Study on Usability and Security Perceptions of Risk-based Authentication


연구 분야: Analysis



학회: ACSAC '20: Proceedings of the 36th Annual Computer Security Applications Conference


초록

Risk-based Authentication (RBA) is an adaptive security measure to strengthen password-based authentication. RBA monitors additional features during login, and when observed feature values differ significantly from previously seen ones, users have to provide additional authentication factors such as a verification code. RBA has the potential to offer more usable authentication, but the usability and the security perceptions of RBA are not studied well. We present the results of a between-group lab study (n=65) to evaluate usability and security perceptions of two RBA variants, one 2FA variant, and password-only authentication. Our study shows with significant results that RBA is considered to be more usable than the studied 2FA variants, while it is perceived as more secure than password-only authentication in general and comparably secure to 2FA in a variety of application types. We also observed RBA usability problems and provide recommendations for mitigation. Our contribution provides a first deeper understanding of the users’ perception of RBA and helps to improve RBA implementations for a broader user acceptance.


Author Profile
Stephan Wiefling

H-BRS University of Applied Sciences Ruhr University Bochum Germany

Germany
Author Profile
Markus Dürmuth

Ruhr University Bochum Germany

Germany
Author Profile
Luigi Lo Iacono

H-BRS University of Applied Sciences

정보 없음

📄 논문 정보

발행 연도 2020년
인용수 29
출판 국가 Germany
사이트 ACM
좋아요 수 0

연관 논문 목록 (395건)