On the Security and Usability Implications of Providing Multiple Authentication Choices on Smartphones

Author:

Cho Geumhwan1,Huh Jun Ho2,Kim Soolin1,Cho Junsung1,Park Heesung2,Lee Yenah2,Beznosov Konstantin3,Kim Hyoungshick1

Affiliation:

1. Department of Electrical and Computer Engineering, Sungkyunkwan University, Republic of Korea

2. Samsung Research, Samsung Electronics, Republic of Korea

3. University of British Columbia, Vancouver, British Columbia, Canada

Abstract

The latest smartphones have started providing multiple authentication options including PINs, patterns, and passwords (knowledge based), as well as face, fingerprint, iris, and voice identification (biometric-based). In this article, we conducted two user studies to investigate how the convenience and security of unlocking phones are influenced by the provision of multiple authentication options. In a task-based user study with 52 participants, we analyze how participants choose an option to unlock their smartphone in daily life. The user study results demonstrate that providing multiple biometric-based authentication choices does not really influence convenience, because fingerprint had monopolistic dominance in the usage of unlock methods (111 of a total of 115 unlock trials that used a biometric-based authentication factor) due to users’ habitual behavior and fastness in unlocking phones. However, convenience was influenced by the provision of both knowledge-based and biometric-based authentication categories, as biometric-based authentication options were used in combination with knowledge-based authentication options—pattern was another frequently used unlock method. Our findings were confirmed and generalized through a follow-up survey with 327 participants. First, knowledge-based and biometric-based authentication options are used interchangeably. Second, providing multiple authentication options for knowledge-based authentication may influence convenience—both PINs (55.7%) and patterns (39.2%) are quite evenly used. Last, in contrast to knowledge-based authentication, providing multiple authentication choices for biometric-based authentication has less influence on choosing unlock options—fingerprint scanner is the most frequently used option (134 of 187 unlock methods used among biometric-based authentication options).

Funder

National Research Foundation of Korea

ICT Consilience Creative

MSIT (Ministry of Science and ICT), Korea

IITP

Publisher

Association for Computing Machinery (ACM)

Subject

Safety, Risk, Reliability and Quality,General Computer Science

Reference26 articles.

1. Android. 2019. Set your device for automatic unlock. Retrieved from https://support.google.com/nexus/answer/6093922. Android. 2019. Set your device for automatic unlock. Retrieved from https://support.google.com/nexus/answer/6093922.

2. Apple. 2017. iOS Security: iOS 10. Retrieved from https://www.apple.com/business/docs/iOS_Security_Guide.pdf. Apple. 2017. iOS Security: iOS 10. Retrieved from https://www.apple.com/business/docs/iOS_Security_Guide.pdf.

3. Biometric Authentication on iPhone and Android: Usability, Perceptions, and Influences on Adoption

4. A Birthday Present Every Eleven Wallets? The Security of Customer-Chosen Banking PINs

Cited by 9 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3