...
首页> 外文期刊>Information management & computer security >Must I, can I? I don't understand your ambiguous password rules
【24h】

Must I, can I? I don't understand your ambiguous password rules

机译:我可以吗?我不明白您的密码规则不明确

获取原文
获取原文并翻译 | 示例
           

摘要

Purpose - The purpose of this research is to investigate user comprehension of ambiguous terminology in password rules. Although stringent password policies are in place to protect information system security, such complexity does not have to mean ambiguity for users. While many aspects of passwords have been studied, no research to date has systematically examined how ambiguous terminology affects user comprehension of password rules. Design/methodology/approach - This research used a combination of quantitative and qualitative methods in a usable security study with 60 participants. Study tasks contained password rules based on real-world password requirements. Tasks consisted of character-selection tasks that varied the terms for non-alphanumeric characters to explore users' interpretations ofpassword rule language, and compliance-checking tasks to investigate how well users can apply their understanding of the allowed character space. Findings - Results show that manipulating password rule terminology causes users' interpretation of the allowed character space to shrink or expand. Users are confused by the terms "non-alphanumeric", "symbols", "special characters" and "punctuation marks" in password rules. Additionally, users are confused by partial lists of allowed characters using "e.g." or "etc." Practical implications - This research provides data-driven usability guidance on constructing clearer language for password policies. Improving language clarity will help usability without sacrificing security, as simplifying password rule language does not change security requirements. Originality/value - This is the first usable security study to systematically measure the effects of ambiguous password rules on user comprehension of the allowed character space.
机译:目的-这项研究的目的是调查用户对密码规则中模棱两可术语的理解。尽管已经制定了严格的密码策略来保护信息系统的安全性,但是这种复杂性并不一定意味着用户的歧义。尽管已经研究了密码的许多方面,但是迄今为止,还没有系统地研究过歧义的术语如何影响用户对密码规则的理解。设计/方法/方法-这项研究在60名参与者的可用安全性研究中使用了定量和定性方法的组合。研究任务包含基于实际密码要求的密码规则。任务包括字符选择任务,这些任务改变了非字母数字字符的术语以探索用户对密码规则语言的解释,以及合规性检查任务以调查用户如何很好地运用他们对允许的字符空间的理解。结果-结果显示,使用密码规则术语会使用户对允许的字符空间的解释缩小或扩展。密码规则中的术语“非字母数字”,“符号”,“特殊字符”和“标点符号”使用户感到困惑。另外,用户对使用“例如”的部分允许字符感到困惑。或“等”。实际意义-这项研究为构建更清晰的密码策略语言提供了数据驱动的可用性指南。提高语言清晰度将在不牺牲安全性的情况下帮助提高可用性,因为简化密码规则语言不会改变安全性要求。原创性/价值-这是第一个可使用的安全性研究,能够系统地测量歧义密码规则对用户理解允许的字符空间的影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号