首页> 外文OA文献 >An investigation into the usability and acceptability of multi-channel authentication to online banking users in Oman
【2h】

An investigation into the usability and acceptability of multi-channel authentication to online banking users in Oman

机译:对阿曼网上银行用户多渠道认证的可用性和可接受性的调查

摘要

Authentication mechanisms provide the cornerstone for security for many distributed systems, especially for increasingly popular online applications. For decades, widely used, traditional authentication methods included passwords and PINs that are now inadequate to protect online users and organizations from ever more sophisticated attacks. This study proposes an improvement to traditional authentication mechanisms. The solution introduced here includes a one-time-password (OTP) and incorporates the concept of multiple levels and multiple channels – features that are much more successful than traditional authentication mechanisms in protecting users' online accounts from being compromised. This research study reviews and evaluates current authentication classes and mechanisms and proposes an authentication mechanism that uses a variety of techniques, including multiple channels, to resist attacks more effectively than most commonly used mechanisms. Three aspects of the mechanism were evaluated: 1. The security of multi-channel authentication (MCA) was evaluated in theoretical terms, using a widely accepted methodology. 2. The usability was evaluated by carrying out a user study. 3. Finally, the acceptability thereof was evaluated by asking the participants in study (2) specific questions which aligned with the technology acceptance model (TAM). The study’s analysis of the data, gathered from online questionnaires and application log tables, showed that most participants found the MCA mechanism superior to other available authentication mechanisms and clearly supported the proposed MCA mechanism and the benefits that it provides. The research presents guidelines on how to implement the proposed mechanism, provides a detailed analysis of its effectiveness in protecting users' online accounts against specific, commonly deployed attacks, and reports on its usability and acceptability. It represents a significant step forward in the evolution of authentication mechanisms meeting the security needs of online users while maintaining usability.
机译:身份验证机制为许多分布式系统(尤其是日益流行的在线应用程序)的安全性提供了基石。几十年来,被广泛使用的传统身份验证方法包括密码和PIN,这些密码和PIN现在不足以保护在线用户和组织免受日益复杂的攻击。这项研究提出了对传统身份验证机制的改进。此处介绍的解决方案包括一次性密码(OTP),并结合了多个级别和多个渠道的概念-在保护用户的在线帐户不受损害方面,该功能比传统的身份验证机制成功得多。这项研究研究回顾并评估了当前的身份验证类别和机制,并提出了一种身份验证机制,该机制使用多种技术(包括多种渠道)来比大多数常用机制更有效地抵御攻击。对该机制的三个方面进行了评估:1.使用广泛接受的方法从理论上评估了多通道身份验证(MCA)的安全性。 2.通过进行用户研究来评估可用性。 3.最后,通过向研究参与者(2)提出与技术接受模型(TAM)一致的特定问题来评估其可接受性。这项研究从在线调查表和应用程序日志表中收集的数据分析表明,大多数参与者发现MCA机制优于其他可用的身份验证机制,并明确支持拟议的MCA机制及其提供的好处。该研究提出了有关如何实施所提出机制的指南,详细分析了该机制在保护用户的在线帐户免受特定的,通常部署的攻击方面的有效性,并报告了其可用性和可接受性。它代表着认证机制的发展迈出了重要的一步,该机制既可满足在线用户的安全需求,又可保持可用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号