Publication:
User perceptions of security and usability of mobile-based single password authentication and two-factor authentication

dc.contributor.coauthorİşler, Devriş
dc.contributor.departmentDepartment of Media and Visual Arts
dc.contributor.departmentDepartment of Computer Engineering
dc.contributor.kuauthorCoşkun, Aykut
dc.contributor.kuauthorKüpçü, Alptekin
dc.contributor.schoolcollegeinstituteCollege of Engineering
dc.contributor.schoolcollegeinstituteCollege of Social Sciences and Humanities
dc.date.accessioned2024-11-09T11:42:52Z
dc.date.issued2019
dc.description.abstractTwo-factor authentication provides a significant improvement over the security of traditional password-based authentication by requiring users to provide an additional authentication factor, e.g., a code generated by a security token. In this decade, single password authentication (SPA) schemes are introduced to overcome the challenges of traditional password authentication, which is vulnerable to the offline dictionary, phishing, honeypot, and man-in-the-middle attacks. Unlike classical password-based authentication systems, in SPA schemes the user is required to remember only a single password (and a username) for all her accounts, while the password is protected against the aforementioned attacks in a provably secure manner. In this paper, for the first time, we implement the state-of-the-art mobile-based SPA system of Acar et al. (2013) as a prototype and assess its usability in a lab environment where we compare it against two-factor authentication (where, in both cases, in addition to the password, the user needs access to her mobile device). Our study shows that mobile-based SPA is as easy as, but less intimidating and more secure than two-factor authentication, making it a better alternative for online banking type deployments. Based on our study, we conclude with deployment recommendations and further usability study suggestions.
dc.description.fulltextYES
dc.description.indexedbyScopus
dc.description.openaccessYES
dc.description.publisherscopeInternational
dc.description.sponsoredbyTubitakEuEU - TÜBİTAK
dc.description.sponsorshipScientific and Technological Research Council of Turkey (TÜBİTAK)
dc.description.sponsorshipRoyal Society of UK Newton Advanced Fellowship
dc.description.sponsorshipEuropean Union (European Union)
dc.description.sponsorshipHorizon 2020
dc.description.sponsorshipEuropean Research Council (ERC) Advanced Grant
dc.description.sponsorshipFWO under an Odysseus Project
dc.description.versionAuthor's final manuscript
dc.identifier.doi10.1007/978-3-030-31500-9_7
dc.identifier.embargoNO
dc.identifier.filenameinventorynoIR02035
dc.identifier.isbn9783030314996
dc.identifier.issn0302-9743
dc.identifier.quartileN/A
dc.identifier.scopus2-s2.0-85075622956
dc.identifier.urihttps://hdl.handle.net/20.500.14288/267
dc.keywordsPassword-based authentication
dc.keywordsSingle password authentication
dc.keywordsTwo-factor authentication
dc.keywordsUsability
dc.language.isoeng
dc.publisherSpringer
dc.relation.grantno115E766
dc.relation.grantnoNA140464
dc.relation.grantnoERC-2015-AdG-IMPaCT
dc.relation.grantnoGOH9718N
dc.relation.ispartofLecture Notes in Computer Science
dc.relation.urihttp://cdm21054.contentdm.oclc.org/cdm/ref/collection/IR/id/8676
dc.subjectAuthentication
dc.subjectSecurity of data
dc.subjectGraphical authentication
dc.titleUser perceptions of security and usability of mobile-based single password authentication and two-factor authentication
dc.typeConference Proceeding
dspace.entity.typePublication
local.contributor.kuauthorKüpçü, Alptekin
local.contributor.kuauthorCoşkun, Aykut
local.publication.orgunit1College of Engineering
local.publication.orgunit1College of Social Sciences and Humanities
local.publication.orgunit2Department of Computer Engineering
local.publication.orgunit2Department of Media and Visual Arts
relation.isOrgUnitOfPublication483fa792-2b89-4020-9073-eb4f497ee3fd
relation.isOrgUnitOfPublication89352e43-bf09-4ef4-82f6-6f9d0174ebae
relation.isOrgUnitOfPublication.latestForDiscovery483fa792-2b89-4020-9073-eb4f497ee3fd
relation.isParentOrgUnitOfPublication8e756b23-2d4a-4ce8-b1b3-62c794a8c164
relation.isParentOrgUnitOfPublication3f7621e3-0d26-42c2-af64-58a329522794
relation.isParentOrgUnitOfPublication.latestForDiscovery8e756b23-2d4a-4ce8-b1b3-62c794a8c164

Files

Original bundle

Now showing 1 - 1 of 1
Thumbnail Image
Name:
8676.pdf
Size:
442.93 KB
Format:
Adobe Portable Document Format