The seven flaws of identity management - Usability and security challenges

被引:68
作者
Dhamija, Rachna [1 ]
Dusseault, Lisa [1 ]
机构
[1] Harvard Univ, Ctr Res Computat & Soc, Cambridge, MA 02138 USA
关键词
Identity management; Privacy; Usability;
D O I
10.1109/MSP.2008.49
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Seven flaws or design challenges that should be met for the general public to accept and use identity management systems are discussed. Identity management systems' scale and complexity, combined with the privacy and security requirements create steep challenges for usability. Identity management is user's primary goal and they are focused on their primary tasks and identity management systems should aim to facilitate such tasks seamlessly, securely, and privately. Direct and indirect costs associated with the identity management system should be minimized that includes the authentication process and password interfaces. Cognitive scalability should be given equal importance as technical scalability, while users should be aware of the information leakage or disclosure and should take proper care of it and focus should be primarily on user authentication. Cognitive burden should be reduced and the systems should be evaluated in the larger context of other systems. © 2008 IEEE.
引用
收藏
页码:24 / 29
页数:6
相关论文
共 17 条
[1]   Privacy and rationality in individual decision making [J].
Acquisti, A ;
Grossklags, J .
IEEE SECURITY & PRIVACY, 2005, 3 (01) :26-33
[2]   Users are not the enemy [J].
Adams, A ;
Sasse, MA .
COMMUNICATIONS OF THE ACM, 1999, 42 (12) :41-46
[3]  
[Anonymous], 2005, P 2005 S USABLE PRIV
[4]  
Dhamija R, 2000, USENIX ASSOCIATION PROCEEDINGS OF THE NINTH USENIX SECURITY SYMPOSIUM, P45
[5]  
Dhamija R., 2006, P SIGCHI C HUMAN FAC, P581, DOI [10.1145/1124772.1124861, DOI 10.1145/1124772.1124861]
[6]  
Fitzpatrick B, THOUGHTS SOCIAL GRAP
[7]  
Florencio Dinei, 2007, P WWW, DOI [DOI 10.1145/1242572.1242661, 10.1145/1242572.1242661]
[8]  
Franks J., 1999, RFC2617 RFC2617
[9]  
GROSS BM, 2007, P C HUM FACT COMP SY, P2393
[10]  
GROSSKLAGS J, 2007, LECT NOTES COMPUTER