10.08.2015 Views

Usability and Security

Usability and Security - Vurore

Usability and Security - Vurore

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

to a large number of citizens. At the same time, small businesses, single traders <strong>and</strong> professionals reportsignificant time savings <strong>and</strong> benefits from online access <strong>and</strong> payments compared to paper-based system<strong>and</strong> access restricted to office hours. Smartcards can offer additional usability benefits: once the loginprocedure is completed, the token can be used to carry sessions from one machine to another, thusremoving the need to log out or lock the screen when leaving the machine unattended for brief periods.They can also offer additional security features for applications such as credit cards.One usability concern arising from the increasing popularity of tokens is that users may end up being‘weighed down’ by a collection of tokens that they find hard to manage. There are two possible ways inwhich this might be prevented 28 :• Single tokens carrying multiple credentials. A single token, such as a smartcard, could be used tostore users’ credentials for multiple systems. The single token could either store data for multipleidentification <strong>and</strong> verification mechanisms operated by different organizations (providing the userwith a personal ‘credential/password manager’), or have a single strong verification (providing theuser with a ‘magic key’). Both approaches would require an open st<strong>and</strong>ard for credentials, <strong>and</strong> thesecond would also require agreement on a single form of authentication <strong>and</strong> a high degree of trustbetween participating organizations. The ‘magic key’ model would create less work for the user, butalso create a single point of attack;• Miniaturization of tokens. Organizations continue to issue their own tokens <strong>and</strong> decide their ownaccess control mechanisms, but the tokens are so small (for example, RFID chips) that users cankeep all of their tokens on them at all times, for example, in a smartcard-type device to whichindividual chips can be added.3.3.3.1 Recapitulation & analysis<strong>Usability</strong> aspects:• Effectiveness: the users’ goal with effectiveness is to get access to a building or remote access asaccurate <strong>and</strong> complete as possible. If the token does not work, the user is able to get it solved by thedepartment in question or person responsible. With regards to an OTP, users in most cases receive anew token when having problems connecting. However, in a normal situation this aspect isapplicable for both types. This aspect is therefore considered when using tokens <strong>and</strong> OTP;• Efficiency: the users’ goal with efficiency is to get access to a building or remote access as accurate<strong>and</strong> complete as possible, using minimal resources (e.g. time). Users are able to use tokens forphysical access, using the swipe principle. With regards to an OTP token, a user needs to rememberhis/ her key fob <strong>and</strong> enter the code which is indicated on the screen of the OTP token. In this caseboth are efficient to use. This aspect is therefore considered when using tokens <strong>and</strong> OTP;• Satisfaction: the users’ goal with satisfaction is a positive attitude towards getting access to abuilding or remote access, without encountering any discomfort. Users use the token for physicalaccess <strong>and</strong> OTP for remote access. If the token does not work, the user is able to get it solved by thedepartment in question or person responsible within an acceptable timeframe. With regards to anOTP, users in most cases receive a new token when having problems connecting, thus the user willnot be able to get remote access. This aspect is therefore only considered for tokens.17

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!