基于文本的移动界面验证码安全性与可用性评价

IF 2.2 3区 工程技术 Q3 ENGINEERING, MANUFACTURING
Nur Merdanoğlu, Pınar Onay Durdu
{"title":"基于文本的移动界面验证码安全性与可用性评价","authors":"Nur Merdanoğlu,&nbsp;Pınar Onay Durdu","doi":"10.1002/hfm.70007","DOIUrl":null,"url":null,"abstract":"<p>Captchas are used as Human interaction proof mechanisms during the authentication process on software applications. They should provide resistance to various attacks to increase security but also be understood easily to ensure usability. Increasing the security generally reduces usability, so it is necessary to use captchas that will meet both the security and usability needs of users balanced. Within the scope of this study, a text-based captcha scheme that end-users commonly encounter during their daily interactions in mobile applications is selected and investigated to determine both a more robust and usable one for users. Six different text-based captcha types, which were distortion-based, non-distortion-based, dictionary-based, random-based, low contrast, and full contrast, were compared in terms of security and usability. Initially, security tests were applied. Afterwards, user tests were conducted with 30 participants. According to security test results, distortion, low contrast, and random-based captcha types were determined to be more robust, respectively. The most usable captcha type among the secure captcha types was determined as a random string captcha based on the user test results. Thus, it has been found that a balanced level of security and usability can be achieved when mobile application developers choose to use a random string captcha when designing interfaces. Recommendations to guide mobile interface developers were provided based on the findings obtained both from the user study and previous relevant literature.</p>","PeriodicalId":55048,"journal":{"name":"Human Factors and Ergonomics in Manufacturing & Service Industries","volume":"35 3","pages":""},"PeriodicalIF":2.2000,"publicationDate":"2025-04-17","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1002/hfm.70007","citationCount":"0","resultStr":"{\"title\":\"Security and Usability Evaluation of Text-Based Captchas on Mobile Interface\",\"authors\":\"Nur Merdanoğlu,&nbsp;Pınar Onay Durdu\",\"doi\":\"10.1002/hfm.70007\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<p>Captchas are used as Human interaction proof mechanisms during the authentication process on software applications. They should provide resistance to various attacks to increase security but also be understood easily to ensure usability. Increasing the security generally reduces usability, so it is necessary to use captchas that will meet both the security and usability needs of users balanced. Within the scope of this study, a text-based captcha scheme that end-users commonly encounter during their daily interactions in mobile applications is selected and investigated to determine both a more robust and usable one for users. Six different text-based captcha types, which were distortion-based, non-distortion-based, dictionary-based, random-based, low contrast, and full contrast, were compared in terms of security and usability. Initially, security tests were applied. Afterwards, user tests were conducted with 30 participants. According to security test results, distortion, low contrast, and random-based captcha types were determined to be more robust, respectively. The most usable captcha type among the secure captcha types was determined as a random string captcha based on the user test results. Thus, it has been found that a balanced level of security and usability can be achieved when mobile application developers choose to use a random string captcha when designing interfaces. Recommendations to guide mobile interface developers were provided based on the findings obtained both from the user study and previous relevant literature.</p>\",\"PeriodicalId\":55048,\"journal\":{\"name\":\"Human Factors and Ergonomics in Manufacturing & Service Industries\",\"volume\":\"35 3\",\"pages\":\"\"},\"PeriodicalIF\":2.2000,\"publicationDate\":\"2025-04-17\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"https://onlinelibrary.wiley.com/doi/epdf/10.1002/hfm.70007\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Human Factors and Ergonomics in Manufacturing & Service Industries\",\"FirstCategoryId\":\"5\",\"ListUrlMain\":\"https://onlinelibrary.wiley.com/doi/10.1002/hfm.70007\",\"RegionNum\":3,\"RegionCategory\":\"工程技术\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q3\",\"JCRName\":\"ENGINEERING, MANUFACTURING\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Human Factors and Ergonomics in Manufacturing & Service Industries","FirstCategoryId":"5","ListUrlMain":"https://onlinelibrary.wiley.com/doi/10.1002/hfm.70007","RegionNum":3,"RegionCategory":"工程技术","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"ENGINEERING, MANUFACTURING","Score":null,"Total":0}
引用次数: 0

摘要

验证码在软件应用程序的身份验证过程中用作人机交互证明机制。它们应该能够抵抗各种攻击以提高安全性,但也应该易于理解以确保可用性。提高安全性通常会降低可用性,因此有必要使用平衡满足用户安全性和可用性需求的验证码。在本研究的范围内,选择并调查了最终用户在移动应用程序的日常交互中经常遇到的基于文本的captcha方案,以确定对用户来说更健壮和可用的方案。从安全性和可用性方面比较了六种不同的基于文本的验证码类型,分别是基于扭曲的、基于非扭曲的、基于字典的、基于随机的、低对比度的和全对比度的。最初,应用了安全性测试。随后,对30名参与者进行了用户测试。根据安全测试结果,失真、低对比度和基于随机的验证码类型分别被确定为更健壮。安全验证码类型中最可用的验证码类型被确定为基于用户测试结果的随机字符串验证码。因此,当移动应用程序开发人员在设计界面时选择使用随机字符串验证码时,可以实现平衡的安全性和可用性。根据用户研究和先前相关文献的发现,提供了指导移动界面开发人员的建议。
本文章由计算机程序翻译,如有差异,请以英文原文为准。

Security and Usability Evaluation of Text-Based Captchas on Mobile Interface

Security and Usability Evaluation of Text-Based Captchas on Mobile Interface

Captchas are used as Human interaction proof mechanisms during the authentication process on software applications. They should provide resistance to various attacks to increase security but also be understood easily to ensure usability. Increasing the security generally reduces usability, so it is necessary to use captchas that will meet both the security and usability needs of users balanced. Within the scope of this study, a text-based captcha scheme that end-users commonly encounter during their daily interactions in mobile applications is selected and investigated to determine both a more robust and usable one for users. Six different text-based captcha types, which were distortion-based, non-distortion-based, dictionary-based, random-based, low contrast, and full contrast, were compared in terms of security and usability. Initially, security tests were applied. Afterwards, user tests were conducted with 30 participants. According to security test results, distortion, low contrast, and random-based captcha types were determined to be more robust, respectively. The most usable captcha type among the secure captcha types was determined as a random string captcha based on the user test results. Thus, it has been found that a balanced level of security and usability can be achieved when mobile application developers choose to use a random string captcha when designing interfaces. Recommendations to guide mobile interface developers were provided based on the findings obtained both from the user study and previous relevant literature.

求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
CiteScore
5.20
自引率
8.30%
发文量
37
审稿时长
6.0 months
期刊介绍: The purpose of Human Factors and Ergonomics in Manufacturing & Service Industries is to facilitate discovery, integration, and application of scientific knowledge about human aspects of manufacturing, and to provide a forum for worldwide dissemination of such knowledge for its application and benefit to manufacturing industries. The journal covers a broad spectrum of ergonomics and human factors issues with a focus on the design, operation and management of contemporary manufacturing systems, both in the shop floor and office environments, in the quest for manufacturing agility, i.e. enhancement and integration of human skills with hardware performance for improved market competitiveness, management of change, product and process quality, and human-system reliability. The inter- and cross-disciplinary nature of the journal allows for a wide scope of issues relevant to manufacturing system design and engineering, human resource management, social, organizational, safety, and health issues. Examples of specific subject areas of interest include: implementation of advanced manufacturing technology, human aspects of computer-aided design and engineering, work design, compensation and appraisal, selection training and education, labor-management relations, agile manufacturing and virtual companies, human factors in total quality management, prevention of work-related musculoskeletal disorders, ergonomics of workplace, equipment and tool design, ergonomics programs, guides and standards for industry, automation safety and robot systems, human skills development and knowledge enhancing technologies, reliability, and safety and worker health issues.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信