论文标题
美丽的秘密:使用美学图像来验证用户
Beautiful secrets: using aesthetic images to authenticate users
论文作者
论文摘要
我们提出和评估一种身份验证方案,该方案由于人们对人们的美学口味和偏好而改善了身份验证过程中的可用性和用户体验问题。该方案使用美学图像来验证计算机用户的身份。它依靠有关视觉美学的三个主要前提:(i)个人对不同美学刺激有不同的偏好; (ii)这些偏好相对一致; (iii)美学口味是主观的,因此,美学偏好存在很大的个体差异。在回顾了这些前提的科学依据之后,我们描述了基于美学评估的身份验证(AEBA)方法的概念,并说明了它的实现。我们解决了AEBA相对于其他相关方法的优势和缺点,并得出结论,它足以适合低到中等安全域。它不能用作强制性方法,因为我们怀疑某个用户群体的某些部分缺乏有效使用该系统所需的美学敏感性程度。从好的方面来说,该方法提供了积极的体验。它使记忆密码的负担减少到最低,相对于其他面向可用性的方案提供了更好的安全性,该方案在肩膀弯曲,网络钓鱼和密码空间方面提供了更好的安全性。最后,我们报告了对该概念及其可行性的试点评估,该概念支持该方法的主要原则,提供了有关实施挑战和改进建议的见解。
We propose and evaluate an authentication scheme that improves usability and user experience issues in the authentication process due to its reliance on people's aesthetic tastes and preferences. The scheme uses aesthetic images to verify the identity of computer users. It relies on three major premises regarding visual aesthetics: (i) that an individual has different preferences for different aesthetic stimuli; (ii) that these preferences are relatively consistent; and (iii) that aesthetic tastes are subjective and, therefore, there are considerable individual differences in aesthetic preferences. Following a review of the scientific basis for these premises, we describe the concept of the aesthetic evaluation-based authentication (AEbA) method and illustrate an implementation of it. We address AEbA's advantages and disadvantages relative to other related methods and conclude that it is adequate for low-to-medium security domains. It cannot serve as a compulsory method because we suspect that a certain portion of the user population lacks the degree of aesthetic sensitivity required to use the system effectively. On the plus side, the method offers a positive experience. It alleviates the burden of memorizing passwords to a minimum, and relative to other usability-oriented schemes provides better security in terms of shoulder-surfing, phishing, and password space. Finally, we report on a pilot evaluation of the concept and its feasibility that supports the method's main tenets, provides insights about implementation challenges and suggestions for improvements.