Article (Scientific journals)
Maybe Poor Johnny Really Cannot Encrypt - The Case for a Complexity Theory for Usable Security
Benenson, Zinaida; Lenzini, Gabriele; Oliveira, Daniela et al.
2015In Proceedings of the New Security Paradigm Workshop
Peer reviewed
 

Files


Full Text
nspw15-usasec-complexity-PREPROCEEDINGS.pdf
Author preprint (2.24 MB)
Request a copy

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
usable security models; human capacities
Abstract :
[en] This paper discusses whether usable security is unattainable for some security tasks due to intrinsic bounds of human cognitive capacities. Will Johnny ever be able to encrypt? Psychology and neuroscience literature shows that there are upper bounds on the human capacity for executing cognitive tasks and for information processing. We argue that the usable security discipline should scientifically understand human capacities for security tasks, i.e., what we can realistically expect from people. We propose a framework for evaluation of human capacities in security that assigns socio-technical systems to complexity classes according to their security and usability. The upper bound of human capacity is considered the point at which people start experiencing cognitive strain while performing a task, because cognitive strain demonstrably leads to errors in the task execution. The ultimate goal of the work we initiate in this paper is to provide designers of security mechanisms or policies with the ability to say:“This feature of the security mechanism X or this security policy element Y is inappropriate, because this evidence shows that it is beyond people’s capacity".
Disciplines :
Computer science
Author, co-author :
Benenson, Zinaida
Lenzini, Gabriele ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Oliveira, Daniela
Parkin, Simon
Uebelacker
External co-authors :
yes
Language :
English
Title :
Maybe Poor Johnny Really Cannot Encrypt - The Case for a Complexity Theory for Usable Security
Publication date :
2015
Journal title :
Proceedings of the New Security Paradigm Workshop
Peer reviewed :
Peer reviewed
FnR Project :
FNR1183245 - Socio-technical Analysis Of Security And Trust, 2011 (01/05/2012-30/04/2015) - Peter Y. A. Ryan
Available on ORBilu :
since 05 August 2015

Statistics


Number of views
188 (16 by Unilu)
Number of downloads
12 (8 by Unilu)

Bibliography


Similar publications



Contact ORBilu