Title
Choose Your Own Authentication
Abstract
To solve the long-standing problems users have in creating and remembering text passwords, a wide variety of alternative authentication schemes have been proposed. Some of these schemes outperform others by various metrics in various contexts. However, none unilaterally outperform all others, and so text passwords persist as the main scheme applications depend upon. In this paper, we challenge the long-standing assumption that only one authentication scheme can be offered by an application service. We propose Choose Your Own Authentication (CYOA): a novel authentication architecture that enables users to choose a scheme amongst several available alternatives. CYOA would enable users to select whichever scheme best suits their preferences, abilities, and usage context. Existing text password systems could easily be replaced. Furthermore, the three-party architecture would enable delegating the management of authentication systems to trusted-third parties. The architecture allows rapid deployment and testing of novel authentication technologies. Our two-week usability study suggests that participants were willing to leverage alternative schemes. Participants were confident that CYOA could keep their financial information secure.
Year
DOI
Venue
2015
10.1145/2841113.2841114
New Security Paradigms Workshop
Field
DocType
Citations 
Lightweight Extensible Authentication Protocol,Internet privacy,Architecture,Software deployment,Authentication,Computer science,Computer security,Usability,Authentication protocol,Password,Delegation
Conference
5
PageRank 
References 
Authors
0.50
37
3
Name
Order
Citations
PageRank
Alain Forget138320.53
Sonia Chiasson291958.49
Robert Biddle352845.50