Security and usability of a personalized user authentication paradigm: insights from a longitudinal study with three healthcare organizations

Argyris Constantinides*, Marios Belk, Christos Fidas, Roy Beumers, David Vidal, Wanting Huang, Juliana Kuster Filipe Bowles, Thais Webber, Agastya Silvina, Andreas Pitsillides

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

Abstract

This paper proposes a user-adaptable and personalized authentication paradigm for healthcare organizations, which anticipates to seamlessly reflect patients’ episodic and autobiographical memories to graphical and textual passwords aiming to improve the security strength of user-selected passwords and provide a positive user experience. We report on a longitudinal study that spanned over three years in which three public European healthcare organizations participated in order to design and evaluate the aforementioned paradigm. Three studies were conducted (n=169) with different stakeholders: i) a verification study aiming to identify existing authentication practices of the three healthcare organizations with diverse stakeholders (n=9); ii) a patient-centric feasibility study during which users interacted with the proposed authentication system (n=68); and iii) a human guessing attack study focusing on vulnerabilities among people sharing common experiences within location-aware images used for graphical passwords (n=92). Results revealed that the suggested paradigm scored high with regards to users’ likeability, perceived security, usability and trust, but more importantly it assists the creation of more secure passwords. On the downside, the suggested paradigm introduces password guessing vulnerabilities by individuals sharing common experiences with the end-users. Findings are expected to scaffold the design of more patient-centric knowledge-based authentication mechanisms within nowadays dynamic computation realms.
Original languageEnglish
Number of pages40
JournalACM Transactions on Computing for Healthcare
Volume4
Issue number1
Early online date12 Oct 2022
DOIs
Publication statusPublished - 1 Jan 2023

Keywords

  • Knowledge-based user authentication
  • Graphical passwords
  • Usability
  • Security
  • Feasibility user study
  • Human guessing attack study

Fingerprint

Dive into the research topics of 'Security and usability of a personalized user authentication paradigm: insights from a longitudinal study with three healthcare organizations'. Together they form a unique fingerprint.

Cite this