Show simple item record

dc.contributor.authorAgarwal, Lalit
dc.date.accessioned2016-08-04 15:57:46 (GMT)
dc.date.available2016-08-04 15:57:46 (GMT)
dc.date.issued2016-08-04
dc.date.submitted2016
dc.identifier.urihttp://hdl.handle.net/10012/10611
dc.description.abstractRe-authenticating users may be necessary for smartphone authentication schemes that leverage user behavior, device context, or task sensitivity. However, due to the unpredictable nature of re-authentication, users may get annoyed when they have to use the default, non-transparent authentication prompt for re-authentication. We address this concern by proposing a few configurations with varying levels of screen transparency and time delays when displaying the authentication prompt. We conduct user studies with 30 participants to evaluate the usability and security of these configurations. We also study whether the user preferences of the configurations vary depending on the application the participants are using on their device or their surrounding environment. We find that the participants generally prefer the authentication configuration with a non-transparent background for sensitive applications, such as banking and photo apps. Our findings also indicate that the user preferences are inclined towards convenient, usable configurations while participants are using their devices at home. Though we did not observe any significant differences in the task completion overhead and context switch overhead among our proposed configurations, we find that participants utilize the time delay just before the authentication prompt is going to appear to complete their current task. We also provide implementation details of our Android lock library, FireLock, which developers can use to re-authenticate users while they are using their app. We conclude with suggestions to improve the design of the proposed configurations as well as a discussion of other mechanisms to notify the users in case of re-authentication.en
dc.language.isoenen
dc.publisherUniversity of Waterlooen
dc.subjectMobile privacyen
dc.subjectAndroid re-authenticationen
dc.subjectSmartphone authenticationen
dc.titleEvaluating Re-authentication Strategies for Smartphonesen
dc.typeMaster Thesisen
dc.pendingfalse
uws-etd.degree.departmentDavid R. Cheriton School of Computer Scienceen
uws-etd.degree.disciplineComputer Scienceen
uws-etd.degree.grantorUniversity of Waterlooen
uws-etd.degreeMaster of Mathematicsen
uws.contributor.advisorHengartner, Urs
uws.contributor.affiliation1Faculty of Mathematicsen
uws.published.cityWaterlooen
uws.published.countryCanadaen
uws.published.provinceOntarioen
uws.typeOfResourceTexten
uws.peerReviewStatusUnrevieweden
uws.scholarLevelGraduateen


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record


UWSpace

University of Waterloo Library
200 University Avenue West
Waterloo, Ontario, Canada N2L 3G1
519 888 4883

All items in UWSpace are protected by copyright, with all rights reserved.

DSpace software

Service outages