User-centered security
Mary Ellen Zurko, Richard T. Simon · 1996
We introduce the term user-centered security to refer to security models, mechanisms, systems, and software that have usability as a primary motivation or goal.We discuss the history of usable secure systems, citing both past problems and present studies.We develop three categories for work in user-friendly security: applying usability testing and techniques to secure systems, developing security models and mechanisms for user-friendly systems, and considering user needs as a primary design goal at the start of secure system development.We discuss our work on user-centered authorization, which started with a rules-based authorization engine (MAP) and will continue with Adage.We outline the lessons we have learned to date and how they apply to our future work.We evaluate the pros and cons of this effort, as a precursor to further work in this area, and include a brief description of our current work in user-centered authorization.As our conclusion points out, we hope to see more work in user-centered security in the future; work that enables users to choose and use the protection they want, that matches their intuitions about security and privacy, and that supports the policies that teams and organizations need and use to get their work done. II. USABILITY IN