The development of an evaluation model for user authentication methods with security, usability, and usage frequency

Olga Ussatova, Shakirt Makilenov, Vladislav Karyukin, Abdul Razaque, Saule T. Amanzholova, Yenlik Begimbayeva · Eastern-European Journal of Enterprise Technologies · 2025

The object of the study is authentication systems in security-critical environments, especially in healthcare. The addressed problem is the absence of comprehensive frameworks that integrate both threat data and user-centric factors for real-world method comparison. This study develops and validates a novel evaluation model for assessing the empirical effectiveness of user authentication methods. The proposed model integrates probabilistic threat modeling, usability data, and weighted multi-criteria analysis to generate context-sensitive effectiveness scores, thereby supporting informed decision-making. Twelve authentication methods were assessed using three criteria: security (resistance to cyber threats), usability (user convenience), and use frequency (real-world adoption). Security coefficients (K2) were computed from threat statistics, while usability and adoption metrics were based on a healthcare survey (n = 70). Weighted normalization (ws = 0.4, wu = 0.3, wf = 0.3) produced overall effectiveness scores (E). The most effective methods were mobile devices (E = 30.915), PIN codes (E = 30.252), and fingerprint authentication (E = 29.235), offering an optimal balance of security and acceptance. Graphical passwords (E = 6.132) and iris scans (E = 7.245) scored lowest due to poor usability and limited adoption. The model’s feature lies in its holistic integration of threat exposure and empirical user data, along with adaptability to organizational requirements and visual interpretability. This feature distinguishes it from single-dimensional or static assessment models

Read the paper · More papers on PaperTik