Communications of the Association for Information Systems · 2006 · 53 citations · 60 references
Silver Bullet SolutionAuthentication AuthorizationEngineeringUsable SecurityInformation SecurityBiometricsInformation ForensicsMulti-factor AuthenticationAuthorizationAccess ControlInternet E-commerceAuthentication ProtocolImplementation IssuesIdentity-based SecurityAuthenticationData PrivacyUser ExperienceComputer ScienceData SecurityCryptographyTechnologyAuthentication Access Control
Computer-based information systems in general, and Internet e-commerce and e-business systems in particular, employ many types of resources that need to be protected against access by unauthorized users. Three main components of access control are used in most information systems: identification, authentication, and authorization. In this paper we focus on authentication, which is the most problematic component. The three main approaches to user authentication are: knowledge-based, possession-based, and biometric-based. We review and compare the various authentication mechanisms of these approaches and the technology and implementation issues they involve. Our conclusion is that there is no silver bullet solution to user authentication problems. Authentication practices need improvement. Further research should lead to a better understanding of user behavior and the applied psychology aspects of computer security.
60
Password memorability and security: empirical results
Junjie Yan, A Blackwell, Ross Anderson et al. · IEEE Security & Privacy · 2004 · 690 citations