Suppr超能文献

通过适当的认证机制实现安全的移动应用程序。

Toward secure mobile applications through proper authentication mechanisms.

作者信息

Albesher Abdulmohsen Saud, Alkhaldi Amal, Aljughaiman Ahmed

机构信息

Department of Information Systems, College of Computer Sciences and Information Technology, King Faisal University, Al-Ahsa, Saudi Arabia.

Department of Computer Networks and Communications, College of Computer Sciences and Information Technology, King Faisal University, Al-Ahsa, Saudi Arabia.

出版信息

PLoS One. 2024 Dec 5;19(12):e0315201. doi: 10.1371/journal.pone.0315201. eCollection 2024.

Abstract

With the increased number of mobile apps, authentication processes play a key role in verifying users' identities and protecting data from security threats. Utilizing proper authentication techniques is key to protecting computer apps from being hacked. In this paper, we aimed to compare the authentication methods of the sign-up, sign-in, and password recovery processes of 50 e-commerce apps. To ensure accurate data analysis, we checked every app in a separate session and used the "think-aloud" technique while recording the screen. The researchers prepared a list of items that were checked during each session to identify the similarities and differences between tested apps regarding the authentication process. The results of this security analysis unequivocally demonstrated how different apps' designs for authentication processes are. Users' memory and comprehension are burdened by these variances, and no app can ensure that they adhere to recommended standards. The results of this study confirmed the necessity for unified and user-friendly authentication processes. This can be possible by following a usable security framework for the authentication process.

摘要

随着移动应用数量的增加,认证过程在验证用户身份和保护数据免受安全威胁方面发挥着关键作用。运用适当的认证技术是保护计算机应用程序不被黑客攻击的关键。在本文中,我们旨在比较50个电子商务应用程序的注册、登录和密码恢复过程的认证方法。为确保准确的数据分析,我们在单独的会话中检查每个应用程序,并在录制屏幕时使用“出声思考”技术。研究人员准备了一份在每个会话中检查的项目列表,以确定测试应用程序在认证过程方面的异同。这项安全分析的结果明确表明了不同应用程序的认证过程设计有多么不同。这些差异给用户的记忆和理解带来了负担,而且没有一个应用程序能够确保它们符合推荐标准。这项研究的结果证实了统一且用户友好的认证过程的必要性。通过遵循一个适用于认证过程的可用安全框架可以实现这一点。

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验