The Users' Mental Models' Effect on their Comprehension of Anonymous Credentials

Anonymous Credentials are a key technology for enforcing data minimisation for online applications. The design of easily understandable user interfaces for the use of anonymous credentials is however a major challenge, as end users are not yet familiar with this rather new and complex technology and no obvious real-world analogies exist for them. In this chapter, we analyse what effects the users’ mental models have on their understanding of the data minimization property of anonymous credentials in the context of an e-Shopping application scenario. In particular, we have investigated the effects of the mental models of a card-based user interface approach and an attribute-based user interface approach and compared these in terms of errors of omission and addition. The results show that the card-based approach leads to significantly more errors of addition (i.e., users believe that they have disclosed more information than they actually have) whereas the attribute-based approach leads to more errors of omission (i.e., users underestimate the amount of data that they have disclosed).