Usability and Security in EU E-Banking Systems - Towards an Integrated Evaluation Framework

The proposed work highlights the interaction between security and usability in the context of e-banking security and proposes a theoretical evaluation framework to analyse this interaction and related extrinsic factors. It is felt that current evaluation methods for security and usability do not sufficiently examine their interplay and neglect other potential interactors in their model. In direct relation, it is also questioned whether current human-computer interaction research methods can be directly transferred to usability analysis of secure systems such as e-banking. The proposed study will therefore aim at aligning security and usability criteria with the object of ultimately developing a robust evaluation framework specific to e-banking. The required criteria will be derived from a comparison between various categories of e-banking security solutions, which is then followed by a security threat model of these solutions and complemented by relevant extrinsic influence factors. This approach is supported by the observed large variation in e-banking security solutions across Europe, their security and usability flaws as well as related literature, which has often been focused on either security or usability in this field. The strength and contribution of the proposed PhD thesis lies in the practical value to banks, the potential for transfer to other business areas as well as the new insight and knowledge added to the research area of usability for security. This document should be viewed as a presentation and introduction to the proposed research in the context of a doctoral symposium.

[1]  Ali E. Abdallah,et al.  Threat modeling approaches and tools for securing architectural designs of an e-banking application , 2010, 2010 Sixth International Conference on Information Assurance and Security.

[2]  Mervyn A. Jack,et al.  Usable security: User preferences for authentication methods in eBanking and the effects of experience , 2010, Interact. Comput..

[3]  Lorrie Faith Cranor,et al.  Security and Usability: Designing Secure Systems that People Can Use , 2005 .

[4]  Steven J. Murdoch,et al.  Optimised to Fail: Card Readers for Online Banking , 2009, Financial Cryptography.

[5]  Jan Jürjens,et al.  UMLsec: Extending UML for Secure Systems Development , 2002, UML.

[6]  A. W. Roscoe,et al.  Security and Usability: Analysis and Evaluation , 2010, 2010 International Conference on Availability, Reliability and Security.

[7]  Cecilia Mascolo,et al.  Integrating security and usability into the requirements and design process , 2007, Int. J. Electron. Secur. Digit. Forensics.

[8]  Thomas Weigold,et al.  Secure Internet banking authentication , 2006, IEEE Security & Privacy.