Skip to main content
QUICK REVIEW

[论文解读] Usability and Security of Different Authentication Methods for an Electronic Health Records System

Saptarshi Purkayastha, Shreya Goyal|arXiv (Cornell University)|Feb 23, 2021
User Authentication and Security Systems参考文献 16被引用 4
一句话总结

本研究评估了67名印第安纳大学珀杜大学印第安纳波利斯分校的研究生在三种电子健康记录(EHR)认证方法——用户名/密码、CAS单点登录和生物识别胶囊面部识别——中的可用性与安全性。通过PLS-SEM建模,研究发现感知安全性对可用性具有积极影响,其中面部识别因高信心度和满意度得分而成为最安全且最易用的方法。

ABSTRACT

We conducted a survey of 67 graduate students enrolled in the Privacy and Security in Healthcare course at Indiana University Purdue University Indianapolis. This was done to measure user preference and their understanding of usability and security of three different Electronic Health Records authentication methods: single authentication method (username and password), Single sign-on with Central Authentication Service (CAS) authentication method, and a bio-capsule facial authentication method. This research aims to explore the relationship between security and usability, and measure the effect of perceived security on usability in these three aforementioned authentication methods. We developed a formative-formative Partial Least Square Structural Equation Modeling (PLS-SEM) model to measure the relationship between the latent variables of Usability, and Security. The measurement model was developed using five observed variables (measures). - Efficiency and Effectiveness, Satisfaction, Preference, Concerns, and Confidence. The results obtained highlight the importance and impact of these measures on the latent variables and the relationship among the latent variables. From the PLS-SEM analysis, it was found that security has a positive impact on usability for Single sign-on and bio-capsule facial authentication methods. We conclude that the facial authentication method was the most secure and usable among the three authentication methods. Further, descriptive analysis was done to draw out the interesting findings from the survey regarding the observed variables.

研究动机与目标

  • 评估用户对三种EHR认证方法在可用性与安全性方面的偏好与感知。
  • 探究EHR系统中感知安全性与可用性之间的关系。
  • 确定哪种认证方法在医疗应用中能实现安全与可用性之间的最佳平衡。
  • 考察用户信心、满意度和担忧如何影响不同认证机制的采用。

提出的方法

  • 在印第安纳大学珀杜大学印第安纳波利斯分校的隐私与安全医疗课程中,对67名研究生进行了调查。
  • 评估了三种认证方法:用户名/密码、CAS单点登录和生物识别胶囊面部认证。
  • 开发了形式-形式部分最小二乘结构方程建模(PLS-SEM)框架,以分析潜在变量:可用性与安全性。
  • 通过五个观测变量测量可用性与安全性:效率与有效性、满意度、偏好、担忧和信心。
  • 使用PLS-SEM评估三种方法中感知安全性与可用性之间的因果关系。
  • 进行描述性分析,以提取用户行为与感知趋势的洞察。

实验结果

研究问题

  • RQ1用户如何感知用户名/密码、CAS单点登录和面部认证在EHR系统中的可用性与安全性?
  • RQ2不同认证方法中,感知安全性与感知可用性之间的关系如何?
  • RQ3用户最偏好哪种认证方法,其依据是可用性与安全性的感知?
  • RQ4用户担忧和信心水平在多大程度上影响认证方法的选择?
  • RQ5效率、有效性和满意度在三种认证方法之间如何变化?

主要发现

  • 面部认证在三种方法中被感知为最安全且最易用,用户信心和满意度得分最高。
  • 感知安全性对CAS单点登录和面部认证方法的感知可用性具有积极且显著的影响。
  • PLS-SEM模型证实了安全性与可用性之间存在统计显著关系,尤其在生物识别和SSO方法中表现明显。
  • 用户对用户名/密码方法表达了更多担忧,认为其信心较低且更易受攻击。
  • 偏好和满意度在面部认证中最高,表明用户对EHR环境中生物识别解决方案具有高度接受度。
  • 效率与有效性在面部认证中评分最高,表明其相比传统凭证具有更快、更可靠的访问体验。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。