The Quest to Secure Email: A Usability Analysis of Key Management Alternatives

The current state of email security is lacking, and the need for end-to-end encryption of email is clear. Recent research has begun to make progress towards usable, secure email for the masses (i.e., novice users without IT support). In this paper, we evaluate the usability implications of three dif...

Full description

Bibliographic Details
Main Author: Andersen, Jeffrey Thomas
Format: Others
Published: BYU ScholarsArchive 2016
Subjects:
Online Access:https://scholarsarchive.byu.edu/etd/6461
https://scholarsarchive.byu.edu/cgi/viewcontent.cgi?article=7461&context=etd
id ndltd-BGMYU2-oai-scholarsarchive.byu.edu-etd-7461
record_format oai_dc
spelling ndltd-BGMYU2-oai-scholarsarchive.byu.edu-etd-74612019-05-16T03:17:01Z The Quest to Secure Email: A Usability Analysis of Key Management Alternatives Andersen, Jeffrey Thomas The current state of email security is lacking, and the need for end-to-end encryption of email is clear. Recent research has begun to make progress towards usable, secure email for the masses (i.e., novice users without IT support). In this paper, we evaluate the usability implications of three different key management approaches: PGP, IBE, and passwords. Our work is the first formal A/B evaluation of the usability of different key management schemes, and the largest formal evaluation of secure email ever performed. Our results reveal interesting inherent usability trade-offs for each approach to secure email. Furthermore, our research results in the first fully-implemented PGP-based secure email system that has been shown to be usable for novice users. We share qualitative feedback from participants that provides valuable insights into user attitudes regarding each key management approach and secure email generally. Finally, our work provides an important validation of methodology and design principles described in prior work. 2016-07-01T07:00:00Z text application/pdf https://scholarsarchive.byu.edu/etd/6461 https://scholarsarchive.byu.edu/cgi/viewcontent.cgi?article=7461&context=etd http://lib.byu.edu/about/copyright/ All Theses and Dissertations BYU ScholarsArchive secure email key management usability testing Computer Sciences
collection NDLTD
format Others
sources NDLTD
topic secure email
key management
usability testing
Computer Sciences
spellingShingle secure email
key management
usability testing
Computer Sciences
Andersen, Jeffrey Thomas
The Quest to Secure Email: A Usability Analysis of Key Management Alternatives
description The current state of email security is lacking, and the need for end-to-end encryption of email is clear. Recent research has begun to make progress towards usable, secure email for the masses (i.e., novice users without IT support). In this paper, we evaluate the usability implications of three different key management approaches: PGP, IBE, and passwords. Our work is the first formal A/B evaluation of the usability of different key management schemes, and the largest formal evaluation of secure email ever performed. Our results reveal interesting inherent usability trade-offs for each approach to secure email. Furthermore, our research results in the first fully-implemented PGP-based secure email system that has been shown to be usable for novice users. We share qualitative feedback from participants that provides valuable insights into user attitudes regarding each key management approach and secure email generally. Finally, our work provides an important validation of methodology and design principles described in prior work.
author Andersen, Jeffrey Thomas
author_facet Andersen, Jeffrey Thomas
author_sort Andersen, Jeffrey Thomas
title The Quest to Secure Email: A Usability Analysis of Key Management Alternatives
title_short The Quest to Secure Email: A Usability Analysis of Key Management Alternatives
title_full The Quest to Secure Email: A Usability Analysis of Key Management Alternatives
title_fullStr The Quest to Secure Email: A Usability Analysis of Key Management Alternatives
title_full_unstemmed The Quest to Secure Email: A Usability Analysis of Key Management Alternatives
title_sort quest to secure email: a usability analysis of key management alternatives
publisher BYU ScholarsArchive
publishDate 2016
url https://scholarsarchive.byu.edu/etd/6461
https://scholarsarchive.byu.edu/cgi/viewcontent.cgi?article=7461&context=etd
work_keys_str_mv AT andersenjeffreythomas thequesttosecureemailausabilityanalysisofkeymanagementalternatives
AT andersenjeffreythomas questtosecureemailausabilityanalysisofkeymanagementalternatives
_version_ 1719185376680083456