The Quest to Secure Email: A Usability Analysis of Key Management Alternatives
The current state of email security is lacking, and the need for end-to-end encryption of email is clear. Recent research has begun to make progress towards usable, secure email for the masses (i.e., novice users without IT support). In this paper, we evaluate the usability implications of three dif...
Main Author: | |
---|---|
Format: | Others |
Published: |
BYU ScholarsArchive
2016
|
Subjects: | |
Online Access: | https://scholarsarchive.byu.edu/etd/6461 https://scholarsarchive.byu.edu/cgi/viewcontent.cgi?article=7461&context=etd |
id |
ndltd-BGMYU2-oai-scholarsarchive.byu.edu-etd-7461 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-BGMYU2-oai-scholarsarchive.byu.edu-etd-74612019-05-16T03:17:01Z The Quest to Secure Email: A Usability Analysis of Key Management Alternatives Andersen, Jeffrey Thomas The current state of email security is lacking, and the need for end-to-end encryption of email is clear. Recent research has begun to make progress towards usable, secure email for the masses (i.e., novice users without IT support). In this paper, we evaluate the usability implications of three different key management approaches: PGP, IBE, and passwords. Our work is the first formal A/B evaluation of the usability of different key management schemes, and the largest formal evaluation of secure email ever performed. Our results reveal interesting inherent usability trade-offs for each approach to secure email. Furthermore, our research results in the first fully-implemented PGP-based secure email system that has been shown to be usable for novice users. We share qualitative feedback from participants that provides valuable insights into user attitudes regarding each key management approach and secure email generally. Finally, our work provides an important validation of methodology and design principles described in prior work. 2016-07-01T07:00:00Z text application/pdf https://scholarsarchive.byu.edu/etd/6461 https://scholarsarchive.byu.edu/cgi/viewcontent.cgi?article=7461&context=etd http://lib.byu.edu/about/copyright/ All Theses and Dissertations BYU ScholarsArchive secure email key management usability testing Computer Sciences |
collection |
NDLTD |
format |
Others
|
sources |
NDLTD |
topic |
secure email key management usability testing Computer Sciences |
spellingShingle |
secure email key management usability testing Computer Sciences Andersen, Jeffrey Thomas The Quest to Secure Email: A Usability Analysis of Key Management Alternatives |
description |
The current state of email security is lacking, and the need for end-to-end encryption of email is clear. Recent research has begun to make progress towards usable, secure email for the masses (i.e., novice users without IT support). In this paper, we evaluate the usability implications of three different key management approaches: PGP, IBE, and passwords. Our work is the first formal A/B evaluation of the usability of different key management schemes, and the largest formal evaluation of secure email ever performed. Our results reveal interesting inherent usability trade-offs for each approach to secure email. Furthermore, our research results in the first fully-implemented PGP-based secure email system that has been shown to be usable for novice users. We share qualitative feedback from participants that provides valuable insights into user attitudes regarding each key management approach and secure email generally. Finally, our work provides an important validation of methodology and design principles described in prior work. |
author |
Andersen, Jeffrey Thomas |
author_facet |
Andersen, Jeffrey Thomas |
author_sort |
Andersen, Jeffrey Thomas |
title |
The Quest to Secure Email: A Usability Analysis of Key Management Alternatives |
title_short |
The Quest to Secure Email: A Usability Analysis of Key Management Alternatives |
title_full |
The Quest to Secure Email: A Usability Analysis of Key Management Alternatives |
title_fullStr |
The Quest to Secure Email: A Usability Analysis of Key Management Alternatives |
title_full_unstemmed |
The Quest to Secure Email: A Usability Analysis of Key Management Alternatives |
title_sort |
quest to secure email: a usability analysis of key management alternatives |
publisher |
BYU ScholarsArchive |
publishDate |
2016 |
url |
https://scholarsarchive.byu.edu/etd/6461 https://scholarsarchive.byu.edu/cgi/viewcontent.cgi?article=7461&context=etd |
work_keys_str_mv |
AT andersenjeffreythomas thequesttosecureemailausabilityanalysisofkeymanagementalternatives AT andersenjeffreythomas questtosecureemailausabilityanalysisofkeymanagementalternatives |
_version_ |
1719185376680083456 |