Challenges with passwordless FIDO2 in an enterprise setting: a usability study

Michal Kepkowski, Maciej Machulak, Ian Wood, Dali Kaafar

Research output: Chapter in Book/Report/Conference proceedingConference proceeding contributionpeer-review

4 Citations (Scopus)

Abstract

Fast Identity Online 2 (FIDO2), a modern authentication protocol, is gaining popularity as a default strong authentication mechanism. It has been recognized as a leading candidate to overcome limitations (e.g., it is phishing resistant) of existing authentication solutions. However, the task of deprecating weak methods such as password-based authentication is not trivial and requires a comprehensive approach. While security, privacy, and end-user usability of FIDO2 have been addressed in both academic and industry literature, the difficulties associated with its integration with production environments, such as solution completeness or edge-case support, have received little attention. In particular, complex environments such as enterprise identity management pose unique challenges for any authentication system. In this paper, we identify challenging enterprise identity lifecycle use cases (e.g., remote workforce and legacy systems) by conducting a usability study, in which 118 professionals shared their perception of challenges to FIDO2 integration from their hands-on field experience. Our analysis of the user study results revealed serious gaps such as account recovery (selected by over 60% of our respondents), and identify priority development areas for the FIDO2 community.

Original languageEnglish
Title of host publicationProceedings 2023 IEEE Secure Development Conference SecDev 2023
Place of PublicationPiscataway, NJ
PublisherInstitute of Electrical and Electronics Engineers (IEEE)
Pages37-48
Number of pages12
ISBN (Electronic)9798350331325
ISBN (Print)9798350331332
DOIs
Publication statusPublished - 2023
Event2023 IEEE Secure Development Conference, SecDev 2023 - Atlanta, United States
Duration: 18 Oct 202320 Oct 2023

Conference

Conference2023 IEEE Secure Development Conference, SecDev 2023
Country/TerritoryUnited States
CityAtlanta
Period18/10/2320/10/23

Fingerprint

Dive into the research topics of 'Challenges with passwordless FIDO2 in an enterprise setting: a usability study'. Together they form a unique fingerprint.

Cite this