论文标题
“告诉我,你怎么知道是我?”对智能扬声器应用程序的安全性和个性化措施的期望
"Tell me, how do you know it's me?" Expectations of security and personalization measures for smart speaker applications
论文作者
论文摘要
语音控制的智能扬声器设备在许多现代家庭中都立足。它们的流行与入侵核心私人生活相结合,激发了对安全和隐私入侵的研究,尤其是那些在此类设备上使用的第三方应用程序执行的研究。在这项工作中,我们从不太悲观的角度仔细研究了这样的第三方应用程序:我们认为它们具有提供个性化和安全的功能并调查对用户进行认证的措施(``PIN'',````语音身份验证)'',``````'''''''的潜力。为此,我们要求100名参与者评估15个应用程序类别和51个具有广泛功能的应用程序。我们探索的主要问题集中在:用户对不同类别应用程序的安全性和个性化的偏好;不同应用程序的首选安全性和个性化措施;以及相应度量的首选频率。 经过初步的试点研究,我们主要关注7种应用程序,据报道安全和个性化很重要。这些包括三个关键类别的金融,账单和购物。我们发现,``语音身份验证''虽然目前尚未由我们研究的应用程序使用,但它是实现安全性和个性化的非常流行的措施。许多参与者愿意探索安全措施的组合,以增加对高度相关应用程序的保护。在这里,``PIN''和``语音身份验证''的组合显然是最需要的。这一发现表明,将``语音身份验证''与其他措施无缝结合的系统可能是未来工作的良好候选人。
Voice-controlled smart speaker devices have gained a foothold in many modern households. Their prevalence combined with their intrusion into core private spheres of life has motivated research on security and privacy intrusions, especially those performed by third-party applications used on such devices. In this work, we take a closer look at such third-party applications from a less pessimistic angle: we consider their potential to provide personalized and secure capabilities and investigate measures to authenticate users (``PIN'', ``Voice authentication'', ``Notification'', and presence of ``Nearby devices''). To this end, we asked 100 participants to evaluate 15 application categories and 51 apps with a wide range of functions. The central questions we explored focused on: users' preferences for security and personalization for different categories of apps; the preferred security and personalization measures for different apps; and the preferred frequency of the respective measure. After an initial pilot study, we focused primarily on 7 categories of apps for which security and personalization are reported to be important; those include the three crucial categories finance, bills, and shopping. We found that ``Voice authentication'', while not currently employed by the apps we studied, is a highly popular measure to achieve security and personalization. Many participants were open to exploring combinations of security measures to increase the protection of highly relevant apps. Here, the combination of ``PIN'' and ``Voice authentication'' was clearly the most desired one. This finding indicates systems that seamlessly combine ``Voice authentication'' with other measures might be a good candidate for future work.