A Requirement-Based Framework for Engineering Adaptive Authentication
Alzubair Hassan, Alkabashi Alnour, Bashar Nuseibeh, Liliana Pasquale

TL;DR
This paper introduces a framework for designing adaptive authentication systems that dynamically select appropriate methods based on changing contextual factors and security risks, ensuring security and usability.
Contribution
It presents a novel framework using goal and feature models, combined with a Fuzzy Causal network and Z3 solver, to guide the selection of authentication methods in dynamic environments.
Findings
Effective at adapting to changing contexts in IoV and healthcare scenarios.
Improves security risk mitigation while maintaining usability.
Demonstrated feasibility through real-world case studies.
Abstract
Authentication is crucial to confirm that an individual or entity trying to perform an action is actually who or what they claim to be. In dynamic environments such as the Internet of Things (IoT), Internet of Vehicles (IoV), healthcare, and smart cities, security risks can change depending on varying contextual factors (e.g., user attempting to authenticate, location, device type). Thus, authentication methods must adapt to mitigate changing security risks while meeting usability and performance requirements. However, existing adaptive authentication systems provide limited guidance on (a) representing contextual factors, requirements, and authentication methods (b) understanding the influence of contextual factors and authentication methods on the fulfilment of requirements, and (c) selecting effective authentication methods that reduce security risks while maximizing the satisfaction…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsUser Authentication and Security Systems · Advanced Authentication Protocols Security · RFID technology advancements
