6th European Symposium on Research in Computer Security (ESORICS 2000)

How Much Negociation and Detail Can Users Handle? Experiences with Security Negociation and the Granularity of Access Control in Communications

Kai Rannenberg

Abstract : Tailor made security is being enabled by more options for specifying security policies and enhanced possibilities for negotiating security. On the other side these new options raise the complexity of transactions and systems: Users can be overwhelmed, which can lead to less security than before. This paper describes conclusions from a case study and trial of personal reachability and security manager for telephone based communication. The device helped to negociate and balance security requirements. The study analysed how much negociation and detail users could handle during their day-to-day transactions and how they could be supported. Some results are strongly related to more 'classic' security techniques like access control that are becoming more and more interactive: When users learn to understand the consequences of their access control decisions and can tune their policies these mature to a satisfying level. When users see advantages for their daily activities they are willing to invest more time into understanding additional complexity.

(Pages 37-54)

