Individual authentication in a collaborative environment | | Posted on:2009-12-04 | Degree:Ph.D | Type:Dissertation | | University:University of Maryland, Baltimore County | Candidate:Heckle, Rosa Renna | Full Text:PDF | | GTID:1448390002995391 | Subject:Information Science | | Abstract/Summary: | | | Healthcare organizations are struggling to meet security best practices, as well as complying with regulatory requirements for individual accountability. Currently emerging as a leading technology for password authentication management is the use of single sign-on technology (SSO). SSO promises to improve usability of authentication for multiple-system users, increase compliance, and help curb system maintenance costs. However, complexities are introduced when SSO is placed within a collaborative environment.;In this work I examine the implementation of an SSO technology in a hospital environment in an effort to get a true understanding of the complexities of the technology when placed in context. In addition, I assess the efficacy of the Security by Consensus model as a framework for guiding authentication security systems implementations.;This 15-month field study resulted in a rich understanding of the socio-technical complexities of an SSO implementation. A key finding is that SSO is problematic in a collaborative environment where momentary changes from individual work to collaborative work creates increased security vulnerabilities and privacy concerns for its users. The implications of these privacy issues for the user exacerbated resistance to SSO adoption. As a result I found that the elements of the social subsystem as identified in the SBC model were not sufficient, as is, for authentication systems. I posit a revised model that includes the 'individual user' as an element of the social sub-system.;Additionally, there has been a body of research around adoption and resistance of information systems. However, the underlying goals and motives of authentication systems differ from other information systems; while information systems provide value-added benefits for the user in their job performance, authentication systems do not enhance or support the user in their job performance. In fact, they are a hurdle that must be cleared before work can even begin. More importantly, authentication systems have personal privacy implications for the user. Currently no one has looked at the effectiveness of resistance or adoption theories to authentication mechanisms. This research work has looked at resistance theories and their applicability to authentication mechanisms, and has found one theoretical body that is informative for authentication mechanisms. | | Keywords/Search Tags: | Authentication, Individual, SSO, Collaborative, Environment, Resistance, Security | | Related items |
| |
|