Title Usability-Driven security design patterns
Translation of Title Usability-Driven Security Design Patterns.
Authors Palh, Jahanzaib Manzoor
Full Text Download
Pages 73
Keywords [eng] Keywords: Usable Security, Semantic Authentication System, Spoofing Prevention, Human-Computer Interaction (HCI), Accessibility in authentication, Large Language Models, Cognitive Load, Anti-Phishing Design. Raktiniai žodžiai: Naudojimo saugumas, Semantinė autentifikavimo sistema, Apgaulinga informacija, Žmogaus ir kompiuterio sąveika (HCI), Prieinamumas autentifikavimo metu, Dideli kalbos modeliai, Kognityvinė apkrova, Apsauga nuo sukčiavimo apsimetant.
Abstract [eng] All authentication design patterns share a fundamental structural weakness: users cannot verify a site's legitimacy before entering their credentials, leaving them vulnerable to phishing and spoofing. The baseline pattern examined in this thesis, security question authentication, performs poorly on both usability and security dimensions, offering no phishing resistance and failing across recoverability, accessibility, navigation, and feedback criteria. This thesis proposes the Semantic Authentication System (SAS), a design pattern built on two independently managed trust factors: a personal secret phrase verified semantically via vector embeddings and LLM judgment, and a user-generated personal image displayed before any input is requested. The pre-login image serves as a passive phishing trust signal that a fake page cannot replicate. At the same time, semantic verification alleviates the exact-recall burden of traditional knowledge-based authentication. Either factor can be updated independently at any time. Evaluation across nineteen criteria yielded Completely Implemented ratings in usability, deployment, and security perspectives. Empirical testing with 10 participants yielded a 100% phishing detection rate, a mean satisfaction rating on the Likert scale of 4.37/5, and a NASA-TLX cognitive load score of 35.6. SAS demonstrates that AI-driven semantic flexibility, combined with a personal visual trust token, can simultaneously resolve the usability, accessibility, and phishing-resistance gaps left unaddressed by current mainstream authentication patterns.
Dissertation Institution Vilniaus universitetas.
Type Master thesis
Language English
Publication date 2026