Jongkil Jeong

dblp:220/4827 · also Jongkil Jay Jeong · DBLP profile ↗
← Back
9ranked-venue papers
3as first author
9since 2021 · last 2024
0000-0003-3491-687XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 1 first-author · 5 since 2021Human-computer interaction and ubiquitous computing · 4 · 2 first-author · 4 since 2021
YearPublicationVenuePosition
2024 POSTER: Addressing the Privacy by Use Challenges in Verifiable Credential based Digital Wallets
abstract
The concept of Verifiable Credentials (VC) has emerged as a viable alternative to federated identity systems and can offer greater levels of control and ownership to users over their Digital Identity. However, the inability of users to make optimal decisions in relation to the use of VC results in privacy risks. To address this gap in VC technology, we present game-theoretic models for optimising the privacy of users and simultaneously ensuring minimum disclosure of PII in line with privacy safeguards around CDR and GDPR expectations around anonymity and unlinkability and demonstrate these properties through a digital credential wallet (DCW). The developed technology will deliver a novel DCW which embeds decision-making ability to quantify, benchmark and recommend the optimal usage of credentials that are held within the DCW.
Jongkil Jeong, Lu-Xing Yang, Robin Doss, Praveen Gauravaram, Zoe Wang, Mohamed Almorsy, Ashish Nanda, Keerthivasan Viswanathan
AsiaCCS1
2024 Examining usable security features and user perceptions of Physical Authentication Devices
abstract
Despite the enhanced security benefits offered by Physical Authentication Devices (PADs) compared to other forms of Multi-Factor Authentication (MFA), the adoption and retention of PADs remain relatively low in comparison to other MFA methods. Evidence indicates that the limited widespread adoption and usage of PADs are primarily due to negative user perceptions concerning their usability and security features. Moreover, there's a limited understanding of how users from diverse backgrounds perceive PADs with their varying standards and features. To bridge this knowledge gap, we undertook a multiple case study with 23 users spanning varied demographic characteristics (age, gender, education, and experience with MFA) to use and test three distinct PADs. Case study participants were provided with three unique PAD devices featuring different characteristics/features and were prompted to share their experiences of installation, usage, and troubleshooting over a 2-week span via an initial questionnaire, logbook, and a final interview. The gathered data were analysed using NVIVO, a Qualitative Research Software platform, uncovering notable disparities between user groups and their predilections for specific PADs. Further discussions from our research illuminate four primary areas (Compatibility, Support, Quality and Simplicity) where usable security features impede positive user perception of PAD devices and addressing these areas is crucial for enhancing PAD adoption and retention rates.
Ashish Nanda, Jongkil Jeong, Syed Wajid Ali Shah, Mohammad Reza Nosouhi, Robin Doss
Comput. Secur.2
2024 User Characteristics and Their Impact on the Perceived Usable Security of Physical Authentication Devices
abstract
Physical authentication devices (PADs) offer a higher level of security than other authentication technologies commonly used in multifactor authentication (MFA) schemes because they are much less vulnerable to attack. However, PAD uptake remains significantly lower than that for SMS and app-based approaches, accounting for only 10% of all authentication technologies currently being utilized in MFA. Prior studies indicate that the primary reason for this low adoption rate is due to negative users' perceptions and attitudes toward the usability of PADs; many of these studies often skew toward a particular set of users (e.g., young university students, etc.), often creating a bias toward what usable security entails. To address this limitation, we have formulated an original research methodology that segments users into specific groups based on their user characteristics (i.e., age, education, and experience) and examines how each group defines usability and ranks their preferences regarding certain security features. Based on a survey of 410 participants, our results indicate that there are indeed different usable security preferences for each user group, and we, therefore, provide recommendations on how existing PADs might be enhanced to support usability and improve adoption rates.
Jongkil Jeong, Syed Wajid Ali Shah, Ashish Nanda, Robin Doss, Mohammad Reza Nosouhi, Jeb Webb
IEEE Trans. Hum. Mach. Syst.1
2023 New directions in convergence computing
Junseok Yoo, Jongkil Jeong
Pers. Ubiquitous Comput.2
2022 Improving Unlinkability of Attribute-based Authentication through Game Theory
abstract
This article first formalizes the problem of unlinkable attribute-based authentication in the system where each user possesses multiple assertions and uses them interchangeably. Currently, there are no recommendations for optimal usage of assertions in such authentication systems. To mitigate this issue, we use conditional entropy to measure the uncertainty for a Relying Party who attempts to link observed assertions with user labels. Conditional entropy is the function of usage statistics for all assertions in the system. Personaldecisionsmade by the users about the usage of assertions contribute to these statistics. This collective effect from all the users impacts the unlinkability of authentication and must be studied using game theory. We specify several instances of the game where context information that is provided to the users differs. Through game theory and based on conditional entropy, we demonstrate how each user optimizes usage for the personal set of assertions. In the experiment, we substantiate the advantage of the proposed rational decision-making approaches: Unlinkability that we obtain under Nash equilibrium is higher than in the system where users authenticate using their assertions at random. We finally propose an algorithm that calculates equilibrium and assists users with the selection of assertions. This manifests that described techniques can be executed in realistic settings. This does not require modification of existing authentication protocols and can be implemented in platform-independent identity agents. As a use case, we describe how our technique can be used in Digital Credential Wallets: We suggest that unlinkability of authentication can be improved for Verifiable Credentials.
Yevhen Zolotavkin, Jongkil Jeong, Veronika Kuchta, Maksym Slavnenko, Robin Doss
ACM Trans. Priv. Secur.2
2021 Evaluating the Current State of Application Programming Interfaces for Verifiable Credentials
abstract
One of the challenges to the adoption of the decentralised approach to digital ID is a lack of consensus and standardisation of how different stakeholders within the ecosystem can inter-operate. As a means to address this issue, we examine the use of standard application programming interfaces (API) to integrate decentralised digital identification systems to preexisting ones. We first examine the current literature and solutions to (a) assess the attributes necessary to compare and contrast APIs, and (b) create a list of API providers within the decentralised digital ID marketplace, (c) compare the API providers against the attributes established. Based on an API Usability and Adoption framework as our lens, we assessed 19 service providers of APIs against their use cases. We identified that whilst the APIs are maturing, the APIs remain inconsistent and poorly adopted. A clear standard API could assist in better adoption. The guidance provided can inform organisations implementing digital identity and VCs along their adoption journey
Nikesh Lalchandani, Frank Jiang 0001, Jongkil Jeong, Yevhen Zolotavkin, Robin Doss
PST3
2021 Enhancing Privacy Through DMMA: Decision-Making Method for Authentication
abstract
Attribute-Based Authentication (ABA) is becoming more prevalent in everyday interactions. In this paper, we propose the Decision-Making Method for Authentication (DMMA) to address the privacy concerns in ABA. The need for DMMA is supported through multiple observations. First, in practice, the indistinguishability of crypto-proof-based assertions (that are posessed by different users) fails with non-zero probability. This explains why cryptographic means alone are insufficient to provide a substantial level of unlinkability in ABA systems with n users. Second, each user in ABA possesses multiple credentials: they can be used interchangeably to get access to the service(s) which is provided by a relying party (RP). DMMA addresses the challenge of interchangeable usage. As an initial step, we synthesized the criterion of unlinkability: it is based on the definitions of international standard ISO 27551 as well as the information theoretic measure of conditional entropy. We then use that criterion to formalize the task of authentication as a non-cooperative coordination game. In this game, players (targets of the attack) maximize their utilities by using their assertions interchangeably. The experiment demonstrates that a number of equilibria with substantially higher unlinkability can be achieved. Unlinkability vary depending on: i) the information (and its trustworthiness) about the moves of the other players in the game; ii) the statistical distribution of user attributes. DMMA demonstrates how users may be provided recommendations over the optimal selection of assertions for ABA. These recommendations can have a practical impact if DMMA is implemented as a feature within Digital Credential Wallets (DCWs).
Maksym Slavnenko, Yevhen Zolotavkin, Jongkil Jeong, Veronika Kuchta, Robin Doss
TrustCom3
2021 The importance of social identity on password formulations
Marthie Grobler, Mahawaga Arachchige Pathum Chamikara, Jacob Abbott, Jongkil Jeong, Surya Nepal, Cécile Paris
Pers. Ubiquitous Comput.4
2021 The current state of research on people, culture and cybersecurity
Jongkil Jeong, Gillian C. Oliver, Eunsuk Kang, Sadie Creese
Pers. Ubiquitous Comput.1