Publications

Publications

Type of Publication: Article in Journal

Building Trust in Remote Attestation Through Transparency – A Qualitative User Study on Observable Attestation

Author(s):
Sebastian Linsner, Kilian Demuth; Sebastian Surminski, Lucas Davi; Reuter, Christian
Title of Journal:
Behaviour & Information Technology
Publication Date:
2024
pages:
1-21
Digital Object Identifier (DOI):
doi:10.1080/0144929X.2024.2374889
Citation:
Download BibTeX

Abstract

Internet of Things (IoT) devices have become increasingly important within the smart home domain, making the security of the devices a critical aspect. The majority of IoT devices are black-box systems running closed and pre-installed firmware. This raises concerns about the trustworthiness of these devices, especially considering that some of them are shipped with a microphone or a camera. Remote attestation aims at validating the trustworthiness of these devices by verifying the integrity of the software. However, users cannot validate whether the attestation has actually taken place and has not been manipulated by an attacker, raising the need for HCI research on trust and understandability. We conducted a qualitative study with 35 participants, investigating trust in the attestation process and whether this trust can be improved by additional explanations in the application. We developed an application that allows users to attest a smart speaker using their smartphone over an audio channel to identify the attested device and observe the attestation process. In order to observe the differences between the applications with and without explanations, we performed A/B testing. We discovered that trust increases when additional explanations of the technical process are provided, improving the understanding of the attestation process.