Publications
Type of Publication: Article in Journal
Building Trust in Remote Attestation Through Transparency – A Qualitative User Study on Observable Attestation
- Author(s):
- Sebastian Linsner, Kilian Demuth; Sebastian Surminski, Lucas Davi; Reuter, Christian
- Title of Journal:
- Behaviour & Information Technology
- Publication Date:
- 2024
- pages:
- 1-21
- Digital Object Identifier (DOI):
- doi:10.1080/0144929X.2024.2374889
- Citation:
- Download BibTeX
Abstract
Internet of Things (IoT) devices have become increasingly important within the smart home domain, making the security of the devices a critical aspect. The majority of IoT devices are black-box systems running closed and pre-installed firmware. This raises concerns about the trustworthiness of these devices, especially considering that some of them are shipped with a microphone or a camera. Remote attestation aims at validating the trustworthiness of these devices by verifying the integrity of the software. However, users cannot validate whether the attestation has actually taken place and has not been manipulated by an attacker, raising the need for HCI research on trust and understandability. We conducted a qualitative study with 35 participants, investigating trust in the attestation process and whether this trust can be improved by additional explanations in the application. We developed an application that allows users to attest a smart speaker using their smartphone over an audio channel to identify the attested device and observe the attestation process. In order to observe the differences between the applications with and without explanations, we performed A/B testing. We discovered that trust increases when additional explanations of the technical process are provided, improving the understanding of the attestation process.