Developing simple and expressive access controls -- interfaces to specify policies that define who should have access to resources and under what circumstances -- is a longstanding challenge in usable security. We present Sketch-based Access Control (SBAC), a sketch-based, AI-assisted access control authoring system that combines the expressive power of sketching with the interpretive capabilities of multimodal large language models (MLLMs) to support the interpretation and validation of policy specifications as they are iteratively refined. Through a formative study with 14 participants, we identified three design requirements and developed a human-AI collaborative workflow composed of three stages -- Specify, Analyze, and Test -- enabled by the system's ability to maintain and interpret evolving access control specifications. In a user evaluation with 14 participants grounded in their real-world access control scenarios, we found the system and the workflow helped participants progressively refine initially underspecified preferences into more complete and precise policies -- surfacing gaps they had not anticipated, resolving ambiguities through dialogue, and validating policy behavior through concrete scenarios.
参考文献
Internet Society
The security blanket of the chat world: An analytic evaluation and a user study of telegram
Ruba Abu-Salma, Kat Krol, Simon Parkin, Victoria Koh, Kevin Kwan, Jazib Mahboob, Zahra Traboulsi, M Angela Sasse
Published: 2017
ACM SIGGRAPH 2007 courses
SketchREAD: a multi-domain sketch recognition engine
Christine Alvarado, Randall Davis
Published: 2007
Proceedings of the SIGCHI Conference on Human Factors in Computing Systems
Real life challenges in access-control management
Lujo Bauer, Lorrie Faith Cranor, Robert W Reeder, Michael K Reiter, Kami Vaniea
Frederic Gmeiner, Nicolai Marquardt, Michael Bentley, Hugo Romat, Michel Pahud, David Brown, Asta Roseway, Nikolas Martelaro, Kenneth Holstein, Ken Hinckley, et al.
Proceedings of the SIGCHI conference on Human factors in computing systems
Technology probes: inspiring design for and with families
Hilary Hutchinson, Wendy Mackay, Bo Westerlund, Benjamin B Bederson, Allison Druin, Catherine Plaisant, Michel Beaudouin-Lafon, Stéphane Conversy, Helen Evans, Heiko Hansen, et al.
Published: 2003
Proceedings of the 2023 CHI Conference on Human Factors in Computing Systems
Less is not more: Improving findability and actionability of privacy controls for online behavioral advertising
Jane Im, Ruiyi Wang, Weikun Lyu, Nick Cook, Hana Habib, Lorrie Faith Cranor, Nikola Banovic, Florian Schaub
Published: 2023
2010 IEEE International Symposium on Policies for Distributed Systems and Networks
Usable policy template authoring for iterative policy refinement
Maritza Johnson, John Karat, Clare-Marie Karat, Keith Grueneberg
Published: 2010
Eleventh symposium on usable privacy and security (SOUPS 2015)
My data just goes Everywhere: user mental models of the internet and implications for privacy and security
Ruogu Kang, Laura Dabbish, Nathaniel Fruchter, Sara Kiesler
Published: 2015
Proceedings of the SIGCHI conference on Human Factors in computing systems
Evaluating interfaces for privacy policy rule authoring
Clare-Marie Karat, John Karat, Carolyn Brodie, Jinjuan Feng