ATbar

Lexdis 2.0

Accessible technology for learning

Main menu

Skip to primary content
Skip to secondary content
  • Welcome
  • News
  • Strategies
  • Digital Accessibility
  • Guides
  • Contribute
  • About

Tag Archives: verification

Multifactor Authentication Challenges for NLive

Posted on August 20, 2021 by E.A. Draffan
finger on iphone screen with thumb print

Logging into certain online services often requires two or multifactor authentication. Many sites or applications no longer consider an email address and password sufficient for security reasons. Just as the UK Gov National Security Centre (August 6th 2021) describe the logic behind three random words as being GCHQ’s preferred method for creating passwords, there remain a long list of what might happen next when we login online.

The problem is that authentication is a process involving the recognition and verification of a user’s identity and it is the verification that adds the complexity to the process. There is usually what the Web Content Accessibility Guidelines (WCAG) describe as a “Cognitive function test”. This means that the task “requires the user to remember, manipulate, or transcribe information.(WCAG 2.2)

People with physical, sensory, cognitive and learning disabilities may need more support and time to complete an authentication task. They may be using assistive technologies, such as screen readers and text to speech apps or keyboard alternatives. Memory and concentration issues as well as distractions can cause problems along with poor instructions or error messaging. There is a new WCAG 2.2 “Success Criterion 3.3.7 Accessible Authentication that will be a Level AA guideline, but alongside the proposed understanding there remain concerns about security issues and accessibility options

“For each step in an authentication process that relies on a cognitive function test, at least one other authentication method is available that does not rely on a cognitive function test, or a mechanism is available to assist the user in completing the cognitive function test.”

Several experts in the accessibility world have discussed these matters in more detail. Dr John Rochford in his ClearHelper blog offers some ‘Challenges & Solutions‘ for those with cognitive impairments and Dr Abi James warned the WCAG Coga task force that ‘Strong Customer Authentication in the UK‘ is now in place with more security tasks for onine payments and thanks to the “Opinion of the European Banking Authority on the elements of strong customer authentication under PSD2” it is possible to see what might be involved:

“Knowledge: Something a person knows

  • Password
  • PIN 
  • Knowledge-based challenge questions 
  • Passphrase
  • Memorised swiping path

Possession: Something a person has

  • Possession of a device evidenced by one time password (OTP) generated by, or received on a device
    • Possession of a device evidenced by a signature generated by a device
    • Card or device evidenced by QR code scanned from an external device
    • App or browser with possession evidenced by device binding
    • Card evidenced by a card reader
    • Card with possession evidenced by a dynamic card security code

Inherence: Something about the person e.g. biometrics

  • Fingerprint scanning
  • Voice recognition
  • Hand & face geometry
  • Retina & iris scanning
  • Keystroke dynamics
  • Angle at which device is held”

The challenge is to map the processes that link to the skills of users and allow for personal preferences to be enabled when accessing sites and services. WCAG has begun the task by providing pass and fail examples and this one is an adaptation for a student situation:

  1. One Time Passcode (OTP)

Pass: Student is sent an OTP passcode to their device which can be pasted into the input field

Failure: Student must generate an OTP passcode on a device in their possession and transcribe it into the payment system which could be on a separate device.

However, any set of criteria that are developed for accessibility will need to be mapped across all the authentication options and will depend on abilities, digital skills, as well the technologies in use including assistive technologies. In the case of the NLive project with the NRemote player for online learning and the presentation of multimedia content (such as video and audio for lecture capture) security, privacy as well as IP need to be considered so we will be mapping the authentication types against the considerations mentioned above!

Posted in News | Tagged authentication, login, verification

These pages show our most recent news or strategies. Search or browse by using the Tag Cloud.

Android annotation ASR assignments authentication browser calendar captions colour computer scientist diary dictionary digital accessibility ebooks ePub Evernote Google calendar Google Docs iPad iPhone iPhone app keyboard access kindle magnification memory MFA notes note taking onscreen reading organisation passwords persona PowerPoint presentations reading references reminders scanning Siri speech recognition TextHelp Read and Write Gold text to speech timetable transcripts voice recognition

Tweets by @EADraffan

Recent Posts

  • Voice Cloning to improve Automatic Speech Recognition
  • Key words can help us remember important points in a transcript. But can AI find them?
  • Expanding the metrics for evaluating ASR recordings to highlight errors possibly related to bias in training data.
  • Automatic Speech Recognition captioning and transcription user needs analysis
  • Add a Touch of AI to your Christmas and New Year Celebrations.

Archives

  • July 2023
  • June 2023
  • April 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • September 2021
  • August 2021
  • December 2020
  • May 2020
  • April 2020
  • March 2020
  • January 2020
  • December 2018
  • October 2018
  • September 2018
  • May 2018
  • December 2017
  • July 2017
  • January 2017
  • December 2016
  • November 2016
  • October 2016
  • September 2016
  • May 2016
  • April 2016
  • February 2016
  • January 2016
  • November 2015
  • February 2015
  • November 2014
  • September 2014
  • February 2014
  • January 2014
  • November 2013
  • October 2013
  • September 2013
  • August 2013
  • July 2013
  • April 2013
  • March 2013
  • February 2013
  • January 2013
  • December 2012
  • November 2012
  • October 2012
  • September 2012
  • August 2012
  • July 2012
  • June 2012
  • May 2012
  • April 2012
  • March 2012

 

Privacy Policy · Accessibility Statement

Creative Commons License
This work is licensed under a Creative Commons Attribution 4.0 International License.
Proudly powered by WordPress