Users embrace the rapid development of virtual reality (VR) technology. We are witnessing a widespread adoption of VR technology in more routine settings, such as gaming, social interactions, shopping, and commerce. VR systems access sensitive user data and assets when handling these routine activities, including payment, which raises the need for user authentication in VR. However, there is a limited understanding of how users perceive user authentication in VR, in particular, how users' interaction experiences factor into their perception of security and privacy. Our work adopts a ``technology probe'' approach to understand this question. We design technology probes of authentication in VR based on existing authentication interactions in both VR and the physical world. Further, we embed these probes in the routine payment of a VR game. Our qualitative analysis reveals that users face unique usability challenges in VR authentication, e.g., in motion control. Such challenges also hinder users from accessing security and privacy accurately in VR authentication. Users' expectations for VR authentication mainly center on improvements in interaction. However, their expectations could appear nonspecific and conflicting. We provide recommendations to accommodate users' expectations and resolve conflicts between usability and security.
翻译:用户热衷于虚拟现实技术的快速发展。我们正在目睹VR技术在更常规的环境下得到广泛应用,如游戏、社交互动、购物和商业。VR系统在处理这些常规活动时接触到敏感的用户数据和资产,包括支付,这就提高了在VR中进行用户身份验证的需求。然而,我们对用户如何感知VR身份验证,特别是用户的交互体验如何影响他们对安全和隐私的感知,了解甚少。我们的工作采用了“技术探针”的方法来理解这个问题。我们基于现有的VR和物理世界中的身份验证交互设计了VR身份验证技术探针。此外,我们把这些技术探针嵌入到VR游戏的日常支付环节中。我们的定性分析揭示了用户在VR身份验证中面临着独特的可用性挑战,例如在运动控制方面。这些挑战也妨碍了用户准确地访问VR身份验证的安全和隐私。用户对于VR身份验证的期望主要集中在改善交互。然而,他们的期望可能显得不具体且存在冲突。我们提供了建议,以适应用户的期望并解决可用性和安全之间的冲突。