Experience Design Framework for securing Large Scale Information and Communication Systems

51
Azadeh Nematzadeh Omar Sosa-Tzec School of Informatics and Computing Indiana University Design Research Society Conference 2014 June 16, 2014. Umeå, Sweden Experience Design Framework for Securing Large Scale Information and Communication Systems

description

* Paper presented at the Design Research Society Conference 2014 at Umeå, Sweden. It proposes a framework for UX design regarding security and privacy of Information and Communication Systems (ICSs) ---- Abstract ----- Securing Information and Communication Systems (ICSs) is a highly complex process due in large part to the feedback relationship that holds between the users and the system and its 'ecosystem' of usage. Such a relationship is critical for experience designers. The design of secure systems can thereby be enhanced by using principles from disciplines where similar relations hold, such as security engineering and adaptive systems. In this work, we propose a user experience design framework based on six principles and use a social networking system as an example of its application. The proposed design principles are grounded in complex systems theory. We address several potential security and privacy challenges inherent in the design of a large-scale adaptive system. By means of this framework we reflect upon the participation of an experience designer regarding the conceptualization, selection, review, and update of security and privacy matters. In this sense, we observe the role of the designer as a translator across disciplines. By introducing our framework, we also attempt to start a conversation about the challenges a designer faces in the appropriation of this role, either for the case of securing large-scale systems or in those situations where the boundaries of design and knowledge from other disciplines already overlap.

Transcript of Experience Design Framework for securing Large Scale Information and Communication Systems

Page 1: Experience Design Framework for securing Large Scale Information and Communication Systems

Azadeh NematzadehOmar Sosa-TzecSchool of Informatics and Computing Indiana University

Design Research Society Conference 2014June 16, 2014. Umeå, Sweden

Experience Design Framework for Securing Large Scale Information and Communication Systems

Page 2: Experience Design Framework for securing Large Scale Information and Communication Systems

1. Security and Privacy Concerns

2. Information and Communication Systems (ICSs) Concerns

3. Complex Systems and ICSs

4. Security and Privacy Framework

5. Implications

6. Conclusions

agenda

Page 3: Experience Design Framework for securing Large Scale Information and Communication Systems

1 . Security and Privacy Concerns

Page 4: Experience Design Framework for securing Large Scale Information and Communication Systems
Page 5: Experience Design Framework for securing Large Scale Information and Communication Systems

As designers, what and howdo we think about

security and privacyof Information and

Communication Systems?

Page 6: Experience Design Framework for securing Large Scale Information and Communication Systems

People have di!ferent privacy and security concerns

Page 7: Experience Design Framework for securing Large Scale Information and Communication Systems

Picture source: http://bit.ly/1xFLspW

responsibility on the users’ hands

Page 8: Experience Design Framework for securing Large Scale Information and Communication Systems
Page 9: Experience Design Framework for securing Large Scale Information and Communication Systems

between public and private

Page 10: Experience Design Framework for securing Large Scale Information and Communication Systems

Unknown and unpredictable security and privacy threats and failures

Page 11: Experience Design Framework for securing Large Scale Information and Communication Systems
Page 12: Experience Design Framework for securing Large Scale Information and Communication Systems
Page 13: Experience Design Framework for securing Large Scale Information and Communication Systems

2. ICSs concerns

Page 14: Experience Design Framework for securing Large Scale Information and Communication Systems

Heterogeneity of users

Page 15: Experience Design Framework for securing Large Scale Information and Communication Systems

Image by the authors

u

u

u

u

u

u

u

u

uu

u

u

u

u

u

u

u

u

u

u

u

u

u

diverse people: a “world” using icss

Page 16: Experience Design Framework for securing Large Scale Information and Communication Systems

ICSs entailmultiple use scenarios

Page 17: Experience Design Framework for securing Large Scale Information and Communication Systems

same system, different use

Page 18: Experience Design Framework for securing Large Scale Information and Communication Systems

different security and privacy scenarios

Page 19: Experience Design Framework for securing Large Scale Information and Communication Systems

Use scenarios change over time

Page 20: Experience Design Framework for securing Large Scale Information and Communication Systems
Page 21: Experience Design Framework for securing Large Scale Information and Communication Systems

Information and Communication Systems also change

Page 22: Experience Design Framework for securing Large Scale Information and Communication Systems

Picture source: http://bit.ly/1lblv7T

Page 23: Experience Design Framework for securing Large Scale Information and Communication Systems

3. Complex Systems and ICSs

Page 24: Experience Design Framework for securing Large Scale Information and Communication Systems

Picture source: http://karaaustin.blogspot.com/

complex systems

Picture source: http://tinyurl.com/k76185y Picture source: http://bit.ly/SDVhE9 Picture source: http://dailym.ai/IUNYDM

Page 25: Experience Design Framework for securing Large Scale Information and Communication Systems

Aspects of security and privacy in ICSs show the characteristics of

complex systems

Page 26: Experience Design Framework for securing Large Scale Information and Communication Systems

Picture source: http://bit.ly/1s7lmw0

self-organization

Page 27: Experience Design Framework for securing Large Scale Information and Communication Systems

Picture source: http://bit.ly/1kQ3X64

emergence

Page 28: Experience Design Framework for securing Large Scale Information and Communication Systems

Picture source: http://bit.ly/1oWmXiy

evolution

Picture source: http://bit.ly/1qBWKXJ

Page 29: Experience Design Framework for securing Large Scale Information and Communication Systems

Picture source: http://bit.ly/1nxVy70

coevolution

Page 30: Experience Design Framework for securing Large Scale Information and Communication Systems

As complex systems, ICSs entail user-system coevolution

Page 31: Experience Design Framework for securing Large Scale Information and Communication Systems

Image by the authors

ICSTimeUser

User-System Coevolution

Page 32: Experience Design Framework for securing Large Scale Information and Communication Systems

4. Security and Privacy Framework

Page 33: Experience Design Framework for securing Large Scale Information and Communication Systems

Complex System

Heterogeneity of users

User's privacy and security concerns and behaviors

Multiple use scenarios

Evolvable use scenarios

Evolution on ICT infrastructure

security and privacy challenges for experience design

Page 34: Experience Design Framework for securing Large Scale Information and Communication Systems

AvoidUnintentional

Disclosure

Securityand Privacy

Matters

Expandability

Personalization

AdaptabilityUsability

Image by the authors

framework

Page 35: Experience Design Framework for securing Large Scale Information and Communication Systems

security and privacy matters

Image by the authors

* Discussion* Re!lection

* Interaction !lows

* Possible security and privacy mechanisms

* Taking into account dynamic behavior

* How to mitigate future attacks* Think about possible system failures

* Generalities of the users* Context of use* Technological aspects

Security and Privacy

Specialist

ExperienceDesigner

User

Page 36: Experience Design Framework for securing Large Scale Information and Communication Systems

personalization

Image by the authors

Users: group 1 Users: group n-1

Large-Scale ICS

Privacy and Security Mechanisms

Users: group n

SensitiveParameters

SensitiveParameters

SensitiveParameters

Page 37: Experience Design Framework for securing Large Scale Information and Communication Systems

Facebook images from author's profile

personalization

Page 38: Experience Design Framework for securing Large Scale Information and Communication Systems

adaptability, expandability and usability

Image by the authors

User

tn t n+1User's attributes

Interaction withthe system

User's attributes

ICS

Page 39: Experience Design Framework for securing Large Scale Information and Communication Systems

Facebook images from author's profile

adaptability, expandability and usability

Page 40: Experience Design Framework for securing Large Scale Information and Communication Systems

Facebook images from author's profile

unintentional disclosure

Page 41: Experience Design Framework for securing Large Scale Information and Communication Systems

5. Implications

Page 42: Experience Design Framework for securing Large Scale Information and Communication Systems

ICSTimeUser

+ +

what is the meaning of this relation?

Page 43: Experience Design Framework for securing Large Scale Information and Communication Systems

The experience designer as translator and communicator

of knowledge

Page 44: Experience Design Framework for securing Large Scale Information and Communication Systems

ICS

TimeUser

ExperienceDesigner

Securityand Privacy Specialist

Client andStakeholders

User-System Coevolution

Design Process

Page 45: Experience Design Framework for securing Large Scale Information and Communication Systems

ICSs entail a challenge forboth design practice

and design pedagogy

Page 46: Experience Design Framework for securing Large Scale Information and Communication Systems

6. Conclusions

Page 47: Experience Design Framework for securing Large Scale Information and Communication Systems

We proposed an experience design framework constituted

by six security and privacy principles

Page 48: Experience Design Framework for securing Large Scale Information and Communication Systems

Security and Privacy MattersPersonalization

AdaptabilityExpandability

UsabilityAvoid Unintentional Disclosure

Page 49: Experience Design Framework for securing Large Scale Information and Communication Systems

Complex SystemsHeterogeneity of Users

Multiple and Evolvable Use ScenariosUser-System Coevolution

Security and PrivacyExperience Design

Page 50: Experience Design Framework for securing Large Scale Information and Communication Systems

Our attempt is to open a conversation about security

and privacy, and also about the implications of user-system

coevolution in ICSs for experience design.