Users’ Privacy Attitudes towards the Use of Behavioral Biometrics Continuous Authentication (BBCA) Technologies: A Protection Motivation Theory Approach
Abstract
1. Introduction
2. Background: Behavioral Biometrics Continuous Authentication
3. Related Work
4. Theoretical Background and Research Model
- Biometrics can be collected or shared without the permission of the specific user, without adequate knowledge, or without a specific purpose [63].
- Biometric data collected for one purpose may be used for an unintended or unauthorized purpose in the future [63].
- Biometrics can be used for purposes other than those explicitly stated, or biometrics can be abused to generate extra information [63].
- Individuals can be identified or tracked by biometrics. Since biometric data is considered unique, it can be used to track and locate persons when they try to get access to certain facilities or as their biometric attributes are collected by a surveillance system [63].
- Biometrics can be stored and/or transmitted incorrectly so they are outside the control of the user. External attacks against biometrics would be possible as a result of this [64].
- The potential threat to users’ privacy posed by the misuse of biometric information is a topic of debate and frequently prevents the widespread adoption of biometric systems [63].
- Biometrics cannot be protected via conventional encryption due to their fuzzy nature. As a consequence, they are vulnerable to a variety of threats [62].
4.1. Threat-Appraisal
4.2. Coping-Appraisal
4.3. Innovativeness
4.4. Privacy Concerns
4.5. Trust
4.6. Survey Instrument
5. Results
5.1. Descriptive Analysis
5.2. Measurement Model
- Composite reliability (CR) estimations generate an internal consistency reliability coefficient based on the proportion of variation explained by the test items compared to the overall variance of the composite test score [91].
5.3. Structural Model Results and Hypotheses Testing
6. Discussion
6.1. Privacy Concerns as Antecedent of Coping Appraisal
6.2. Perceived Vulnerability
6.3. Self Efficacy
6.4. Perceived Response Efficacy
6.5. Innovativeness
7. Implications, Limitations, and Future Research
8. Conclusions
- 72.4% of users have the intention to use BBCA technology. Among them.
- 34% will use BBCA because of Perceived Vulnerability.
- 20.8% will use BBCE because of Perceived Severity.
- 64.9% will use BBCA because of Perceived Response Efficacy.
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Acknowledgments
Conflicts of Interest
Appendix A. Questionnaire
| Construct | Item | Question | Adapted From | 
|---|---|---|---|
| Innovativeness I | I1 | I am among the first to try out new technologies. | |
| I2 | When I hear about a new technology, I look for ways to adopt it. | [97] | |
| I3 | I like to experiment with new technologies. | [98] | |
| I4 | I am a person who searches for novel approaches not required at the time. | ||
| Privacy Concerns PC | PC1 | I am concerned that my personal information could be used for wrong purposes. | [99] | 
| PC2 | I am concerned that my personal information could be accessed by unknown parties. | ||
| Trust in Technology TT | TT1 | I would trust biometric authentication system. | |
| TT2 | I think the biometric authentication service would be reliable. | [100] | |
| TT3 | I believe that a biometric authentication system would be employed in my best | [101] | |
| TT4 | Interest. I feel fine using biometric authentication systems since they are generally reliable and accurate. | ||
| Perceived Vulnerability PV | PV1 | If my data leak while using my mobile phone, I could be vulnerable to an information security threat. | [102] | 
| PV2 | If any data breach while using my mobile phone, my organization could be vulnerable to an information security threat. | [66] | |
| PV3 | If the data that I keep in my phone (e.g., photos, messages) leak, then my privacy would be compromised. | Self-developed | |
| Perceived Severity PS | PS1 | I believe that if my personal data that I keep in my mobile phone leak, it will be harmful for me. | [103] | 
| PS2 | A loss of my personal data from my mobile phone could cause a serious anxiety problem to me and my family. | [102] | |
| PS3 | My lost or stolen mobile phone would bring financial or reputational loss to my company. | [104] | |
| Self-Efficacy SE | SE1 | I would use mobile internet technologies, including biometric authentication systems, if I had only the system manuals for reference. | [105] | 
| SE2 | I would use mobile internet technologies, including biometric authentication systems, if I had seen someone else using it before trying it myself. | [106] | |
| SE3 | I would use mobile internet technologies, including biometric authentication systems, if I could call someone for help if I got stuck. | ||
| Perceived Response Efficacy PRE | PRE1 | The biometric authentication measures available to me to for stopping people from getting my confidential information from my mobile phone are adequate. | [107] | 
| PRE2 | I am confident that biometric authentication systems would be effective in keeping my data safe. | [108] | |
| PRE3 | I am confident that the biometric authentication system will not use my personal data for other purposes. | ||
| Perceived Response Cost PRC | PRC1 | Using a biometric authentication system is too much trouble. | [103] | 
| PRC2 | Biometric authentication system may cause problems to other programs on my mobile phone. | [109] | |
| PRC3 | Biometric authentication system may make me loose critical information. | ||
| PRC4 | The cost of using a biometric authentication system, including the inconvenience it might cause to me, exceeds benefits. | [107] | |
| Behavioral Intention to accept the technology BI | BI1 | I should apply this BBCA technology as soon as possible. | [110] | 
| BI2 | I should use this BBCA technology soon after it is launched. | 
References
- Martin, T.; Karopoulos, G.; Hernández-Ramos, J.L.; Kambourakis, G.; Fovino, I.N. Demystifying COVID-19 Digital Contact Tracing: A Survey on Frameworks and Mobile Apps. Wirel. Commun. Mob. Comput. 2020, 2020, 8851429. [Google Scholar] [CrossRef]
- Global Stats Counter. 2020. Available online: https://gs.statcounter.com/platform-market-share/desktop-mobile-tablet/worldwide/2020 (accessed on 23 October 2021).
- Xu, H.; Gupta, S.; Rosson, M.B.; Carroll, J.M. Measuring Mobile Users’ Concerns for Information Privacy; Citeseer: Princeton, NJ, USA, 2012. [Google Scholar]
- Kurkovsky, S.; Syta, E. Digital natives and mobile phones: A survey of practices and attitudes about privacy and security. In Proceedings of the 2010 IEEE International Symposium on Technology and Society, Wollongong, NSW, Australia, 7–9 June 2010; pp. 441–449. [Google Scholar] [CrossRef]
- Feng, T.; Liu, Z.; Kwon, K.A.; Shi, W.; Carbunar, B.; Jiang, Y.; Nguyen, N. Continuous mobile authentication using touchscreen gestures. In Proceedings of the 2012 IEEE Conference on Technologies for Homeland Security (HST), Waltham, MA, USA, 13–15 November 2012; pp. 451–456. [Google Scholar]
- Yildirim, C.; Correia, A.-P. Exploring the dimensions of nomophobia: Development and validation of a self-reported questionnaire. Comput. Hum. Behav. 2015, 49, 130–137. [Google Scholar] [CrossRef]
- Aguilera-Manrique, G.; Márquez-Hernández, V.V.; Alcaraz-Córdoba, T.; Granados-Gámez, G.; Gutierrez-Puertas, V.; Gutiérrez-Puertas, L. The relationship between nomophobia and the distraction associated with smartphone use among nursing students in their clinical practicum. PLoS ONE 2018, 13, e0202953. [Google Scholar] [CrossRef] [PubMed]
- Gonçalves, S.; Dias, P.; Correia, A.-P. Nomophobia and lifestyle: Smartphone use and its relationship to psychopathologies. Comput. Hum. Behav. Rep. 2020, 2, 100025. [Google Scholar] [CrossRef]
- Bhattacharya, N. Behavioural biometrics in action. Biomed. Technol. Today 2020, 2020, 8–11. [Google Scholar] [CrossRef]
- Clarke, N. Transparent User Authentication: Biometrics, RFID and Behavioural Profiling; Springer Science & Business Media: Cham, Switzerland, 2011. [Google Scholar]
- Ben-Asher, N.; Kirschnick, N.; Sieger, H.; Meyer, J.; Ben-Oved, A.; Möller, S. On the need for different security methods on mobile phones. In Proceedings of the 13th International Conference on Human Computer Interaction with Mobile Devices and Services, Stockholm, Sweden, 30 August–2 September 2011; pp. 465–473. [Google Scholar]
- Clarke, N.L.; Furnell, S.M. Authentication of users on mobile telephones—A survey of attitudes and practices. Comput. Secur. 2005, 24, 519–527. [Google Scholar] [CrossRef]
- Ahern, S.; Eckles, D.; Good, N.S.; King, S.; Naaman, M.; Nair, R. Over-exposed? Privacy patterns and considerations in online and mobile photo sharing. In Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, San Jose, CA, USA, 28 April–3 May 2007; Association for Computing Machinery: New York, NY, USA, 2007; pp. 357–366. [Google Scholar] [CrossRef]
- Keith, M.J.; Thompson, S.C.; Hale, J.; Lowry, P.; Greer, C. Information disclosure on mobile devices: Re-examining privacy calculus with actual user behavior. Int. J. Hum. Comput. Stud. 2013, 71, 1163–1173. [Google Scholar] [CrossRef]
- Stylios, I.; Kokolakis, S.; Thanou, O.; Chatzis, S. Behavioral biometrics & continuous user authentication on mobile devices: A survey. Inf. Fusion 2020, 66, 76–99. [Google Scholar] [CrossRef]
- Crowston, K. Amazon Mechanical Turk: A Research Tool for Organizations and Information Systems Scholars; Springer: Cham, Switzerland, 2012; pp. 210–221. [Google Scholar] [CrossRef]
- Sitova, Z.; Sedenka, J.; Yang, Q.; Peng, G.; Zhou, G.; Gasti, P.; Balagani, K.S. HMOG: New Behavioral Biometric Features for Continuous Authentication of Smartphone Users. IEEE Trans. Inf. Forensics Secur. 2015, 11, 877–892. [Google Scholar] [CrossRef]
- Mahbub, U.; Patel, V.M.; Chandra, D.; Barbello, B.; Chellappa, R. Partial face detection for continuous authentication. In Proceedings of the 2016 IEEE International Conference on Image Processing (ICIP), Phoenix, AZ, USA, 25–28 September 2016; pp. 2991–2995. [Google Scholar]
- Abuhamad, M.; Abuhmed, T.; Mohaisen, D.; Nyang, D.H. AUToSen: Deep-Learning-Based Implicit Continuous Authentication Using Smartphone Sensors. IEEE Internet Things J. 2020, 7, 5008–5020. [Google Scholar] [CrossRef]
- Abuhamad, M.; Abusnaina, A.; Nyang, D.H.; Mohaisen, D. Sensor-Based Continuous Authentication of Smartphones’ Users Using Behavioral Biometrics: A Contemporary Survey. IEEE Internet Things J. 2020, 8, 65–84. [Google Scholar] [CrossRef]
- Stylios, I.; Thanou, O.; Androulidakis, I.; Zaitseva, E. A Review of Continuous Authentication Using Behavioral Biometrics. In Proceedings of the SouthEast European Design Automation, Computer Engineering, Computer Networks and Social Media Conference, Kastoria, Greece, 25–27 September 2016; pp. 72–79. [Google Scholar] [CrossRef]
- Schaffer, K. Expanding Continuous Authentication with Mobile Devices. Computer 2015, 48, 92–95. [Google Scholar] [CrossRef]
- Patel, V.M.; Chellappa, R.; Chandra, D.; Barbello, B. Continuous User Authentication on Mobile Devices: Recent progress and remaining challenges. IEEE Signal Process. Mag. 2016, 33, 49–61. [Google Scholar] [CrossRef]
- Buriro, A.; Crispo, B.; Del Frari, F.; Klardie, J.; Wrona, K. ITSME: Multi-Modal and Unobtrusive Behavioural User Authentication for Smartphones; Springer: Cham, Switzerland, 2016; pp. 45–61. [Google Scholar] [CrossRef]
- Saevanee, H.; Clarke, N.L.; Furnell, S.M. Multi-modal behavioural biometric authentication for mobile devices. In IFIP International Information Security Conference; Springer: Berlin/Heidelberg, Germany, 2012; pp. 465–474. [Google Scholar]
- Stylios, I.; Skalkos, A.; Kokolakis, S.; Karyda, M. BioPrivacy: Development of a Keystroke Dynamics Continuous Authentication System. In Proceedings of the 5th International Workshop on SECurity and Privacy Requirements Engineering SECPRE, Online, 4–8 October 2021. [Google Scholar]
- Koivumäki, T.; Ristola, A.; Kesti, M. The perceptions towards mobile services: An empirical analysis of the role of use facilitators. Pers. Ubiquitous Comput. 2006, 12, 67–75. [Google Scholar] [CrossRef]
- Hom, E. Mobile Device Security: Startling Statistics on Data Loss and Data Breaches. 2017. Available online: https://www.channelpronetwork.com/article/mobile-device-security-startling-statistics-data-loss-and-data-breaches (accessed on 8 January 2021).
- Prakash, A.; Mukesh, R. A Biometric Approach for Continuous User Authentication by Fusing Hard and Soft Traits. IJ Netw. Secur. 2014, 16, 65–70. [Google Scholar]
- Shnidman, R. Biometric Authentication: The How and Why. 2017. Available online: https://about-fraud.com/biometric-authentication (accessed on 11 January 2021).
- Liang, Y.; Samtani, S.; Guo, B.; Yu, Z. Behavioral Biometrics for Continuous Authentication in the Internet-of-Things Era: An Artificial Intelligence Perspective. IEEE Internet Things J. 2020, 7, 9128–9143. [Google Scholar] [CrossRef]
- Alzubaidi, A.; Kalita, J. Authentication of Smartphone Users Using Behavioral Biometrics. IEEE Commun. Surv. Tutor. 2016, 18, 1998–2026. [Google Scholar] [CrossRef]
- Crawford, H.; Renaud, K.; Storer, T. A framework for continuous, transparent mobile device authentication. Comput. Secur. 2013, 39, 127–136. [Google Scholar] [CrossRef]
- Dourish, P.; Grinter, R.E.; De La Flor, J.D.; Joseph, M. Security in the wild: User strategies for managing security as an everyday, practical problem. Pers. Ubiquitous Comput. 2004, 8, 391–401. [Google Scholar] [CrossRef]
- Alwahaishi, S.; Snásel, V. Consumers Acceptance and Use of Information and Communications Technology: A UTAUT and Flow Based Theoretical Model. J. Technol. Manag. Innov. 2013, 8, 9–10. [Google Scholar] [CrossRef]
- Albrechtsen, E. A qualitative study of users view on information security. Comput. Secur. 2007, 26, 276–289. [Google Scholar] [CrossRef]
- Gerber, N.; Zimmermann, V.; Volkamer, M. Why johnny fails to protect his privacy. In Proceedings of the 2019 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), Stockholm, Sweden, 17–19 June 2019; pp. 109–118. [Google Scholar]
- Alkaldi, N.; Renaud, K. Why do people adopt or reject smartphone security tools? In Proceedings of the Tenth International Symposium on Human Aspects of Information Security & Assurance, HAISA 2016, Frankfurt, Germany, 19–21 July 2016; pp. 135–144. [Google Scholar]
- Volkamer, M.; Renaud, K. Mental models—General introduction and review of their application to human-centred security. In Number Theory and Cryptography; Springer: Berlin/Heidelberg, Germany, 2013; pp. 255–280. [Google Scholar] [CrossRef]
- Chen, H.; Li, W. Mobile device users’ privacy security assurance behavior. Inf. Comput. Secur. 2017, 25, 330–344. [Google Scholar] [CrossRef]
- Furnell, S.; Dowland, P.; Illingworth, H.; Reynolds, P. Authentication and Supervision: A Survey of User Attitudes. Comput. Secur. 2000, 19, 529–539. [Google Scholar] [CrossRef]
- Karatzouni, S.; Furnell, S.M.; Clarke, N.L.; Botha, R.A. Perceptions of User Authentication on Mobile Devices. In Proceedings of the 6th Annual ISOnEworld Conference, Las Vegas, NV, USA, 11–13 April 2007; pp. 11–13. [Google Scholar]
- Alhussain, T.; Alghamdi, R.; Alkhalaf, S.; Alfarraj, O. Users Perceptions of Mobile Phone Security: A Survey Study in the Kingdom of Saudi Arabia. Int. J. Comput. Theory Eng. 2013, 5, 793–796. [Google Scholar] [CrossRef][Green Version]
- Guerra-Casanova, J.; Ríos-Sánchez, B.; Viana-Matesanz, M.; Bailador, G.; Sanchez-Avila, C.; De Giles, M.J.M. Comfort and security perception of biometrics in mobile phones with widespread sensors. In Proceedings of the 2016 IEEE 35th Symposium on Reliable Distributed Systems Workshops (SRDSW), Budapest, Hungary, 26 September 2016; pp. 13–18. [Google Scholar]
- Volaka, H.C.; Alptekin, G.; Basar, O.E.; Isbilen, M.; Incel, O.D. Towards Continuous Authentication on Mobile Phones using Deep Learning Models. Procedia Comput. Sci. 2019, 155, 177–184. [Google Scholar] [CrossRef]
- Abazi, B.; Qehaja, B.; Hajrizi, E. Application of biometric models of authentication in mobile equipment. IFAC-PapersOnLine 2019, 52, 543–546. [Google Scholar] [CrossRef]
- Khan, H.; Hengartner, U.; Vogel, D. Usability and security perceptions of implicit authentication: Convenient, secure, sometimes annoying. In Proceedings of the Eleventh USENIX Conference on Usable Privacy and Security (SOUPS ‘15), USENIX Association, Ottawa, ON, Canada, 22–24 July 2015; pp. 225–239. [Google Scholar]
- Rasnayaka, S.; Sim, T. Who wants Continuous Authentication on Mobile Devices? In Proceedings of the 2018 IEEE 9th International Conference on Biometrics Theory, Applications and Systems (BTAS), Redondo Beach, CA, USA, 22–25 October 2018; pp. 1–9. [Google Scholar]
- Rogers, R.W. A Protection Motivation Theory of Fear Appeals and Attitude Change1. J. Psychol. 1975, 91, 93–114. [Google Scholar] [CrossRef] [PubMed]
- Vance, A.; Siponen, M.; Pahnila, S. Motivating IS security compliance: Insights from Habit and Protection Motivation Theory. Inf. Manag. 2012, 49, 190–198. [Google Scholar] [CrossRef]
- Rogers, R.W.; Prentice-Dunn, S. Protection motivation theory. In Handbook of Health Behavior Research 1: Personal and Socialdeterminants; Gochman, D.S., Ed.; Plenum Press: New York, NY, USA, 1997; pp. 113–132. [Google Scholar]
- Floyd, D.L.; Prentice-Dunn, S.; Rogers, R.W. A Meta-Analysis of Research on Protection Motivation Theory. J. Appl. Soc. Psychol. 2000, 30, 407–429. [Google Scholar] [CrossRef]
- Milne, G.R.; Labrecque, L.I.; Cromer, C. Toward an Understanding of the Online Consumer’s Risky Behavior and Protection Practices. J. Consum. Aff. 2009, 43, 449–473. [Google Scholar] [CrossRef]
- Abraham, C.S.; Sheeran, P.; Abrams, W.D.J.; Spears, R. Exploring teenagers’ adaptive and maladaptive thinking in relation to the threat of hiv infection. Psychol. Health 1994, 9, 253–272. [Google Scholar] [CrossRef]
- Hanus, B.; Wu, Y. Impact of Users’ Security Awareness on Desktop Security Behavior: A Protection Motivation Theory Perspective. Inf. Syst. Manag. 2015, 33, 2–16. [Google Scholar] [CrossRef]
- Ifinedo, P. Understanding information systems security policy compliance: An integration of the theory of planned behavior and the protection motivation theory. Comput. Secur. 2012, 31, 83–95. [Google Scholar] [CrossRef]
- Tsai, H.-Y.S.; Jiang, M.; Alhabash, S.; LaRose, R.; Rifon, N.J.; Cotten, S.R. Understanding online safety behaviors: A protection motivation theory perspective. Comput. Secur. 2016, 59, 138–150. [Google Scholar] [CrossRef]
- Verkijika, S.F. Understanding smartphone security behaviors: An extension of the protection motivation theory with anticipated regret. Comput. Secur. 2018, 77, 860–870. [Google Scholar] [CrossRef]
- Jansen, J.; Van Schaik, P. Understanding Precautionary Online Behavioural Intentions: A Comparison of Three Models. In Proceedings of the Tenth International Symposium on Human Aspects of Information Security & Assurance, HAISA 2016, Frankfurt, Germany, 19–21 July 2016; pp. 1–11. [Google Scholar]
- Ogden, J. Some problems with social cognition models: A pragmatic and conceptual analysis. Health Psychol. 2003, 22, 424–428. [Google Scholar] [CrossRef] [PubMed]
- Anderson, C.L.; Agarwal, R. Practicing Safe Computing: A Multimethod Empirical Examination of Home Computer User Security Behavioral Intentions. MIS Q. 2010, 34, 613. [Google Scholar] [CrossRef]
- Stajkovic, A.D.; Luthans, F. Self-efficacy and work-related performance: A meta-analysis. Psychol. Bull. 1998, 124, 240. [Google Scholar] [CrossRef]
- Campisi, P. Security and Privacy in Biometrics: Towards a Holistic Approach; Springer: Cham, Switzerland, 2013; pp. 1–23. [Google Scholar] [CrossRef]
- Tran, Q.N.; Turnbull, B.P.; Hu, J. Biometrics and Privacy-Preservation: How Do They Evolve? IEEE Open J. Comput. Soc. 2021, 2, 179–191. [Google Scholar] [CrossRef]
- Rogers, R. Cognitive and physiological processes in fear-based attitude change: A revised theory of protection motivation. In Social Psychophysiology: A Sourcebook; Cacioppo, J., Petty, R., Eds.; Guilford Press: New York, NY, USA, 1983; pp. 153–176. [Google Scholar]
- Woon, I.M.Y.; Tan, G.W.; Low, R.T. A protection motivation theory approach to home wireless security. In Proceedings of the International Conference on Information Systems, ICIS 2005, Las Vegas, NV, USA, 11–14 December 2005. [Google Scholar]
- Rippetoe, S.; Rogers, R.W. Effects of Components of Protection-Motivation Theory on Adaptive and Maladaptive Coping with a Health Threat. J. Personal. Soc. Psychol. 1987, 52, 596–604. [Google Scholar] [CrossRef]
- Wurtele, S.K.; Maddux, J.E. Relative Contributions of Protection Motivation Theory Components in Predicting Exercise Intentions and Behavior. Health Psychol. 1987, 6, 453–466. [Google Scholar] [CrossRef] [PubMed]
- Ng, B.-Y.; Kankanhalli, A.; Xu, Y. Studying users’ computer security behavior: A health belief perspective. Decis. Support Syst. 2009, 46, 815–825. [Google Scholar] [CrossRef]
- Rhee, H.-S.; Kim, C.; Ryu, Y.U. Self-efficacy in information security: Its influence on end users’ information security practice behavior. Comput. Secur. 2009, 28, 816–826. [Google Scholar] [CrossRef]
- Agarwal, R.; Prasad, J. A Conceptual and Operational Definition of Personal Innovativeness in the Domain of Information Technology. Inf. Syst. Res. 1998, 9, 204–215. [Google Scholar] [CrossRef]
- Xiao, S.; Witschey, J.; Murphy-Hill, E. Social influences on secure development tool adoption: Why security tools spread. In Proceedings of the 17th ACM conference on Computer Supported Cooperative Work & Social Computing, Baltimore, MD, USA, 15–19 February 2014; pp. 1095–1106. [Google Scholar]
- Rogers, E.M. Diffusion of Innovations; Simon and Schuster: New York, NY, USA, 2010. [Google Scholar]
- Ware, W.H. Records, Computers, and the Rights of Citizens: Report; US Department of Health, Education & Welfare: Washington, DC, USA, 1973; Volume 10.
- Gove, W.R. Review of the Environment and Social Behavior: Privacy, Personal Space, Territory, Crowding., by I. Altman. Contemp. Sociol. 1978, 7, 638. [Google Scholar] [CrossRef]
- Malhorta, N.K.; Kim, S.S.; Agarwal, J. Internet users’ information privacy concerns (IUIPC): The construct, the scale and a causal model. Inf. Syst. Res. 2004, 15, 336–355. [Google Scholar]
- Son, J.Y.; Kim, S.S. Internet users’ information privacy-protective responses: A taxonomy and a nomological model. MIS Q. 2008, 32, 503–529. [Google Scholar] [CrossRef]
- Sheehan, K.B.; Hoy, M.G. Flaming, Complaining, Abstaining: How Online Users Respond to Privacy Concerns. J. Advert. 1999, 28, 37–51. [Google Scholar] [CrossRef]
- Youn, S.; Hall, K. Gender and Online Privacy among Teens: Risk Perception, Privacy Concerns, and Protection Behaviors. Cyber Psychol. Behav. 2008, 11, 763–765. [Google Scholar] [CrossRef] [PubMed]
- Chen, H.-T.; Chen, W. Couldn’t or Wouldn’t? The Influence of Privacy Concerns and Self-Efficacy in Privacy Management on Privacy Protection. Cyber Psychol. Behav. Soc. Netw. 2015, 18, 13–19. [Google Scholar] [CrossRef]
- Skalkos, A.; Tsohou, A.; Karyda, M.; Kokolakis, S. Identifying the values associated with users’ behavior towards anonymity tools through means-end analysis. Comput. Hum. Behav. Rep. 2020, 2, 100034. [Google Scholar] [CrossRef]
- Ejdys, J. Building technology trust in ICT application at a university. Int. J. Emerg. Mark. 2018, 13, 980–997. [Google Scholar] [CrossRef]
- Vance, A.; Elie-Dit-Cosaque, C.M.; Straub, D.W. Examining Trust in Information Technology Artifacts: The Effects of System Quality and Culture. J. Manag. Inf. Syst. 2008, 24, 73–100. [Google Scholar] [CrossRef]
- Krasnova, H.; Veltri, N.F.; Günther, O. Self-disclosure and Privacy Calculus on Social Networking Sites: The Role of Culture. Bus. Inf. Syst. Eng. 2012, 4, 127–135. [Google Scholar] [CrossRef]
- Hertzum, M. The importance of trust in software engineers’ assessment and choice of information sources. Inf. Organ. 2002, 12, 1–18. [Google Scholar] [CrossRef]
- Miltgen, C.L.; Popovič, A.; Oliveira, T. Determinants of end-user acceptance of biometrics: Integrating the “Big 3” of technology acceptance with privacy context. Decis. Support Syst. 2013, 56, 103–114. [Google Scholar] [CrossRef]
- Chin, W.W.; Marcolin, B.L.; Newsted, P.R. A Partial Least Squares Latent Variable Modeling Approach for Measuring Interaction Effects: Results from a Monte Carlo Simulation Study and an Electronic-Mail Emotion/Adoption Study. Inf. Syst. Res. 2003, 14, 189–217. [Google Scholar] [CrossRef]
- Hair, J.F., Jr.; Hult, G.T.M.; Ringle, C.; Sarstedt, M. A Primer on Partial Least Squares Structural Equation Modeling (PLS-SEM); Sage Publications: Thousand Oaks, CA, USA, 2016. [Google Scholar]
- Ringle, C.M.; Wende, S.; Becker, J.M. SmartPLS 3; SmartPLS GmbH: Boenningstedt, Germany, 2015. [Google Scholar]
- Tavakol, M.; Dennick, R. Making sense of Cronbach’s alpha. Int. J. Med. Educ. 2011, 2, 53. [Google Scholar] [CrossRef] [PubMed]
- Kalkbrenner, M.T. Alpha, Omega, and H Internal Consistency Reliability Estimates: Reviewing These Options and When to Use Them. Couns. Outcome Res. Eval. 2021, 12, 1–12. [Google Scholar] [CrossRef]
- Ahmad, S.; Zulkurnain, N.N.A.; Khairushalimi, F.I. Assessing the Validity and Reliability of a Measurement Model in Structural Equation Modeling (SEM). Br. J. Math. Comput. Sci. 2016, 15, 1–8. [Google Scholar] [CrossRef] [PubMed]
- Eom, S.B.; Ashill, N. The Determinants of Students’ Perceived Learning Outcomes and Satisfaction in University Online Education: An Update. Decis. Sci. J. Innov. Educ. 2016, 14, 185–215. [Google Scholar] [CrossRef]
- Cronbach, L.J. Coefficient alpha and the internal structure of tests. Psychometrika 1951, 16, 297–334. [Google Scholar] [CrossRef]
- Rifon, N.J.; LaRose, R.; Choi, S.M. Your Privacy Is Sealed: Effects of Web Privacy Seals on Trust and Personal Disclosures. J. Consum. Aff. 2005, 39, 339–362. [Google Scholar] [CrossRef]
- Boss, S.R.; Galletta, D.F.; Lowry, P.B.; Moody, G.D.; Polak, P. What Do Systems Users Have to Fear? Using Fear Appeals to Engender Threats and Fear that Motivate Protective Security Behaviors. MIS Q. 2015, 39, 837–864. [Google Scholar] [CrossRef]
- Yi, M.Y.; Jackson, J.D.; Park, J.S.; Probst, J.C. Understanding information technology acceptance by individual professionals: Toward an integrative view. Inf. Manag. 2006, 43, 350–363. [Google Scholar] [CrossRef]
- Clegg, C.W.; Unsworth, K.; Epitropaki, O.; Parker, G. Implicating trust in the innovation process. J. Occup. Organ. Psychol. 2002, 75, 409–422. [Google Scholar] [CrossRef]
- Adhikari, K.; Panda, R.K. Users’ Information Privacy Concerns and Privacy Protection Behaviors in Social Networks. J. Glob. Mark. 2018, 31, 96–110. [Google Scholar] [CrossRef]
- Pavlou, P.A. Consumer Acceptance of Electronic Commerce: Integrating Trust and Risk with the Technology Acceptance Model. Int. J. Electron. Commer. 2003, 7, 101–134. [Google Scholar] [CrossRef]
- Li, X.; Hess, T.J.; Valacich, J.S. Why do we trust new technology? A study of initial trust formation with organizational information systems. J. Strat. Inf. Syst. 2008, 17, 39–71. [Google Scholar] [CrossRef]
- Mohamed, N.; Ahmad, I.H. Information privacy concerns, antecedents and privacy measure use in social networking sites: Evidence from Malaysia. Comput. Hum. Behav. 2012, 28, 2366–2375. [Google Scholar] [CrossRef]
- Liang, H.; Xue, Y. Understanding security behaviors in personal computer usage: A threat avoidance perspective. J. Assoc. Inf. Syst. 2010, 11, 394–413. [Google Scholar] [CrossRef]
- Solove, D.J.; Citron, D.K. Risk and anxiety: A theory of data-breach harms. Tex. L. Rev. 2017, 96, 737. [Google Scholar] [CrossRef]
- Tu, Z.; Yuan, Y.; Archer, N. Understanding user behaviour in coping with security threats of mobile device loss and theft. Int. J. Mob. Commun. 2014, 12, 603. [Google Scholar] [CrossRef]
- Tassabehji, R.; Kamala, M.A. Improving E-Banking Security with Biometrics: Modelling User Attitudes and Acceptance. In Proceedings of the 2009 3rd International Conference on New Technologies, Mobility and Security, Cairo, Egypt, 20–23 December 2009; pp. 1–6. [Google Scholar] [CrossRef]
- Workman, M.; Bommer, W.H.; Straub, D. Security lapses and the omission of information security measures: A threat control model and empirical test. Comput. Hum. Behav. 2008, 24, 2799–2816. [Google Scholar] [CrossRef]
- Zhang, X.; Han, X.; Dang, Y.; Meng, F.; Guo, X.; Lin, J. User acceptance of mobile health services from users’ perspectives: The role of self-efficacy and response-efficacy in technology acceptance. Inform. Health Soc. Care 2016, 42, 194–206. [Google Scholar] [CrossRef] [PubMed]
- Grimmelmann, J. Some skepticism about search neutrality. In The Next Digital Decade: Essays on the Future of the Internet; TechFreedom: Washington, DC, USA, 2010; pp. 435–459. [Google Scholar]
- Davis, F.D. Perceived usefulness, perceived ease of use, and user acceptance of information technology. MIS Q. 1989, 13, 319–340. [Google Scholar] [CrossRef]






| Construct | Item | Mean | Std. Dev. | Factor Loadings | 
|---|---|---|---|---|
| Innovation | I1 | 5.49 | 1.31 | 0.875 | 
| I2 | 5.53 | 1.28 | 0.825 | |
| I3 | 5.66 | 1.19 | 0.803 | |
| Privacy Concern | PC1 | 5.40 | 1.39 | 0.907 | 
| PC2 | 5.67 | 1.29 | 0.874 | |
| Trust in Technology | TT1 | 5.52 | 1.28 | 0.866 | 
| TT2 | 5.66 | 1.18 | 0.805 | |
| TT3 | 5.52 | 1.29 | 0.829 | |
| TT4 | 5.61 | 1.17 | 0.841 | |
| Perceived Vulnerability | PV1. | 5.65 | 1.24 | 0.843 | 
| PV2 | 5.51 | 1.35 | 0.746 | |
| PV3 | 5.59 | 1.32 | 0.781 | |
| Perceived Severity | PS1 | 5.59 | 1.27 | 0.817 | 
| PS2 | 5.57 | 1.34 | 0.789 | |
| PS3 | 5.18 | 1.52 | 0.786 | |
| Self-Efficacy | SE1 | 5.31 | 1.34 | 0.861 | 
| SE2 | 5.42 | 1.32 | 0.766 | |
| SE3 | 5.35 | 1.32 | 0.839 | |
| Perceived Response Efficacy | PRE1 | 5.42 | 1.28 | 0.855 | 
| PRE2 | 5.60 | 1.19 | 0.781 | |
| PRE3 | 5.29 | 1.40 | 0.835 | |
| Perceived Response Cost | PRC1 | 4.57 | 1.79 | 0.920 | 
| PRC2 | 4.70 | 1.76 | 0.877 | |
| PRC3 | 4.61 | 1.79 | 0.901 | |
| PRC4 | 4.87 | 1.62 | 0.846 | |
| Behavioral Intention | BI1 | 5.40 | 1.36 | 0.917 | 
| BI2 | 5.49 | 1.33 | 0.897 | 
| Path | Direct Effects β | t-Value | R2 | Hypothesis Confirmations | 
|---|---|---|---|---|
| Behavioral Intention (BI) | 0.724 | |||
| H1: Perceived Vulnerability (PV) | −0.100 | 3.193 | Not Supported | |
| H2: Perceived Severity (PS) | 0.046 | 1.261 | Rejected | |
| H3: Self-Efficacy (SE) | 0.103 | 3.273 | Supported | |
| H4: Perceived Response Efficacy (PRE) | 0.532 | 13.735 | Supported | |
| H5: Perceived Response Cost (PRC) | −0.007 | 0.275 | Supported | |
| H6: Innovativeness (Innov) | 0.347 | 9.676 | Supported | |
| Perceived Vulnerability (PV) | ||||
| H7: Privacy Concerns (PC) | 0.583 | 16.356 | 0.340 | Supported | 
| Perceived Severity (PS) | 0.208 | |||
| H8: Privacy Concerns (PC) | 0.456 | 10.463 | Supported | |
| Self-Efficacy (SE) | 0.059 | |||
| H9: Privacy Concerns (PC) | 0.242 | 5.921 | Supported | |
| Perceived Response Efficacy (PRE) | 0.649 | |||
| H10: Privacy Concerns (PC) | 0.073 | 2.673 | Supported | |
| H12: Trust in Technology (TT) | 0.784 | 35.674 | Supported | |
| Perceived Response Cost (PRC) | ||||
| H11: Privacy Concerns (PC) | 0.213 | 4.904 | Supported | |
| H13: Trust in Technology (TT) | 0.063 | 1.442 | 0.056 | Rejected | 
| Publisher’s Note: MDPI stays neutral with regard to jurisdictional claims in published maps and institutional affiliations. | 
© 2021 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
Share and Cite
Skalkos, A.; Stylios, I.; Karyda, M.; Kokolakis, S. Users’ Privacy Attitudes towards the Use of Behavioral Biometrics Continuous Authentication (BBCA) Technologies: A Protection Motivation Theory Approach. J. Cybersecur. Priv. 2021, 1, 743-766. https://doi.org/10.3390/jcp1040036
Skalkos A, Stylios I, Karyda M, Kokolakis S. Users’ Privacy Attitudes towards the Use of Behavioral Biometrics Continuous Authentication (BBCA) Technologies: A Protection Motivation Theory Approach. Journal of Cybersecurity and Privacy. 2021; 1(4):743-766. https://doi.org/10.3390/jcp1040036
Chicago/Turabian StyleSkalkos, Andreas, Ioannis Stylios, Maria Karyda, and Spyros Kokolakis. 2021. "Users’ Privacy Attitudes towards the Use of Behavioral Biometrics Continuous Authentication (BBCA) Technologies: A Protection Motivation Theory Approach" Journal of Cybersecurity and Privacy 1, no. 4: 743-766. https://doi.org/10.3390/jcp1040036
APA StyleSkalkos, A., Stylios, I., Karyda, M., & Kokolakis, S. (2021). Users’ Privacy Attitudes towards the Use of Behavioral Biometrics Continuous Authentication (BBCA) Technologies: A Protection Motivation Theory Approach. Journal of Cybersecurity and Privacy, 1(4), 743-766. https://doi.org/10.3390/jcp1040036
 
         
                                                


 
       