Shoulder surfing defence for recall-based graphical passwords

SOUPS '11: Proceedings of the Seventh Symposium on Usable Privacy and Security(2011)

引用 177|浏览2
暂无评分
摘要
Graphical passwords are often considered prone to shoulder-surfing attacks, where attackers can steal a user's password by peeking over his or her shoulder in the authentication process. In this paper, we explore shoulder surfing defence for recall-based graphical password systems such as Draw-A-Secret and Background Draw-A-Secret, where users doodle their passwords (i.e. secrets) on a drawing grid. We propose three innovative shoulder surfing defence techniques, and conduct two separate controlled laboratory experiments to evaluate both security and usability perspectives of the proposed techniques. One technique was expected to work to some extent theoretically, but it turned out to provide little protection. One technique provided the best overall shoulder surfing defence, but also caused some usability challenges. The other technique achieved reasonable shoulder surfing defence and good usability simultaneously, a good balance which the two other techniques did not achieve. Our results appear to be also relevant to other graphical password systems such as Pass-Go.
更多
查看译文
关键词
usability challenge,innovative shoulder,reasonable shoulder,overall shoulder,surfing defence,proposed technique,graphical password system,graphical password,good usability,defence technique,recall-based graphical password system,usability
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要