Spinlock: A Single-Cue Haptic and Audio PIN Input Technique for Authentication

Spinlock: A Single-Cue Haptic and Audio PIN Input Technique for Authentication
复制标题

Spinlock:用于身份验证的单提示触觉和音频 PIN 输入技术

DOI:
10.1007/978-3-642-22950-3_9
复制
发表时间:
2011
期刊:
2020 IEEE Conference on Virtual Reality and 3D User Interfaces Abstracts and Workshops (VRW)
影响因子:
--
通讯作者:
D. Kwon
D. Kwon
中科院分区:
--
文献类型:
--
作者:
Andrea Bianchi;Ian Oakley;D. Kwon

文献摘要

被引文献

相似文献

公共空间中的身份验证固有地暴露于观察攻击,其中通过观察数据输入过程的简单行为来窃取密码。解决这个问题的是通过PIN或密码来保护身份验证输入的系统,这些PIN或密码依赖于相对不可观察的触觉或音频提示集。然而,虽然安全,但这样的系统通常在其用户中引起高水平的认知负荷,这在冗长的认证时间和高错误率中被实例化,并且很可能是由于在处理、映射或调用非视觉信息方面的显著认知需求。为了解决这个问题,本文介绍了Spinlock,一种新的认证技术的基础上重复演示,识别和枚举的一个单一的,简单的无形的线索(音频或触觉),而不是一组结构化的刺激。这种方法保持了安全性,但避免了以前系统的复杂性。一个原型说明了这一概念,以及一项研究比较模式和衡量整体水平的性能,可用性和安全性。结果表明,使用Spinlock的身份验证比以前的非视觉系统更快,更不容易出错,同时保持类似的安全级别。局限性和未来的工作进行了讨论。
Authentication in public spaces is inherently exposed to observation attacks in which passwords are stolen by the simple act of watching the data input process. Addressing this issue are systems that secure authentication input via PINs or passwords that rely on sets of relatively unobservable tactile or audio cues. However, although secure, such systems typically invoke high levels of cognitive load in their users which is instantiated in lengthy authentication times and high error rates and most likely due to significant cognitive demands in terms of processing, mapping or recalling non visual information. To address this issue this paper introduces Spinlock, a novel authentication technique based on repeated presentation, recognition and enumeration of a single, simple invisible cue (audio or haptic), rather than a set of structured stimuli. This approach maintains the security but avoids the complexity of previous systems. A prototype illustrating this concept is described as well as a study comparing modalities and gauging overall levels of performance, usability and security. The results show that authentication with Spinlock is faster and less error prone than previous non-visual systems, while maintaining a similar security level. Limitations and future work are discussed.