A closer look at recognition-based graphical passwords on mobile devices

A closer look at recognition-based graphical passwords on mobile devices
复制标题

DOI:
10.1145/1837110.1837114
复制
发表时间:
2010-07
影响因子:
2
通讯作者:
Paul Dunphy;A. Heiner;N. Asokan
Paul Dunphy;A. Heiner;N. Asokan
中科院分区:
数学3区
文献类型:
--
作者:
Paul Dunphy;A. Heiner;N. Asokan

文献摘要

被引文献

相似文献

基于照片识别的图形密码系统是减轻当前对字母数字密码和PIN的过度依赖的候选者。然而,尽管基于一个简单的概念-用户评估一致报告令人印象深刻的记忆保留-只有一个商业例子存在,总体采用率很低。吸收的障碍包括感知到的易受观察攻击的脆弱性;关于可部署性的问题;以及无害的设计决策对安全性的影响尚未正式确定。我们的贡献是在移动的设备的背景下剖析这些问题中的每一个--由于其日益重要的意义和吸引未经授权的访问的高潜力,这是一个特别合适的应用领域。这产生:1)一种新颖而简单的交叉攻击解决方案,允许登录挑战的更大变化; 2)对肩部冲浪威胁的详细分析,考虑了模拟和人体测试; 3)首先看看图像处理技术,以实现自动照片过滤。我们在现场环境中操作我们的观察和收集数据,在现场环境中,不同熵的分散机制安装在参与者的个人设备上。在两个工作周内,从高熵版本的用户中收集的成功率与低熵版本的成功率相似,为77%,并且在整个研究中登录持续时间显着减少。
Graphical password systems based on the recognition of photographs are candidates to alleviate current over-reliance on alphanumeric passwords and PINs. However, despite being based on a simple concept -- and user evaluations consistently reporting impressive memory retention -- only one commercial example exists and overall take-up is low. Barriers to uptake include a perceived vulnerability to observation attacks; issues regarding deployability; and the impact of innocuous design decisions on security not being formalized. Our contribution is to dissect each of these issues in the context of mobile devices -- a particularly suitable application domain due to their increasing significance, and high potential to attract unauthorized access. This produces: 1) A novel yet simple solution to the intersection attack that permits greater variability in login challenges; 2) Detailed analysis of the shoulder surfing threat that considers both simulated and human testing; 3) A first look at image processing techniques to contribute towards automated photograph filtering. We operationalize our observations and gather data in a field context where decentralized mechanisms of varying entropy were installed on the personal devices of participants. Across two working weeks success rates collected from users of a high entropy version were similar to those of a low entropy version at 77%, and login durations decreased significantly across the study.