Completely Automated Public Physical test to tell Computers and Humans Apart: A usability study on mobile devices

被引:12
|
作者
Guerar, Meriem [1 ]
Merlo, Alessio [2 ]
Migliardi, Mauro [3 ]
机构
[1] Univ Sci & Technol Oran Mohamed Boudiaf, Bir El Djir, Algeria
[2] Univ Genoa, DIBRIS, Genoa, Italy
[3] Univ Padua, DEI, Padua, Italy
关键词
Security; Mobile; Usability; CAPTCHA; CAPPCHA;
D O I
10.1016/j.future.2017.03.012
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
A very common approach adopted to fight the increasing sophistication and dangerousness of malware and hacking is to introduce more complex authentication mechanisms. This approach, however, introduces additional cognitive burdens for users and lowers the whole authentication mechanism acceptability to the point of making it unusable. On the contrary, what is really needed to fight the onslaught of automated attacks to users data and privacy is to first tell human and computers apart and then distinguish among humans to guarantee correct authentication. Such an approach is capable of completely thwarting any automated attempt to achieve unwarranted access while it allows keeping simple the mechanism dedicated to recognizing the legitimate user. This kind of approach is behind the concept of Completely Automated Public Turing test to tell Computers and Humans Apart (CAPTCHA), yet CAPTCHA leverages cognitive capabilities, thus the increasing sophistication of computers calls for more and more difficult cognitive tasks that make them either very long to solve or very prone to false negatives. We argue that this problem can be overcome by substituting the cognitive component of CAPTCHA with a different property that programs cannot mimic: the physical nature. In past work we have introduced the Completely Automated Public Physical test to tell Computer and Humans Apart (CAPPCHA) as a way to enhance the PIN authentication method for mobile devices and we have provided a proof of concept implementation. Similarly to CAPTCHA, this mechanism can also be used to prevent automated programs from abusing online services. However, to evaluate the real efficacy of the proposed scheme, an extended empirical assessment of CAPPCHA is required as well as a comparison of CAPPCHA performance with the existing state of the art. To this aim, in this paper we carry out an extensive experimental study on both the performance and the usability of CAPPCHA involving a high number of physical users, and we provide comparisons of CAPPCHA with existing flavors of CAPTCHA. (C) 2017 Elsevier B.V. All rights reserved.
引用
收藏
页码:617 / 630
页数:14
相关论文
共 3 条
  • [1] A Completely Automatic Public Physical test to tell Computers and Humans Apart: a way to enhance authentication schemes in mobile devices
    Guerar, Meriem
    Merlo, Alessio
    Benmohammed, Mohamed
    Migliardi, Mauro
    Messabih, Belhadri
    PROCEEDINGS OF THE 2015 INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING & SIMULATION (HPCS 2015), 2015, : 203 - 210
  • [2] On Random Field Completely Automated Public Turing Test to Tell Computers and Humans Apart Generation
    Kouritzin, Michael A.
    Newton, Fraser
    Wu, Biao
    IEEE TRANSACTIONS ON IMAGE PROCESSING, 2013, 22 (04) : 1654 - 1664
  • [3] Robustness of text-based completely automated public turing test to tell computers and humans apart
    Gao, Haichang
    Wang, Xuqin
    Cao, Fang
    Zhang, Zhengya
    Lei, Lei
    Qi, Jiao
    Liu, Xiyang
    IET INFORMATION SECURITY, 2016, 10 (01) : 45 - 52