LocPass: A Graphical Password Method to Prevent Shoulder-Surfing

被引:5
|
作者
Por, Lip Yee [1 ]
Adebimpe, Lateef Adekunle [1 ,2 ]
Idris, Mohd Yamani Idna [1 ]
Khaw, Chee Siong [1 ]
Ku, Chin Soon [3 ]
机构
[1] Univ Malaya, Fac Comp Sci & Informat Technol, Dept Comp Syst & Technol, Kuala Lumpur 50603, Malaysia
[2] Emmanuel Alayande Coll Educ, Oyo 211225, Nigeria
[3] Univ Tunku Abdul Rahman, Dept Comp Sci, Kampar 31900, Malaysia
来源
SYMMETRY-BASEL | 2019年 / 11卷 / 10期
关键词
graphical password; shoulder-surfing; pass-location; authentication; cardinal directions;
D O I
10.3390/sym11101252
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
Graphical passwords are a method of authentication in computer security. Computer security is one of the disciplines of computer science. Shoulder-surfing attacks are a well-known threat to graphical passwords, although is getting commonly used especially in granting access for a secure system. Shoulder-surfing occurs when attackers skillfully capture important data/activities, such as login passwords, via direct observation or video recording methods. Many methods have been proposed to overcome the problem of shoulder-surfing attacks. After we reviewed some related works, we found out that most of the existing methods are still vulnerable to multiple observations and video-recorded shoulder-surfing attacks. Thus, we propose a new method to combat this problem. In our proposed method, we make used of two concepts to combat shoulder-surfing attacks. In the first concept, we used registered locations (something that only the users know) and 5 image directions (something that the users can see) to determine a pass-location (new knowledge). Secondly, the images used in our proposed method have higher chances to offset each other. The idea of offset could increase the password spaces of our proposed method if an attacker intended to guess the registered location used. By combining these two concepts, the pass-location produced by our proposed method in each challenge set could be varied. Therefore, it is impossible for the attackers to shoulder-surf any useful information such as the images/locations clicked by the user in each challenge set. A user study was conducted to evaluate the capabilities of the proposed method to prevent shoulder-surfing attacks. The shoulder-surfing testing results indicated that none of the participants were able to login, although they knew the underlying algorithm and they have been given sufficient time to perform a shoulder-surfing attack. Therefore, the proposed method has proven it can prevent shoulder-surfing attacks, provided the enrolment procedure is carried out in a secure manner.
引用
收藏
页数:20
相关论文
共 50 条
  • [31] A Camouflage Text-Based Password Approach for Mobile Devices against Shoulder-Surfing Attack
    Alsuhibany, Suliman A.
    SECURITY AND COMMUNICATION NETWORKS, 2021, 2021
  • [32] Generating Session Password Using Text and Color to Prevent Shoulder Surfing
    Devi, D. Surya
    Selvi, M. Tamil
    Sowmiya, T.
    Pavithra, M. J.
    Emilyn, J. Jeba
    INTERNATIONAL CONFERENCE ON MODELLING OPTIMIZATION AND COMPUTING, 2012, 38 : 1309 - 1317
  • [33] Shoulder surfing resistant graphical password schema: Randomized Pass Points (RPP)
    Bostan, Hakan
    Bostan, Atila
    MULTIMEDIA TOOLS AND APPLICATIONS, 2023, 82 (28) : 43517 - 43541
  • [34] A Simple Text-Based Shoulder Surfing Resistant Graphical Password Scheme
    Chen, Yi-Lun
    Ku, Wei-Chi
    Yeh, Yu-Chang
    Liao, Dun-Min
    IEEE INTERNATIONAL SYMPOSIUM ON NEXT-GENERATION ELECTRONICS 2013 (ISNE 2013), 2013,
  • [35] Shoulder surfing resistant graphical password schema: Randomized Pass Points (RPP)
    Hakan Bostan
    Atila Bostan
    Multimedia Tools and Applications, 2023, 82 : 43517 - 43541
  • [36] User Authentication Based on the Chess Graphical Password Scheme Resistant to Shoulder Surfing
    Yakovlev, V. A.
    Arkhipov, V. V.
    AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2015, 49 (08) : 803 - 812
  • [37] I (Don't) See What You Typed There! Shoulder-surfing Resistant Password Entry on Gamepads
    Mayer, Peter
    Gerber, Nina
    Reinheimer, Benjamin
    Rack, Philipp
    Braun, Kristoffer
    Volkamer, Melanie
    CHI 2019: PROCEEDINGS OF THE 2019 CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS, 2019,
  • [38] A Comparison of a Touch-Gesture- and a Keystroke-Based Password Method: Toward Shoulder-Surfing Resistant Mobile User Authentication
    Zhou, Lina
    Wang, Kanlun
    Lai, Jianwei
    Zhang, Dongsong
    IEEE TRANSACTIONS ON HUMAN-MACHINE SYSTEMS, 2023, 53 (02) : 303 - 314
  • [39] Shoulder-Surfing Resistance with Eye-Gaze Entry in Cued-Recall Graphical Passwords
    Forget, Alain
    Chiasson, Sonia
    Biddle, Robert
    CHI2010: PROCEEDINGS OF THE 28TH ANNUAL CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS, VOLS 1-4, 2010, : 1107 - 1110
  • [40] Authentication Method against Shoulder-Surfing Attacks using Secondary Channel
    Aratani, Akira
    Kanai, Atsushi
    2015 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS (ICCE), 2015, : 430 - 431