GTmoPass: Two-factor Authentication on Public Displays Using Gaze-Touch passwords and Personal Mobile Devices

被引:25
|
作者
Khamis, Mohamed [1 ]
Hasholzner, Regina [1 ]
Bulling, Andreas [2 ]
Alt, Florian [1 ]
机构
[1] Ludwig Maximilians Univ Munchen, Ubiquitous Interact Syst Grp, Munich, Germany
[2] Max Planck Inst Informat, Saarland Informat Campus, Saarbrucken, Germany
关键词
Multi-factor Authentication; Pervasive Displays; Eye Gestures;
D O I
10.1145/3078810.3078815
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
As public displays continue to deliver increasingly private and personalized content, there is a need to ensure that only the legitimate users can access private information in sensitive contexts. While public displays can adopt similar authentication concepts like those used on public terminals (e.g., ATMs), authentication in public is subject to a number of risks. Namely, adversaries can uncover a user's password through (1) shoulder surfing, (2) thermal attacks, or (3) smudge attacks. To address this problem we propose GTmoPass, an authentication architecture that enables Multi-factor user authentication on public displays. The first factor is a knowledge-factor: we employ a shoulder-surfing resilient multimodal scheme that combines gaze and touch input for password entry. The second factor is a possession-factor: users utilize their personal mobile devices, on which they enter the password. Credentials are securely transmitted to a server via Bluetooth beacons. We describe the implementation of GTmoPass and report on an evaluation of its usability and security, which shows that although authentication using GTmoPass is slightly slower than traditional methods, it protects against the three aforementioned threats.
引用
收藏
页码:53 / 61
页数:9
相关论文
共 15 条
  • [1] Mobile one-time passwords: two-factor authentication using mobile phones
    Eldefrawy, Mohamed Hamdy
    Khan, Muhammad Khurram
    Alghathbar, Khaled
    Kim, Tai-Hoon
    Elkamchouchi, Hassan
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2012, 5 (05) : 508 - 516
  • [2] TouchIn: Sightless Two-factor Authentication on Multi-touch Mobile Devices
    Sun, Jingchao
    Zhang, Rui
    Zhang, Jinxue
    Zhang, Yanchao
    [J]. 2014 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2014, : 436 - 444
  • [3] SignToLogin Cloud Service of Biometric Two-Factor Authentication Using Mobile Devices
    Pasenchuk, Viktor A.
    Volkov, Danil A.
    [J]. 2016 17TH INTERNATIONAL CONFERENCE OF YOUNG SPECIALISTS ON MICRO/NANOTECHNOLOGIES AND ELECTRON DEVICES (EDM), 2016, : 164 - 167
  • [4] Your Song Your Way: Rhythm-Based Two-Factor Authentication for Multi-Touch Mobile Devices
    Chen, Yimin
    Sun, Jingchao
    Zhang, Rui
    Zhang, Yanchao
    [J]. 2015 IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (INFOCOM), 2015,
  • [5] SecuriCast: Zero-Touch Two-Factor Authentication using Web Bluetooth
    Dressel, Thomas
    List, Eik
    Echtler, Florian
    [J]. PROCEEDINGS OF THE ACM SIGCHI SYMPOSIUM ON ENGINEERING INTERACTIVE COMPUTING SYSTEMS (EICS'19), 2019,
  • [6] GazeCast: Using Mobile Devices to Allow Gaze-based Interaction on Public Displays
    Namnakani, Omar
    Sinrattanavong, Penpicha
    Abdrabou, Yasmeen
    Bulling, Andreas
    Alt, Florian
    Khamis, Mohamed
    [J]. ACM SYMPOSIUM ON EYE TRACKING RESEARCH & APPLICATIONS, ETRA 2023, 2023,
  • [7] TrustTokenF: a Generic Security Framework for Mobile Two-factor Authentication Using TrustZone
    Zhang, Yingjun
    Zhao, Shijun
    Qin, Yu
    Yang, Bo
    Feng, Dengguo
    [J]. 2015 IEEE TRUSTCOM/BIGDATASE/ISPA, VOL 1, 2015, : 41 - 48
  • [8] Highly reliable two-factor biometric authentication based on handwritten and voice passwords using flexible neural networks
    Sulavko, A. E.
    [J]. COMPUTER OPTICS, 2020, 44 (01) : 82 - 91
  • [9] User-centred multimodal authentication: securing handheld mobile devices using gaze and touch input
    Khamis, Mohamed
    Marky, Karola
    Bulling, Andreas
    Alt, Florian
    [J]. BEHAVIOUR & INFORMATION TECHNOLOGY, 2022, 41 (10) : 2047 - 2069
  • [10] CNN-Based Multi-Factor Authentication System for Mobile Devices Using Faces and Passwords
    Han, Jinho
    [J]. APPLIED SCIENCES-BASEL, 2024, 14 (12):