Use the Force: Evaluating Force-Sensitive Authentication for Mobile Devices

نویسندگان

  • Katharina Krombholz
  • Thomas Hupperich
  • Thorsten Holz
چکیده

Modern, off-the-shelf smartphones provide a rich set of possible touchscreen interactions, but knowledge-based authentication schemes still rely on simple digit or character input. Previous studies examined the shortcomings of such schemes based on unlock patterns, PINs, and passcodes. In this paper, we propose to integrate pressure-sensitive touchscreen interactions into knowledge-based authentication schemes. By adding a (practically) invisible, pressuresensitive component, users can select stronger PINs that are harder to observe for a shoulder surfer. We conducted a within-subjects design lab study (n = 50) to compare our approach termed force-PINs with standard four-digit and six-digit PINs regarding their usability performance and a comprehensive security evaluation. In addition, we conducted a field study that demonstrated lower authentication overhead. Finally, we found that force-PINs let users select higher entropy PINs that are more resilient to shoulder surfing attacks with minimal impact on the usability performance.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A Survey of behavioral authentication using keystroke dynamics: Touch screens and mobile devices

Nowadays most systems became computerized and use internet for remote access, including systems which have critical and sensitive data such as banks and governmental institutions. This led to the huge need for a reliable and efficient authentication system to secure data. User authentication is mostly done using passwords. But it is not a sufficient way to use just a password since it has many ...

متن کامل

DoS-Resistant Attribute-Based Encryption in Mobile Cloud Computing with Revocation

Security and privacy are very important challenges for outsourced private data over cloud storages. By taking Attribute-Based Encryption (ABE) for Access Control (AC) purpose we use fine-grained AC over cloud storage. In this paper, we extend previous Ciphertext Policy ABE (CP-ABE) schemes especially for mobile and resource-constrained devices in a cloud computing environment in two aspects, a ...

متن کامل

A Two Factor Authentication System for Touchscreen Mobile Devices Using Static Keystroke Dynamics and Password

The number of touchscreen mobile devices are rapidly increasing each day and so are the number of people that use them. Username-password combination is the most common method of authentication but has many vulnerabilities like shoulder surfing, social engineering, brute force attacks, key-loggers, etc. Keystroke Dynamics provides a novel approach to strengthen this existing method. Typing rhyt...

متن کامل

Evaluating the effects of near-field earthquakes on the behavior of moment resisting frames

Following the 1994 Northridge and 1995 Kobe earthquakes, most of modern structures damaged seriously or devastated totally despite the seismic codes of these countries that had been expected to bear advanced criteria for seismic design of structures. After extensive research, the most probable reason of those destructions was attributed to special specifications of near-field earthquakes. In th...

متن کامل

KeySens: Passive User Authentication through Micro-behavior Modeling of Soft Keyboard Interaction

Mobile devices have become almost ever-present in our daily lives and increasingly so in the professional workplace. Applications put company data, personal information and sensitive documents in the hands of busy nurses at hospitals, company employees on business trips and government workers at large conferences. Smartphones and tablets also not only store data on-device, but users are frequen...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2016