当前位置: X-MOL 学术Comput. Secur. › 论文详情
Our official English website, www.x-mol.net, welcomes your feedback! (Note: you will need to create a separate account there.)
Utilizing binary code to improve usability of pressure-based authentication
Computers & Security ( IF 5.6 ) Pub Date : 2021-01-08 , DOI: 10.1016/j.cose.2021.102187
Zhangyu Meng , Jun Kong , Juan Li

Due to its invisibility feature, pressure is useful to enhance the security of authentication, especially preventing the shoulder surfing attack. However, users are more familiar with digital passwords than pressure-based passwords. In order to improve the usability of pressure-based authentication, this paper instantiates a pressure-based password (i.e., a sequence of pressures) to a decimal number. In addition, our approach features personalized pressure detection. The personalization further enhances security since an attacker must have a pressure habit that is consistent with the user. We conducted a series of user studies to compare the traditional four-digit password with our pressure-based password. The empirical result indicates that a pressure-based password is more resistant to the shoulder surfing attack than a four-digit password. However, it takes more time to input a pressure-based password on the first-time usage. The slowdown is caused by a modality change from vision to pressure. A field study that lasted for 10 days revealed that the side effect of modality change can be overcome through regular usages.



中文翻译:

利用二进制代码提高基于压力的身份验证的可用性

由于其隐身功能,压力可用于增强身份验证的安全性,尤其是防止肩膀冲浪攻击。但是,用户比基于压力的密码更熟悉数字密码。为了提高基于压力的身份验证的可用性,本文将基于压力的密码(即压力序列)实例化为十进制数。此外,我们的方法还具有个性化的压力检测功能。由于攻击者必须具有与用户一致的压力习惯,因此个性化可以进一步提高安全性。我们进行了一系列用户研究,以比较传统的四位数密码和基于压力的密码。实验结果表明,基于压力的密码比四位数密码更能抵抗肩膀冲浪攻击。但是,首次使用时需要花费更多时间输入基于压力的密码。减速是由于从视觉到压力的模态变化引起的。历时10天的现场研究表明,可以通过定期使用来克服模态变化的副作用。

更新日期:2021-01-29
down
wechat
bug