DocumentCode :
3286844
Title :
A visual dictionary attack on Picture Passwords
Author :
Sadovnik, Amir ; Chen, T.
fYear :
2013
fDate :
15-18 Sept. 2013
Firstpage :
4447
Lastpage :
4451
Abstract :
Microsoft´s Picture Password provides a method to authenticate a user without the need of typing a character based password. The password consists of a set of gestures drawn on an image. The position, direction and order of these gestures constitute the password. Besides being more convenient to use on touch screen devices, this authentication method promises improved memorability in addition to improving the password strength against guessing attacks. However, how unpredictable is the picture password? In this paper we exploit the fact that different users are drawn to similar image regions, and therefore these passwords are vulnerable to guessing attacks. More specifically, we show that for portrait pictures users are strongly drawn to use facial features as gesture locations. We collect a set of Picture Passwords and, using computer vision techniques, derive a list of password guesses in decreasing probability order. We show that guessing in this order we are able to improve the likelihood of cracking a password within a limited number of guesses.
Keywords :
cryptographic protocols; face recognition; gesture recognition; touch sensitive screens; Microsoft Picture Password; character based password; computer vision; facial features; gesture locations; portrait pictures; touch screen devices; user authentication; visual dictionary attack; Graphical Password; Picture Password;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Image Processing (ICIP), 2013 20th IEEE International Conference on
Conference_Location :
Melbourne, VIC
Type :
conf
DOI :
10.1109/ICIP.2013.6738916
Filename :
6738916
Link To Document :
بازگشت