DocumentCode
56695
Title
Analysis and Improvement of a PIN-Entry Method Resilient to Shoulder-Surfing and Recording Attacks
Author
Taekyoung Kwon ; Jin Hong
Author_Institution
Grad. Sch. of Inf., Yonsei Univ., Seoul, South Korea
Volume
10
Issue
2
fYear
2015
fDate
Feb. 2015
Firstpage
278
Lastpage
292
Abstract
Devising a user authentication scheme based on personal identification numbers (PINs) that is both secure and practically usable is a challenging problem. The greatest difficulty lies with the susceptibility of the PIN entry process to direct observational attacks, such as human shoulder-surfing and camera-based recording. This paper starts with an examination of a previous attempt at solving the PIN entry problem, which was based on an elegant adaptive black-and-white coloring of the 10-digit keypad in the standard layout. Even though the method required uncomfortably many user inputs, it had the merit of being easy to understand and use. Our analysis that takes both the experimental and theoretical approaches reveals multiple serious shortcomings of the previous method, including round redundancy, unbalanced key presses, highly frequent system errors, and insufficient resilience to recording attacks. The lessons learned through our analysis are then used to improve the black-and-white PIN entry scheme. The new scheme has the remarkable property of resisting camera-based recording attacks over an unlimited number of authentication sessions without leaking any of the PIN digits.
Keywords
authorisation; image sensors; interactive devices; 10-digit keypad; PIN-entry method; authentication sessions; black-and-white PIN entry scheme; camera-based recording attacks; direct observational attacks; elegant adaptive black-and-white coloring; highly frequent system errors; human shoulder-surfing; personal identification numbers; recording attack resilience; recording attacks; round redundancy; unbalanced key presses; user authentication scheme; Authentication; Color; Image color analysis; Pins; Presses; Redundancy; PIN; authentication; shoulder-surfing;
fLanguage
English
Journal_Title
Information Forensics and Security, IEEE Transactions on
Publisher
ieee
ISSN
1556-6013
Type
jour
DOI
10.1109/TIFS.2014.2374352
Filename
6966749
Link To Document