DocumentCode :
56695
Title :
Analysis and Improvement of a PIN-Entry Method Resilient to Shoulder-Surfing and Recording Attacks
Author :
Taekyoung Kwon ; Jin Hong
Author_Institution :
Grad. Sch. of Inf., Yonsei Univ., Seoul, South Korea
Volume :
10
Issue :
2
fYear :
2015
fDate :
Feb. 2015
Firstpage :
278
Lastpage :
292
Abstract :
Devising a user authentication scheme based on personal identification numbers (PINs) that is both secure and practically usable is a challenging problem. The greatest difficulty lies with the susceptibility of the PIN entry process to direct observational attacks, such as human shoulder-surfing and camera-based recording. This paper starts with an examination of a previous attempt at solving the PIN entry problem, which was based on an elegant adaptive black-and-white coloring of the 10-digit keypad in the standard layout. Even though the method required uncomfortably many user inputs, it had the merit of being easy to understand and use. Our analysis that takes both the experimental and theoretical approaches reveals multiple serious shortcomings of the previous method, including round redundancy, unbalanced key presses, highly frequent system errors, and insufficient resilience to recording attacks. The lessons learned through our analysis are then used to improve the black-and-white PIN entry scheme. The new scheme has the remarkable property of resisting camera-based recording attacks over an unlimited number of authentication sessions without leaking any of the PIN digits.
Keywords :
authorisation; image sensors; interactive devices; 10-digit keypad; PIN-entry method; authentication sessions; black-and-white PIN entry scheme; camera-based recording attacks; direct observational attacks; elegant adaptive black-and-white coloring; highly frequent system errors; human shoulder-surfing; personal identification numbers; recording attack resilience; recording attacks; round redundancy; unbalanced key presses; user authentication scheme; Authentication; Color; Image color analysis; Pins; Presses; Redundancy; PIN; authentication; shoulder-surfing;
fLanguage :
English
Journal_Title :
Information Forensics and Security, IEEE Transactions on
Publisher :
ieee
ISSN :
1556-6013
Type :
jour
DOI :
10.1109/TIFS.2014.2374352
Filename :
6966749
Link To Document :
بازگشت