DocumentCode
978
Title
Security Notions and Advanced Method for Human Shoulder-Surfing Resistant PIN-Entry
Author
Mun-Kyu Lee
Author_Institution
Sch. of Comput. & Inf. Eng., Inha Univ., Incheon, South Korea
Volume
9
Issue
4
fYear
2014
fDate
Apr-14
Firstpage
695
Lastpage
708
Abstract
The personal identification number (PIN) is a well-known authentication method used in various devices, such as ATMs, mobile devices, and electronic door locks. Unfortunately, the conventional PIN-entry method is vulnerable to shoulder-surfing attacks. Consequently, various shoulder-surfing resistant methods have been proposed. However, the security analyses used to justify these proposed methods are not based on rigorous quantitative analysis, but instead on the results of experiments involving a limited number of human attackers. In this paper, we propose new theoretical and experimental techniques for quantitative security analysis of PIN-entry methods. We first present new security notions and guidelines for secure PIN-entry methods by analyzing the existing methods under the new framework. On the basis of these guidelines, we develop a new PIN-entry method that effectively obviates human shoulder-surfing attacks by significantly increasing the amount of short-term memory required in an attack.
Keywords
authorisation; ATM; authentication method; electronic door locks; human attackers; human shoulder-surfing attacks; human shoulder-surfing resistant PIN-entry; mobile devices; personal identification number; quantitative analysis; quantitative security analysis; security notions; Authentication; Immune system; Memory management; Mobile handsets; Pins; Usability; User authentication; personal identification number; shoulder-surfing attack;
fLanguage
English
Journal_Title
Information Forensics and Security, IEEE Transactions on
Publisher
ieee
ISSN
1556-6013
Type
jour
DOI
10.1109/TIFS.2014.2307671
Filename
6746671
Link To Document