Abstract

Personal identification number or PIN based authentication systems are most commonly used authentication systems. Due to maturity and simplicity, these authentication systems are vastly deployed in many different areas such as automatic teller machine (ATM), point of sale (POS), electronic door access system and in different kinds of mobile applications. However, due to limited password space and small password length, they are highly susceptible to different kinds of shoulder surfing attacks. In this paper, we have proposed a graphical PIN entry scheme that provides resistance against shoulder surfing attacks. To alleviate the shoulder surfing attack in our proposed scheme, we have used specialized interface design and indirect PIN entry method. For indirect PIN entry method we have used extra information in the form of reference location, which is not observable for the attacker. We have implemented the prototype of the proposed authentication scheme using C# and conducted a user study to evaluate the usability of our proposed scheme. The results of the user study show that this scheme provides a reasonable balance between security and usability.

Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call