Abstract
The personal identification number (PIN) is a well-known authentication method used in various devices, such as ATMs, mobile devices, and electronic door locks. Unfortunately, the conventional PIN-entry method is vulnerable to shoulder-surfing attacks. Consequently, various shoulder-surfing resistant methods have been proposed. However, the security analyses used to justify these proposed methods are not based on rigorous quantitative analysis, but instead on the results of experiments involving a limited number of human attackers. In this paper, we propose new theoretical and experimental techniques for quantitative security analysis of PIN-entry methods. We first present new security notions and guidelines for secure PIN-entry methods by analyzing the existing methods under the new framework. On the basis of these guidelines, we develop a new PIN-entry method that effectively obviates human shoulder-surfing attacks by significantly increasing the amount of short-term memory required in an attack.
Talk to us
Join us for a 30 min session where you can share your feedback and ask us any queries you have
More From: IEEE Transactions on Information Forensics and Security
Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.