Abstract

Swiftness, simplicity, and security is crucial for mobile device authentication. Currently, most mobile devices are protected by a six pin numerical passcode authentication layer which is extremely vulnerable to Shoulder-Surfing attacks and Spyware attacks. This paper proposes a multi-elemental graphical password authentication model for mobile devices that are resistant to shoulder surfing attacks and spyware attacks. The proposed Coin Passcode model simplifies the complex user interface issues that previous graphical password models have, which work as a swift passcode security mechanism for mobile devices. The Coin Passcode model also has a high memorability rate compared to the existing numerical and alphanumerical passwords, as psychology studies suggest that human are better at remembering graphics than words. The results shows that the Coin Passcode is able to overcome the current shoulder-surfing and spyware attack vulnerability that existing mobile application numerical passcode authentication layers suffer from.

Highlights

  • Authentication technology is crucial to the integrity and confidentiality of smart mobile device users, especially when many important features such as banking and finance are accessible through mobile applications

  • It is shown that having a Multi-elemental passcode for a mobile login interface can prevent direct observation password attacks, and at the same time provide a higher password complexity against brute-force and password guessing attacks

  • It is a combination of the behavioral context uniqueness of each person that makes this multi-elemental passcode a stronger mobile password interface

Read more

Summary

INTRODUCTION

Authentication technology is crucial to the integrity and confidentiality of smart mobile device users, especially when many important features such as banking and finance are accessible through mobile applications. Current mobile security mechanisms use the four or six pin numerical passcodes which are remembered, while providing a swift security authentication for the users. This security mechanism has its flaws when it faces modern attackers who can guess or shoulder surf for the password combinations. There are several other user authentication mechanisms such as the alpha-numerical passwords and the pattern drawing lock, which are prone to shoulder surfing attacks. This paper is structured in six sections, including the Introduction Section, Related Works, The Coin Passcode Mobile Graphic Authentication Model, Security Analysis and Usability Metrics, Discussion and Conclusion

Cognitive Biometrics
Recognition-Based Techniques
Recall-Based Techniques
Hybrid Scheme
THE COIN PASSCODE MOBILE GRAPHICAL PASSWORD AUTHENTICATION MODEL
The Coin Passcode Structure
The Coin Passcode Authentication Algorithm
The Coin Passcode Registration
Usability Metrics and Security Analysis
Password Complexity Comparison
Shoulder Surfing Attack and Spyware Attack
Password Guessing and Dictionary Attack
DISCUSSIONS
CONCLUSION
FUTURE WORK
Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call