首页> 外文会议>International Conference on Research Challenges in Information Science >Security analysis and psychological study of authentication methods with PIN codes
【24h】

Security analysis and psychological study of authentication methods with PIN codes

机译:PIN码认证方式的安全性分析与心理研究

获取原文

摘要

Touch screens have become ubiquitous in the past few years, like for instance in smartphones and tablets. These devices are often the entry door to numerous information systems, hence having a secure and practical authentication mechanism is crucial. In this paper, we examine the complexity of different authentication methods specifically designed for such devices. We study the widely spread technology to authenticate a user using a Personal Identifier Number code (PIN code). Entering the code is a critical moment where there are several possibilities for an attacker to discover the secret. We consider the three attack models: a Bruteforce Attack (BA) model, a Smudge Attack (SA) model, and an Observation Attack (OA) model where the attacker sees the user logging in on his device. The aim of the intruder is to learn the secret code. Our goal is to propose alternative methods to enter a PIN code. We compare such different methods in terms of security. Some methods require more intentional resources than other, this is why we performed a psychological study on the different methods to evaluate the users' perception of the different methods and their usage.
机译:在过去的几年中,触摸屏已经无处不在,例如在智能手机和平板电脑中。这些设备通常是众多信息系统的入门门,因此具有安全实用的身份验证机制至关重要。在本文中,我们检查了专门为此类设备设计的不同身份验证方法的复杂性。我们研究了广泛使用的技术,以使用个人标识符号码代码(PIN码)对用户进行身份验证。输入代码是关键时刻,攻击者有多种可能会发现秘密。我们考虑了三种攻击模型:暴力攻击(BA)模型,污迹攻击(SA)模型和观察攻击(OA)模型,攻击者会看到用户在其设备上登录。入侵者的目的是学习密码。我们的目标是提出输入PIN码的替代方法。我们在安全性方面比较了这些不同的方法。有些方法比其他方法需要更多的有意资源,这就是为什么我们对不同方法进行了心理研究,以评估用户对不同方法及其用法的看法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号