首页> 外文会议>International Conference on Computing and Network Communications >Oracle model to validate shoulder-surfing resistance of virtual keyboards
【24h】

Oracle model to validate shoulder-surfing resistance of virtual keyboards

机译:甲骨文模型验证虚拟键盘的肩膀冲浪阻力

获取原文

摘要

In the era of digital world, online services like net banking, e-wallet, bill payment portals, e-mail and many other Cloud services became inevitable part of life. These service providers possess private and valuable data of their users. This makes online service portals a target to steal e-assets. Shoulder-surfing provides an easy way to loot e-assets by stealing user credentials. Plenty of counter mechanisms are available in the literature to overcome shoulder-surfing attack. Most of those proposals lack formal security proof. Hence it is difficult to compare them or validate their claim. Another setback is that some of the shoulder-surfing resistant keyboards are designed to resist human observer and validated by making a group of humans to observe the interaction between user and virtual keyboard and then guess the password correctly. Since human cognition varies, systems evaluated using a group of humans cannot be considered as a standard method to compare and evaluate the shoulder-surfing resistance of virtual keyboards. This paper proposes traditional oracle model based framework to evaluate shoulder-surfing resistant keyboards. Three shoulder-surfing resistant virtual keyboards from literature are chosen and their resistance to shoulder-surfing is computed in terms of minimum advantage of an adversary using the proposed oracle framework. This paper also presents basic password recovery algorithms to recover the password that are entered using the virtual keyboards selected for this study.
机译:在数字世界时代,网络银行,电子钱包,账单支付门户,电子邮件和许多其他云服务等在线服务已成为生活中不可避免的一部分。这些服务提供商拥有其用户的私人和宝贵数据。这使在线服务门户成为窃取电子资产的目标。网上冲浪提供了一种通过窃取用户凭据来掠夺电子资产的简便方法。文献中提供了许多应对机制来克服肩膀冲浪攻击。这些建议大多数都缺乏正式的安全证明。因此,很难对它们进行比较或验证其主张。另一个挫折是,某些抗肩膀冲浪的键盘被设计为抵抗人类观察者,并通过让一群人观察用户和虚拟键盘之间的交互,然后正确猜测密码来进行验证。由于人类的认知各不相同,因此不能将使用一组人类进行评估的系统视为比较和评估虚拟键盘的肩膀冲浪阻力的标准方法。本文提出了一种基于传统oracle模型的框架来评估抗肩膀冲浪键盘。从文献中选择了三个抗肩膀冲浪的虚拟键盘,并使用提议的oracle框架根据对手的最小优势来计算其抗肩膀冲浪的能力。本文还介绍了基本的密码恢复算法,以恢复使用此研究选择的虚拟键盘输入的密码。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号