首页> 外文OA文献 >Risks and potentials of graphical and gesture-based authentication for touchscreen mobile devices
【2h】

Risks and potentials of graphical and gesture-based authentication for touchscreen mobile devices

机译:触摸屏移动设备的图形和基于手势的身份验证的风险和潜力

摘要

While a few years ago, mobile phones were mainly used for making phone calls and texting short messages, the functionality of mobile devices has massively grown. We are surfing the web, sending emails and we are checking our bank accounts on the go. As a consequence, these internet-enabled devices store a lot of potentially sensitive data and require enhanced protection. We argue that authentication often represents the only countermeasure to protect mobile devices from unwanted access.ududKnowledge-based concepts (e.g., PIN) are the most used authentication schemes on mobile devices. They serve as the main protection barrier for many users and represent the fallback solution whenever alternative mechanisms fail (e.g., fingerprint recognition). This thesis focuses on the risks and potentials of gesture-based authentication concepts that particularly exploit the touch feature of mobile devices. The contribution of our work is threefold. Firstly, the problem space of mobile authentication is explored. Secondly, the design space is systematically evaluated utilizing interactive prototypes. Finally, we provide generalized insights into the impact of specific design factors and present recommendations for the design and the evaluation of graphical gesture-based authentication mechanisms. ududThe problem space exploration is based on four research projects that reveal important real-world issues of gesture-based authentication on mobile devices. The first part focuses on authentication behavior in the wild and shows that the mobile context makes great demands on the usability of authentication concepts. The second part explores usability features of established concepts and indicates that gesture-based approaches have several benefits in the mobile context. The third part focuses on observability and presents a prediction model for the vulnerability of a given grid-based gesture. Finally, the fourth part investigates the predictability of user-selected gesture-based secrets. ududThe design space exploration is based on a design-oriented research approach and presents several practical solutions to existing real-world problems. The novel authentication mechanisms are implemented into working prototypes and evaluated in the lab and the field. In the first part, we discuss smudge attacks and present alternative authentication concepts that are significantly more secure against such attacks. The second part focuses on observation attacks. We illustrate how relative touch gestures can support eyes-free authentication and how they can be utilized to make traditional PIN-entry secure against observation attacks. The third part addresses the problem of predictable gesture choice and presents two concepts which nudge users to select a more diverse set of gestures.ududFinally, the results of the basic research and the design-oriented applied research are combined to discuss the interconnection of design space and problem space. We contribute by outlining crucial requirements for mobile authentication mechanisms and present empirically proven objectives for future designs. In addition, we illustrate a systematic goal-oriented development process and provide recommendations for the evaluation of authentication on mobile devices.
机译:几年前,移动电话主要用于拨打电话和发短信,但移动设备的功能却得到了极大的发展。我们正在网上冲浪,发送电子邮件,并且正在旅途中检查我们的银行帐户。结果,这些启用了Internet的设备会存储大量潜在的敏感数据,并需要增强的保护。我们认为,身份验证通常是保护移动设备免受不必要访问的唯一对策。 ud ud基于知识的概念(例如PIN)是移动设备上使用最多的身份验证方案。它们是许多用户的主要保护屏障,并在备用机制出现故障(例如指纹识别)时代表备用解决方案。本文主要研究基于手势的身份验证概念的风险和潜力,这些概念特别利用了移动设备的触摸功能。我们工作的贡献是三方面的。首先,探讨了移动认证的问题空间。其次,利用交互式原型系统地评估设计空间。最后,我们提供了对特定设计因素影响的概括见解,并提出了设计和基于图形手势的身份验证机制评估的建议。 ud ud问题空间探索基于四个研究项目,这些项目揭示了移动设备上基于手势的身份验证的现实世界中的重要问题。第一部分着重于野外的身份验证行为,并表明移动上下文对身份验证概念的可用性提出了很高的要求。第二部分探讨了已建立概念的可用性特征,并指出了基于手势的方法在移动环境中具有多个好处。第三部分着重于可观察性,并给出了针对给定基于网格的手势的脆弱性的预测模型。最后,第四部分研究了用户选择的基于手势的秘密的可预测性。 ud ud设计空间探索基于面向设计的研究方法,并提出了一些解决现有实际问题的实用解决方案。新颖的身份验证机制已实现为可工作的原型,并在实验室和现场进行了评估。在第一部分中,我们讨论了污点攻击并提出了替代的身份验证概念,这些概念明显更安全地抵御此类攻击。第二部分重点介绍观察攻击。我们将说明相对触摸手势如何支持无眼认证,以及如何利用它们使传统的PIN输入安全以防止观察攻击。第三部分解决了可预测的手势选择问题,并提出了两个促使用户选择更为多样化的手势的概念。 ud ud最后,将基础研究的结果与面向设计的应用研究相结合,以讨论互连性设计空间和问题空间。我们通过概述对移动身份验证机制的关键要求做出贡献,并提出经验证明的未来设计目标。此外,我们说明了系统的面向目标的开发过程,并为评估移动设备上的身份验证提供了建议。

著录项

  • 作者

    Zezschwitz Emanuel von;

  • 作者单位
  • 年度 2016
  • 总页数
  • 原文格式 PDF
  • 正文语种
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号