Fast and Secure Authentication in Virtual Reality Using Coordinated 3D Manipulation and Pointing

Florian Mathis, John Williamson, Kami Vaniea, M. Khamis
{"title":"Fast and Secure Authentication in Virtual Reality Using Coordinated 3D Manipulation and Pointing","authors":"Florian Mathis, John Williamson, Kami Vaniea, M. Khamis","doi":"10.1145/3428121","DOIUrl":null,"url":null,"abstract":"There is a growing need for usable and secure authentication in immersive virtual reality (VR). Established concepts (e.g., 2D authentication schemes) are vulnerable to observation attacks, and most alternatives are relatively slow. We present RubikAuth, an authentication scheme for VR where users authenticate quickly and secure by selecting digits from a virtual 3D cube that leverages coordinated 3D manipulation and pointing. We report on results from three studies comparing how pointing using eye gaze, head pose, and controller tapping impact RubikAuth’s usability, memorability, and observation resistance under three realistic threat models. We found that entering a four-symbol RubikAuth password is fast: 1.69–3.5 s using controller tapping, 2.35–4.68 s using head pose and 2.39 –4.92 s using eye gaze, and highly resilient to observations: 96–99.55% of observation attacks were unsuccessful. RubikAuth also has a large theoretical password space: 45n for an n-symbols password. Our work underlines the importance of considering novel but realistic threat models beyond standard one-time attacks to fully assess the observation-resistance of authentication schemes. We conclude with an in-depth discussion of authentication systems for VR and outline five learned lessons for designing and evaluating authentication schemes.","PeriodicalId":322583,"journal":{"name":"ACM Transactions on Computer-Human Interaction (TOCHI)","volume":"15 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-01-20","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"46","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"ACM Transactions on Computer-Human Interaction (TOCHI)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3428121","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 46

Abstract

There is a growing need for usable and secure authentication in immersive virtual reality (VR). Established concepts (e.g., 2D authentication schemes) are vulnerable to observation attacks, and most alternatives are relatively slow. We present RubikAuth, an authentication scheme for VR where users authenticate quickly and secure by selecting digits from a virtual 3D cube that leverages coordinated 3D manipulation and pointing. We report on results from three studies comparing how pointing using eye gaze, head pose, and controller tapping impact RubikAuth’s usability, memorability, and observation resistance under three realistic threat models. We found that entering a four-symbol RubikAuth password is fast: 1.69–3.5 s using controller tapping, 2.35–4.68 s using head pose and 2.39 –4.92 s using eye gaze, and highly resilient to observations: 96–99.55% of observation attacks were unsuccessful. RubikAuth also has a large theoretical password space: 45n for an n-symbols password. Our work underlines the importance of considering novel but realistic threat models beyond standard one-time attacks to fully assess the observation-resistance of authentication schemes. We conclude with an in-depth discussion of authentication systems for VR and outline five learned lessons for designing and evaluating authentication schemes.
基于协调的三维操作和指向的虚拟现实快速安全认证
在沉浸式虚拟现实(VR)中,对可用且安全的身份验证的需求日益增长。已建立的概念(例如,2D身份验证方案)容易受到观察攻击,并且大多数替代方案相对较慢。我们提出了rubikath,这是一种VR认证方案,用户可以通过从虚拟3D立方体中选择数字来快速安全地进行身份验证,该立方体利用协调的3D操作和指向。我们报告了三项研究的结果,比较了在三种现实威胁模型下,使用眼睛凝视、头部姿势和控制器敲击来指示如何影响rubikath的可用性、可记忆性和观察阻力。我们发现,输入四个符号的rubikath密码速度很快:使用控制器轻敲1.69-3.5秒,使用头部姿势2.35-4.68秒,使用眼睛凝视2.39 -4.92秒,并且对观察具有很高的弹性:96-99.55%的观察攻击是不成功的。RubikAuth也有很大的理论密码空间:n个符号的密码有45n个。我们的工作强调了考虑超越标准一次性攻击的新颖但现实的威胁模型以充分评估身份验证方案的观察抗性的重要性。最后,我们深入讨论了VR的身份验证系统,并概述了设计和评估身份验证方案的五个经验教训。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信