Herman Kabetta, Hermawan Setiawan, Fetty Amelia, Muhammad Qolby Fawzan
{"title":"Seamless Security on Mobile Devices Textual Password Quantification Model Based Usability Evaluation of Secure Rotary Entry Pad Authentication","authors":"Herman Kabetta, Hermawan Setiawan, Fetty Amelia, Muhammad Qolby Fawzan","doi":"10.30812/matrik.v22i2.2700","DOIUrl":null,"url":null,"abstract":"Mobile devices are vulnerable to shoulder surfing and smudge attacks, which should occur when a user enters a PIN for authentication purposes. This attack can be avoided by implementing a rotary entry pad mechanism. Despite this, several studies have found that using a rotary entry pad reduces user usability. This study uses a Design Research Methodology approach. It will implement a rotary entry pad authentication in the Android operating system as an authentication method to protect the device against Shoulder Surfing Attacks and Smudge Attacks. Furthermore, it combined JSON Web Token (JWT) to secure the authentication process from the client to the server. At the end of implementation, it compared with other studies in terms of usability and evaluated it using the TQ-Model, which showed that the usability aspect has improved. Regarding security, we conducted a shoulder surfing attack simulation to assess the efficacy of guessing PINs. The results showed that only a limited number of attempts were successful, with two out of five samples failing to guess any numbers and only one sample successfully guessing six 10-digit PIN combinations out of 10 to the power of 10. The security test results show that shoulder surfing attacks are more difficult to perform after implementing the rotary entry pad. The evaluation showed that the JSpinpad performed better, with seven parameters showing improvement, one parameter showing a decline, and ten parameters remaining unchanged.","PeriodicalId":364657,"journal":{"name":"MATRIK : Jurnal Manajemen, Teknik Informatika dan Rekayasa Komputer","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-03-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"MATRIK : Jurnal Manajemen, Teknik Informatika dan Rekayasa Komputer","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.30812/matrik.v22i2.2700","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
Mobile devices are vulnerable to shoulder surfing and smudge attacks, which should occur when a user enters a PIN for authentication purposes. This attack can be avoided by implementing a rotary entry pad mechanism. Despite this, several studies have found that using a rotary entry pad reduces user usability. This study uses a Design Research Methodology approach. It will implement a rotary entry pad authentication in the Android operating system as an authentication method to protect the device against Shoulder Surfing Attacks and Smudge Attacks. Furthermore, it combined JSON Web Token (JWT) to secure the authentication process from the client to the server. At the end of implementation, it compared with other studies in terms of usability and evaluated it using the TQ-Model, which showed that the usability aspect has improved. Regarding security, we conducted a shoulder surfing attack simulation to assess the efficacy of guessing PINs. The results showed that only a limited number of attempts were successful, with two out of five samples failing to guess any numbers and only one sample successfully guessing six 10-digit PIN combinations out of 10 to the power of 10. The security test results show that shoulder surfing attacks are more difficult to perform after implementing the rotary entry pad. The evaluation showed that the JSpinpad performed better, with seven parameters showing improvement, one parameter showing a decline, and ten parameters remaining unchanged.
移动设备很容易受到肩部冲浪和涂抹攻击,当用户输入PIN进行身份验证时,就会发生这种情况。这种攻击可以通过实现旋转进入垫机制来避免。尽管如此,几项研究发现,使用旋转输入垫会降低用户的可用性。本研究采用设计研究方法论方法。它将在Android操作系统中实现旋转输入板认证,作为一种认证方法,以保护设备免受肩部冲浪攻击和涂抹攻击。此外,它结合了JSON Web Token (JWT)来保护从客户端到服务器的身份验证过程。在实施结束时,与其他研究在可用性方面进行了比较,并使用tq模型对其进行了评估,结果表明可用性方面有所提高。在安全性方面,我们进行了肩部冲浪攻击模拟,以评估猜测pin的有效性。结果显示,只有有限的几次尝试是成功的,五个样本中有两个没有猜出任何数字,只有一个样本成功猜出了10的10次方中的6个10位数的密码组合。安全测试结果表明,采用旋转入口垫后,肩部冲浪攻击更难实施。评价结果表明,JSpinpad性能较好,其中7个参数有所改善,1个参数有所下降,10个参数保持不变。