GTmoPass:在公共展览上使用目光触摸密码和个人移动设备进行双因素认证

M. Khamis, Regina Hasholzner, A. Bulling, Florian Alt
{"title":"GTmoPass:在公共展览上使用目光触摸密码和个人移动设备进行双因素认证","authors":"M. Khamis, Regina Hasholzner, A. Bulling, Florian Alt","doi":"10.1145/3078810.3078815","DOIUrl":null,"url":null,"abstract":"As public displays continue to deliver increasingly private and personalized content, there is a need to ensure that only the legitimate users can access private information in sensitive contexts. While public displays can adopt similar authentication concepts like those used on public terminals (e.g., ATMs), authentication in public is subject to a number of risks. Namely, adversaries can uncover a user's password through (1) shoulder surfing, (2) thermal attacks, or (3) smudge attacks. To address this problem we propose GTmoPass, an authentication architecture that enables Multi-factor user authentication on public displays. The first factor is a knowledge-factor: we employ a shoulder-surfing resilient multimodal scheme that combines gaze and touch input for password entry. The second factor is a possession-factor: users utilize their personal mobile devices, on which they enter the password. Credentials are securely transmitted to a server via Bluetooth beacons. We describe the implementation of GTmoPass and report on an evaluation of its usability and security, which shows that although authentication using GTmoPass is slightly slower than traditional methods, it protects against the three aforementioned threats.","PeriodicalId":437505,"journal":{"name":"Proceedings of the 6th ACM International Symposium on Pervasive Displays","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-06-07","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"43","resultStr":"{\"title\":\"GTmoPass: two-factor authentication on public displays using gaze-touch passwords and personal mobile devices\",\"authors\":\"M. Khamis, Regina Hasholzner, A. Bulling, Florian Alt\",\"doi\":\"10.1145/3078810.3078815\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"As public displays continue to deliver increasingly private and personalized content, there is a need to ensure that only the legitimate users can access private information in sensitive contexts. While public displays can adopt similar authentication concepts like those used on public terminals (e.g., ATMs), authentication in public is subject to a number of risks. Namely, adversaries can uncover a user's password through (1) shoulder surfing, (2) thermal attacks, or (3) smudge attacks. To address this problem we propose GTmoPass, an authentication architecture that enables Multi-factor user authentication on public displays. The first factor is a knowledge-factor: we employ a shoulder-surfing resilient multimodal scheme that combines gaze and touch input for password entry. The second factor is a possession-factor: users utilize their personal mobile devices, on which they enter the password. Credentials are securely transmitted to a server via Bluetooth beacons. We describe the implementation of GTmoPass and report on an evaluation of its usability and security, which shows that although authentication using GTmoPass is slightly slower than traditional methods, it protects against the three aforementioned threats.\",\"PeriodicalId\":437505,\"journal\":{\"name\":\"Proceedings of the 6th ACM International Symposium on Pervasive Displays\",\"volume\":\"1 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2017-06-07\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"43\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Proceedings of the 6th ACM International Symposium on Pervasive Displays\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1145/3078810.3078815\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 6th ACM International Symposium on Pervasive Displays","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3078810.3078815","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 43

摘要

由于公共显示继续提供越来越私密和个性化的内容,因此需要确保只有合法用户才能访问敏感上下文中的私密信息。虽然公共显示器可以采用与公共终端(例如自动取款机)类似的身份验证概念,但公共场所的身份验证存在许多风险。也就是说,攻击者可以通过(1)肩部冲浪,(2)热攻击或(3)污迹攻击来发现用户的密码。为了解决这个问题,我们提出了GTmoPass,一种允许在公共显示器上进行多因素用户身份验证的身份验证体系结构。第一个因素是知识因素:我们采用肩膀冲浪弹性多模式方案,结合凝视和触摸输入密码。第二个因素是占有因素:用户使用他们的个人移动设备,并在其上输入密码。凭据通过蓝牙信标安全地传输到服务器。我们描述了GTmoPass的实现,并报告了对其可用性和安全性的评估,结果表明,尽管使用GTmoPass进行身份验证的速度比传统方法稍慢,但它可以防止上述三种威胁。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
GTmoPass: two-factor authentication on public displays using gaze-touch passwords and personal mobile devices
As public displays continue to deliver increasingly private and personalized content, there is a need to ensure that only the legitimate users can access private information in sensitive contexts. While public displays can adopt similar authentication concepts like those used on public terminals (e.g., ATMs), authentication in public is subject to a number of risks. Namely, adversaries can uncover a user's password through (1) shoulder surfing, (2) thermal attacks, or (3) smudge attacks. To address this problem we propose GTmoPass, an authentication architecture that enables Multi-factor user authentication on public displays. The first factor is a knowledge-factor: we employ a shoulder-surfing resilient multimodal scheme that combines gaze and touch input for password entry. The second factor is a possession-factor: users utilize their personal mobile devices, on which they enter the password. Credentials are securely transmitted to a server via Bluetooth beacons. We describe the implementation of GTmoPass and report on an evaluation of its usability and security, which shows that although authentication using GTmoPass is slightly slower than traditional methods, it protects against the three aforementioned threats.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信