How to fend off shoulder surfers
Date: June 2006 Publication: Journal of Banking and Finance, 30(6) Page(s): 1727 - 1751 Publisher: Elsevier Source 1: http://www.volkerroth.com/download/Roth2005b.pdf Source 2: http://dx.doi.org/10.1016/j.jbankfin.2005.09.010 - Subscription or payment required Abstract or Summary:
Magnetic stripe cards are in common use for electronic payments and cash withdrawal. Reported incidents document that criminals easily pickpocket cards or skim them by swiping them through additional card readers. Personal identification numbers (PINs) are obtained by shoulder surfing, through the use of mirrors or concealed miniature cameras. Both elements, the PIN and the card, are generally sufficient to give the criminal full access to the victim’s account. In this paper, we present alternative PIN entry methods to which we refer as cognitive trapdoor games. These methods make it significantly harder for a criminal to obtain PINs even if he fully observes the entire input and output of a PIN entry procedure. We also introduce the idea of probabilistic cognitive trapdoor games, which offer resilience to shoulder surfing even if the criminal records a PIN entry procedure with a camera. We studied the security as well as the usability of our methods. The result support the hypothesis that our primary mechanism strikes a balance between security and usability that is of practical value. In this article, we give a detailed account of our mechanisms and their evaluation. Do you have additional information to contribute regarding this research paper? If so, please email siteupdates@passwordresearch.com with the details.
<-- Back to Authentication Research Paper Index |