首页> 外文会议>IFIP TC 13 International Conference on Human-Computer Interaction >CipherCard: A Token-Based Approach Against Camera-Based Shoulder Surfing Attacks on Common Touchscreen Devices
【24h】

CipherCard: A Token-Based Approach Against Camera-Based Shoulder Surfing Attacks on Common Touchscreen Devices

机译:CipherCard:一种基于令牌的方法,可对常见触摸屏设备进行基于摄像头的肩膀冲浪攻击

获取原文

摘要

We present CipherCard, a physical token that defends against shoulder-surfing attacks on user authentication on capacitive touchscreen devices. When CipherCard is placed over a touchscreen's pin-pad, it remaps a user's touch point on the physical token to a different location on the pin-pad. It hence translates a visible user password into a different system password received by a touchscreen, but is hidden from observers as well as the user. CipherCard enhances authentication security through Two-Factor Authentication (TFA), in that both the correct user password and a specific card are needed for successful authentication. We explore the design space of CipherCard, and describe three implemented variations each with unique capabilities. Based on user feedback, we discuss the security and usability implications of CipherCard, and describe several avenues for continued exploration.
机译:我们提出了CipherCard,这是一种物理令牌,可防止电容式触摸屏设备上的用户身份验证遭受肩膀冲浪攻击。将CipherCard放在触摸屏的键盘上时,它将用户物理令牌上的触摸点重新映射到键盘上的其他位置。因此,它将可见的用户密码转换为触摸屏接收到的不同的系统密码,但对观察者和用户均隐藏。 CipherCard通过两因素身份验证(TFA)增强了身份验证的安全性,因为正确的用户密码和特定的卡都需要成功的身份验证。我们探索了CipherCard的设计空间,并描述了三种实现的变体,每种变体具有独特的功能。基于用户反馈,我们讨论了CipherCard的安全性和可用性含义,并描述了继续探索的几种途径。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号