...
首页> 外文期刊>Information Forensics and Security, IEEE Transactions on >Analysis and Improvement of a PIN-Entry Method Resilient to Shoulder-Surfing and Recording Attacks
【24h】

Analysis and Improvement of a PIN-Entry Method Resilient to Shoulder-Surfing and Recording Attacks

机译:可抵抗肩膀冲浪和录制攻击的PIN输入方法的分析和改进

获取原文
获取原文并翻译 | 示例
           

摘要

Devising a user authentication scheme based on personal identification numbers (PINs) that is both secure and practically usable is a challenging problem. The greatest difficulty lies with the susceptibility of the PIN entry process to direct observational attacks, such as human shoulder-surfing and camera-based recording. This paper starts with an examination of a previous attempt at solving the PIN entry problem, which was based on an elegant adaptive black-and-white coloring of the 10-digit keypad in the standard layout. Even though the method required uncomfortably many user inputs, it had the merit of being easy to understand and use. Our analysis that takes both the experimental and theoretical approaches reveals multiple serious shortcomings of the previous method, including round redundancy, unbalanced key presses, highly frequent system errors, and insufficient resilience to recording attacks. The lessons learned through our analysis are then used to improve the black-and-white PIN entry scheme. The new scheme has the remarkable property of resisting camera-based recording attacks over an unlimited number of authentication sessions without leaking any of the PIN digits.
机译:基于安全且实用的个人识别码(PIN)设计用户认证方案是一个具有挑战性的问题。最大的困难在于PIN输入过程是否易于直接进行观察性攻击,例如人的肩膀冲浪和基于摄像机的记录。本文首先探讨了解决PIN输入问题的先前尝试,该尝试基于标准布局中10位数字小键盘的优雅自适应黑白着色。即使该方法需要许多用户输入,这具有易于理解和使用的优点。我们的分析采用了实验方法和理论方法,揭示了前一种方法的多个严重缺陷,包括圆形冗余,按键不平衡,系统错误频繁发生以及对记录攻击的恢复能力不足。然后,通过我们的分析获得的经验教训将被用于改进黑白PIN输入方案。新方案具有显着的性能,可以在无限制的身份验证会话中抵御基于摄像机的记录攻击,而不会泄漏任何PIN码。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号