Title :
Security Notions and Advanced Method for Human Shoulder-Surfing Resistant PIN-Entry
Author_Institution :
Sch. of Comput. & Inf. Eng., Inha Univ., Incheon, South Korea
Abstract :
The personal identification number (PIN) is a well-known authentication method used in various devices, such as ATMs, mobile devices, and electronic door locks. Unfortunately, the conventional PIN-entry method is vulnerable to shoulder-surfing attacks. Consequently, various shoulder-surfing resistant methods have been proposed. However, the security analyses used to justify these proposed methods are not based on rigorous quantitative analysis, but instead on the results of experiments involving a limited number of human attackers. In this paper, we propose new theoretical and experimental techniques for quantitative security analysis of PIN-entry methods. We first present new security notions and guidelines for secure PIN-entry methods by analyzing the existing methods under the new framework. On the basis of these guidelines, we develop a new PIN-entry method that effectively obviates human shoulder-surfing attacks by significantly increasing the amount of short-term memory required in an attack.
Keywords :
authorisation; ATM; authentication method; electronic door locks; human attackers; human shoulder-surfing attacks; human shoulder-surfing resistant PIN-entry; mobile devices; personal identification number; quantitative analysis; quantitative security analysis; security notions; Authentication; Immune system; Memory management; Mobile handsets; Pins; Usability; User authentication; personal identification number; shoulder-surfing attack;
Journal_Title :
Information Forensics and Security, IEEE Transactions on
DOI :
10.1109/TIFS.2014.2307671