Skip to main content
Top

2022 | OriginalPaper | Chapter

Bu-Dash: A Universal and Dynamic Graphical Password Scheme

Authors : Panagiotis Andriotis, Myles Kirby, Atsuhiro Takasu

Published in: HCI for Cybersecurity, Privacy and Trust

Publisher: Springer International Publishing

Activate our intelligent search to find suitable subject content or patents.

search-config
loading …

Abstract

Biometric authentication gradually replaces knowledge-based methods on mobile devices. However, Personal Identification Numbers, passcodes, and graphical password schemes such as the Android Pattern Unlock (APU) are often the primary means for authentication, or they constitute an auxiliary (or backup) method to be used in case biometrics fail. Passcodes need to be memorable to be usable, hence users tend to choose easy to guess passwords, compromising security. The APU is a great example of a popular and usable graphical password scheme which can be easily compromised, by exploiting common and predominant human behavioristic traits. Despite its vulnerabilities, the scheme’s popularity has led researchers to propose adjustments and variations that enhance security but maintain its familiar user interface. Nevertheless, prior work demonstrated that improving security while preserving usability remains frequently a hard task. In this paper we propose a novel graphical password scheme built on the foundations of the well-accepted APU method, which is usable, inclusive, universal, and robust against shoulder surfing and smudge attacks. Our scheme, named Bu-Dash, features a dynamic user interface that mutates every time a user swipes the screen. Our pilot studies illustrate that Bu-Dash attracts positive user acceptance rates and maintains acceptable usability levels.

Dont have a licence yet? Then find out more about our products and how to get one now:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Footnotes
2
We utilized Google’s “Material Icons” as the password building blocks in this research work: https://​fonts.​google.​com/​icons.
 
3
We refer to viewers of the popular series “Squid Game”.
 
Literature
3.
go back to reference Andriotis, P., Tryfonas, T., Oikonomou, G., Yildiz, C.: A pilot study on the security of pattern screen-lock methods and soft side channel attacks. In: Proceedings of the Sixth ACM Conference on Security and Privacy in Wireless and Mobile Networks, WiSec 2013, pp. 1–6. ACM, New York (2013). https://doi.org/10.1145/2462096.2462098 Andriotis, P., Tryfonas, T., Oikonomou, G., Yildiz, C.: A pilot study on the security of pattern screen-lock methods and soft side channel attacks. In: Proceedings of the Sixth ACM Conference on Security and Privacy in Wireless and Mobile Networks, WiSec 2013, pp. 1–6. ACM, New York (2013). https://​doi.​org/​10.​1145/​2462096.​2462098
4.
go back to reference Aviv, A.J., Budzitowski, D., Kuber, R.: Is bigger better? Comparing user-generated passwords on \(3 \times 3\) vs. \(4 \times 4\) grid sizes for Android’s pattern unlock. In: Proceedings of the 31st Annual Computer Security Applications Conference, ACSAC 2015, pp. 301–310. Association for Computing Machinery, New York (2015). https://doi.org/10.1145/2818000.2818014 Aviv, A.J., Budzitowski, D., Kuber, R.: Is bigger better? Comparing user-generated passwords on \(3 \times 3\) vs. \(4 \times 4\) grid sizes for Android’s pattern unlock. In: Proceedings of the 31st Annual Computer Security Applications Conference, ACSAC 2015, pp. 301–310. Association for Computing Machinery, New York (2015). https://​doi.​org/​10.​1145/​2818000.​2818014
5.
go back to reference Aviv, A.J., Davin, J.T., Wolf, F., Kuber, R.: Towards baselines for shoulder surfing on mobile authentication. In: Proceedings of the 33rd Annual Computer Security Applications Conference, ACSAC 2017, pp. 486–498. Association for Computing Machinery, New York (2017). https://doi.org/10.1145/3134600.3134609 Aviv, A.J., Davin, J.T., Wolf, F., Kuber, R.: Towards baselines for shoulder surfing on mobile authentication. In: Proceedings of the 33rd Annual Computer Security Applications Conference, ACSAC 2017, pp. 486–498. Association for Computing Machinery, New York (2017). https://​doi.​org/​10.​1145/​3134600.​3134609
6.
go back to reference Aviv, A.J., Gibson, K., Mossop, E., Blaze, M., Smith, J.M.: Smudge attacks on smartphone touch screens. In: Proceedings of the 4th USENIX Conference on Offensive Technologies, WOOT 2010, pp. 1–7. USENIX Association (2010) Aviv, A.J., Gibson, K., Mossop, E., Blaze, M., Smith, J.M.: Smudge attacks on smartphone touch screens. In: Proceedings of the 4th USENIX Conference on Offensive Technologies, WOOT 2010, pp. 1–7. USENIX Association (2010)
10.
go back to reference Dai, L., Zhang, K., Zheng, X.S., Martin, R.R., Li, Y., Yu, J.: Visual complexity of shapes: a hierarchical perceptual learning model. Vis. Comput. 38, 419–432 (2021)CrossRef Dai, L., Zhang, K., Zheng, X.S., Martin, R.R., Li, Y., Yu, J.: Visual complexity of shapes: a hierarchical perceptual learning model. Vis. Comput. 38, 419–432 (2021)CrossRef
12.
go back to reference De Luca, A., et al.: Now you see me, now you don’t: protecting smartphone authentication from shoulder surfers. In: Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, CHI 2014, pp. 2937–2946. Association for Computing Machinery, New York (2014). https://doi.org/10.1145/2556288.2557097 De Luca, A., et al.: Now you see me, now you don’t: protecting smartphone authentication from shoulder surfers. In: Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, CHI 2014, pp. 2937–2946. Association for Computing Machinery, New York (2014). https://​doi.​org/​10.​1145/​2556288.​2557097
14.
go back to reference Gugenheimer, J., De Luca, A., Hess, H., Karg, S., Wolf, D., Rukzio, E.: ColorSnakes: using colored decoys to secure authentication in sensitive contexts. In: Proceedings of the 17th International Conference on Human-Computer Interaction with Mobile Devices and Services, MobileHCI 2015, pp. 274–283. Association for Computing Machinery, New York (2015). https://doi.org/10.1145/2785830.2785834 Gugenheimer, J., De Luca, A., Hess, H., Karg, S., Wolf, D., Rukzio, E.: ColorSnakes: using colored decoys to secure authentication in sensitive contexts. In: Proceedings of the 17th International Conference on Human-Computer Interaction with Mobile Devices and Services, MobileHCI 2015, pp. 274–283. Association for Computing Machinery, New York (2015). https://​doi.​org/​10.​1145/​2785830.​2785834
15.
go back to reference Kabir, M.M., Hasan, N., Tahmid, M.K.H., Ovi, T.A., Rozario, V.S.: Enhancing smartphone lock security using vibration enabled randomly positioned numbers. In: Proceedings of the International Conference on Computing Advancements, ICCA 2020. Association for Computing Machinery, New York (2020). https://doi.org/10.1145/3377049.3377099 Kabir, M.M., Hasan, N., Tahmid, M.K.H., Ovi, T.A., Rozario, V.S.: Enhancing smartphone lock security using vibration enabled randomly positioned numbers. In: Proceedings of the International Conference on Computing Advancements, ICCA 2020. Association for Computing Machinery, New York (2020). https://​doi.​org/​10.​1145/​3377049.​3377099
17.
go back to reference Kim, S.H., Kim, J.W., Kim, S.Y., Cho, H.G.: A new shoulder-surfing resistant password for mobile environments. In: Proceedings of the 5th International Conference on Ubiquitous Information Management and Communication, ICUIMC 2011. Association for Computing Machinery, New York (2011). https://doi.org/10.1145/1968613.1968647 Kim, S.H., Kim, J.W., Kim, S.Y., Cho, H.G.: A new shoulder-surfing resistant password for mobile environments. In: Proceedings of the 5th International Conference on Ubiquitous Information Management and Communication, ICUIMC 2011. Association for Computing Machinery, New York (2011). https://​doi.​org/​10.​1145/​1968613.​1968647
23.
go back to reference Loge, M., Duermuth, M., Rostad, L.: On user choice for android unlock patterns. In: European Workshop on Usable Security, ser. EuroUSEC, vol. 16 (2016) Loge, M., Duermuth, M., Rostad, L.: On user choice for android unlock patterns. In: European Workshop on Usable Security, ser. EuroUSEC, vol. 16 (2016)
26.
go back to reference Schneegass, S., Steimle, F., Bulling, A., Alt, F., Schmidt, A.: SmudgeSafe: geometric image transformations for smudge-resistant user authentication. In: Proceedings of the 2014 ACM International Joint Conference on Pervasive and Ubiquitous Computing, UbiComp 2014, pp. 775–786. Association for Computing Machinery, New York (2014). https://doi.org/10.1145/2632048.2636090 Schneegass, S., Steimle, F., Bulling, A., Alt, F., Schmidt, A.: SmudgeSafe: geometric image transformations for smudge-resistant user authentication. In: Proceedings of the 2014 ACM International Joint Conference on Pervasive and Ubiquitous Computing, UbiComp 2014, pp. 775–786. Association for Computing Machinery, New York (2014). https://​doi.​org/​10.​1145/​2632048.​2636090
27.
29.
go back to reference Tupsamudre, H., Banahatti, V., Lodha, S., Vyas, K.: Pass-O: a proposal to improve the security of pattern unlock scheme. In: Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, ASIA CCS 2017, pp. 400–407. Association for Computing Machinery, New York (2017). https://doi.org/10.1145/3052973.3053041 Tupsamudre, H., Banahatti, V., Lodha, S., Vyas, K.: Pass-O: a proposal to improve the security of pattern unlock scheme. In: Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, ASIA CCS 2017, pp. 400–407. Association for Computing Machinery, New York (2017). https://​doi.​org/​10.​1145/​3052973.​3053041
30.
go back to reference Uellenbeck, S., Dürmuth, M., Wolf, C., Holz, T.: Quantifying the security of graphical passwords: the case of Android unlock patterns. In: Proceedings of the 2013 ACM SIGSAC Conference on Computer and Communications Security, CCS 2013, pp. 161–172. Association for Computing Machinery, New York (2013). https://doi.org/10.1145/2508859.2516700 Uellenbeck, S., Dürmuth, M., Wolf, C., Holz, T.: Quantifying the security of graphical passwords: the case of Android unlock patterns. In: Proceedings of the 2013 ACM SIGSAC Conference on Computer and Communications Security, CCS 2013, pp. 161–172. Association for Computing Machinery, New York (2013). https://​doi.​org/​10.​1145/​2508859.​2516700
31.
go back to reference Vaddepalli, S., Nivas, S., Chettoor Jayakrishnan, G., Sirigireddy, G., Banahatti, V., Lodha, S.: Passo - new circular patter lock scheme evaluation. In: 22nd International Conference on Human-Computer Interaction with Mobile Devices and Services, MobileHCI 2020. Association for Computing Machinery, New York (2020). https://doi.org/10.1145/3406324.3417167 Vaddepalli, S., Nivas, S., Chettoor Jayakrishnan, G., Sirigireddy, G., Banahatti, V., Lodha, S.: Passo - new circular patter lock scheme evaluation. In: 22nd International Conference on Human-Computer Interaction with Mobile Devices and Services, MobileHCI 2020. Association for Computing Machinery, New York (2020). https://​doi.​org/​10.​1145/​3406324.​3417167
32.
go back to reference Wang, D., Gu, Q., Huang, X., Wang, P.: Understanding human-chosen PINs: characteristics, distribution and security. In: Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, ASIA CCS 2017, pp. 372–385. Association for Computing Machinery, New York (2017). https://doi.org/10.1145/3052973.3053031 Wang, D., Gu, Q., Huang, X., Wang, P.: Understanding human-chosen PINs: characteristics, distribution and security. In: Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, ASIA CCS 2017, pp. 372–385. Association for Computing Machinery, New York (2017). https://​doi.​org/​10.​1145/​3052973.​3053031
35.
go back to reference von Zezschwitz, E., et al.: On quantifying the effective password space of grid-based unlock gestures. In: Proceedings of the 15th International Conference on Mobile and Ubiquitous Multimedia, MUM 2016, pp. 201–212. Association for Computing Machinery, New York (2016). https://doi.org/10.1145/3012709.3012729 von Zezschwitz, E., et al.: On quantifying the effective password space of grid-based unlock gestures. In: Proceedings of the 15th International Conference on Mobile and Ubiquitous Multimedia, MUM 2016, pp. 201–212. Association for Computing Machinery, New York (2016). https://​doi.​org/​10.​1145/​3012709.​3012729
Metadata
Title
Bu-Dash: A Universal and Dynamic Graphical Password Scheme
Authors
Panagiotis Andriotis
Myles Kirby
Atsuhiro Takasu
Copyright Year
2022
DOI
https://doi.org/10.1007/978-3-031-05563-8_14