2010
DOI: 10.14236/ewic/hci2010.13
|View full text |Cite
|
Sign up to set email alerts
|

Evaluating the usability and security of a graphical one-time PIN system

Abstract: Traditional Personal Identification Numbers (PINs) are widely used, but the attacks in which they are captured have been increasing. One-time PINs offer better security, but potentially create greater workload for users. In this paper, we present an independent evaluation of a commercial system that makes PINs more resistant to observation attacks by using graphical passwords on a grid to generate a one-time PIN. 83 participants were asked to register with the system and log in at varying intervals. The succes… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

3
12
0

Year Published

2011
2011
2022
2022

Publication Types

Select...
5
2

Relationship

2
5

Authors

Journals

citations
Cited by 22 publications
(15 citation statements)
references
References 10 publications
3
12
0
Order By: Relevance
“…GrIDsure is one such example, users are asked to memorise a pattern and then when authenticating they receive a grid filled with digits and need to enter the digits that correspond to their pattern. Brostoff, Inglesant and Sasse (2010) looked at the usability of GrIDsure and found that in nearly 18% of usages, participants were trying to enter the PIN on the grid directly instead of typing it. This undermines the security property offered by the grid, namely resistance to shoulder-surfing.…”
Section: Related Workmentioning
confidence: 99%
“…GrIDsure is one such example, users are asked to memorise a pattern and then when authenticating they receive a grid filled with digits and need to enter the digits that correspond to their pattern. Brostoff, Inglesant and Sasse (2010) looked at the usability of GrIDsure and found that in nearly 18% of usages, participants were trying to enter the PIN on the grid directly instead of typing it. This undermines the security property offered by the grid, namely resistance to shoulder-surfing.…”
Section: Related Workmentioning
confidence: 99%
“…The mechanisms studied include graphical passwords [8], Passfaces [9] and grids (e.g. [10], [11]) to name a few. In reality, securityrelated actions are secondary tasks and a study has to mimic this set-up.…”
Section: Related Workmentioning
confidence: 99%
“…GrIDsure has been found to be easy to learn and the recall of patterns is acceptably reliable; however, as with other password schemes, the effective pattern space is far smaller than the maximum possible [7]. However, to understand the actual pattern space, simple assumptions are not sufficient [6]; as well as the shape, the order of cells and placement on the grid are important factors distinguishing between patterns.…”
Section: B Existing Research On Gridsurementioning
confidence: 99%
“…However, to understand the actual pattern space, simple assumptions are not sufficient [6]; as well as the shape, the order of cells and placement on the grid are important factors distinguishing between patterns. Although there are common patterns, these do not all occur with similar frequency [6], [7]. Brostoff et al have developed a taxonomy of patterns, and our current work builds on this.…”
Section: B Existing Research On Gridsurementioning
confidence: 99%
See 1 more Smart Citation