Authentication Using Graphical Password: Effects of Increased - - PowerPoint PPT Presentation

authentication using graphical password effects of
SMART_READER_LITE
LIVE PREVIEW

Authentication Using Graphical Password: Effects of Increased - - PowerPoint PPT Presentation

Authentication Using Graphical Password: Effects of Increased Security on Usability William M. Martin Aaron G. Cass March 3, 2018 Introduction 01 Human Computer Interface Security (HCIsec) 02 Password Problem 03 Graphical User


slide-1
SLIDE 1

Authentication Using Graphical Password: Effects of Increased Security on Usability

Aaron G. Cass March 3, 2018 William M. Martin

slide-2
SLIDE 2

Introduction

Human Computer Interface Security (HCIsec) Password Problem Graphical User Authentication

01 02 03

slide-3
SLIDE 3

Introduction

slide-4
SLIDE 4

Introduction

slide-5
SLIDE 5

Introduction

Quick registration and login times. Error rates and failed login attempts are reduced. Extreamly suitable for mobile devices. Greater ability to memorize images in long term memory.

Graphical User Authentication

slide-6
SLIDE 6

Background and Related Work

Previous Research states that in many areas, GUA is more secure when compared to alphanumeric authentication.

Brute-Force Dictionary Phishing Spy-Ware

slide-7
SLIDE 7

Background and Related Work

slide-8
SLIDE 8

Research Question

Can a Graphical User Authentication System achieve resilience towards shoulder surfing without lowering usability?

slide-9
SLIDE 9

Methods and Design

PassPoints Discrete Wavelet Transform

Increase Security

slide-10
SLIDE 10

Methods and Design

PassDecoy PassMatrix

slide-11
SLIDE 11

Methods and Design

Hybrid Imagery

High Frequency - Password Image Low Frequency - Decoy Image

slide-12
SLIDE 12
slide-13
SLIDE 13
slide-14
SLIDE 14
slide-15
SLIDE 15
slide-16
SLIDE 16
slide-17
SLIDE 17
slide-18
SLIDE 18
slide-19
SLIDE 19
slide-20
SLIDE 20
slide-21
SLIDE 21
slide-22
SLIDE 22
slide-23
SLIDE 23

Experiments Performed

User Study

20 Participants Test order was randomly administered Interact with both systems

  • Number of Failures
  • Number of Errors

Effectiveness

  • 5 question survey
  • Likert-Scale Responses

Satisfaction

  • Registration Time
  • Login Time

Efficiency

slide-24
SLIDE 24

Results

Number of Failed Login Attempts

There is insufficient evidence to demonstrate that there is a difference between the two systems, if this test was given to a larger group.

Number of User Errors

There is insufficient evidence to demonstrate that there is a difference between the two systems, if this test was given to a larger group. p-value: .716 p-value: 1

Less Usable More Usable Less Usable More Usable

slide-25
SLIDE 25

Results

With a confidence of 95%, it can be said that PassDecoy will take users an additional .25 - 1.13 seconds per login attempt.

Login Time

There is sufficient evidence to demonstrate that there is a difference between the two systems, if the test was given to a larger group. p-value: .004 p-value:

Difference in Login Time

slide-26
SLIDE 26

Results

Once I created my password, I was able to input it correctly.

There is insufficient evidence to demonstrate that there is a difference between the two systems, if this test was given to a larger group.

It did not take me long to input my password 3 times.

There is insufficient evidence to demonstrate that there is a difference between the two systems, if this test was given to a larger group. p-value: .330 p-value: .666

Less Usable More Usable Less Usable More Usable

slide-27
SLIDE 27

Results

Inputting my password was easy.

There is insufficient evidence to demonstrate that there is a difference between the two systems, if this test was given to a larger group.

Registering my password was fast.

There is insufficient evidence to demonstrate that there is a difference between the two systems, if this test was given to a larger group. p-value: .494 p-value: .330

Less Usable More Usable Less Usable More Usable

slide-28
SLIDE 28

Results

My password images are easy to memorize.

There is sufficient evidence to demonstrate that there is a difference between the two systems, if this test was given to a larger group. p-value: .007

Less Usable More Usable

slide-29
SLIDE 29

Research Question

Can a Graphical User Authentication System achieve resilience towards shoulder surfing without lowering usability?

slide-30
SLIDE 30

Future Work

Remove color from the password image during registration. Test how differences in visual capability effected the results. Conduct additional user tests to see if login time can be reduced through practice.

01 02 03

slide-31
SLIDE 31

References