charPattern: Rethinking Android Lock Pattern to Adapt to Remote Authentication


Bicakci K., Satiev T.

International Conference on Passwords (PASSWORDS), Trondheim, Norveç, 8 - 10 Aralık 2014, cilt.9393, ss.74-86 identifier identifier

  • Yayın Türü: Bildiri / Tam Metin Bildiri
  • Cilt numarası: 9393
  • Doi Numarası: 10.1007/978-3-319-24192-0_5
  • Basıldığı Şehir: Trondheim
  • Basıldığı Ülke: Norveç
  • Sayfa Sayıları: ss.74-86
  • İstanbul Teknik Üniversitesi Adresli: Hayır

Özet

Android Lock Pattern is popular as a screen lock method on mobile devices but it cannot be used directly over the Internet for user authentication. In our work, we carefully adapt Android Lock Pattern to satisfy the requirements of remote authentication and introduce a new pattern based method called charPattern. Our new method allows dual-mode of input (typing a password and drawing a pattern) hence accommodate users who login alternately with a physical keyboard and a touchscreen device. It uses persuasive technology to create strong passwords which withstand attacks involving up to 10 6 guesses; an amount many experts believe sufficient against online attacks. We conduct a hybrid lab and web study to evaluate the usability of the new method and observe that logins with charPattern are significantly faster than the ones with text passwords on mobile devices.