Graphical One-Time Password (GOTPass): A usability evaluation

被引:3
作者
Alsaiari, Hussain [1 ]
Papadaki, Maria [1 ]
Dowland, Paul [1 ]
Furnell, Steven [1 ]
机构
[1] Univ Plymouth, Sch Comp Elect & Math, Ctr Secur Commun & Network Res, Plymouth PL4 8AA, Devon, England
来源
INFORMATION SECURITY JOURNAL | 2016年 / 25卷 / 1-3期
关键词
Authentication; graphical passwords; knowledge-based authentication; One-Time Password; usable security;
D O I
10.1080/19393555.2016.1179374
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Complying with a security policy often requires users to create long and complex passwords to protect their accounts. However, remembering such passwords is difficult for many and may lead to insecure practices, such as choosing weak passwords or writing them down. In addition, they are vulnerable to various types of attacks, such as shoulder surfing, replay, and keylogger attacks (Gupta, Sahni, Sabbu, Varma, & Gangashetty, 2012) One-Time Passwords (OTPs) aim to overcome such problems (Gupta et al., 2012); however, most implemented OTP techniques require special hardware, which not only adds cost, but there are also issues regarding its availability (Brostoff, Inglesant, & Sasse, 2010). In contrast, the use of graphical passwords is an alternative authentication mechanism designed to aid memorability and ease of use, often forming part of a multifactor authentication process. This article is complementary to the earlier work that introduced and evaluated the security of the new hybrid user-authentication approach: Graphical One-Time Password (GOTPass) (Alsaiari et al., 2015). The scheme aims to combine the usability of recognition-based and draw-based graphical passwords with the security of OTP. The article presents the results of an empirical user study that investigates the usability features of the proposed approach, as well as pretest and posttest questionnaires. The experiment was conducted during three separate sessions, which took place over five weeks, to measure the efficiency, effectiveness, memorability, and user satisfaction of the new scheme. The results showed that users were able to easily create and enter their credentials as well as remember them over time. Participants carried out a total of 1,302 login attempts with a 93% success rate and an average login time of 24.5 s.
引用
收藏
页码:94 / 108
页数:15
相关论文
共 23 条
[1]   Secure Graphical One Time Password (GOTPass): An Empirical Study [J].
Alsaiari, H. ;
Papadaki, M. ;
Dowland, P. ;
Furnell, S. .
INFORMATION SECURITY JOURNAL, 2015, 24 (4-6) :207-220
[2]   An empirical evaluation of the System Usability Scale [J].
Bangor, Aaron ;
Kortum, Philip T. ;
Miller, James T. .
INTERNATIONAL JOURNAL OF HUMAN-COMPUTER INTERACTION, 2008, 24 (06) :574-594
[3]  
Biddle Robert, 2011, COMPUTER SURVEYS, V44, P4
[4]   The Quest to Replace Passwords: A Framework for Comparative Evaluation of Web Authentication Schemes [J].
Bonneau, Joseph ;
Herley, Cormac ;
van Oorschot, Paul C. ;
Stajano, Frank .
2012 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2012, :553-567
[5]  
Brostoff S., 2010, 24 BCS INT SPEC GROU, P88
[6]  
Chiang H., 2013, P 15 INT C HUM COMP, P251
[7]   Is a picture really worth a thousand words? Exploring the feasibility of graphical authentication systems [J].
De Angeli, A ;
Coventry, L ;
Johnson, G ;
Renaud, K .
INTERNATIONAL JOURNAL OF HUMAN-COMPUTER STUDIES, 2005, 63 (1-2) :128-152
[8]  
De Angeli A, 2003, CONTEMPORARY ERGONOMICS 2003, P253
[9]  
De Angeli A., 2002, P WORK C ADV VIS INT, P316, DOI DOI 10.1145/1556262.1556312
[10]  
Gao H., 2009, PROC ACM SYMP USABLE, P15