Geographical Security Questions for Fallback Authentication

被引:4
|
作者
Addas, Alaadin [1 ]
Salehi-Abari, Amirali [1 ]
Thorpe, Julie [1 ]
机构
[1] Ontario Tech Univ, Oshawa, ON, Canada
基金
加拿大自然科学与工程研究理事会;
关键词
PURELY AUTOMATED ATTACKS; PASSPOINTS;
D O I
10.1109/pst47121.2019.8949063
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Fallback authentication is the backup authentication method used when the primary authentication method (e.g., passwords, biometrics, etc.) fails. Currently, widely-deployed fallback authentication methods (e.g., security questions, email resets, and SMS resets) suffer from documented security and usability flaws that threaten the security of accounts. These flaws motivate us to design and study Geographical Security Questions (GeoSQ), a system for fallback authentication. GeoSQ is an Android application that utilizes autobiographical location data for fallback authentication. We performed security and usability analyses of GeoSQ through an in-person two-session lab study (n=36, 18 pairs). Our results indicate that GeoSQ exceeds the security of its counterparts, while its usability (specifically login time and memorability) has room for improvement.
引用
收藏
页码:217 / 222
页数:6
相关论文
共 50 条
  • [1] Evaluating knowledge-based security questions for fallback authentication
    AlHusain R.
    Alkhalifah A.
    PeerJ Computer Science, 2022, 8
  • [2] Evaluating knowledge-based security questions for fallback authentication
    AlHusain, Reem
    Alkhalifah, Ali
    PEERJ COMPUTER SCIENCE, 2022, 8
  • [3] Evaluating smartphone-based dynamic security questions for fallback authentication: a field study
    Albayram, Yusuf
    Khan, Mohammad Maifi Hasan
    HUMAN-CENTRIC COMPUTING AND INFORMATION SCIENCES, 2016, 6
  • [4] I Know What You Did Last Week! Do You? Dynamic Security Questions for Fallback Authentication on Smartphones
    Hang, Alina
    De Luca, Alexander
    Hussmann, Heinrich
    CHI 2015: PROCEEDINGS OF THE 33RD ANNUAL CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS, 2015, : 1383 - 1392
  • [5] Enhancing smartphone security with human centric bimodal fallback authentication leveraging sensors
    Farhan, Asma Ahmad
    Basharat, Amna
    Allheeib, Nasser
    Kanwal, Summrina
    SCIENTIFIC REPORTS, 2024, 14 (01):
  • [6] Secure Fallback Authentication and the Trusted Friend Attack
    Javed, Ashar
    Bletgen, David
    Kohlar, Florian
    Duermuth, Markus
    Schwenk, Joerg
    2014 IEEE 34TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS WORKSHOPS (ICDCSW), 2014, : 22 - 28
  • [7] Understanding users’ perceptions to improve fallback authentication
    Micallef N.
    Arachchilage N.A.G.
    Personal and Ubiquitous Computing, 2021, 25 (05) : 893 - 910
  • [8] It's no secret Measuring the security and reliability of authentication via 'secret' questions
    Schechter, Stuart
    Brush, A. J. Bernheim
    Egelman, Serge
    PROCEEDINGS OF THE 2009 30TH IEEE SYMPOSIUM ON SECURITY AND PRIVACY, 2009, : 375 - 390
  • [9] Evaluating fallback authentication research: A systematic literature review
    AlHusain, Reem
    Alkhalifah, Ali
    COMPUTERS & SECURITY, 2021, 111
  • [10] Evaluating security and usability of profile based challenge questions authentication in online examinations
    Ullah, Abrar
    Xiao, Hannan
    Barker, Trevor
    Lilley, Mariana
    JOURNAL OF INTERNET SERVICES AND APPLICATIONS, 2014, 5 (05) : 1 - 16