Is Bigger Better? Comparing User-Generated Passwords on 3x3 vs. 4x4 Grid Sizes for Android's Pattern Unlock

dc.contributor.authorAviv, Adam J.
dc.contributor.authorBudzitowski, Devon
dc.contributor.authorKuber, Ravi
dc.date.accessioned2020-10-14T18:32:26Z
dc.date.available2020-10-14T18:32:26Z
dc.date.issued2015-12
dc.descriptionACSAC ’15, December 07 - 11, 2015, Los Angeles, CA, USAen_US
dc.description.abstractAndroid’s graphical authentication mechanism requires users to unlock their devices by “drawing” a pattern that connects a sequence of contact points arranged in a 3x3 grid. Prior studies demonstrated that human-generated 3x3 patterns are weak (CCS’13); large portions can be trivially guessed with sufficient training. An obvious solution would be to increase the grid size to increase the complexity of chosen patterns. In this paper we ask the question: Does increasing the grid size increase the security of human-generated patterns? We conducted two large studies to answer this question, and our analysis shows that for both 3x3 and 4x4 patterns, there is a high incidence of repeated patterns and symmetric pairs (patterns that derive from others based on a sequence of flips and rotations), and many 4x4 patterns are expanded versions of 3x3 patterns. Leveraging this information, we developed an advanced guessing algorithm and used it to quantified the strength of the patterns using the partial guessing entropy. We find that guessing the first 20% (G˜₀.₂) of patterns for both 3x3 and 4x4 can be done as efficiently as guessing a random 2-digit PIN. While guessing larger portions of 4x4 patterns (G˜₀.₅) requires 2-bits more entropy than guessing the same ratio of 3x3 patterns, it remains on the order of cracking random 3-digit PINs. Of the patterns tested, our guessing algorithm successful cracks 15% of 3x3 patterns within 20 guesses (a typical phone lockout) and 19% of 4x4 patterns within 20 guesses; however, after 50,000 guesses, we correctly guess 95.9% of 3x3 patterns but only 66.7% of 4x4 patterns. While there may be some benefit to expanding the grid size to 4x4, we argue the majority of patterns chosen by users will remain trivially guessable and insecure against broad guessing attacks.en_US
dc.description.sponsorshipThis work was support in part by the Office of Naval Research and the National Security Agency. At the Naval Academy, high school intern Jeanne Luning-Prak contributed in developing the online survey, and Midshipman Justin Maguire aided in data entry for the paper surveys. Flynn Wolf at the UMBC also assisted in administering paper surveys. Finally, we thank Rida Bazzi for shepherding this paper, and the anonymous reviewers for their helpful feedback in improving this paper.en_US
dc.description.urihttps://dl.acm.org/doi/10.1145/2818000.2818014en_US
dc.format.extent10 pagesen_US
dc.genreconference papers and proceedingsen_US
dc.identifierdoi:10.13016/m2stv7-uuec
dc.identifier.citationAviv, Adam J.; Budzitowski, Devon; Kuber, Ravi; Is Bigger Better? Comparing User-Generated Passwords on 3x3 vs. 4x4 Grid Sizes for Android's Pattern Unlock; ACSAC 2015: Proceedings of the 31st Annual Computer Security Applications Conference, December 2015, Pages 301–310; https://dl.acm.org/doi/10.1145/2818000.2818014en_US
dc.identifier.urihttps://doi.org/10.1145/2818000.2818014
dc.identifier.urihttp://hdl.handle.net/11603/19893
dc.language.isoen_USen_US
dc.publisherAssociation for Computing Machineryen_US
dc.relation.isAvailableAtThe University of Maryland, Baltimore County (UMBC)
dc.relation.ispartofUMBC Information Systems Department Collection
dc.relation.ispartofUMBC Faculty Collection
dc.rightsThis item is likely protected under Title 17 of the U.S. Copyright Law. Unless on a Creative Commons license, for uses protected by Copyright Law, contact the copyright holder or the author.
dc.rightsPublic Domain Mark 1.0*
dc.rightsThis work was written as part of one of the author's official duties as an Employee of the United States Government and is therefore a work of the United States Government. In accordance with 17 U.S.C. 105, no copyright protection is available for such works under U.S. Law.
dc.rights.urihttp://creativecommons.org/publicdomain/mark/1.0/*
dc.titleIs Bigger Better? Comparing User-Generated Passwords on 3x3 vs. 4x4 Grid Sizes for Android's Pattern Unlocken_US
dc.typeTexten_US

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
2818000.2818014.pdf
Size:
517.07 KB
Format:
Adobe Portable Document Format
Description:
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
2.56 KB
Format:
Item-specific license agreed upon to submission
Description: