H4Plock: Supporting Mobile User Authentication through Gestural Input and Tactile Output

dc.contributor.authorAli, Abdullah
dc.contributor.authorKuber, Ravi
dc.contributor.authorAviv, Adam J.
dc.date.accessioned2020-10-15T17:27:48Z
dc.date.available2020-10-15T17:27:48Z
dc.date.issued2015-07-22
dc.descriptionSymposium On Usable Privacy and Security, July 22-25, Ottawa, Canadaen_US
dc.description.abstractWe have developed a novel authentication mechanism, H4Plock (pronounced “Hap-lock”), that leverages gestural input and tactile feedback to defend against casual observation attacks. Users enter up to four on-screen gestures based on receiving tactile prompts, in the form of vibrations, from the mobile device. These prompts inform the user as to which gestures should be entered. The style of vibrations, e.g., short versus long, indicate the specific gestures that should be entered from a previously chosen primary or secondary passcode. As a result, the sequence of gestures will vary on each authentication attempt, reducing the capability of an attacker to “shoulder surf” and accurately recreate the authentication process. We developed a protype of the application and conducted an IRB approved pilot study. Findings show that 94% of participants were able to properly authenticate using H4Plock, with 73% successfully accessing the system after a gap of five days without rehearsal. We also examined the security of the H4Plock where participants were asked to recreate passcodes through a video replay, simulating a shoulder surfing attack scenario. Even after direct observations, only 25% of the pascodes could be successfully recreated.en_US
dc.description.urihttps://cups.cs.cmu.edu/soups/2015/posters/soups2015_posters-final5.pdfen_US
dc.format.extent2 pagesen_US
dc.genreconference papers and proceeding preprintsen_US
dc.identifierdoi:10.13016/m2n8cx-6fsl
dc.identifier.citationAli, Abdullah; Kuber, Ravi; Aviv, Adam J.; H4Plock: Supporting Mobile User Authentication through Gestural Input and Tactile Output; Symposium On Usable Privacy and Security (2015); https://cups.cs.cmu.edu/soups/2015/posters/soups2015_posters-final5.pdfen_US
dc.identifier.urihttp://hdl.handle.net/11603/19907
dc.language.isoen_USen_US
dc.publisherCyLab Usable Privacy and Security Laboratoryen_US
dc.relation.isAvailableAtThe University of Maryland, Baltimore County (UMBC)
dc.relation.ispartofUMBC Information Systems Department Collection
dc.relation.ispartofUMBC Faculty Collection
dc.rightsThis item is likely protected under Title 17 of the U.S. Copyright Law. Unless on a Creative Commons license, for uses protected by Copyright Law, contact the copyright holder or the author.
dc.rightsPublic Domain Mark 1.0*
dc.rightsThis work was written as part of one of the author's official duties as an Employee of the United States Government and is therefore a work of the United States Government. In accordance with 17 U.S.C. 105, no copyright protection is available for such works under U.S. Law.
dc.rights.urihttp://creativecommons.org/publicdomain/mark/1.0/*
dc.titleH4Plock: Supporting Mobile User Authentication through Gestural Input and Tactile Outputen_US
dc.typeTexten_US

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
soups2015_posters-final5.pdf
Size:
3.57 MB
Format:
Adobe Portable Document Format
Description:
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
2.56 KB
Format:
Item-specific license agreed upon to submission
Description: