Authentication Using Graphical Password: Effects of...

31
Authentication Using Graphical Password: Effects of Increased Security on Usability Aaron G. Cass March 3, 2018 William M. Martin

Transcript of Authentication Using Graphical Password: Effects of...

Page 1: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security

Authentication Using Graphical Password:

Effects of Increased Security on Usability

Aaron G. Cass

March 3, 2018

William M. Martin

Page 2: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security

Introduction

Human Computer Interface Security (HCIsec)

Password Problem

Graphical User Authentication

01

02

03

Page 3: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security

Introduction

Page 4: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security

Introduction

Page 5: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security

Introduction

Quick registration and

login times.

Error rates and failed login

attempts are reduced.

Extreamly suitable for

mobile devices.

Greater ability to memorize

images in long term memory.

Graphical

User

Authentication

Page 6: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security

Background and Related Work

Previous Research states that

in many areas, GUA is more

secure when compared to

alphanumeric authentication.

Brute-Force Dictionary Phishing Spy-Ware

Page 7: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security

Background and Related Work

Page 8: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security

Research Question

Can a Graphical User Authentication System

achieve resilience towards shoulder surfing

without lowering usability?

Page 9: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security

Methods and Design

PassPoints Discrete Wavelet Transform

Increase

Security

Page 10: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security

Methods and Design

PassDecoyPassMatrix

Page 11: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security

Methods and DesignHybrid Imagery

High Frequency - Password Image Low Frequency - Decoy Image

Page 12: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security
Page 13: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security
Page 14: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security
Page 15: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security
Page 16: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security
Page 17: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security
Page 18: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security
Page 19: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security
Page 20: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security
Page 21: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security
Page 22: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security
Page 23: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security

Experiments Performed

User Study

20 Participants

Test order was randomly

administered

Interact with both systems

• Number of Failures

• Number of Errors

Effectiveness

• 5 question survey

• Likert-Scale Responses

Satisfaction

• Registration Time

• Login Time

Efficiency

Page 24: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security

Results

Number of Failed Login Attempts

There is insufficient evidence to demonstrate that there

is a difference between the two systems, if this test was

given to a larger group.

Number of User Errors

There is insufficient evidence to demonstrate that there

is a difference between the two systems, if this test was

given to a larger group.

p-value: .716 p-value: 1

Less

Usable

More

Usable

Less

Usable

More

Usable

Page 25: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security

Results

With a confidence of 95%, it can be said that PassDecoy

will take users an additional .25 - 1.13 seconds per login

attempt.

Login Time

There is sufficient evidence to demonstrate that there is

a difference between the two systems, if the test was

given to a larger group.

p-value: .004 p-value:

Difference in Login Time

Page 26: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security

Results

Once I created my password, I was

able to input it correctly.

There is insufficient evidence to demonstrate that there

is a difference between the two systems, if this test was

given to a larger group.

It did not take me long to input my

password 3 times.

There is insufficient evidence to demonstrate that there

is a difference between the two systems, if this test was

given to a larger group.

p-value: .330 p-value: .666

Less

Usable

More

Usable

Less

Usable

More

Usable

Page 27: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security

Results

Inputting my password was easy.

There is insufficient evidence to demonstrate that there

is a difference between the two systems, if this test was

given to a larger group.

Registering my password was fast.

There is insufficient evidence to demonstrate that there

is a difference between the two systems, if this test was

given to a larger group.

p-value: .494 p-value: .330

Less

Usable

More

Usable

Less

Usable

More

Usable

Page 28: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security

Results

My password images are easy to memorize.

There is sufficient evidence to demonstrate that there is

a difference between the two systems, if this test was

given to a larger group.

p-value: .007

Less

Usable

More

Usable

Page 29: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security

Research Question

Can a Graphical User Authentication System

achieve resilience towards shoulder surfing

without lowering usability?

Page 30: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security

Future Work

Remove color from the password image during registration.

Test how differences in visual capability effected the results.

Conduct additional user tests to see if login time can be

reduced through practice.

01

02

03

Page 31: Authentication Using Graphical Password: Effects of ...orzo.union.edu/Archives/SeniorProjects/2018/CS.2018/...Authentication Using Graphical Password: Effects of Increased Security

References