VibroAuth: Authentication with Haptics Based Non-visual, Rearranged Keypads to Mitigate Shoulder Surfing Attacks

Manisha Varma, Stacey Watson, Liwei Chan, Roshan Peiris*

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

7 Scopus citations

Abstract

PIN (Personal Identification Number) code entry is a widely used authentication method used on smartphones, ATMs, etc. However, it is typically subject to shoulder surfing attacks where, a bystander may observe the user’s keypad during PIN code entry. To mitigate this issue, we present a novel method that uses non-visual keypads for entering PIN codes where, the numbers on the keypad are invisible and rearranged. The numbers are rearranged by shifting the rows/columns of the keypad and we use haptic patterns to privately convey the keypad layout information to the user. The results of our first study with 22 participants indicated that the participants could learn the haptic patterns relatively fast and use the non-visual keypads with high accuracy. Next, a security experiment with 12 participants discusses the effectiveness of our method in mitigating shoulder surfing attacks.

Original languageEnglish
Title of host publicationHCI for Cybersecurity, Privacy and Trust - 4th International Conference, HCI-CPT 2022, Held as Part of the 24th HCI International Conference, HCII 2022, Proceedings
EditorsAbbas Moallem
PublisherSpringer Science and Business Media Deutschland GmbH
Pages280-303
Number of pages24
ISBN (Print)9783031055621
DOIs
StatePublished - 2022
Event4th International Conference on HCI for Cybersecurity, Privacy and Trust, HCI-CPT 2022 Held as Part of the 24th HCI International Conference, HCII 2022 - Virtual, Online
Duration: 26 Jun 20221 Jul 2022

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume13333 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference4th International Conference on HCI for Cybersecurity, Privacy and Trust, HCI-CPT 2022 Held as Part of the 24th HCI International Conference, HCII 2022
CityVirtual, Online
Period26/06/221/07/22

Keywords

  • Authentication
  • Haptic
  • Mobile
  • PIN codes
  • Usable security

Fingerprint

Dive into the research topics of 'VibroAuth: Authentication with Haptics Based Non-visual, Rearranged Keypads to Mitigate Shoulder Surfing Attacks'. Together they form a unique fingerprint.

Cite this