An Anti-shoulder-surfing Authentication Scheme of Mobile Device

Jia-Ning Luo,
Ming-Hour Yang,
Cho-Luen Tsai,

Abstract


Text-based passwords, such as personal identification number (PIN) and Android screen pattern locks, are the most commonly used identity authentication method in smartphones. However, text-based passwords are unable to prevent shoulder-surfing attacks; by directly looking at the passwords entered by users, attackers are able to steal the users’ passwords, which poses significant threats to the users.
In this study, a new authentication mechanism was introduced. Such a method enabled users to send out misleading information to attackers when the former entered its text-based passwords; the latter was unable to decipher the true passwords by simply recording or looking at them. The misleading information was the pressure values (i.e., pressures exerted by the users) measured by pressure sensors embedded under the smartphone touchscreens. The systems detected each pressure value entered by the users and determined whether it was to be saved (i.e., as a true password) or omitted (i.e., as misleading information). Regarding this authentication method, because attackers were unable to know the users’ pressure values, they were unable to differentiate between true and misleading information and thus had no way of knowing the users’ actual passwords. In the end, our authentication mechanism improved the deficiency of current text-based passwords and enhanced system security.


Citation Format:
Jia-Ning Luo, Ming-Hour Yang, Cho-Luen Tsai, "An Anti-shoulder-surfing Authentication Scheme of Mobile Device," Journal of Internet Technology, vol. 19, no. 4 , pp. 1263-1272, Jul. 2018.

Full Text:

PDF

Refbacks

  • There are currently no refbacks.





Published by Executive Committee, Taiwan Academic Network, Ministry of Education, Taipei, Taiwan, R.O.C
JIT Editorial Office, Office of Library and Information Services, National Dong Hwa University
No. 1, Sec. 2, Da Hsueh Rd., Shoufeng, Hualien 974301, Taiwan, R.O.C.
Tel: +886-3-931-7314  E-mail: jit.editorial@gmail.com