A graphical PIN authentication mechanism with applications to smart cards and low-cost devices

  • Authors:
  • Luigi Catuogno;Clemente Galdi

  • Affiliations:
  • Dipartimento di Informatica ed Applicazioni, Università di Salerno, Fisciano, SA, Italy;Dipartimento di Scienze Fisiche, Università di Napoli "Federico II", Napoli, NA, Italy

  • Venue:
  • WISTP'08 Proceedings of the 2nd IFIP WG 11.2 international conference on Information security theory and practices: smart devices, convergence and next generation networks
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

Passwords and PINs are still the most deployed authenticationmechanisms and their protection is a classical branch of research incomputer security. Several password schemes, as well as more sophisticatedtokens, algorithms, and protocols, have been proposed during thelast years. Some proposals require dedicated devices, such as biometricsensors, whereas, others of them have high computational requirements.Graphical passwords are a promising research branch, but implementationof many proposed schemes often requires considerable resources(e.g., data storage, high quality displays) making difficult their usage onsmall devices, like old fashioned ATM terminals, smart cards and manylow-price cellular phones. In this paper we present a graphical mechanism that handles authenticationby means of a numerical PIN, that users have to type on the basisof a secret sequence of objects and a graphical challenge. The proposedscheme can be instantiated in a way to require low computation capabilities,making it also suitable for small devices with limited resources.We prove that our scheme is effective against "shoulder surfing" attacks.