Modeling user choice in the PassPoints graphical password scheme

  • Authors:
  • Ahmet Emir Dirik;Nasir Memon;Jean-Camille Birget

  • Affiliations:
  • Polytechnic University, Brooklyn, NY;Polytechnic University, Brooklyn, NY;Rutgers University at Camden, Camden, NJ

  • Venue:
  • Proceedings of the 3rd symposium on Usable privacy and security
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

We develop a model to identify the most likely regions for users to click in order to create graphical passwords in the PassPoints system. A PassPoints password is a sequence of points, chosen by a user in an image that is displayed on the screen. Our model predicts probabilities of likely click points; this enables us to predict the entropy of a click point in a graphical password for a given image. The model allows us to evaluate automatically whether a given image is well suited for the PassPoints system, and to analyze possible dictionary attacks against the system. We compare the predictions provided by our model to results of experiments involving human users. At this stage, our model and the experiments are small and limited; but they show that user choice can be modeled and that expansions of the model and the experiments are a promising direction of research.