Graphical passwords & qualitative spatial relations

  • Authors:
  • Di Lin;Paul Dunphy;Patrick Olivier;Jeff Yan

  • Affiliations:
  • Newcastle University, UK;Newcastle University, UK;Newcastle University, UK;Newcastle University, UK

  • Venue:
  • Proceedings of the 3rd symposium on Usable privacy and security
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

A potential drawback of graphical password schemes is that they are more vulnerable to shoulder surfing than conventional alphanumeric text passwords. We present a variation of the Draw-a-Secret scheme originally proposed by Jermyn et al [1] that is more resistant to shoulder surfing through the use of a qualitative mapping between user strokes and the password, and the use of dynamic grids to both obfuscate attributes of the user secret and encourage them to use different surface realizations of the secret. The use of qualitative spatial relations relaxes the tight constraints on the reconstruction of a secret; allowing a range of deviations from the original. We describe QDAS (Qualitative Draw-A-Secret), an initial implementation of this graphical password scheme, and the results of an empirical study in which we examined the memorability of secrets, and their susceptibility to shoulder-surfing attacks, for both Draw-A-Secret and QDAS.