Skip to main content

Research Repository

Advanced Search

Bu-Dash: A universal and dynamic graphical password scheme

Andriotis, Panagiotis; Kirby, Myles; Takasu, Atsuhiro

Bu-Dash: A universal and dynamic graphical password scheme Thumbnail


Authors

Profile Image

Dr Panos Andriotis Panagiotis.Andriotis@uwe.ac.uk
Senior Lecturer in Computer Forensics and Security

Myles Kirby

Atsuhiro Takasu



Contributors

Abbas Moallem
Editor

Abstract

Biometric authentication gradually replaces knowledge-based methods on mobile devices. However, Personal Identification Numbers, passcodes, and graphical password schemes such as the Android Pattern Unlock (APU) are often the primary means for authentication, or they constitute an auxiliary (or backup) method to be used in case biometrics fail. Passcodes need to be memorable to be usable, hence users tend to choose easy to guess passwords, compromising security. The APU is a great example of a popular and usable graphical password scheme which can be easily compromised, by exploiting common and predominant human behavioristic traits. Despite its vulnerabilities, the scheme’s popularity has led researchers to propose adjustments and variations that enhance security but maintain its familiar user interface. Nevertheless, prior work demonstrated that improving security while preserving usability remains frequently a hard task. In this paper we propose a novel graphical password scheme built on the foundations of the well-accepted APU method, which is usable, inclusive, universal, and robust against shoulder surfing and smudge attacks. Our scheme, named Bu-Dash, features a dynamic user interface that mutates every time a user swipes the screen. Our pilot studies illustrate that Bu-Dash attracts positive user acceptance rates and maintains acceptable usability levels.

Citation

Andriotis, P., Kirby, M., & Takasu, A. (2022). Bu-Dash: A universal and dynamic graphical password scheme. In A. Moallem (Ed.), HCI for Cybersecurity, Privacy and Trust: 4th International Conference, HCI-CPT 2022, Held as Part of the 24th HCI International Conference, HCII 2022, Virtual Event, June 26 – July 1, 2022, Proceedings (209-227). https://doi.org/10.1007/978-3-031-05563-8_14

Conference Name HCI International 2022
Conference Location Virtual
Start Date Jun 26, 2022
End Date Jul 1, 2022
Acceptance Date Dec 14, 2021
Online Publication Date Jun 16, 2022
Publication Date Jun 16, 2022
Deposit Date Jan 24, 2022
Publicly Available Date Jun 17, 2023
Publisher Springer Verlag
Volume 13333 LNCS
Pages 209-227
Series Title Lecture Notes in Computer Science (LNCS, volume 13333)
Series ISSN 0302-9743; 1611-3349
Book Title HCI for Cybersecurity, Privacy and Trust: 4th International Conference, HCI-CPT 2022, Held as Part of the 24th HCI International Conference, HCII 2022, Virtual Event, June 26 – July 1, 2022, Proceedings
Chapter Number 14
ISBN 978-3-031-05562-1
DOI https://doi.org/10.1007/978-3-031-05563-8_14
Keywords Smudge attacks, Android pattern, User authentication, Shoulder surfing
Public URL https://uwe-repository.worktribe.com/output/8674865
Publisher URL https://link.springer.com/chapter/10.1007/978-3-031-05563-8_14
Related Public URLs https://link.springer.com/book/10.1007/978-3-031-05563-8

https://link.springer.com/conference/hcii

https://www.springer.com/series/558

Files




You might also like



Downloadable Citations