Dr Panos Andriotis Panagiotis.Andriotis@uwe.ac.uk
Senior Lecturer in Computer Forensics and Security
Dr Panos Andriotis Panagiotis.Andriotis@uwe.ac.uk
Senior Lecturer in Computer Forensics and Security
Myles Kirby
Atsuhiro Takasu
Abbas Moallem
Editor
Biometric authentication gradually replaces knowledge-based methods on mobile devices. However, Personal Identification Numbers, passcodes, and graphical password schemes such as the Android Pattern Unlock (APU) are often the primary means for authentication, or they constitute an auxiliary (or backup) method to be used in case biometrics fail. Passcodes need to be memorable to be usable, hence users tend to choose easy to guess passwords, compromising security. The APU is a great example of a popular and usable graphical password scheme which can be easily compromised, by exploiting common and predominant human behavioristic traits. Despite its vulnerabilities, the scheme’s popularity has led researchers to propose adjustments and variations that enhance security but maintain its familiar user interface. Nevertheless, prior work demonstrated that improving security while preserving usability remains frequently a hard task. In this paper we propose a novel graphical password scheme built on the foundations of the well-accepted APU method, which is usable, inclusive, universal, and robust against shoulder surfing and smudge attacks. Our scheme, named Bu-Dash, features a dynamic user interface that mutates every time a user swipes the screen. Our pilot studies illustrate that Bu-Dash attracts positive user acceptance rates and maintains acceptable usability levels.
Presentation Conference Type | Conference Paper (published) |
---|---|
Conference Name | HCI International 2022 |
Start Date | Jun 26, 2022 |
End Date | Jul 1, 2022 |
Acceptance Date | Dec 14, 2021 |
Online Publication Date | Jun 16, 2022 |
Publication Date | Jun 16, 2022 |
Deposit Date | Jan 24, 2022 |
Publicly Available Date | Jun 17, 2023 |
Publisher | Springer Verlag |
Volume | 13333 LNCS |
Pages | 209-227 |
Series Title | Lecture Notes in Computer Science (LNCS, volume 13333) |
Series ISSN | 0302-9743; 1611-3349 |
Book Title | HCI for Cybersecurity, Privacy and Trust: 4th International Conference, HCI-CPT 2022, Held as Part of the 24th HCI International Conference, HCII 2022, Virtual Event, June 26 – July 1, 2022, Proceedings |
Chapter Number | 14 |
ISBN | 978-3-031-05562-1 |
DOI | https://doi.org/10.1007/978-3-031-05563-8_14 |
Keywords | Smudge attacks, Android pattern, User authentication, Shoulder surfing |
Public URL | https://uwe-repository.worktribe.com/output/8674865 |
Publisher URL | https://link.springer.com/chapter/10.1007/978-3-031-05563-8_14 |
Related Public URLs | https://link.springer.com/book/10.1007/978-3-031-05563-8 https://link.springer.com/conference/hcii https://www.springer.com/series/558 |
Bu-Dash: A universal and dynamic graphical password scheme
(389 Kb)
PDF
Licence
http://www.rioxx.net/licenses/all-rights-reserved
Publisher Licence URL
http://www.rioxx.net/licenses/all-rights-reserved
Copyright Statement
This is the author's accepted manuscript. The final published version is available here: URL
Smartphone message sentiment analysis
(2014)
Book Chapter
Studying users’ adaptation to Android's run-time fine-grained access control system
(2018)
Journal Article
Multilevel visualization using enhanced social network analysis with smartphone data
(2013)
Journal Article
About UWE Bristol Research Repository
Administrator e-mail: repository@uwe.ac.uk
This application uses the following open-source libraries:
Apache License Version 2.0 (http://www.apache.org/licenses/)
Apache License Version 2.0 (http://www.apache.org/licenses/)
SIL OFL 1.1 (http://scripts.sil.org/OFL)
MIT License (http://opensource.org/licenses/mit-license.html)
CC BY 3.0 ( http://creativecommons.org/licenses/by/3.0/)
Powered by Worktribe © 2025
Advanced Search