Bu-Dash: a universal and dynamic graphical password scheme (extended version)

Panagiotis Andriotis*, Myles Kirby, Atsuhiro Takasu

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

64 Downloads (Pure)

Abstract

Passwordless authentication is a trending theme in cyber security, while biometrics gradually replace knowledge-based schemes. However, Personal Identification Numbers, passcodes, and graphical passwords are still considered as the primary means for authentication. Passwords must be memorable to be usable; therefore, users tend to choose easy to guess secrets, compromising security. The Android Pattern Unlock is a popular graphical password scheme that can be easily attacked by exploiting human behavioristic traits. Despite its vulnerabilities, the popularity of the scheme has led researchers to propose adjustments and variations that enhance security but maintain its familiar user interface. Nevertheless, prior work demonstrated that improving security while preserving usability remains frequently a hard task. In this paper we propose a novel graphical password scheme built on the foundations of the well-accepted Android Pattern Unlock method, which is usable, inclusive, universal, and robust against shoulder surfing and (basically) smudge attacks. Our scheme, named Bu-Dash, features a dynamic user interface that mutates every time a user swipes the screen. Our pilot studies illustrate that Bu-Dash attracts positive user acceptance rates, it is secure, and maintains high usability levels. We define complexity metrics that can be used to further diversify user input, and we conduct complexity and security assessments.
Original languageEnglish
JournalInternational Journal of Information Security
Early online date4 Dec 2022
DOIs
Publication statusE-pub ahead of print - 4 Dec 2022

Keywords

  • Usability
  • Acceptance study
  • User authentication
  • Mobile device
  • Complexity
  • Android
  • Pattern unlock
  • Usable security

Fingerprint

Dive into the research topics of 'Bu-Dash: a universal and dynamic graphical password scheme (extended version)'. Together they form a unique fingerprint.

Cite this