Sciweavers

CHI
2009
ACM

Vibrapass: secure authentication based on shared lies

14 years 6 months ago
Vibrapass: secure authentication based on shared lies
Authentication in public spaces is a risky task. Frauds on cash machines (ATMs) are not uncommon nowadays. The biggest group of attacks is observation attacks, which focus on recording the input done by the users. In this work, we present VibraPass, a system created to be resilient against observation attacks using tactile feedback provided by the users’ own mobile devices. In this way, secret information is shared between the terminal and the users to add an overhead of ‘lies’ to the input which makes it hard for attackers to steal the real PIN or password. We present an evaluation, which shows that VibraPass has the potential to replace current authentication systems due to increased security combined with reasonable input speed and error rates. Author Keywords Security, Public Terminals, Authentication, Lie Input ACM Classification Keywords H5.2. Information interfaces and presentation (e.g., HCI): User Interfaces-Input devices and strategies, evaluation.
Alexander De Luca, Emanuel von Zezschwitz, Heinric
Added 19 May 2010
Updated 19 May 2010
Type Conference
Year 2009
Where CHI
Authors Alexander De Luca, Emanuel von Zezschwitz, Heinrich Hußmann
Comments (0)