Camouflage Text Download

0 views
Skip to first unread message

Carlee Panella

unread,
Jan 21, 2024, 3:42:52 AM1/21/24
to negalsearchmi

The user authentication is broadly categorized into three classes [2]: token-based authentication, which is based on something one has such as traditional keys to the doors; biometric-based authentication, which is based on a physiological or behavioral characteristic such as fingerprint and keystroke dynamic; knowledge-based authentication, which is based on something one knows such as text-based passwords. The use of text-based passwords is almost the popular method of the knowledge-based authentication class. However, a number of drawbacks of using text-based password have been raised; for example, a short text-based password can be easily guessed, while long passwords are often hard to remember [3]. To overcome this weakness, a graphical password has been proposed [4] as an alternative to the text-based password, where a user can remember pictures better than text.

camouflage text download


DOWNLOAD ✓✓✓ https://t.co/w2KQ1LZGJJ



Based on the proposed approach, three defensive techniques are designed and implemented for mobile devices. The first technique allows the user to specify the length of camouflage characters in which the activation and deactivation keys are reflected by a number of characters and have the same length. The second technique allows the user to specify the length of camouflage characters of both keys but with various lengths. The third technique allows the user to specify only one character as an activation key and another as a deactivation key. For testing these techniques, we developed an Android application. Then, we conducted an empirical experiment for evaluating the security and usability aspects. The accomplished results showed a statistical significance difference between the three defensive techniques. In particular, the third technique was the best in terms of security and usability aspects.

In terms of the convenience, Yan et al. [9] stated that many of the deficiencies of textual passwords arise from the limitations of human memory. Moreover, the usability and shoulder-surfing vulnerability of text-based password entry on mobile devices are investigated in [28]. This study provided a set of insights for the security-aware design of on-screen keyboards. Furthermore, evaluations of a number of mobile devices have been performed in [6]. A study by Florencio et al. [29] reported the results of a large-scale study of text-based password. These results include password strength and length of the chosen password. Furthermore, the password strength and user behavior are investigated in [30] using a large-scale study. Besides, the results of a user survey are discussed in [31] in which actual stories of shoulder surfing on mobile devices from both users and observers are investigated. Likewise, in 2019, a new approach to mask text passwords by distorting them by using graphical filters was proposed; that is, once the password is distorted, it can be difficult to be observed by attackers as they cannot mentally reverse the distortions [32]. Additionally, a hybrid scheme, which combines the advantage aspects of graphical-based and text-based methods, is proposed in [33]. Also, the characters of the text-based password are modified in [34] in order to provide higher entropy levels. A hybrid approach that exploits the advantages of textual and graphical passwords is introduced in [35]. A shoulder-surfing resistance scheme embedded in the textual password is proposed in [36]. The results of this study are promising in terms of both accuracy level and time.

A recent study by Pais et al. [11] introduced a camouflage pattern technique as a shoulder-surfing resistance approach for mobile devices. Despite the camouflage notion is applied in this study, it is implemented only on the pattern password method which is an alternative authentication approach for the password-based authentication scheme. Accordingly, applying camouflage notion on the password-based authentication might enhance its resistance against shoulder-surfing attacks.

The proposed approach in this paper, therefore, focuses on redefining the concept of alphanumeric passwords. What differentiates our approach is that the sequence of entries is not necessary. In fact, the main strength of this novel approach is that it deliberately marginalizes this sequencing requirement in passwords. Since, in the shared spaces such as tabletops, in one way or another, there is the trade-off between security and usability, and the proposed approach takes into account the compromise between the usability and security. Thus, the contributions of our paper are as follows: (1) introducing a camouflage text-based password approach for mobile devices against the shoulder-surfing attack; (2) based on this approach, three defensive techniques are designed, implemented, and empirically evaluated.

The camouflage text-based password approach basically redefines the traditional password concept where what you input is what you get. Specifically, the proposed approach uses two master keys: enable (i.e., the activation key) and disable (i.e., the deactivation key). The former enables entering the actual password, whereas the latter disables the actual password. Assigning these functions to keys adds another layer to the process of selecting a password. To enter a password, firstly, the user can enter any number of random Camouflage Characters (CC). Then, these camouflage characters are followed by an Activation Key (AK), and this activation key should be followed by the password. Finally, the user enters a Deactivation Key (DK) followed by any number of random CCs. Figure 1 summarizes this mechanism.

The initial version of this approach was established in [10]. In this paper, however, we extend this approach to be applicable for mobile devices by introducing three defensive techniques. The first technique allows the user to specify the same length of camouflage characters in which the activation and deactivation keys are reflected by a number of characters. The second technique allows the user to specify the length of camouflage characters of both keys but with various lengths. The third technique allows the user to specify only one character as an activation key and another as a deactivation key. In order to define precisely each one of these techniques, the following paragraphs explore these techniques, respectively. Figure 2 shows a screenshot from the first interface of the developed application.

As stated in [42], the password strength is a combination of length, complexity, and unpredictability. Therefore, in the proposed approach, the camouflage characters can generally give the illusion of added complexity and length to a chosen password, whereas the activation and deactivation keys can provide the unpredictability concept. This could have broad implications for a wide range of authentication contexts in general and password entry techniques in particular.

In particular, using the proposed approach showed a significant difference among the three proposed techniques; that is, the Type 3 showed the best in the usability experiment with short password entry times, high typing accuracy, and satisfaction. Moreover, this type also showed the best in the success rate of the shoulder surfer with 8.8% compared to 29.4% and 44.1% for types 1 and 2, respectively. It might be worth to note that no hidden factors are included in the proposed techniques, and for example, Bianchi et al. [6] proposed the audio and haptic feedback that can only be available to users, as it cannot be obtained by attackers. However, the proposed camouflage characters approach in general is a challenge for attackers, as shown in our experiments. Moreover, a diversification in using the proposed techniques, along with a better understanding of how they are used, reduces the possibility of deducing the real password. Furthermore, the possible key to gain the advantage of Type 3 may be its functionality, as shown in Table 1, that is, the activation and deactivation keys are independent from the camouflage characters and more importantly, each key has only one digit. Despite this advantage, there might be some cognitive load that needs to be exerted by the person inputting the password as they need to pay attention to which keys are assigned to which roles. However, this might not be a downside as much as a strong feature of the technique since every login now is unique.

Similarly, the impact of the screen size on the usability and security aspects [28] can be reflected by the achieved results. For example, the average time needed to enter the password in the HTC device was more than in the Tab device for all types, as shown in Figure 2. Furthermore, regardless of the defensive technique used, the screen size of the tablet device might have an effect on the vulnerability to the shoulder-surfing attack, as shown in Table 5. These results can support the results in [49]. The solution of this may be, additionally to use a defensive technique, increasing the attention of users while using devices with a large screen size. Although creating text-based passwords on mobile devices takes significantly longer [8], we believe that the proposed defensive techniques can be suggested as a way to easy password entry for mobile users. Moreover, the implications for the design of privacy protection mechanisms due to the shoulder-surfing attack in the real world have been investigated in [31]. Thus, the proposed defensive techniques can be a protection mechanism against this attack. Table 6 compares our results with most related works in terms of security and usability aspects.

The concept of alphanumeric passwords for mobile devices is redefined in this paper by proposing the camouflage character scheme. Based on this scheme, three defensive techniques are introduced. By using an Android platform, the introduced techniques are implemented. In order to evaluate the usability and security levels of the proposed approach, two experimental studies were conducted. The results of this evaluation showed that the Type 3 of the proposed defensive techniques demonstrated higher ratings in the usability experiments with short password entry times, high typing accuracy, and high scores on its satisfaction survey. In addition, the Type 3 proved also to be the best in resisting shoulder-surfing attacks. Moreover, the results obtained with the Type 3 show the possibility of choosing very short passwords, while insuring that the password remains hidden amongst a large number of key presses. This makes passwords tend to be very long without requiring any extra memory load.

df19127ead
Reply all
Reply to author
Forward
0 new messages