Title
Picture Gesture Authentication: Empirical Analysis, Automated Attacks, and Scheme Evaluation
Abstract
Picture gesture authentication has been recently introduced as an alternative login experience to text-based password on touch-screen devices. In particular, the newly on market Microsoft Windows 8™ operating system adopts such an alternative authentication to complement its traditional text-based authentication. We present an empirical analysis of picture gesture authentication on more than 10,000 picture passwords collected from more than 800 subjects through online user studies. Based on the findings of our user studies, we propose a novel attack framework that is capable of cracking passwords on previously unseen pictures in a picture gesture authentication system. Our approach is based on the concept of selection function that models users’ thought processes in selecting picture passwords. Our evaluation results show the proposed approach could crack a considerable portion of picture passwords under different settings. Based on the empirical analysis and attack results, we comparatively evaluate picture gesture authentication using a set of criteria for a better understanding of its advantages and limitations.
Year
DOI
Venue
2015
10.1145/2701423
ACM Trans. Inf. Syst. Secur.
Keywords
DocType
Volume
automated attacks,empirical analysis,picture gesture authentication,scheme evaluation,security,security and protection
Journal
17
Issue
ISSN
Citations 
4
1094-9224
9
PageRank 
References 
Authors
0.46
47
3
Name
Order
Citations
PageRank
Ziming Zhao132230.52
Gail-Joon Ahn23012203.39
Hongxin Hu3123082.32