Composition policies for gesture passwords: User choice, security, usability and memorability

dc.contributorAalto-yliopistofi
dc.contributorAalto Universityen
dc.contributor.authorClark, Gradeighen_US
dc.contributor.authorLindqvist, Janneen_US
dc.contributor.authorOulasvirta, Anttien_US
dc.contributor.departmentDepartment of Communications and Networkingen
dc.contributor.groupauthorHelsinki Institute for Information Technology (HIIT)en
dc.contributor.groupauthorUser Interfacesen
dc.contributor.organizationRutgers, The State University of New Jerseyen_US
dc.date.accessioned2018-03-16T10:31:11Z
dc.date.available2018-03-16T10:31:11Z
dc.date.issued2017en_US
dc.description.abstractResearch on gesture passwords suggest they are highly usable and secure, leading them to be proposed as a strong alternative authentication method for touchscreen devices. However, studies demonstrate that user-chosen gesture passwords are biased towards familiar symbols, increasing the risk of guessing. Prior work on gesture elicitation focuses on creating sets with high overlap, but gesture passwords require solving an inverse problem: minimal overlap between different users. We present the results of the first study (N = 128) of composition policies for gesture passwords, wherein we compare four policies derived from unique properties of gesture passwords. Our main result is that implementing a policy changes user choice, security, usability, and memorability compared to a control group and that the strength of those changes depend on the policies. We report trade-offs among the instruction policies while showing that simple policies cause users to choose stronger and diverse gesture passwords.en
dc.description.versionPeer revieweden
dc.format.extent9
dc.format.mimetypeapplication/pdfen_US
dc.identifier.citationClark, G, Lindqvist, J & Oulasvirta, A 2017, Composition policies for gesture passwords: User choice, security, usability and memorability. in 2017 IEEE Conference on Communications and Network Security (CNS). IEEE Conference on Communications and Network Security, IEEE, IEEE Conference on Communications and Network Security, Las Vegas, Nevada, United States, 09/10/2017. https://doi.org/10.1109/CNS.2017.8228644en
dc.identifier.doi10.1109/CNS.2017.8228644en_US
dc.identifier.isbn978-1-5386-0684-1
dc.identifier.isbn978-1-5386-0683-4
dc.identifier.issn2474-025X
dc.identifier.otherPURE UUID: 0b2356c6-c181-4f34-8eb3-7ad35101f8d1en_US
dc.identifier.otherPURE ITEMURL: https://research.aalto.fi/en/publications/0b2356c6-c181-4f34-8eb3-7ad35101f8d1en_US
dc.identifier.otherPURE FILEURL: https://research.aalto.fi/files/17418533/oulasvirta_et_al_CNS17_gesturepolicies.pdfen_US
dc.identifier.urihttps://aaltodoc.aalto.fi/handle/123456789/30245
dc.identifier.urnURN:NBN:fi:aalto-201803161715
dc.language.isoenen
dc.relation.ispartofIEEE Conference on Communications and Network Securityen
dc.relation.ispartofseries2017 IEEE Conference on Communications and Network Security (CNS)en
dc.relation.ispartofseriesIEEE Conference on Communications and Network Securityen
dc.rightsopenAccessen
dc.titleComposition policies for gesture passwords: User choice, security, usability and memorabilityen
dc.typeA4 Artikkeli konferenssijulkaisussafi
dc.type.versionacceptedVersion

Files