|
ABSTRACT
Users gain access to cash, confidential information and services at Automated Teller Machines (ATMs) via an authentication process involving a Personal Identification Number (PIN). These users frequently have many different PINs, and fail to remember them without recourse to insecure behaviours. This is not a failing of users. It is a usability failing in the ATM authentication mechanism. This paper describes research executed to evaluate whether users find multiple graphical passwords more memorable than multiple PINs. The research also investigates the success of two memory augmentation strategies in increasing memorability of graphical passwords. The results demonstrate that multiple graphical passwords are substantially more effective than multiple PIN numbers. Memorability is further improved by the use of mnemonics to aid their recall.This study will be of interest to HCI practitioners and information security researchers exploring approaches to usable security.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
 |
1
|
|
| |
2
|
Brostoff, S., & Sasse, M. A. (2000). Are passfaces more usable than passwords? A field trial investigation. In Proc. HCI 2000.
|
| |
3
|
Brown, SC. & Park, D.C. (2003) Theoretical models of cognitive aging and implications for translational research in medicine. Gerontologist, 43(1), 57--67.
|
 |
4
|
|
| |
5
|
|
| |
6
|
|
| |
7
|
Frøkjær, E. & Hornbææk, K. (2002). Metaphors of Human Thinking in HCI: Habit, Stream of Thought, Awareness, Utterance, and Knowing. In Proc. HF2002/OzCHI 2002.
|
 |
8
|
|
 |
9
|
|
| |
10
|
Ian Jermyn , Alain Mayer , Fabian Monrose , Michael K. Reiter , Aviel D. Rubin, The design and analysis of graphical passwords, Proceedings of the 8th conference on USENIX Security Symposium, p.1-1, August 23-26, 1999, Washington, D.C.
|
 |
11
|
|
| |
12
|
Renaud, K., & De Angeli, A. (2004). My password is here! An investigation into visuo-spatial authentication mechanisms. Interacting with computers, 16(2004), 1017--1041.
|
| |
13
|
Renaud, K., & Smith, E. (2001). Jiminy: helping users to remember their passwords. In Proc. SAICSIT Annual Conference.
|
| |
14
|
|
 |
15
|
|
| |
16
|
|
 |
17
|
|
 |
18
|
|
 |
19
|
Susan Wiedenbeck , Jim Waters , Jean-Camille Birget , Alex Brodskiy , Nasir Memon, Authentication using graphical passwords: effects of tolerance and image choice, Proceedings of the 2005 symposium on Usable privacy and security, p.1-12, July 06-08, 2005, Pittsburgh, Pennsylvania
[doi> 10.1145/1073001.1073002]
|
| |
20
|
|
| |
21
|
Yan, J., Blackwell, A., Anderson, R., & Grant, A. (2001). The memorability and security of passwords -- Some empirical results. (Technical report No. 500). Cambridge: Cambridge University Computer Laboratory.
|
CITED BY 9
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Katherine M. Everitt , Tanya Bragin , James Fogarty , Tadayoshi Kohno, A comprehensive study of frequency, interference, and training of multiple graphical passwords, Proceedings of the 27th international conference on Human factors in computing systems, April 04-09, 2009, Boston, MA, USA
|
|
|
|
INDEX TERMS
Primary Classification:
H.
Information Systems
H.5
INFORMATION INTERFACES AND PRESENTATION (I.7)
H.5.2
User Interfaces (D.2.2, H.1.2, I.3.6)
Subjects:
Interaction styles (e.g., commands, menus, forms, direct manipulation)
Additional Classification:
H.
Information Systems
H.5
INFORMATION INTERFACES AND PRESENTATION (I.7)
H.5.2
User Interfaces (D.2.2, H.1.2, I.3.6)
Subjects:
User-centered design;
Graphical user interfaces (GUI);
Screen design (e.g., text, graphics, color)
K.
Computing Milieux
K.6
MANAGEMENT OF COMPUTING AND INFORMATION SYSTEMS
K.6.5
Security and Protection (D.4.6, K.4.2)
Subjects:
Authentication
General Terms:
Human Factors,
Security
Keywords:
ATMs,
authentication mechanisms,
graphical passwords,
usable security,
user authentication
|