Shoulder-Surfing Resistant Authentication for Augmented Reality

Düzgün, Reyhan 1; Mayer, Peter ORCID iD icon 1; Volkamer, Melanie 1
1 Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB), Karlsruher Institut für Technologie (KIT)


Augmented Reality (AR) Head-Mounted Displays (HMD) are increasingly used in industry to digitize processes and enhance user experience by enabling real-time interaction with both physical and virtual objects. In this context, HMD provide access to sensitive data and applications which demand authenticating users before granting access. Furthermore, these devices are often used in shared spaces. Thus, shoulder-surfing attacks need to be addressed. As users can remember pictures more easily than text, we applied the recognition-based graphical password scheme “Things” from previous work on an AR HMD while placing the pictures for each authentication attempt in a random order. We implemented this scheme for the HMD Microsoft HoloLens and conducted a user study evaluating Things's usability. All participants could be successfully authenticated and the System Usability Scale (SUS) score is with 74 categorized as above average. We discuss as future work how to improve the SUS scores, e.g., by using different grid designs and input methods.

DOI: 10.5445/IR/1000150196
DOI: 10.1145/3546155.3546663
Zitationen: 4
Zugehörige Institution(en) am KIT Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB)
Kompetenzzentrum für angewandte Sicherheitstechnologie (KASTEL)
Publikationstyp Proceedingsbeitrag
Publikationsjahr 2022
Sprache Englisch
Identifikator ISBN: 978-1-4503-9699-8
KITopen-ID: 1000150196
HGF-Programm 46.23.01 (POF IV, LK 01) Methods for Engineering Secure Systems
Erschienen in Nordic Human Computer Interaction Conference (NordiCHI '22)
Veranstaltung Nordic Conference on Human-Computer Interaction (NordiCHI 2022), Århus, Dänemark, 10.10.2022 – 12.10.2022
Verlag ACM Digital Library
Seiten Art.Nr. 29
Schlagwörter Augmented Reality, Head-Mounted Displays, authentication, graphical passwords, usability evaluation
Nachgewiesen in Scopus
