CueAuth: Comparing Touch, Mid-Air Gestures, and Gaze for Cue-based Authentication on Situated Displays

Secure authentication on situated displays (e.g., to access sensitive information or to make purchases) is becoming increasingly important. A promising approach to resist shoulder surfing attacks is to employ cues that users respond to while authenticating; this overwhelms observers by requiring the...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Veröffentlicht in:Proceedings of ACM on interactive, mobile, wearable and ubiquitous technologies mobile, wearable and ubiquitous technologies, 2018-12, Vol.2 (4), p.1-22
Hauptverfasser: Khamis, Mohamed, Trotter, Ludwig, Mäkelä, Ville, Zezschwitz, Emanuel von, Le, Jens, Bulling, Andreas, Alt, Florian
Format: Artikel
Sprache:eng
Online-Zugang:Volltext
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
container_end_page 22
container_issue 4
container_start_page 1
container_title Proceedings of ACM on interactive, mobile, wearable and ubiquitous technologies
container_volume 2
creator Khamis, Mohamed
Trotter, Ludwig
Mäkelä, Ville
Zezschwitz, Emanuel von
Le, Jens
Bulling, Andreas
Alt, Florian
description Secure authentication on situated displays (e.g., to access sensitive information or to make purchases) is becoming increasingly important. A promising approach to resist shoulder surfing attacks is to employ cues that users respond to while authenticating; this overwhelms observers by requiring them to observe both the cue itself as well as users' response to the cue. Although previous work proposed a variety of modalities, such as gaze and mid-air gestures, to further improve security, an understanding of how they compare with regard to usability and security is still missing as of today. In this paper, we rigorously compare modalities for cue-based authentication on situated displays. In particular, we provide the first comparison between touch, mid-air gestures, and calibration-free gaze using a state-of-the-art authentication concept. In two in-depth user studies (N=20, N=17) we found that the choice of touch or gaze presents a clear tradeoff between usability and security. For example, while gaze input is more secure, it is also more demanding and requires longer authentication times. Mid-air gestures are slightly slower and more secure than touch but users hesitate to use them in public. We conclude with three significant design implications for authentication using touch, mid-air gestures, and gaze and discuss how the choice of modality creates opportunities and challenges for improved authentication in public.
doi_str_mv 10.1145/3287052
format Article
fullrecord <record><control><sourceid>crossref</sourceid><recordid>TN_cdi_crossref_primary_10_1145_3287052</recordid><sourceformat>XML</sourceformat><sourcesystem>PC</sourcesystem><sourcerecordid>10_1145_3287052</sourcerecordid><originalsourceid>FETCH-crossref_primary_10_1145_32870523</originalsourceid><addsrcrecordid>eNpjYOA3NNAzNDQx1Tc2sjA3MDViYuA0MjE30bU0NTNnQWJzMPAWF2cZGBgYWhobWxiYczKwO5emOpaWZPAwsKYl5hSn8kJpbgZ1N9cQZw_d5KL84uKi1LT4gqLM3MSiynhDg3iQVfFQq4yJVwkASCkqHg</addsrcrecordid><sourcetype>Aggregation Database</sourcetype><iscdi>true</iscdi><recordtype>article</recordtype></control><display><type>article</type><title>CueAuth: Comparing Touch, Mid-Air Gestures, and Gaze for Cue-based Authentication on Situated Displays</title><source>ACM Digital Library Complete</source><creator>Khamis, Mohamed ; Trotter, Ludwig ; Mäkelä, Ville ; Zezschwitz, Emanuel von ; Le, Jens ; Bulling, Andreas ; Alt, Florian</creator><creatorcontrib>Khamis, Mohamed ; Trotter, Ludwig ; Mäkelä, Ville ; Zezschwitz, Emanuel von ; Le, Jens ; Bulling, Andreas ; Alt, Florian</creatorcontrib><description>Secure authentication on situated displays (e.g., to access sensitive information or to make purchases) is becoming increasingly important. A promising approach to resist shoulder surfing attacks is to employ cues that users respond to while authenticating; this overwhelms observers by requiring them to observe both the cue itself as well as users' response to the cue. Although previous work proposed a variety of modalities, such as gaze and mid-air gestures, to further improve security, an understanding of how they compare with regard to usability and security is still missing as of today. In this paper, we rigorously compare modalities for cue-based authentication on situated displays. In particular, we provide the first comparison between touch, mid-air gestures, and calibration-free gaze using a state-of-the-art authentication concept. In two in-depth user studies (N=20, N=17) we found that the choice of touch or gaze presents a clear tradeoff between usability and security. For example, while gaze input is more secure, it is also more demanding and requires longer authentication times. Mid-air gestures are slightly slower and more secure than touch but users hesitate to use them in public. We conclude with three significant design implications for authentication using touch, mid-air gestures, and gaze and discuss how the choice of modality creates opportunities and challenges for improved authentication in public.</description><identifier>ISSN: 2474-9567</identifier><identifier>EISSN: 2474-9567</identifier><identifier>DOI: 10.1145/3287052</identifier><language>eng</language><ispartof>Proceedings of ACM on interactive, mobile, wearable and ubiquitous technologies, 2018-12, Vol.2 (4), p.1-22</ispartof><lds50>peer_reviewed</lds50><woscitedreferencessubscribed>false</woscitedreferencessubscribed><cites>FETCH-crossref_primary_10_1145_32870523</cites></display><links><openurl>$$Topenurl_article</openurl><openurlfulltext>$$Topenurlfull_article</openurlfulltext><thumbnail>$$Tsyndetics_thumb_exl</thumbnail><link.rule.ids>314,777,781,27905,27906</link.rule.ids></links><search><creatorcontrib>Khamis, Mohamed</creatorcontrib><creatorcontrib>Trotter, Ludwig</creatorcontrib><creatorcontrib>Mäkelä, Ville</creatorcontrib><creatorcontrib>Zezschwitz, Emanuel von</creatorcontrib><creatorcontrib>Le, Jens</creatorcontrib><creatorcontrib>Bulling, Andreas</creatorcontrib><creatorcontrib>Alt, Florian</creatorcontrib><title>CueAuth: Comparing Touch, Mid-Air Gestures, and Gaze for Cue-based Authentication on Situated Displays</title><title>Proceedings of ACM on interactive, mobile, wearable and ubiquitous technologies</title><description>Secure authentication on situated displays (e.g., to access sensitive information or to make purchases) is becoming increasingly important. A promising approach to resist shoulder surfing attacks is to employ cues that users respond to while authenticating; this overwhelms observers by requiring them to observe both the cue itself as well as users' response to the cue. Although previous work proposed a variety of modalities, such as gaze and mid-air gestures, to further improve security, an understanding of how they compare with regard to usability and security is still missing as of today. In this paper, we rigorously compare modalities for cue-based authentication on situated displays. In particular, we provide the first comparison between touch, mid-air gestures, and calibration-free gaze using a state-of-the-art authentication concept. In two in-depth user studies (N=20, N=17) we found that the choice of touch or gaze presents a clear tradeoff between usability and security. For example, while gaze input is more secure, it is also more demanding and requires longer authentication times. Mid-air gestures are slightly slower and more secure than touch but users hesitate to use them in public. We conclude with three significant design implications for authentication using touch, mid-air gestures, and gaze and discuss how the choice of modality creates opportunities and challenges for improved authentication in public.</description><issn>2474-9567</issn><issn>2474-9567</issn><fulltext>true</fulltext><rsrctype>article</rsrctype><creationdate>2018</creationdate><recordtype>article</recordtype><recordid>eNpjYOA3NNAzNDQx1Tc2sjA3MDViYuA0MjE30bU0NTNnQWJzMPAWF2cZGBgYWhobWxiYczKwO5emOpaWZPAwsKYl5hSn8kJpbgZ1N9cQZw_d5KL84uKi1LT4gqLM3MSiynhDg3iQVfFQq4yJVwkASCkqHg</recordid><startdate>20181227</startdate><enddate>20181227</enddate><creator>Khamis, Mohamed</creator><creator>Trotter, Ludwig</creator><creator>Mäkelä, Ville</creator><creator>Zezschwitz, Emanuel von</creator><creator>Le, Jens</creator><creator>Bulling, Andreas</creator><creator>Alt, Florian</creator><scope>AAYXX</scope><scope>CITATION</scope></search><sort><creationdate>20181227</creationdate><title>CueAuth</title><author>Khamis, Mohamed ; Trotter, Ludwig ; Mäkelä, Ville ; Zezschwitz, Emanuel von ; Le, Jens ; Bulling, Andreas ; Alt, Florian</author></sort><facets><frbrtype>5</frbrtype><frbrgroupid>cdi_FETCH-crossref_primary_10_1145_32870523</frbrgroupid><rsrctype>articles</rsrctype><prefilter>articles</prefilter><language>eng</language><creationdate>2018</creationdate><toplevel>peer_reviewed</toplevel><toplevel>online_resources</toplevel><creatorcontrib>Khamis, Mohamed</creatorcontrib><creatorcontrib>Trotter, Ludwig</creatorcontrib><creatorcontrib>Mäkelä, Ville</creatorcontrib><creatorcontrib>Zezschwitz, Emanuel von</creatorcontrib><creatorcontrib>Le, Jens</creatorcontrib><creatorcontrib>Bulling, Andreas</creatorcontrib><creatorcontrib>Alt, Florian</creatorcontrib><collection>CrossRef</collection><jtitle>Proceedings of ACM on interactive, mobile, wearable and ubiquitous technologies</jtitle></facets><delivery><delcategory>Remote Search Resource</delcategory><fulltext>fulltext</fulltext></delivery><addata><au>Khamis, Mohamed</au><au>Trotter, Ludwig</au><au>Mäkelä, Ville</au><au>Zezschwitz, Emanuel von</au><au>Le, Jens</au><au>Bulling, Andreas</au><au>Alt, Florian</au><format>journal</format><genre>article</genre><ristype>JOUR</ristype><atitle>CueAuth: Comparing Touch, Mid-Air Gestures, and Gaze for Cue-based Authentication on Situated Displays</atitle><jtitle>Proceedings of ACM on interactive, mobile, wearable and ubiquitous technologies</jtitle><date>2018-12-27</date><risdate>2018</risdate><volume>2</volume><issue>4</issue><spage>1</spage><epage>22</epage><pages>1-22</pages><issn>2474-9567</issn><eissn>2474-9567</eissn><abstract>Secure authentication on situated displays (e.g., to access sensitive information or to make purchases) is becoming increasingly important. A promising approach to resist shoulder surfing attacks is to employ cues that users respond to while authenticating; this overwhelms observers by requiring them to observe both the cue itself as well as users' response to the cue. Although previous work proposed a variety of modalities, such as gaze and mid-air gestures, to further improve security, an understanding of how they compare with regard to usability and security is still missing as of today. In this paper, we rigorously compare modalities for cue-based authentication on situated displays. In particular, we provide the first comparison between touch, mid-air gestures, and calibration-free gaze using a state-of-the-art authentication concept. In two in-depth user studies (N=20, N=17) we found that the choice of touch or gaze presents a clear tradeoff between usability and security. For example, while gaze input is more secure, it is also more demanding and requires longer authentication times. Mid-air gestures are slightly slower and more secure than touch but users hesitate to use them in public. We conclude with three significant design implications for authentication using touch, mid-air gestures, and gaze and discuss how the choice of modality creates opportunities and challenges for improved authentication in public.</abstract><doi>10.1145/3287052</doi></addata></record>
fulltext fulltext
identifier ISSN: 2474-9567
ispartof Proceedings of ACM on interactive, mobile, wearable and ubiquitous technologies, 2018-12, Vol.2 (4), p.1-22
issn 2474-9567
2474-9567
language eng
recordid cdi_crossref_primary_10_1145_3287052
source ACM Digital Library Complete
title CueAuth: Comparing Touch, Mid-Air Gestures, and Gaze for Cue-based Authentication on Situated Displays
url https://sfx.bib-bvb.de/sfx_tum?ctx_ver=Z39.88-2004&ctx_enc=info:ofi/enc:UTF-8&ctx_tim=2025-01-17T20%3A59%3A51IST&url_ver=Z39.88-2004&url_ctx_fmt=infofi/fmt:kev:mtx:ctx&rfr_id=info:sid/primo.exlibrisgroup.com:primo3-Article-crossref&rft_val_fmt=info:ofi/fmt:kev:mtx:journal&rft.genre=article&rft.atitle=CueAuth:%20Comparing%20Touch,%20Mid-Air%20Gestures,%20and%20Gaze%20for%20Cue-based%20Authentication%20on%20Situated%20Displays&rft.jtitle=Proceedings%20of%20ACM%20on%20interactive,%20mobile,%20wearable%20and%20ubiquitous%20technologies&rft.au=Khamis,%20Mohamed&rft.date=2018-12-27&rft.volume=2&rft.issue=4&rft.spage=1&rft.epage=22&rft.pages=1-22&rft.issn=2474-9567&rft.eissn=2474-9567&rft_id=info:doi/10.1145/3287052&rft_dat=%3Ccrossref%3E10_1145_3287052%3C/crossref%3E%3Curl%3E%3C/url%3E&disable_directlink=true&sfx.directlink=off&sfx.report_link=0&rft_id=info:oai/&rft_id=info:pmid/&rfr_iscdi=true