RubikAuth: Fast and Secure Authentication in Virtual Reality


연구 분야: Analysis



학회: CHI EA '20: Extended Abstracts of the 2020 CHI Conference on Human Factors in Computing Systems


초록

There is a growing need for usable and secure authentication in virtual reality (VR). Established concepts (e.g., 2D graphical PINs) are vulnerable to observation attacks, and proposed alternatives are relatively slow. We present RubikAuth, a novel authentication scheme for VR where users authenticate quickly by selecting digits from a virtual 3D cube that is manipulated with a handheld controller. We report two studies comparing how pointing using gaze, head pose, and controller tapping impacts RubikAuth's usability and observation resistance under three realistic threat models. Entering a four-symbol RubikAuth password is fast: 1.69 s to 3.5 s using controller tapping, 2.35 s to 4.68 s using head pose, and 2.39 s to 4.92 s using gaze and highly resilient to observations; 97.78% to 100% of observation attacks were unsuccessful. Our results suggest that providing attackers with support material contributes to more realistic security evaluations.


Author Profile
Florian Mathis

University of Glasgow Glasgow United Kingdom

United Kingdom
Author Profile
John H Williamson

University of Glasgow Glasgow United Kingdom

United Kingdom
Author Profile
Kami Vaniea

University of Edinburgh Edinburgh United Kingdom

United Kingdom

📄 논문 정보

발행 연도 2020년
인용수 51
출판 국가 United Kingdom
사이트 ACM
좋아요 수 0

연관 논문 목록 (434건)