TY - GEN
T1 - On the security and usability of segment-based visual cryptographic authentication protocols
AU - Wang, Tianhao
AU - Ge, Huangyi
AU - Chowdhury, Omar
AU - Maji, Hemanta K.
AU - Li, Ninghui
N1 - Publisher Copyright:
© 2016 ACM.
PY - 2016/10/24
Y1 - 2016/10/24
N2 - Visual cryptography has been applied to design human computable authentication protocols. In such a protocol, the user and the server share a secret key in the form of an image printed on a transparent medium, which the user superimposes on server-generated image challenges, and visually decodes a response code from the image. An example of such protocols is PassWindow, an award-winning commercial product. We study the security and usability of segmentbased visual cryptographic authentication protocols (SVAPs), which include PassWindow as a particular case. In an SVAP, the images consist of segments and are thus structured. Our overall findings are negative. We introduce two attacks that together can break all SVAPs we considered in the paper. Moreover, our attacks exploit fundamental weaknesses of SVAPs that appear difficult to fix. We have also evaluated the usability of different SVAPs and found that the protocol that offers the best security has the poorest usability.
AB - Visual cryptography has been applied to design human computable authentication protocols. In such a protocol, the user and the server share a secret key in the form of an image printed on a transparent medium, which the user superimposes on server-generated image challenges, and visually decodes a response code from the image. An example of such protocols is PassWindow, an award-winning commercial product. We study the security and usability of segmentbased visual cryptographic authentication protocols (SVAPs), which include PassWindow as a particular case. In an SVAP, the images consist of segments and are thus structured. Our overall findings are negative. We introduce two attacks that together can break all SVAPs we considered in the paper. Moreover, our attacks exploit fundamental weaknesses of SVAPs that appear difficult to fix. We have also evaluated the usability of different SVAPs and found that the protocol that offers the best security has the poorest usability.
KW - Attack
KW - User authentication
KW - Visual cryptography
UR - https://www.scopus.com/pages/publications/84995402675
U2 - 10.1145/2976749.2978417
DO - 10.1145/2976749.2978417
M3 - Conference contribution
AN - SCOPUS:84995402675
T3 - Proceedings of the ACM Conference on Computer and Communications Security
SP - 603
EP - 615
BT - CCS 2016 - Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security
PB - Association for Computing Machinery
T2 - 23rd ACM Conference on Computer and Communications Security, CCS 2016
Y2 - 24 October 2016 through 28 October 2016
ER -