CueAuth: comparing touch, mid-air gestures, and gaze for cue-based authentication on situated displays

Khamis, M. , Trotter, L., Mäkelä, V., von Zezschwitz, E., Le, J., Bulling, A. and Alt, F. (2018) CueAuth: comparing touch, mid-air gestures, and gaze for cue-based authentication on situated displays. Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies, 2(4), 174. (doi: 10.1145/3287052)

[img]
Preview
Text
173105.pdf - Accepted Version

3MB

Abstract

Secure authentication on situated displays (e.g., to access sensitive information or to make purchases) is becoming increasingly important. A promising approach to resist shoulder surfing attacks is to employ cues that users respond to while authenticating; this overwhelms observers by requiring them to observe both the cue itself as well as users’ response to the cue. Although previous work proposed a variety of modalities, such as gaze and mid-air gestures, to further improve security, an understanding of how they compare with regard to usability and security is still missing as of today. In this paper, we rigorously compare modalities for cue-based authentication on situated displays. In particular, we provide the first comparison between touch, mid-air gestures, and calibration-free gaze using a state-of-the-art authentication concept. In two in-depth user studies (N=37) we found that the choice of touch or gaze presents a clear trade-off between usability and security. For example, while gaze input is more secure, it is also more demanding and requires longer authentication times. Mid-air gestures are slightly slower and more secure than touch but users hesitate to use them in public. We conclude with three significant design implications for authentication using touch, mid-air gestures, and gaze and discuss how the choice of modality creates opportunities and challenges for improved authentication in public.

Item Type:Articles
Status:Published
Refereed:Yes
Glasgow Author(s) Enlighten ID:Khamis, Dr Mohamed
Authors: Khamis, M., Trotter, L., Mäkelä, V., von Zezschwitz, E., Le, J., Bulling, A., and Alt, F.
College/School:College of Science and Engineering > School of Computing Science
Journal Name:Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies
Journal Abbr.:IMWUT
Publisher:Association for Computing Machinery
ISSN:2474-9567
ISSN (Online):2474-9567
Copyright Holders:Copyright © 2018 The Authors
First Published:First published in Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies 2(4):174
Publisher Policy:Reproduced in accordance with the copyright policy of the publisher

University Staff: Request a correction | Enlighten Editors: Update this record