PIN Scrambler: Assessing the Impact of Randomised Layouts on the Usability and Security of PINs

Kirkwood, D., Tombul, C., Firth, C., MacDonald, F., Priftis, K., Mathis, F., Khamis, M. and Marky, K. (2022) PIN Scrambler: Assessing the Impact of Randomised Layouts on the Usability and Security of PINs. In: 21st International Conference on Mobile and Ubiquitous Multimedia (MUM 2022), Lisbon, Portugal, 27-30 Nov 2022, pp. 83-88. ISBN 9781450398206 (doi: 10.1145/3568444.3568450)

[img] Text
282931.pdf - Accepted Version
Available under License Creative Commons Attribution.

1MB

Abstract

Randomizing the layout of the keypad has been proposed to improve the security of PIN entry. However, there has been no empirical quantification of its impact on usability and security. We present the first usability (N=17) and security (N=24) evaluations to compare PIN entry with the standard vs randomized layout. Our results show that randomizing the layout increases resistance to shoulder surfing and thermal attacks significantly, and has a very minor impact on entry accuracy, but it increases entry time (from ≈ 1.4 seconds to ≈ 2 seconds). We discuss how this simple approach can improve security with little impact on usability.

Item Type:Conference Proceedings
Status:Published
Refereed:Yes
Glasgow Author(s) Enlighten ID:Marky, Dr Karola and Mathis, Mr Florian and Khamis, Dr Mohamed
Authors: Kirkwood, D., Tombul, C., Firth, C., MacDonald, F., Priftis, K., Mathis, F., Khamis, M., and Marky, K.
College/School:College of Science and Engineering > School of Computing Science
ISBN:9781450398206
Copyright Holders:Copyright © 2022 The Authors
First Published:First published in 21st International Conference on Mobile and Ubiquitous Multimedia (MUM 2022): 83-88
Publisher Policy:Reproduced in accordance with the publisher copyright policy

University Staff: Request a correction | Enlighten Editors: Update this record

Project CodeAward NoProject NamePrincipal InvestigatorFunder's NameFunder RefLead Dept
310627TAPS: Assessing, Mitigating and Raising Awareness of the Security and Privacy Risks of Thermal ImagingMohamed KhamisEngineering and Physical Sciences Research Council (EPSRC)EP/V008870/1Computing Science