AuthZit: Personalized Visual-Spatial and Loci-Tagging Fallback Authentication

Joon Kuy Han, Dennis Wong, Zhoulai Fu, Byungkon Kang

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Designing a fallback authentication that is both memorable and strong poses a challenging task due to the need for authentication secrets to remain secure and easily recallable without frequent reinforcement. This could be especially prevalent for cloud computing security and resiliency. Inspired by the robust visual-spatial memory and associative memory of individuals, we introduce AuthZit, a novel system. AuthZit encodes authentication secrets as paths implementing a fault-tolerant algorithm through a 3D map of real-life places, navigated in both first person and 2D bird’s-eye perspective, coupled with a loci-tag (textual secret) associated with the location. Two experiments were conducted to iteratively design and evaluate AuthZit. First, it was observed that visual-spatial secrets are most memorable when navigated through a combination of 3D first-person and 2D bird’s-eye view perspectives. Second, we evaluated AuthZit against security questions and Android’s 9-dot pattern lock across three dimensions: memorability, security, and speed. AuthZit’s complexity-controlled secrets were significantly more memorable after three months, more resilient to shoulder surfing, and close adversaries.

Original languageEnglish
Title of host publicationProceedings - 2024 IEEE 29th Pacific Rim International Symposium on Dependable Computing, PRDC 2024
PublisherIEEE Computer Society
Pages120-130
Number of pages11
ISBN (Electronic)9798331540746
DOIs
Publication statusPublished - 2024
Event29th IEEE Pacific Rim International Symposium on Dependable Computing, PRDC 2024 - Osaka, Japan
Duration: 13 Nov 202415 Nov 2024

Publication series

NameProceedings of IEEE Pacific Rim International Symposium on Dependable Computing, PRDC
ISSN (Print)1541-0110

Conference

Conference29th IEEE Pacific Rim International Symposium on Dependable Computing, PRDC 2024
Country/TerritoryJapan
CityOsaka
Period13/11/2415/11/24

Fingerprint

Dive into the research topics of 'AuthZit: Personalized Visual-Spatial and Loci-Tagging Fallback Authentication'. Together they form a unique fingerprint.

Cite this