Prevention of Shoulder-Surfing Attack Using Shifting Condition with the Digraph Substitution Rules

Authors

  • Amanul Islam Department of Computer Science and Information Technology, University of Malaya, Malaysia https://orcid.org/0000-0002-0366-895X
  • Fazidah Othman Department of Computer Science and Information Technology, University of Malaya, Malaysia
  • Nazmus Sakib Department of Computer Science and Engineering, Dhaka International University, Bangladesh https://orcid.org/0000-0001-9354-3095
  • Hafiz Md. Hasan Babu Department of Computer Science and Engineering, Dhaka University, Bangladesh

DOI:

https://doi.org/10.47852/bonviewAIA2202289

Keywords:

graphical password, authentication, shoulder-surfing, digraph substitution rules, shifting condition

Abstract

Graphical passwords are implemented as an alternative scheme to replace alphanumeric passwords to help users to memorize their password. However, most of the graphical password systems are vulnerable to shoulder-surfing attack due to the usage of the visual interface. In this research, a method that uses shifting condition with digraph substitution rules is proposed to address shoulder-surfing attack problem. The proposed algorithm uses both password images and decoy images throughout the user authentication procedure to confuse adversaries from obtaining the password images via direct observation or watching from a recorded session. The pass-images generated by this suggested algorithm are random and can only be generated if the algorithm is fully understood. As a result, adversaries will have no clue to obtain the right password images to log in. A user study was undertaken to assess the proposed method's effectiveness to avoid shoulder-surfing attacks. The results of the user study indicate that the proposed approach can withstand shoulder-surfing attacks (both direct observation and video recording method).The proposed method was tested and the results showed that it is able to resist shoulder-surfing and frequency of occurrence analysis attacks. Moreover, the experience gained in this research can be pervaded the gap on the realm of knowledge of the graphical password.

 

Received: 29 June 2022 | Revised: 10 November 2022 | Accepted: 14 November 2022 

 

Conflicts of Interest

The authors declare that they have no conflicts of interest to this work.

Metrics

Metrics Loading ...

Downloads

Published

2022-11-15

How to Cite

Islam, A., Othman, F., Sakib, N., & Babu, H. M. H. (2022). Prevention of Shoulder-Surfing Attack Using Shifting Condition with the Digraph Substitution Rules. Artificial Intelligence and Applications, 1(1), 58–68. https://doi.org/10.47852/bonviewAIA2202289

Issue

Section

Research Article