论文标题

双模式:提高Android解锁模式安全性的可用解决方案

Double Patterns: A Usable Solution to Increase the Security of Android Unlock Patterns

论文作者

Forman, Timothy J., Aviv, Adam J.

论文摘要

Android解锁模式仍然很普遍。我们的研究以及其他人都发现,在解锁手机时,大约有25%的受访者使用模式。尽管有已知的安全问题,但自首次启动以来,模式接口的设计仍保持不变。我们提出了双重图案,这是一种自然且易于采用的Android解锁图案,以维护核心设计功能,但没有选择单个图案,而是选择了两个同时的Android Unlock模式,输入了一个又一次的超级超级强制,并在同一3x3 Grid上。我们通过在三种治疗中进行$ n = 634 $的参与者进行在线研究来评估安全性和可用性的双重模式:对照治疗,第一个模式入口区块列表和两种模式的排名列表。我们发现,在所有设置中,用户选择的双重模式比基于标准猜测指标的传统模式更安全,更类似于4-/6位销钉,甚至对于模拟攻击者而言,更难猜测。用户对定性反馈表示积极的情感,尤其是那些目前(或以前)使用Android解锁模式的反馈,总体而言,参与者发现双模式界面非常可用,具有很高的召回率保留率,并且与传统模式相当。尤其是,目前的Android模式使用者(双重模式的目标人群)报告了第80个百分点的SUS分数以及对开放式和闭合问题的响应的安全性和可用性的高度看法。根据这些发现,我们建议将双重模式添加为Android模式的进步,就像允许增加销钉长度一样。

Android unlock patterns remain quite common. Our study, as well as others, finds that roughly 25\% of respondents use a pattern when unlocking their phone. Despite known security issues, the design of the pattern interface remains unchanged since first launch. We propose Double Patterns, a natural and easily adoptable advancement on Android unlock patterns that maintains the core design features, but instead of selecting a single pattern, a user selects two, concurrent Android unlock patterns entered one-after-the-other super-imposed on the same 3x3 grid. We evaluated Double Patterns for both security and usability by conducting an online study with $n=634$ participants in three treatments: a control treatment, a first pattern entry blocklist, and a blocklist for both patterns. We find that in all settings, user chosen Double Patterns are more secure than traditional patterns based on standard guessability metrics, more similar to that of 4-/6-digit PINs, and even more difficult to guess for a simulated attacker. Users express positive sentiments in qualitative feedback, particularly those who currently (or previously) used Android unlock patterns, and overall, participants found the Double Pattern interface quite usable, with high recall retention and comparable entry times to traditional patterns. In particular, current Android pattern users, the target population for Double Patterns, reported SUS scores in the 80th percentile and high perceptions of security and usability in responses to open- and closed-questions. Based on these findings, we would recommend adding Double Patterns as an advancement to Android patterns, much like allowing for added PIN length.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源