IllusionPIN: Shoulder-Surfing Resistant Authentication Using Hybrid Images
Athanasios Papadopoulos, Toan Nguyen, Emre Durmus, Nasir Memon

TL;DR
IllusionPIN is a touchscreen authentication method that uses hybrid images to prevent shoulder-surfing attacks by making the keypad appear differently to nearby users and distant observers, enhancing security.
Contribution
The paper introduces IllusionPIN, a novel hybrid image-based PIN entry system that significantly improves resistance to shoulder-surfing and camera-based observation attacks.
Findings
None of the simulated attacks succeeded against the estimations.
The minimum distance for effective shoulder-surfing is significantly increased.
Camera capture of PINs is practically impossible with IllusionPIN.
Abstract
We address the problem of shoulder-surfing attacks on authentication schemes by proposing IllusionPIN (IPIN), a PIN-based authentication method that operates on touchscreen devices. IPIN uses the technique of hybrid images to blend two keypads with different digit orderings in such a way, that the user who is close to the device is seeing one keypad to enter her PIN, while the attacker who is looking at the device from a bigger distance is seeing only the other keypad. The user's keypad is shuffled in every authentication attempt since the attacker may memorize the spatial arrangement of the pressed digits. To reason about the security of IllusionPIN, we developed an algorithm which is based on human visual perception and estimates the minimum distance from which an observer is unable to interpret the keypad of the user. We tested our estimations with 84 simulated shoulder-surfing…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
