PassNum: A usable and secure method against repeated shoulder surfing
Awais Ahmad,
Muhammad Asif,
Isma Hamid and
Hanan Aljuaid
Behaviour and Information Technology, 2025, vol. 44, issue 17, 4220-4246
Abstract:
Conventional PIN and password methods failed to be resilient against observational attacks. In the wake of usable security, this gap is filled with enormous proposals of graphical passwords that claim to be resistant but sacrifice the usability concerns in the shape of other afflictions (second device ‘phone/PC’, headset, vibration motor, weird hand motions). In comparison, we propose PassNum, a grid-based usable, deployable, and secure graphical PIN authentication method (GPA) in the replacement (for every device) of conventional PIN. It is low-cost, user-friendly (child vs. old), secure (high entropy), and has a compatible design for low-sensitive (social sites) to more sensitive (banking apps). Through extensive experiments with 32 participants, PassNum achieved 98% accuracy with 10 s login time (average scores) and 100% memorability (cumulative scores). Furthermore, the 4th variation of PassNum proves to be 100% resilient against even recurring (3 repeated login sessions) recorded shoulder surfing attacks. Our qualitative survey revealed that PassNum might be the prime replacement for conventional PIN and password methods.
Date: 2025
References: Add references at CitEc
Citations:
Downloads: (external link)
http://hdl.handle.net/10.1080/0144929X.2025.2469665 (text/html)
Access to full text is restricted to subscribers.
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:taf:tbitxx:v:44:y:2025:i:17:p:4220-4246
Ordering information: This journal article can be ordered from
http://www.tandfonline.com/pricing/journal/tbit20
DOI: 10.1080/0144929X.2025.2469665
Access Statistics for this article
Behaviour and Information Technology is currently edited by Dr Panos P Markopoulos
More articles in Behaviour and Information Technology from Taylor & Francis Journals
Bibliographic data for series maintained by Chris Longhurst ().