EconPapers    
Economics at your fingertips  
 

PassNum: A usable and secure method against repeated shoulder surfing

Awais Ahmad, Muhammad Asif, Isma Hamid and Hanan Aljuaid

Behaviour and Information Technology, 2025, vol. 44, issue 17, 4220-4246

Abstract: Conventional PIN and password methods failed to be resilient against observational attacks. In the wake of usable security, this gap is filled with enormous proposals of graphical passwords that claim to be resistant but sacrifice the usability concerns in the shape of other afflictions (second device ‘phone/PC’, headset, vibration motor, weird hand motions). In comparison, we propose PassNum, a grid-based usable, deployable, and secure graphical PIN authentication method (GPA) in the replacement (for every device) of conventional PIN. It is low-cost, user-friendly (child vs. old), secure (high entropy), and has a compatible design for low-sensitive (social sites) to more sensitive (banking apps). Through extensive experiments with 32 participants, PassNum achieved 98% accuracy with 10 s login time (average scores) and 100% memorability (cumulative scores). Furthermore, the 4th variation of PassNum proves to be 100% resilient against even recurring (3 repeated login sessions) recorded shoulder surfing attacks. Our qualitative survey revealed that PassNum might be the prime replacement for conventional PIN and password methods.

Date: 2025
References: Add references at CitEc
Citations:

Downloads: (external link)
http://hdl.handle.net/10.1080/0144929X.2025.2469665 (text/html)
Access to full text is restricted to subscribers.

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:taf:tbitxx:v:44:y:2025:i:17:p:4220-4246

Ordering information: This journal article can be ordered from
http://www.tandfonline.com/pricing/journal/tbit20

DOI: 10.1080/0144929X.2025.2469665

Access Statistics for this article

Behaviour and Information Technology is currently edited by Dr Panos P Markopoulos

More articles in Behaviour and Information Technology from Taylor & Francis Journals
Bibliographic data for series maintained by Chris Longhurst ().

 
Page updated 2025-11-05
Handle: RePEc:taf:tbitxx:v:44:y:2025:i:17:p:4220-4246