Fast and Secure Authentication in Virtual Reality Using Coordinated 3D Manipulation and Pointing

Author:

Mathis Florian1,Williamson John H.1,Vaniea Kami2,Khamis Mohamed1

Affiliation:

1. University of Glasgow, Glasgow, Scotland

2. University of Edinburgh, Edinburgh, Scotland

Abstract

There is a growing need for usable and secure authentication in immersive virtual reality (VR). Established concepts (e.g., 2D authentication schemes) are vulnerable to observation attacks, and most alternatives are relatively slow. We present RubikAuth, an authentication scheme for VR where users authenticate quickly and secure by selecting digits from a virtual 3D cube that leverages coordinated 3D manipulation and pointing. We report on results from three studies comparing how pointing using eye gaze, head pose, and controller tapping impact RubikAuth’s usability, memorability, and observation resistance under three realistic threat models. We found that entering a four-symbol RubikAuth password is fast: 1.69–3.5 s using controller tapping, 2.35–4.68 s using head pose and 2.39 –4.92 s using eye gaze, and highly resilient to observations: 96–99.55% of observation attacks were unsuccessful. RubikAuth also has a large theoretical password space: 45 n for an n -symbols password. Our work underlines the importance of considering novel but realistic threat models beyond standard one-time attacks to fully assess the observation-resistance of authentication schemes. We conclude with an in-depth discussion of authentication systems for VR and outline five learned lessons for designing and evaluating authentication schemes.

Funder

Royal Society of Edinburgh

University of Edinburgh and University of Glasgow Joint PhD Studentship

Publisher

Association for Computing Machinery (ACM)

Subject

Human-Computer Interaction

Cited by 39 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Privacy threats of behaviour identity detection in VR;Frontiers in Virtual Reality;2024-01-29

2. Usable Security: A Systematic Literature Review;Information;2023-11-30

3. 3DK-Reate: Create Your Own 3D Key for Distributed Authentication in the Metaverse;2023 IEEE Gaming, Entertainment, and Media Conference (GEM);2023-11-19

4. User Authentication Mechanisms Based on Immersive Technologies: A Systematic Review;Information;2023-10-02

5. Cybersecurity in the Metaverse: Challenges and Approaches;2023 International Conference on Intelligent Metaverse Technologies & Applications (iMETA);2023-09-18

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3