Wan Tingjie, Zhang Liangyuting, Xu Yunxin, Guo Zixuan, Gao Boyu, Liang Hai-Ning
IEEE Trans Vis Comput Graph. 2024 Nov;30(11):7075-7085. doi: 10.1109/TVCG.2024.3456195. Epub 2024 Oct 10.
Authentication in digital security relies heavily on text-based passwords, even with other available methods like biometrics and graphical passwords. While virtual reality (VR) keyboards are typically invisible to onlookers, the presence of inconspicuous sensors, including accelerometers, gyroscopes, and barometers, poses a potential risk of unauthorized observation and recording. Traditional defense shoulder-surfing attack methods typically involve breaking apart the Qwerty layout, which destroys the user's inherent familiarity with the layout. This research addresses the need for secure password entry in VR environments while retaining the Qwerty layout. We explore three keyboard-related position alteration strategies to ensure security while mitigating the decline in user experience. These strategies involve moving the entire keyboard, cursor, and keys. Our theoretical study assesses the effectiveness of these strategies against shoulder-surfing attacks. Two user studies, employing ray-based and position-based text entry methods, respectively, evaluate the practical effectiveness of the three strategies in resisting shoulder-surfing attacks, as well as their impact on typing performance and user experience. Our findings demonstrate that the three strategies achieve shoulder-surfing attack resistance comparable to a random layout keyboard. Moreover, compared to a random layout, the two strategies involving the movement of the entire keyboard and the repositioning of keys support faster entry rates and enhanced user experience.
数字安全中的身份验证严重依赖基于文本的密码,即便还有生物识别和图形密码等其他可用方法。虽然虚拟现实(VR)键盘通常对旁观者不可见,但包括加速度计、陀螺仪和气压计在内的不显眼传感器的存在,带来了未经授权观察和记录的潜在风险。传统的防御肩窥攻击方法通常涉及拆解标准键盘布局,这会破坏用户对该布局的固有熟悉度。本研究满足了在VR环境中进行安全密码输入的需求,同时保留了标准键盘布局。我们探索了三种与键盘相关的位置改变策略,以确保安全性,同时减轻用户体验的下降。这些策略包括移动整个键盘、光标和按键。我们的理论研究评估了这些策略抵御肩窥攻击的有效性。两项用户研究分别采用基于射线和基于位置的文本输入方法,评估了这三种策略在抵御肩窥攻击方面的实际有效性,以及它们对打字性能和用户体验的影响。我们的研究结果表明,这三种策略实现了与随机布局键盘相当的抵御肩窥攻击能力。此外, 与随机布局相比,涉及移动整个键盘和重新定位按键的两种策略支持更快的输入速度并提升了用户体验。