4.2 Article

On the Security of Smartphone Unlock PINs

期刊

出版社

ASSOC COMPUTING MACHINERY
DOI: 10.1145/3473040

关键词

Security; usability; authentication; PIN; blocklist; mobile; smartphone

资金

  1. the research training group Human Centered Systems Security - state of North Rhine-Westphalia, Germany
  2. Deutsche Forschungsgemeinschaft (DFG, German Research Foundation) under Germany's Excellence Strategy [EXC 2092 CASA -390781972]
  3. National Science Foundation [1845300]

向作者/读者索取更多资源

The study shows that using six-digit PINs does not significantly improve security over four-digit PINs against throttled attacks, and may even decrease security. The blocklists used by iOS for PIN selection have limited effectiveness for four-digit PINs, with larger blocklists showing better security gains.
In this article, we provide the first comprehensive study of user-chosen four- and six-digit PINs (n = 1705) collected on smartphones with participants being explicitly primed for device unlocking. We find that against a throttled attacker (with 10, 30, or 100 guesses, matching the smartphone unlock setting), using six-digit PINs instead of four-digit PINs provides little to no increase in security and surprisingly may even decrease security. We also study the effects of blocklists, where a set of easy to guess PINs is disallowed during selection. Two such blocklists are in use today by iOS, for four digits (274 PINs) as well as six digits (2,910 PINs). We extracted both blocklists and compared them with six other blocklists, three for each PIN length. In each case, we had a small (four-digit: 27 PINs; six-digit: 29 PINs), a large (four-digit: 2,740 PINs; six-digit: 291,000 PINs), and a placebo blocklist that always excluded the first-choice PIN. For four-digit PINs, we find that the relatively small blocklist in use today by iOS offers little to no benefit against a throttled guessing attack. Security gains are only observed when the blocklist is much larger. In the six-digit case, we were able to reach a similar security level with a smaller blocklist. As the user frustration increases with the blocklists size, developers should employ a blocklist that is as small as possible while ensuring the desired security. Based on our analysis, we recommend that for four-digit PINs a blocklist should contain the 1,000 most popular PINs to provide the best balance between usability and security and for six-digit PINs the 2,000 most popular PINs should be blocked.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.2
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据