On the Security and Usability of Segment-based Visual Cryptographic Authentication Protocols
Tianhao Wang, Huangyi Ge, Omar Chowdhury, Hemanta K. Maji, Ninghui Li
Abstract
Visual cryptography has been applied to design human computable authentication protocols. In such a protocol, the user and the server share a secret key in the form of an image printed on a transparent medium, which the user superimposes on server-generated image challenges, and visually decodes a response code from the image. An example of such protocols is PassWindow, an award-winning commercial product. We study the security and usability of segmentbased visual cryptographic authentication protocols (SVAPs), which include PassWindow as a particular case. In an SVAP, the images consist of segments and are thus structured. Our overall findings are negative. We introduce two attacks that together can break all SVAPs we considered in the paper. Moreover, our attacks exploit fundamental weaknesses of SVAPs that appear difficult to fix. We have also evaluated the usability of different SVAPs and found that the protocol that offers the best security has the poorest usability.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5ee25ecf-f697-4cb3-b6ca-20de3996589fRelated papers
- Transient Authentication from First-Person-View VideoLe Ngu Nguyen, Rainhard Dieter Findling, Maija Poikela, Si Zuo et al.UbiComp 2025
- PassWalk: Spatial Authentication Leveraging Lateral Shift and Gaze on Mobile HeadsetsAbhishek Kumar, Lik-Hang Lee, Jagmohan Chauhan, Xiang Su et al.ACM MM 2022 · 16 citations
- Better, Funner, Stronger: A Gameful Approach to Nudge People into Making Less Predictable Graphical Password ChoicesGeorge E. Raptis, Christina P. Katsini, Andrew Jian-lan Cen, Nalin Asanka Gamagedara Arachchilage et al.CHI 2021 · 28 citations
- Multi-Stage Group Key Distribution and PAKEs: Securing Zoom Groups against Malicious Servers without New Security ElementsCas Cremers, Eyal Ronen, Mang ZhaoS&P 2024 · 2 citations
- May the Force Not Be With You: Brute-Force Resistant Biometric Authentication and Key ReconstructionAlexandra Boldyreva, Deep Inder Mohan, Tianxin TangCCS 2025
