IDEAS home Printed from https://ideas.repec.org/a/taf/tbitxx/v44y2025i17p4220-4246.html
   My bibliography  Save this article

PassNum: A usable and secure method against repeated shoulder surfing

Author

Listed:
  • Awais Ahmad
  • Muhammad Asif
  • Isma Hamid
  • Hanan Aljuaid

Abstract

Conventional PIN and password methods failed to be resilient against observational attacks. In the wake of usable security, this gap is filled with enormous proposals of graphical passwords that claim to be resistant but sacrifice the usability concerns in the shape of other afflictions (second device ‘phone/PC’, headset, vibration motor, weird hand motions). In comparison, we propose PassNum, a grid-based usable, deployable, and secure graphical PIN authentication method (GPA) in the replacement (for every device) of conventional PIN. It is low-cost, user-friendly (child vs. old), secure (high entropy), and has a compatible design for low-sensitive (social sites) to more sensitive (banking apps). Through extensive experiments with 32 participants, PassNum achieved 98% accuracy with 10 s login time (average scores) and 100% memorability (cumulative scores). Furthermore, the 4th variation of PassNum proves to be 100% resilient against even recurring (3 repeated login sessions) recorded shoulder surfing attacks. Our qualitative survey revealed that PassNum might be the prime replacement for conventional PIN and password methods.

Suggested Citation

  • Awais Ahmad & Muhammad Asif & Isma Hamid & Hanan Aljuaid, 2025. "PassNum: A usable and secure method against repeated shoulder surfing," Behaviour and Information Technology, Taylor & Francis Journals, vol. 44(17), pages 4220-4246, October.
  • Handle: RePEc:taf:tbitxx:v:44:y:2025:i:17:p:4220-4246
    DOI: 10.1080/0144929X.2025.2469665
    as

    Download full text from publisher

    File URL: http://hdl.handle.net/10.1080/0144929X.2025.2469665
    Download Restriction: Access to full text is restricted to subscribers.

    File URL: https://libkey.io/10.1080/0144929X.2025.2469665?utm_source=ideas
    LibKey link: if access is restricted and if your library uses this service, LibKey will redirect you to where you can use your library subscription to access this item
    ---><---

    As the access to this document is restricted, you may want to

    for a different version of it.

    More about this item

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:taf:tbitxx:v:44:y:2025:i:17:p:4220-4246. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    We have no bibliographic references for this item. You can help adding them by using this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Chris Longhurst (email available below). General contact details of provider: http://www.tandfonline.com/tbit .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.