Visual authentication
Luis Roalter, Matthias Kranz, Andreas Möller, Stefan Diewald, Tobias Stockinger, Marion Koelle, Patrick Lindemann · 2013
User authentication on publicly exposed terminals with established mechanisms, such as typing the credentials on a virtual keyboard, can be insecure e.g. due to shoulder surfing or due to a hacked terminal. In addition, username and password entry can be time-consuming and thus improvable with relation to usability. As security and comfort are often competing with each other, novel authentication and authorization methods especially for public terminals are desirable. In this paper, we present an approach on a distributed authentication and authorization system, where the user can be easily identified and enabled to use a service with his smartphone. The smartphone (as personal and private device the user is always in control of) can provide a highly secure authentication token that is renewed and exchanged in the background without the user's participation. The claimed improvements were supported by a user survey with an implementation of a digital room management system as an example for a public display. The proposed authentication procedure would increase security and yet enable fast authentication within publicly exposed terminals.