Keynote

A Shoulder-Surfing-Resistant Graphical Authentication Scheme for Networked Information Systems

Prof. Por Lip Yee
Prof. Por Lip Yee
Prof. Por Lip Yee

Prof. Por Lip Yee, Professor at CSNET, Universiti Malaya.

Prof. Por Lip Yee was invited as a Keynote Speaker at the 5th International Conference on Big Data, Information and Computer Network (BDICN 2026), where he delivered new research on graphical authentication. His keynote, titled "A Shoulder-Surfing-Resistant Graphical Authentication Scheme for Networked Information Systems", addresses a persistent vulnerability in knowledge-based authentication systems used across modern networked environments.

The Problem with Graphical Passwords

Authentication remains one of the most critical challenges in securing networked information systems. Graphical passwords are generally easier to remember than complex alphanumeric sequences, which helps reduce the well-documented burden of password fatigue. However, many existing graphical schemes are susceptible to shoulder-surfing attacks, where an attacker observes or records a user's login gestures to deduce their credentials. This threat is especially significant in public or shared environments such as hospital workstations, financial terminals, and educational portals, where users must authenticate frequently under conditions that cannot always guarantee visual privacy.

The Proposed Scheme

The scheme introduced in this paper addresses the observation-based threat through two principal mechanisms. First, randomized graphical challenges ensure that each login session presents a visually distinct interface, preventing an attacker from mapping observed interactions to a fixed credential pattern across multiple sessions. Second, a lightweight computation layer processes the user's input in a manner that decouples visible authentication gestures from the underlying secret, so that a complete observation of a successful login still yields no exploitable information to the attacker.

Evaluation and Results

Security and usability were evaluated through a structured user study covering three distinct threat models: direct visual observation, video-recorded replay attacks, and multiple-observation correlation attacks. The scheme demonstrated strong resistance across all three scenarios. On the usability side, participants achieved an average improvement of approximately 18% in authentication speed compared to selected benchmark methods, demonstrating that enhanced security does not require a corresponding sacrifice in user efficiency.

Target Applications

The work identifies healthcare information systems, financial platforms, and educational networks as primary target domains, where sensitive data access must be both secure and frictionless for legitimate users. The scheme is designed with low computational overhead, making it suitable for integration with modern networked applications and a viable upgrade path for systems that currently rely on weaker authentication controls.

The paper was presented at BDICN 2026, the 5th International Conference on Big Data, Information and Computer Network.

Explore More from CSNET

Read more articles, research updates, and news from our team.