A systematic review of graphical password methods resistant to shoulder-surfing attacks

Farid Binbeshr*, Khaw Chee Siong, Lip Yee Por, Muhammad Imam, Alawi A. Al-Saggaf, Anas A. Abudaqa

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

1 Scopus citations

Abstract

Graphical passwords have emerged as an alternative to traditional alphanumeric passwords, offering potentially better memorability. However, they are often vulnerable to shoulder-surfing attacks, where attackers observe users entering their credentials. This Systematic Literature Review (SLR) addresses this critical gap by comprehensively analyzing existing graphical password methods resistant to shoulder-surfing attacks. A review protocol was developed to systematically search, conduct, and report the SLR. Two authors searched six databases and extracted the data from 183 articles. The review sheds light on effective graphical password methods resistant to shoulder-surfing attacks, evaluation methods used to evaluate these methods, and challenges hindering the adoption of graphical passwords as the mainstream authentication method. By synthesizing existing research, this SLR serves as a guide for future investigations and contributes to the development of more secure authentication methods.

Original languageEnglish
Article number46
JournalInternational Journal of Information Security
Volume24
Issue number1
DOIs
StatePublished - Feb 2025

Bibliographical note

Publisher Copyright:
© The Author(s), under exclusive licence to Springer-Verlag GmbH Germany, part of Springer Nature 2024.

Keywords

  • Authentication
  • Graphical password
  • Shoulder surfing
  • Systematic literature review
  • security

ASJC Scopus subject areas

  • Software
  • Information Systems
  • Safety, Risk, Reliability and Quality
  • Computer Networks and Communications

Fingerprint

Dive into the research topics of 'A systematic review of graphical password methods resistant to shoulder-surfing attacks'. Together they form a unique fingerprint.

Cite this