{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T17:22:06Z","timestamp":1783099326917,"version":"3.54.6"},"reference-count":140,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2012,8,1]],"date-time":"2012-08-01T00:00:00Z","timestamp":1343779200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2012,8]]},"abstract":"<jats:p>Starting around 1999, a great many graphical password schemes have been proposed as alternatives to text-based password authentication. We provide a comprehensive overview of published research in the area, covering both usability and security aspects as well as system evaluation. The article first catalogues existing approaches, highlighting novel features of selected schemes and identifying key usability or security advantages. We then review usability requirements for knowledge-based authentication as they apply to graphical passwords, identify security threats that such systems must address and review known attacks, discuss methodological issues related to empirical evaluation, and identify areas for further research and improved methodology.<\/jats:p>","DOI":"10.1145\/2333112.2333114","type":"journal-article","created":{"date-parts":[[2012,9,11]],"date-time":"2012-09-11T22:21:06Z","timestamp":1347402066000},"page":"1-41","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":358,"title":["Graphical passwords"],"prefix":"10.1145","volume":"44","author":[{"given":"Robert","family":"Biddle","sequence":"first","affiliation":[{"name":"Carleton University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sonia","family":"Chiasson","sequence":"additional","affiliation":[{"name":"Carleton University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"P.C.","family":"Van Oorschot","sequence":"additional","affiliation":[{"name":"Carleton University"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2012,9,7]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"Proceedings of the HCI on People and Computers. 1--9.","author":"Adams A.","unstructured":"Adams , A. , Sasse , M. A. , and Lunt , P . 1997. Making passwords secure and usable . In Proceedings of the HCI on People and Computers. 1--9. Adams, A., Sasse, M. A., and Lunt, P. 1997. Making passwords secure and usable. In Proceedings of the HCI on People and Computers. 1--9."},{"key":"e_1_2_1_2_1","volume-title":"Proceedings of the IEEE International Conference on Virtual Environments, Human-Computer Interfaces and Measurement Systems.","author":"Alsulaiman F.","unstructured":"Alsulaiman , F. and El Saddik, A. 2006. A novel 3D graphical password schema . In Proceedings of the IEEE International Conference on Virtual Environments, Human-Computer Interfaces and Measurement Systems. Alsulaiman, F. and El Saddik, A. 2006. A novel 3D graphical password schema. In Proceedings of the IEEE International Conference on Virtual Environments, Human-Computer Interfaces and Measurement Systems."},{"key":"e_1_2_1_3_1","unstructured":"Amazon. 2010. Amazon mechanical turk. http:\/\/www.mturk.com\/.  Amazon. 2010. Amazon mechanical turk. http:\/\/www.mturk.com\/."},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1037\/h0033773"},{"key":"e_1_2_1_5_1","first-page":"237","article-title":"Memory. Handbook of Perception and Cognition 2nd Ed. Academic Press, New York","volume":"8","author":"Anderson M.","year":"1996","unstructured":"Anderson , M. and Neely , J. 1996 . Memory. Handbook of Perception and Cognition 2nd Ed. Academic Press, New York , NY. Chapter 8 , 237 -- 313 . Anderson, M. and Neely, J. 1996. Memory. Handbook of Perception and Cognition 2nd Ed. Academic Press, New York, NY. Chapter 8, 237--313.","journal-title":"NY. Chapter"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1207\/S15327590IJHC1602_04"},{"key":"e_1_2_1_7_1","volume-title":"Proceedings of the USENIX 4th Workshop on Offensive Technologies.","author":"Aviv A. J.","unstructured":"Aviv , A. J. , Gibson , K. , Mossop , E. , Blaze , M. , and Smith , J. M . 2010. Smudge attacks on smartphone touch screens . In Proceedings of the USENIX 4th Workshop on Offensive Technologies. Aviv, A. J., Gibson, K., Mossop, E., Blaze, M., and Smith, J. M. 2010. Smudge attacks on smartphone touch screens. In Proceedings of the USENIX 4th Workshop on Offensive Technologies."},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.25"},{"key":"e_1_2_1_9_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy.","author":"Bellovin S. M.","unstructured":"Bellovin , S. M. and Merritt , M . 1992. Encrypted key exchange: Password based protocols secure against dictionary attacks . In Proceedings of the IEEE Symposium on Security and Privacy. Bellovin, S. M. and Merritt, M. 1992. Encrypted key exchange: Password based protocols secure against dictionary attacks. In Proceedings of the IEEE Symposium on Security and Privacy."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1007\/11427896_8"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/290163.290164"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/1180405.1180436"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCIS.2008.4717862"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC.2009.153"},{"key":"e_1_2_1_15_1","volume-title":"Proceedings of the 3rd IFIP WG 11.11 International Conference on Trust Management.","author":"Bicakci K.","unstructured":"Bicakci , K. , Yuceel , M. , Erdeniz , B. , Gurbaslar , H. , and Atalay , N. B . 2009b. Graphical passwords as browser extension: Implementation and usability study . In Proceedings of the 3rd IFIP WG 11.11 International Conference on Trust Management. Bicakci, K., Yuceel, M., Erdeniz, B., Gurbaslar, H., and Atalay, N. B. 2009b. Graphical passwords as browser extension: Implementation and usability study. In Proceedings of the 3rd IFIP WG 11.11 International Conference on Trust Management."},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2011.2116781"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2006.879305"},{"key":"e_1_2_1_18_1","volume-title":"Graphical password. U.S. patent 5,559,961, field","author":"Blonder G.","year":"1995","unstructured":"Blonder , G. 1996. Graphical password. U.S. patent 5,559,961, field August 30, 1995 , and issued September 24, 1996. Blonder, G. 1996. Graphical password. U.S. patent 5,559,961, field August 30, 1995, and issued September 24, 1996."},{"key":"e_1_2_1_19_1","unstructured":"Bond M. 2008. Comments on grIDsure authentication. http:\/\/www.cl.cam.ac.uk\/~mkb23\/research\/GridsureComments.pdf.  Bond M. 2008. Comments on grIDsure authentication. http:\/\/www.cl.cam.ac.uk\/~mkb23\/research\/GridsureComments.pdf."},{"key":"e_1_2_1_20_1","volume-title":"Proceedings of the BCS Conference on Human Computer Interaction (HCI).","author":"Brostoff S.","unstructured":"Brostoff , S. , Inglesant , P. , and Sasse , M. A . 2010. Evaluating the usability and security of a graphical one-time PIN system . In Proceedings of the BCS Conference on Human Computer Interaction (HCI). Brostoff, S., Inglesant, P., and Sasse, M. A. 2010. Evaluating the usability and security of a graphical one-time PIN system. In Proceedings of the BCS Conference on Human Computer Interaction (HCI)."},{"key":"e_1_2_1_21_1","volume-title":"Proceedings of the BCS Conference on Human Computer Interaction (HCI).","author":"Brostoff S.","unstructured":"Brostoff , S. and Sasse , M . 2000. Are Passfaces more usable than passwords&quest; A field trial investigation . In Proceedings of the BCS Conference on Human Computer Interaction (HCI). Brostoff, S. and Sasse, M. 2000. Are Passfaces more usable than passwords&quest; A field trial investigation. In Proceedings of the BCS Conference on Human Computer Interaction (HCI)."},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/1280680.1280682"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.5555\/1531514.1531531"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-009-0080-7"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653722"},{"key":"e_1_2_1_27_1","volume-title":"Proceedings of the USENIX Usability, Psychology, and Security Workshop (UPSEC).","author":"Chiasson S.","year":"2008","unstructured":"Chiasson , S. , Srinivasan , J. , Biddle , R. , and van Oorschot , P. C. 2008 b. Centered discretization with application to graphical passwords . In Proceedings of the USENIX Usability, Psychology, and Security Workshop (UPSEC). Chiasson, S., Srinivasan, J., Biddle, R., and van Oorschot, P. C. 2008b. Centered discretization with application to graphical passwords. In Proceedings of the USENIX Usability, Psychology, and Security Workshop (UPSEC)."},{"key":"e_1_2_1_28_1","volume-title":"Proceedings of the 15th USENIX Security Symposium.","author":"Chiasson S.","unstructured":"Chiasson , S. , van Oorschot , P. C. , and Biddle , R . 2006. A usability study and critique of two password managers . In Proceedings of the 15th USENIX Security Symposium. Chiasson, S., van Oorschot, P. C., and Biddle, R. 2006. A usability study and critique of two password managers. In Proceedings of the 15th USENIX Security Symposium."},{"key":"e_1_2_1_29_1","volume-title":"Proceedings of the European Symposium on Research in Computer Security (ESORICS). Lecture Notes in Computer Science","volume":"4734","author":"Chiasson S.","unstructured":"Chiasson , S. , van Oorschot , P. C. , and Biddle , R . 2007b. Graphical password authentication using Cued Click Points . In Proceedings of the European Symposium on Research in Computer Security (ESORICS). Lecture Notes in Computer Science , vol. 4734 , Springer, Berlin, 359--374. Chiasson, S., van Oorschot, P. C., and Biddle, R. 2007b. Graphical password authentication using Cued Click Points. In Proceedings of the European Symposium on Research in Computer Security (ESORICS). Lecture Notes in Computer Science, vol. 4734, Springer, Berlin, 359--374."},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-85886-7_29"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1037\/0278-7393.13.3.474"},{"key":"e_1_2_1_32_1","volume-title":"Proceedings of the 13th USENIX Security Symposium.","author":"Davis D.","unstructured":"Davis , D. , Monrose , F. , and Reiter , M . 2004. On user choice in graphical password schemes . In Proceedings of the 13th USENIX Security Symposium. Davis, D., Monrose, F., and Reiter, M. 2004. On user choice in graphical password schemes. In Proceedings of the 13th USENIX Security Symposium."},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijhcs.2005.04.020"},{"key":"e_1_2_1_34_1","volume-title":"Proceedings of the 9th USENIX Security Symposium.","author":"Dhamija R.","unstructured":"Dhamija , R. and Perrig , A . 2000. D\u00e9j\u00e0 Vu: A user study using images for authentication . In Proceedings of the 9th USENIX Security Symposium. Dhamija, R. and Perrig, A. 2000. D\u00e9j\u00e0 Vu: A user study using images for authentication. In Proceedings of the 9th USENIX Security Symposium."},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/1124772.1124861"},{"key":"e_1_2_1_36_1","volume-title":"Statistical Analysis of Spatial Point Patterns","author":"Diggle P.","unstructured":"Diggle , P. 1983. Statistical Analysis of Spatial Point Patterns . Academic Press , New York, NY . Diggle, P. 1983. Statistical Analysis of Spatial Point Patterns. Academic Press, New York, NY."},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/1280680.1280684"},{"key":"e_1_2_1_38_1","volume-title":"Proceedings of the 4th Conference on Communication by Gaze Interaction (COGAIN).","author":"Dunphy P.","unstructured":"Dunphy , P. , Fitch , A. , and Olivier , P . 2008a. Gaze-contingent passwords at the ATM . In Proceedings of the 4th Conference on Communication by Gaze Interaction (COGAIN). Dunphy, P., Fitch, A., and Olivier, P. 2008a. Gaze-contingent passwords at the ATM. In Proceedings of the 4th Conference on Communication by Gaze Interaction (COGAIN)."},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/1837110.1837114"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/1408664.1408668"},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315252"},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/1518701.1518837"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.3758\/BF03195514"},{"key":"e_1_2_1_44_1","volume-title":"Proceedings of the International Cryptology Conference (CRYPTO'89)","author":"Feldmeier D.","unstructured":"Feldmeier , D. and Karn , P . 1989. UNIX password security\u2014Ten years later . In Proceedings of the International Cryptology Conference (CRYPTO'89) . Feldmeier, D. and Karn, P. 1989. UNIX password security\u2014Ten years later. In Proceedings of the International Cryptology Conference (CRYPTO'89)."},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/1242572.1242661"},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/1837110.1837124"},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2008.19"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/506443.506639"},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2007.13"},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-74835-9_23"},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/49.223865"},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/1322192.1322233"},{"key":"e_1_2_1_53_1","unstructured":"GrIDsure. 2009. GrIDsure corporate website. http:\/\/www.gridsure.com.  GrIDsure. 2009. GrIDsure corporate website. http:\/\/www.gridsure.com."},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/AMS.2008.136"},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/1408664.1408670"},{"key":"e_1_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-03549-4_14"},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1037\/0096-1523.28.1.113"},{"key":"e_1_2_1_58_1","unstructured":"ICANN Security and Stability Advisory Committee. 2005. Domain name hijacking: Incidents threats risks and remedial actions. http:\/\/www.icann.org\/en\/announcements\/hijacking-report-12jul05.pdf.  ICANN Security and Stability Advisory Committee. 2005. Domain name hijacking: Incidents threats risks and remedial actions. http:\/\/www.icann.org\/en\/announcements\/hijacking-report-12jul05.pdf."},{"key":"e_1_2_1_59_1","volume-title":"Proceedings of the 8th USENIX Security Symposium.","author":"Jermyn I.","unstructured":"Jermyn , I. , Mayer , A. , Monrose , F. , Reiter , M. , and Rubin , A . 1999. The design and analysis of graphical passwords . In Proceedings of the 8th USENIX Security Symposium. Jermyn, I., Mayer, A., Monrose, F., Reiter, M., and Rubin, A. 1999. The design and analysis of graphical passwords. In Proceedings of the 8th USENIX Security Symposium."},{"key":"e_1_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/1753326.1753561"},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1145\/1753326.1753489"},{"key":"e_1_2_1_62_1","volume-title":"Models of Human Memory","author":"Kintsch W.","unstructured":"Kintsch , W. 1970. Models for free recall and recognition . In Models of Human Memory , D. Norman, Ed. Academic Press , New York, NY . Kintsch, W. 1970. Models for free recall and recognition. In Models of Human Memory, D. Norman, Ed. Academic Press, New York, NY."},{"key":"e_1_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1037\/h0068244"},{"key":"e_1_2_1_64_1","volume-title":"Proceedings of the IFIP TC-11 21st International Information Security Conference on Security and Privacy in Dynamic Environments (SEC","volume":"201","author":"Kirovski D.","year":"2006","unstructured":"Kirovski , D. , Jojie , N. , and Roberts , P . 2006. Click passwords . In Proceedings of the IFIP TC-11 21st International Information Security Conference on Security and Privacy in Dynamic Environments (SEC 2006 ). Vol. 201 , 351--363. Kirovski, D., Jojie, N., and Roberts, P. 2006. Click passwords. In Proceedings of the IFIP TC-11 21st International Information Security Conference on Security and Privacy in Dynamic Environments (SEC 2006). Vol. 201, 351--363."},{"key":"e_1_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1145\/1357054.1357127"},{"key":"e_1_2_1_66_1","volume-title":"Proceedings of the 2nd USENIX Security Workshop.","author":"Klein D.","year":"1990","unstructured":"Klein , D. 1990 . Foiling the cracker: A survey of, and improvements to, password security . In Proceedings of the 2nd USENIX Security Workshop. Klein, D. 1990. Foiling the cracker: A survey of, and improvements to, password security. In Proceedings of the 2nd USENIX Security Workshop."},{"key":"e_1_2_1_67_1","volume-title":"Proceedings of the Graphics Interface Conference (GI).","author":"Komanduri S.","unstructured":"Komanduri , S. and Hutchings , D . 2008. Order and entropy in Picture Passwords . In Proceedings of the Graphics Interface Conference (GI). Komanduri, S. and Hutchings, D. 2008. Order and entropy in Picture Passwords. In Proceedings of the Graphics Interface Conference (GI)."},{"key":"e_1_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455830"},{"key":"e_1_2_1_69_1","volume-title":"Imagery, Memory, and Cognition: Essays in Honor of Allan Paivio","author":"Madigan S.","unstructured":"Madigan , S. 1983. Picture memory . In Imagery, Memory, and Cognition: Essays in Honor of Allan Paivio , J. Yuille, Ed. Lawrence Erlbaum Associates , Mahwah, NJ , Chapter 3, 65--89. Madigan, S. 1983. Picture memory. In Imagery, Memory, and Cognition: Essays in Honor of Allan Paivio, J. Yuille, Ed. Lawrence Erlbaum Associates, Mahwah, NJ, Chapter 3, 65--89."},{"key":"e_1_2_1_70_1","unstructured":"Mitnick K. and Simon W. 2002. The Art of Deception: Controlling the Human Element of Security. John Wiley & Sons New York NY.   Mitnick K. and Simon W. 2002. The Art of Deception: Controlling the Human Element of Security. John Wiley & Sons New York NY."},{"key":"e_1_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1145\/1240624.1240758"},{"key":"e_1_2_1_72_1","first-page":"157","article-title":"Graphical passwords. In Security and Usability: Designing Secure Systems That People Can Use, L. Cranor and S. Garfinkel, Eds. O'Reilly Media, Stebastopol, CA","volume":"9","author":"Monrose F.","year":"2005","unstructured":"Monrose , F. and Reiter , M. 2005 . Graphical passwords. In Security and Usability: Designing Secure Systems That People Can Use, L. Cranor and S. Garfinkel, Eds. O'Reilly Media, Stebastopol, CA , Chapter 9 , 157 -- 174 . Monrose, F. and Reiter, M. 2005. Graphical passwords. In Security and Usability: Designing Secure Systems That People Can Use, L. Cranor and S. Garfinkel, Eds. O'Reilly Media, Stebastopol, CA, Chapter 9, 157--174.","journal-title":"Chapter"},{"key":"e_1_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1145\/359168.359172"},{"key":"e_1_2_1_74_1","unstructured":"Muffett A. 2004. Crack password cracker. http:\/\/ciac.llnl.gov\/ciac\/ToolsUnixAuth.html.  Muffett A. 2004. Crack password cracker. http:\/\/ciac.llnl.gov\/ciac\/ToolsUnixAuth.html."},{"key":"e_1_2_1_75_1","unstructured":"Nali D. and Thorpe J. 2004. Analyzing user choice in graphical passwords. Tech. rep. TR-04-01 School of Computer Science Carleton University. Ottawa.  Nali D. and Thorpe J. 2004. Analyzing user choice in graphical passwords. Tech. rep. TR-04-01 School of Computer Science Carleton University. Ottawa."},{"key":"e_1_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102168"},{"key":"e_1_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1037\/0278-7393.2.5.523"},{"key":"e_1_2_1_78_1","volume-title":"Usability Engineering. AP Professional","author":"Nielsen J.","unstructured":"Nielsen , J. 1993. Usability Engineering. AP Professional , Boston, MA . Nielsen, J. 1993. Usability Engineering. AP Professional, Boston, MA."},{"key":"e_1_2_1_79_1","doi-asserted-by":"crossref","unstructured":"Nielsen J. and Mack R. 1994. Usability Inspection Methods. John Wiley & Sons New York NY.   Nielsen J. and Mack R. 1994. Usability Inspection Methods. John Wiley & Sons New York NY.","DOI":"10.1145\/259963.260531"},{"key":"e_1_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-45146-4_36"},{"key":"e_1_2_1_81_1","volume-title":"Proceedings of the Virtual Concept Conference.","author":"Orozco M.","year":"2006","unstructured":"Orozco , M. , Malek , B. , Eid , M. , and El Saddik , A. 2006 . Haptic-based sensible graphical password . In Proceedings of the Virtual Concept Conference. Orozco, M., Malek, B., Eid, M., and El Saddik, A. 2006. Haptic-based sensible graphical password. In Proceedings of the Virtual Concept Conference."},{"key":"e_1_2_1_82_1","volume-title":"Mind and Its Evolution: A Dual Coding Theoretical Approach","author":"Paivio A.","unstructured":"Paivio , A. 2006. Mind and Its Evolution: A Dual Coding Theoretical Approach . Lawrence Erlbaum , Mahwah, NJ . Paivio, A. 2006. Mind and Its Evolution: A Dual Coding Theoretical Approach. Lawrence Erlbaum, Mahwah, NJ."},{"key":"e_1_2_1_83_1","doi-asserted-by":"crossref","unstructured":"Paivio A. Rogers T. and Smythe P. C. 1968. Why are pictures easier to recall than words&quest; Psychonomic Sci. 11 4 137--138.  Paivio A. Rogers T. and Smythe P. C. 1968. Why are pictures easier to recall than words&quest; Psychonomic Sci. 11 4 137--138.","DOI":"10.3758\/BF03331011"},{"key":"e_1_2_1_84_1","unstructured":"Passfaces Corporation. 2009. The science behind Passfaces. White paper. http:\/\/www.passfaces.com\/enterprise\/resources\/white_papers.htm.  Passfaces Corporation. 2009. The science behind Passfaces. White paper. http:\/\/www.passfaces.com\/enterprise\/resources\/white_papers.htm."},{"key":"e_1_2_1_85_1","unstructured":"Perfetti C. and Landesman L. 2001. Eight is not enough. User Interface Engineering. http.\/\/www.ulle.com\/articles\/eight_is_not_enough.  Perfetti C. and Landesman L. 2001. Eight is not enough. User Interface Engineering. http.\/\/www.ulle.com\/articles\/eight_is_not_enough."},{"key":"e_1_2_1_86_1","doi-asserted-by":"publisher","DOI":"10.1109\/MPRV.2003.1186723"},{"key":"e_1_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.1145\/586110.586133"},{"key":"e_1_2_1_88_1","first-page":"943","article-title":"The design and implementation of background Pass-Go scheme towards security threats","volume":"5","author":"Por L. Y.","year":"2008","unstructured":"Por , L. Y. , Lim , X. T. , Su , M. T. , and Kianoush , F. 2008 . The design and implementation of background Pass-Go scheme towards security threats . WSEAS Trans. Inf. Sci. Appl. 5 , 6, 943 -- 952 . Por, L. Y., Lim, X. T., Su, M. T., and Kianoush, F. 2008. The design and implementation of background Pass-Go scheme towards security threats. WSEAS Trans. Inf. Sci. Appl. 5, 6, 943--952.","journal-title":"WSEAS Trans. Inf. Sci. Appl."},{"key":"e_1_2_1_89_1","volume-title":"Proceedings of the 17th USENIX Security Symposium.","author":"Provos N.","unstructured":"Provos , N. , Mavrommatis , P. , Abu Rajab , M. , and Monrose , F . 2008. All your iFrames point to us . In Proceedings of the 17th USENIX Security Symposium. Provos, N., Mavrommatis, P., Abu Rajab, M., and Monrose, F. 2008. All your iFrames point to us. In Proceedings of the 17th USENIX Security Symposium."},{"key":"e_1_2_1_90_1","doi-asserted-by":"publisher","DOI":"10.1146\/annurev.ps.43.020192.001225"},{"key":"e_1_2_1_91_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2007.76"},{"key":"e_1_2_1_92_1","first-page":"103","article-title":"Evaluating authentication mechanisms. In Security and Usability: Designing Secure Systems That People Can Use, L. Cranor and S. Garfinkel, Eds. O'Reilly Media, Stebastopol, C.A","volume":"6","author":"Renaud K.","year":"2005","unstructured":"Renaud , K. 2005 a. Evaluating authentication mechanisms. In Security and Usability: Designing Secure Systems That People Can Use, L. Cranor and S. Garfinkel, Eds. O'Reilly Media, Stebastopol, C.A , Chapter 6 , 103 -- 128 . Renaud, K. 2005a. Evaluating authentication mechanisms. In Security and Usability: Designing Secure Systems That People Can Use, L. Cranor and S. Garfinkel, Eds. O'Reilly Media, Stebastopol, C.A, Chapter 6, 103--128.","journal-title":"Chapter"},{"key":"e_1_2_1_93_1","volume-title":"Proceedings of the BCS Conference on Human Computer Interaction (HCI). 167--182","author":"Renaud K.","year":"2005","unstructured":"Renaud , K. 2005 b. A visuo-biometric authentication mechanism for older users . In Proceedings of the BCS Conference on Human Computer Interaction (HCI). 167--182 . Renaud, K. 2005b. A visuo-biometric authentication mechanism for older users. In Proceedings of the BCS Conference on Human Computer Interaction (HCI). 167--182."},{"key":"e_1_2_1_94_1","doi-asserted-by":"publisher","DOI":"10.1504\/IJICS.2009.026621"},{"key":"e_1_2_1_95_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jvlc.2008.04.001"},{"key":"e_1_2_1_96_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.intcom.2004.06.012"},{"key":"e_1_2_1_97_1","volume-title":"Jiminy: Helping user to remember their passwords. Tech. Rep., School of Computing","author":"Renaud K.","year":"2001","unstructured":"Renaud , K. and Smith , E . 2001 . Jiminy: Helping user to remember their passwords. Tech. Rep., School of Computing , University of South Africa . Renaud, K. and Smith, E. 2001. Jiminy: Helping user to remember their passwords. Tech. Rep., School of Computing, University of South Africa."},{"key":"e_1_2_1_98_1","volume-title":"Proceedings of the 14th USENIX Security Symposium.","author":"Ross B.","unstructured":"Ross , B. , Jackson , C. , Miyake , N. , Boneh , D. , and Mitchell , J . 2005. Stronger password authentication using browser extensions . In Proceedings of the 14th USENIX Security Symposium. Ross, B., Jackson, C., Miyake, N., Boneh, D., and Mitchell, J. 2005. Stronger password authentication using browser extensions. In Proceedings of the 14th USENIX Security Symposium."},{"key":"e_1_2_1_99_1","doi-asserted-by":"publisher","DOI":"10.1145\/1030083.1030116"},{"key":"e_1_2_1_100_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2008.18"},{"key":"e_1_2_1_101_1","doi-asserted-by":"publisher","DOI":"10.1023\/A:1011902718709"},{"key":"e_1_2_1_102_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2009.11"},{"key":"e_1_2_1_103_1","unstructured":"Seifert C. 2006. Analyzing malicious SSH login attempts. http:\/\/www.securityfocus.com\/infocus\/1876.  Seifert C. 2006. Analyzing malicious SSH login attempts. http:\/\/www.securityfocus.com\/infocus\/1876."},{"key":"e_1_2_1_104_1","doi-asserted-by":"publisher","DOI":"10.1145\/1753326.1753383"},{"key":"e_1_2_1_105_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0022-5371(67)80067-7"},{"key":"e_1_2_1_106_1","unstructured":"Shuanglei Z. 2005. Project RainbowCrack. http:\/\/www.antsight.com\/zsl\/rainbowcrack.  Shuanglei Z. 2005. Project RainbowCrack. http:\/\/www.antsight.com\/zsl\/rainbowcrack."},{"key":"e_1_2_1_107_1","doi-asserted-by":"publisher","DOI":"10.1145\/634067.634236"},{"key":"e_1_2_1_108_1","doi-asserted-by":"publisher","DOI":"10.3758\/BF03337426"},{"key":"e_1_2_1_109_1","doi-asserted-by":"publisher","DOI":"10.1145\/1920261.1920273"},{"key":"e_1_2_1_110_1","unstructured":"Stubblefield A. and Simon D. 2004. Inkblot authentication Tech. rep. MSR-TR-2004-85. Microsoft Research.  Stubblefield A. and Simon D. 2004. Inkblot authentication Tech. rep. MSR-TR-2004-85. Microsoft Research."},{"key":"e_1_2_1_112_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2005.27"},{"key":"e_1_2_1_113_1","unstructured":"Tafasa. 2010. Patternlock. http:\/\/www.tafasa.com\/patternlock.html.  Tafasa. 2010. Patternlock. http:\/\/www.tafasa.com\/patternlock.html."},{"key":"e_1_2_1_115_1","first-page":"273","article-title":"Pass-Go: A proposal to improve the usability of graphical passwords","volume":"7","author":"Tao H.","year":"2008","unstructured":"Tao , H. and Adams , C. 2008 . Pass-Go: A proposal to improve the usability of graphical passwords . Int. J. Net. Secur. 7 , 2, 273 -- 292 . Tao, H. and Adams, C. 2008. Pass-Go: A proposal to improve the usability of graphical passwords. Int. J. Net. Secur. 7, 2, 273--292.","journal-title":"Int. J. Net. Secur."},{"key":"e_1_2_1_116_1","doi-asserted-by":"publisher","DOI":"10.1145\/1143120.1143128"},{"key":"e_1_2_1_117_1","doi-asserted-by":"publisher","DOI":"10.1145\/1593105.1593162"},{"key":"e_1_2_1_119_1","volume-title":"Proceedings of the 13th USENIX Security Symposium.","author":"Thorpe J.","unstructured":"Thorpe , J. and van Oorschot, P. C. 2004. Graphical dictionaries and the memorable space of graphical passwords . In Proceedings of the 13th USENIX Security Symposium. Thorpe, J. and van Oorschot, P. C. 2004. Graphical dictionaries and the memorable space of graphical passwords. In Proceedings of the 13th USENIX Security Symposium."},{"key":"e_1_2_1_120_1","volume-title":"Proceedings of the 16th USENIX Security Symposium.","author":"Thorpe J.","unstructured":"Thorpe , J. and van Oorschot, P. C. 2007. Human-seeded attacks and exploiting hot-spots in graphical passwords . In Proceedings of the 16th USENIX Security Symposium. Thorpe, J. and van Oorschot, P. C. 2007. Human-seeded attacks and exploiting hot-spots in graphical passwords. In Proceedings of the 16th USENIX Security Symposium."},{"key":"e_1_2_1_121_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0022-5371(66)80048-8"},{"key":"e_1_2_1_122_1","doi-asserted-by":"publisher","DOI":"10.2307\/1422081"},{"key":"e_1_2_1_123_1","volume-title":"An evaluation of the Passface personal authentication system. Tech. rep","author":"Valentine T.","unstructured":"Valentine , T. 1999. An evaluation of the Passface personal authentication system. Tech. rep ., Goldsmiths College University of London . Valentine, T. 1999. An evaluation of the Passface personal authentication system. Tech. rep., Goldsmiths College University of London."},{"key":"e_1_2_1_124_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2010.2053706"},{"key":"e_1_2_1_125_1","doi-asserted-by":"publisher","DOI":"10.1145\/1284680.1284685"},{"key":"e_1_2_1_126_1","doi-asserted-by":"publisher","DOI":"10.5555\/2011216.2011218"},{"key":"e_1_2_1_127_1","volume-title":"Proceedings of the 4th International MCETECH Conference on eTechnologies.","author":"van Oorschot P. C.","unstructured":"van Oorschot , P. C. and Wan , T . 2009. TwoStep: An authentication method combining text and graphical passwords . In Proceedings of the 4th International MCETECH Conference on eTechnologies. van Oorschot, P. C. and Wan, T. 2009. TwoStep: An authentication method combining text and graphical passwords. In Proceedings of the 4th International MCETECH Conference on eTechnologies."},{"key":"e_1_2_1_128_1","volume-title":"Passdoodles: A lightweight authentication method","author":"Varenhorst C.","year":"2004","unstructured":"Varenhorst , C. 2004 . Passdoodles: A lightweight authentication method . MIT Research Science Institute . Varenhorst, C. 2004. Passdoodles: A lightweight authentication method. MIT Research Science Institute."},{"key":"e_1_2_1_129_1","volume-title":"Refining the test phase of usability evaluation: How many subjects is enough&quest","author":"Virzi R.","unstructured":"Virzi , R. 1992. Refining the test phase of usability evaluation: How many subjects is enough&quest ; Human Factors 34, 457--468. Virzi, R. 1992. Refining the test phase of usability evaluation: How many subjects is enough&quest; Human Factors 34, 457--468."},{"key":"e_1_2_1_130_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijhcs.2007.03.007"},{"key":"e_1_2_1_131_1","volume-title":"The statistical security of GrIDsure. Tech. rep","author":"Weber R.","unstructured":"Weber , R. 2006. The statistical security of GrIDsure. Tech. rep ., University of Cambridge . Weber, R. 2006. The statistical security of GrIDsure. Tech. rep., University of Cambridge."},{"key":"e_1_2_1_132_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.10"},{"key":"e_1_2_1_133_1","doi-asserted-by":"publisher","DOI":"10.1145\/1463160.1463202"},{"key":"e_1_2_1_134_1","doi-asserted-by":"publisher","DOI":"10.1145\/142750.142864"},{"key":"e_1_2_1_135_1","volume-title":"Proceedings of the 8th USENIX Security Symposium.","author":"Whitten A.","unstructured":"Whitten , A. and Tygar , J . 1999. Why Johnny can't encrypt: A usability evaluation of PGP 5.0 . In Proceedings of the 8th USENIX Security Symposium. Whitten, A. and Tygar, J. 1999. Why Johnny can't encrypt: A usability evaluation of PGP 5.0. In Proceedings of the 8th USENIX Security Symposium."},{"key":"e_1_2_1_136_1","volume-title":"Proceedings of the 11th International Conference on Human-Computer Interaction (HC11)","author":"Wiedenbeck S.","unstructured":"Wiedenbeck , S. , Waters , J. , Birget , J. , Brodskiy , A. , and Memon , N . 2005a. Authentication using graphical passwords: Basic results . In Proceedings of the 11th International Conference on Human-Computer Interaction (HC11) . Wiedenbeck, S., Waters, J., Birget, J., Brodskiy, A., and Memon, N. 2005a. Authentication using graphical passwords: Basic results. In Proceedings of the 11th International Conference on Human-Computer Interaction (HC11)."},{"key":"e_1_2_1_137_1","doi-asserted-by":"publisher","DOI":"10.1145\/1073001.1073002"},{"key":"e_1_2_1_138_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijhcs.2005.04.010"},{"key":"e_1_2_1_139_1","doi-asserted-by":"publisher","DOI":"10.1145\/1133265.1133303"},{"key":"e_1_2_1_140_1","doi-asserted-by":"publisher","DOI":"10.1080\/10658980701788165"},{"key":"e_1_2_1_141_1","volume-title":"Proceedings of the Network and Distributed System Security Symposium (NDSS).","author":"Wu T.","year":"1998","unstructured":"Wu , T. 1998 . The secure remote password protocol . In Proceedings of the Network and Distributed System Security Symposium (NDSS). Wu, T. 1998. The secure remote password protocol. In Proceedings of the Network and Distributed System Security Symposium (NDSS)."},{"key":"e_1_2_1_142_1","volume-title":"Proceedings of the Network and Distributed System Security Symposium (NDSS).","author":"Wu T.","year":"1999","unstructured":"Wu , T. 1999 . A real-world analysis of Kerberos password security . In Proceedings of the Network and Distributed System Security Symposium (NDSS). Wu, T. 1999. A real-world analysis of Kerberos password security. In Proceedings of the Network and Distributed System Security Symposium (NDSS)."},{"key":"e_1_2_1_143_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2004.81"},{"key":"e_1_2_1_144_1","first-page":"129","article-title":"The memorability and security of passwords. In Security and Usability: Designing Secure Systems That People Can Use, L. Cranor and S. Garfinkel, Eds. O'Reilly Media, Stebastopol, CA","volume":"7","author":"Yan J.","year":"2005","unstructured":"Yan , J. , Blackwell , A. , Anderson , R. , and Grant , A. 2005 . The memorability and security of passwords. In Security and Usability: Designing Secure Systems That People Can Use, L. Cranor and S. Garfinkel, Eds. O'Reilly Media, Stebastopol, CA , Chapter 7 , 129 -- 142 . Yan, J., Blackwell, A., Anderson, R., and Grant, A. 2005. The memorability and security of passwords. In Security and Usability: Designing Secure Systems That People Can Use, L. Cranor and S. Garfinkel, Eds. O'Reilly Media, Stebastopol, CA, Chapter 7, 129--142.","journal-title":"Chapter"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2333112.2333114","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2333112.2333114","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T09:21:06Z","timestamp":1750238466000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2333112.2333114"}},"subtitle":["Learning from the first twelve years"],"short-title":[],"issued":{"date-parts":[[2012,8]]},"references-count":140,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2012,8]]}},"alternative-id":["10.1145\/2333112.2333114"],"URL":"https:\/\/doi.org\/10.1145\/2333112.2333114","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012,8]]},"assertion":[{"value":"2010-04-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2011-03-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2012-09-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}