{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T13:25:03Z","timestamp":1780406703504,"version":"3.54.1"},"reference-count":35,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2020,3,12]],"date-time":"2020-03-12T00:00:00Z","timestamp":1583971200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Cyber-Phys. Syst."],"published-print":{"date-parts":[[2020,7,31]]},"abstract":"<jats:p>In the last months, the market for personal wearable devices has been booming significantly, and, in particular, smartwatches are starting to assume a fundamental role in the Bring Your Own Device (BYOD) arena as well as in the more general Internet of Things (IoT) ecosystem, by acting both as sensitive data sources and as user identity proxies. These new roles, complementing the more traditional personal assistance and telemetry\/tracking ones, open new perspectives in their integration in complex IoT-based critical infrastructures such as e-payment, health care monitoring, and emergency systems, as well as in their usage as remote control facilities in smart services. Users can access their IoT devices at any time from any place through smartwatches. We argue that this new scenario calls for a strengthened and more resilient authentication of users on these devices, despite their limitations in terms of dimensions and hardware constraints that may considerably affect the usability of security mechanisms. In this article, we present an innovative authentication scheme targeted at smartwatches, namely CirclePIN, that provides both resilience to most common attacks and a high level of usability in tests with real users.<\/jats:p>","DOI":"10.1145\/3365995","type":"journal-article","created":{"date-parts":[[2020,3,12]],"date-time":"2020-03-12T07:49:20Z","timestamp":1583999360000},"page":"1-19","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":27,"title":["CirclePIN"],"prefix":"10.1145","volume":"4","author":[{"given":"Meriem","family":"Guerar","sequence":"first","affiliation":[{"name":"DIBRIS - University of Genoa, Genoa, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Luca","family":"Verderame","sequence":"additional","affiliation":[{"name":"DIBRIS - University of Genoa, Genoa, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Alessio","family":"Merlo","sequence":"additional","affiliation":[{"name":"DIBRIS - University of Genoa, Genoa, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Francesco","family":"Palmieri","sequence":"additional","affiliation":[{"name":"University of Salerno, Salerno, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mauro","family":"Migliardi","sequence":"additional","affiliation":[{"name":"DEI - University of Padua, Padua, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Luca","family":"Vallerini","sequence":"additional","affiliation":[{"name":"DEI - University of Padua, Padua, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,3,12]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"Proceedings of the 4th USENIX Conference on Offensive Technologies (WOOT\u201910)","author":"Aviv Adam J.","year":"1925"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1935701.1935740"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/1753326.1753490"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.3390\/s17092043"},{"key":"e_1_2_1_5_1","volume-title":"Security Engineering and Intelligence Informatics","author":"Gobbo Nicola"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.3233\/JHS-160545"},{"key":"e_1_2_1_7_1","first-page":"64","article-title":"ClickPattern: A pattern lock system resilient to smudge and side-channel attacks","volume":"8","author":"Guerar Meriem","year":"2017","journal-title":"JoWUA"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2017.03.012"},{"key":"e_1_2_1_9_1","volume-title":"Invisible CAPPCHA: A usable mechanism to distinguish between malware and humans on the mobile IoT. Computers 8 Security 78","author":"Guerar Meriem","year":"2018"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPCSim.2015.7237041"},{"key":"e_1_2_1_11_1","first-page":"4","article-title":"Using screen brightness to improve security in mobile social network access","volume":"15","author":"Guerar M.","year":"2018","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"e_1_2_1_12_1","unstructured":"HP. 2015. Internet of Things security study: Smartwatches. Retrieved from https:\/\/www.ftc.gov\/system\/files\/documents\/public_comments\/2015\/10\/00050-98093.pdf.  HP. 2015. Internet of Things security study: Smartwatches. Retrieved from https:\/\/www.ftc.gov\/system\/files\/documents\/public_comments\/2015\/10\/00050-98093.pdf."},{"key":"e_1_2_1_13_1","first-page":"31","article-title":"Secure remote attestation","volume":"2018","author":"Jakobsson Markus","year":"2018","journal-title":"IACR Cryptology ePrint Archive"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/BTAS.2015.7358794"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3098279.3098542"},{"key":"e_1_2_1_16_1","volume-title":"TinyLock: Affordable defense against smudge attacks on smartphone pattern lock systems. Computers 8 Security 42","author":"Kwon Taekyoung","year":"2014"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2016.7860521"},{"key":"e_1_2_1_18_1","volume-title":"Snoopy: Sniffing your smartwatch passwords via deep sequence learning. IMWUT 1","author":"Lu Chris Xiaoxuan","year":"2017"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/1518701.1518840"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/2802083.2808397"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-150530"},{"key":"e_1_2_1_22_1","volume-title":"2011 Proceedings of the 34th International Convention MIPRO. IEEE, 1452--1457","author":"Migliardi M."},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/WAINA.2013.214"},{"key":"e_1_2_1_24_1","volume-title":"13th Symposium on Usable Privacy and Security (SOUPS\u201917)","author":"Nguyen Toan","year":"2017"},{"key":"e_1_2_1_25_1","volume-title":"Tap-based user authentication for smartwatches. Computers 8 Security 78","author":"Nguyen Toan","year":"2018"},{"key":"e_1_2_1_26_1","volume-title":"DRAW-A-PIN: Authentication using finger-drawn PIN on touch devices. Computers 8 Security 66","author":"Nguyen Toan Van","year":"2017"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2014.2307331"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196555"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/WIFS.2015.7368569"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11623-016-0582-1"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2005.24"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/2702123.2702212"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2017.2737533"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/2897845.2897847"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/PERCOMW.2015.7134097"}],"container-title":["ACM Transactions on Cyber-Physical Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3365995","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3365995","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T17:49:07Z","timestamp":1750268947000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3365995"}},"subtitle":["A Novel Authentication Mechanism for Smartwatches to Prevent Unauthorized Access to IoT Devices"],"short-title":[],"issued":{"date-parts":[[2020,3,12]]},"references-count":35,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2020,7,31]]}},"alternative-id":["10.1145\/3365995"],"URL":"https:\/\/doi.org\/10.1145\/3365995","relation":{},"ISSN":["2378-962X","2378-9638"],"issn-type":[{"value":"2378-962X","type":"print"},{"value":"2378-9638","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,3,12]]},"assertion":[{"value":"2019-01-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2019-10-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-03-12","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}