{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T05:05:21Z","timestamp":1750309521404,"version":"3.41.0"},"reference-count":45,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2025,1,2]],"date-time":"2025-01-02T00:00:00Z","timestamp":1735776000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["62202099, 62102081, 62072102, 62132009"],"award-info":[{"award-number":["62202099, 62102081, 62072102, 62132009"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/100000001","name":"US National Science Foundation","doi-asserted-by":"crossref","award":["1931871, 1915780"],"award-info":[{"award-number":["1931871, 1915780"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Jiangsu Provincial Natural Science Foundation of China","award":["BK20220806"],"award-info":[{"award-number":["BK20220806"]}]},{"name":"Jiangsu Provincial Key R&D Programs","award":["BE2021729, BE2022680, BE2022065-5"],"award-info":[{"award-number":["BE2021729, BE2022680, BE2022065-5"]}]},{"name":"\u201dZhishan\u201d Young Scholar Program of Southeast University","award":["2242024RCB0012"],"award-info":[{"award-number":["2242024RCB0012"]}]},{"name":"Jiangsu Provincial Key Laboratory of Network and Information Security","award":["BM2003201"],"award-info":[{"award-number":["BM2003201"]}]},{"name":"Key Laboratory of Computer Network and Information Integration of Ministry of Education of China","award":["93K-9"],"award-info":[{"award-number":["93K-9"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Multimedia Comput. Commun. Appl."],"published-print":{"date-parts":[[2025,2,28]]},"abstract":"<jats:p>\n            With metaverse attracting increasing attention from both academic and industry, the application of virtual reality (VR) has extended beyond 3D immersive viewing\/gaming to a broader range of areas, such as banking, shopping, tourism, education, and so on, which involves a growing amount of sensitive and private user data into VR systems. However, with current password-based user authentication schemes in mainstream VR devices, studies demonstrate that side-channel attacks can pose a severe threat to VR user privacy. To mitigate the threat, we propose a novel panoramic-image-based VR user authentication system, i.e.,\n            <jats:italic>Pivot<\/jats:italic>\n            , to defend against such attacks, yet maintain high usability. Specifically, in\n            <jats:italic>Pivot<\/jats:italic>\n            , we design an image-random-pivoting-based user interaction mechanism to assist users in quickly and securely selecting memorable points of interest in a panoramic image. Then an image region segmentation algorithm is designed to automatically scatter the points to regions to form the customized graphic password for the user, which could ensure a sufficiently large password space and also reduce the near-region point misclicks. Afterward, the region indexes are used to generate the hashed password for authentication. Both theoretical security analysis and extensive user studies demonstrate that\n            <jats:italic>Pivot<\/jats:italic>\n            is secure and user-friendly in practice.\n          <\/jats:p>","DOI":"10.1145\/3694975","type":"journal-article","created":{"date-parts":[[2024,9,9]],"date-time":"2024-09-09T17:06:47Z","timestamp":1725901607000},"page":"1-19","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Pivot: Panoramic-Image-Based VR User Authentication against Side-Channel Attacks"],"prefix":"10.1145","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-4127-6009","authenticated-orcid":false,"given":"Gui","family":"Xiao","sequence":"first","affiliation":[{"name":"School of Cyber Science and Engineering, Southeast University, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9691-8702","authenticated-orcid":false,"given":"Zhen","family":"Ling","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Southeast University, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-4638-2845","authenticated-orcid":false,"given":"Qunqun","family":"Fan","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Southeast University, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1628-906X","authenticated-orcid":false,"given":"Xiangyu","family":"Xu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Southeast University, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4437-0850","authenticated-orcid":false,"given":"Wenjia","family":"Wu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Southeast University, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6597-3725","authenticated-orcid":false,"given":"Ding","family":"Ding","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Southeast University, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-9969-1779","authenticated-orcid":false,"given":"Chen","family":"Chen","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Southeast University, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2391-7789","authenticated-orcid":false,"given":"Xinwen","family":"Fu","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of Massachusetts Lowell, Lowell, MA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,1,2]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1109\/VR50410.2021.00081"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10055-020-00467-1"},{"key":"e_1_3_2_4_2","unstructured":"Bloomberg. 2021. Metaverse May Be $800 Billion Market Next Tech Platform. Retrieved July 30 2022 from https:\/\/www.bloomberg.com\/professional\/blog\/metaverse-may-be-800-billion-market-next-tech-platform\/"},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1002\/jts.22690"},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/sp.2018.00010"},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.14236\/ewic\/hci2008.12"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-74835-9_24"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1145\/57167.57203"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2721359"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/3290607.3312959"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/sp.2019.00074"},{"key":"e_1_3_2_13_2","first-page":"1","volume-title":"Proceedings of ISOC Network and Distributed System Security Symposium (NDSS \u201917)","author":"George Ceenu","year":"2017","unstructured":"Ceenu George, Mohamed Khamis, Emanuel von Zezschwitz, Marinus Burger, Henri Schmidt, Florian Alt, and Heinrich Hussmann. 2017. Seamless and secure VR: Adapting and evaluating established authentication systems for virtual reality. In Proceedings of ISOC Network and Distributed System Security Symposium (NDSS \u201917). ISOC, 1\u201315."},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1109\/VR.2019.8797862"},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1145\/3383668.3419917"},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr.2013.271"},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1080\/01621459.1952.10483441"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1109\/PERCOM.2016.7456514"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/cns.2019.8802674"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/VR51125.2022.00064"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.1109\/sp40000.2020.00100"},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1145\/3334480.3382799"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1145\/3428121"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/VR51125.2022.00098"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1109\/AIVR46125.2019.00058"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1145\/2307636.2307666"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.3390\/S20102944"},{"key":"e_1_3_2_28_2","unstructured":"Vishnu Prajapati. 2018. Silhouette on People Standing on Mountain during Blue Hour. Retrieved from https:\/\/unsplash.com\/photos\/silhouette-on-people-standing-on-mountain-during-blue-hour-RaEFRWLy9ME"},{"key":"e_1_3_2_29_2","unstructured":"Samsung. 2019. The GearVR Framework (GearVRf). Retrieved July 30 2022 from https:\/\/github.com\/Samsung\/GearVRf"},{"key":"e_1_3_2_30_2","unstructured":"Bob Shea. 2018. Seashore During Daytime. Retrieved from https:\/\/unsplash.com\/photos\/seashore-during-daytime-hIuCzCYx_pg"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2018.2800048"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/3447993.3483272"},{"key":"e_1_3_2_33_2","first-page":"261","volume-title":"Transforming Legacy Banking Applications to Banking Experience Platforms","author":"Shivakumar Shailesh Kumar","year":"2019","unstructured":"Shailesh Kumar Shivakumar and Sourabhh Sethii. 2019. Transforming Legacy Banking Applications to Banking Experience Platforms. Springer, 261\u2013295."},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23060"},{"key":"e_1_3_2_35_2","unstructured":"David Vives. 2020. Aerial View of City Buildings near Sea during Daytime. Retrieved from https:\/\/unsplash.com\/photos\/aerial-view-of-city-buildings-near-sea-during-daytime-VP-Xs6MF0Fk"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053031"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijhcs.2005.04.010"},{"key":"e_1_3_2_38_2","unstructured":"Wikipedia. 2022. Equirectangular Projection. Retrieved July 30 2022 from https:\/\/en.wikipedia.org\/wiki\/Equirectangular_projection"},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516709"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23130"},{"key":"e_1_3_2_41_2","unstructured":"Yevheniia. 2021. A View of a City and a Body of Water. Retrieved from https:\/\/unsplash.com\/photos\/a-view-of-a-city-and-a-body-of-water-ZMuldmPnOOI"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1109\/APCCAS.2016.7804002"},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660288"},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243777"},{"key":"e_1_3_2_45_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.24298"},{"key":"e_1_3_2_46_2","unstructured":"Mark Zuckerberg and Gayle King. 2021. Facebook Launches \u201cHorizon Workrooms.\u201d Here\u2019s How It Works. Retrieved February 15 2022 from https:\/\/www.cbsnews.com\/video\/facebook-launches-horizon-workrooms-heres-how-it-works\/"}],"container-title":["ACM Transactions on Multimedia Computing, Communications, and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3694975","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3694975","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:18:07Z","timestamp":1750295887000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3694975"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,1,2]]},"references-count":45,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2025,2,28]]}},"alternative-id":["10.1145\/3694975"],"URL":"https:\/\/doi.org\/10.1145\/3694975","relation":{},"ISSN":["1551-6857","1551-6865"],"issn-type":[{"type":"print","value":"1551-6857"},{"type":"electronic","value":"1551-6865"}],"subject":[],"published":{"date-parts":[[2025,1,2]]},"assertion":[{"value":"2023-12-30","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-08-20","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-01-02","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}