Source-linked AI summary

Context or Digits? Balancing Memorability and Efficiency in Virtual Reality Authentication

Yuxuan Huang, Qiao Jin, Tongyu Nie, Victoria Interrante, Evan Suma Rosenberg

arXiv:2608.29531v1cs.CRcs.HC

TL;DR

VR knowledge-based authentication must balance memorability, efficiency, and security. This paper introduces ADBA, which enforces context-based password creation while allowing context- or digit-based entry, and evaluates it in a remote longitudinal study against 6-digit PINs. ADBA showed better memorability, lower overall task load, and higher perceived efficiency despite longer entry times, within the studied usage scenarios.

  • Problem

    Knowledge-based VR authentication requires explicit password memorization and entry, creating tradeoffs among efficiency, memorability, and security.

  • Method

    ADBA decouples users’ temporal priorities by enforcing context-based password creation while supporting context- and digit-based entry during authentication.

  • Results

    ADBA achieved better memorability, lower overall task load, and higher perceived efficiency than PIN-based methods despite longer password-entry times.

  • Takeaways & Limitations

    ADBA offers a context-centered authentication design that supports memorable and efficient options under the usage scenarios examined.

  • Takeaways & Limitations

    The study did not directly compare ADBA with DBA, so improvements over DBA remain inferential rather than statistically validated.

Abstract

from arXiv · show

We present Adaptive Direction-Based Authentication (ADBA), a knowledge-based authentication method for Virtual Reality that decouples users' needs temporally by enforcing password creation based on virtual environment context while supporting both context- and digit-based entries during authentication. This design prioritizes memorability for new passwords and offers both efficient and memorable options to support users' evolving needs. We conducted a remote longitudinal study with 66 participants comparing ADBA against 6-digit PINs over 2-3 weeks. The results demonstrated that ADBA achieved superior memorability and lower perceived task load. Interestingly, no participant chose to enter via digits in the study, yet they still perceived ADBA to be highly efficiency despite longer objective entry times. ADBA also provided security benefits through randomly-generated digit representations, though some degree of password homogeneity was observed in specific virtual environments. Our findings suggest that ADBA offers solid advantages to the traditional PINs, and successfully addresses the tradeoffs between efficiency, memorability, and security under the usage scenarios considered in the study.

1 Introduction

Knowledge-based VR authentication is familiar and hardware-independent, but requires memorization and entry that create tradeoffs among efficiency, memorability, and security. ADBA addresses these gaps by prioritizing users’ changing needs over time and evaluating the approach in a remote longitudinal study.

  • Knowledge-based authentication remains widely used because of its simplicity, hardware independence, and user familiarity.
  • Longer or stronger passwords can increase security demands while users’ password choices and entry requirements can reduce memorability or efficiency.
  • DBA combined symbol entry, context cues, and randomization, but did not account for temporal changes in users’ priorities.
  • ADBA introduces a temporal perspective that decouples efficiency and memorability by prioritizing what users need at a given stage.
  • The study used a remote longitudinal design to improve ecological validity by emulating real-world authentication.
  • Users did not prioritize sheer entry efficiency even under daily authentication.

2 Related Work

Prior VR authentication methods trade efficiency, memorability, and security in different ways. ADBA builds on DBA by incorporating temporal priorities and environmental context to address these tradeoffs under more realistic usage conditions.

  • VR authentication methods are categorized as symbol-based or context-based according to the information users must remember.
  • Symbol-based methods are efficient on compact PIN-pads but can weaken security or memorability when passwords become stronger.
  • Context-based methods leverage picture memory for high memorability, but visual search and locomotion can make authentication inefficient.
  • DBA unified symbols and contexts through directional passwords, but did not address usage-dependent tradeoffs or empirically validate its memorability advantage.
  • ADBA uses environmental context as memorable information and as additional context for recalling corresponding symbols, while evaluating the design longitudinally and remotely.

3 The Adaptive Direction-Based Authentication

ADBA requires context-based password creation but supports context- or digit-based authentication entry. This design preserves memorable cues while offering an alternative entry mode as users’ priorities change.

  • ADBA contains six virtual environments, each divided into ten directions corresponding to digits 0 through 9.
  • Password Creation: During password creation, users select directions from visible environments while the corresponding digits remain hidden.
  • Password Creation: Hidden digit correspondences prevent users from choosing weak sequences, while randomly generated digit representations provide a security benefit.
  • Password Entry: During authentication, users see both the environment and a rotating radial PIN-pad, allowing selection by context or digit.
  • Password Entry: ADBA can remain context-based, become symbol-based, or combine both modes according to users’ evolving memorability and efficiency priorities.

4 Methods

The study evaluated ADBA against user-selected and randomly assigned 6-digit PINs in a remote, longitudinal VR experiment. It measured entry efficiency, memorability, usability, task load, and password homogeneity across realistic authentication stages.

  • Study Design: The between-subject remote longitudinal design let participants authenticate with personal setups, at their own pace, and at realistic frequencies.
  • Study Design: The three conditions were ADBA, user-selected 6-digit PIN, and randomly assigned 6-digit PIN, with identical theoretical password spaces of 10^6.
  • Procedure: The study spanned 2–3 weeks with password setup, low-frequency entry, high-frequency entry, and an exit survey.
  • Participants: 66 participants completed the study, including university-community and Prolific recruits aged 18 to 74.
  • Measures: Entry efficiency was measured by password-entry time, while memorability was assessed through recall rate and entries per authentication.
  • Measures: Usability and task load were measured with SUS, NASA TLX, and custom perceived-efficiency and memorability ratings.
  • Measures: Password homogeneity was assessed using Shannon entropy of selected directions within each environment, with lower entropy indicating more homogeneous choices.

5 Results

ADBA improved recall, reduced authentication attempts, and lowered perceived workload relative to PIN-based methods, while remaining objectively slower. Participants also perceived ADBA as more efficient and memorable, although directional choices showed lower diversity in some environments.

  • Memorability: ADBA recall reached 86% in Session 2 and 95% in Session 3, compared with 73% and 77% for both PIN conditions.
  • Memorability: ADBA required the fewest authentication entries, with posterior probabilities of 0.92 against 6-Digit-PIN and 0.97 against Random-PIN.
  • Efficiency: 25.2 seconds was ADBA’s median correct entry time, versus 5.5 seconds for 6-Digit-PIN and 5.9 seconds for Random-PIN.
  • Efficiency: ADBA entry times decreased faster across sessions but remained 14.4–32.1 seconds slower than both PIN methods in every session.
  • Usability: Participants rated ADBA as more efficient than 6-digit-PIN and more memorable than both PIN conditions, despite credible intervals including zero.
  • Usability: ADBA had the lowest perceived task load (M=14.5, SD=9.5), with moderate evidence of lower workload than 6-Digit-PIN and Random-PIN.

6 Discussion

ADBA improved memorability, perceived efficiency, and task load relative to PIN-based methods, despite longer objective entry times. Its randomized digit representations offered security benefits, although environment-specific password homogeneity remains a concern.

  • Memorability: ADBA demonstrated superior memorability over PIN-based methods across subjective and objective measures.The authors attribute this partly to picture superiority and reduced interference between distinct environments.
  • Memorability: ADBA reduced confusion between passwords by using distinct environments rather than reusing the same ten digits across positions.The authors suggest distinct environments may also help users distinguish passwords across different accounts.
  • Memorability: The 6-digit PIN condition did not produce better memorability than the Random-PIN condition, likely because users selected weak patterned sequences.Random-PIN participants appeared more deliberate and attentive when memorizing their passwords.
  • Efficiency: ADBA required more time for correct entry than PIN-based methods, yet participants rated it as more efficient than the 6-Digit-PIN.No participants switched to digit entry, even though ADBA offered that alternative.
  • Security: ADBA offers 10^6 possible combinations and randomly generated digit representations, reducing the convenience-based creation of trivial or predictable sequences.Observation resistance was not directly measured, and password homogeneity in some environments could increase predictability.
  • Usability and Task Load: ADBA produced lower perceived task load than PIN-based methods, especially the 6-Digit-PIN, despite higher physical demand from turning and searching.Lower mental demand was primarily associated with better memorability, while perceived performance exceeded 6-Digit-PIN but not Random-PIN.

7 Limitations and Future Work

The study’s conclusions are bounded by its comparison design, remote uncontrolled setting, constrained authentication frequencies, participant demographics, and user-selected PIN assumptions. Future work should test broader usage scenarios and develop environments that reduce password homogeneity.

  • Study Design: Because DBA was not included as a study condition, improvements over the predecessor remain inferential rather than statistically validated.The study prioritized practical adoptability against widely used 6-digit PINs in ecologically valid settings.
  • Study Design: The remote design improved ecological validity but limited procedural control and the amount of data collected.Participants were unobserved during the study.
  • Generalizability: User-selected PIN requirements supported fair comparisons and privacy, but may limit generalizability because real-world users may choose insecure PINs for memorability.The boundary concerns scenarios where users select passwords under ordinary real-world conditions.
  • Generalizability: The examined low and high authentication frequencies may not represent usage occurring multiple times per day or weeks apart.The frequency range was constrained by study logistics.
  • Generalizability: The limited sample size and gender imbalance may affect generalizability despite coverage across different age groups.Demographic controls were limited by the practical demands of a remote longitudinal study requiring personal VR access.
  • Future Work: Future research should develop reliable environment-selection or generation methods that promote diverse directional preferences and mitigate password homogeneity.The authors identify password homogeneity as ADBA’s primary limitation.

8 Conclusion

The paper introduces ADBA as a VR authentication method that separates memorability and efficiency needs over time. In a longitudinal comparison with PIN methods, ADBA improved memorability, perceived efficiency, and task load, while retaining security benefits subject to environment-specific homogeneity.

  • Conclusion: ADBA enforces context-based password creation while supporting both context-based and digit-based authentication entry.This design decouples users’ memorability and efficiency needs temporally.
  • Conclusion: ADBA outperformed widely used PIN-based methods in memorability, perceived efficiency, and overall task load despite longer password-entry times.The conclusion reports these advantages from a remote longitudinal study with varying entry-frequency periods.
  • Conclusion: ADBA provided security benefits through randomly generated digit representations, but users’ context-direction choices showed varying degrees of environment-dependent homogeneity.The authors identify reliable environment selection as an important direction for future validation.
Loading 2608.29531v1…