What are graphical passwords?
- Graphical Passwords = Visual Passwords
Three main classes
- Recall-Based Systems: drawing your passwords
- Recognition-Based Systems: remember your pass-pictures
- Cued-Recall Systems: remember your pass-points (in a picture)
Two surveys you can read to learn more:
- Robert Biddle, Sonia Chiasson and P. C. van Oorschot, "Graphical Passwords: Learning from the First Twelve Years," ACM Computing Surveys, vol. 44, no. 4, Article No. 19, ACM, August 2012
- Xiaoyuan Suo, Ying Zhu and G. Scott Owen, "Graphical Passwords: A Survey," in Proceedings of the 21st Annual Computer Security Applications Conference (ACSAC 2005), IEEE Computer Society, 2005
Why do we need graphical passwords?
Selected graphical password schemes
More Graphical Password Schemes: KeyWalker

Are graphical passwords really so good?
Unfortunately, the answer is no.-
Users' choices of pass-pictures in recognition-based systems are not random!
Users' drawings in recall-based systems are not random, either!
There are hotspots in cued-recall systems! => Dictionary attacks still work!
Dictionary attacks still work on recall-based systems as well!
"The cognitive aspects of visual information processing would appear to make the use of spatial position untenablefor authentication systems."
What has Shujun Li been doing on graphical passwords?
Cryptanalysis of graphical password systems against passive observers
Hassan Jameel Asghar, Shujun Li, Ron Steinfeld and Josef Pieprzyk, "Does Counting Still Count? Revisiting the Security of Counting based User Authentication Protocols against Statistical Attacks," in Proceedings of 20th Annual Network & Distributed System Security Symposium (NDSS 2013), Internet Society, 2013 (Acceptance rate: 47/250=18.8%)
New designs of secure human-computer interface (SecHCI) against observation attacks and graphical implementations
Shujun Li and Heung-Yeung Shum, "Secure Human-Computer Identification against Peeping Attacks (SecHCI): A Survey," technical report, Jan. 2003 (an early version has been published online in Elesevier Science's Comuter Science Preprint Archive, vol. 2003, no. 1, pp. 5-57, 2003)
Shujun Li and Heung-Yeung Shum, "Secure Human-Computer Identification (Interface) Systems against Peeping Attacks: SecHCI," IACR's Cryptology ePrint Archive: Report 2005/268, received on 12 Aug 2005 (an early version has been appeared online in Elesevier Science's Comuter Science Preprint Archive, vol. 2004, no. 3, pp. 21-69, 2004)
- Design of new graphical passwords based on fractals and other interesting stuff (ongoing research)
- Combine graphical passwords with other computer security applications (ongoing research)
- Password checker for graphical passwords