Future Work:
The proposed Cued Click Points scheme shows promise as
a usable and memorable authentication mechanism. By
taking advantage of users’ ability to recognize images and
the memory trigger associated with seeing a new image,
CCP has advantages over PassPoints in terms of usability.
Being cued as each image is shown and having to
remember only one click-point per image appears easier
than having to remember an ordered series of clicks on
one image. In our small comparison group, users strongly
preferred CCP.We believe that CCP offers a more secure
alternative to PassPoints. CCP increases the workload for
attackers by forcing them to first acquire image sets for
each user, and then conduct hotspot analysis on each of
these images. Furthermore, the system’s flexibility to
increase the overall number of images in the system
allows us to arbitrarily increase this workload. Future
work should include a thorough assessment of the
viability of CCP as an authentication mechanism,
including a long term study of how these passwords work
in practice and whether longer CCP passwords would be
usable.The security of CCP also deserves closer
examination, and should address how attackers might
exploit the emergence of hotspots.