ARCHIVES
Original Article
Secure Password Management in Terminal Environments Using Encrypted USB Storage to Mitigate Key logging
Intisar A. Mohamedali1
Yahia Fadlalla2
1 PhD Candidate, Faculty of Computer Science, Sudan University of Science and Technology Khartoum, Sudan. 2 Professor and Lead Researcher/Consultant InfoSec Consulting Hamilton, Ontario, Canada.
Published Online: July-August 2026
Pages: 46-55
Cite this article
↗ https://www.doi.org/10.59256/ijire.20260704008References
1. Ajibi, J. (2026). Hardware-Rooted Tri-Factor Authentication for Kernel-Enforced Ransomware Protection: TPM Attestation, Device
Fingerprinting, and Post-Quantum USB Tokens. In Zenodo (CERN European Organization for Nuclear Research). European
Organization for Nuclear Research. https://doi.org/10.5281/zenodo.18989541
2. Akshaya, N., Namrutha, M., G, N. R., & Kavitha, C. R. (2025). Secure Offline Password Manager With AES-256-GCM and Honey
Encryption for Brute-Force Attack Resilience. https://doi.org/10.1109/icact67549.2025.11351416
3. Allen, S. E., Čapkun, S., Eyal, I., Fanti, G., Ford, B., Grimmelmann, J., Juels, A., Kostiainen, K., Meiklejohn, S., Miller, A., Prasad,
E., Wüst, K., & Zhang, F. (2020). Design Choices for Central Bank Digital Currency: Policy and Technical Considerations. In National
Bureau of Economic Research. https://doi.org/10.3386/w27634
4. Alqubaisi, F., Wazan, A. S., Ahmad, L., & Chadwick, D. (2020). Should We Rush to Implement Password-less Single Factor FIDO2
based Authentication? 1–6. https://doi.org/10.1109/urc49805.2020.9099190
5. Alsultan, A., Warwick, K., & Wei, H. (2017). Non-conventional keystroke dynamics for user authentication. Pattern Recognition
Letters, 89, 53–59. https://doi.org/10.1016/j.patrec.2017.02.010
6. Bhatta, N. P., Singh, H., Ghimire, A., & Amsaad, F. (2024). Analyzing Aging Effects on SRAM PUFs: Implications for Security andReliability. Journal of Hardware and Systems Security, 8(3), 174–186. https://doi.org/10.1007/s41635-024-00154-6
7. Bintang, R. M. G. S., Arizal, Purwoko, R., Syahral, M., Zen, S. S., Putra, I. G. M., & Wijayanti, R. A. (2025). SafeUSB: Implementation
of Keystroke Monitoring System to Prevent BadUSB HID Injection Attack. 286–291.
https://doi.org/10.1109/icocics68032.2025.11383963
8. Carr, M., & Shahandashti, S. F. (2020). Revisiting Security Vulnerabilities in Commercial Password Managers. In arXiv (Cornell
University) (pp. 265–279). Cornell University. https://doi.org/10.1007/978-3-030-58201-2_18
9. Chatzoglou, E., Kampourakis, V., Tsiatsikas, Z., Καρόπουλος, Γ., & Kambourakis, G. (2024a). Keep Your Memory Dump Shut:
Unveiling Data Leaks in Password Managers. In IFIP advances in information and communication technology (pp. 61–75). Springer
Science+Business Media. https://doi.org/10.1007/978-3-031-65175-5_5
10. Chatzoglou, E., Kampourakis, V., Tsiatsikas, Z., Καρόπουλος, Γ., & Kambourakis, G. (2024b). Keep your memory dump shut:
Unveiling data leaks in password managers. In arXiv (Cornell University). Cornell University.
https://doi.org/10.48550/arxiv.2404.00423
11. Chatzoglou, E., Kampourakis, V., Tsiatsikas, Z., Καρόπουλος, Γ., & Kambourakis, G. (2024c). Unmasking the hidden credential leaks
in password managers and VPN clients. Computers & Security, 150, 104298–104298. https://doi.org/10.1016/j.cose.2024.104298
12. Condrey, D. (2026). On the Insecurity of Keystroke-Based AI Authorship Detection: Timing-Forgery Attacks Against Motor-Signal
Verification. In arXiv (Cornell University). Cornell University. https://doi.org/10.48550/arxiv.2601.17280
13. Cui, Q. (2013). Secure Storage Technology Based on Virtual File System. Microelectronics & Computer.
http://en.cnki.com.cn/Article_en/CJFDTOTAL-WXYJ201306014.htm
14. Damopoulos, D., & Kambourakis, G. (2019). Hands-Free one-Time and continuous authentication using glass wearable devices.
Journal of Information Security and Applications, 46, 138–150. https://doi.org/10.1016/j.jisa.2019.02.002
15. Data Encryption Mobile Storage Management Procedure Based on Virtual Disk. (2023). https://doi.org/10.48047/nq.2020.18.8.nq20241
16. Deshmukh, R., Petewar, P. R., Rathod, S. M., Bijwe, S. D., Pawar, V. D., & Bondre, T. S. (2024). Review on Proposal of a Password
Manager, satisfying security and Usability through “Key-Master.” International Journal of Innovative Science and Research
Technology (IJISRT), 585–590. https://doi.org/10.38124/ijisrt/ijisrt24nov975.
17. Dhar, A., Ulqinaku, E., Kostiainen, K., & Čapkun, S. (2020). ProtectIOn: Root-of-Trust for IO in Compromised Platforms (Vol. 2019,
p. 869). https://doi.org/10.14722/ndss.2020.24112
18. Dumitru, R., Genkin, D., Wabnitz, A., & Yarom, Y. (2022). The Impostor Among US(B): Off-Path Injection Attacks on USB
Communications. In arXiv (Cornell University). Cornell University. https://doi.org/10.48550/arxiv.2211.01109
19. Elelegwu, D., Chen, L., Ji, Y., & Kim, J. (2024). A Novel Approach to Detecting and Mitigating Keyloggers. 1583–1590.
https://doi.org/10.1109/southeastcon52093.2024.10500122
20. Elmaghbub, A., & Hamdaoui, B. (2024). Domain-Agnostic Hardware Fingerprinting-Based Device Identifier for Zero-Trust IoT
Security. IEEE Wireless Communications, 31(2), 42–48. https://doi.org/10.1109/mwc.001.2300420
21. Fakiha, B. S. (2024). Forensic analysis of bad USB attacks: A methodology for detecting and mitigating malicious USB device
activities. Edelweiss Applied Science and Technology, 8(5), 1090–1100. https://doi.org/10.55214/25768484.v8i5.1809
22. Fu, Y., & Wang, D. (2024). Leaky Autofill: An Empirical Study on the Privacy Threat of Password Managers’ Autofill Functionality.
288–303. https://doi.org/10.1109/acsac63791.2024.00037
23. Gangwal, A., Singh, S., & Srivastava, A. (2023). AutoSpill: Credential Leakage from Mobile Password Managers. 39–47.
https://doi.org/10.1145/3577923.3583658
24. Gao, Y., Ranasinghe, D. C., Al-Sarawi, S. F., Kavehei, O., & Abbott, D. (2015). Memristive crypto primitive for building highly secure
physical unclonable functions. Scientific Reports, 5(1), 12785–12785. https://doi.org/10.1038/srep12785
25. Gautam, A., Yadav, T., Seamons, K., & Ruoti, S. (2024). Passwords Are Meant to Be Secret: A Practical Secure Password Entry
Channel for Web Browsers. In arXiv (Cornell University). Cornell University. https://doi.org/10.48550/arxiv.2402.06159
26. Ghosh, A., Mitra, A., Chakkaravarathy, S. S., Priya, V., Anitha, S., & Babu, R. T. S. (2024). Saila: Human Interface Device (HID)
Injection Protection with Smart Phone based Passwordless Security. 122–127. https://doi.org/10.1109/icdcsw63686.2024.00023
27. Goldberg, I., Jenkinson, G., & Stajano, F. (2016). Low-Cost Mitigation Against Cold Boot Attacks for an Authentication Token. In
Lecture notes in computer science (pp. 36–57). Springer Science+Business Media. https://doi.org/10.1007/978-3-319-39555-5_3
28. Griscioli, F., & Pizzonia, M. (2018). USBCaptchaIn: Preventing (Un)Conventional Attacks from Promiscuously\n Used USB Devices
in Industrial Control Systems. In arXiv (Cornell University). Cornell University. https://doi.org/10.48550/arxiv.1810.05005
29. Griscioli, F., & Pizzonia, M. (2021). USBCaptchaIn: Preventing (un)conventional attacks from promiscuously used USB devices in
industrial control systems. Iris (Roma Tre University). https://doi.org/10.3233/jcs-191404
30. Guo-song, F. (2012). A Design of Security USB2.0 Device Controller. Jisuanji Gongcheng.
http://en.cnki.com.cn/Article_en/CJFDTOTAL-JSJC201224070.htm
31. Gurčinas, V., Dautartas, J., Janulevičius, J., Goranin, N., & Čenys, A. (2023). A Deep-Learning-Based Approach to Keystroke-
Injection Payload Generation. Electronics, 12(13), 2894–2894. https://doi.org/10.3390/electronics12132894.
32. Halderman, J. A., Schoen, S. D., Heninger, N., Clarkson, W., Paúl, W., Calandrino, J. A., Feldman, A. J., Appelbaum, J., & Felten, E.
W. (2008). Lest we remember: cold boot attacks on encryption keys. Munich Personal RePEc Archive (Ludwig Maximilian University
of Munich), 43(5), 45–60. http://library.tue.nl/csp/dare/LinkToRepository.csp?recordnumber=860730
33. He, D., Kumar, N., Lee, J., & Sherratt, R. S. (2014). Enhanced three-factor security protocol for consumer USB mass storage devices.
IEEE Transactions on Consumer Electronics, 60(1), 30–37. https://doi.org/10.1109/tce.2014.6780922
34. Hernandez, G., Fowze, F., Tian, D., Yavuz, T., & Butler, K. (2017). FirmUSB. arXiv (Cornell University), 2245–2262.
https://doi.org/10.1145/3133956.3134050
35. Huang, C., Lee, H.-M., Wang, J.-C., & Mao, C.-H. (2019). Identifying HID-based attacks through process event graph using guilt-by-
association analysis. 273–278. https://doi.org/10.1145/3309074.3309080
36. Huseynov, E. (2020). Improving user experience with TOTP hardware tokens by implementing QR codes and HID keyboard emulation.
23, 1–5. https://doi.org/10.1109/aict50176.2020.9368574
37. Ibrahim, O. A., Sciancalepore, S., Oligeri, G., & Pietro, R. D. (2020). MAGNETO. ACM Transactions on Embedded Computing
Systems, 20(1), 1–26. https://doi.org/10.1145/3422308
38. Kang, M., & Saiedian, H. (2017). USBWall: A novel security mechanism to protect against maliciously reprogrammed USB devices.
Information Security Journal A Global Perspective, 26(4), 166–185. https://doi.org/10.1080/19393555.2017.132946139. Khande, Ms. S. R. R. (2023). Prevention of code injection from Human Interface Device (HID). Zenodo (CERN European Organization
for Nuclear Research). https://doi.org/10.5281/zenodo.7795499
40. Koshiy, P. G. (2025). Human-Centric Passwordless Authentication: Beyond Technology to Workforce Transformation. International
Journal of Computational and Experimental Science and Engineering, 11(4). https://doi.org/10.22399/ijcesen.4002
41. Kutyłowski, M., Lauks-Dutka, A., Kubiak, P., & Zawada, M. (2024). FIDO2 Facing Kleptographic Threats By-Design. Applied
Sciences, 14(23), 11371–11371. https://doi.org/10.3390/app142311371
42. Liang, S., Yue, Z., Li, B., Guo, X., Jia, C., & Liu, Z. (2018). Secureweb: Protecting sensitive information through the web browser
extension with a security token. Tsinghua Science & Technology, 23(5), 526–538. https://doi.org/10.26599/tst.2018.9010015
43. Masoumian, S., Selimis, G., Wang, R., Schrijen, G.-J., Hamdioui, S., & Taouil, M. (2022). A Reliability Analysis of FinFET-Based
SRAM PUFs for 16nm, 14nm, and 7nm Technology Nodes. Research Repository (Delft University of Technology), 1189–1192.
https://doi.org/10.23919/date54114.2022.9774735
44. Meng, G. (2006). File encryption approach based on virtual disk. Jisuanji Gongcheng Yu Sheji.
https://en.cnki.com.cn/Article_en/CJFDTOTAL-SJSJ200615038.htm
45. Ness, J. (2017). Presentation Attack and Detection in Keystroke Dynamics [Vilnius University]. In BIBSYS Brage (BIBSYS
(Norway)). http://hdl.handle.net/11250/2448954
46. Neuner, S., Voyiatzis, A. G., Fotopoulos, S., Mulliner, C., & Weippl, E. (2018). USBlock: Blocking USB-Based Keypress Injection
Attacks. In Lecture notes in computer science (pp. 278–295). Springer Science+Business Media. https://doi.org/10.1007/978-3-319-
95729-6_18
47. Ni, L., & Zhang, J. (2024). S2RAM PUF: An Ultra-low Power Subthreshold SRAM PUF with Zero Bit Error Rate. 1–6.
https://doi.org/10.1145/3649329.3658246
48. Nicho, M., & Sabry, I. (2022). Threat and Vulnerability Modelling of Malicious Human Interface Devices. The Eurasia Proceedings
of Science Technology Engineering and Mathematics, 21, 241–247. https://doi.org/10.55549/epstem.1225679
49. Papadamou, K., Gevers, S., Xenakis, C., Sirivianos, M., Zannettou, S., Chifor, B., Ţeican, S., Gugulea, G., Caponi, A., Recupero, A.,
Pisa, C., & Bianchi, G. (2019). Killing the Password and Preserving Privacy With Device-Centric and Attribute-Based Authentication.
arXiv (Cornell University), 15, 2183–2193. https://doi.org/10.1109/tifs.2019.2958763
50. Patel, H. (2026). Post-Quantum Security Enhancements for WebAuthn and FIDO2 Protocols. Journal of Information Systems
Engineering & Management, 11, 853–862. https://doi.org/10.52783/jisem.v11i1s.14185
51. Pawan, V. R. (2023). Beyond Traditional Keyloggers: Developing and Detecting Advanced Keystroke Monitoring Systems. 1–6.
https://doi.org/10.1109/csitss60515.2023.10334216
52. Samanta, S., Ray, B., & Milenković, A. (2025). Analysis of Temperature Effect on SRAM PUF for Low Cost Applications. 1–7.
https://doi.org/10.1109/paine66113.2025.11320191
53. Sen, Ö., Hassan, T. M., Ulbig, A., & Henze, M. (2024). Enhancing SCADA Security: Developing a Host-Based Intrusion Detection
System to Safeguard Against Cyberattacks. In arXiv (Cornell University). Cornell University.
https://doi.org/10.48550/arxiv.2402.14599
54. Shadman, R., Wahab, A. A., Manno, M., Lukaszewski, M., Hou, D., & Hussain, F. (2025).A Keystroke Dynamics: Concepts,
Techniques, and Applications. ACM Computing Surveys, 57(11), 1–35. https://doi.org/10.1145/3733103
55. Sharma, P. (2023). Destroke. International Journal for Research in Applied Science and Engineering Technology, 11(11), 1633–1635.
https://doi.org/10.22214/ijraset.2023.56880
56. Shukla, S., Varshney, G., Singh, S., & Goel, S. (2024). A Passwordless MFA Utlizing Biometrics, Proximity and Contactless
Communication. In arXiv (Cornell University). Cornell University. https://doi.org/10.48550/arxiv.2406.09000
57. Siahaan, C. R. P., & Chowanda, A. (2022). Spoofing keystroke dynamics authentication through synthetic typing pattern extracted
from screen-recorded video. Journal Of Big Data, 9(1). https://doi.org/10.1186/s40537-022-00662-8.
58. Silver, D., Jana, S., Boneh, D., Chen, E., & Jackson, C. (2014). Password managers: attacks and defenses. 449–464.
http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.432.8172
59. Singh, N. T., Shukla, A., Nagar, A., Arya, K., Tiwari, A., & Varun, Y. (2023). Keylogger Development: Technical Aspects, Ethical
Considerations, and Mitigation Strategies. 1–5. https://doi.org/10.1109/icemce57940.2023.10434134
60. Sultan, I., & Banday, M. T. (2019). Addressing Security Issues of the Internet of Things Using Physically Unclonable Functions. In
Advances in information security, privacy, and ethics book series (pp. 95–116). IGI Global. https://doi.org/10.4018/978-1-5225-5742-
5.ch004
61. Swierczynski, P., Fyrbiak, M., Koppe, P., Moradi, A., & Paar, C. (2016). Interdiction in practice—Hardware Trojan against a high-
security USB flash drive. arXiv (Cornell University), 7(3), 199–211. https://doi.org/10.1007/s13389-016-0132-7
62. Tian, D., Scaife, N., Bates, A., Butler, K., & Traynor, P. (2016). Making {USB} Great Again with {USBFILTER}. USENIX Security
Symposium, 415–430. https://atc.usenix.org/system/files/conference/usenixsecurity16/sec16_paper_tian.pdf
63. Tritilanunt, S., Thanyamanorot, N., & Ritdecha, N. (2014). A secure authentication protocol using HOTP on USB storage devices. 17,
1908–1912. https://doi.org/10.1109/infoseee.2014.6946255
64. Varshney, G., Misra, M., & Atrey, P. K. (2017). Detecting Spying and Fraud Browser Extensions. 45–52.
https://doi.org/10.1145/3137616.3137619
65. Vella, M., Colombo, C., Abela, R., & Špaček, P. (2021). RV-TEE: secure cryptographic protocol execution based on runtime
verification. Journal of Computer Virology and Hacking Techniques, 17(3), 229–248. https://doi.org/10.1007/s11416-021-00391-1
66. Wang, X., Han, Z., & Zhang, D. (2012). IDKeeper: A Web Password Manager with Roaming Capability Based on USB Key. 1228–
1231. https://doi.org/10.1109/icicee.2012.326
67. Williams, S., Khalil, K., & Bayoumi, M. (2024). A Novel 0.04 pJ/bit Dynamic TRNG using Bit Reconfigurable Ring Oscillators. 1546–
1552. https://doi.org/10.1109/southeastcon52093.2024.10500289
68. Xiao, K., Rahman, M. T., Forte, D., Huang, Y., Su, M., & Tehranipoor, M. (2014). Bit selection algorithm suitable for high-volume
production of SRAM-PUF. 101–106. https://doi.org/10.1109/hst.2014.6855578
69. Xu, M., Ng, W. C., Lim, W. Y. B., Kang, J., Xiong, Z., Niyato, D., Yang, Q., Shen, X., & Miao, C. (2022). A Full Dive Into Realizing
the Edge-Enabled Metaverse: Visions, Enabling Technologies, and Challenges. IEEE Communications Surveys & Tutorials, 25(1),
656–700. https://doi.org/10.1109/comst.2022.3221119
70. Yadav, D. (2025). Duck Hunter: Encountering USB Rubber Ducky Threat. International Journal for Research in Applied Science andEngineering Technology, 13(6), 2580–2587. https://doi.org/10.22214/ijraset.2025.72679
71. Yadav, R. K., & Patel, S. C. (2026). Tamper-Resistant USB Storage Device using BLAKE3 Hashing. In Research Square.
https://doi.org/10.21203/rs.3.rs-8415630/v1.
72. Yamauchi, T., Akao, Y., Yoshitani, R., Nakamura, Y., & Hashimoto, M. (2020). Additional kernel observer: privilege escalation attack
prevention mechanism focusing on system call privilege changes. International Journal of Information Security, 20(4), 461–473.
https://doi.org/10.1007/s10207-020-00514-7
73. Zhou, Z. (2014). On-demand Isolated I/O for Security-sensitive Applications on Commodity Platforms. Research Showcase @
Carnegie Mellon University (Carnegie Mellon University). https://doi.org/10.1184/r1/6720932
74. Zuyeva, Y. A., Pyrkova, A., Saparbayev, A., Makulova, A., & Ordabayeva, G. (2022).
75. Devising an approach to analyze the parameters for determining potential premodified firmware of USB devices. Eastern-European
Journal of Enterprise Technologies, 6, 51–58. https://doi.org/10.15587/1729-4061.2022.269031.
Fingerprinting, and Post-Quantum USB Tokens. In Zenodo (CERN European Organization for Nuclear Research). European
Organization for Nuclear Research. https://doi.org/10.5281/zenodo.18989541
2. Akshaya, N., Namrutha, M., G, N. R., & Kavitha, C. R. (2025). Secure Offline Password Manager With AES-256-GCM and Honey
Encryption for Brute-Force Attack Resilience. https://doi.org/10.1109/icact67549.2025.11351416
3. Allen, S. E., Čapkun, S., Eyal, I., Fanti, G., Ford, B., Grimmelmann, J., Juels, A., Kostiainen, K., Meiklejohn, S., Miller, A., Prasad,
E., Wüst, K., & Zhang, F. (2020). Design Choices for Central Bank Digital Currency: Policy and Technical Considerations. In National
Bureau of Economic Research. https://doi.org/10.3386/w27634
4. Alqubaisi, F., Wazan, A. S., Ahmad, L., & Chadwick, D. (2020). Should We Rush to Implement Password-less Single Factor FIDO2
based Authentication? 1–6. https://doi.org/10.1109/urc49805.2020.9099190
5. Alsultan, A., Warwick, K., & Wei, H. (2017). Non-conventional keystroke dynamics for user authentication. Pattern Recognition
Letters, 89, 53–59. https://doi.org/10.1016/j.patrec.2017.02.010
6. Bhatta, N. P., Singh, H., Ghimire, A., & Amsaad, F. (2024). Analyzing Aging Effects on SRAM PUFs: Implications for Security andReliability. Journal of Hardware and Systems Security, 8(3), 174–186. https://doi.org/10.1007/s41635-024-00154-6
7. Bintang, R. M. G. S., Arizal, Purwoko, R., Syahral, M., Zen, S. S., Putra, I. G. M., & Wijayanti, R. A. (2025). SafeUSB: Implementation
of Keystroke Monitoring System to Prevent BadUSB HID Injection Attack. 286–291.
https://doi.org/10.1109/icocics68032.2025.11383963
8. Carr, M., & Shahandashti, S. F. (2020). Revisiting Security Vulnerabilities in Commercial Password Managers. In arXiv (Cornell
University) (pp. 265–279). Cornell University. https://doi.org/10.1007/978-3-030-58201-2_18
9. Chatzoglou, E., Kampourakis, V., Tsiatsikas, Z., Καρόπουλος, Γ., & Kambourakis, G. (2024a). Keep Your Memory Dump Shut:
Unveiling Data Leaks in Password Managers. In IFIP advances in information and communication technology (pp. 61–75). Springer
Science+Business Media. https://doi.org/10.1007/978-3-031-65175-5_5
10. Chatzoglou, E., Kampourakis, V., Tsiatsikas, Z., Καρόπουλος, Γ., & Kambourakis, G. (2024b). Keep your memory dump shut:
Unveiling data leaks in password managers. In arXiv (Cornell University). Cornell University.
https://doi.org/10.48550/arxiv.2404.00423
11. Chatzoglou, E., Kampourakis, V., Tsiatsikas, Z., Καρόπουλος, Γ., & Kambourakis, G. (2024c). Unmasking the hidden credential leaks
in password managers and VPN clients. Computers & Security, 150, 104298–104298. https://doi.org/10.1016/j.cose.2024.104298
12. Condrey, D. (2026). On the Insecurity of Keystroke-Based AI Authorship Detection: Timing-Forgery Attacks Against Motor-Signal
Verification. In arXiv (Cornell University). Cornell University. https://doi.org/10.48550/arxiv.2601.17280
13. Cui, Q. (2013). Secure Storage Technology Based on Virtual File System. Microelectronics & Computer.
http://en.cnki.com.cn/Article_en/CJFDTOTAL-WXYJ201306014.htm
14. Damopoulos, D., & Kambourakis, G. (2019). Hands-Free one-Time and continuous authentication using glass wearable devices.
Journal of Information Security and Applications, 46, 138–150. https://doi.org/10.1016/j.jisa.2019.02.002
15. Data Encryption Mobile Storage Management Procedure Based on Virtual Disk. (2023). https://doi.org/10.48047/nq.2020.18.8.nq20241
16. Deshmukh, R., Petewar, P. R., Rathod, S. M., Bijwe, S. D., Pawar, V. D., & Bondre, T. S. (2024). Review on Proposal of a Password
Manager, satisfying security and Usability through “Key-Master.” International Journal of Innovative Science and Research
Technology (IJISRT), 585–590. https://doi.org/10.38124/ijisrt/ijisrt24nov975.
17. Dhar, A., Ulqinaku, E., Kostiainen, K., & Čapkun, S. (2020). ProtectIOn: Root-of-Trust for IO in Compromised Platforms (Vol. 2019,
p. 869). https://doi.org/10.14722/ndss.2020.24112
18. Dumitru, R., Genkin, D., Wabnitz, A., & Yarom, Y. (2022). The Impostor Among US(B): Off-Path Injection Attacks on USB
Communications. In arXiv (Cornell University). Cornell University. https://doi.org/10.48550/arxiv.2211.01109
19. Elelegwu, D., Chen, L., Ji, Y., & Kim, J. (2024). A Novel Approach to Detecting and Mitigating Keyloggers. 1583–1590.
https://doi.org/10.1109/southeastcon52093.2024.10500122
20. Elmaghbub, A., & Hamdaoui, B. (2024). Domain-Agnostic Hardware Fingerprinting-Based Device Identifier for Zero-Trust IoT
Security. IEEE Wireless Communications, 31(2), 42–48. https://doi.org/10.1109/mwc.001.2300420
21. Fakiha, B. S. (2024). Forensic analysis of bad USB attacks: A methodology for detecting and mitigating malicious USB device
activities. Edelweiss Applied Science and Technology, 8(5), 1090–1100. https://doi.org/10.55214/25768484.v8i5.1809
22. Fu, Y., & Wang, D. (2024). Leaky Autofill: An Empirical Study on the Privacy Threat of Password Managers’ Autofill Functionality.
288–303. https://doi.org/10.1109/acsac63791.2024.00037
23. Gangwal, A., Singh, S., & Srivastava, A. (2023). AutoSpill: Credential Leakage from Mobile Password Managers. 39–47.
https://doi.org/10.1145/3577923.3583658
24. Gao, Y., Ranasinghe, D. C., Al-Sarawi, S. F., Kavehei, O., & Abbott, D. (2015). Memristive crypto primitive for building highly secure
physical unclonable functions. Scientific Reports, 5(1), 12785–12785. https://doi.org/10.1038/srep12785
25. Gautam, A., Yadav, T., Seamons, K., & Ruoti, S. (2024). Passwords Are Meant to Be Secret: A Practical Secure Password Entry
Channel for Web Browsers. In arXiv (Cornell University). Cornell University. https://doi.org/10.48550/arxiv.2402.06159
26. Ghosh, A., Mitra, A., Chakkaravarathy, S. S., Priya, V., Anitha, S., & Babu, R. T. S. (2024). Saila: Human Interface Device (HID)
Injection Protection with Smart Phone based Passwordless Security. 122–127. https://doi.org/10.1109/icdcsw63686.2024.00023
27. Goldberg, I., Jenkinson, G., & Stajano, F. (2016). Low-Cost Mitigation Against Cold Boot Attacks for an Authentication Token. In
Lecture notes in computer science (pp. 36–57). Springer Science+Business Media. https://doi.org/10.1007/978-3-319-39555-5_3
28. Griscioli, F., & Pizzonia, M. (2018). USBCaptchaIn: Preventing (Un)Conventional Attacks from Promiscuously\n Used USB Devices
in Industrial Control Systems. In arXiv (Cornell University). Cornell University. https://doi.org/10.48550/arxiv.1810.05005
29. Griscioli, F., & Pizzonia, M. (2021). USBCaptchaIn: Preventing (un)conventional attacks from promiscuously used USB devices in
industrial control systems. Iris (Roma Tre University). https://doi.org/10.3233/jcs-191404
30. Guo-song, F. (2012). A Design of Security USB2.0 Device Controller. Jisuanji Gongcheng.
http://en.cnki.com.cn/Article_en/CJFDTOTAL-JSJC201224070.htm
31. Gurčinas, V., Dautartas, J., Janulevičius, J., Goranin, N., & Čenys, A. (2023). A Deep-Learning-Based Approach to Keystroke-
Injection Payload Generation. Electronics, 12(13), 2894–2894. https://doi.org/10.3390/electronics12132894.
32. Halderman, J. A., Schoen, S. D., Heninger, N., Clarkson, W., Paúl, W., Calandrino, J. A., Feldman, A. J., Appelbaum, J., & Felten, E.
W. (2008). Lest we remember: cold boot attacks on encryption keys. Munich Personal RePEc Archive (Ludwig Maximilian University
of Munich), 43(5), 45–60. http://library.tue.nl/csp/dare/LinkToRepository.csp?recordnumber=860730
33. He, D., Kumar, N., Lee, J., & Sherratt, R. S. (2014). Enhanced three-factor security protocol for consumer USB mass storage devices.
IEEE Transactions on Consumer Electronics, 60(1), 30–37. https://doi.org/10.1109/tce.2014.6780922
34. Hernandez, G., Fowze, F., Tian, D., Yavuz, T., & Butler, K. (2017). FirmUSB. arXiv (Cornell University), 2245–2262.
https://doi.org/10.1145/3133956.3134050
35. Huang, C., Lee, H.-M., Wang, J.-C., & Mao, C.-H. (2019). Identifying HID-based attacks through process event graph using guilt-by-
association analysis. 273–278. https://doi.org/10.1145/3309074.3309080
36. Huseynov, E. (2020). Improving user experience with TOTP hardware tokens by implementing QR codes and HID keyboard emulation.
23, 1–5. https://doi.org/10.1109/aict50176.2020.9368574
37. Ibrahim, O. A., Sciancalepore, S., Oligeri, G., & Pietro, R. D. (2020). MAGNETO. ACM Transactions on Embedded Computing
Systems, 20(1), 1–26. https://doi.org/10.1145/3422308
38. Kang, M., & Saiedian, H. (2017). USBWall: A novel security mechanism to protect against maliciously reprogrammed USB devices.
Information Security Journal A Global Perspective, 26(4), 166–185. https://doi.org/10.1080/19393555.2017.132946139. Khande, Ms. S. R. R. (2023). Prevention of code injection from Human Interface Device (HID). Zenodo (CERN European Organization
for Nuclear Research). https://doi.org/10.5281/zenodo.7795499
40. Koshiy, P. G. (2025). Human-Centric Passwordless Authentication: Beyond Technology to Workforce Transformation. International
Journal of Computational and Experimental Science and Engineering, 11(4). https://doi.org/10.22399/ijcesen.4002
41. Kutyłowski, M., Lauks-Dutka, A., Kubiak, P., & Zawada, M. (2024). FIDO2 Facing Kleptographic Threats By-Design. Applied
Sciences, 14(23), 11371–11371. https://doi.org/10.3390/app142311371
42. Liang, S., Yue, Z., Li, B., Guo, X., Jia, C., & Liu, Z. (2018). Secureweb: Protecting sensitive information through the web browser
extension with a security token. Tsinghua Science & Technology, 23(5), 526–538. https://doi.org/10.26599/tst.2018.9010015
43. Masoumian, S., Selimis, G., Wang, R., Schrijen, G.-J., Hamdioui, S., & Taouil, M. (2022). A Reliability Analysis of FinFET-Based
SRAM PUFs for 16nm, 14nm, and 7nm Technology Nodes. Research Repository (Delft University of Technology), 1189–1192.
https://doi.org/10.23919/date54114.2022.9774735
44. Meng, G. (2006). File encryption approach based on virtual disk. Jisuanji Gongcheng Yu Sheji.
https://en.cnki.com.cn/Article_en/CJFDTOTAL-SJSJ200615038.htm
45. Ness, J. (2017). Presentation Attack and Detection in Keystroke Dynamics [Vilnius University]. In BIBSYS Brage (BIBSYS
(Norway)). http://hdl.handle.net/11250/2448954
46. Neuner, S., Voyiatzis, A. G., Fotopoulos, S., Mulliner, C., & Weippl, E. (2018). USBlock: Blocking USB-Based Keypress Injection
Attacks. In Lecture notes in computer science (pp. 278–295). Springer Science+Business Media. https://doi.org/10.1007/978-3-319-
95729-6_18
47. Ni, L., & Zhang, J. (2024). S2RAM PUF: An Ultra-low Power Subthreshold SRAM PUF with Zero Bit Error Rate. 1–6.
https://doi.org/10.1145/3649329.3658246
48. Nicho, M., & Sabry, I. (2022). Threat and Vulnerability Modelling of Malicious Human Interface Devices. The Eurasia Proceedings
of Science Technology Engineering and Mathematics, 21, 241–247. https://doi.org/10.55549/epstem.1225679
49. Papadamou, K., Gevers, S., Xenakis, C., Sirivianos, M., Zannettou, S., Chifor, B., Ţeican, S., Gugulea, G., Caponi, A., Recupero, A.,
Pisa, C., & Bianchi, G. (2019). Killing the Password and Preserving Privacy With Device-Centric and Attribute-Based Authentication.
arXiv (Cornell University), 15, 2183–2193. https://doi.org/10.1109/tifs.2019.2958763
50. Patel, H. (2026). Post-Quantum Security Enhancements for WebAuthn and FIDO2 Protocols. Journal of Information Systems
Engineering & Management, 11, 853–862. https://doi.org/10.52783/jisem.v11i1s.14185
51. Pawan, V. R. (2023). Beyond Traditional Keyloggers: Developing and Detecting Advanced Keystroke Monitoring Systems. 1–6.
https://doi.org/10.1109/csitss60515.2023.10334216
52. Samanta, S., Ray, B., & Milenković, A. (2025). Analysis of Temperature Effect on SRAM PUF for Low Cost Applications. 1–7.
https://doi.org/10.1109/paine66113.2025.11320191
53. Sen, Ö., Hassan, T. M., Ulbig, A., & Henze, M. (2024). Enhancing SCADA Security: Developing a Host-Based Intrusion Detection
System to Safeguard Against Cyberattacks. In arXiv (Cornell University). Cornell University.
https://doi.org/10.48550/arxiv.2402.14599
54. Shadman, R., Wahab, A. A., Manno, M., Lukaszewski, M., Hou, D., & Hussain, F. (2025).A Keystroke Dynamics: Concepts,
Techniques, and Applications. ACM Computing Surveys, 57(11), 1–35. https://doi.org/10.1145/3733103
55. Sharma, P. (2023). Destroke. International Journal for Research in Applied Science and Engineering Technology, 11(11), 1633–1635.
https://doi.org/10.22214/ijraset.2023.56880
56. Shukla, S., Varshney, G., Singh, S., & Goel, S. (2024). A Passwordless MFA Utlizing Biometrics, Proximity and Contactless
Communication. In arXiv (Cornell University). Cornell University. https://doi.org/10.48550/arxiv.2406.09000
57. Siahaan, C. R. P., & Chowanda, A. (2022). Spoofing keystroke dynamics authentication through synthetic typing pattern extracted
from screen-recorded video. Journal Of Big Data, 9(1). https://doi.org/10.1186/s40537-022-00662-8.
58. Silver, D., Jana, S., Boneh, D., Chen, E., & Jackson, C. (2014). Password managers: attacks and defenses. 449–464.
http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.432.8172
59. Singh, N. T., Shukla, A., Nagar, A., Arya, K., Tiwari, A., & Varun, Y. (2023). Keylogger Development: Technical Aspects, Ethical
Considerations, and Mitigation Strategies. 1–5. https://doi.org/10.1109/icemce57940.2023.10434134
60. Sultan, I., & Banday, M. T. (2019). Addressing Security Issues of the Internet of Things Using Physically Unclonable Functions. In
Advances in information security, privacy, and ethics book series (pp. 95–116). IGI Global. https://doi.org/10.4018/978-1-5225-5742-
5.ch004
61. Swierczynski, P., Fyrbiak, M., Koppe, P., Moradi, A., & Paar, C. (2016). Interdiction in practice—Hardware Trojan against a high-
security USB flash drive. arXiv (Cornell University), 7(3), 199–211. https://doi.org/10.1007/s13389-016-0132-7
62. Tian, D., Scaife, N., Bates, A., Butler, K., & Traynor, P. (2016). Making {USB} Great Again with {USBFILTER}. USENIX Security
Symposium, 415–430. https://atc.usenix.org/system/files/conference/usenixsecurity16/sec16_paper_tian.pdf
63. Tritilanunt, S., Thanyamanorot, N., & Ritdecha, N. (2014). A secure authentication protocol using HOTP on USB storage devices. 17,
1908–1912. https://doi.org/10.1109/infoseee.2014.6946255
64. Varshney, G., Misra, M., & Atrey, P. K. (2017). Detecting Spying and Fraud Browser Extensions. 45–52.
https://doi.org/10.1145/3137616.3137619
65. Vella, M., Colombo, C., Abela, R., & Špaček, P. (2021). RV-TEE: secure cryptographic protocol execution based on runtime
verification. Journal of Computer Virology and Hacking Techniques, 17(3), 229–248. https://doi.org/10.1007/s11416-021-00391-1
66. Wang, X., Han, Z., & Zhang, D. (2012). IDKeeper: A Web Password Manager with Roaming Capability Based on USB Key. 1228–
1231. https://doi.org/10.1109/icicee.2012.326
67. Williams, S., Khalil, K., & Bayoumi, M. (2024). A Novel 0.04 pJ/bit Dynamic TRNG using Bit Reconfigurable Ring Oscillators. 1546–
1552. https://doi.org/10.1109/southeastcon52093.2024.10500289
68. Xiao, K., Rahman, M. T., Forte, D., Huang, Y., Su, M., & Tehranipoor, M. (2014). Bit selection algorithm suitable for high-volume
production of SRAM-PUF. 101–106. https://doi.org/10.1109/hst.2014.6855578
69. Xu, M., Ng, W. C., Lim, W. Y. B., Kang, J., Xiong, Z., Niyato, D., Yang, Q., Shen, X., & Miao, C. (2022). A Full Dive Into Realizing
the Edge-Enabled Metaverse: Visions, Enabling Technologies, and Challenges. IEEE Communications Surveys & Tutorials, 25(1),
656–700. https://doi.org/10.1109/comst.2022.3221119
70. Yadav, D. (2025). Duck Hunter: Encountering USB Rubber Ducky Threat. International Journal for Research in Applied Science andEngineering Technology, 13(6), 2580–2587. https://doi.org/10.22214/ijraset.2025.72679
71. Yadav, R. K., & Patel, S. C. (2026). Tamper-Resistant USB Storage Device using BLAKE3 Hashing. In Research Square.
https://doi.org/10.21203/rs.3.rs-8415630/v1.
72. Yamauchi, T., Akao, Y., Yoshitani, R., Nakamura, Y., & Hashimoto, M. (2020). Additional kernel observer: privilege escalation attack
prevention mechanism focusing on system call privilege changes. International Journal of Information Security, 20(4), 461–473.
https://doi.org/10.1007/s10207-020-00514-7
73. Zhou, Z. (2014). On-demand Isolated I/O for Security-sensitive Applications on Commodity Platforms. Research Showcase @
Carnegie Mellon University (Carnegie Mellon University). https://doi.org/10.1184/r1/6720932
74. Zuyeva, Y. A., Pyrkova, A., Saparbayev, A., Makulova, A., & Ordabayeva, G. (2022).
75. Devising an approach to analyze the parameters for determining potential premodified firmware of USB devices. Eastern-European
Journal of Enterprise Technologies, 6, 51–58. https://doi.org/10.15587/1729-4061.2022.269031.
Related Articles
2026
AI-Based Stomach Cancer Detection Using Biomarkers, Medical Images, and Voice Analysis
2026
Hydrogen-Efficient Eco-Driving and Route Planning for Fuel-Cell Electric Vehicles Using Multi-Objective Optimization Under Traffic and Terrain Uncertainty
2026
A Data-Driven Machine Learning Framework for Assessing Patent Commercial Value and Technological Significance
2026
Evaluating Student Academic Performance Through a Benchmark of Fuzzy Reasoning Models
2026
A Hybrid Soft Computing Approach for Managing Uncertainty in Data Analytics
2026
Soft Computing Approaches for Robust Analysis of Imbalanced and Noisy Data
Share Article
Or copy link
https://www.theijire.com/archives/secure-password-management-in-terminal-environments-using-encrypted-usb-storage-to-mitigate-key-logging
*Instagram doesn't support direct link sharing from web. Copy the link and share it in your Instagram story or post.