首页> 外文会议>Americas conference on information systems;AMCIS 2005 >The Effectiveness and Usabilityof Passphrases for Authentication
【24h】

The Effectiveness and Usabilityof Passphrases for Authentication

机译:验证密码短语的有效性和可用性

获取原文

摘要

In developing password policies, IT managers must strike a balance between security and memorability. Rules that improvestructural integrity against attacks (e.g., increasing length and multiple character types) may also result in passwords that aredifficult to remember. Recent technologies have relaxed the 8-character password constraint – permitting the creation oflonger pass-“phrases” consisting of multiple words. Psychology theories suggest users can remember passphrases at least aswell as passwords. This paper reports an experiment currently in progress that tests the usability of passphrases. Subjects arerandomly assigned to three different password creation techniques: a control group with no constraints, a secure group givenstrong password requirements, and a passphrase group. It is expected that the passphrases group will have fewer failed loginattempts than the secure group and no more failed login attempts than the control group. Practical implications includestronger authentication with reduced help desk costs.
机译:在制定密码策略时,IT管理员必须在安全性和可记忆性之间取得平衡。改进针对攻击的结构完整性的规则(例如,增加长度和多种字符类型)也可能导致密码难以记住。最新技术已放宽了8个字符的密码限制,从而允许创建由多个单词组成的更长的通行短语。心理学理论认为,用户至少可以记住密码以及密码。本文报告了一个正在进行的测试密码短语可用性的实验。主题被随机分配给三种不同的密码创建技术:无限制的控制组,具有严格密码要求的安全组和密码组。预计密码短语组的失败登录尝试次数将少于安全组,并且失败的登录尝试次数不会多于控制组。实际的含义包括更强的身份验证和更低的帮助台成本。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号