【24h】

Grid Authentication: A Memorability and User Sentiment Study

机译:网格身份验证:记忆性和用户情感研究

获取原文

摘要

Despite being one of the most crucial parts of online transactions, the most used authentication system, the username and password system, has shown to be weaker than ever. With the increase of processing power within computers, offline password attacks such as dictionary attacks, rainbow tables, and hash tables have become more effective against divulging account information from stolen databases. This has led to alternative solutions being proposed, such as logging in with a social media account or password managers, which do not replace the password entirely. Graphical alternatives have previously proposed, but none of them have become widely used. In a previous paper we proposed our own alternative called 'Grid Authentication', which would allow users to authenticate using a sequence of clicks on a colored Grid, shown to be resistant against offline password attacks. Now we have implemented and tested Grid Authentication's memorability and recorded user sentiment data. Participants logged in using a newly created password, an 8-character password randomly generated for them, as well as used Grid Authentication scheme for three days each, once per day. We found that overall, Grid Authentication's memorability was like a user chosen password, and far superior to the randomly generated 8-character password. We also observed that user's overall sentiment towards Grid Authentication increased significantly after three days of regular use. Despite this, while sentiment over the system was overall positive, users perceived that they remembered the password more easily, perhaps given hints as to why alternative authentication types have not become widely used.
机译:尽管它是在线交易中最关键的部分之一,但最常用的身份验证系统(用户名和密码系统)显示出比以往任何时候都弱的身份。随着计算机内部处理能力的增强,脱机密码攻击(例如字典攻击,彩虹表和哈希表)已变得更加有效,可以防止从被盗数据库中泄露帐户信息。这导致提出了替代解决方案,例如使用社交媒体帐户或密码管理器登录,但不能完全替换密码。先前已经提出了图形替代方案,但是它们都没有被广泛使用。在先前的论文中,我们提出了自己的替代方法,称为“网格身份验证”,该方法将允许用户使用在彩色网格上的一系列单击来进行身份验证,这表明可以抵抗脱机密码攻击。现在,我们已经实现并测试了Grid Authentication的可记忆性并记录了用户情感数据。参与者使用新创建的密码,为他们随机生成的8个字符的密码以及每天三天,每三天使用的网格身份验证方案登录。我们发现,总体而言,Grid Authentication的记忆力就像用户选择的密码,并且远远优于随机生成的8个字符的密码。我们还观察到,在常规使用三天后,用户对网格身份验证的总体感觉大大提高了。尽管如此,尽管总体上对该系统的看法是积极的,但用户仍认为他们更容易记住密码,这可能暗示了为什么其他身份验证类型没有得到广泛使用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号