首页> 外文会议>International Conference on Computational Intelligence and Security >CombinedPWD: A New Password Authentication Mechanism Using Separators Between Keystrokes
【24h】

CombinedPWD: A New Password Authentication Mechanism Using Separators Between Keystrokes

机译:contactpwwd:使用击键之间的分隔符的新密码身份验证机制

获取原文

摘要

The password security has been paid much attention to by many scholars. The conventional password cracking methods are based on probabilistic models leveraging the leaked password datasets. In order to reduce this risk, our study proposes a new online password authentication mechanism, combinedPWD, through inserting separators (e.g. blanks) into the passwords to strengthen the existing password authentication system. This scheme utilizes the custom of users' input. In our research, website users can insert spaces in their password where they want to pause when they register an account and the website back-end records the number of spaces in every gap. Only input the correct password and the corresponding number of separators matching accounts to be admitted into the system. Any trials with wrong password or correct password but with a wrong number of spaces will be rejected by the system. Through the experiments verification, the proposed mechanism can resist brute force attack and dictionary attack effectively. To avoid keyloggers, we further propose to use two-dimensional code to store the encrypted password. And this scheme has better operability and security.
机译:密码安全已经受到许多学者的关注。传统的密码开裂方法基于利用泄漏的密码数据集的概率模型。为了减少这种风险,我们的研究通过将分隔符(例如空白)插入密码来加强现有密码认证系统的密码,提出了新的在线密码身份验证机制,COMPANDPWD。该方案利用用户输入的自定义。在我们的研究中,网站用户可以在他们的密码中插入空格,在他们想要暂停时,他们在注册帐户时暂停,网站后端记录每个间隙中的空格数。只输入正确的密码和相应数量的分隔符匹配帐户即可进入系统。系统的任何试验都是错误的密码,但具有错误的空格数量的试验将被系统拒绝。通过实验验证,所提出的机制可以有效地抵抗蛮力攻击和字典攻击。为避免键盘,我们进一步建议使用二维代码来存储加密密码。该方案具有更好的可操作性和安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号