【24h】

Naturally Rehearsing Passwords

机译:自然地练习密码

获取原文

摘要

We introduce quantitative usability and security models to guide the design of password management schemes - systematic strategies to help users create and remember multiple passwords. In the same way that security proofs in cryptography are based on complexity-theoretic assumptions (e.g., hardness of factoring and discrete logarithm), we quantify usability by introducing usability assumptions. In particular, password management relies on assumptions about human memory, e.g., that a user who follows a particular rehearsal schedule will successfully maintain the corresponding memory. These assumptions are informed by research in cognitive science and can be tested empirically. Given rehearsal requirements and a user's visitation schedule for each account, we use the total number of extra rehearsals that the user would have to do to remember all of his passwords as a measure of the usability of the password scheme. Our usability model leads us to a key observation: password reuse benefits users not only by reducing the number of passwords that the user has to memorize, but more importantly by increasing the natural rehearsal rate for each password. We also present a security model which accounts for the complexity of password management with multiple accounts and associated threats, including online, offline, and plaintext password leak attacks. Observing that current password management schemes are either insecure or unusable, we present Shared Cues - a new scheme in which the underlying secret is strategically shared across accounts to ensure that most rehearsal requirements are satisfied naturally while simultaneously providing strong security. The construction uses the Chinese Remainder Theorem to achieve these competing goals.
机译:我们引入定量的可用性和安全性模型来指导密码管理方案的设计,这是帮助用户创建和记住多个密码的系统策略。就像密码学中的安全性证明基于复杂性理论假设(例如分解因式和离散对数)一样,我们通过引入可用性假设来量化可用性。特别地,密码管理依赖于关于人类记忆的假设,例如,遵循特定排练时间表的用户将成功维护相应的记忆。这些假设是根据认知科学的研究得出的,可以通过经验进行检验。给定每个帐户的排练要求和用户访问计划,我们将使用用户记住所有密码时必须进行的额外排练总数来衡量密码方案的可用性。我们的可用性模型使我们得出一个关键的观察结果:密码重用不仅通过减少用户必须记住的密码数量,而且通过提高每个密码的自然排练率,使用户受益。我们还提出了一种安全模型,该模型解决了具有多个帐户和相关威胁(包括在线,脱机和明文密码泄漏攻击)的密码管理的复杂性。观察到当前的密码管理方案不安全或不可用,我们提出了“共享提示”(Shared Cues)-一种新的方案,该策略在各个帐户之间战略性地共享基本机密,以确保自然地满足大多数排练要求,同时提供强大的安全性。该构造使用中国剩余定理来实现这些相互竞争的目标。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号