首页> 外文会议>International conference on world wide web >Security Implications of Password Discretization for Click-based Graphical Passwords
【24h】

Security Implications of Password Discretization for Click-based Graphical Passwords

机译:基于点击的图形密码的密码离散化的安全隐患

获取原文

摘要

Discretization is a standard technique used in click-based graphical passwords for tolerating input variance so that approximately correct passwords are accepted by the system. In this paper, we show for the first time that two representative discretization schemes leak a significant amount of password information, undermining the security of such graphical passwords. We exploit such information leakage for successful dictionary attacks on Persuasive Cued Click Points (PCCP), which is to date the most secure click-based graphical password scheme and was considered to be resistant to such attacks. In our experiments, our purely automated attack successfully guessed 69.2% of the passwords when Centered Discretization was used to implement PCCP, and 39.4% of the passwords when Robust Discretization was used. Each attack dictionary we used was of approximately 2~(35) entries, whereas the full password space was of 2~(43) entries. For Centered Discretization, our attack still successfully guessed 50% of the passwords when the dictionary size was reduced to approximately 2~(30) entries. Our attack is also applicable to common implementations of other click-based graphical password systems such as PassPoints and Cued Click Points - both have been extensively studied in the research communities.
机译:离散化是基于点击的图形密码中用于容忍输入差异的一种标准技术,因此系统可以接受大约正确的密码。在本文中,我们首次展示了两种代表性的离散化方案泄漏了大量的密码信息,从而破坏了这种图形密码的安全性。我们利用这种信息泄漏来成功地对有说服力的提示点击点(PCCP)进行字典攻击,这是迄今为止最安全的基于点击的图形密码方案,被认为可以抵抗此类攻击。在我们的实验中,当使用“中心离散化”实现PCCP时,我们的纯自动化攻击成功猜出了69.2%的密码,而使用“稳健离散化”时,成功猜到了39.4%的密码。我们使用的每个攻击字典大约有2〜(35)个条目,而完整的密码空间则是2〜(43)个条目。对于集中式离散化,当字典大小减小到大约2〜(30)个条目时,我们的攻击仍能成功猜出50%的密码。我们的攻击还适用于其他基于点击的图形密码系统的通用实现,例如PassPoints和Cued Click Points,它们在研究社区中都得到了广泛的研究。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号