首页> 外文会议>Annual Conference on Privacy, Security and Trust >System-Assigned Passwords You Can’t Write Down, But Don’t Need To
【24h】

System-Assigned Passwords You Can’t Write Down, But Don’t Need To

机译:您无法写下但不需要的系统分配的密码

获取原文

摘要

We explore the feasibility of Tacit Secrets: systemassigned passwords that you can remember, but cannot write down or otherwise communicate. We design an approach to creating Tacit Secrets based on Contextual Cueing, an implicit learning method previously studied in the cognitive psychology literature. Our feasibility study involving 30 participants indicates that our approach has strong security properties: resistance to brute-force attacks, online attacks, phishing attacks, and some coercion attacks. It also offers protection against leaks from other verifiers as the secrets are system-assigned. Our approach also has a high login success rate and low false positive rates. We explore the trade-offs of different configurations of our design and provide insight into valuable directions for future work.
机译:我们探讨了“默认秘密”的可行性:您可以记住但不能写下或以其他方式交流的系统分配的密码。我们设计了一种基于上下文提示来创建默认秘密的方法,上下文提示是先前在认知心理学文献中研究的一种隐式学习方法。我们的30名参与者的可行性研究表明,我们的方法具有很强的安全性:抵抗暴力攻击,在线攻击,网络钓鱼攻击和某些强制攻击。由于机密是系统分配的,因此它还提供了防止其他验证程序泄漏的保护措施。我们的方法还具有较高的登录成功率和较低的误报率。我们探索了设计的不同配置之间的权衡,并为以后的工作提供了有价值的方向的见解。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号