【24h】

Naturally Rehearsing Passwords

机译:自然排练密码

获取原文

摘要

We introduce quantitative usability and security models to guide the design of password management schemes - systematic strategies to help users create and remember multiple passwords. In the same way that security proofs in cryptography are based on complexity-theoretic assumptions (e.g., hardness of factoring and discrete logarithm), we quantify usability by introducing usability assumptions. In particular, password management relies on assumptions about human memory, e.g., that a user who follows a particular rehearsal schedule will successfully maintain the corresponding memory. These assumptions are informed by research in cognitive science and can be tested empirically. Given rehearsal requirements and a user's visitation schedule for each account, we use the total number of extra rehearsals that the user would have to do to remember all of his passwords as a measure of the usability of the password scheme. Our usability model leads us to a key observation: password reuse benefits users not only by reducing the number of passwords that the user has to memorize, but more importantly by increasing the natural rehearsal rate for each password. We also present a security model which accounts for the complexity of password management with multiple accounts and associated threats, including online, offline, and plaintext password leak attacks. Observing that current password management schemes are either insecure or unusable, we present Shared Cues - a new scheme in which the underlying secret is strategically shared across accounts to ensure that most rehearsal requirements are satisfied naturally while simultaneously providing strong security. The construction uses the Chinese Remainder Theorem to achieve these competing goals.
机译:我们介绍定量可用性和安全模型,以指导密码管理方案的设计 - 系统策略,以帮助用户创建和记住多个密码。以相同的方式,加密中的安全性证明基于复杂性 - 理论假设(例如,考虑和离散对数的硬度),我们通过引入可用性假设来量化可用性。特别是,密码管理依赖于关于人类内存的假设,例如,遵循特定排练计划的用户将成功维护相应的内存。这些假设通过认知科学的研究通知,并且可以经验测试。给定每个帐户的排练要求和用户的探讨时间表,我们使用用户必须要记住所有密码作为密码方案可用性的衡量标准的总数。我们的可用性模型将我们引导我们的关键观察:密码重复使用不仅通过减少用户必须记忆的密码数量,而且更重要的是通过提高每个密码的自然排练率更重要。我们还提出了一种安全模型,其考虑了密码管理的复杂性,其中包含多个帐户和相关威胁,包括在线,脱机和明文密码泄漏攻击。观察当前密码管理方案是不可思议的或不可用的,我们呈现共享提示 - 一种新的计划,其中基础秘密在战略上共享账户,以确保自然地满足大多数排练要求,同时提供强大的安全性。建筑利用中国剩余的定理来实现这些竞争目标。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号