首页> 外文会议>International Conference on Network and System Security >Make mine a quadruple: Strengthening the security of graphical one-time PIN authentication
【24h】

Make mine a quadruple: Strengthening the security of graphical one-time PIN authentication

机译:让我的四重射量:加强图形一次性引脚认证的安全性

获取原文

摘要

Secure and reliable authentication is an essential prerequisite for many online systems, yet achieving this in a way which is acceptable to customers remains a challenge. GrIDsure, a one-time PIN scheme using random grids and personal patterns, has been proposed as a way to overcome some of these challenges. We present an analytical study which demonstrates that GrIDsure in its current form is vulnerable to interception. To strengthen the scheme, we propose a way to fortify GrIDsure against Man-in-the-Middle attacks through (i) an additional secret transmitted out-of-band and (ii) multiple patterns. Since the need to recall multiple patterns increases user workload, we evaluated user performance with multiple captures with 26 participants making 15 authentication attempts each over a 3-week period. In contrast with other research into the use of multiple graphical passwords, we find no significant difference in the usability of GrIDsure with single and with multiple patterns.
机译:安全可靠的身份验证是许多在线系统的必要先决条件,但以客户可接受的方式实现这一目标仍然是一个挑战。 GridSure是一种使用随机网格和个人模式的一次性引脚方案,已经提出了一种克服这些挑战的方法。我们提出了一个分析研究,表明其目前形式的网格易受拦截。为了加强该计划,我们建议通过(i)通过(i)传输带外和(ii)多种模式的额外秘密来强化网格对中间人攻击的方法。由于需要调用多个模式来增加用户工作负载,因此我们评估了用户性能,具有多个捕获,其中26名参与者在3周内,每个验证尝试都有15个认证尝试。与多种图形密码使用的其他研究相比,我们发现单个和多种模式的网格度的可用性没有显着差异。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号