首页> 外文学位 >A system-generated password and mnemonic approach to optimize the security and usability of text-based passwords.
【24h】

A system-generated password and mnemonic approach to optimize the security and usability of text-based passwords.

机译:系统生成的密码和助记符方法,用于优化基于文本的密码的安全性和可用性。

获取原文
获取原文并翻译 | 示例

摘要

In this study a novel password generation policy called the system-generated password and mnemonic was designed and implemented. The intent of this policy was to optimize both the security and usability of text-based passwords. After implementing the policy we evaluated its usability and compared it with three other existing policies: user-generated password, system-generated password and user-generated mnemonic for a system-generated password. In order to have a fair comparison among the policies we maintained a constant level of security of 30+/-2 entropy as dictated by NIST level 2 standards.;The study involved 64 participants, equally divided into four groups, 16 in each password policy condition. The study took place over two sessions, with a period of 5--7 days in between them. In the first session, depending on the password policy condition, the participants were either assigned or asked to create a password. The participants were then asked to recall their passwords in the same session and after 5--7 days in the second session. The four password policy conditions were compared with respect to the following dependent variables: the time taken to create the password account, the password creation error rate, the time taken to recall and recall error rates for both sessions, unrecoverable passwords in the second session, proximity of the recalled password to the stored password as measured by the Damerau-Levenshtein and Jaro-Winkler edit distances; and the subjective ratings for the NASA task load indices and the System Usability Scale questionnaire.;There was a significant effect of password policy condition on the time taken to create a password account and for the performance index of the NASA-TLX questionnaire. Across the task sessions, there were statistically significant differences for the time taken to recall the password, recall error rates, the performance index of the NASA-TLX questionnaire and the SUS score. There were no significant differences for creation error rates, creation SUS, recall error rates and unrecoverable passwords among the password policy conditions.;The results of this study suggest that overall performance was better for the user-generated policies (user-generated password and system-generated password along with a user-generated mnemonic) than for the system-generated policies (system-generated password and system-generated password and mnemonic). One of the reasons for this result might be that the direct involvement of the user in generating the password or mnemonic enhances their memorability. Other reasons mentioned by the users were that the system-generated mnemonic policy was complex and employed difficult words which were difficult to memorize and thus recollect. As a result of conducting this experiment it is concluded that user-generated policies are better in terms of usability and memorability than system-generated passwords. However, the user feedback recorded in this study suggests a number of approaches for improving the usability of system-generated password policies.
机译:在这项研究中,设计并实现了一种新颖的密码生成策略,称为系统生成的密码和助记符。该策略的目的是优化基于文本的密码的安全性和可用性。实施该策略后,我们评估了其可用性并将其与其他三个现有策略进行了比较:用户生成的密码,系统生成的密码和用户生成的针对系统生成的密码的助记符。为了在政策之间进行公平的比较,我们按照NIST 2级标准将安全性维持在30 +/- 2熵的恒定水平。该研究涉及64位参与者,分为4组,每组密码策略16位健康)状况。该研究历时两届,为期五至七天。在第一个会话中,根据密码策略条件,分配或要求参与者创建密码。然后,要求参与者在同一会话中以及第二会话的5--7天后恢复其密码。针对以下因变量比较了四种密码策略条件:创建密码帐户所需的时间,密码创建错误率,两个会话的重调用和重调用错误率所花费的时间,第二个会话中不可恢复的密码,由Damerau-Levenshtein和Jaro-Winkler编辑距离测量的召回密码与存储密码的接近程度; NASA任务负载指数和系统可用性量表调查表的主观评分。密码策略条件对创建密码帐户所花费的时间和NASA-TLX调查表的性能指数有显着影响。在整个任务会话中,召回密码,召回错误率,NASA-TLX调查问卷的性能指标和SUS得分所花费的时间在统计上存在显着差异。密码策略条件之间的创建错误率,创建SUS,召回错误率和不可恢复的密码没有显着差异。这项研究的结果表明,用户生成的策略(用户生成的密码和系统的整体性能更好)生成的密码以及用户生成的助记符),而不是系统生成的策略(系统生成的密码以及系统生成的密码和助记符)。此结果的原因之一可能是用户直接参与生成密码或助记符会增强其记忆力。用户提到的其他原因是系统生成的助记符策略很复杂,并且使用了难以记忆的难以记忆的单词。进行此实验的结果是,可以得出结论,就可用性和记忆性而言,用户生成的策略比系统生成的密码更好。但是,此研究中记录的用户反馈建议了许多方法来改善系统生成的密码策略的可用性。

著录项

  • 作者

    Ranganayakulu, Sanjaykumar.;

  • 作者单位

    Clemson University.;

  • 授予单位 Clemson University.;
  • 学科 Information Technology.;Engineering Industrial.
  • 学位 M.S.
  • 年度 2012
  • 页码 112 p.
  • 总页数 112
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

  • 入库时间 2022-08-17 11:43:24

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号