首页> 外文期刊>Computers & Security >EvoPass: Evolvable graphical password against shoulder-surfing attacks
【24h】

EvoPass: Evolvable graphical password against shoulder-surfing attacks

机译:EvoPass:可扩展的图形密码,可抵御肩膀冲浪攻击

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

The passwords for authenticating users are susceptible to shoulder-surfing attacks in which attackers learn users' passwords through direct observations without any technical support. A straightforward solution to defend against such attacks is to change passwords periodically or even constantly, making the previously observed passwords useless. However, this may lead to a situation in which users run out of strong passwords they can remember, or they are forced to choose passwords that are weak, correlated, or difficult to memorize. To achieve both security and usability in user authentication, we propose EvoPass, the first evolvable graphical password authentication system. EvoPass transforms a set of user-selected pass images to pass sketches as user credentials. Users are required to identify their pass sketches from a set of challenge images for user authentication. Particularly, EvoPass improves password strength gradually over time through continually degrading pass sketches without annoying users to reselect pass images. The evolving feature makes it difficult for observational adversaries to identify the pass sketches, even though part of pass sketches may have been exposed to adversaries previously. We introduce two metrics, Information Retention Rate (IRR) and Password Diversity Score (PDS) to guide the process of generating pass sketches and a set of challenge images. Our experimental analysis reveals that applying reasonable IRR and PDS in EvoPass can remarkably improve the resistance to shoulder-surfing attacks without negatively affecting user experience. We also implement a prototype of EvoPass on Android platform with reasonable IRR and PDS applied. Our experimental results on the prototype further demonstrate that EvoPass could work efficiently and achieve a desired usability.
机译:用于验证用户身份的密码易受肩膀冲浪攻击的攻击,攻击者无需任何技术支持即可通过直接观察来学习用户的密码。防御此类攻击的一种直接解决方案是定期甚至持续更改密码,从而使以前观察到的密码无用。但是,这可能会导致以下情况:用户用尽了他们可以记住的强密码,或者被迫选择弱,关联或难以记忆的密码。为了实现用户身份验证的安全性和可用性,我们提出了EvoPass,这是第一个可发展的图形密码身份验证系统。 EvoPass转换一组用户选择的传递图像,以传递草图作为用户凭证。要求用户从一组挑战图像中识别出通行草图,以进行用户身份验证。特别是,EvoPass通过不断降低通行草图的质量,随着时间的推移逐渐提高了密码强度,而不会惹恼用户重新选择通行图像。不断发展的功能使观察对手很难识别通过草图,即使通过草图的一部分以前可能已经暴露给对手。我们引入了两个指标,信息保留率(IRR)和密码多样性分数(PDS),以指导生成通行证草图和一组挑战图像的过程。我们的实验分析表明,在EvoPass中应用合理的IRR和PDS可以显着提高抵抗肩膀冲浪攻击的能力,而不会对用户体验产生负面影响。我们还在Android平台上实现了EvoPass的原型,并应用了合理的IRR和PDS。我们在原型上的实验结果进一步证明,EvoPass可以有效地工作并实现所需的可用性。

著录项

  • 来源
    《Computers & Security》 |2017年第9期|179-198|共20页
  • 作者单位

    Secure Mobile Centre, School of Information Systems, Singapore Management University, Singapore;

    RealTime Invent, Inc., China;

    Secure Mobile Centre, School of Information Systems, Singapore Management University, Singapore;

    College of Information Science and Technology, Beijing Normal University, China,School of Computer and Control Engineering, University of Chinese Academy of Sciences, China;

    Data Assurance and Communication Security Research Center, Chinese Academy of Sciences, China,State Key Laboratory of Information Security, Institute of Information Engineering, Chinese Academy of Sciences, China;

    Data Assurance and Communication Security Research Center, Chinese Academy of Sciences, China,State Key Laboratory of Information Security, Institute of Information Engineering, Chinese Academy of Sciences, China;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Authentication security; Graphical password; Shoulder-surfing; Evolvable; Time-evolving;

    机译:认证安全;图形密码;肩冲浪;不断发展随时间变化;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号