首页> 外文期刊>Human-Machine Systems, IEEE Transactions on >PassBYOP: Bring Your Own Picture for Securing Graphical Passwords
【24h】

PassBYOP: Bring Your Own Picture for Securing Graphical Passwords

机译:PassBYOP:自带图片以保护图形密码

获取原文
获取原文并翻译 | 示例
       

摘要

PassBYOP is a new graphical password scheme for public terminals that replaces the static digital images typically used in graphical password systems with personalized physical tokens, herein in the form of digital pictures displayed on a physical user-owned device such as a mobile phone. Users present these images to a system camera and then enter their password as a sequence of selections on live video of the token. Highly distinctive optical features are extracted from these selections and used as the password. We present three feasibility studies of PassBYOP examining its reliability, usability, and security against observation. The reliability study shows that image-feature based passwords are viable and suggests appropriate system thresholds—password items should contain a minimum of seven features, 40% of which must geometrically match originals stored on an authentication server in order to be judged equivalent. The usability study measures task completion times and error rates, revealing these to be 7.5 s and 9%, broadly comparable with prior graphical password systems that use static digital images. Finally, the security study highlights PassBYOP's resistance to observation attack—three attackers are unable to compromise a password using shoulder surfing, camera-based observation, or malware. These results indicate that PassBYOP shows promise for security while maintaining the usability of current graphical password schemes.
机译:PassBYOP是一种用于公共终端的新的图形密码方案,该方案以个性化的物理令牌代替了通常在图形密码系统中使用的静态数字图像,此处以显示在物理用户拥有的设备(如移动电话)上的数字图片的形式。用户将这些图像呈现给系统摄像机,然后在令牌的实况视频上输入密码作为一系列选择。从这些选择中提取高度独特的光学功能,并将其用作密码。我们目前对PassBYOP进行三项可行性研究,以检查其可靠性,可用性和针对观察的安全性。可靠性研究表明,基于图像特征的密码是可行的,并提出了适当的系统阈值-密码项应至少包含七个特征,其中40%必须在几何上与存储在身份验证服务器上的原始特征相匹配才能被判断为等效。可用性研究衡量了任务完成时间和错误率,发现它们分别为7.5 s和9%,与使用静态数字图像的现有图形密码系统大致相当。最后,安全研究强调了PassBYOP对观察攻击的抵抗力-三名攻击者无法通过肩膀冲浪,基于摄像头的观察或恶意软件来破坏密码。这些结果表明,PassBYOP在保证当前图形密码方案的可用性的同时,也显示出安全性的希望。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号