首页> 外文期刊>IEEE transactions on information forensics and security >Captcha as Graphical Passwords—A New Security Primitive Based on Hard AI Problems
【24h】

Captcha as Graphical Passwords—A New Security Primitive Based on Hard AI Problems

机译:验证码作为图形密码-基于硬AI问题的新安全性原语

获取原文
获取原文并翻译 | 示例

摘要

Many security primitives are based on hard mathematical problems. Using hard AI problems for security is emerging as an exciting new paradigm, but has been under-explored. In this paper, we present a new security primitive based on hard AI problems, namely, a novel family of graphical password systems built on top of Captcha technology, which we call Captcha as graphical passwords (CaRP). CaRP is both a Captcha and a graphical password scheme. CaRP addresses a number of security problems altogether, such as online guessing attacks, relay attacks, and, if combined with dual-view technologies, shoulder-surfing attacks. Notably, a CaRP password can be found only probabilistically by automatic online guessing attacks even if the password is in the search set. CaRP also offers a novel approach to address the well-known image hotspot problem in popular graphical password systems, such as PassPoints, that often leads to weak password choices. CaRP is not a panacea, but it offers reasonable security and usability and appears to fit well with some practical applications for improving online security.
机译:许多安全原语都基于困难的数学问题。将硬AI问题用于安全性正在成为一种令人兴奋的新范例,但尚未得到充分研究。在本文中,我们提出了一个基于AI难题的新安全原语,即基于Captcha技术构建的新型图形密码系统系列,我们将Captcha称为图形密码(CaRP)。 CaRP既是验证码又是图形密码方案。 CaRP完全解决了许多安全问题,例如在线猜测攻击,中继攻击,以及(如果与双视图技术结合使用)肩膀冲浪攻击。值得注意的是,即使密码在搜索集中,也只能通过自动在线猜测攻击概率地找到CaRP密码。 CaRP还提供了一种新颖的方法来解决流行的图形密码系统(例如PassPoints)中众所周知的图像热点问题,该问题通常会导致密码选择不力。 CaRP不是万能药,但它提供了合理的安全性和可用性,并且似乎与某些实际应用程序非常适合,以提高在线安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号