首页> 外文期刊>Interacting with Computers >On designing usable and secure recognition-based graphical authentication mechanisms
【24h】

On designing usable and secure recognition-based graphical authentication mechanisms

机译:在设计基于可用和安全识别的图形身份验证机制时

获取原文
获取原文并翻译 | 示例
           

摘要

In this article we present the development of a new, web-based, graphical authentication mechanism called ImagePass. The authentication mechanism introduces a novel feature based on one-time passwords that increases the security of the system without compromising its usability. Regarding usability, we explore the users' perception of recognition-based, graphical authentication mechanisms in a web environment. Specifically, we investigate whether the memorability of recognition-based authentication keys is influenced by image content. We also examine how the frequency of use affects the usability of the system and whether user training via mnemonic instructions improves the graphical password recognition rate. The design and development process of the proposed system began with a study that assessed how the users remember abstract, face or single-object images, and showed that single-object images have a higher memorability rate. We then proceeded with the design and development of a recognition-based graphical authentication mechanism, ImagePass, which uses single-objects as the image content and follows usable security guidelines. To conclude the research, in a follow-up study we evaluated the performance of 151 participants under different conditions. We discovered that the frequency of use had a great impact on users" performance, while the users' gender had a limited task-specific effect. In contrast, user training through mnemonic instructions showed no differences in the users' authentication metrics. However, a post-study, focus-group analysis revealed that these instructions greatly influenced the users' perception for memorability and the usability of the graphical authentication. In general, the results of these studies suggest that single-object graphical authentication can be a complementary replacement for traditional passwords, especially in ubiquitous environments and mobile devices.
机译:在本文中,我们介绍了一种称为ImagePass的基于Web的新图形身份验证机制的开发。身份验证机制引入了一种基于一次性密码的新颖功能,该功能可在不损害系统可用性的情况下提高系统的安全性。关于可用性,我们探索了用户对Web环境中基于识别的图形身份验证机制的看法。具体来说,我们调查基于识别的身份验证密钥的记忆性是否受图像内容影响。我们还将研究使用频率如何影响系统的可用性,以及通过助记符指令进行的用户培训是否会提高图形密码识别率。所提出系统的设计和开发过程始于一项研究,该研究评估了用户如何记住抽象图像,面部图像或单个对象的图像,并表明单个对象的图像具有较高的记忆率。然后,我们进行了基于识别的图形认证机制ImagePass的设计和开发,该机制使用单个对象作为图像内容并遵循可用的安全准则。总结研究,在一项后续研究中,我们评估了151名参与者在不同条件下的表现。我们发现使用频率对用户的性能有很大影响,而用户的性别对特定任务的影响有限。相比之下,通过助记符指令进行的用户培训在用户的身份验证指标上没有差异。研究后的焦点小组分析表明,这些说明极大地影响了用户对记忆性和图形认证可用性的看法,总体而言,这些研究的结果表明,单对象图形认证可以替代传统的图形认证。密码,尤其是在无处不在的环境和移动设备中。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号