首页> 外文期刊>International Journal of Information Security >Enhanced Tacit Secrets: System-assigned passwords you can't write down, but don't need to
【24h】

Enhanced Tacit Secrets: System-assigned passwords you can't write down, but don't need to

机译:增强的默契秘密:系统分配的密码您不能写下来,但不需要

获取原文
获取原文并翻译 | 示例
           

摘要

We explore the feasibility of Tacit Secrets: system-assigned passwords that you can remember, but cannot write down or otherwise communicate. We design an approach to creating Tacit Secrets based on contextual cueing, an implicit learning method previously studied in the cognitive psychology literature. Our feasibility study indicates that our approach has strong security properties: resistance to brute-force attacks, online attacks, phishing attacks, some coercion attacks, and targeted impersonation attacks. It also offers protection against leaks from other verifiers as the secrets are system-assigned. Our approach also has some interesting usability properties, a high login success rate, and low false positive rates. We explore enhancements to our approach and find that incorporating eye-tracking data offers substantial improvements. We also explore the trade-offs of different configurations of our design and provide insight into valuable directions for future work.
机译:我们探讨了默认秘密的可行性:您可以记住的系统分配的密码,但无法写下或以其他方式进行通信。 我们设计一种基于语境提示来创建默契秘密的方法,是在认知心理学文献中研究过的隐含学习方法。 我们的可行性研究表明,我们的方法具有强大的安全性质:抵抗蛮力攻击,在线攻击,网络钓鱼攻击,一些胁迫攻击以及针对性的模拟攻击。 它还提供防止其他Verifiers的泄漏,因为秘密被分配。 我们的方法还具有一些有趣的可用性属性,高登录成功率和低误率。 我们探索我们的方法的增强功能,并发现结合眼跟踪数据提供了大量的改进。 我们还探讨了我们设计的不同配置的权衡,并提供了对未来工作的宝贵方向的洞察力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号