Improving usability of passphrase authentication

Improving usability of passphrase authentication
复制标题

提高密码验证的可用性

DOI:
--
复制
发表时间:
2014
期刊:
2014 Twelfth Annual International Conference on Privacy, Security and Trust
影响因子:
--
通讯作者:
C. Jensen
C. Jensen
中科院分区:
--
文献类型:
--
作者:
G. Nielsen;Michael Vedel;C. Jensen

文献摘要

被引文献

相似文献

用户名和密码的组合已经成为计算机系统中用户认证的主要方法。大多数用户在不同的系统上有多个帐户,这对允许用户选择的密码的长度和复杂性施加了不同的约束。这样做是为了确保适当程度的安全性,但相反,它使用户难以记住他们的密码,这导致密码不安全,但容易记住,或写在纸上。在本文中,我们解决的问题,在用户认证的可用性。我们提倡使用密码短语,它提供更好的安全性,而且通常比密码更容易记住。密码短语将比密码长得多,这使得它们更难以在键盘上正确输入。我们通过提出一个新的密码验证算法来解决这个问题,该算法接受最常见的键入错误。该算法已在安全硬件中实现,并集成到标准Unix系统中。我们目前的设计,实现和初步评估开发的密码短语认证原型。
The combination of user-names and passwords has become the predominant method of user authentication in computer systems. Most users have multiple accounts on different systems, which impose different constraints on the length and complexity of passwords that the user is allowed to select. This is done to ensure an appropriate degree of security, but instead, it makes it difficult for users to remember their password, which results in passwords that are either insecure, but easy to remember, or written down on paper. In this paper we address the problem of usability in user authentication. We promote the use of passphrases, which provide better security and are often easier to remember than passwords. Passphrases will be significantly longer than passwords, which makes them more difficult to enter correctly on a keyboard. We solve this problem by proposing a new passphrase validation algorithm, which accepts the most common typing mistakes. The proposed algorithm has been implemented in secure hardware and integrated into a standard Unix system. We present the design, implementation and preliminary evaluation of the developed passphrase authentication prototype.