课题基金 / 基金详情

Memory-Enhanced User Authentication Systems

Memory-Enhanced User Authentication Systems
内存增强型用户身份验证系统
批准号:
RGPIN-2019-05803
负责人:
Thorpe, Julie
金额:
$2.99万
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2022
资助国家:
加拿大
项目状态:
已结题
起止时间:
2022-01-01 至 2023-12-31

项目摘要

项目成果

Thorpe, Julie的其他基金

相似基金

相关文献

中文摘要
翻译
用户身份验证是大多数计算机系统的第一道防线,范围从移动设备到关键系统(例如,公用事业和医疗保健系统)。基于知识的认证系统是最常见的,它基于你知道的秘密(例如,密码和密码短语)。这些系统通常保护我们的机密信息(如电子邮件和文件)、财务(如网上银行),甚至我们的家(如通过智能家居服务)。基于知识的身份验证系统,特别是密码,由于其低成本和缺乏专门的硬件要求而广泛流行。目前,密码单独使用或与其他方法(如密码管理器(作为主密码)、生物识别技术(在合法用户被拒绝时用于备份身份验证)或多因素身份验证(例如,使用物理令牌)结合使用都很重要。不幸的是,由于最近利用公开泄露的密码和个人信息进行密码攻击的进展,密码安全已成为一个严重的问题。这些攻击对现有密码系统的可行性提出了质疑,并表明需要新的方法来提高安全性。人们对难以记住安全密码感到沮丧。然而,到目前为止,还没有新的认证方案被广泛采用来取代传统的文本密码。广泛采用的主要障碍包括成本、安全性和可用性问题(例如,错误的频率和可记忆性)。该研究项目将设计、开发和评估基于知识的身份验证方法,以帮助用户创建和记住安全的秘密,重点是增强可记忆性的可用系统。具体目标包括开发:(a)利用内隐记忆的认证系统;(b)支持显式内存的认证系统。外显记忆和内隐记忆的区别在于一个人是否有意识地意识到他/她的回忆。该计划的成果预计将有助于提高人们在各种身份验证环境(例如,移动、网络、工作场所和家庭)中的安全性和用户体验。预计,通过该研究创建的一些身份验证系统将进行大规模研究,最终目标是部署。我们的发现和我们设计的系统将帮助加拿大人(和其他人)在各种环境中保护他们的敏感信息,包括网络、移动、金融、医疗保健、家庭和关键系统。该研究项目还将研究设计新的认证系统的基础,这些系统可以增强人类的记忆能力,供该领域的其他研究人员使用。
英文摘要
User authentication is the first line of defense for most computer systems, ranging from mobile devices to critical systems (e.g., for utilities and health care). Knowledge-based authentication systems are the most common, based on a secret that you know (e.g., passwords and passphrases). These systems typically protect our confidential information (e.g., emails and documents), finances (e.g., online banking), and even our homes (e.g., through smart home services). Knowledge-based authentication systems, particularly passwords, are widely popular due to their low-cost and lack of specialized hardware requirements. Currently, passwords are important alone or in combination with other approaches such as password managers (as the master password), biometrics (for backup authentication when legitimate users are rejected), or multi-factor authentication (e.g., with physical tokens). Unfortunately, password security has become a serious concern, due to recent advances in password attacks using publicly leaked password and personal information. These attacks call into question the viability of existing password systems and demonstrate the need for new approaches to improve security. People are frustrated with the difficulty to remember a secure password. However, to date, no new authentication proposal has been widely adopted to replace traditional text passwords. Major barriers to widespread adoption include cost, security, and usability issues (e.g., frequency of errors and memorability). This research program will design, develop, and evaluate knowledge-based authentication approaches to help users create and remember secure secrets, with a focus on usable systems that enhance memorability. Specific objectives include the development of: (a) authentication systems that harness implicit memory; and (b) authentication systems that support explicit memory. Explicit and implicit memory are differentiated by whether or not an individual is consciously aware of his/her recollection. The outcomes of this program are anticipated to help improve the security and user experience of people in a wide variety of authentication environments (e.g., mobile, web, workplace, and home). It is expected that a number of the authentication systems created through the research will undergo large-scale studies with the goal of eventual deployment. Our findings and systems we design will help Canadians (and others) protect their sensitive information in a variety of environments, including web, mobile, financial, healthcare, home, and critical systems. The research program will also investigate foundations for designing new authentication systems that empower human memory capabilities, which can be used by other researchers in the field.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Memory-Enhanced User Authentication Systems
Memory-Enhanced User Authentication Systems
Memory-Enhanced User Authentication Systems
Towards Cognitive Aids For Stronger Computer Security
海外基金