Enhancing Authentication: Towards Password Memorability Meters, and Leveraging Implicit Learning for System-Assigned Passwords
Enhancing Authentication: Towards Password Memorability Meters, and Leveraging Implicit Learning for System-Assigned Passwords
批准号:
RGPIN-2018-05919
负责人:
VargasMartin, Miguel
金额:
$2.04万
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2022
资助国家:
加拿大
项目状态:
已结题
起止时间:
2022-01-01 至 2023-12-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Text passwords remain as one of the most widespread authentication mechanisms in computer systems. The strength of a password is thus of paramount importance to security. As such, a number of password strengthening techniques have been proposed in the literature and deployed in the real world. Nevertheless, there exists a trade-off between password strength and memorability, and while password strength meters are common, according to the related literature and to the best of my knowledge, no reliable memorability meter has been published or deployed. The proposed research program will endeavour to analyze memorability of system-assigned passwords at the time of creation, by studying the brain waves generated while seeing a password for the first time. This work will lead to a password meter that can help users to choose a system-assigned password that has higher probability of being remembered, by predicting its recall chances at the time of assigning the password to a user.So far, together with my team of students, I have been able to establish that passwords can be classified based on the electroencephalogram (EEG) signals they elicit. This was found through a series of experiments that used consumer-grade brain-computer interface (BCI) devices to compare EEG differences between random and common passwords (i.e., most common passwords as exposed by popular password leaks). In light of these experiments it became evident that a password meter could be built by measuring short- and long-term password recall. For example, when the user is given a choice of two system-assigned passwords, there are statistically significant correlations between the EEG signals and the chosen password, recalling the password from short- and long-term memory, and the number of attempts to remember the password correctly.To address password usability from a different angle, the proposed research program will investigate authentication techniques that leverage implicit learning phenomena from the psychology field. Some of the most important advantages of implicitly learnt passwords are that the user is not imposed with a conscious cognitive burden, can't retrieve them at will, and therefore to a certain extent implicitly learnt passwords are coercion- and insider-attack resistant. During the past years, my research team and I have designed and tested an authentication technique based on two branches of implicit learning, namely, contextual cueing and semantic priming, which have shown promise not only in terms of accuracy but in training time compared to the most cited recent related works available in the literature. The proposed research program will continue this line of research to improve accuracy as well as training and authentication time.Over 10 highly qualified personnel will be trained in authentication with strong theoretical foundations, benefitting the research community and Canadians in general.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Enhancing Authentication: Towards Password Memorability Meters, and Leveraging Implicit Learning for System-Assigned Passwords
-
批准号:RGPIN-2018-05919
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2021
-
负责人:VargasMartin, Miguel
-
依托单位:
Enhancing Authentication: Towards Password Memorability Meters, and Leveraging Implicit Learning for System-Assigned Passwords
-
批准号:RGPIN-2018-05919
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2020
-
负责人:VargasMartin, Miguel
-
依托单位:
Enhancing Authentication: Towards Password Memorability Meters, and Leveraging Implicit Learning for System-Assigned Passwords
-
批准号:RGPIN-2018-05919
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2019
-
负责人:VargasMartin, Miguel
-
依托单位:
Enhancing Authentication: Towards Password Memorability Meters, and Leveraging Implicit Learning for System-Assigned Passwords
-
批准号:RGPIN-2018-05919
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2018
-
负责人:VargasMartin, Miguel
-
依托单位:
Towards New Security Paradigms for User Authentication and Traffic Inspection: Harnessing Implicit Mistakes and Auditory Sense
-
批准号:312183-2013
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.09万
-
财政年份:2017
-
负责人:VargasMartin, Miguel
-
依托单位:
Towards New Security Paradigms for User Authentication and Traffic Inspection: Harnessing Implicit Mistakes and Auditory Sense
-
批准号:312183-2013
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.09万
-
财政年份:2015
-
负责人:VargasMartin, Miguel
-
依托单位:
Towards New Security Paradigms for User Authentication and Traffic Inspection: Harnessing Implicit Mistakes and Auditory Sense
-
批准号:312183-2013
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.09万
-
财政年份:2014
-
负责人:VargasMartin, Miguel
-
依托单位:
Towards New Security Paradigms for User Authentication and Traffic Inspection: Harnessing Implicit Mistakes and Auditory Sense
-
批准号:312183-2013
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.09万
-
财政年份:2013
-
负责人:VargasMartin, Miguel
-
依托单位:
Network security with automatic mitigation of disruptive traffic, attack containment, and intrusion detection
-
批准号:312183-2008
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.09万
-
财政年份:2012
-
负责人:VargasMartin, Miguel
-
依托单位:
Network security with automatic mitigation of disruptive traffic, attack containment, and intrusion detection
-
批准号:312183-2008
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.09万
-
财政年份:2011
-
负责人:VargasMartin, Miguel
-
依托单位:
Network security with automatic mitigation of disruptive traffic, attack containment, and intrusion detection
-
批准号:312183-2008
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.09万
-
财政年份:2010
-
负责人:VargasMartin, Miguel
-
依托单位:
Network security with automatic mitigation of disruptive traffic, attack containment, and intrusion detection
-
批准号:312183-2008
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.09万
-
财政年份:2009
-
负责人:VargasMartin, Miguel
-
依托单位:
Network security with automatic mitigation of disruptive traffic, attack containment, and intrusion detection
-
批准号:312183-2008
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.09万
-
财政年份:2008
-
负责人:VargasMartin, Miguel
-
依托单位:
Network infrastructure security through prevention, detection, reaction, and mitigation of malicious software attacks
-
批准号:312183-2005
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$0.87万
-
财政年份:2007
-
负责人:VargasMartin, Miguel
-
依托单位:
Laboratory for network security with automatic mitigation of disruptive traffic, attack containment, and intrusion detection
-
批准号:360226-2008
-
项目类别:Research Tools and Instruments - Category 1 (<$150,000)
-
资助金额:$1.29万
-
财政年份:2007
-
负责人:VargasMartin, Miguel
-
依托单位:
Network infrastructure security through prevention, detection, reaction, and mitigation of malicious software attacks
-
批准号:312183-2005
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$0.87万
-
财政年份:2006
-
负责人:VargasMartin, Miguel
-
依托单位:
Network infrastructure security through prevention, detection, reaction, and mitigation of malicious software attacks
-
批准号:312183-2005
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$0.87万
-
财政年份:2005
-
负责人:VargasMartin, Miguel
-
依托单位:
国内基金
海外基金
基于ARM Pointer Authentication的操作系统内核数据保护研究
-
批准号:62002317
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:申文博
-
依托单位: