Password Strength Measurement without Password Disclosure

被引:0
|
作者
Sugai, Taku [1 ]
Ohigashi, Toshihiro [2 ]
Kakizaki, Yoshio [3 ]
Kanaoka, Akira [1 ]
机构
[1] Toho Univ, Chiba, Japan
[2] Tokai Univ, Tokyo, Japan
[3] Tokyo Denki Univ, Tokyo, Japan
关键词
Password; Hash Function; Secure Scoring;
D O I
10.1109/AsiaJCIS.2019.00030
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As a mechanism for promoting improvement in the strength of the user password, there is a mechanism that measures the password strength and gives feedback to the user. There are a wide variety of current strength measurement methods, and there are also methods that transmit a password during input to the remote server to perform strength measurement. However, the threat of sending passwords externally during input has not been sufficiently discussed. In this paper, we first survey the current password strength measurement method, and clarify how much remote side strength measurement exists. Then, the threat of remote strength measurement is organized, and the need for its protection is indicated. The necessity of the method of measuring the password strength without disclosure as the protection method is described, and three approaches are shown. Furthermore, the feasibility of each approach is discussed, and the prototype with the highest feasibility was developed. Moreover, we evaluate the performance and usability of the prototype system. As a result, although basic performance changes depending on system configuration, the result of the user study shows that the usability is not low, and the proposed method is sufficiently practical while reducing the threat.
引用
收藏
页码:157 / 164
页数:8
相关论文
共 50 条
  • [1] On Password Strength Measurements: Password Entropy and Password Quality
    Taha, Mariam M.
    Alhaj, Taqwa A.
    Moktar, Ala E.
    Salim, Azza H.
    Abdullah, Settana M.
    2013 INTERNATIONAL CONFERENCE ON COMPUTING, ELECTRICAL AND ELECTRONICS ENGINEERING (ICCEEE), 2013, : 497 - 501
  • [2] Delayed Password Disclosure
    Jakobsson, Markus
    Myers, Steven
    DIM'07: PROCEEDINGS OF THE 2007 ACM WORKSHOP ON DIGITAL IDENTITY MANAGEMENT, 2007, : 17 - 26
  • [3] A Password Meter without Password Exposure
    Kim, Pyung
    Lee, Younho
    Hong, Youn-Sik
    Kwon, Taekyoung
    SENSORS, 2021, 21 (02) : 1 - 25
  • [4] PASSWORD AUTHENTICATION WITHOUT USING A PASSWORD TABLE
    HORNG, GB
    INFORMATION PROCESSING LETTERS, 1995, 55 (05) : 247 - 250
  • [5] MonoPass: A Password Manager without Master Password Authentication
    Jeong, Hyeonhak
    Jung, Hyunggu
    26TH INTERNATIONAL CONFERENCE ON INTELLIGENT USER INTERFACES (IUI '21 COMPANION), 2021, : 52 - 54
  • [6] Deep Learning for Password Guessing and Password Strength Evaluation, A Survey
    Zhang, Tao
    Cheng, Zelei
    Qin, Yi
    Li, Qiang
    Shi, Lin
    2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, : 1163 - 1167
  • [7] LPSE: Lightweight password-strength estimation for password meters
    Guo, Yimin
    Zhang, Zhenfeng
    COMPUTERS & SECURITY, 2018, 73 : 507 - 518
  • [8] Password Security in Organizations: User Attitudes and Behaviors Regarding Password Strength
    Almehmadi, Tahani
    Alsolami, Fahad
    16TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY-NEW GENERATIONS (ITNG 2019), 2019, 800 : 9 - 13
  • [9] Password Strength: An Empirical Analysis
    Dell'Amico, Matteo
    Michiardi, Pietro
    Roudier, Yves
    2010 PROCEEDINGS IEEE INFOCOM, 2010,
  • [10] On the Accuracy of Password Strength Meters
    Golla, Maximilian
    Duermuth, Markus
    PROCEEDINGS OF THE 2018 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'18), 2018, : 1567 - 1582