User Study, Analysis, and Usable Security of Passwords Based on Digital Objects

被引:21
|
作者
Biddle, Robert [1 ]
Mannan, Mohammad [2 ]
van Oorschot, Paul C. [1 ]
Whalen, Tara [1 ]
机构
[1] Carleton Univ, Sch Comp Sci, Ottawa, ON K1S 5B6, Canada
[2] Univ Toronto, Elect & Comp Engn Dept, Toronto, ON M5S 3G4, Canada
基金
加拿大自然科学与工程研究理事会;
关键词
Affective passwords; image-based passwords; password authentication; personal digital objects; usable security;
D O I
10.1109/TIFS.2011.2116781
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Despite all efforts, password schemes intended to deploy or encourage the use of strong passwords have largely failed. As an alternative to enable users to create, maintain, and use high-quality passwords willingly, we propose Object-based Password (ObPwd), leveraging the universe of personal or personally meaningful digital content that many users now own or have access to. ObPwd converts user-selected digital objects to high-entropy text passwords. Memorization of exact passwords is replaced by remembering password objects. We present the design details, variants, and usability and security analysis of ObPwd, and report on the results of a hybrid in-lab/at-home user study on 32 participants. The results suggest the scheme has good usability, with excellent memorability, acceptable login times, and very positive user perception, achieved while providing strong security for the threat context explored. We believe this work lays the foundation for a promising password selection paradigm.
引用
收藏
页码:970 / 979
页数:10
相关论文
共 50 条
  • [1] Challenge Set Designs and User Guidelines for Usable and Secured Recognition-Based Graphical Passwords
    Aljahdali, Hani Moaiteq
    Poet, Ron
    2014 IEEE 13TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM), 2014, : 973 - 982
  • [2] A Set of Heuristics for Usable Security and User Authentication
    Realpe, Paulo C.
    Collazos, Cesar A.
    Hurtado, Julio
    Granollers, Antoni
    PROCEEDINGS OF THE XVII INTERNATIONAL CONFERENCE ON HUMAN COMPUTER INTERACTION INTERACCION 2016, 2016,
  • [3] User interface design affects security: patterns in click-based graphical passwords
    Chiasson, Sonia
    Forget, Alain
    Biddle, Robert
    van Oorschot, P. C.
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2009, 8 (06) : 387 - 398
  • [4] User practice in password security: An empirical study of real-life passwords in the wild
    Shen, Chao
    Yu, Tianwen
    Xu, Haodi
    Yang, Gengshan
    Guan, Xiaohong
    COMPUTERS & SECURITY, 2016, 61 : 130 - 141
  • [5] User interface design affects security: patterns in click-based graphical passwords
    Sonia Chiasson
    Alain Forget
    Robert Biddle
    P. C. van Oorschot
    International Journal of Information Security, 2009, 8 : 387 - 398
  • [6] An Empirical Analysis on the Usability and Security of Passwords
    Walia, Kanwardeep Singh
    Shenoy, Shweta
    Cheng, Yuan
    2020 IEEE 21ST INTERNATIONAL CONFERENCE ON INFORMATION REUSE AND INTEGRATION FOR DATA SCIENCE (IRI 2020), 2020, : 1 - 8
  • [7] A User-Centered Model for Usable Security and Privacy
    Feth, Denis
    Maier, Andreas
    Polst, Svenja
    HUMAN ASPECTS OF INFORMATION SECURITY, PRIVACY AND TRUST (HAS 2017), 2017, 10292 : 74 - 89
  • [8] A Survey of User Experience in Usable Security and Privacy Research
    Jacobs, Danielle
    McDaniel, Troy
    HCI FOR CYBERSECURITY, PRIVACY AND TRUST, HCI-CPT 2022, 2022, 13333 : 154 - 172
  • [9] Evaluating security tools towards usable security - A usability taxonomy for the evaluation of security tools based on a categorization of user errors
    Kaiser, J
    Reichenbach, M
    USABILITY: GAINING A COMPETITIVE EDGE, 2002, 99 : 247 - 256
  • [10] User authentication via behavior based passwords
    Yampolskiy, Roman V.
    2007 IEEE LONG ISLAND SYSTEMS, APPLICATIONS AND TECHNOLOGY CONFERENCE, 2007, : 10 - +