User Study, Analysis, and Usable Security of Passwords Based on Digital Objects

被引:21
|
作者
Biddle, Robert [1 ]
Mannan, Mohammad [2 ]
van Oorschot, Paul C. [1 ]
Whalen, Tara [1 ]
机构
[1] Carleton Univ, Sch Comp Sci, Ottawa, ON K1S 5B6, Canada
[2] Univ Toronto, Elect & Comp Engn Dept, Toronto, ON M5S 3G4, Canada
基金
加拿大自然科学与工程研究理事会;
关键词
Affective passwords; image-based passwords; password authentication; personal digital objects; usable security;
D O I
10.1109/TIFS.2011.2116781
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Despite all efforts, password schemes intended to deploy or encourage the use of strong passwords have largely failed. As an alternative to enable users to create, maintain, and use high-quality passwords willingly, we propose Object-based Password (ObPwd), leveraging the universe of personal or personally meaningful digital content that many users now own or have access to. ObPwd converts user-selected digital objects to high-entropy text passwords. Memorization of exact passwords is replaced by remembering password objects. We present the design details, variants, and usability and security analysis of ObPwd, and report on the results of a hybrid in-lab/at-home user study on 32 participants. The results suggest the scheme has good usability, with excellent memorability, acceptable login times, and very positive user perception, achieved while providing strong security for the threat context explored. We believe this work lays the foundation for a promising password selection paradigm.
引用
收藏
页码:970 / 979
页数:10
相关论文
共 50 条
  • [21] An Innovative User Authentication Method: Replacements of Text Based Passwords
    Shukla, Varun
    Dixit, Shivani
    Kumar, Ravi
    Patidar, Manish
    INFORMATION SYSTEMS AND MANAGEMENT SCIENCE, ISMS 2021, 2023, 521 : 210 - 224
  • [22] Banking Security System Based on SVD Fingerprints and Cryptography Passwords
    Srihi, Sofienne
    Balti, Ala
    Fnaiech, Farhat
    Hamam, Habib
    2018 INTERNATIONAL CONFERENCE ON CONTROL, AUTOMATION AND DIAGNOSIS (ICCAD), 2018,
  • [23] Research on Security User Authentication Based on Digital Signature in Electronic Commerce
    Jiang, KeWei
    Fu, Ke
    Gao, ZhiBiao
    EIGHTH WUHAN INTERNATIONAL CONFERENCE ON E-BUSINESS, VOLS I-III, 2009, : 812 - 817
  • [24] Security design based on social and cultural practice: Sharing of passwords
    Singh, Supriya
    Cabraal, Anuja
    Demosthenous, Catherine
    Astbrink, Gunela
    Furlong, Michele
    USABILITY AND INTERNATIONALIZATION, PT 2, PROCEEDINGS: GLOBAL AND LOCAL USER INTERFACES, 2007, 4560 : 476 - +
  • [25] Usability and Security of Gaze-Based Graphical Grid Passwords
    Arianezhad, Majid
    Stebila, Douglas
    Mozaffari, Behzad
    FINANCIAL CRYPTOGRAPHY AND DATA SECURITY: FC 2013 WORKSHOPS, 2013, 7862 : 17 - 33
  • [26] Usable Security and Aesthetics: Designing for engaging online security warnings and cautions to optimise user security whilst affording ease of use
    Carroll, Fiona
    PROCEEDINGS OF THE 2021 EUROPEAN SYMPOSIUM ON USABLE SECURITY, EUROUSEC 2021, 2021, : 23 - 28
  • [27] Achieving Flatness: Honeywords Generation Method for Passwords based on User Behaviours
    Akif, Omar Z.
    Sabeeh, Ann F.
    Rodgers, G. J.
    Al-Raweshidy, H. S.
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2019, 10 (03) : 28 - 37
  • [28] Usable security and aesthetics: Designing for engaging online security warnings and cautions to optimise user security whilst affording ease of use
    Carroll, Fiona
    ACM International Conference Proceeding Series, 2021, : 23 - 28
  • [29] The Role of Visual Features in Text-Based CAPTCHAs: An fNIRS Study for Usable Security
    Mulazimoglu, Emre
    Cakir, Murat P.
    Acarturk, Cengiz
    COMPUTATIONAL INTELLIGENCE AND NEUROSCIENCE, 2021, 2021
  • [30] Unmasking the Potential of Usable Security and Privacy Technologies in Empowering African Digital Landscapes
    Gamundani, Attlee M.
    PROCEEDINGS OF THE 4TH AFRICAN CONFERENCE FOR HUMAN COMPUTER INTERACTION, AFRICHI 2023, 2023, : 201 - 207