Back to Search
Start Over
CombinedPWD: A New Password Authentication Mechanism Using Separators Between Keystrokes
- Source :
- CIS
- Publication Year :
- 2017
- Publisher :
- IEEE, 2017.
-
Abstract
- The password security has been paid much attention to by many scholars. The conventional password cracking methods are based on probabilistic models leveraging the leaked password datasets. In order to reduce this risk, our study proposes a new online password authentication mechanism, combinedPWD, through inserting separators (e.g. blanks) into the passwords to strengthen the existing password authentication system. This scheme utilizes the custom of users' input. In our research, website users can insert spaces in their password where they want to pause when they register an account and the website back-end records the number of spaces in every gap. Only input the correct password and the corresponding number of separators matching accounts to be admitted into the system. Any trials with wrong password or correct password but with a wrong number of spaces will be rejected by the system. Through the experiments verification, the proposed mechanism can resist brute force attack and dictionary attack effectively. To avoid keyloggers, we further propose to use two-dimensional code to store the encrypted password. And this scheme has better operability and security.
- Subjects :
- Password
Authentication
Dictionary attack
Computer science
business.industry
computer.internet_protocol
010401 analytical chemistry
Password cracking
020206 networking & telecommunications
Cryptography
02 engineering and technology
Encryption
Computer security
computer.software_genre
Keystroke logging
01 natural sciences
0104 chemical sciences
Password strength
ComputingMilieux_MANAGEMENTOFCOMPUTINGANDINFORMATIONSYSTEMS
Brute-force attack
0202 electrical engineering, electronic engineering, information engineering
Message authentication code
Password authentication protocol
business
computer
Subjects
Details
- Database :
- OpenAIRE
- Journal :
- 2017 13th International Conference on Computational Intelligence and Security (CIS)
- Accession number :
- edsair.doi...........305c1a86b8890dbe2046e2b8357e450b
- Full Text :
- https://doi.org/10.1109/cis.2017.00129