Security analysis of Game Changer Password System

被引:5
|
作者
Brumen, Bostjan [1 ]
机构
[1] Univ Maribor, Fac Elect Engn & Comp Sci, Inst Informat, Smetanova 17, SI-2000 Maribor, Slovenia
关键词
Security; Passwords; Cryptanalysis; Games; Memory; AUTHENTICATION; MEMORABILITY;
D O I
10.1016/j.ijhcs.2019.01.004
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In the paper we present the results of security analysis of the Game Changer Password System, proposed by McLennan et al. a mnemonic variant of password security that uses game positions as passwords. The idea is that several different games are graphically presented on the screen, allowing users to select the game first and then to enter his or her password in the game selected in the form of putting pieces on a board. For example, a user first selects chess, then puts four chess figures on the chessboard. A password is represented by the fact that chess was used and figures' locations. The first issue with the proposed system is a small search space the number of possible combinations of passwords, enabling relatively simple and quite inexpensive brute force attacks. The second issue is that users prefer specific locations and figures over others, further reducing the search space and thus enabling attackers to speed up the attacks with high probabilities of success. Based on the issue of non-uniformity of locations and figures attackers can build special dictionaries to launch dictionary-based attacks. We elaborate on the weaknesses and propose a solution that produces stronger passwords. However, the tradeoff between memorability and attack resilience must be taken into the account.
引用
收藏
页码:44 / 52
页数:9
相关论文
共 50 条
  • [1] An evaluation of the Game Changer Password System: A new approach to password security
    McLennan, Conor T.
    Manning, Philip
    Tuft, Samantha E.
    INTERNATIONAL JOURNAL OF HUMAN-COMPUTER STUDIES, 2017, 100 : 1 - 17
  • [2] Layered Battleship Game Changer Password System
    Brumen, Bostjan
    Crepulja, Darko
    Bosnjak, Leon
    INFORMATICA, 2022, 33 (02) : 225 - 246
  • [3] Simulating security: a game changer
    Halsema, John
    Scott, Robert, III
    NUCLEAR ENGINEERING INTERNATIONAL, 2017, 62 (752): : 26 - 27
  • [4] Password Security as a Game of Entropies
    Rass, Stefan
    Koenig, Sandra
    ENTROPY, 2018, 20 (05)
  • [5] Password Security: Password Behavior Analysis at a Small University
    Awad, Mohammed
    Al-Qudah, Zakaria
    Idwan, Sahar
    Jallad, Abdul Halim
    2016 5TH INTERNATIONAL CONFERENCE ON ELECTRONIC DEVICES, SYSTEMS AND APPLICATIONS (ICEDSA), 2016,
  • [6] IoT Security with QoS: Game changer for Industry and STEM Education
    Jamro, M. Y.
    2021 INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2021,
  • [7] A VOICE PASSWORD SYSTEM FOR ACCESS SECURITY
    BIRNBAUM, M
    COHEN, LA
    WELSH, FX
    AT&T TECHNICAL JOURNAL, 1986, 65 (05): : 68 - 74
  • [8] Game Changer: The Impact of 9/11 on North American Security
    Sands, Christopher
    INTERNATIONAL JOURNAL, 2015, 70 (01): : 175 - 176
  • [9] Game Changer
    Adams, Susan
    FORBES, 2010, 185 (06): : 60 - 60
  • [10] Game changer
    Cozier, Muriel
    BIOFUELS BIOPRODUCTS & BIOREFINING-BIOFPR, 2014, 8 (05): : 612 - 612