Towards Making Random Passwords Memorable: Leveraging Users' Cognitive Ability Through Multiple Cues

被引:23
作者
Al-Ameen, Mahdi Nasrullah [1 ]
Wright, Matthew [1 ]
Scielzo, Shannon [2 ]
机构
[1] Univ Texas Arlington, Dept CSE, Arlington, TX USA
[2] Univ Texas Arlington, Dept Psychol, Arlington, TX 76019 USA
来源
CHI 2015: PROCEEDINGS OF THE 33RD ANNUAL CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS | 2015年
基金
美国国家科学基金会;
关键词
Usable security; authentication; cued-recognition; K. 6.5 Management of Computing and Information Systems; Security and Protection-Authentication;
D O I
10.1145/2702123.2702241
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Given the choice, users produce passwords reflecting common strategies and patterns that ease recall but offer uncertain and often weak security. System-assigned passwords provide measurable security but suffer from poor memorability. To address this usability-security tension, we argue that systems should assign random passwords but also help with memorization and recall. We investigate the feasibility of this approach with CuedR, a novel cued-recognition authentication scheme that provides users with multiple cues (visual, verbal, and spatial) and lets them choose the cues that best fit their learning process for later recognition of system-assigned keywords. In our lab study, all 3 7 of our participants could log in within three attempts one week after registration (mean login time: 3 8 : 0 seconds). A pilot study on using multiple CuedR passwords also showed 1 0 0 % recall within three attempts. Based on our results, we suggest appropriate applications for CuedR, such as financial and e-commerce accounts.
引用
收藏
页码:2315 / 2324
页数:10
相关论文
共 48 条
  • [1] Al-Ameen M. N., 2014, TECH REP
  • [2] RECOGNITION AND RETRIEVAL PROCESSES IN FREE-RECALL
    ANDERSON, JR
    BOWER, GH
    [J]. PSYCHOLOGICAL REVIEW, 1972, 79 (02) : 97 - &
  • [3] Atinkson C.R., 1968, Advances in the psychol- ogy of learning and motivation
  • [4] Graphical Passwords: Learning from the First Twelve Years
    Biddle, Robert
    Chiasson, Sonia
    Van Oorschot, P. C.
    [J]. ACM COMPUTING SURVEYS, 2012, 44 (04)
  • [5] Bonneau J., 2010, WEIS
  • [6] Bonneau J., 2012, IEEE S P
  • [7] Bridis T., 2008, ASS PRESS 0918
  • [8] Chiasson S., 2007, SOUPS
  • [9] Chiasson S., 2012, IEEE TDSC
  • [10] Chiasson S., 2007, ESORICS