Captcha as Graphical Passwords-A New Security Primitive Based on Hard AI Problems

被引:45
作者
Zhu, Bin B. [1 ]
Yan, Jeff [2 ]
Bao, Guanbo [3 ]
Yang, Maowei [4 ]
Xu, Ning [1 ]
机构
[1] Microsoft Res Asia, Beijing 100080, Peoples R China
[2] Newcastle Univ, Newcastle Upon Tyne NE1 7RU, Tyne & Wear, England
[3] Chinese Acad Sci, Inst Automat, Beijing 100190, Peoples R China
[4] Sichuan Univ, Chengdu 610207, Peoples R China
关键词
Graphical password; password; hotspots; CaRP; Captcha; dictionary attack; password guessing attack; security primitive; PASSPOINTS;
D O I
10.1109/TIFS.2014.2312547
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Many security primitives are based on hard mathematical problems. Using hard AI problems for security is emerging as an exciting new paradigm, but has been under-explored. In this paper, we present a new security primitive based on hard AI problems, namely, a novel family of graphical password systems built on top of Captcha technology, which we call Captcha as graphical passwords (CaRP). CaRP is both a Captcha and a graphical password scheme. CaRP addresses a number of security problems altogether, such as online guessing attacks, relay attacks, and, if combined with dual-view technologies, shoulder-surfing attacks. Notably, a CaRP password can be found only probabilistically by automatic online guessing attacks even if the password is in the search set. CaRP also offers a novel approach to address the well-known image hotspot problem in popular graphical password systems, such as PassPoints, that often leads to weak password choices. CaRP is not a panacea, but it offers reasonable security and usability and appears to fit well with some practical applications for improving online security.
引用
收藏
页码:891 / 904
页数:14
相关论文
共 41 条
[1]   Revisiting Defenses against Large-Scale Online Password Guessing Attacks [J].
Alsaleh, Mansour ;
Mannan, Mohammad ;
van Oorschot, P. C. .
IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2012, 9 (01) :128-141
[2]  
[Anonymous], 2002, Proceedings of the 9th ACM conference on Computer and communications security, DOI DOI 10.1145/586110.586133
[3]  
[Anonymous], 2011, 12 AUSTR US INT C
[4]  
[Anonymous], 2012, SCI PASSFACES
[5]   Graphical Passwords: Learning from the First Twelve Years [J].
Biddle, Robert ;
Chiasson, Sonia ;
Van Oorschot, P. C. .
ACM COMPUTING SURVEYS, 2012, 44 (04)
[6]  
Bonneau J., 2012, P IEEE S SEC PRIV JU, P20
[7]  
Chellapilla K, 2005, LECT NOTES COMPUT SC, V3517, P1
[8]  
Chiasson S., 2008, BCS HCI 08 P 22 BRIT, P121
[9]  
Chiasson S, 2007, LECT NOTES COMPUT SC, V4734, P359
[10]  
Davies D. R., 2004, Proceedings of the Society of Feed Technologists, 2003, P1