Captcha as Graphical Passwords-A New Security Primitive Based on Hard AI Problems

被引:44
作者
Zhu, Bin B. [1 ]
Yan, Jeff [2 ]
Bao, Guanbo [3 ]
Yang, Maowei [4 ]
Xu, Ning [1 ]
机构
[1] Microsoft Res Asia, Beijing 100080, Peoples R China
[2] Newcastle Univ, Newcastle Upon Tyne NE1 7RU, Tyne & Wear, England
[3] Chinese Acad Sci, Inst Automat, Beijing 100190, Peoples R China
[4] Sichuan Univ, Chengdu 610207, Peoples R China
关键词
Graphical password; password; hotspots; CaRP; Captcha; dictionary attack; password guessing attack; security primitive; PASSPOINTS;
D O I
10.1109/TIFS.2014.2312547
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Many security primitives are based on hard mathematical problems. Using hard AI problems for security is emerging as an exciting new paradigm, but has been under-explored. In this paper, we present a new security primitive based on hard AI problems, namely, a novel family of graphical password systems built on top of Captcha technology, which we call Captcha as graphical passwords (CaRP). CaRP is both a Captcha and a graphical password scheme. CaRP addresses a number of security problems altogether, such as online guessing attacks, relay attacks, and, if combined with dual-view technologies, shoulder-surfing attacks. Notably, a CaRP password can be found only probabilistically by automatic online guessing attacks even if the password is in the search set. CaRP also offers a novel approach to address the well-known image hotspot problem in popular graphical password systems, such as PassPoints, that often leads to weak password choices. CaRP is not a panacea, but it offers reasonable security and usability and appears to fit well with some practical applications for improving online security.
引用
收藏
页码:891 / 904
页数:14
相关论文
共 41 条
  • [1] Revisiting Defenses against Large-Scale Online Password Guessing Attacks
    Alsaleh, Mansour
    Mannan, Mohammad
    van Oorschot, P. C.
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2012, 9 (01) : 128 - 141
  • [2] [Anonymous], 2002, Proceedings of the 9th ACM conference on Computer and communications security, DOI DOI 10.1145/586110.586133
  • [3] [Anonymous], 2011, 12 AUSTR US INT C
  • [4] [Anonymous], 2012, SCI PASSFACES
  • [5] Graphical Passwords: Learning from the First Twelve Years
    Biddle, Robert
    Chiasson, Sonia
    Van Oorschot, P. C.
    [J]. ACM COMPUTING SURVEYS, 2012, 44 (04)
  • [6] Bonneau J., 2012, P IEEE S SEC PRIV JU, P20
  • [7] Chellapilla K, 2005, LECT NOTES COMPUT SC, V3517, P1
  • [8] Chiasson S., 2008, BCS HCI 08 P 22 BRIT, P121
  • [9] Chiasson S, 2007, LECT NOTES COMPUT SC, V4734, P359
  • [10] Davies D. R., 2004, Proceedings of the Society of Feed Technologists, 2003, P1