Improving security and usability of passphrases with guided word choice - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2018

Improving security and usability of passphrases with guided word choice

Clément Malaingre
  • Fonction : Auteur
Ted Selker
  • Fonction : Auteur
  • PersonId : 1006548

Résumé

Passphrases have many uses, such as serving as seeds for passwords. User-created passphrases are easier to remember, but tend to be less secure than ones created from words randomly chosen in a dictionary. This paper develops a way of making more memorable, more secure passphrases. It investigates the security and usability of creating a passphrase by choosing from a randomly generated set of words presented as a two-dimensional array. A usability experiment shows that participants using this method achieved 97% to 99% of the maximal theoretical entropy and commited fewer than half as many memory mistakes as a control group with assigned passphrases. It also shows that their choices are affected by word familiarity and weakly by the word’s position in the array. Prompting a person with random words from a large dictionary is an effective way of helping them make a more memorable high-entropy passphrase.
Fichier principal
Vignette du fichier
improving-security-usability (12).pdf (1.14 Mo) Télécharger le fichier
improving-security-usability (7).pdf (385.26 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01781233 , version 1 (22-07-2018)

Identifiants

Citer

Nicolas Blanchard, Clément Malaingre, Ted Selker. Improving security and usability of passphrases with guided word choice. Annual Computer Security Applications Conference (ACSAC), Dec 2018, San Juan, Puerto Rico. ⟨10.1145/3274694.3274734⟩. ⟨hal-01781233⟩
63 Consultations
351 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More