Skip to main content

2015 | OriginalPaper | Buchkapitel

PassCue: The Shared Cues System in Practice

verfasst von : Mats Sandvoll, Colin Boyd, Bjørn B. Larsen

Erschienen in: Technology and Practice of Passwords

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

Shared Cues is a password management system proposed by Blocki, Blum and Datta at Asiacrypt 2013. Unlike the majority of password management systems Shared Cues passwords are never stored, even on the management device. The idea of the Shared Cues system is to help users choose and remember passwords in a manner proven to avoid brute force searching under reasonable assumptions.
Blocki et al. analysed Shared Cues theoretically but did not describe any practical tests. We report on the design and implementation of an iOS application based on Shared Cues, which we call PassCue. This enables us to consider the practicality of Shared Cues in the real world and address important issues of user interface, parameter choices and applicability on popular web sites. PassCue demonstrates that the Shared Cues password management system is useable and secure in practice as well as in theory.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Anhänge
Nur mit Berechtigung zugänglich
Literatur
1.
Zurück zum Zitat Anderson, J.R., Matessa, M., Lebiere, C.: Act-r: a theory of higher level cognition and its relation to visual attention. Hum. Comput. Interact. 12(4), 439–462 (1997)CrossRef Anderson, J.R., Matessa, M., Lebiere, C.: Act-r: a theory of higher level cognition and its relation to visual attention. Hum. Comput. Interact. 12(4), 439–462 (1997)CrossRef
2.
Zurück zum Zitat Anderson, J.R., Schooler, L.J.: Reflections of the environment in memory. Psychol. Sci. 2(6), 396–408 (1991)CrossRef Anderson, J.R., Schooler, L.J.: Reflections of the environment in memory. Psychol. Sci. 2(6), 396–408 (1991)CrossRef
3.
Zurück zum Zitat Baddeley, A.D.: Human Memory: Theory and Practice. Lawrence Erlbaum Associates, Hove (1990) Baddeley, A.D.: Human Memory: Theory and Practice. Lawrence Erlbaum Associates, Hove (1990)
4.
Zurück zum Zitat Blocki, J., Blum, M., Datta, A.: Naturally rehearsing passwords. In: Sako, K., Sarkar, P. (eds.) ASIACRYPT 2013, Part II. LNCS, vol. 8270, pp. 361–380. Springer, Heidelberg (2013) CrossRef Blocki, J., Blum, M., Datta, A.: Naturally rehearsing passwords. In: Sako, K., Sarkar, P. (eds.) ASIACRYPT 2013, Part II. LNCS, vol. 8270, pp. 361–380. Springer, Heidelberg (2013) CrossRef
6.
Zurück zum Zitat Castelluccia, C., Dürmuth, M., Perito, D.: Adaptive password-strength meters from Markov models. In: NDSS. The Internet Society (2012) Castelluccia, C., Dürmuth, M., Perito, D.: Adaptive password-strength meters from Markov models. In: NDSS. The Internet Society (2012)
7.
Zurück zum Zitat Danescu-Niculescu-Mizil, C., Cheng, J., Kleinberg, J.M., Lee, L.: You had me at hello: How phrasing affects memorability. CoRR, abs/1203.6360 (2012) Danescu-Niculescu-Mizil, C., Cheng, J., Kleinberg, J.M., Lee, L.: You had me at hello: How phrasing affects memorability. CoRR, abs/1203.6360 (2012)
9.
Zurück zum Zitat Dell’Amico, M., Michiardi, P., Roudier, Y.: Password strength: an empirical analysis. In: Proceedings of the 29th Conference on Information Communications, INFOCOM 2010, pp. 983–991. IEEE Press (2010) Dell’Amico, M., Michiardi, P., Roudier, Y.: Password strength: an empirical analysis. In: Proceedings of the 29th Conference on Information Communications, INFOCOM 2010, pp. 983–991. IEEE Press (2010)
12.
Zurück zum Zitat Foer, J.: Moonwalking with Einstein: The Art and Science of Remembering Everything. Penguin Books Limited, New York (2011) Foer, J.: Moonwalking with Einstein: The Art and Science of Remembering Everything. Penguin Books Limited, New York (2011)
14.
Zurück zum Zitat Johnson, G.J.: A distinctiveness model of serial learning. Psychol. Rev. 98(2), 204–217 (1999)CrossRef Johnson, G.J.: A distinctiveness model of serial learning. Psychol. Rev. 98(2), 204–217 (1999)CrossRef
16.
Zurück zum Zitat Kelley, P.G., Komanduri, S., Mazurek, M.L., Shay, R., Vidas, T., Bauer, L., Christin, N., Cranor, L.F., Lopez, J.: Guess again (and again and again): Measuring password strength by simulating password-cracking algorithms. In: 2012 IEEE Symposium on Security and Privacy (SP), pp. 523–537, May 2012 Kelley, P.G., Komanduri, S., Mazurek, M.L., Shay, R., Vidas, T., Bauer, L., Christin, N., Cranor, L.F., Lopez, J.: Guess again (and again and again): Measuring password strength by simulating password-cracking algorithms. In: 2012 IEEE Symposium on Security and Privacy (SP), pp. 523–537, May 2012
17.
Zurück zum Zitat Kohonen, T.: Associative Memory: A System-Theoretical Approach. Springer, Berlin (1977)CrossRefMATH Kohonen, T.: Associative Memory: A System-Theoretical Approach. Springer, Berlin (1977)CrossRefMATH
18.
Zurück zum Zitat Komanduri, S., Shay, R., Kelley, P.G., Mazurek, M.L., Bauer, L., Christin, N., Cranor, L.F., Egelman, S.: Of passwords and people: measuring the effect of password-composition policies. In: Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, CHI 2011, New York, NY, USA, pp. 2595–2604. ACM (2011) Komanduri, S., Shay, R., Kelley, P.G., Mazurek, M.L., Bauer, L., Christin, N., Cranor, L.F., Egelman, S.: Of passwords and people: measuring the effect of password-composition policies. In: Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, CHI 2011, New York, NY, USA, pp. 2595–2604. ACM (2011)
20.
Zurück zum Zitat Miller, G.A.: The magical number seven, plus or minus two: some limits on our capacity for processing information. Psychol. Rev. 63(2), 81–97 (1956)CrossRef Miller, G.A.: The magical number seven, plus or minus two: some limits on our capacity for processing information. Psychol. Rev. 63(2), 81–97 (1956)CrossRef
21.
Zurück zum Zitat Sandvoll, M.: Design and analysis of a password management system. Masters thesis, NTNU (2014) Sandvoll, M.: Design and analysis of a password management system. Masters thesis, NTNU (2014)
22.
Zurück zum Zitat Smith, R.E.: The strong password dilemma. Comput. Secur. J. 18(2), 31–38 (2002) Smith, R.E.: The strong password dilemma. Comput. Secur. J. 18(2), 31–38 (2002)
23.
Zurück zum Zitat Squire, L.R.: On the course of forgetting in very long-term-memory. J. Exp. Psychol. Learn. 15(2), 241–245 (1989)CrossRef Squire, L.R.: On the course of forgetting in very long-term-memory. J. Exp. Psychol. Learn. 15(2), 241–245 (1989)CrossRef
25.
Zurück zum Zitat Willshaw, D.J., Buckingham, J.T.: An assessment of Marrs theory of the hippocampus as a temporary memory store. Philos. Trans. R. Soc. Lond. B. Biol. Sci. 329(1253), 205–215 (1990)CrossRef Willshaw, D.J., Buckingham, J.T.: An assessment of Marrs theory of the hippocampus as a temporary memory store. Philos. Trans. R. Soc. Lond. B. Biol. Sci. 329(1253), 205–215 (1990)CrossRef
26.
Zurück zum Zitat Woźniak, P.A., Gorzelańczyk, E.J.: Optimization of repetition spacing in the practice of learning. Acta Neurobiol. Exp. 54(1), 59–62 (1994) Woźniak, P.A., Gorzelańczyk, E.J.: Optimization of repetition spacing in the practice of learning. Acta Neurobiol. Exp. 54(1), 59–62 (1994)
27.
Zurück zum Zitat Yan, J., Blackwell, A., Anderson, R., Grant, A.: Password memorability and security: empirical results. IEEE Secur. Priv. 2(5), 25–31 (2004)CrossRef Yan, J., Blackwell, A., Anderson, R., Grant, A.: Password memorability and security: empirical results. IEEE Secur. Priv. 2(5), 25–31 (2004)CrossRef
Metadaten
Titel
PassCue: The Shared Cues System in Practice
verfasst von
Mats Sandvoll
Colin Boyd
Bjørn B. Larsen
Copyright-Jahr
2015
DOI
https://doi.org/10.1007/978-3-319-24192-0_8