摘要
针对九宫格手势认证方法中的手势密码的单一性问题,通过增加一位随机数和若干次数变量来改进程序,实现了认证密码的动态变化。通过改进认证过程,减少用户绘制认证点数,提高了认证机制的便捷性。认证过程改进为:根据随机数确定本次认证点数;根据上次成功认证的末位认证点,确定本次认证起始点,即上次成功认证的末位认证点向下间隔一位认证点为本次认证起始点。认证失败3次,随机数会自动更新,认证失败导致随机数更新2次,手机会自动发送具体位置到指定邮箱。最后,通过理论和实验两个方面分析改进后的认证方法的便捷性和安全性。实验表明,改进后的认证方法有效地提高了其安全性与便捷性。
Given the singularity problem of the gesture password in speed dial gesture authentication,we can improve the program by adding a 1-bit random number and some frequency variables,thus realizing the dynamic change of the authentication password.By improving the authentication process,the number of user authentication points is reduced and the convenience of the authentication mechanism is enhanced.The authentication process is improved as following:the number of authentication points is determined according to the random number and the starting point of the authentication is determined according to the last authentication point of the latest successful authentication(i.e.,the authentication point adjacent to the last authentication point of the latest successful authentication is taken as the starting point of the authentication point).If the authentication fails for three times,the random number will be automatically updated.If the random number is updated twice due to the authentication failures,the mobile phone automatically sends its location to the specified mailbox.Finally,the convenience and security of the improved authentication method are analyzed through theory and experiment.Experiments show that the improved authentication method has better security and is more convenient.
作者
耿博
葛丽娜
王秋月
王利娟
GENG Bo;GE Li-na;WANG Qiu-yue;WANG Li-juan(College of Information Science and Engineering,Guangxi University for Nationalities,Nanning 530006;ASEAN Research Center(Guangxi Science Experimental Center),Guangxi University for Nationalities,Nanning 530006,China)
出处
《计算机工程与科学》
CSCD
北大核心
2018年第9期1591-1597,共7页
Computer Engineering & Science
基金
广西自然科学基金(2018GXNSFAA138147)
国家自然科学基金(61462009)
广西民族大学中国-东盟研究中心(广西科学实验中心)2014年度开放课题(TD201404)
关键词
九宫格
随机数
污渍攻击
肩窥攻击
猜测攻击
认证
speed dial
random number
stain attack
shoulder glimpse attack
guessing attack
authentication