期刊文献+

基于中文句法的口令助记策略 被引量:1

Chinese Sentence-based Password Mnemonic Strategy
下载PDF
导出
摘要 助记策略用于帮助用户生成安全性较高且易于记忆的口令,近年来受到中外学者的广泛关注。现有助记策略多存在安全性低、不便记忆等问题。现提出一种基于中文句法的口令助记策略,用户选择一个易于记忆的句子作助记句,利用预定义规则或基于用户的选择,将其转换为口令,通过对照实验评估了其性能。采用马尔可夫链模型等性能评估工具,将实验中收集的口令与大量真实口令进行对比、分析,评估该助记策略的安全性和易用性。在易用性方面,NASA-TLX量表结果显示,虽然使用助记策略在生成口令阶段的负荷量偏高,但在短期可记忆性和长期可记忆性方面,是否使用助记策略没有明显的差别。此外,在安全性方面,所有口令强度评估结果均表明,该助记策略生成的口令强度远高于真实口令。在将助记句转化为口令的同时,本策略隐藏了个人敏感信息,降低了因个人信息泄露而导致口令泄露的风险,提高了方案的安全性。 Mnemonic strategy is used to help users to generate secure and memorable passwords,this topic has attracted extensive interests from worldwide researchers in recent years.Most of the existing mnemonic strategies have some problems such as low security and inconvenient memory.A Chinese sentence-based password mnemonic strategy was presented,the user selects a memorable sentence as a mnemonic sentence,and then converts it into a password based on predefined rules or the user's choice,Its performance was evaluate by a control experiment.To evaluate the security and usability of the mnemonic strategy,performance assessment tools such as the Markov chain model,was used to compare the generated passwords with a large number of real-world passwords.In terms of usability,NASA-TLX shows that although the workloads required in our mnemonic strategy are higher than those from non-strategy in password generation phase,whether to use mnemonic strategies has no significant difference in short-term memory and long-term memory.In addition,in terms of security,all password strength assessment tools show that the passwords generated by our mnemonic strategy are stronger than the real-world passwords.While converting the mnemonic sentence into a password,this strategy hides personal sensitive information,so it reduces the risk of password leakage due to personal information leakage,and improves the security of the strategy.
作者 张艺 咸鹤群 于爱民 ZHANG Yi;XIAN He-qun;YU Ai-min(College of Computer Science Technology, Qingdao University, Qingdao 266071, China;Institute of Information Engineerging, Chinese Academy of Science, Beijing 100093, China)
出处 《科学技术与工程》 北大核心 2019年第35期253-258,共6页 Science Technology and Engineering
基金 国家自然科学基金(61303197、61702294) 山东省自然科学基金(ZR2019MF058)资助
关键词 助记策略 口令安全 口令生成 口令强度评估 mnemonic strategy password security password generation password strength assessment
  • 相关文献

参考文献5

二级参考文献18

  • 1Yah J, Blackwell A, Anderson and security: Empirical results. Magazine, 2004, 2(5): 25-31.
  • 2R. Password memorability IEEE Security & Privacy Daniel V K. Foiling the cracker: A survey of, and improve- ments to, password security. Programming and Computer Software, 1992, 17(3): 158-166.
  • 3Bloom B. Space/time trade-offs in hash coding with allowable errors. Communications of the ACM, 1979, 13(7): 422-426.
  • 4Chris D, Ravi G. BApasswd: A new proactive password eheeker//Proceedings of the 16th National Computer Security Conference. Baltimore, USA, 1993:1-15.
  • 5Pham H P, Phan D D, Duong N T, et al. Password recoveryfor encrypted ZIP archives using GPUs//Proeeedings of the 2010 Symposium on Information and Communication Technology. Hanoi, Vietnam, 2010.. 27-28.
  • 6Miller G A. The magical number seven, plus or minus two: Limits on our capacity for processing Information. Psycho- logical Review, 1956, 63(2): 81-87.
  • 7Johnson G J. A distinctiveness model of serial learning. Psychological Review, 1991, 98(2): 204-217.
  • 8Paivio A. Dual coding theory: Retrospect and current status. Journal of Psychology, 1991, 45(3) : 255-287.
  • 9McDowell M, Hernan S, Rafail J. Security Tip (ST04-002) : Choosing and Protecting Passwords. US-CERT, 2013.06.
  • 10Burr W E, Dodson D F, Newton E M, et al. Electronic Authentication Guideline. US-NIST. 2014.04.

共引文献66

同被引文献2

引证文献1

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部