Authentication for Humans.ppt
《Authentication for Humans.ppt》由会员分享,可在线阅读,更多相关《Authentication for Humans.ppt(22页珍藏版)》请在麦多课文档分享上搜索。
1、Authentication for Humans,Rachna Dhamija SIMS, UC Berkeley rachnasims.berkeley.eduDIMACS Workshop on Usable Privacy and Security Software July 7, 2004,Talk Outline,Machines Authenticating Users Dj Vu User Study- Using Images for AuthenticationUsers Authenticating Remote Servers Interfaces for websit
2、e authentication,Password Usability and Security,Simple and meaningful passwords - Memorable, but easier to guessComplex passwords - Strong, but hard to rememberAdvantages of passwords Cheap and easy to implement We develop muscle memory,Previous Solutions,Stronger password hashing & storage Proacti
3、ve password cracking Enforce system policies Better user education and training Significant non compliance rate by usersWe try to address the fundamental problem: Recall is hard,Picture recognition is easier,Humans have a vast memory for pictures 2560 photos for a few seconds: 90% recognition Standi
4、ng, Conezio, Haber 10,000 photos: 66% recognition after 2 days Standing 200 random photos: 90% after 1-3 months Weinshal/Kirkpatrik, CHI2004 Fractions of a second is enough to remember Picture recognition is easier than verbal recognition Picture recognition is easier than picture recall Harder to r
5、ecall semantics or to redraw picture But picture recall is better than verbal recall,Dj Vu Design Goals,Base security on human strengths Recognition over recallPrevent weak passwordsPrevent password sharingNo biometrics or tokens,Authentication through Images,Choose image portfolio Challenge set = p
6、ortfolio + decoys Photos and Random Art,Random Art,Algorithm: seed - pseudo-random number generator- random expression tree maps pixels to RGB - random art,Choose Image Portfolio,Portfolio Training,Challenge,Portfolio Creation Screen,Login Screen,Attacks,Brute Force optimal portfolio and challenge d
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
2000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- AUTHENTICATIONFORHUMANSPPT
