• DocumentCode
    2028093
  • Title

    Towards a metric for recognition-based graphical password security

  • Author

    English, Rosanne ; Poet, Ron

  • Author_Institution
    Sch. of Comput. Sci., Univ. of Glasgow, Glasgow, UK
  • fYear
    2011
  • fDate
    6-8 Sept. 2011
  • Firstpage
    239
  • Lastpage
    243
  • Abstract
    Recognition-based graphical password (RBGP) schemes are not easily compared in terms of security. Current research uses many different measures which results in confusion as to whether RBGP schemes are secure against guessing and capture attacks. If it were possible to measure all RBGP schemes in a common way it would provide an easy comparison between them, allowing selection of the most secure design. This paper presents a discussion of potential attacks against recognition-based graphical password (RBGP) authentication schemes. As a result of this examination a preliminary measure of the security of a recognition-based scheme is presented. The security measure is a 4-tuple based on distractor selection, shoulder surfing, intersection and replay attacks. It is aimed to be an initial proposal and is designed in a way which is extensible and adjustable as further research in the area develops. Finally, an example is provided by application to the PassFaces scheme.
  • Keywords
    authorisation; computer graphics; software metrics; PassFaces scheme; authentication schemes; distractor selection; intersection attacks; recognition based graphical password security metric; replay attacks; shoulder surfing; Authentication; Dictionaries; Educational institutions; Radiation detectors; Semantics; Servers;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network and System Security (NSS), 2011 5th International Conference on
  • Conference_Location
    Milan
  • Print_ISBN
    978-1-4577-0458-1
  • Type

    conf

  • DOI
    10.1109/ICNSS.2011.6060007
  • Filename
    6060007