Title : 
Stronger authentication for password using virtual password and secret little functions
         
        
            Author : 
Umadevi, P. ; Saranya, V.
         
        
            Author_Institution : 
CSE Dept., Arulmigu Meenakshi Amman Coll. of Eng., Thiruvannamalai, India
         
        
        
        
        
        
            Abstract : 
People enjoy the convenience of on-line services, Automated Teller Machines (ATMs), and pervasive computing, but online environments, ATMs, and pervasive computing may bring many risks by adversaries. To prevent users passwords from adversaries by implementing a differentiated virtual password concept in which a user has the freedom to choose a virtual password scheme ranging from weak security to strong security, where a virtual password requires a small amount of human computing to secure users passwords. A user-specified function/program is used to implement the virtual password concept with a tradeoff of security for complexity requiring a small amount of human computing. Further we propose several functions to serve as system recommended functions and provide a security analysis. For user-specified functions, we adopt a secret little functions in which security is enhanced by hiding secret functions/algorithms. Analyze how the proposed scheme defends against phishing, key logger, and shoulder-surfing attacks. The virtual password mechanism is the first one which is able to defend against all three attacks together.
         
        
            Keywords : 
authorisation; computer crime; authentication; key logger; phishing; secret function hiding; secret little functions; security analysis; shoulder-surfing attacks; system recommended functions; user-specified function; user-specified program; virtual password; Authentication; Complexity theory; Educational institutions; Electronic mail; Servers; Trojan horses; Codebooks; differentiated virtual passwords; key logger; phishing; secret little functions; shoulder-surfing;
         
        
        
        
            Conference_Titel : 
Information Communication and Embedded Systems (ICICES), 2014 International Conference on
         
        
            Conference_Location : 
Chennai
         
        
            Print_ISBN : 
978-1-4799-3835-3
         
        
        
            DOI : 
10.1109/ICICES.2014.7033936