Enhanced textual password scheme for better security and memorability

Hina Bhanbhro, Shah Zaman Nizamani, Syed Raheel Hassan, Sheikh Tahir Bakhsh, Madini O. Alassafi

Allbwn ymchwil: Cyfraniad at gyfnodolynErthygladolygiad gan gymheiriaid

4 Dyfyniadau (Scopus)


Traditional textual password scheme provides a large number of password combinations but users generally use a small portion of available password space. Complex textual passwords are difficult to remember, therefore most users choose passwords with small length and contain dictionary words. Due to the use of small password length and dictionary words, textual passwords become easy to crack through offline guessability attacks. Traditional textual passwords scheme is also weak against keystroke logger attacks because alphanumeric characters are directly inserted into the password field. In this paper, enhancements are proposed in the registration and login screen of the traditional textual password scheme for improving security against offline guessability attacks and keystroke logger attacks. The proposed registration screen also improve memorability of traditional textual passwords through visual cues or patternbased approach. In the proposed login screen, passwords are indirectly inserted into the password field, to resist keystroke logger attacks. A comparative analysis between the passwords created in traditional and proposed pattern-based approach is presented. The testing results show that users create strong and high entropy passwords in the proposed pattern-based approach as compared to the traditional textual passwords approach.

Iaith wreiddiolSaesneg
Tudalennau (o-i)209-215
Nifer y tudalennau7
CyfnodolynInternational Journal of Advanced Computer Science and Applications
Rhif cyhoeddi7
Dynodwyr Gwrthrych Digidol (DOIs)
StatwsCyhoeddwyd - 2018
Cyhoeddwyd yn allanolIe

Dyfynnu hyn