DocumentCode
1799970
Title
Improving usability of passphrase authentication
Author
Nielsen, Glen ; Vedel, Michael ; Jensen, Christian D.
Author_Institution
Dept. of Appl. Math. & Comput. Sci., Tech. Univ. of Denmark, Lyngby, Denmark
fYear
2014
fDate
23-24 July 2014
Firstpage
189
Lastpage
198
Abstract
The combination of user-names and passwords has become the predominant method of user authentication in computer systems. Most users have multiple accounts on different systems, which impose different constraints on the length and complexity of passwords that the user is allowed to select. This is done to ensure an appropriate degree of security, but instead, it makes it difficult for users to remember their password, which results in passwords that are either insecure, but easy to remember, or written down on paper. In this paper we address the problem of usability in user authentication. We promote the use of passphrases, which provide better security and are often easier to remember than passwords. Passphrases will be significantly longer than passwords, which makes them more difficult to enter correctly on a keyboard. We solve this problem by proposing a new passphrase validation algorithm, which accepts the most common typing mistakes. The proposed algorithm has been implemented in secure hardware and integrated into a standard Unix system. We present the design, implementation and preliminary evaluation of the developed passphrase authentication prototype.
Keywords
Unix; cryptography; computer systems; passphrase authentication prototype; passphrase validation algorithm; secure hardware; standard Unix system; user authentication; Authentication; Cryptography; Entropy; Natural languages; Prototypes; Usability;
fLanguage
English
Publisher
ieee
Conference_Titel
Privacy, Security and Trust (PST), 2014 Twelfth Annual International Conference on
Conference_Location
Toronto, ON
Print_ISBN
978-1-4799-3502-4
Type
conf
DOI
10.1109/PST.2014.6890939
Filename
6890939
Link To Document