• DocumentCode
    1453588
  • Title

    User Study, Analysis, and Usable Security of Passwords Based on Digital Objects

  • Author

    Biddle, Robert ; Mannan, Mohammad ; Van Oorschot, Paul C. ; Whalen, Tara

  • Author_Institution
    Sch. of Comput. Sci., Carleton Univ., Ottawa, ON, Canada
  • Volume
    6
  • Issue
    3
  • fYear
    2011
  • Firstpage
    970
  • Lastpage
    979
  • Abstract
    Despite all efforts, password schemes intended to deploy or encourage the use of strong passwords have largely failed. As an alternative to enable users to create, maintain, and use high-quality passwords willingly, we propose Object-based Password (ObPwd), leveraging the universe of personal or personally meaningful digital content that many users now own or have access to. ObPwd converts user-selected digital objects to high-entropy text passwords. Memorization of exact passwords is replaced by remembering password objects. We present the design details, variants, and usability and security analysis of ObPwd, and report on the results of a hybrid in-lab/at-home user study on 32 participants. The results suggest the scheme has good usability, with excellent memorability, acceptable login times, and very positive user perception, achieved while providing strong security for the threat context explored. We believe this work lays the foundation for a promising password selection paradigm.
  • Keywords
    message authentication; ObPwd; high-entropy text passwords; object-based password; password selection paradigm; password usable security; user-selected digital objects; Authentication; Dictionaries; Electronic mail; Fires; Portable computers; Usability; Affective passwords; image-based passwords; password authentication; personal digital objects; usable security;
  • fLanguage
    English
  • Journal_Title
    Information Forensics and Security, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1556-6013
  • Type

    jour

  • DOI
    10.1109/TIFS.2011.2116781
  • Filename
    5715877