• DocumentCode
    2554327
  • Title

    Password-based authentication: a system perspective

  • Author

    Conklin, Art ; Dietrich, Glenn ; Walz, Diane

  • Author_Institution
    Dept. of Inf. Syst., Texas Univ., San Antonio, TX, USA
  • fYear
    2004
  • fDate
    5-8 Jan. 2004
  • Abstract
    User authentication in computer systems has been a cornerstone of computer security for decades. The concept of a user id and password is a cost effective and efficient method of maintaining a shared secret between a user and a computer system. One of the key elements in the password solution for security is a reliance on human cognitive ability to remember the shared secret. In early computing days with only a few computer systems and a small select group of users, this model proved effective. With the advent of the Internet, e-commerce, and the proliferation of PCs in offices and schools, the user base has grown both in number and in demographic base. Individual users no longer have single passwords for single systems, but are presented with the challenge of remembering numerous passwords for numerous systems, from email, to web accounts, to banking and financial services. This paper presents a conceptual model depicting how users and systems work together in this function and examines the consequences of the expanding user base and the use of password memory aids. A system model of the risks associated with password-based authentication is presented from a user centric point of view including the construct of user password memory aids. When confronted with too much data to remember, users develop memory aids to assist them in the task of remembering important pieces of information. These user password memory aids form a bridge between otherwise unconnected systems and have an effect on system level security across multiple systems interconnected by the user. A preliminary analysis of the implications of this user centric interconnection of security models is presented.
  • Keywords
    authorisation; message authentication; computer security; password memory aids; password-based authentication; Authentication; Computer security; Costs; Demography; Educational institutions; Electronic mail; Humans; Information security; Internet; Personal communication networks;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    System Sciences, 2004. Proceedings of the 37th Annual Hawaii International Conference on
  • Print_ISBN
    0-7695-2056-1
  • Type

    conf

  • DOI
    10.1109/HICSS.2004.1265412
  • Filename
    1265412