Leakage Resilient Password Systems Leakage Resilient Password Systems
SpringerBriefs in Computer Science

Leakage Resilient Password Systems

Yingjiu Li and Others
    • $59.99
    • $59.99

Publisher Description

This book investigates tradeoff between security and usability in designing leakage resilient password systems (LRP) and introduces two practical LRP systems named Cover Pad and ShadowKey. It demonstrates that existing LRP systems are subject to both brute force attacks and statistical attacks and that these attacks cannot be effectively mitigated without sacrificing the usability of LRP systems. Quantitative analysis proves that a secure LRP system in practical settings imposes a considerable amount of cognitive workload unless certain secure channels are involved. The book introduces a secure and practical LRP system, named Cover Pad, for password entry on touch-screen mobile devices. Cover Pad leverages a temporary secure channel between a user and a touch screen which can be easily realized by placing a hand shielding gesture on the touch screen. The temporary secure channel is used to deliver a hidden message to the user for transforming each password symbol before entering it on the touch screen. A user study shows the impact of these testing conditions on the users' performance in practice. Finally, this book introduces a new LRP system named ShadowKey. Shadow Key is designed to achieve better usability for leakage resilient password entry. It leverages either a permanent secure channel, which naturally exists between a user and the display unit of certain mobile devices, or a temporary secure channel, which can be easily realized between a user and a touch screen with a hand-shielding gesture. The secure channel protects the mappings between original password symbols and associated random symbols. Unlike previous LRP system users, Shadow Key users do not need to remember anything except their passwords. Leakage Resilient Password Systems is designed for professionals working in the security industry. Advanced-level students studying computer science and electrical engineering will find this brief full of useful material.

GENRE
Computing & Internet
RELEASED
2015
23 April
LANGUAGE
EN
English
LENGTH
74
Pages
PUBLISHER
Springer International Publishing
SELLER
Springer Nature B.V.
SIZE
1.5
MB

More Books Like This

Technology and Practice of Passwords Technology and Practice of Passwords
2016
ICT Systems Security and Privacy Protection ICT Systems Security and Privacy Protection
2018
Information Systems Security Information Systems Security
2018
Advances in User Authentication Advances in User Authentication
2017
Information Security Applications Information Security Applications
2020
Computer Security -- ESORICS 2015 Computer Security -- ESORICS 2015
2015

More Books by Yingjiu Li, Qiang Yan & Robert H. Deng

Security and Privacy in Communication Networks Security and Privacy in Communication Networks
2018
Security and Privacy in Communication Networks Security and Privacy in Communication Networks
2018
Data and Applications Security and Privacy XXV Data and Applications Security and Privacy XXV
2011

Other Books in This Series

Encrypted Email Encrypted Email
2015
Fitting Splines to a Parametric Function Fitting Splines to a Parametric Function
2019
Edge Computing: A Primer Edge Computing: A Primer
2018
Autonomous Robotics and Deep Learning Autonomous Robotics and Deep Learning
2014
Agile Risk Management Agile Risk Management
2014
Open-Set Text Recognition Open-Set Text Recognition
2024