跳到主要內容

臺灣博碩士論文加值系統

(216.73.217.33) 您好!臺灣時間:2026/09/25 14:36
字體大小: 字級放大   字級縮小   預設字形  
回查詢結果 :::

詳目顯示

: 
twitterline
研究生:邱培嘉
研究生(外文):Pei-Jia QIU
論文名稱:以數字與圖示及位置為基礎之可抵擋觀察攻擊的圖形化通行碼設計
論文名稱(外文):Observation Attacks Resistant Graphical Password Schemes Based on Number-Icon-Location
指導教授:顧維祺
指導教授(外文):Wei-Chi KU
口試委員:顧維祺、林嬿雯、洪國寶
口試委員(外文):Wei-Chi KU、Yen-Wen Lin、Gwoboa Horng
口試日期:2015-07-02
學位類別:碩士
校院名稱:國立臺中教育大學
系所名稱:資訊工程學系
學門:工程學門
學類:電資工程學類
論文種類:學術論文
論文出版年:2015
畢業學年度:103
語文別:中文
論文頁數:33
中文關鍵詞:意外登入、觀察攻擊、圖形化通行碼、安全性、使用性
外文關鍵詞:Accidental Login、Observation Attacks、Graphical Password、Security、Usability
相關次數:
  • 被引用被引用:0
  • 點閱點閱:157
  • 評分評分:
  • 下載下載:9
  • 收藏至我的研究室書目清單書目收藏:0
使用者在使用通行碼登入系統的認證過程中可能遭受肩窺攻擊或攝影機攻擊等的觀察攻擊,觀察攻擊者藉由觀察使用者的登入資訊以直接獲得或經分析比對後破解使用者的通行碼。由於傳統的文字通行碼設計與一般的圖形化通行碼設計皆無法防禦觀察攻擊,因此,Sobrado和Birget在2002年提出三套防觀察攻擊之圖形化通行碼設計,此後,有許多安全性與使用性各異的防觀察攻擊之圖形化通行碼設計被提出,然而這些設計多未同時具備高使用性和符合大多數應用環境的安全需求。在本論文中,我們提出一套基於動態圖示的改良型防觀察攻擊之圖形化通行碼設計 ─ NIL,此設計結合數字、圖示與位置的記憶方式,減少同類型物件的記憶干擾,同時具備易於學習的優點,並可滿足大多數應用環境的安全需求。然而,考量對於部分重視效率的應用系統而言,NIL的登入時間可能仍然太長,因此我們在本論文中另提出一套NIL的修改設計 ─ NILplus,藉由耳機的輔助改變登入方式以大幅度減少登入時間,進而提高使用性。另外,在安全性方面,使用耳機作為Second Channel的方法可減少登入過程中外洩破解資訊給攻擊者的機會,因此亦可提升觀察攻擊的抵擋能力。有別於一般對於圖形化通行碼研究較片面、籠統且不精確的安全性及使用性分析,我們以客觀的量化分析方法來分析我們所提兩套設計的安全性和使用性。
Common textual password schemes and graphical password schemes are vulnerable to observation attacks, in which the adversary can obtain the user's password information while users in the login process by using the shoulder-surfing attack and/or the hidden-camera attack. In 2002, Sobrado and Birget proposed three observation attacks resistant graphical password schemes. Since then, many graphical password schemes with different degrees of resistance to observation attacks have been proposed. However, none of these schemes can achieve both sufficient security and good usability. Herein, we propose an enhanced observation attacks resistant graphical password scheme, NIL, based on moving icons. This memory interference can be reduced by combining simple numbers, icons, and locations. We show that NIL can achieve both sufficient security and good usability for general environments. However, the average login time of NIL is still too long for high-efficiency environments. In addition, the resistance of NIL to observation attacks is insufficient for high threat environments. Therefore, we also propose a modified version of NIL, NILplus. By using earphones, NILplus can significantly decrease the average login time. In addition, the success probability of NILplus to observation attacks will remain extremely low even if the adversary has observed the user's login sessions many times. Furthermore, NILplus is also superior to the NIL with respect to the password space while the resistance of NILplus to accidental login roughly equals NIL.
目錄
摘要 i
Abstract ii
目錄 iii
圖目錄 v
表目錄 vi
第一章 序論 1
第二章 研究背景 6
第三章 高實用性防觀察攻擊之圖形化通行碼-NIL 11
3.1 NIL的介紹 11
3.1.1 註冊階段 11
3.1.2 登入階段 13
3.2 NIL的安全性分析 16
3.2.1 NIL之通行碼空間 16
3.2.2 NIL之意外登入抵擋能力 16
3.2.3 NIL之觀察攻擊抵擋能力 17
3.3 NIL的使用性分析 18
3.3.1 NIL之記憶負擔 18
3.3.2 NIL之學習難易度 19
3.3.3 NIL之操作負擔 19
3.3.4 NIL之登入時間 19
3.4 NIL與CHC的安全性及使用性比較 20
第四章 運用耳機以防觀察攻擊之圖形化通行碼-NILplus 21
4.1 NILplus的介紹 21
4.1.1 註冊階段 21
4.1.2 登入階段 22
4.2 NILplus的安全性分析 25
4.2.1 NILplus之通行碼空間 25
4.2.2 NILplus之意外登入抵擋能力 25
4.2.3 NILplus之觀察攻擊抵擋能力 26
4.3 NILplus的使用性分析 26
4.3.1 NILplus之記憶負擔 26
4.3.2 NILplus之學習難易度 26
4.3.3 NILplus之操作負擔 27
4.3.4 NILplus之登入時間 27
4.4 NILplus與NIL的安全性及使用性比較 28
第五章 結論 29
參考文獻 30
著作目錄 33
[AM13]I. AM and P. Patil, “Graphical password authentication using persuasive cued click point,” International Journal of Advanced Research in Electrical, Electronics and Instrumentation Engineering, vol. 2, issue 7, July 2013.
[Ande96]M. C. Anderson and J. M. Neely, Handbook of Perception and Cognition, 2nd Ed., Academic Press, New York, NY. Chapter 8, pp. 237-313, 1996.
[Bian11]A. Bianchi, I. Oakley, V. Kostakos, and D. S. Kwon, “The phone lock: Audio and haptic shoulder-surfing resistant PIN entry methods for mobile devices,” Proceedings of the 2011 TEI, 2011, pp. 197–200, 2011.
[Bian12]A. Bianchi, I. Oakley, and D. S. Kwon, “Counting clicks and beeps: Exploring numerosity based haptic and audio PIN entry,” Interact. Comput., vol. 24, no. 5, pp. 409–422, 2012.
[Bidd12]R. Biddle, S. Chiasson, and P. C. van Oorschot, “Graphical passwords: Learning from the first twelve years,” ACM Computing Surveys, vol. 44, no. 4, 2012.
[Blon96]G. E. Blonder, “Graphical passwords,” U. S. Patent 5 559 961, 1996.
[Calk98]M. W. Calkins, “Short studies in memory and association,” Psychological Review, vol. 5, pp. 451-462, 1898.
[Chen11]W. P. Chen, B. R. Cheng, W. C. Ku, and Y. C. Yeh, “A graphical password scheme with dynamically adjustable resistance to login-recording attacks,” Proceedings of the 2011 National Computer Symposium, 2011.
[Eeke13]W. V. Eekelen, J. V. D. Elst, and V. J. Khan, “Picassopass: A password scheme using a dynamically layered combination of graphical elements,” Proceedings of the 2013 CHI, 2013.
[Gao09a]H. Gao, X. Liu, S. Wang, H. Liu, and R. Dai, “Design and analysis of a graphical password scheme,” Proceedings of the 4th International Conference on Innovative Computing, Information and Control, 2009.
[Gao09b]H. Gao, X. Liu, S. Wang, and R. Dai, “A new graphical scheme against spyware by using CAPTCHA,” Proceedings of the 2009 Symposium on Usable Privacy and Security, 2009.
[Grid15]GrIDsure, (http://www.gridsure-security.co.uk/).
[Haqu14]A. Haque and B. Imam, “A new graphical password: Combination of recall & recognition based approach,” International Journal of Computer, Information Science and Engineering, vol. 8, no.2, 2014.
[Hart06]B. Hartanto, B. Santoso, and S. Welly, “The usage of graphical password as a replacement to the alphanumerical password,” Journal Informatika, vol. 7, no. 2, 2006.
[Hoan05]B. Hoanca and K. Mock, “Screen oriented technique for reducing the incidence of shoulder surfing,” Proceedings of the International Conference on Security and Management, 2005.
[Jerm99]I. Jermyn, A. Mayer, F. Monrose, M. Reiter, and A. Rubin, “The design and analysis of graphical passwords,” Proceedings of the 8th USENIX Security Symposium, pp. 1-14, 1999.
[Kim11]S. H. Kim, J. W. Kim, S. Y. Kim, and H. G. Cho, “A new shoulder-surfing resistant password for mobile environments,” Proceedings of the 5th International Conference on Ubiquitous Information Management and Communication, 2011.
[Kim12a]S. H. Kim, and H. G. Cho, “Candidate password analysis of user-interactive password schemes,” Proceedings of the 2012 International Conference on Information and Computer Applications, 2012.
[Kim12b]S. H. Kim and H. G. Cho, “A grid based password system against shoulder surfing using hidden challenges,” Proceedings of the 2012 IST, pp. 296-298, 2012.
[Kirk94]B. Kirkpatrick, “An experimental study of memory,” Psychological Review, vol. 1, pp. 602-609, 1894.
[Kita13]Y. Kita, F. Sugai, M. Park, and N. Okazaki, “A proposal and implementation of the shoulder-surfing attack resistant authentication method using two shift functions,” Proceedings of the Second International Conference on Cyber Security, Cyber Peacefare and Digital Forensic, pp. 54-59, 2013.
[Koma08]S. Komanduri and D. R. Hutchings, “Order and entropy in picture passwords,” Proceedings of the 2008 Graphics Interface Conference, 2008.
[Kuri14]T. Kuribara, B. Shizuki, and J. Tanaka, “VibraInput: Two-step PIN entry system based on vibration and visual information,” Proceedings of the 2014 CHI, pp. 2473-2478, 2014.
[Lada13]A. Ladage, S. Gaikwad, and A. Chougule, “Graphical based password authentication,” International Journal of Engineering Research & Technology, vol. 2, issue 4, 2013.
[Li05]Z. Li, Q. Sun, Y. Lian, and D. D. Giusto, “An association-based graphical password design resistant to shoulder-surfing attack,” Proceedings of the IEEE International Conference on Multimedia and EXPO, 2005.
[Liu11]X. Liu, J. Qiu, L. Ma, H. Gao, and Z. Ren, “A novel cued-recall graphical password scheme,” Proceedings of the 2011 Sixth International Conference on Image and Graphics, pp. 949-956, 2011.
[Luca13]A. Luca, E. Zezschwitz, N. Nguyen, M. Maurer, E. Rubegni, M. Scipioni, and M. Langheinrich, “Back-of-device authentica¬tion on smartphones,” Proceedings of the 2013 CHI, 2013.
[Madi83]S. Madigan, “Picture memory,” Imagery, memory and cognition, pp. 65–89, 1983.
[Mulw13]K. Mulwani, S. Naik, N. Gurnani, N. Giri, and S. Sengupta, “3LAS (three level authentication scheme),” International Journal of Emerging Technology and Advanced Engineering, vol. 3, pp. 103-107, 2013.
[Rao12]M. K. Rao and S. Yalamanchili, “Novel shoulder-surfing resistant authentication schemes using text-graphical passwords,” International Journal of Information & Network Security, vol. 1, no. 3, pp. 163-170, 2012.
[Ritt13]D. Ritter, F. Schaub, M. Walch, and M. Weber, “MIBA: Multitouch image-based authentication on smartphones,” Proceedings of the 2013 CHI, 2013.
[Sin11]C. Singh and L. Singh, “Investigating the combination of text and graphical passwords for a more secure and usable experience,” International Journal of Network Security & Its Applications, vol. 3, no. 2, 2011.
[Sobr02]L. Sobrado and J. C. Birget, “Graphical passwords,” The Rutgers Scholar, vol. 4, 2002.
[Sobr05]L. Sobrado and J. C. Birget, “Shoulder-surfing resistant graphical passwords,” Draft, 2005.
[SSL11]The Secure Sockets Layer (SSL) Protocol Version 3.0, RFC 6101, 2011.
[Thor04]J. Thorpe and P. C. Van Oorschot, “Graphical dictionaries and the memorable space of graphical passwords,” Proceedings of the 13th USENIX Security Symposium, 2004.
[TLS08]The Transport Layer Security (TLS) Protocol Version 1.2, RFC 5246, 2008.
[Wied05]S. Wiedenbeck, J. Waters, J. C. Birget, A. Brodskiy, and N. Memon, “PassPoints: Design and longitudinal evaluation of a graphical password system,” International Journal of Human Computer Studies, vol. 63, no. 1, pp. 102-127, 2005.
[Wied06]S. Wiedenbeck, J. Waters, L. Sobrado, and J. C. Birget, “Design and evaluation of a shoulder-surfing resistant graphical password scheme,” Proceedings of the 2006 Advanced Visual Interfaces, 2006.
[Wixt04]J. T. Wixted, “The psychology and neuroscience of forgetting,” Annual Review of Psychology, vol. 55, pp. 235-269, 2004.
[Wu14]T. Wu, M. Lee, H. Lin, and C. Wang, “Shoulder-surfing-proof graphical password authentication scheme,” International Journal of Information Security, vol. 13, pp. 245-254, 2014.
[Yama09]T. Yamamoto, Y. Kojima, and M. Nishigaki, “A shoulder-surfing-resistant image-based authentication system with temporal indirect image selection,” Proceedings of the 2009 International Conference on Security & Management, pp. 188-194, 2009.
[Zhao07]H. Zhao and X. Li, “S3PAS: A scalable shoulder-surfing resistant textual-graphical password authentication scheme,” Proceedings of the 21st International Conference on Advanced Information Networking and Applications Workshops, vol. 2, pp. 467-472, 2007.
[Zhen09]Z. Zheng, X. Liu, L. Yin, and Z. Liu, “A stroke-based textual password authentication scheme,” First International Workshop on Education Technology and Computer Science, 2009.
[Zheng10]Z. Zheng, X. Liu, L. Yin, and Z. Liu, “A hybrid password authentication scheme based on shape and text,” Journal of Computers, vol. 5, no. 5, 2010.

QRCODE
 
 
 
 
 
                                                                                                                                                                                                                                                                                                                                                                                                               
第一頁 上一頁 下一頁 最後一頁 top