A study on password system with shoulder surfing resistance

碩士 === 國立交通大學 === 資訊科學與工程研究所 === 98 === The most common way to protect the user accounts is to authenticate users through their textual account/password. However, account stealing is still a serious problem. Besides the use of weak/simple password or accidently letting out the password by themselv...

Full description

Bibliographic Details
Main Authors: Lee, You-Shung, 李侑昇
Other Authors: Tsai, Wen-Nung
Format: Others
Language:zh-TW
Published: 2010
Online Access:http://ndltd.ncl.edu.tw/handle/20035793339445917679
id ndltd-TW-098NCTU5394085
record_format oai_dc
spelling ndltd-TW-098NCTU53940852016-04-18T04:21:39Z http://ndltd.ncl.edu.tw/handle/20035793339445917679 A study on password system with shoulder surfing resistance 關於密碼系統抵抗側錄攻擊之研究 Lee, You-Shung 李侑昇 碩士 國立交通大學 資訊科學與工程研究所 98 The most common way to protect the user accounts is to authenticate users through their textual account/password. However, account stealing is still a serious problem. Besides the use of weak/simple password or accidently letting out the password by themselves, data logging tools like keystroke logger (keylogger) are often used to steal account/password. This behavior is called “shoulder surfing” attack because that it is very similar to the case that someone watching you while you are typing your password. Although there are new types of authentication method, which data logging has less effect on, but those methods usually need extra hardware during the login procedure. Some researchers had been trying to find better authenticating methods without extra hardware. In this thesis, we proposed a method with shoulder surfing resistance to authenticate user without special hardware by using an on screen grid structure with user defined rules. Applying user-defined rules to random grid layout on the screen, a dynamic password is required during the login procedure. And thus, it is hard to analyze the logging data when the authenticating rules are unknown. Tsai, Wen-Nung 蔡文能 2010 學位論文 ; thesis 65 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 碩士 === 國立交通大學 === 資訊科學與工程研究所 === 98 === The most common way to protect the user accounts is to authenticate users through their textual account/password. However, account stealing is still a serious problem. Besides the use of weak/simple password or accidently letting out the password by themselves, data logging tools like keystroke logger (keylogger) are often used to steal account/password. This behavior is called “shoulder surfing” attack because that it is very similar to the case that someone watching you while you are typing your password. Although there are new types of authentication method, which data logging has less effect on, but those methods usually need extra hardware during the login procedure. Some researchers had been trying to find better authenticating methods without extra hardware. In this thesis, we proposed a method with shoulder surfing resistance to authenticate user without special hardware by using an on screen grid structure with user defined rules. Applying user-defined rules to random grid layout on the screen, a dynamic password is required during the login procedure. And thus, it is hard to analyze the logging data when the authenticating rules are unknown.
author2 Tsai, Wen-Nung
author_facet Tsai, Wen-Nung
Lee, You-Shung
李侑昇
author Lee, You-Shung
李侑昇
spellingShingle Lee, You-Shung
李侑昇
A study on password system with shoulder surfing resistance
author_sort Lee, You-Shung
title A study on password system with shoulder surfing resistance
title_short A study on password system with shoulder surfing resistance
title_full A study on password system with shoulder surfing resistance
title_fullStr A study on password system with shoulder surfing resistance
title_full_unstemmed A study on password system with shoulder surfing resistance
title_sort study on password system with shoulder surfing resistance
publishDate 2010
url http://ndltd.ncl.edu.tw/handle/20035793339445917679
work_keys_str_mv AT leeyoushung astudyonpasswordsystemwithshouldersurfingresistance
AT lǐyòushēng astudyonpasswordsystemwithshouldersurfingresistance
AT leeyoushung guānyúmìmǎxìtǒngdǐkàngcèlùgōngjīzhīyánjiū
AT lǐyòushēng guānyúmìmǎxìtǒngdǐkàngcèlùgōngjīzhīyánjiū
AT leeyoushung studyonpasswordsystemwithshouldersurfingresistance
AT lǐyòushēng studyonpasswordsystemwithshouldersurfingresistance
_version_ 1718226613284372480