A study on password system with shoulder surfing resistance
碩士 === 國立交通大學 === 資訊科學與工程研究所 === 98 === The most common way to protect the user accounts is to authenticate users through their textual account/password. However, account stealing is still a serious problem. Besides the use of weak/simple password or accidently letting out the password by themselv...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | zh-TW |
Published: |
2010
|
Online Access: | http://ndltd.ncl.edu.tw/handle/20035793339445917679 |
id |
ndltd-TW-098NCTU5394085 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-098NCTU53940852016-04-18T04:21:39Z http://ndltd.ncl.edu.tw/handle/20035793339445917679 A study on password system with shoulder surfing resistance 關於密碼系統抵抗側錄攻擊之研究 Lee, You-Shung 李侑昇 碩士 國立交通大學 資訊科學與工程研究所 98 The most common way to protect the user accounts is to authenticate users through their textual account/password. However, account stealing is still a serious problem. Besides the use of weak/simple password or accidently letting out the password by themselves, data logging tools like keystroke logger (keylogger) are often used to steal account/password. This behavior is called “shoulder surfing” attack because that it is very similar to the case that someone watching you while you are typing your password. Although there are new types of authentication method, which data logging has less effect on, but those methods usually need extra hardware during the login procedure. Some researchers had been trying to find better authenticating methods without extra hardware. In this thesis, we proposed a method with shoulder surfing resistance to authenticate user without special hardware by using an on screen grid structure with user defined rules. Applying user-defined rules to random grid layout on the screen, a dynamic password is required during the login procedure. And thus, it is hard to analyze the logging data when the authenticating rules are unknown. Tsai, Wen-Nung 蔡文能 2010 學位論文 ; thesis 65 zh-TW |
collection |
NDLTD |
language |
zh-TW |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 國立交通大學 === 資訊科學與工程研究所 === 98 === The most common way to protect the user accounts is to authenticate users through their textual account/password. However, account stealing is still a serious problem. Besides the use of weak/simple password or accidently letting out the password by themselves, data logging tools like keystroke logger (keylogger) are often used to steal account/password. This behavior is called “shoulder surfing” attack because that it is very similar to the case that someone watching you while you are typing your password.
Although there are new types of authentication method, which data logging has less effect on, but those methods usually need extra hardware during the login procedure. Some researchers had been trying to find better authenticating methods without extra hardware.
In this thesis, we proposed a method with shoulder surfing resistance to authenticate user without special hardware by using an on screen grid structure with user defined rules. Applying user-defined rules to random grid layout on the screen, a dynamic password is required during the login procedure. And thus, it is hard to analyze the logging data when the authenticating rules are unknown.
|
author2 |
Tsai, Wen-Nung |
author_facet |
Tsai, Wen-Nung Lee, You-Shung 李侑昇 |
author |
Lee, You-Shung 李侑昇 |
spellingShingle |
Lee, You-Shung 李侑昇 A study on password system with shoulder surfing resistance |
author_sort |
Lee, You-Shung |
title |
A study on password system with shoulder surfing resistance |
title_short |
A study on password system with shoulder surfing resistance |
title_full |
A study on password system with shoulder surfing resistance |
title_fullStr |
A study on password system with shoulder surfing resistance |
title_full_unstemmed |
A study on password system with shoulder surfing resistance |
title_sort |
study on password system with shoulder surfing resistance |
publishDate |
2010 |
url |
http://ndltd.ncl.edu.tw/handle/20035793339445917679 |
work_keys_str_mv |
AT leeyoushung astudyonpasswordsystemwithshouldersurfingresistance AT lǐyòushēng astudyonpasswordsystemwithshouldersurfingresistance AT leeyoushung guānyúmìmǎxìtǒngdǐkàngcèlùgōngjīzhīyánjiū AT lǐyòushēng guānyúmìmǎxìtǒngdǐkàngcèlùgōngjīzhīyánjiū AT leeyoushung studyonpasswordsystemwithshouldersurfingresistance AT lǐyòushēng studyonpasswordsystemwithshouldersurfingresistance |
_version_ |
1718226613284372480 |