Improving password system effectiveness

As computers reach more aspects of our everyday life, so too do the passwords that keep them secure. Coping with these passwords can be a problem for many individuals and organisations who have to deal with the consequences of passwords being forgotten, yet little is known of this issue. This thesis...

Full description

Bibliographic Details
Main Author: Brostoff, Alexander
Published: University College London (University of London) 2005
Subjects:
Online Access:http://ethos.bl.uk/OrderDetails.do?uin=uk.bl.ethos.413494
id ndltd-bl.uk-oai-ethos.bl.uk-413494
record_format oai_dc
spelling ndltd-bl.uk-oai-ethos.bl.uk-4134942016-06-21T03:20:18ZImproving password system effectivenessBrostoff, Alexander2005As computers reach more aspects of our everyday life, so too do the passwords that keep them secure. Coping with these passwords can be a problem for many individuals and organisations who have to deal with the consequences of passwords being forgotten, yet little is known of this issue. This thesis considers the effectiveness of password authentication systems for three groups of stakeholders including users, support staff, and system owners. The initial problem of how to create memorable but secure passwords is reconceptualised as how to improve password system effectiveness. Interview, questionnaire, and system log studies in BT, and experiments at UCL-CS confirm some basic hypotheses about key variables impacting performance, and show that other variables than the memorability of password content are also important which have hitherto not figured in security research and practice. Interventions based on these findings are proposed. Empirical evaluation suggests that the interventions proposed that 'redesign' the user but exclude other parts of the system would fail. Reason's (1990) Generic Error Modelling System (GEMS) is used as a basis for modelling password system performance at the level of individual users. GEMS and the Basic Elements of Production are used generalise these findings, and for the first time to model information security. This new model, "Elevation", is validated by expert review, and a modified version is presented.005.82University College London (University of London)http://ethos.bl.uk/OrderDetails.do?uin=uk.bl.ethos.413494http://discovery.ucl.ac.uk/1445330/Electronic Thesis or Dissertation
collection NDLTD
sources NDLTD
topic 005.82
spellingShingle 005.82
Brostoff, Alexander
Improving password system effectiveness
description As computers reach more aspects of our everyday life, so too do the passwords that keep them secure. Coping with these passwords can be a problem for many individuals and organisations who have to deal with the consequences of passwords being forgotten, yet little is known of this issue. This thesis considers the effectiveness of password authentication systems for three groups of stakeholders including users, support staff, and system owners. The initial problem of how to create memorable but secure passwords is reconceptualised as how to improve password system effectiveness. Interview, questionnaire, and system log studies in BT, and experiments at UCL-CS confirm some basic hypotheses about key variables impacting performance, and show that other variables than the memorability of password content are also important which have hitherto not figured in security research and practice. Interventions based on these findings are proposed. Empirical evaluation suggests that the interventions proposed that 'redesign' the user but exclude other parts of the system would fail. Reason's (1990) Generic Error Modelling System (GEMS) is used as a basis for modelling password system performance at the level of individual users. GEMS and the Basic Elements of Production are used generalise these findings, and for the first time to model information security. This new model, "Elevation", is validated by expert review, and a modified version is presented.
author Brostoff, Alexander
author_facet Brostoff, Alexander
author_sort Brostoff, Alexander
title Improving password system effectiveness
title_short Improving password system effectiveness
title_full Improving password system effectiveness
title_fullStr Improving password system effectiveness
title_full_unstemmed Improving password system effectiveness
title_sort improving password system effectiveness
publisher University College London (University of London)
publishDate 2005
url http://ethos.bl.uk/OrderDetails.do?uin=uk.bl.ethos.413494
work_keys_str_mv AT brostoffalexander improvingpasswordsystemeffectiveness
_version_ 1718312137337602048