TY - JOUR
T1 - CMAPS: A chess-based multi-facet password scheme for mobile devices
AU - Zhu, Ye
AU - Gurary, Jonathan
AU - Corser, George
AU - Oluoch, Jared
AU - Alnahash, Nahed
AU - Fu, Huirong
AU - Tang, Junhua
PY - 2018/1/1
Y1 - 2018/1/1
N2 - It has long been recognized, by both security researchers and human-computer interaction researchers, that no silver bullet for authentication exists to achieve security, usability, and memorability. Aiming to achieve the goals, we propose a Multi-fAcet Password Scheme (MAPS) for mobile authentication. MAPS fuses information from multiple facets to form a password, allowing MAPS to enlarge the password space and improve memorability by reducing memory interference, which impairs memory performance according to psychology interference theory. The information fusion in MAPS can increase usability, as fewer input gestures are required for passwords of the same security strength. Based on the idea of MAPS, we implement a Chess-based MAPS (CMAPS) for Android systems. Only two and six gestures are required for CMAPS to generate passwords with better security strength than 4-digit PINs and 8-character alphanumeric passwords, respectively. Our user studies show that CMAPS can achieve high recall rates while exceeding the security strength of standard 8-character alphanumeric passwords used for secure applications.
AB - It has long been recognized, by both security researchers and human-computer interaction researchers, that no silver bullet for authentication exists to achieve security, usability, and memorability. Aiming to achieve the goals, we propose a Multi-fAcet Password Scheme (MAPS) for mobile authentication. MAPS fuses information from multiple facets to form a password, allowing MAPS to enlarge the password space and improve memorability by reducing memory interference, which impairs memory performance according to psychology interference theory. The information fusion in MAPS can increase usability, as fewer input gestures are required for passwords of the same security strength. Based on the idea of MAPS, we implement a Chess-based MAPS (CMAPS) for Android systems. Only two and six gestures are required for CMAPS to generate passwords with better security strength than 4-digit PINs and 8-character alphanumeric passwords, respectively. Our user studies show that CMAPS can achieve high recall rates while exceeding the security strength of standard 8-character alphanumeric passwords used for secure applications.
KW - Authentication
KW - graphical user interfaces
KW - human computer interaction
UR - https://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=85054358558&origin=inward
UR - https://www.scopus.com/inward/citedby.uri?partnerID=HzOxMe3b&scp=85054358558&origin=inward
U2 - 10.1109/ACCESS.2018.2872772
DO - 10.1109/ACCESS.2018.2872772
M3 - Article
SN - 2169-3536
VL - 6
SP - 54795
EP - 54810
JO - IEEE Access
JF - IEEE Access
M1 - 8476573
ER -