Author's Personal Copy Pin Selection Policies: Are They Really Effective? Author's Personal Copy 2. Related Work Author's Personal Copy 3. What Real World Pins Look Like

نویسندگان

  • Hyoungshick Kim
  • Jun Ho Huh
چکیده

Users have conflicting sets of requirements when it comes to choosing Personal Identification Numbers (PINs) for mobile phones or other systems that use PINs for authentication: the conflict lies between the ‘easy to remember’ usability requirement and the ‘hard to guess’ security requirement. Users often ignore the security requirement and choose PINs that are easy to remember and reuse, making it also easy for attackers to guess and compromise them. Just as the password strength is controlled through various password policies, PIN selection policies may be used to help users choose stronger PINs and meet various security requirements. An example policy would not allow the use of the most commonly selected PINs. An online user study was conducted to investigate the effectiveness of such PIN selection policies, requesting the participants to choose PINs under some carefully designed policies. The participants were also asked to record the memorability (remembrance difficulty) score of each PIN, indicating how easy/hard it was to remember the selected PIN. Based on the entropies calculated on the collected PINs and their memorability scores, this paper demonstrates that restricting some number of commonly used PINs (e.g. restricting the 200 most commonly used ones) is beneficial: this type of policy would significantly increase the randomness of PINs without incurring significant memorability overhead. Our results also showed that any PINor PIN-pattern-based blacklisting policy should be constructed with caution since the total PIN space may become too small, making it easier for attackers to guess PINs. a 2012 Elsevier Ltd. All rights reserved.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Author's Personal Copy I Move, Therefore I Am: a New Theoretical Framework to Investigate Agency and Ownership Consciousness and Cognition Author's Personal Copy Author's Personal Copy Author's Personal Copy Author's Personal Copy Author's Personal Copy

The neurocognitive structure of the acting self has recently been widely studied, yet is still perplexing and remains an often confounded issue in cognitive neuroscience, psychopathology and philosophy. We provide a new systematic account of two of its main features, the sense of agency and the sense of ownership, demonstrating that although both features appear as phenomenally uniform, they ea...

متن کامل

Author's Personal Copy Author's Personal Copy Author's Personal Copy Author's Personal Copy

Software for two dimensional visualization of values that have been automatically measured with in place sensors is difficult to find. Usually these programs assume a regular area and a regular grid of measuring points. In practice, however, both the shape of the area and the position of the sensors are often irregular. This paper describes the program TDRFree, which visualizes the soil moistur...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2012