Captcha as Graphical Passwords - A New Security Primitive Based on Hard AI Problems

نویسندگان

  • Bin B. Zhu
  • Jeff Yan
  • Guanbo Bao
  • Maowei Yang
  • Ning Xu
چکیده

Many security primitives are based on hard mathematical problems. Using hard AI problems for security is emerging as an exciting new paradigm, but has been under-explored. In this paper, we present a new security primitive based on hard AI problems, namely, a novel family of graph-ical password systems built on top of Captcha technology, which we call Captcha as graphical passwords (CaRP). CaRP is both a Captcha and a graphical password scheme. CaRP addresses a number of security problems altogether, such as online guessing attacks, relay attacks, and, if combined with dual-view technologies, shoulder-surfing attacks. Notably, a CaRP password can be found only probabilistically by automatic online guessing attacks even if the password is in the search set. CaRP also offers a novel approach to address the well-known image hotspot problem in popular graphical password systems, such as PassPoints, that often leads to weak password choices. CaRP is not a panacea, but it offers reasonable security and usability and appears to fit well with some practical applications for improving online security. INTRODUCTION AFundamental task in security is to create cryptographic primitives based on hard mathematical problems that are computationally intractable. For example, the problemof integer factorization is fundamental to the RSA public-key cryptosystem and the Rabin encryption. The discrete logarithm problem is fundamental to the ElGamal encryption, the DiffieHellman key exchange, the Digital Signature Algorithm, the elliptic curve cryptography and so on.Using hard AI (Artificial Intelligence) problems for security, initially proposed in [17], is an exciting new par-adigm. Under this paradigm, the most notable primitive invented is Captcha, which distinguishes human users from computers by presenting a challenge, i.e., a puzzle, beyondthe capability of computers but easy for humans. Captcha is now a standard Internet security technique to protect online email and other services from being abused by bots. CAPTCHA AS GRAPHICAL PASSWORDS A. A New Way to Thwart Guessing Attacks In a guessing attack, a password guess tested in an International Journal of Emerging Trends in Engineering Research, Vol.3. No.10, Pages : 234-240 (2015) Special Issue of ICACSSE 2015 Held on October 30, 2015 in St. Ann’s College of Engineering & Technology, Chirala, AP, India http://www.warse.org/IJETER/static/pdf/Issue/icacsse2015sp41.pdf

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

CAPCHA as Graphical Password

The most common computer authentication method is to use alphanumerical usernames and passwords. This method has been shown to have significant drawbacks. For example, user tends to pick a passwords that can be easily guessed. On the other hand, if a password is hard to guess, then it is often hard to remember. In this paper, we conduct a comprehensive survey of the existing graphical password ...

متن کامل

Captcha as Graphical Passwords—a New Security Primitive Based on Hard AI Problems

Many security primitives are based on hard mathematical problems. Using hard AI problems for security is emerging as an exciting new paradigm,but has been under explored a novel family of graphical password systems built on top of Captcha technology,which we call Captcha as a graphical passwords (CaRP).. CaRP addresses a such as online guessing attacks, relay attacks, and, if combined withdual-...

متن کامل

Towards New Security Primitives Based on Hard AI Problems

Many security primitives are based on hard mathematical problems. Using hard AI problems for security has emerged as an exciting new paradigm (with Captcha being the most successful example). However, this paradigm has achieved just a limited success, and has been under-explored. In this paper, we motivate and sketch a new security primitive based on hard AI problems.

متن کامل

Graphical Password Using Captcha for More Secure Authentication Scheme

388 ISSN: 2278 – 1323 All Rights Reserved © 2015 IJARCET  Abstract: A new security primitive for new graphical authentication scheme based on hard artificial intelligence problems. Number of graphical password scheme has been proposed as options to traditional to text password authentication, namely a new family of graphical password system for Captcha technology with the level of security. We...

متن کامل

A Study of Various Graphical Passwords Authentication Schemes Using Ai Hans Peter Wickelgren Approach

Using AI Hans peter Wickelgren applying the usage of text-based passwords is common authentication system in any Application. This conventional authentication scheme faces some kind of limitations and drawbacks with usability and crypto-graphical security issues that bring troubles to users. For example, user tends to pick passwords that can be easily guessed. On the contrary, if a password is ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • IEEE Trans. Information Forensics and Security

دوره 9  شماره 

صفحات  -

تاریخ انتشار 2014