graphical dictionaries presentation by roger kahn1 graphical dictionaries & memorable space of...

25
Graphical Dictionaries Pr esentation by Roger Kahn 1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Post on 15-Jan-2016

240 views

Category:

Documents


3 download

TRANSCRIPT

Page 1: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

1

Graphical Dictionaries & Memorable Space of Graphical Passwords

Page 2: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

2

Memorable Space of Graphical Passwords

Based on Article by Thorpe, van

Oorschot USENIX 2004

Contains References to The Design and Analysis of Graphical Passwords by Jermyn et. al

Page 3: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

3

Memorable Space of Graphical Passwords

Purpose of Paper Define a class of memorable

graphical passwords Map it on the DAS scheme from

Jermyn et al (Moti’s lecture)

Page 4: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

4

Memorable Space of Graphical Passwords

Textual Passwords Passwords chosen are usually ones

that are easy to remember Concrete words easier to remember Text Password space used (with high

probability) vulnerable to dictionary attacks since it’s a relatively small subset of total password space

Page 5: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

5

Memorable Space of Graphical Passwords

Graphical Passwords Recall by people of pictures is better

than words – including concrete nouns

Presumably better since memorable password space and total password space is larger

Page 6: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

6

Memorable Space of Graphical Passwords

Recall of Pictures that are symmetric are far better

Recall of pictures symmetric around some truly vertical or horizontal axis is still better due to mirror symmetry

Studies indicate that horizontal and vertical symmetry that are centered is still better

Page 7: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

7

Memorable Space of Graphical Passwords

Are Types of images recalled better than others?

The paper criticizes the visual recall studies due to short recall times in the tests

Suggestion that recall is far better than studied

Page 8: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

8

Memorable Space of Graphical Passwords

DAS Scheme Review User defined Drawings Repeatable Drawings Start and End Points for drawing Stroke – Movement of the pen on grid

between clearly defined points movements on border not accepted

Password - List of successive points which stroke goes through separated by pen-up

Stroke goes from neighbor to neighbor

Page 9: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

9

Memorable Space of Graphical Passwords

DAS Scheme Review(cont’d) If current point is (x,y) neighbors are

(x,y+1), (x,y-1), (x+1,y), (x-1, y) Stroke length is # of neighbors drawn

through until pen-up Password Length is the sum of the stroke

lengths Password Space for Lmax=2 on 5X5 grid is

258 8 Character password < 253

Page 10: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

10

Memorable Space of Graphical Passwords

Proposed Class of Memorable Graphical Passwords Purpose of Study Mirror Symmetrical graphical passwords selected Psychological Studies show recall improved over

time toward mirror symmetrical images Need to remember less(½ of image plus

symmetry axis) Objects viewed and recalled better than pictures

Page 11: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

11

Memorable Space of Graphical Passwords

Class I of memorable Passwords Mirror Symmetry about a reflection

axis (Vertical or Horizontal) which cuts a 2D set of grid cells of size 5x5

Each Component may be a pair of mirror symmetric components as well

Naming Leaves open possibility for future types

Page 12: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

12

Memorable Space of Graphical Passwords

Page 13: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

13

Memorable Space of Graphical Passwords

Page 14: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

14

Memorable Space of Graphical Passwords

Page 15: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

15

Memorable Space of Graphical Passwords

Class I of memorable Passwords(cont’d) Assumption: User draws password such that

the composite stroke of each mirror symmetric component are drawn symmetrically

Assumption taken since temporal order of password affects ability of user to recall password

One to many relationship between stroke order and drawing

Page 16: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

16

Memorable Space of Graphical Passwords

Symmetric Encoding Example

Page 17: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

17

Memorable Space of Graphical Passwords

Symmetry Example

Page 18: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

18

Memorable Space of Graphical Passwords

Continuous, Enclosed, Disjoint Cases

Page 19: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

19

Memorable Space of Graphical Passwords

Continuous, Enclosed, Disjoint Cases

Page 20: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

20

Memorable Space of Graphical Passwords

Smaller Password Spaces Class Ia – Subset of Class I passwords

whos components are symmetric (individually or pairwise)

Class Ib – Subset of Class Ia. Symmetric around Vertical and Horizontal Axes

Page 21: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

21

Memorable Space of Graphical Passwords

Quantifying Memorable Password Space General Approach # of passwords given a

maximum stroke length This paper’s method include only symmetric

strokes Stroke set is the number of symmetric

strokes from start to end of length l. # of permutations of 4 directions while

symmetric around a valid axis Parameters are path diversions, room

between current point and the grid bound

Page 22: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

22

Memorable Space of Graphical Passwords

Approximate Size of Class I Passwords Class I dictionary size very close to

the size of the full password space Class Ia, Ib much more vulnerable to

Brute-Force attacks. It’s a much smaller password space.

Page 23: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

23

Memorable Space of Graphical Passwords

Page 24: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

24

Memorable Space of Graphical Passwords

Questions and [email protected]

Page 25: Graphical Dictionaries Presentation by Roger Kahn1 Graphical Dictionaries & Memorable Space of Graphical Passwords

Graphical Dictionaries Presentation by Roger Kahn

25

Memorable Space of Graphical Passwords

Assignment Why are the password subclasses

more vulnerable to a brute force dictionary attacks?

What is easier for Humans to recall pictures or words?

What types of pictures and words are the easiest to recall?

What is a stroke?