论文标题

基于图像的密码身份验证系统

Image Based Password Authentication System

论文作者

Sharna, Sanjida Akter, Ali, Sheikh Ashraf

论文摘要

信息和计算机安全性的保存在广义上取决于由密码支撑的安全身份验证系统。基于文本的密码是一个常用的,可用的系统用于身份验证。但是,它具有许多局限性,例如肩膀冲浪,字典攻击,网络钓鱼,猜测密码等。但是,这些图形系统都没有被认为是足够的冒险精神来跟上这些问题。在这里,我们提出了一个基于图像的密码身份验证系统,该系统更有条理,可以应对最近密码身份验证系统的每个漏洞。为了使我们的系统麻烦免费,更可靠,我们只会从用户那里获取用户名以进行注册目的,因为我们的系统将为该特定用户生成唯一的密钥编号,并且该密钥将用作以后登录过程的密码。用户名和密钥都将使用加密算法进行加密,以防止数据库黑客入侵。我们的系统中将有一个随机单击的图像网格。通过单击此图像网格,用户将输入密码键以进行登录目的。在这里,我们已经开发了另一种方法,即抗抗抗药性密码。为了防止肩膀冲浪的攻击,如果任何用户希望更改我们的系统提供的密码密钥,那么他或她可以使用这种方法这样做。此外,这种方法允许用户每次登录时更改密码。用户不需要在我们最近的模块中输入任何文本密码以进行身份​​验证,因此所有这些功能的组合可以改善系统的安全性,可用性和用户友好性。

Preservation of information and computer security is broadly dependent on the secured authentication system which is underpinned by password. Text based password is a commonly used and available system for authentication. But it bears many limitations like shoulder surfing, dictionary attack, Phishing, guessing the password etc. In order to overwhelm these vulnerabilities of ancient textual password, many graphical or image based password authentication system has been introduced form last few years. But none of this graphical system is considered as enough adventurous to keep pace with these issues. Here we have proposed an image based password authentication system which is more methodical and can cope up with every vulnerability of recent password authentication system. To make our system hassle free and more reliable, we will only take username from an user for registration purpose as our system will generate a unique key number for that particular user and this key will be used as password for later login procedure. The user name and key both will be encrypted using a cryptography algorithm to prevent database hacking. There will be a randomized clickable image grid in our system. By clicking on this image grid, user will input the password key for login purpose. Here we have developed another method namely shoulder surfing resistant password. To prevent the attack of shoulder surfing, if any user wishes to change our system provided password key then he or she is allowed to do so by using this method. Besides this method allows user to change the password every single time of login. A user doesn't need to enter any textual password for authentication in our recent module and hence combination of all these features improve the security, usability and user friendliness of our system.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源