| Naslov: | Security analysis and improvements to the psychopass method |
|---|
| Avtorji: | ID Brumen, Boštjan (Avtor) ID Heričko, Marjan (Avtor) ID Rozman, Ivan (Avtor) ID Hölbl, Marko (Avtor) |
| Datoteke: | Journal_of_Medical_Internet_Research_2013_Brumen_et_al._Security_Analysis_and_Improvements_to_the_PsychoPass_Method.pdf (542,01 KB) MD5: 53EE0C3A1E855B54D93F9550A252CD11 PID: 20.500.12556/dkum/522c5a21-e6c0-49c7-bacf-ce5ae7ad787d
http://www.jmir.org/2013/8/e161/
|
|---|
| Jezik: | Angleški jezik |
|---|
| Vrsta gradiva: | Znanstveno delo |
|---|
| Tipologija: | 1.01 - Izvirni znanstveni članek |
|---|
| Organizacija: | FERI - Fakulteta za elektrotehniko, računalništvo in informatiko
|
|---|
| Opis: | Background: In a recent paper, Pietro Cipresso et al proposed the PsychoPass method, a simple way to create strong passwords that are easy to remember. However, the method has some security issues that need to be addressed.
Objective: To perform a security analysis on the PsychoPass method and outline the limitations of and possible improvements to the method.
Methods: We used the brute force analysis and dictionary attack analysis of the PsychoPass method to outline its weaknesses.
Results: The first issue with the Psychopass method is that it requires the password reproduction on the same keyboard layout as was used to generate the password. The second issue is a security weakness: although the produced password is 24 characters long, the password is still weak. We elaborate on the weakness and propose a solution that produces strong passwords. The proposed version first requires the use of the SHIFT and ALT-GR keys in combination with other keys, and second, the keys need to be 1-2 distances apart.
Conclusions: The proposed improved PsychoPass method yields passwords that can be broken only in hundreds of years based on current computing powers. The proposed PsychoPass method requires 10 keys, as opposed to 20 keys in the original method, for comparable password strength. |
|---|
| Ključne besede: | passwords, cryptanalysis, data security |
|---|
| Status publikacije: | Objavljeno |
|---|
| Verzija publikacije: | Objavljena publikacija |
|---|
| Leto izida: | 2013 |
|---|
| Št. strani: | str. 1-7 |
|---|
| Številčenje: | Letn. 15, št. 8 |
|---|
| PID: | 20.500.12556/DKUM-67103  |
|---|
| ISSN: | 1438-8871 |
|---|
| UDK: | 61:004.6 |
|---|
| COBISS.SI-ID: | 17522198  |
|---|
| DOI: | 10.2196/jmir.2366  |
|---|
| ISSN pri članku: | 1438-8871 |
|---|
| NUK URN: | URN:SI:UM:DK:QVWAUX2Q |
|---|
| Datum objave v DKUM: | 02.08.2017 |
|---|
| Število ogledov: | 1488 |
|---|
| Število prenosov: | 734 |
|---|
| Metapodatki: |  |
|---|
| Področja: | Ostalo
|
|---|
|
:
|
Kopiraj citat |
|---|
| | | | Skupna ocena: | (0 glasov) |
|---|
| Vaša ocena: | Ocenjevanje je dovoljeno samo prijavljenim uporabnikom. |
|---|
| Objavi na: |  |
|---|
Postavite miškin kazalec na naslov za izpis povzetka. Klik na naslov izpiše
podrobnosti ali sproži prenos. |