Cued Mnemonics for Better Security and Memorability Primal - - PowerPoint PPT Presentation

cued mnemonics for better security and memorability
SMART_READER_LITE
LIVE PREVIEW

Cued Mnemonics for Better Security and Memorability Primal - - PowerPoint PPT Presentation

Cued Mnemonics for Better Security and Memorability Primal Wijesekera , Ivan Cherapau, Ayumi Samarakoon, Konstantin Beznosov Laboratory for Education and Research in Secure Systems Engineering ( LERSSE) University of British Columbia Passwords


slide-1
SLIDE 1

Cued Mnemonics for Better Security and Memorability

Primal Wijesekera, Ivan Cherapau, Ayumi Samarakoon, Konstantin Beznosov

Laboratory for Education and Research in Secure Systems Engineering ( LERSSE) University of British Columbia

slide-2
SLIDE 2

Passwords … things we all know

slide-3
SLIDE 3

Mnemonics

Chosen Phrase Password

  • Generation Effect
  • Memorability
  • Security
  • Future Vulnerability
slide-4
SLIDE 4

Question time

hhelibebocnofnenamgalsipsclarkca

slide-5
SLIDE 5

Question time

hhelibebocnofnenamgalsipsclarkca H He Li Be Bo C N O F Ne Na Mg Al Si P S Cl Ar K Ca

slide-6
SLIDE 6

Question time

hhelibebocnofnenamgalsipsclarkca H He Li Be Bo C N O F Ne Na Mg Al Si P S Cl Ar K Ca

slide-7
SLIDE 7

Mnemonics in Chemistry

  • Tens of Mnemonics are used in memorizing

different aspects, rules, components in Chemistry.

  • From RANDOM set of characters to a cued

phrase.

Something to learn from Chemists ...

slide-8
SLIDE 8

We propose ...

  • Reversing the Mnemonic process.
  • Generate a random password.

○ System generated complying to the policies.

  • Generate a “Cued” phrase

○ Self Reference effect ○ Episodic Memory

slide-9
SLIDE 9

Example

Password: pa-3mp1y(TNB)

slide-10
SLIDE 10

Example

Password: pa-3mp1y(TNB) User’s interest: Running

slide-11
SLIDE 11

Example

Password: pa-3mp1y(TNB) User’s interest: Running Phrase: personal achievement - 3 marathons per 1 year (Tokyo, New York, Boston)

slide-12
SLIDE 12

The Reverse Process

  • Phrase is more personally related …

○ Self reference effect ○ Trigger for autobiographical episodes ■ Episodic memory

  • Can accommodate generation effect ...
slide-13
SLIDE 13

Phrase Generation

  • Information Gathering

○ Questionnaire before password creation. ○ Traverse public information - Social Networks, Blogs ○ Eventual knowledge base

  • Generation

○ Semantics - to find words. ○ NLP - to generate a meaningful sentence.

slide-14
SLIDE 14

Questions

slide-15
SLIDE 15

Fantastic Four

Primal Ivan Ayumi Kosta

http://lersse.ece.ubc.ca/

Laboratory for Education and Research in Secure Systems Engineering ( LERSSE) University of British Columbia