Traditional textual password scheme provides a large number of password combinations but users generally use a small portion of available password space. Complex textual passwords are difficult to remember, therefore most users choose passwords with small length and contain dictionary words. Due to the use of small password length and dictionary words, textual passwords become easy to crack through offline guessability attacks. Traditional textual passwords scheme is also weak against keystroke logger attacks because alphanumeric characters are directly inserted into the password field. In this paper, enhancements are proposed in the registration and login screen of the traditional textual password scheme for improving security against offline guessability attacks and keystroke logger attacks. The proposed registration screen also improve memorability of traditional textual passwords through visual cues or patternbased approach. In the proposed login screen, passwords are indirectly inserted into the password field, to resist keystroke logger attacks. A comparative analysis between the passwords created in traditional and proposed pattern-based approach is presented. The testing results show that users create strong and high entropy passwords in the proposed pattern-based approach as compared to the traditional textual passwords approach.
CITATION STYLE
Bhanbhro, H., Nizamani, S. Z., Hassan, S. R., Bakhsh, S. T., & Alassafi, M. O. (2018). Enhanced textual password scheme for better security and memorability. International Journal of Advanced Computer Science and Applications, 9(7), 209–215. https://doi.org/10.14569/IJACSA.2018.090730
Mendeley helps you to discover research relevant for your work.