中国科学院机构知识库网格
Chinese Academy of Sciences Institutional Repositories Grid
PUFPass: A password management mechanism based on software/hardware codesign

文献类型:期刊论文

作者Lan, Yazhu4; Li, Bing2; Hu, Yu3,4; Li, Xiaowei3,4; Zhang, Guohe1; Guo, Qingli3,4; Ye, Jing3,4
刊名INTEGRATION-THE VLSI JOURNAL
出版日期2019
卷号64页码:173-183
关键词Password Password management mechanism PUF Security Usability
ISSN号0167-9260
DOI10.1016/j.vlsi.2018.10.003
英文摘要Secure passwords need high entropy, but are difficult for users to remember. Password managers minimize the memory burden by storing site passwords locally or generating secure site passwords from a master password through hashing or key stretching. Unfortunately, they are threatened by the single point of failure introduced by the master password which is vulnerable to various attacks such as offline attack and shoulder surfing attack. To handle these issues, this paper proposes the PUFPass, a secure password management mechanism based on software/hardware codesign. By introducing the hardware primitive, Physical Unclonable Function (PUF), into PUFPass, the random physical disorder is exploited to strengthen site passwords. An illustration of PUFPass in the Android operating system is given. PUFPass is evaluated from aspects of both security and preliminary usability. The security of the passwords is evaluated using a compound heuristic algorithm based PUF attack software and an open source password cracking software, respectively. Finally, PUFPass is compared with other password management mechanisms using the Usability-Deployability-Security (UDS) framework. The results show that PUFPass has great advantages in security while maintaining most benefits in usability.
资助项目National Natural Science Foundation of China (NSFC)[61532017] ; National Natural Science Foundation of China (NSFC)[61704174] ; National Natural Science Foundation of China (NSFC)[61432017] ; National Natural Science Foundation of China (NSFC)[61521092]
WOS研究方向Computer Science ; Engineering
语种英语
WOS记录号WOS:000451494300018
出版者ELSEVIER SCIENCE BV
源URL[http://119.78.100.204/handle/2XEOYT63/3528]  
专题中国科学院计算技术研究所期刊论文_英文
通讯作者Li, Xiaowei; Ye, Jing
作者单位1.Xi An Jiao Tong Univ, Sch Microelect, Xian 710049, Shanxi, Peoples R China
2.Duke Univ, Durham, NC 27708 USA
3.Univ Chinese Acad Sci, Beijing 100049, Peoples R China
4.Chinese Acad Sci, Inst Comp Technol, State Key Lab Comp Architecture, Beijing 100190, Peoples R China
推荐引用方式
GB/T 7714
Lan, Yazhu,Li, Bing,Hu, Yu,et al. PUFPass: A password management mechanism based on software/hardware codesign[J]. INTEGRATION-THE VLSI JOURNAL,2019,64:173-183.
APA Lan, Yazhu.,Li, Bing.,Hu, Yu.,Li, Xiaowei.,Zhang, Guohe.,...&Ye, Jing.(2019).PUFPass: A password management mechanism based on software/hardware codesign.INTEGRATION-THE VLSI JOURNAL,64,173-183.
MLA Lan, Yazhu,et al."PUFPass: A password management mechanism based on software/hardware codesign".INTEGRATION-THE VLSI JOURNAL 64(2019):173-183.

入库方式: OAI收割

来源:计算技术研究所

浏览0
下载0
收藏0
其他版本

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。