Password-Based Authentication: A System Perspective
Year: 2004, Volume: 8, Pages: 70170b
DOI Bookmark: 10.1109/HICSS.2004.1265412
Authors
Art Conklin, University of Texas at San Antonio
Glenn Dietrich, University of Texas at San Antonio
Diane Walz, University of Texas at San Antonio
Download PDF
Abstract
User authentication in computer systems has been a cornerstone of computer security for decades. The concept of a user id and password is a cost effective method of maintaining a shared secret between a user and a computer system. With the advent of the Internet and the proliferation of computers, individual users face the challenge of remembering numerous passwords for different systems. This paper presents a conceptual model that depicts how users and systems work together and examines the implications of user memory aids on system security.
1. Introduction
Identifying a user is essential for applying security in the form of permissions to various objects. The implementation of user authentication using a password was valid when there were few applications; however, today, users have multiple accounts on various systems, leading to increased cognitive strain.
The purpose of this paper is to present a conceptual model of password-based security across multiple systems and the effects of user-generated memory aids on overall security. User password memory aids can decrease user security while also causing inter-system security issues, developing a need for a shift in mindset among system developers.
2. Conceptual Development
2.1 Authentication
Authentication involves the verification of credentials to establish authorization. This fundamental process verifies the identity of any entity using a computer system. As the internet expands, so does the complexity and number of account credentials required of a user.
2.2 Human Cognitive Ability
Research shows individuals struggle to remember multiple passwords, leading users to create memory aids. Designing authentication systems without considering user memory limitations can lead to vulnerabilities in security deployments.
2.3 System Design
Security is often an emergent property of interconnected systems, which complicates designing a secure user experience. The increasing interconnectedness of networked systems demands a design approach that considers the holistic environment users engage with.
2.4 Password-Based Risk
Security risks arise from unauthorized access attempts. Mitigating these risks involves implementing robust safeguards against brute force attacks, discovery, and social engineering. Understanding user memory aids is essential to analyzing security vulnerabilities.
3. Risk Models
Figures illustrate the impacts of connection and interdependence between systems based on user memory aids. As users engage with numerous systems, vulnerabilities may expose security across systems.
4. Conclusions
Designers of security systems must account for the implications of user choices and authentication subsystems on system security. Broadening the view of security to consider user behaviors will aid in designing effective systems against evolving threats.
5. Implications
The interconnected nature of computing requires systems to address user-centric authentication methods while managing cross-system vulnerabilities. Research must prioritize reducing reliance on insecure memory aids and exploring alternative authentication techniques.