3D Password

3-D Password

Abdul Rauf Butt B-15142

Department of Bachelor Science in Computer Science University of South Asia Lahore, Punjab, Pakistan AbdulRauf!Butt"2#$ma%l!&om I! AB()RAC)

Izhar-ul-Haq Cheema B-14 55

Department of Bachelor Science in Computer Science University of South Asia Lahore, Punjab, Pakistan Izhar&heema"'#$ma%l!&om $ra.h%&al .asswords was de+elo.ed! 2a,- $ra.h%&al .assword s&hemes ha+e bee, .ro.osed! Dham%Da a,d Perr%$ @'B .ro.osed DEDF >u/ wh%&h %s a Re&o$,%t%o,-based $ra.h%&al .assword s-stem that authe,t%&ates 6sers b- &hoos%,$ .ortfol%os amo,$ de&o- .ortfol%os! )hese .ortfol%os are art ra,dom%zed .ortfol%os! 8a&h %ma$e %s der%+ed from a, -B seed! )herefore/ a, authe,t%&at%o, ser+er does ,ot ,eed to store the whole %ma$eG %t s%m.l- ,eeds to store the -B seed! A,other re&o$,%t%o,-based $ra.h%&al .assword %s Pass fa&es @ B! Pass fa&es s%m.l- wor0s b- ha+%,$ the user sele&t a sub$rou. of 0 fa&es from a $rou. of , fa&es! 3or authe,t%&at%o,/ the s-stem shows m fa&es a,d o,e of the fa&es belo,$s to the sub$rou. 0! )he user has to do the sele&t%o, ma,- t%mes to &om.lete the authe,t%&at%o, .ro&ess! A,other s&heme %s the (tors&heme @HB/ wh%&h requ%res the sele&t%o, of .%&tures of obDe&ts 9.eo.le/ &ars/ foods/ a%r.la,es/ s%$htsee%,$/ et&!: to form a stor- l%,e! Da+%s et al! @HB &o,&luded that the user;s &ho%&es %, Pass fa&es a,d %, the (tor- s&heme result %, a .assword s.a&e that %s far less tha, the theoret%&al e,tro.-! )herefore/ %t leads to a, %,se&ure authe,t%&at%o, s&heme! )he $ra.h%&al .assword s&hema of Blo,der @AB %s &o,s%dered to be re&all based s%,&e the user must remember sele&t%o, lo&at%o,s! 2oreo+er/ Pass Po%,t @1"BC@12B %s a re&all-based $ra.h%&al .assword s&hema/ where a ba&0$rou,d .%&ture %s .rese,ted a,d the user %s free to sele&t a,- .o%,t o, the .%&ture as the user;s .assword 9user;s Pass Po%,t:! Draw a (e&ret 9DA(:/ wh%&h %s a re&all-based $ra.h%&al .assword s&hema a,d %,trodu&ed b- Ierm-, et al! @13B/ %s s%m.l- a $r%d %, wh%&h the user &reates a draw%,$! >! 28)H5D5J5?=

*e ha+e had ma,- authe,t%&at%o, s&hemes .rese,tl-/ but the- all ha+e some drawba&0s! (o latel-/ the 3D .assword .arad%$m was %,trodu&ed! )he 3-D .assword %s a mult%fa&tor authe,t%&at%o, s&heme! It &a, &omb%,e all e1%st%,$ authe,t%&at%o, s&hemes %,to a s%,$le 3-D +%rtual e,+%ro,me,t! Howe+er the 3-D .assword %s st%ll %, %ts earl- sta$es! Des%$,%,$ +ar%ous 0%,ds of 3-D +%rtual e,+%ro,me,ts/ de&%d%,$ o, .assword s.a&es/ a,d %,ter.ret%,$ user feedba&0 a,d e1.er%e,&es from su&h e,+%ro,me,ts w%ll result %, e,ha,&%,$ a,d %m.ro+%,$ the user e1.er%e,&e of the 3-D .assword! 2oreo+er/ $ather%,$ atta&0ers from d%ffere,t ba&0$rou,ds to brea0 the s-stem %s o,e of the future wor0s that w%ll lead to s-stem %m.ro+eme,t a,d .ro+e the &om.le1%t- of brea0%,$ a 3-D .assword! )h%s .a.er .rese,ts a stud- of the 3D .assword a,d a, a..roa&h to stre,$the, %t b- wa- of add%,$ a 3ourth d%me,s%o,/ that deals w%th $esture re&o$,%t%o, a,d t%me re&ord%,$/ a,d that would hel. stre,$the, the authe,t%&at%o, .arad%$m alto$ether! II! I4)R5D6C)I54

*hat method %s a..l%ed for data &olle&t%o,7 A,d wh%&h fa&tors are a..l%ed also/ 81.la%,! How mu&h users use the te1tual .asswords a,d what &hara&ters the- use 9wee0 .assword/ med%um .assword/ stro,$ .assword:! *hat %s the .er&e.t%o, of users about 3d .assword7 How 3d .assword &a, rel%ef us a,d what are the drawba&0s7 How 3D .assword;s t%m%,$ a,d s.a&e &a, be &om.l%&ated7 *here 3d .assword &a, be used %, w%de areas for se&ur%t- s-stem7 III! <8=*5RD(

Authe,t%&at%o,/ Password/ (e&ur%t-/ 3D Password/ Password )e&h,olo$-/ 3d 8,+%ro,me,t I>! BAC<?R564D *5R<

3or &olle&t%,$ the data about 3D .assword the method has bee, used %s that &o,sult%,$ the related eBoo0s/ forums/ resear&h .a.ers/ ,ews.a.ers/ blo$s a,d d%re&t hel. from d%ffere,t &om.a,%es a,d thes%s! >I! DA)A C5JJ8C)I54

2a,- $ra.h%&al .assword s&hemes ha+e bee, .ro.osed @ABC@ B/ @1"BC@12B! Blo,der @AB %,trodu&ed the f%rst $ra.h%&al .assword s&hema! Blo,der;s %dea of $ra.h%&al .asswords %s that b- ha+%,$ a .redeterm%,ed %ma$e/ the user &a, sele&t or tou&h re$%o,s of the %ma$e &aus%,$ the seque,&e a,d the lo&at%o, of the tou&hes to &o,stru&t the user;s $ra.h%&al .assword! After Blo,der @AB/ the ,ot%o, of

A &om.a,- &o,du&ted a user stud- o, 3-D .asswords us%,$ the e1.er%me,tal 3-D +%rtual e,+%ro,me,ts! )he stud- re+%ewed the usa$e of te1tual .asswords a,d other authe,t%&at%o, s&hemes! )he stud- &o+ered almost 3" users! )he users +ar%ed %, a$e/ se1/ a,d edu&at%o, le+el! 8+e, thou$h %t %s a small set of users/ the stud- .rodu&ed some d%st%,&t results @5B! Com.a,obser+ed the follow%,$ re$ard%,$ te1tual .asswords/ 3D .asswords/ a,d other authe,t%&at%o, s&hemes!



1! 2ost users who use te1tual .asswords of HC12 &hara&ter le,$ths or who use ra,dom &hara&ters as a .assword ha+e o,l- o,e to three u,%que .asswords! 2! 2ore tha, 5"K of user;s te1tual .asswords are e%$ht &hara&ters or less! 3! Almost 25K of users use mea,%,$ful words as the%r te1tual .asswords! 4! Almost '5K of users use mea,%,$ful words or .art%all- mea,%,$ful words as the%r te1tual .asswords! I, &o,trast/ o,l- 25K of users use ra,dom &hara&ters a,d letters as te1tual .asswords! 5! 5+er 4"K of users ha+e o,l- o,e to three u,%que te1tual .asswords/ a,d o+er H"K of users ha+e e%$ht u,%que te1tual .asswords or less! A! 5+er H"K of users do ,ot &ha,$e the%r te1tual .asswords u,less the- are requ%red to b- the s-stem! '! 5+er H5K of users u,der stud- ha+e ,e+er used a,$ra.h%&al .assword s&heme as a mea,s of authe,t%&at%o,! ! 2ost users feel that 3-D .asswords ha+e a h%$h a&&e.tab%l%t-! H! 2ost users bel%e+e that there %s ,o threat to .erso,al .r%+a&- b- us%,$ a 3-D .assword as a, authe,t%&at%o, s&heme! 3D Password s&heme %s &omb%,at%o, of re-&all based/ re&o$,%zed based/ B%ometr%&s et&! %,to s%,$le authe,t%&at%o, te&h,%que @1B! Due to use of mult%.le s&hemes %,to o,e s&heme .assword s.a&e %s %,&reased to $reat e1te,t! 2ore se&ure authe,t%&at%o, s&heme o+er &urre,tl- a+a%lable s&hemes! )%me a,d memor- requ%reme,t %s lar$e! (houlder-suffer%,$ atta&0 %s st%ll &a, affe&t the s&hema! 2ore e1.e,s%+e as &ost requ%red %s more tha, other s&hemes! >III! C54CJ6(I54

remember a,d re&all a .assword m%$ht &hoose te1tual a,d $ra.h%&al .asswords as .art of the%r 3-D .assword! 5, the other ha,d/ users who ha+e more d%ff%&ult- w%th memor- or re&all m%$ht .refer to &hoose smart &ards or b%ometr%&s as .art of the%r 3-D .assword! 2oreo+er/ users who .refer to 0ee. a,- 0%,d of b%ometr%&al data .r%+ate m%$ht ,ot %,tera&t w%th obDe&ts that requ%re b%ometr%& %,format%o,! )herefore/ %t %s the user;s &ho%&e a,d de&%s%o, to &o,stru&t the des%red a,d .referred 3-D .assword! IL! R838R84C8(

