首页 | 本学科首页   官方微博 | 高级检索  
     


User-friendly password methods for computer-mediated information systems
Authors:Ben F Barton  Marthalee S Barton
Affiliation:Department of Electrical and Computer Engineering, University of Michigan, Ann Arbor, MI 48109, USA;College of Engineering, University of Michigan, Ann Arbor, MI 48109, USA
Abstract:Violations of published strictures on password use have led to widespread unauthorized access to computer systems. The problem may compound as inexpert users, handicapped by inadequate guidance and ignorance of computers, are increasingly involved on networked, supposedly “user-friendly” workstations. The literature on password methods reflects a technocentric focus emphasizing security without due regard for user comfort, i.e., a “user-hostile”, system perspective. We present a “user-friendly” model for the password selection and re-creation processes rooted in cognitive psychology. The model suggests two approaches to password selection — one rooted in a nomothetic, or particularized, the other in an idiographic, or generalized, treatment of experience — that exploit principles of recall, memory aids and simple formal transformations. A third approach, exploiting environmental cues — hence recognition rather than recall — is also considered. Intermediate approaches enable tradeoffs between password security and memorability appropriate to the context and cognitive style of the user. The reduction of the approaches to practice is illustrated in numerous examples. The approaches yield passwords more vulnerable to discovery than those envisioned in system-oriented theory, yet operationally superior to many prompted by strictures reflecting a technocentric system perspective. We recommend that guidance materials on password use be made available on systems.
Keywords:passwords  user authentication  user-friendly  cognitive psychology  human-memory model
本文献已被 ScienceDirect 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号