تجاوز إلى المحتوى الرئيسي
User Image

Noura Nassir AlOmar نوره بنت ناصر العمر

Lecturer

College of Computer and Information Sciences , Software Engineering Department.

علوم الحاسب والمعلومات
Building 6, 3rd floor, office# 61
المنشورات
مقال فى مجلة
2017

Someone in Your Contact List: Cued Recall-Based Textual Passwords

Alomar, Noura . 2017

Authentication Passwords Password Hint Password Recall Cued Recall-Based Textual Passwords

Textual passwords remain the most commonly employed user authentication mechanism, and potentially will continue to be so for years to come. Despite the well-known security and usability issues concerning textual passwords, none of the numerous proposed authentication alternatives appear to have achieved a sufficient level of adoption to dominate in the foreseeable future. Password hints, consisting of a user generated text saved at the account setup stage, are employed in several authentication systems to help users to recall forgotten passwords. However, users are often unable to create hints that jog the memory without revealing too much information regarding the passwords themselves. We propose a rethink of password hints by introducing S`YNTHIMA, a novel cued recall-based textual password method that reveals no information regarding the password, requires no modifications to authentication servers, and requires no additional setup or registration steps. S`YNTHIMA makes use of users’ contact lists, so that mapped password hints extracted from a user’s contacts are automatically generated while the user is typing the password. We create formal models for relevant aspects of the password hint mechanism, define its threat model, and analyze the security and usability of S`YNTHIMA. We also present the results of an in-lab user study of S`YNTHIMA on 30 participants to evaluate its effectiveness and usability. The results demonstrate that S`YNTHIMA minimizes the number of incorrect login attempts and improves long-term password recall, with acceptable login times and positive user feedback. We summarize the lessons learned from the user study, with the hope of provoking further insights regarding the design of effective cued recall-based textual password schemes.

مجلة/صحيفة
IEEE Transactions on Information Forensics and Security
مزيد من المنشورات
publications

The invention provides a method and system for dynamically generating a hint to recall a password for a user account of a user.

بواسطة Abdulrahman Saad Alarifi, Mansour Abdulrahman Alsaleh, Noura Nassir Alomar
2018
publications

The present disclosure generally relates to information security and, more particularly, to systems and methods implementing color image ray transform (IRT) for detecting phishing web pages. A…

بواسطة Alaa Mohammed Alhumaisan
2018
publications

The invention provides a method and system for managing a gamified trustee based social authentication to recover an account of a user. The method for managing the gamified trustee based social…

بواسطة Noura Nassir Alomar, Mansour Abdulrahman Alsaleh
2018