2013Journal of Global Research in Computer SciencesRequires access

PASSWORD KNIGHT SHIELDS PASSWORD STEALING AND RE-USE ATTACK

D Caine, V. Shyam, G Michael

Open publisher page 0 citations

Abstract

Passwords are the powerful tools that tend to keep all data and information digitally safe. It is often noticed that text password remains predominantly popular over the other formats of passwords, due to the fact that it is simple and convenient. However, text passwords are not always strong enough and are very easily stolen and misused under different vulnerabilities. Others can acquire a text password when a person creates a weak password or a password that is completely reused in many sites. In this condition if one password is stolen, it can be used for all the websites. This is called as the Domino Effect. Another risky environment is when a person enters his/her password in a computer that is not trust-worthy; the password is prone to stealing attacks such as phishing, malware and key loggers etc. In this paper, a user authentication protocol named Password Knight is designed, that makes use of the customer’s cellular phone and short message service to ensure protection against password stealing attacks. Password Knight requires a unique phone number that will be possessed by each participating website. The registration and the recovery phases involve a telecommunication service provider.

About this research paper

What this paper is about

Passwords are the powerful tools that tend to keep all data and information digitally safe. It is often noticed that text password remains predominantly popular over the other formats of passwords, due to the fact that it is simple and convenient. However, text passwords are not always strong enough and are very easily stolen and misused under different vulnerabilities. Others can acquire a text password when a person creates a weak password or a password that is completely reused in many sites. In this condition if one password is stolen, it can be used for all the websites. This is called as the Domino Effect. Another risky environment is when a person enters his/her password in a computer that is not trust-worthy; the password is prone to stealing attacks such as phishing, malware and key loggers etc. In this paper, a user authentication protocol named Password Knight is designed, that makes use of the customer’s cellular phone and short message service to ensure protection against password stealing attacks. Password Knight requires a unique phone number that will be possessed by each participating website. The registration and the recovery phases involve a telecommunication service provider.

Why it matters

A significance statement is not available in the OpenAlex record.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Passwords are the powerful tools that tend to keep all data and information digitally safe. It is often noticed that text password remains predominantly popular over the other formats of passwords, due to the fact that it is simple and convenient. However, text passwords are not always strong enough and are very easily stolen and misused under different vulnerabilities. Others can acquire a text password when a person creates a weak password or a password that is completely reused in many sites. In this condition if one password is stolen, it can be used for all the websites. This is called as the Domino Effect. Another risky environment is when a person enters his/her password in a computer that is not trust-worthy; the password is prone to stealing attacks such as phishing, malware and key loggers etc. In this paper, a user authentication protocol named Password Knight is designed, that makes use of the customer’s cellular phone and short message service to ensure protection against password stealing attacks. Password Knight requires a unique phone number that will be possessed by each participating website. The registration and the recovery phases involve a telecommunication service provider.

Key concepts: Password, Computer science, Computer security, Password strength, Cognitive password, S/KEY, One-time password, Password policy

Related papers

Back to paper searchBrowse research topicsOriginal source
PASSWORD KNIGHT SHIELDS PASSWORD STEALING AND RE-USE ATTACK — Research Paper | ScholarLens