立即打开
还敢用密码和手势锁屏?试试更安全的涂鸦吧!

还敢用密码和手势锁屏?试试更安全的涂鸦吧!

Robert Hackett 2014年06月26日
手机、iPad等触屏移动设备的九宫格和四位数密码都很容易遭到窃取,导致泄密。但一项新的研究显示,大家信手涂鸦画出的图案却能形成安全性极高的新型密码。

    林奎斯特说:“无论如何,对于复杂的手势,大家绝对不可能做到百分之百准确重现。”林奎斯特指出,至少需要三次重复或模板才能使手势稳定。(为了提高准确度,在研究中对每位被试者采用了10个模板。)

    研究者还使用了一种适应性很强的算法。被试者们能够在移动设备屏幕的任何地方、以任意角度画出图案,大小也可随心所欲,只要手势的形状正确即可。这样灵活的算法可以让同一手势跨平台使用,例如大屏幕的平板和屏幕相对较小的智能手机能使用相同的手势密码。

    为了准确衡量每种手势的安全性,研究人员引入了信息论中的“微分熵”概念。这个概念能量化手势的“信息内容”或者说“多样性”。一般来说,越复杂的手势越安全,它们有些看着像荆棘、风滚草等植物,还有些看起来像是有很多面的珠宝。

    通常,与最安全的手势相比,那些最容易记住的手势一般比较简洁,其中包括简单的图案造型,例如三角形和签名等。

    而最不安全的手势则要数单调循环的圆圈。

    另一种衡量安全性的方法是所谓的“背后偷窥”测试。方法是让六名学生志愿者独自观看一位学生演示三种典型手势的视频,然后凭记忆重复这些手势。

    初步测试的效果令人振奋。林奎斯特称:“偷窥者们甚至都无法画出相近的手势。”

    事实上,还是有一人几乎画出了其中一种手势——一个倒写的字母“N”,但相似度没有达到系统“识别”通过的程度。

    纽约大学(New York University)计算机科学与工程专业教授纳西尔•梅蒙说:“输入密码已经过时了,我们亟需发掘替代方案。”梅蒙并没有参与上面提到的研究。

    不过,即便有肌肉记忆辅助,我们也可能会被一大堆手势密码弄得不知所措。

    梅蒙反问:“如果你的三个账号有三个不同的手势密码,你怎么区分?”

    林奎斯特表示,在未来的研究中,他计划指导被试者,帮助他们掌握最佳的做法,获得安全又好记的手势。此外,他还希望扩展背后窥视测试。他说:“我认为手势密码非常安全,比现有方案要好。我希望在这个领域继续深入研究。”

    如果这种新方法靠谱,未来密码安全可能不再靠键盘,而是靠信手涂鸦。不过,目前全球几十亿移动设备用户只能用谷歌安卓系统的标准模式锁屏和苹果的个人识别号码。

    梅蒙说:“手势密码确实有潜力。但它要得到广泛的采用还有很长的路要走。”(财富中文网)

    译者:项航

    “You never can, in any case—with any kind of meaningfully complex gesture—repeat it exactly the same way,” Lindqvist said, noting that it takes at least three repetitions, or templates, for a gesture to become stable. (For improved accuracy, the study used 10 templates per participant.)

    The researchers also used a flexible algorithm. Participants were able to draw anywhere on the device’s screen at whatever size and angle they wished, as long as the shape of the gesture was correct. Such flexibility may allow single gestures to adapt across platforms: for instance, on the larger screen of a tablet versus the smaller screen of a smartphone.

    To measure each gesture’s level of security, the researchers imported a concept from Information Theory called “differential entropy.” This metric quantified the “information content,” or “surprisingness,” of a gesture. Generally, the most secure gestures were the most complex. Some of these looked like brambles, tumbleweeds or multi-faceted jewels.

    On average the most memorable gestures were shorter and simpler than those best for security. Some of the most memorable ones included simple angular shapes, like triangles, and signatures.

    The least-secure gestures consisted of gentle, looping circles.

    Another measure of security involved a “shoulder surfing” test. Six student volunteers independently watched videos of another student performing three representative gestures. These “attackers” were then asked to replicate each gesture.

    The preliminary results were promising. “None of the attackers came even close to the gesture,” Lindqvist said.

    In fact, one attacker did nearly replicate one of the gestures—a backwards “N”—but did not come close enough for a “recognizer” to authenticate.

    “Typing in a password seems to be an artifact of the past,” said Nasir Memon, professor of computer science and engineering at New York University, who was not involved in the study. “There is definitely a need to explore the alternatives.”

    Still, even with the aid of muscle memory, one must question how confusing a world of security gestures might become.

    “If you have three different gestures for three different accounts, how do you deal with that?” Memon asked.

    In future studies, Lindqvist said he plans to instruct participants in best practices for generating secure and memorable gestures. He also hopes to expand the shoulder-surfing test. “I think that this robust alternative and a better alternative than the current method, and looking forward to working on this more,” Lindqvist said.

    If the new tactic’s promise holds, the future of password security may look less like a keyboard and more like finger-skating. For now, though, the billions of people around the world using mobile devices must stick with their PINs and patterns.

    “It holds potential,” Memon said. “But we’re still a long way from it being seriously adopted.”

  • 热读文章
  • 热门视频
活动
扫码打开财富Plus App