A pattern for successful authentication

Stephen Howes · Computer Fraud & Security · 2011

Authentication has always been a problem for systems security. Generally, people use a ‘shared secret’ for accessing systems, but this creates challenges. The user must be able to remember the secret, which means that it must be short and simple enough for everyday use. Alternatively, it must be held in a separate device. No wonder that so many secrets are stolen and systems compromised. How can shared secrets be enhanced, so that they are at once intuitive to the user, strong enough not to be guessed or ‘brute forced’, and easy to deploy? Pattern-based authentication provides a useful alternative to traditional methods. Traditional authentication systems have a number of well-known weaknesses. Passwords are either strong or easy to remember, but rarely both. And they tend to be changed infrequently. Even promising technological solutions such as biometrics, hardware tokens and out-of-band authentication are prone to theft or involve expensive and equipment that is difficult to manage. Pattern-Based Authentication (PBA), however, exploits humans' built-in ability to remember even quite complex patterns. Matched with grids of random numbers, this presents an opportunity for strong yet easily implemented authentication systems, says Stephen Howes of GrIDsure.

Read the paper · More papers on PaperTik