A Typo-Tolerant Password Authentication Scheme with Targeted Error Correction
Xin Chen, Xinyi Huang, Yi Mu, Ding Wang · 2019
Password-based authentication is used in almost every computer system. However, users might not always type their passwords correctly. In order to improve the accuracy of password authentication without reducing security, Chatterjee et al. (IEEE S&P'16) and Guan et al. (SecureComm'17) proposed typo-tolerant schemes, respectively. However, these schemes do not consider the impact of personal information on password usages when generating candidate sets, while Wang et al. (NDSS'18) show that 36.95%~51.43% of users employ their personal information to generate passwords. In this paper, we propose a typo-tolerant password authentication scheme with targeted error correction. Our scheme focuses on two aspects: fuzzy judgment and error correction. During the process of password authentication, we first use fuzzy judgment to determine whether the input password contains personal information, and then correct the password according to the result of the fuzzy judgment. The error correction is divided into two types: with personal information and without personal information. Our experimental results show that our solution, when correcting the password entered by the user, is generally able to achieve higher accuracy. When considering the four main errors occurring in the mobile dataset and the general dataset, the average correct rate is 96.29%. The analysis illustrates that the average success proportion of targeted error correction (68.56%) is two times higher than the average success proportion of non-targeted error correction (31.44%), indicating the feasibility of our scheme.