230 likes | 249 Views
Learn about Passfaces, a secure authentication method leveraging facial recognition, cognitive science, and user intuition for successful login sessions. Discover how Passfaces offer a unique, user-friendly experience that balances security and usability effectively.
E N D
Graphical Passwords with Integrated Trustworthy Interface Patricia Lareau V P Product Management TIPPI Workshop June 19, 2006
Authentication Design Goals Consider Security and Usability
Usability Security Security Requirements • Randomly assigned • Unique to the application • Robust against known attacks • Simple • Reliable – no fallback needed • Not sharable casually or easily • Lacks social vulnerabilities • Useable anywhere • Two-way AuthN
Security Usability Usability Requirements • Graphical User Interface • Intuitive to use • No user rules • Independent of user’s aptitude, training or attentiveness • No on-going training • EASY to use • Portable • Fun!
Usability Security Successful AuthN is Both or Neither Design Leverages: • Secret • Interface • Protocol
Passfaces Meets the Challenge Secure and Usable
The Secret Based on Cognitive Science
The Brain Deals with Faces Differently than Any Other Image Face recognition is a dedicated process which is different from general object recognition. Source: Face Recognition: A Literature Survey. National Institute of Standards and Technology
In the Beginning… Thinking Outside of the Box Approach…. “Let’s Authenticate the Person” • Science has proven that we are genetically predisposed with a unique talent. • We all have the innate ability to easily recognize human faces. • There was a time that recognizing another's face could mean LIFE or DEATH. • Today that need is not so great, but the ability is still there. • There is a special place in the brain dedicated to facial recognition and facial recognition only.
Recall vs. Recognize You must RECALL a password You simply RECOGNIZE a face Remember High School …. What kind of test did your prefer? Multiple Choice Fill in the Blank 1 2 3 g f w y
Our approach Familiarize the user with a randomly-selected set of faces and check if they can recognize them when they see them again It’s as easy as recognizing an old friend
Authentication Session The secret is • Random • Easy to recognize but • Difficult to describe/share • No “cribsheets” needed • Always Available • Intuitive - Independent of user age, language or education • Not socially vulnerable
The Interface Reinforce the Design Objectives
How Passfaces Works Library of Faces User Interface Users Are Assigned a Set of 5* Passfaces * Typical implementation – 3 to 7 possible as standard
How Passfaces Works • 5 Passfaces are Associated with 40 associated decoys • Passfaces are presented in five 3 by 3 matrices each having 1 Passface and 8 decoys
New Users are Familiarized with their Passfaces • Users enroll with a 2 to 4 minute familiarization process • Using instant feedback, encouragement, and simple dialogs, users are trained until they can easily recognize their Passfaces • The process is optimized and presented like an easy game Let’s Practice Let’s Practice Action Click OnYour Passface It’s Moving (There is only One on this Page)
Familiarization Puts Cookies in the Brain Like a mindprintor brain cookie But, unlike fingerprints, Passfacesrequire no special hardware And, unlike browser cookies, Passfacesauthenticate the actual user
Authentication Session The interface… • Graphical • Self-prompting • User cannot choose or reuse • NO burden of recall • 3X3 grid • Ergonomic • Maps to keypad, phone, pinpad • More entropy than a user chosen secret
The Protocol Maximize Defenses – Maximize Usability
Configuration Data • Grid set is random per user • Grids need not be secret but must be correct • AUTHENTICATION IS NOT POSSIBLE WITHOUT PRESENTATION OF CORRECT GRIDS • Mutual Authentication is implicit- user attentiveness unnecessary • Phishing today is stopped • Phishing tomorrow is hard work • Blacklisting is possible John Doe sparky123
Grid Presentation • Multiple Grids • Random display within grid • Familiar order of grids for user comfort • Library Use • Thousands of random sets available • Shoulder surfing deterrent • Anti phishing strategies • Mutual AuthN enhanced
A New Class of Authentication • Passfaces represents a new, 4th class of authentication: Cognometrics Recognition-Based Authentication
Thank you! Patricia Lareau V P Product Management patricia.lareau@passfaces.com 805.544.1138 Questions?