The TypTop System: Personalized Typo-Tolerant Password Checking
Rahul Chatterjee, Joanne Woodage, Yuval Pnueli, Anusha Chowdhury, Thomas Ristenpart
摘要
Password checking systems traditionally allow login only if the correct password is submitted. Recent work on typo-tolerant password checking suggests that usability can be improved, with negligible security loss, by allowing a small number of typographical errors. Existing systems, however, can only correct a handful of errors, such as accidentally leaving caps lock on or incorrect capitalization of the first letter in a password. This leaves out numerous kinds of typos made by users, such as transposition errors, substitutions, or capitalization errors elsewhere in a password. Some users therefore receive no benefit from existing typo-tolerance mechanisms.
We introduce personalized typo-tolerant password checking. In our approach, the authentication system learns over time the typos made by a specific user. In experiments using Mechanical Turk, we show that 45% of users would benefit from personalization. Therefore, we design a system, called TypTop, that securely implements personalized typo-tolerance. Underlying TypTop is a new stateful password-based encryption scheme that can be used to store recent failed login attempts. Our formal analysis shows that security in the face of an attacker that obtains the state of the system reduces to the difficulty of a brute-force dictionary attack against the real password. We implement TypTop for Linux and Mac OS login and report on a proof-of-concept deployment.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren 等CCS 2023 · 被引用 19 次
- Don't Forget the Stuffing! Revisiting the Security Impact of Typo-Tolerant Password AuthenticationSena Sahin, Frank LiCCS 2021 · 被引用 13 次
- Might I Get Pwned: A Second Generation Compromised Credential Checking ServiceBijeeta Pal, Mazharul Islam, Marina Sanusi Bohuk, Nick Sullivan 等USENIX Security 2022
- Conditional Encryption with Applications to Secure Personalized Password Typo CorrectionMohammad Hassan Ameri, Jeremiah BlockiCCS 2024
- Towards a Rigorous Statistical Analysis of Empirical Password DatasetsJeremiah Blocki, Peiyuan LiuS&P 2023
它引用的顶会 Paper2
相关 Paper
- How to Tolerate Typos in Strong Asymmetric PAKEIan McQuoid, Mike Rosulek, Jiayu XuCRYPTO 2025 · 被引用 3 次
- Exploring the Effect of Music on User Typing and Identification through Keystroke DynamicsLukas Mecke, Assem Mahmoud, Simon Marat, Florian AltCHI 2025 · 被引用 1 次
- Security and Privacy Failures in Popular 2FA AppsConor Gilsenan, Fuzail Shakir, Noura Alomar, Serge EgelmanUSENIX Security 2023
- AirtypeLogger: How Short Keystrokes in Virtual Space Can Expose Your Semantic Input to Nearby CamerasTongyu Zhang, Yiran Shen, Ning Chen, Guoming Zhang 等IEEE VR 2025 · 被引用 1 次
- PhraseFlow: Designs and Empirical Studies of Phrase-Level InputMingrui Ray Zhang, Shumin ZhaiCHI 2021 · 被引用 12 次
