信息网络安全 ›› 2019, Vol. 19 ›› Issue (6): 37-44.doi: 10.3969/j.issn.1671-1122.2019.06.005

• 技术研究 • 上一篇    下一篇

不同口令组成策略下用户真实口令的安全性分析

郭亚军(), 叶贝, 周伟   

  1. 华中师范大学计算机学院,湖北武汉 430079
  • 收稿日期:2019-03-27 出版日期:2019-06-10 发布日期:2020-05-11
  • 作者简介:

    作者简介:郭亚军(1965—),男,湖北,教授,博士,主要研究方向为信息安全;叶贝(1994—),女,湖北,硕士研究生,主要研究方向为信息安全;周伟(1980—),男,湖北,讲师,博士,主要研究方向为信息安全。

  • 基金资助:
    国家自然科学基金[61772224];中央高校基本科研业务费资助项目 [CCNU19ZN008]

Security Analysis of User Real Password under Different Password Composition Policies

Yajun GUO(), Bei YE, Wei ZHOU   

  1. School of Computer, Central China Normal University, Wuhan Hubei 430079, China
  • Received:2019-03-27 Online:2019-06-10 Published:2020-05-11

摘要:

口令组成策略对用户创建口令的长度和复杂性提出了要求。目前的一些研究表明,使用口令组成策略有助于提高用户口令强度,但是这些研究主要是通过招募参与者的形式在实验室或者网络上进行,参与者被要求创建的口令并不一定出现在现实中。不同于这些研究,文章从实际出发,利用网站中泄露出来的真实口令,研究现实网站中采用较多的几种口令组成策略对用户创建口令所产生的影响。文章主要比较了没有口令组成策略、basic6策略和2class6策略这3种情形下真实口令的一些特征,分析了这些口令的安全性。研究发现,口令组成策略会对用户所选择口令的长度和字符类型造成影响,要求多字符类型的口令组成策略会增加口令的长度。此外,研究也发现,上述3类口令组成策略都不能很好地帮助用户创建强口令。

关键词: 口令, 口令组成策略, 安全

Abstract:

Password composition policies place requirements on the length and complexity of passwords created by users. Current studies have shown that using password composition policies can help improve user password strength, but these studies are mainly conducted in the laboratory or on the network by recruiting participants, and the passwords that participants are required to create may not appear in reality. Different from these studies, starting from the reality, this paper studies the impact of several password composition policies used in the real websites on the passwords created by users by using the real passwords leaked from the websites. This paper mainly compares some features of the real passwords in three scenes: no password policy, basic6 policy and 2class6 policy, and analyzes the security of these passwords. The study finds that password composition policy affects the length and character type of the password selected by the user, and policy which requires multiple character types increases the length of the password. The study also finds that none of the above three password composition policies can help users create strong passwords.

Key words: password, password composition policies, security

中图分类号: