Rass Stefan, König Sandra
System Security Group, Institute of Applied Informatics, Universität Klagenfurt, 9020 Klagenfurt, Austria.
Austrian Institute of Technology, Center for Digital Safety & Security, 1210 Vienna, Austria.
Entropy (Basel). 2018 Apr 25;20(5):312. doi: 10.3390/e20050312.
We consider a formal model of password security, in which two actors engage in a competition of optimal password choice against potential attacks. The proposed model is a multi-objective two-person game. Player 1 seeks an optimal password choice policy, optimizing matters of memorability of the password (measured by Shannon entropy), opposed to the difficulty for player 2 of guessing it (measured by min-entropy), and the cognitive efforts of player 1 tied to changing the password (measured by relative entropy, i.e., Kullback-Leibler divergence). The model and contribution are thus twofold: (i) it applies multi-objective game theory to the password security problem; and (ii) it introduces different concepts of entropy to measure the quality of a password choice process under different angles (and not a given password itself, since this cannot be quality-assessed in terms of entropy). We illustrate our approach with an example from everyday life, namely we analyze the password choices of employees.
我们考虑一种密码安全的形式化模型,其中两个参与者针对潜在攻击进行最优密码选择的竞争。所提出的模型是一个多目标两人博弈。参与者1寻求一种最优密码选择策略,优化密码的可记忆性(由香农熵衡量),同时对抗参与者2猜测密码的难度(由最小熵衡量),以及参与者1与更改密码相关的认知努力(由相对熵,即库尔贝克 - 莱布勒散度衡量)。因此,该模型和贡献有两个方面:(i)它将多目标博弈论应用于密码安全问题;(ii)它引入不同的熵概念,从不同角度衡量密码选择过程的质量(而不是给定密码本身,因为密码本身无法根据熵进行质量评估)。我们用一个日常生活中的例子来说明我们的方法,即分析员工的密码选择。