02787aam 2200469I 450 991070959660332120160926090653.0GOVPUB-C13-8062767e03ba2467301fe5b36548a003(CKB)5470000002479030(OCoLC)958885806(EXLCZ)99547000000247903020160921d2016 ua 0engrdacontentrdamediardacarrierMeasuring the usability and security of permuted passwords on mobile platforms /Kristen K. Greene; John Kelsey; Joshua M. FranklinGaithersburg, MD :U.S. Dept. of Commerce, National Institute of Standards and Technology,2016.1 online resource (65 pages) illustrations (color)NISTIR ;8040April 2016.Contributed record: Metadata reviewed, not verified. Some fields updated by batch processes.Title from PDF title page (viewed April 30, 2016).Includes bibliographical references.Password entry on mobile devices significantly impacts both usability and security, but there is a lack of usable security research in this area, specifically for complex password entry. To address this research gap, we set out to assign strength metrics to passwords for which we already had usability data, in an effort to have a more meaningful comparison between usability and security. This document reports a method of optimizing the input of randomly generated passwords on mobile devices via password permutation to allow for a comparison of password usability data. We found that the number of keystrokes saved the efficiency gained via permutation depends on the number of onscreen keyboard changes required in the original password rather than on password length. Additionally, we created and are releasing Python scripts (publicly available from https://github.com/usnistgov/PasswordMetrics) for the experiments on entropy loss we conducted across passwords ranging in length from 5 to 20 characters.ComputersAccess controlPasswordsMobile communication systemsComputersAccess controlPasswords.Mobile communication systems.Greene Kristen K1396962Franklin Joshua M1412362Greene Kristen K1396962Kelsey John1381105Information Technology Laboratory (National Institute of Standards and Technology)NBSNBSGPONBSBOOK9910709596603321Measuring the usability and security of permuted passwords on mobile platforms3505651UNINA