<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1 plus MathML 2.0 plus SVG 1.1//EN" "http://www.w3.org/2002/04/xhtml-math-svg/xhtml-math-svg.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
  <head>
    <meta http-equiv="Content-Type" content="application/xhtml+xml; charset=utf-8"/>
    <title>Project-Team:PRIVATICS</title>
    <link rel="stylesheet" href="../static/css/raweb.css" type="text/css"/>
    <meta name="description" content="Highlights of the Year - A Novel Authentication Scheme based on Implicit Memory"/>
    <meta name="dc.title" content="Highlights of the Year - A Novel Authentication Scheme based on Implicit Memory"/>
    <meta name="dc.subject" content=""/>
    <meta name="dc.publisher" content="INRIA"/>
    <meta name="dc.date" content="(SCHEME=ISO8601) 2017-01"/>
    <meta name="dc.type" content="Report"/>
    <meta name="dc.language" content="(SCHEME=ISO639-1) en"/>
    <meta name="projet" content="PRIVATICS"/>
    <script type="text/javascript" src="https://cdn.mathjax.org/mathjax/latest/MathJax.js?config=TeX-MML-AM_CHTML">
      <!--MathJax-->
    </script>
  </head>
  <body>
    <div class="tdmdiv">
      <div class="logo">
        <a href="http://www.inria.fr">
          <img style="align:bottom; border:none" src="../static/img/icons/logo_INRIA-coul.jpg" alt="Inria"/>
        </a>
      </div>
      <div class="TdmEntry">
        <div class="tdmentete">
          <a href="uid0.html">Project-Team Privatics</a>
        </div>
        <span>
          <a href="uid1.html">Personnel</a>
        </span>
      </div>
      <div class="TdmEntry">Overall Objectives<ul><li><a href="./uid3.html">Context</a></li></ul></div>
      <div class="TdmEntry">Application Domains<ul><li><a href="uid5.html&#10;&#9;&#9;  ">Privacy in smart environments</a></li><li><a href="uid6.html&#10;&#9;&#9;  ">Big Data and Privacy</a></li></ul></div>
      <div class="TdmEntry">Highlights of the Year<ul><li><a href="./uid8.html">An Privacy Risk Analysis of the TES system</a></li><li class="tdmActPage"><a href="./uid9.html">A Novel Authentication Scheme based on Implicit Memory</a></li></ul></div>
      <div class="TdmEntry">New Software and Platforms<ul><li><a href="uid11.html&#10;&#9;&#9;  ">FECFRAME</a></li><li><a href="uid14.html&#10;&#9;&#9;  ">Mobilitcs</a></li><li><a href="uid17.html&#10;&#9;&#9;  ">MyTrackingChoices</a></li><li><a href="uid20.html&#10;&#9;&#9;  ">OMEN+</a></li><li><a href="uid23.html&#10;&#9;&#9;  ">OPENFEC</a></li></ul></div>
      <div class="TdmEntry">New Results<ul><li><a href="uid29.html&#10;&#9;&#9;  ">A refinement approach for the reuse of privacy risk analysis results</a></li><li><a href="uid30.html&#10;&#9;&#9;  ">Interdisciplinarity in practice: Challenges and benefits for privacy research</a></li><li><a href="uid31.html&#10;&#9;&#9;  ">Capacity: an abstract model of control over personal data</a></li><li><a href="uid32.html&#10;&#9;&#9;  ">Privacy Risk Analysis to Enable Informed Privacy Settings</a></li><li><a href="uid33.html&#10;&#9;&#9;  ">Secure electronic documents: is the centralisation of biometric data really inevitable? Inria Analysis Note</a></li><li><a href="uid37.html&#10;&#9;&#9;  ">Biometric Systems Private by Design: Reasoning about privacy properties of biometric system architectures</a></li><li><a href="uid38.html&#10;&#9;&#9;  ">Wi-Fi and privacy</a></li><li><a href="uid39.html&#10;&#9;&#9;  ">Towards Privacy-preserving Wi-Fi Analytics</a></li><li><a href="uid40.html&#10;&#9;&#9;  ">Towards Implicit Visual Memory-Based Authentication</a></li><li><a href="uid41.html&#10;&#9;&#9;  ">MyAdChoices: Bringing transparency and control to online advertising</a></li><li><a href="uid42.html&#10;&#9;&#9;  ">Differentially Private Mixture of Generative Neural Networks</a></li><li><a href="uid43.html&#10;&#9;&#9;  ">Revisiting Private Web Search using Intel SGX</a></li><li><a href="uid44.html&#10;&#9;&#9;  ">PULP: Achieving Privacy and Utility Trade-off in User Mobility Data</a></li><li><a href="uid45.html&#10;&#9;&#9;  ">The Pitfalls of Hashing for Privacy</a></li><li><a href="uid46.html&#10;&#9;&#9;  ">Duck Attack on Accountable Distributed Systems</a></li><li><a href="uid47.html&#10;&#9;&#9;  ">Less Latency and Better Protection with AL-FEC Sliding Window Codes: a Robust Multimedia CBR Broadcast Case Study</a></li><li><a href="uid48.html&#10;&#9;&#9;  ">Coding for efficient Network Communications Research Group (NWCRG)</a></li></ul></div>
      <div class="TdmEntry">Bilateral Contracts and Grants with Industry<ul><li><a href="uid50.html&#10;&#9;&#9;  ">Bilateral Contracts with Industry</a></li></ul></div>
      <div class="TdmEntry">Partnerships and Cooperations<ul><li><a href="uid58.html&#10;&#9;&#9;  ">National Initiatives</a></li><li><a href="uid100.html&#10;&#9;&#9;  ">European Initiatives</a></li><li><a href="uid116.html&#10;&#9;&#9;  ">Regional Initiatives</a></li></ul></div>
      <div class="TdmEntry">Dissemination<ul><li><a href="uid137.html&#10;&#9;&#9;  ">Promoting Scientific Activities</a></li><li><a href="uid161.html&#10;&#9;&#9;  ">Teaching - Supervision - Juries</a></li><li><a href="uid203.html&#10;&#9;&#9;  ">Popularization</a></li></ul></div>
      <div class="TdmEntry">
        <div>Bibliography</div>
      </div>
      <div class="TdmEntry">
        <ul>
          <li>
            <a id="tdmbibentyear" href="bibliography.html">Publications of the year</a>
          </li>
        </ul>
      </div>
    </div>
    <div id="main">
      <div class="mainentete">
        <div id="head_agauche">
          <small><a href="http://www.inria.fr">
	    
	    Inria
	  </a> | <a href="../index.html">
	    
	    Raweb 
	    2017</a> | <a href="http://www.inria.fr/en/teams/privatics">Presentation of the Project-Team PRIVATICS</a> | <a href="http://team.inria.fr/privatics/">PRIVATICS Web Site
	  </a></small>
        </div>
        <div id="head_adroite">
          <table class="qrcode">
            <tr>
              <td>
                <a href="privatics.xml">
                  <img style="align:bottom; border:none" alt="XML" src="../static/img/icons/xml_motif.png"/>
                </a>
              </td>
              <td>
                <a href="privatics.pdf">
                  <img style="align:bottom; border:none" alt="PDF" src="IMG/qrcode-privatics-pdf.png"/>
                </a>
              </td>
              <td>
                <a href="../privatics/privatics.epub">
                  <img style="align:bottom; border:none" alt="e-pub" src="IMG/qrcode-privatics-epub.png"/>
                </a>
              </td>
            </tr>
            <tr>
              <td/>
              <td>PDF
</td>
              <td>e-Pub
</td>
            </tr>
          </table>
        </div>
      </div>
      <!--FIN du corps du module-->
      <br/>
      <div class="bottomNavigation">
        <div class="tail_aucentre">
          <a href="./uid8.html" accesskey="P"><img style="align:bottom; border:none" alt="previous" src="../static/img/icons/previous_motif.jpg"/> Previous | </a>
          <a href="./uid0.html" accesskey="U"><img style="align:bottom; border:none" alt="up" src="../static/img/icons/up_motif.jpg"/>  Home</a>
          <a href="./uid11.html" accesskey="N"> | Next <img style="align:bottom; border:none" alt="next" src="../static/img/icons/next_motif.jpg"/></a>
        </div>
        <br/>
      </div>
      <div id="textepage">
        <!--DEBUT2 du corps du module-->
        <h2>Section: 
      Highlights of the Year</h2>
        <h3 class="titre3">A Novel Authentication Scheme based on Implicit Memory</h3>
        <p>Selecting and remembering secure passwords puts a high cognitive burden on the user, which has adverse
effects on usability and security. Authentication schemes based on implicit memory can relieve the user
of the burden of actively remembering a secure password. In <a href="./bibliography.html#privatics-2017-bid1">[8]</a>, we propose a new authentication scheme
(MooneyAuth) that relies on implicitly remembering the content of previously seen Mooney images. These
images are thresholded two-tone images derived from images containing single objects. Our scheme has two
phases: In the enrollment phase, a user is presented with Mooney images, their corresponding original images,
and labels. This creates an implicit link between the Mooney image and the object in the user’s memory that
serves as the authentication secret. In the authentication phase, the user has to label a set of Mooney images, a
task that gets performed with substantially fewer mistakes if the images have been seen in the enrollment phase.
We applied an information-theoretical approach to compute the eligibility of the user, based on which images
were labeled correctly. This new dynamic scoring is substantially better than previously proposed static scoring
by considering the surprisal of the observed events. We built a prototype and performed three experiments
with 230 and 70 participants over the course of 264 and 21 days, respectively. We show that MooneyAuth
outperforms current implicit memory-based schemes, and demonstrates a promising new approach for fallback
authentication procedures on the Web.
This work was published at ISOC NDSS’17, one of top conferences in security and privacy.</p>
      </div>
      <!--FIN du corps du module-->
      <br/>
      <div class="bottomNavigation">
        <div class="tail_aucentre">
          <a href="./uid8.html" accesskey="P"><img style="align:bottom; border:none" alt="previous" src="../static/img/icons/previous_motif.jpg"/> Previous | </a>
          <a href="./uid0.html" accesskey="U"><img style="align:bottom; border:none" alt="up" src="../static/img/icons/up_motif.jpg"/>  Home</a>
          <a href="./uid11.html" accesskey="N"> | Next <img style="align:bottom; border:none" alt="next" src="../static/img/icons/next_motif.jpg"/></a>
        </div>
        <br/>
      </div>
    </div>
  </body>
</html>
