Hitoshi Kokumai

4年前 · 4 分の読書時間 · ~10 ·

ブログ作成
>
ブログ Hitoshi
>
History, Current Status and Future Scenarios of Expanded Password System

History, Current Status and Future Scenarios of Expanded Password System

Secret Credenti

 
   
 

Memories

Episodic Memory

Predicament of Digital Identity

Passwords are so hard to manage that some people are urging the removal of passwords from digital identity altogether. What would happen, then, if the password is removed from our identity assurance?

Where the password was kicked out, security providers would be given only the physical token and the biometrics as security factors, whereas biometrics requires a fallback measure against false rejection. With the password removed, nothing but the token could be the fallback measure for the biometrics. Then system designer could have only the two choices as follows.

(1) authentication by the token alone, with an option of adding another token. Its security effect is highlighted in this cartoon we published14 years ago.

(2) authentication by the biometrics deployed in ‘multi-entrance’ method with the token as a fallback measure, security of which is lower than (1) irrespective of however called it may be, with an option of adding another token, as quantitatively explained here.

What a barren desert it would be!

More significantly, the password-less (will/volition-less authentication) is not consistent with the value of democracy. It would be a 1984-like Dystopia if our identity is authenticated without our knowledge or against our will.

Then What Else?

‘Achieving higher-security by removing the password’ and ‘Killing the password by password-dependent biometrics’ are both no more than the hyped myths. Then, what else can we look to as a valid solution to the predicament of digital identity?

The answer is expanding the password system to accept credentials based on our non-text memories as well as the text memories. We call this proposition ‘Expanded Password System’

“Expanded Password System

Bans & Only I can select all of
BL] them correctly

Broader choices with both images and characters accepted

i

 

 

 

 

Easy 10 manage reletons between accounts and corresponding passwords.

&

Torturous login is hstory. Login is now comfortable, relaxing and heaing

SRO
250
8

By accepting non-text memories, especially images associated with autobiographic/episodic memories, the Expanded Password System is able to offer a number of excellent features as follows.

- It is not only stress-free for users but fun to use.

- It turns a low-entropy password into high-entropy authentication data

- It eases the burden of managing the relationship between accounts and passwords

- It deters phishing attacks with this unique feature.

https://www.linkedin.com/pulse/targetedspear-phishing-expanded-password-system-hitoshi-kokumai/

- It can be deployed under any type of circumstance, including, combat and other panicky situations.

https://www.slideshare.net/HitoshiKokumai/identity-assurance-in-emergencies

- It supports existing schemes, such as:

- - Biometrics which require passwords as a fallback means

- - Two/multi-factor authentications that require passwords as one of the factors

- - ID Federations such as password managers and single-sign-on services that require passwords as the master-password

- Simple pictorial/emoji-passwords and patterns-on-grid can be deployed on this platform.

- It is relevant whenever text passwords and pin numbers are in use

- And, nothing would be lost for people who want to keep using text passwords

- Last but not least, it continues to rely on free will.

History and Current Status

The concept of this Expanded Password System first came up in 2000. It was followed by the prototyping in 2001 and the commercial implementations from 2003. The history is outlined in this article – How Expanded Password System Got This Way - .

Actually, over the period of 2003 to 2008, the business grew successfully. We saw several commercial adoptions amounting to some US$1 million, even though handling images was a much heavier task in those days when CPU was slow, the bandwidth narrow and the storage expensive.

It then ceased to grow as people were more and more carried away by the myths of biometrics and password-less authentication which the advocates alleged would kill the passwords altogether, with our proposition included, although we knew that biometrics have to depend on the password as a fallback measure and that a password-less auathentication, if literally implemented, would only bring tragically insecure cyberspace..

After struggling in vain to fight back for several years, we chose to get out of Japan where biometrics vendors were far more dominant than anywhere else, and started to look for bigger chances worldwide. Now, we have a lot of friends and supporters globally. The writer was invited to speak at KuppingerCole's Consumer Identity World 2018 in Seattle and Amsterdam. Expanded Password System is now acknowledged as Draft Proposal' for OASIS Open Projects.

Well, as indicated in the above, we had come up with not just prototypes but also several commercial products developed for the Japanese market such as follows:

Client Software for

- Device Login (commercial implementation)

- Applications Login (prototype)

- Image-to-Code Conversion (p)

Server Software for

- Online-Access (c.i.)

- 2-Factor Scheme (c.i.)

- Open ID Compatible (p)

Data Encryption Software with on-the-fly key generation

- Single & Distributed Authority (c.i.)

None of them, however, are well suited for the services and sales on the global markets, since the programs were all written by Japanese engineers for the Japanese clients with no consideration about the operation, support and maintenance outside Japan.

This also means, however, that we will be able to come up with the products for the global market easily and quickly with a relatively small budget because all that we need to do is to re-write the software in English with the updated cryptography.

For a brief glimpse of what Expanded Password System can offer, please watching these brief videos.

Basic Operation - on Smartphone (1m41s)

High-Security Operation - local on PC (4m28s)

Capture and registration of pictures - mapping to long PIN Codes (1m26s)

The readers might also be interested in this comprehensive FAQ -

Future Scenarios

In view of the global nature of our enterprise, we are planning to set up the headquarters in an English-speaking country where we have easy access to the sufficient business and technological resources.

Identity/Security-related businesses who are interested to share the benefits of Expanded Password System could choose one or some of the scenarios as quoted below.

1. Become one of the co-founders of a new business entity that we are going to set up as the global headquarters.

2. Secure a highly privileged status by joining our team at OASIS Open Projects as a voting sponsorship member.

3. Secure some advantageous status by taking part in the active discussions at the OASIS Projects as a non-voting member.

4. Consider other scenarios depending on their aspiration and budget.

* All would depend on their judgement on

- how large or small the enterprise of the now-unknown Expanded Password System could grow and how long or short it could survive and sustain,

- as compared with the now-popular propositions such as ‘password-less authentication’, ‘biometrics as a password-killer’ and ‘physical tokens as a password-killer’,

- as a legitimate successor to the traditional seals, autographs and text-passwords, bearing it in mind that this enterprise could keep a value for long-term social good.

< Related Articles >

Big Myths in Digital Identity

Digital Identity and Democracy


コメント
#8
Yes. It's a system I've developed over the years that is more secure than the current standard and immune to quantum cryptanalysis since it relies on complex systems theory rather than plain math. I've talked about it openly on one of my videos on the O'Reilly platform (aka Safari Books Online) and I'm open to sharing the source code with anyone who is up for providing me any feedback (it's written in Julia language). I'm quite interested in cryptanalysis myself and have studied it quite a bit, always with the use of a computer. I've managed to break several codes over the years and even created a video on the topic (also published on O'Reilly). Yet, despite all this, I've never managed to break the Thunderstorm code, while anyone who's ever seen it hasn't managed to pinpoint a weakness yet. That's not to say that it's perfect, however, which is why I never tried commercializing it.

Hitoshi Kokumai

4年前 #6

#4
Likewise

Hitoshi Kokumai

4年前 #5

#2
We would lose the future if we lose the secret credentials.
#4
I can see how this image-based system, coupled with a powerful encryption method like Thunderstorm (a system I've devised that works with large keys in a very chaotic manner, making cryptanalysis exceptionally hard), could offer a new level of security, unfathomable by today's standards. Perhaps we can discuss a potential collaboration at one point, if you are interested. Cheers

Hitoshi Kokumai

4年前 #3

#1
The password (secret credential) is absolute necessary in democratic societies. 'Text Password' is known to be insufficient. Then, if we think logically, trying something for 'Non-Text Password' is the only way forward.

Hitoshi Kokumai

4年前 #2

#2
Digital identity could have a future without 'Text Password' but would not have the future without 'Password' or 'Secret Credentials'.
Fascinating! The existing password system could definitely use an upgrade and this approach seems quite a practical alternative.

Hitoshi Kokumaiの記事

ブログを見る
2年前 · 2 分の読書時間

Another topic for today is “Passwordless made simple with user empowerment” · https://www.securitym ...

2年前 · 2 分の読書時間

We’ve come up with a slide presentation for “Bring a healthy second life to your legacy password sys ...

2年前 · 2 分の読書時間

We today take up this report “NSA: We 'don't know when or even if' a quantum computer will ever be a ...

関連プロフェッショナル

この職種に興味がある方はこちら

  • やる気スイッチのスクールIE 八広校

    塾講師 アルバイト 個別指導

    次の場所にあります: beBee S2 JP - 5日前


    やる気スイッチのスクールIE 八広校 墨田区, 日本 パートタイム

    雇用形態 · アルバイト · 職種・指導形態 · 個別指導 · 講師1名:生徒2名 · ※90分間生徒2人の間に座り、じっくり教えることができます。 · 給与 · 1授業90分1,986円〜2,186円 · ※準備給186円(1日あたり)含む · ※事務作業・研修時は別途給与支給 · 最寄駅 · 八広駅より徒歩2分 · 待遇 · 交通費全額支給 · 事務・研修時手当支給 · 交通費支給 昇給あり 研修制度充実 · 仕事内容 · 小学生~高校生を対象とした個別指導を行います。1:1または1:2の授業スタイルになりますので、大勢の前での授業とは違い、教えや ...

  • 東京個別指導学院(ベネッセグループ)西葛西教室

    塾講師 アルバイト 個別指導

    次の場所にあります: beBee S2 JP - 1日前


    東京個別指導学院(ベネッセグループ)西葛西教室 江戸川区, 日本 パートタイム

    雇用形態 · アルバイト · 職種・指導形態 · 個別指導 · 給与 · 1コマ90分1,725円〜2,640円 · 時給¥1,150~¥1,760円 · ※1コマ=授業時間(80分)+準備時間等(前後5分ずつ) · ※試用期間は3ヶ月で給与は1コマ1680円(時給換算1120円)となります。 · (2023年10月の最低賃金改定に基づく) · 授業以外の作業などにもきちんと給与をお支払いしますのでご安心ください。 · 例)カリキュラム作成、事務・研修、保護者面談時など (当社規定有) · ・授業(1,725円/1コマ):55,200円 · (※週3日/ ...

  • ホールセールをメインにさまざまな事業を展開する総合旅行会社:求人コード77027

    営業職(総合旅行会社/ホールセール担当)

    次の場所にあります: beBee S2 JP - 3日前


    ホールセールをメインにさまざまな事業を展開する総合旅行会社:求人コード77027 大阪府, 日本 フルタイム

    ■事業内容 · 同社は、1987年の設立以来、留学、海外出張、旅行、研修などの旅行代理店業務だけでなく、生命保険・損害保険といった保険代理店業務、 各旅行代理店に向けた海外航空会社の座席卸売り業務(ホールセール)と幅広い業務内容を展開しています。旅は人・物・場所など、さまざまなモノとの出会いがあり、その人の価値観や人生観を変えてしまうことも少なくありません。旅を無事に終えたとき、お客様が喜ぶ顔を間近で見ることは大きなやりがいになるはずです。同社では、「人と人とのつながりを大切に」を合言葉に、お客さま1人ひとりのご要望に添ったサービスを提供し続けています。 ...