arXiv:2510.09645cs.CRcs.HC2025-10

通过行为与凭证分析实现自适应密码认证,兼顾安全与易用

AdaptAuth: Multi-Layered Behavioral and Credential Analysis for a Secure and Adaptive Authentication Framework for Password Security

  • 融合密码拆解、行为模式等多层特征构建用户画像
  • 能识别身份并抵御绝大多数非法访问与设备冒用
  • 自适应策略让用户参与设置,提升合规性

密码安全需应对现代系统日益增强的计算能力。但现有措施常因复杂而降低用户配合度,导致弱密码或管理不当,仍易受攻击。本文提出 AdaptAuth 框架,整合密码拆解机制、动态密码策略、人类行为模式、设备特征、网络参数、地理上下文等多维因素,借助学习模型建立详尽用户画像,实现身份精准识别,有效防止未经授权访问及设备冒用。该框架在强化防护的同时,通过自适应机制让用户参与策略制定,显著提升可用性与安全性,优于现有标准。

原文摘要 · Abstract (English)

Password security has been compelled to evolve in response to the growing computational capabilities of modern systems. However, this evolution has often resulted in increasingly complex security practices that alienate users, leading to poor compliance and heightened vulnerability. Consequently, individuals remain exposed to attackers through weak or improperly managed passwords, underscoring the urgent need for a comprehensive defense mechanism that effectively addresses password-related risks and threats. In this paper, we propose a multifaceted solution designed to revolutionize password security by integrating diverse attributes such as the Password Dissection Mechanism, Dynamic Password Policy Mechanism, human behavioral patterns, device characteristics, network parameters, geographical context, and other relevant factors. By leveraging learning-based models, our framework constructs detailed user profiles capable of recognizing individuals and preventing nearly all forms of unauthorized access or device possession. The proposed framework enhances the usability-security paradigm by offering stronger protection than existing standards while simultaneously engaging users in the policy-setting process through a novel, adaptive approach.

身份认证自适应安全行为分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。