UCAM-CL-TR-817 Technical Report ISSN 1476-2986 Number 817 Computer Laboratory The quest to replace passwords: a framework for comparative evaluation of Web authentication schemes Joseph Bonneau, Cormac Herley, Paul C. van Oorschot, Frank Stajano March 2012 15 JJ Thomson Avenue Cambridge CB3 0FD United Kingdom phone +44 1223 763500 http://www.cl.cam.ac.uk/ c 2012 Joseph Bonneau, Cormac Herley, Paul C. van Oorschot, Frank Stajano Technical reports published by the University of Cambridge Computer Laboratory are freely available via the Internet: http://www.cl.cam.ac.uk/techreports/ ISSN 1476-2986 3 The Quest to Replace Passwords: A Framework for Comparative Evaluation of Web Authentication Schemes ∗ [FULL LENGTH TECHNICAL REPORT] Joseph Bonneau University of Cambridge Cambridge, UK
[email protected] Cormac Herley Microsoft Research Redmond, WA, USA
[email protected] Paul C. van Oorschot Carleton University Ottawa, ON, Canada
[email protected] Frank Stajanoy University of Cambridge Cambridge, UK
[email protected] Abstract—We evaluate two decades of proposals to replace text passwords for general-purpose user authentication on the web using a broad set of twenty-five usability, deployability and security benefits that an ideal scheme might provide. The scope of proposals we survey is also extensive, including password management software, federated login protocols, graphical password schemes, cognitive authentication schemes, one-time passwords, hardware tokens, phone-aided schemes and biometrics. Our comprehensive approach leads to key insights about the difficulty of replacing passwords. Not only does no known scheme come close to providing all desired benefits: none even retains the full set of benefits that legacy passwords already provide.