GrIDsureGrIDsure was a personal identification system which extends the standard ‘shared-secret’ authentication model to create a secure methodology whereby a dynamic ‘one-time’ password or PIN can be generated by a user. It was invented by Jonathan Craymer and Stephen Howes in November 2005. It has received positive media reception.[1][2][3] GrIDsure went into liquidation in October 2011 after investor funding dried up.[4] On 18 November 2011 Cryptocard announced it had acquired the intellectual property of GrIDsure, which includes eight patents that have been granted and a further 16 pending. Cryptocard was already a GrIDsure OEM partner and uses the product in their portfolio.[citation needed] Authentication methodIn order to authenticate, the user is asked to input a series of numbers based on a preregistered pattern on a grid (that the user knows) and a grid of pseudo-random numbers generated by the authenticator. This results in a different series of numbers each time the user authenticates.[5] Academic receptionA study was carried out on the statistical security of GrIDsure by Richard Weber in the Statistical Laboratory of the University of Cambridge. He concluded "This is one of the most beautiful ideas I have seen in many years of looking at algorithms and optimisation problems." [citation needed] In March 2008, an independent security researcher, Mike Bond,[6] identified flaws[7] in the Gridsure authentication scheme, specifically commenting on Weber's analysis, and concluded:
The introduction to Dr Bond's paper states "This document is not intended to be a fully representative or balanced appraisal of the scheme."[citation needed] University College London conducted a usability trial. In a covering letter to the study report, Professor Sasse states:
See alsoReferences
|