Issue No.05 - September-October (2004 vol.2)
Mike Just , Public Works and Government Services Canada
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/MSP.2004.80
The author describes a framework for designing user authentication systems with challenge questions that includes privacy, security, and usability criteria for evaluating a candidate challenge-question system. The proposed challenge-question system for recovering user credentials is based on this framework.
Challenge questions, credential recovery, password recovery, user authentication
Mike Just, "Designing and Evaluating Challenge-Question Systems", IEEE Security & Privacy, vol.2, no. 5, pp. 32-39, September-October 2004, doi:10.1109/MSP.2004.80