The author describes a framework for designing user authentication systems with challenge questions that includes privacy, security, and usability criteria for evaluating a candidate challenge-question system. The proposed challenge-question system for recovering user credentials is based on this framework.
Index Terms:
Challenge questions, credential recovery, password recovery, user authentication
Citation:
Mike Just, "Designing and Evaluating Challenge-Question Systems," IEEE Security and Privacy, vol. 2, no. 5, pp. 32-39, Sept. 2004, doi:10.1109/MSP.2004.80