Issue No. 05 - September-October (2004 vol. 2)
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/MSP.2004.80
Mike Just , Public Works and Government Services Canada
The author describes a framework for designing user authentication systems with challenge questions that includes privacy, security, and usability criteria for evaluating a candidate challenge-question system. The proposed challenge-question system for recovering user credentials is based on this framework.
Challenge questions, credential recovery, password recovery, user authentication
M. Just, "Designing and Evaluating Challenge-Question Systems," in IEEE Security & Privacy, vol. 2, no. , pp. 32-39, 2004.