Abstract :
The author describes a framework for designing user authentication systems with challenge questions that includes privacy, security, and usability criteria for evaluating a candidate challenge-question system. The proposed challenge-question system for recovering user credentials is based on this framework.
Keywords :
authorisation; data privacy; candidate challenge-question system; privacy; security; usability criteria; user authentication systems; user credentials; Authentication; Computer security; Entropy; Environmental economics; Information security; Privacy; Protection; Usability; Challenge questions; credential recovery; password recovery; user authentication;