DocumentCode :
1431752
Title :
When the Password Doesn´t Work: Secondary Authentication for Websites
Author :
Reeder, Robert W. ; Schechter, Stuart
Volume :
9
Issue :
2
fYear :
2011
Firstpage :
43
Lastpage :
49
Abstract :
Nearly all websites that maintain user-specific accounts employ passwords to verify that a user attempting to access an account is, in fact, the account holder. However, websites must still be able to identify users who can´t provide their correct password, as passwords might be lost, forgotten, or stolen. In this case, users will require a form of secondary authentication to prove that they are who they say they are and regain account access. Websites can use a variety of secondary authentication. The article discusses secondary authentication mechanisms, emphasizing the importance of assembling an arsenal of mechanisms that meet users´ security and reliability needs.
Keywords :
Web sites; authorisation; message authentication; Websites; account access; password; secondary authentication; user security; user specific accounts; Access control; Authentication; Data privacy; Knowledge based systems; Reliability; Web services; authentication; password reset; passwords; security question; trustees;
fLanguage :
English
Journal_Title :
Security & Privacy, IEEE
Publisher :
ieee
ISSN :
1540-7993
Type :
jour
DOI :
10.1109/MSP.2011.1
Filename :
5696724
Link To Document :
بازگشت