返回
Query-directed passwords
DOI:10.1016/j.cose.2005.06.006.png)
摘要
En 中文
A classical tradeoff in the field of user authentication is between user convenience and system security. Should users authenticate themselves with their mother's maiden name, which is easily recalled but not very secure; or should they memorize a long, random password that is secure but unmemorable? In recent years, tokens and biometrics have been offered as the answer to this convenience-versus-security conflict; however, these require infrastructure modifications. We introduce query-directed passwords (QDP), an authentication procedure based on questions and answers - where the answers are known, not memorized. QDP is particularly convenient for infrequent use, such as monthly or yearly authentication to seldom-accessed accounts. Applications are described that capitalize on advantages of QDP. One of these is an automated password recovery system where testing showed a reduced use of Help Desk personnel for repeated, forgotten passwords from 20% to 2.7%. We discuss other applications, experimental results, and future research directions. (C) 2005 Elsevier Ltd. All rights reserved.
Keyword:
user authentication
passwords
knowledge-based authentication
challenge questions
password reset
password creation
call center authentication
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
C
IF:
5.4
论文数:
4.6K
被引数:
1.4W
机构
暂无机构信息
引用论文
Word association computer passwords: The effect of formulation techniques on recall and guessing rates
COMPUTERS & SECURITY
IF5.4

