arrow
Return

Query-directed passwords

delete2005-10-01
delete13
PRE
AI
L
Lawrence O’Gorman
A
Amit Bagga
J
Jon Bentley
DOI:10.1016/j.cose.2005.06.006delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
A classical tradeoff in the field of user authentication is between user convenience and system security. Should users authenticate themselves with their mother's maiden name, which is easily recalled but not very secure; or should they memorize a long, random password that is secure but unmemorable? In recent years, tokens and biometrics have been offered as the answer to this convenience-versus-security conflict; however, these require infrastructure modifications. We introduce query-directed passwords (QDP), an authentication procedure based on questions and answers - where the answers are known, not memorized. QDP is particularly convenient for infrequent use, such as monthly or yearly authentication to seldom-accessed accounts. Applications are described that capitalize on advantages of QDP. One of these is an automated password recovery system where testing showed a reduced use of Help Desk personnel for repeated, forgotten passwords from 20% to 2.7%. We discuss other applications, experimental results, and future research directions. (C) 2005 Elsevier Ltd. All rights reserved.
Keywords:
user authentication
passwords
knowledge-based authentication
challenge questions
password reset
password creation
call center authentication
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

C
Computers and Security
IF:
5.4
Papers:
4.6K
Citations:
1.4W

Organization

No organization information available