Abstract

Knowledge-based Authentication (KBA) is an au-thentication approach, which verifying the user identity when accessing services such as finical websites. KBA requests specific information to prove personal identity of the owner. This paper discusses the challenges that are faced by KBA techniques. Memorability is the main obstacle in KBA since the users trying to utilize simple passwords or unify the passwords in various services, a step that cause problems and issues with compliance with security policies. Furthermore, the technique of mixing username/password is considered as another important challenge of KBA due to the recall-based authentication. This discussion includes a comparative analysis of KBA’s techniques based on trade-off criteria to support making of decision. This study’s results can support organizations in the recommendations process of a suitable KBA technique for organizations.

Highlights

  • Authorization [1, 2] is the process of ensuring only authorized rights are exercised in the process of determining rights

  • It is based on Knowledge-based authentication (KBA) that requires to depend on four dimensions [18], which are known as KBA techniques, memorability, usability, performance, and cost

  • This paper introduces the authentication survey and makes comparison of the different types of authentication mechanisms

Read more

Summary

INTRODUCTION

Authorization [1, 2] is the process of ensuring only authorized rights are exercised in the process of determining rights. Previous researches discuss the different identification and authentication techniques and their different key terms which include protect credentials, identity, password, biometrics, and others [6]. Any system that relies on the secret user identity information such as text or image passwords that the user provided in the registrations process or when creating passwords is said to be dependent on knowledge-based authentication for its users authentication [7]. In Addition, the static KBA refers to the process that enable users to choose security questions and provide answers that are www.ijacsa.thesai.org. The dynamic KBA refers to go a step that generate questions that applies only to the intended end user and do not require a previous relationship with the customer. This study discuses the definition, importance, types, techniques, and challenges of KBA.

RELATED WORKS
Knowledge-based Authentication Challenges
Knowledge-based Authentication Security Measurements
DISCUSSION
Dynamic
OPEN RESEARCH TRENDS
CONCLUSION AND FUTURE WORKS
Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call