{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,6,9]],"date-time":"2024-06-09T13:32:53Z","timestamp":1717939973581},"reference-count":27,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2015,6,24]],"date-time":"2015-06-24T00:00:00Z","timestamp":1435104000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2015,6,24]],"date-time":"2015-06-24T00:00:00Z","timestamp":1435104000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Hum. Cent. Comput. Inf. Sci."],"published-print":{"date-parts":[[2015,12]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Online service providers often use challenge questions (a.k.a. knowledge\u2010based authentication) to facilitate resetting of passwords or to provide an extra layer of security for authentication. While prior schemes explored both static and dynamic challenge questions to improve security, they do not systematically investigate the problem of designing challenge questions and its effect on user recall performance. Interestingly, as answering different styles of questions may require different amount of cognitive effort and evoke different reactions among users, we argue that the style of challenge questions itself can have a significant effect on user recall performance and usability of such systems. To address this void and investigate the effect of question types on user performance, this paper explores location\u2010based challenge question generation schemes where different types of questions are generated based on users\u2019 locations tracked by smartphones and presented to users. For evaluation, we deployed our location tracking application on users\u2019 smartphones and conducted two real\u2010life studies using four different kinds of challenge questions. Each study was approximately 30 days long and had 14 and 15 users respectively. Our findings suggest that the question type can have a significant effect on user performance. Finally, as individual users may vary in terms of performance and recall rate, we investigate and present a Bayesian classifier based authentication algorithm that can authenticate legitimate users with high accuracy by leveraging individual response patterns while reducing the success rate of adversaries.<\/jats:p>","DOI":"10.1186\/s13673-015-0032-3","type":"journal-article","created":{"date-parts":[[2015,6,23]],"date-time":"2015-06-23T03:03:35Z","timestamp":1435028615000},"update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Designing challenge questions for location\u2010based authentication systems: a real\u2010life study"],"prefix":"10.1186","volume":"5","author":[{"given":"Yusuf","family":"Albayram","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mohammad Maifi","family":"Hasan Khan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Athanasios","family":"Bamis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sotirios","family":"Kentros","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nhan","family":"Nguyen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ruhua","family":"Jiang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2015,6,24]]},"reference":[{"key":"32_CR1","first-page":"9","volume-title":"Proceedings of the 5th Symposium on Usable Privacy and Security","author":"S Schechter","year":"2009","unstructured":"Schechter S, Reeder RW (2009) 1+1= you: Measuring the comprehensibility of metaphors for configuring backup authentication In: Proceedings of the 5th Symposium on Usable Privacy and Security, 9.. ACM, New York, NY, USA."},{"issue":"5","key":"32_CR2","doi-asserted-by":"publisher","first-page":"695","DOI":"10.1109\/TKDE.2007.1024","volume":"19","author":"Y Chen","year":"2007","unstructured":"Chen Y, Liginlal D (2007) Bayesian Networks for Knowledge\u2010Based Authentication. IEEE Trans Knowl Data Eng 19(5): 695\u2013710. IEEE Educational Activities Department, Piscataway, NJ, USA.","journal-title":"IEEE Trans Knowl Data Eng"},{"issue":"1","key":"32_CR3","doi-asserted-by":"publisher","first-page":"388","DOI":"10.1016\/j.dss.2008.07.008","volume":"46","author":"Y Chen","year":"2008","unstructured":"Chen Y, Liginlal D (2008) A maximum entropy approach to feature selection in knowledge\u2010based authentication. Decision Support Systems 46(1): 388\u2013398.","journal-title":"Decision Support Systems"},{"key":"32_CR4","doi-asserted-by":"crossref","unstructured":"Jakobsson M (2012) The Death of the Internet. John Wiley & Sons.","DOI":"10.1002\/9781118312551"},{"key":"32_CR5","doi-asserted-by":"publisher","first-page":"13","DOI":"10.1145\/1408664.1408667","volume-title":"Proceedings of the 4th Symposium on Usable Privacy and Security","author":"A Rabkin","year":"2008","unstructured":"Rabkin A (2008) Personal knowledge questions for fallback authentication: Security questions in the era of facebook In: Proceedings of the 4th Symposium on Usable Privacy and Security, 13\u201323.. ACM, New York, NY, USA."},{"key":"32_CR6","doi-asserted-by":"publisher","first-page":"375","DOI":"10.1109\/SP.2009.11","volume-title":"Proceedings of the 2009 30th IEEE Symposium on Security and Privacy","author":"S Schechter","year":"2009","unstructured":"Schechter S, Brush AB, Egelman S (2009) It\u2019s no secret. measuring the security and reliability of authentication via \u201csecret\u201d questions In: Proceedings of the 2009 30th IEEE Symposium on Security and Privacy, 375\u2013390.. IEEE Computer Society, Washington, DC, USA."},{"key":"32_CR7","doi-asserted-by":"publisher","first-page":"54","DOI":"10.1007\/978-3-540-27809-2_6","volume-title":"Financial Cryptography","author":"L O\u2019Gorman","year":"2004","unstructured":"O\u2019Gorman L, Bagga A, Bentley J (2004) Call center customer verification by query\u2010directed passwords In: Financial Cryptography, 54\u201367.. Springer, Berlin Heidelberg."},{"key":"32_CR8","first-page":"6","volume":"7","author":"F Asgharpour","year":"2007","unstructured":"Asgharpour F, Jakobsson M (2007) Adaptive challenge questions algorithm in password reset\/recovery. First International Workshop on Security for Spontaneous Interaction (IWIISI \u201907), Innsbruck, Austria, (2007) 7: 6.","journal-title":"First International Workshop on Security for Spontaneous Interaction (IWIISI \u201907), Innsbruck, Austria, (2007)"},{"key":"32_CR9","volume-title":"Proceedings of Customer Focused Mobile Services Workshop at WWW2005","author":"A Nosseir","year":"2005","unstructured":"Nosseir A, Connor R, Dunlop MD (2005) Internet authentication based on personal history\u2010A Feasibility Test In: Proceedings of Customer Focused Mobile Services Workshop at WWW2005.. ACM Press, New York, NY, USA."},{"issue":"2","key":"32_CR10","first-page":"18","volume":"5","author":"M Nishigaki","year":"2007","unstructured":"Nishigaki M, Koike M (2007) A user authentication based on personal history\u2010a user authentication system using e\u2010mail history. J Syst Cybern Inform 5(2): 18\u201323.","journal-title":"J Syst Cybern Inform"},{"key":"32_CR11","doi-asserted-by":"publisher","first-page":"429","DOI":"10.1145\/1182475.1182529","volume-title":"Proceedings of the 4th Nordic Conference on Human\u2010computer Interaction: Changing Roles","author":"A Nosseir","year":"2006","unstructured":"Nosseir A, Connor R, Revie C, Terzis S (2006) Question\u2010based authentication using context data In: Proceedings of the 4th Nordic Conference on Human\u2010computer Interaction: Changing Roles, 429\u2013432.. ACM, New York, NY, USA."},{"key":"32_CR12","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1145\/2493432.2493453","volume-title":"Proceedings of the 2013 ACM International Joint Conference on Pervasive and Ubiquitous Computing","author":"S Das","year":"2013","unstructured":"Das S, Hayashi E, Hong JI (2013) Exploring capturable everyday memory for autobiographical authentication In: Proceedings of the 2013 ACM International Joint Conference on Pervasive and Ubiquitous Computing, 211\u2013220.. ACM, New York, NY, USA."},{"key":"32_CR13","doi-asserted-by":"publisher","first-page":"137","DOI":"10.1109\/JCIT.1990.128279","volume-title":"Information Technology, 1990.\u2019Next Decade in Information Technology\u2019, Proceedings of the 5th Jerusalem Conference on (Cat. No. 90TH0326\u20109)","author":"M Zviran","year":"1990","unstructured":"Zviran M, Haga WJ (1990) User authentication by cognitive passwords: an empirical assessment In: Information Technology, 1990.\u2019Next Decade in Information Technology\u2019, Proceedings of the 5th Jerusalem Conference on (Cat. No. 90TH0326\u20109), 137\u2013144.. IEEE Computer Society Press, Los Alamitos, CA, USA."},{"key":"32_CR14","doi-asserted-by":"publisher","first-page":"304","DOI":"10.1109\/OZCHI.1996.560026","volume-title":"Proceedings of the 6th Australian Conference on Computer\u2010Human Interaction (OZCHI \u201996)","author":"J Podd","year":"1996","unstructured":"Podd J, Bunnell J, Henderson R (1996) Cost\u2010effective computer security: Cognitive and associative passwords In: Proceedings of the 6th Australian Conference on Computer\u2010Human Interaction (OZCHI \u201996), 304\u2013305.. IEEE Computer Society, Washington, DC, USA."},{"key":"32_CR15","first-page":"63","volume-title":"Proceedings of the 12th International Conference on Enterprise Information Systems (ICEIS\u201910)","author":"A Nosseir","year":"2010","unstructured":"Nosseir A, Terzis S (2010) A study in authentication via electronic personal history questions In: Proceedings of the 12th International Conference on Enterprise Information Systems (ICEIS\u201910), 63\u201370.. HCI, Funchal, Madeira, Portugal."},{"issue":"1","key":"32_CR16","doi-asserted-by":"publisher","first-page":"2","DOI":"10.1186\/1869-0238-5-2","volume":"5","author":"A Ullah","year":"2014","unstructured":"Ullah A, Xiao H, Barker T, Lilley M (2014) Evaluating security and usability of profile based challenge questions authentication in online examinations. J Internet Serv Appl 5(1): 2.","journal-title":"J Internet Serv Appl"},{"key":"32_CR17","doi-asserted-by":"publisher","first-page":"479","DOI":"10.1109\/PerComW.2012.6197540","volume-title":"Pervasive Computing and Communications Workshops (PERCOM Workshops), 2012 IEEE International Conference On","author":"P Gupta","year":"2012","unstructured":"Gupta P, Wee TK, Ramasubbu N, Lo D, Gao D, Balan RK (2012) Human: Creating memorable fingerprints of mobile users In: Pervasive Computing and Communications Workshops (PERCOM Workshops), 2012 IEEE International Conference On, 479\u2013482.. IEEE, Washington, DC, USA."},{"key":"32_CR18","doi-asserted-by":"crossref","unstructured":"Xu K, Yao D, P\u00e9rez\u2010Quinones MA, Link C, Scott Geller E (2014) Role\u2010playing game for studying user behaviors in security: A case study on email secrecy In: Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom), 2014 International Conference On, 18\u201326.. IEEE.","DOI":"10.4108\/icst.collaboratecom.2014.257242"},{"key":"32_CR19","doi-asserted-by":"crossref","first-page":"19","DOI":"10.1145\/2600075.2600077","volume-title":"Proceedings of the 2nd International Workshop on Security in Cloud Computing","author":"BJ Choi","year":"2014","unstructured":"Choi BJ, Sun K, Choi S (2014) Cloud\u2010based user authentication with Geo\u2010temporal queries on smartphones In: Proceedings of the 2nd International Workshop on Security in Cloud Computing, 19\u201326.. ACM, New York, NY, USA."},{"key":"32_CR20","unstructured":"GSam Battery Monitor Application. https:\/\/play.google.com\/store\/apps\/details?id=com.gsamlabs.bbm&hl=en."},{"key":"32_CR21","unstructured":"Ester M, Kriegel HP, Sander J, Xu X (1996) A density\u2010based algorithm for discovering clusters in large spatial databases with noise In: KDD, 226\u2013231."},{"key":"32_CR22","unstructured":"The Google Maps Geolocation API. https:\/\/developers.google.com\/maps\/documentation\/business\/geolocation\/."},{"key":"32_CR23","unstructured":"The Haversine Formula. http:\/\/en.wikipedia.org\/wiki\/Haversine_formula."},{"key":"32_CR24","unstructured":"Supported Place Types in the Google Places API. https:\/\/developers.google.com\/places\/documentation\/supported_types."},{"key":"32_CR25","volume-title":"Basic Statistics for the Behavioral Sciences","author":"GW Heiman","year":"2010","unstructured":"Heiman GW (2010) Basic Statistics for the Behavioral Sciences. Cengage Learning, Belmont, CA, USA."},{"key":"32_CR26","first-page":"14","volume-title":"Proceedings of the Ninth Symposium on Usable Privacy and Security","author":"J Thorpe","year":"2013","unstructured":"Thorpe J, MacRae B, Salehi\u2010Abari A (2013) Usability and security evaluation of GeoPass: a geographic location\u2010password scheme In: Proceedings of the Ninth Symposium on Usable Privacy and Security, 14.. ACM, New York, NY, USA."},{"key":"32_CR27","volume-title":"Statistics with STATA: Version 12","author":"LC Hamilton","year":"2012","unstructured":"Hamilton LC (2012) Statistics with STATA: Version 12. Duxbury Press, Boston, MA, USA."}],"container-title":["Human-centric Computing and Information Sciences"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13673-015-0032-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s13673-015-0032-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1186\/s13673-015-0032-3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13673-015-0032-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,7,30]],"date-time":"2021-07-30T07:18:38Z","timestamp":1627629518000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s13673-015-0032-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,6,24]]},"references-count":27,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2015,12]]}},"alternative-id":["32"],"URL":"https:\/\/doi.org\/10.1186\/s13673-015-0032-3","relation":{},"ISSN":["2192-1962"],"issn-type":[{"value":"2192-1962","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015,6,24]]},"assertion":[{"value":"22 December 2014","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"4 May 2015","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"24 June 2015","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"17"}}