Content deleted Content added
mNo edit summary |
Arlo Barnes (talk | contribs) →See also: 'what you know' is usually one of the factors in MFA |
||
(26 intermediate revisions by 19 users not shown) | |||
Line 1:
{{Short description|Method of user authentication that requires knowledge of private information}}
'''Knowledge-based authentication''', commonly referred to as '''KBA''', is a method of [[authentication]] which seeks to prove the identity of someone accessing a service
== Static KBA (
Static KBA, also referred to as "shared secrets" or "shared secret questions
The weakness of static KBA was demonstrated in [[Sarah Palin email hack|an incident in 2008]] where
Some identity verification providers have recently introduced secret sounds
== Dynamic KBA ==
Dynamic KBA is a high level of authentication that uses knowledge questions to verify each individual identity
To initiate the process, basic identification factors
▲Dynamic KBA is a high level of authentication that uses knowledge questions to verify each individual identity, but does not require the person to have provided the questions and answers beforehand. Questions are compiled from public and private data such as marketing data, [[credit reports]], or transaction history.
Dynamic KBA is employed in several different industries to verify the identities of customers as a means of fraud prevention and compliance adherence.
▲To initiate the process, basic identification factors, such as name, address, and date of birth must be provided by the consumer and checked with an [[identity verification service]]. After the identity is verified, questions are generated in realtime from the data records corresponding to the individual identity provided. Typically the knowledge needed to answer the questions is not available in a person's wallet (some companies call them "out-of-wallet questions"), making it difficult for anyone other than the actual identity to know the answer and obtain access to secured information. Generally the period of time for the person is given to respond to questions and the number of attempts is limited to prevent answers from being researched.
▲Dynamic KBA is employed in several different industries to verify the identities of customers as a means of fraud prevention and compliance adherence. Because this type of KBA is not based on an existing relationship with a consumer, it gives businesses a way to have higher identity assurance on customer identity during account origination.
== See also ==
* [[Cognitive password]]
* [[Identity verification service]]
* [[Multi-factor authentication]]
* [[Out of wallet]]
== References ==
{{reflist}}
[[Category:Computer network security]]
|