Knowledge-Based Authentication (KBA) verifies identity by challenging a user to supply information presumed known only to them, such as a password, PIN, or answers to security questions. Static KBA uses pre-registered secrets, while dynamic KBA generates questions from third-party records at challenge time. Because the underlying secrets can be guessed, phished, or harvested through social engineering, KBA is increasingly supplemented or replaced by possession- and biometric-based factors.

Overview

  • Knowledge Based Authentication sits within the Multi-Factor Authentication area of the security domain.
  • It is referenced by existing classes in the knowledge graph and is materialised here as a defined, rooted node so those edges resolve.

Key aspects

  • Establishes a precise, shared meaning for knowledge based authentication usable across coordinating components.
  • Integrates with neighbouring concepts through the relations enumerated below.
  • Maturity assessed as established based on established practice and literature.

Mechanisms

  • Operates through the dependencies and components captured in its requires, uses, and hasPart relations.
  • Produces the capabilities captured in its enables and supports relations.

Applications

  • Applied wherever security systems need the function described above.
  • Connects to broader workflows via the bridging relations listed below.

Provenance