Knowledge-Based Authentication (KBA) verifies identity by challenging a user to supply information presumed known only to them, such as a password, PIN, or answers to security questions. Static KBA uses pre-registered secrets, while dynamic KBA generates questions from third-party records at challenge time. Because the underlying secrets can be guessed, phished, or harvested through social engineering, KBA is increasingly supplemented or replaced by possession- and biometric-based factors.
Overview
- Knowledge Based Authentication sits within the Multi-Factor Authentication area of the security domain.
- It is referenced by existing classes in the knowledge graph and is materialised here as a defined, rooted node so those edges resolve.
Key aspects
- Establishes a precise, shared meaning for knowledge based authentication usable across coordinating components.
- Integrates with neighbouring concepts through the relations enumerated below.
- Maturity assessed as established based on established practice and literature.
Mechanisms
- Operates through the dependencies and components captured in its
requires,uses, andhasPartrelations. - Produces the capabilities captured in its
enablesandsupportsrelations.
Applications
- Applied wherever security systems need the function described above.
- Connects to broader workflows via the bridging relations listed below.