Evaluating Security and Usability of Profile Based Challenge Questions Authentication in Online Examinations

Abrar Ullah, Hannan Xiao, Trevor Barker, Mariana Lilley

Research output: Contribution to journalArticlepeer-review

14 Citations (Scopus)
192 Downloads (Pure)


Student authentication in online learning environments is an increasingly challenging issue due to the inherent absence of physical interaction with online users and potential security threats to online examinations. This study is part of ongoing research on student authentication in online examinations evaluating the potential benefits of using challenge questions. The authors developed a Profile Based Authentication Framework (PBAF), which utilises challenge questions for students’ authentication in online examinations. This paper examines the findings of an empirical study in which 23 participants used the PBAF including an abuse case security analysis of the PBAF approach. The overall usability analysis suggests that the PBAF is efficient, effective and usable. However, specific questions need replacement with suitable alternatives due to usability challenges. The results of the current research study suggest that memorability, clarity of questions, syntactic variation and question relevance can cause usability issues leading to authentication failure. A configurable traffic light system was designed and implemented to improve the usability of challenge questions. The security analysis indicates that the PBAF is resistant to informed guessing in general, however, specific questions were identified with security issues. The security analysis identifies challenge questions with potential risks of informed guessing by friends and colleagues. The study was performed with a small number of participants in a simulation online course and the results need to be verified in a real educational context on a larger sample size
Original languageEnglish
Article number2
Number of pages16
JournalJournal of Internet Services and Applications
Issue number1
Publication statusPublished - 4 Mar 2014


Dive into the research topics of 'Evaluating Security and Usability of Profile Based Challenge Questions Authentication in Online Examinations'. Together they form a unique fingerprint.

Cite this