An authentication protocol where the verifier sends the claimant a challenge (usually a random value or a nonce) that the claimant combines with a secret (often by hashing the challenge and a shared secret together, or by applying a private key operation to the challenge) to generate a response that is sent to the verifier. The verifier can independently verify the response generated by the Claimant (such as by re-computing the hash of the challenge and the shared secret and comparing to the response, or performing a public key operation on the response) and establish that the Claimant possesses and controls the secret. (SP 800-63) (NISTIR)
What is a challenge-response protocol?
The term Challenge Response Protocol refers to an authentication method in which one party issues an unpredictable challenge and the other proves possession of a secret or credential by producing the correct response. It gives election, security, legal, or technical readers a specific label for the concept rather than a broader everyday meaning.
How does challenge-response authentication work?
In practice, Challenge Response Protocol is applied to the technical or security purpose captured by its definition: an authentication method in which one party issues an unpredictable challenge and the other proves possession of a secret or credential by producing the correct response. Organizations combine that function with documented procedures, authorized access, testing, monitoring, and controls appropriate to the system.
Why does challenge-response resist password replay?
Understanding Challenge Response Protocol matters because the concept can affect security, reliability, auditability, or trusted operation. In this glossary context, it refers to an authentication method in which one party issues an unpredictable challenge and the other proves possession of a secret or credential by producing the correct response.
Understand more election terms clearly
Get one important election term explained each week, with authoritative sources, practical context and related definitions.
An authentication protocol where the verifier sends the claimant a challenge (usually a random value or a nonce) that the claimant combines with a secret (often by hashing the challenge and a shared secret together, or by applying a private key operation to the challenge) to generate a response that is sent to the verifier. The verifier can independently verify the response generated by the Claimant (such as by re-computing the hash of the challenge and the shared secret and comparing to the response, or performing a public key operation on the response) and establish that the Claimant possesses and controls the secret. (SP 800-63) (NISTIR)
Cite this term
Election Security Glossary. (2026). Challenge Response Protocol. In Election Security Glossary. Retrieved August 20, 2026, from https://electionsecurityglossary.com/glossary/challenge-response-protocol
Sources
01
Single-source
Get the weekly election term
Receive one cited, source-backed election explanation in your inbox each week.