Back to Search Start Over

Continuous Nonintrusive Mobile Device Soft Keyboard Biometric Authentication.

Authors :
Dee, Timothy
Richardson, Ian
Tyagi, Akhilesh
Source :
Cryptography (2410-387X). Jun2022, Vol. 6 Issue 2, p1-24. 24p.
Publication Year :
2022

Abstract

Mobile banking, shopping, and in-app purchases utilize persistent authentication states for access to sensitive data. One-shot authentication permits access for a fixed time period. For instance, a username/password-based authentication allows a user access to all the shopping and payments data in the Amazon shopping app. Traditional user passwords and lock screens are easily compromised. Snooping attacks--observing an unsuspecting user entering passwords--and smudge attacks--examining touchscreen finger oil residue--enable compromised user authentication. Mobile device interactions provide robust human and device identity data. Such biometrics enhance authentication. In this paper, behavioral attributes during user input constitute the password. Adversary password reproduction difficulty increases since pure observation is insufficient. Current mobile continuous authentication schemes use, among others, touchscreen-swipe interactions or keyboard input timing. Many of these methods require cumbersome training or intrusive authentication. Software keyboard interactions provide a consistent biometric data stream. We develop biometric profiles using touch pressure, location, and timing. New interactions authenticate against a profile using a divergence measure. In our limited user-device data sets, the classification achieves virtually perfect accuracy. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
2410387X
Volume :
6
Issue :
2
Database :
Academic Search Index
Journal :
Cryptography (2410-387X)
Publication Type :
Academic Journal
Accession number :
157924399
Full Text :
https://doi.org/10.3390/cryptography6020014