Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze
  1. Pubblicazioni

Risk-Driven Behavioral Biometric-based One-Shot-cum-Continuous User Authentication Scheme

Articolo
Data di Pubblicazione:
2021
Abstract:
The paper presents a risk-driven behavioral biometric-based user authentication scheme for smartphones. Our scheme delivers one-shot-cum-continuous authentication, thus not only authenticates users at the start of the application sign-in process but also, throughout the active user session. The scheme leverages the widely used PIN/password-based authentication technology by giving flexibility to users to enter any random 8-digit alphanumeric text, instead of pre-configured PIN/Passwords. Internally, the scheme exploits two behavioral biometric traits, i.e., touch-timing-differences of the entered strokes and the hand-movement gesture recorded during the random text entry, to authenticate users. And, for the entire user session, the scheme continuously authenticates the user by computing the risk-score every time the user initiates a sensitive activity. If the risk-score is higher than the predefined threshold, the current user session terminates. Afterward, the scheme requests the user to re-authenticate. Thus, our scheme serves three main objectives: Firstly, it offers users the flexibility to enter an 8 - digit random alphanumeric text as their secret enhancing the usability of PIN/password-based schemes. Secondly, it strengthens the security of PIN/password-based schemes as verification decision is not binary, and mimicking the invisible touch-timings and hand-movements simultaneously, could be extremely difficult as our security analysis determined. Lastly, the scheme does not require any dedicated device (e.g., a smart token for OTP generation) for 2-factor authentication. The results obtained on 11,400 user-samples (collected by 3 days in-the-wild testing) and user-experience responses (received from the Software Usability Scale survey) of 95 testers demonstrate our scheme as an accurate and acceptable user authentication scheme.
Tipologia CRIS:
01.01 Articolo in rivista
Keywords:
Cyber Security; behavioural biometrics; user authentication; risk
Elenco autori:
Yautsiukhin, Artsiom
Autori di Ateneo:
YAUTSIUKHIN ARTSIOM
Link alla scheda completa:
https://iris.cnr.it/handle/20.500.14243/449044
Link al Full Text:
https://iris.cnr.it//retrieve/handle/20.500.14243/449044/198342/s11265-021-01654-2.pdf
Pubblicato in:
JOURNAL OF SIGNAL PROCESSING SYSTEMS FOR SIGNAL, IMAGE, AND VIDEO TECHNOLOGY
Journal
  • Dati Generali

Dati Generali

URL

https://link.springer.com/article/10.1007/s11265-021-01654-2
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)