A multi-faceted approach to user authentication for mobile devices — Using human movement, usage, and location patterns
Devu Manikantan Shila, Kunal Srivastava, Paul H. O’Neill, Kishore Reddy, Vincent Sritapan · 2016
Mobile devices have now become indispensable and ubiquitous enablers for collaboration. Such a ubiquity increases concerns over the resilience of existing mobile authentication methods and their ability to safeguard the growing amount of sensitive information stored and processed on these devices. Conventional knowledge-based authentication techniques such as PINs, passwords and pattern locks are inadequate to fully realize the current needs of the users due to low user-friendliness and insufficient security. One approach to enhance user-friendliness is to enable authentication merely for sensitive and critical applications, thereby not requiring users to inconveniently authenticate on the device every time it is accessed for e.g., while accessing low security applications such as games, news, and entertainment. However, knowledge-based techniques fail to deliver strong security guarantees for sensitive applications as they are vulnerable to classic cyber-attacks such as brute-force, social engineering, shoulder surfing, and smudge etc. Physiological biometrics such as fingerprint, voice or facial recognition can enable user-friendly and strong security, but they only provide single-shot authentication and lack ability to continuously authenticate the user. In this effort, we take a different approach by designing a multi-faceted authentication scheme termed as mAuth that continuously and unobtrusively authenticates the user while the device is being in contact with the user. By leveraging a combination of supervised and unsupervised learning techniques on the raw low-level sensor data from the mobile device, multiple inferences about the user (or higher-level contexts) such as the frequently visited locations, physical proximity with the device (carrying in the pocket or placed on the table), and gait patterns are extracted. These multiple high-level contexts regarding the user are further fused to generate a dynamic trust score that determines the degree to which the user is trustworthy to access the applications. Experiments demonstrate the performance of the individual learning algorithms as well as the overall method in identifying users under natural settings. Various attack scenarios targeting mobile devices are designed to prove the security of the proposed approach. We also explore ways to unobtrusively acquire data for supervised learning algorithms without explicit user annotation.