Continuous Transparent Mobile Device Touchscreen Soft Keyboard Biometric Authentication

Timothy Dee, Ian G. Richardson, Akhilesh Tyagi · 2019

Mobile banking, shopping, and in-app purchases utilize persistent authentication states for access to sensitive data. One-shot authentication permits access for a fixed time period. For instance, a [user name, password] based authentication allows a user access to all the shopping and payments data in the Amazon shopping app. Traditional user passwords and lock screens are easily compromised. Snooping attacks - observing an unsuspecting user entering passwords - and Smudge attacks - examining touchscreen finger oil residue - enable compromised user authentication. Mobile device interactions provide robust human and device identity data. Such biometrics enhance authentication. Behavioral attributes during information input constitute the password. Adversary password reproduction difficulty increases since pure observation is insufficient. Current mobile continuous authentication schemes use, among others, touchscreen swipe interactions or keyboard input timing. Many of these methods require cumbersome training or intrusive authentication. Software keyboard interactions provide a consistent biometric data stream. We develop biometric profiles using touch pressure, location, and timing. New interactions authenticate against a profile using a distance metric. Classification achieves 100% accuracy in 3840.33 milliseconds on Nexus 7 tablets.

Read the paper · More papers on PaperTik