A Continuous Authentication Technique for XR Utilizing Time-Based One Time Passwords, Haptics, and Kinetic Activity
Jerônimo G Grandi, Jerry W. Terrell, Kadir Lofca, Carlos Ruizvalencia, Régis Kopper · 2023
Authentication in Extended Reality (XR) applications typically re-quires the user to enter a pattern or traditional password into an adapted two-dimensional UI or to enter information from outside the XR environment such as a pairing code on a mobile device. The existing solutions are far from ideal due to the inconvenience of repeatedly exiting and entering the XR environment to transfer codes, the risk associated with relying on static passwords, and the vulnerability caused by only authenticating at the start of the session. We present an authentication method developed for XR that offers robust security and an uninterrupted user experience. Our method uses a web-connected device able to generate time-based one-time passwords (TOTP) via haptics and maintain continuous authentication by tracking the user's kinetic activity. We refer to this theoretical device as the authentication device and emulate it for this paper using either an XR tracker or a networked microcontroller with an attached IMU.