首页> 外文会议>International Conference on Data and Software Engineering >A continuous fusion authentication for Android based on keystroke dynamics and touch gesture
【24h】

A continuous fusion authentication for Android based on keystroke dynamics and touch gesture

机译:基于击键动态和触摸手势的Android的连续融合认证

获取原文

摘要

As one of the most popular smartphone operating system nowadays, Android is used for various needs start from casual purpose such as games up to critical aims like banking. To avoid any access by impostor (unauthorized parties), the use of authentication system is a must. Android provides basic authentication system based on screen-lock using PIN, password, or pattern. However all those ways have several vulnerabilities, i.e: 1) leak or transfered key access, 2) only supports full binary authentication, and 3) no re-authentication nor revocation. This research aims at developing continuous behavioral authentication as a solution for those vulnerabilities. Our solution uses authentication score, not just a binary authentication. The score is constructed using fusion approach combining two modalities i.e. keystroke dynamics (typing behavior) and touch gesture (tap, swipe, and pinch behavior). Each of those authentication model is built using two-class machine learning classification. This authentication system is designed to run continuously on Android background, so it is possible to change authorization or make a revocation anytime needed. This proposed solution has been implemented as a prototype on a testing application. There are some tests have been held, first is modality experiment to find the best classifier each modality, second is continuous fusion authentication test, third is performance test. The result shows that our proposed fusion authentication get more accurate than if the modalities work respectively. Based on the continuous and live authentication testing on Android device, best fusion method is mean Olympic with a threshold 0.81 that makes the FAR and FRR equal in 0.26.
机译:作为如今最受欢迎的智能手机操作系统之一,Android用于各种需求从休闲目的开始,例如游戏,如银行业务。为避免冒名顶替者(未经授权的派对)进行任何访问,则使用身份验证系统是必须的。 Android提供基于屏幕锁的基本身份验证系统,使用PIN,密码或图案。然而,所有这些方式都有几种漏洞,即:1)泄漏或转移密钥访问,2)仅支持完整的二进制身份验证,3)无重新认证也不撤销。本研究旨在开发持续行为认证作为这些漏洞的解决方案。我们的解决方案使用身份验证分数,而不仅仅是二进制身份验证。使用融合方法构造得分,组合两个模态即击键动态(键入行为)和触摸手势(点击,刷卡和捏合行为)。每个身份验证模型都是使用两级机器学习分类构建的。此身份验证系统旨在在Android背景上连续运行,因此可以更改授权或随时进行撤销。该提出的解决方案已在测试应用程序上实现为原型。已经举行了一些测试,首先是模态实验,找到最佳分类器每种方式,第二是连续融合认证测试,第三是性能测试。结果表明,我们所提出的融合认证分别比分别工作得更准确。基于Android设备上的连续和现场认证测试,最佳融合方法是替代奥林匹克,其阈值0.81,使得远程和FRR在0.26中等。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号