Source-linked AI summary

Authentication of Smartphone Users Using Behavioral Biometrics

Abdulaziz Alzubaidi, Jugal Kalita

arXiv:1911.04104v1cs.CR

TL;DR

Smartphones concentrate valuable private information while remaining vulnerable when lost, stolen, or accessed by unauthorized people. This paper reviews continuous authentication and behavioral-biometric approaches, comparing their methodologies, datasets, classifiers, and evaluation practices. It concludes that future methods should address varied attacks while remaining easy to use and adapted to individual owners.

  • Problem

    Smartphones store extensive private information, while conventional entry authentication may be vulnerable to attacks and does not detect intruders after access.

  • Method

    The paper surveys seven behavioral biometrics and compares existing smartphone-authentication studies by methodology, datasets, classifiers, evaluation results, and user security needs.

  • Results

    The paper discusses and compares existing continuous-authentication solutions from several perspectives and identifies open problems and future work.

  • Takeaways & Limitations

    Future smartphone-authentication methods should address multiple characteristics and attacks while remaining easy to use and adapted to each owner.

Abstract

from arXiv · show

Smartphones and tablets have become ubiquitous in our daily lives. Smartphones, in particular, have become more than personal assistants. These devices have provided new avenues for consumers to play, work, and socialize whenever and wherever they want. Smartphones are small in size, so they are easy to handle and to stow and carry in users' pockets or purses. However, mobile devices are also susceptible to various problems. One of the greatest concerns is the possibility of breach in security and privacy if the device is seized by an outside party. It is possible that threats can come from friends as well as strangers. Due to the size of smart devices, they can be easily lost and may expose details of users' private lives. In addition, this might enable pervasive observation or imitation of one's movements and activities, such as sending messages to contacts, accessing private communication, shopping with a credit card, and relaying information about where one has been. This paper highlights the potential risks that occur when smartphones are stolen or seized, discusses the concept of continuous authentication, and analyzes current approaches and mechanisms of behavioral biometrics with respect to methodology, associated datasets and evaluation approaches.

I. INTRODUCTION

The paper surveys smartphone authentication research motivated by growing security and privacy risks, focusing on seven behavioral biometrics and comparing methodologies, datasets, classifiers, and evaluation results.

  • I. INTRODUCTION: Smartphone adoption has increased while devices store extensive personal, communication, and location-related information.The introduction describes smartphones as multifunctional devices with substantial storage for valuable personal data.
  • I. INTRODUCTION: The survey reviews seven behavioral biometrics: handwaving, gait, touchscreen, keystroke, voice, signature, and general profiling.It covers the methodologies, associated datasets, evaluation approaches, and classifiers used in smartphone authentication studies.
  • I. INTRODUCTION: The paper compares existing studies and summarizes lessons learned, open problems, and future work for continuous authentication on smartphones.Its stated contributions include characterizing behavioral biometrics, recognition algorithms, and results obtained with different techniques.
  • I. INTRODUCTION: Lost, stolen, or physically accessed smartphones can expose private information and enable unauthorized use of social, financial, and other applications.The survey notes increasing device losses and limited use of PINs or visual codes among owners.
  • I. INTRODUCTION: Existing authentication mechanisms can be cumbersome, vulnerable to evasion, shoulder surfing, and smudge attacks, motivating research into stronger protections.The paper identifies weaknesses in current security mechanisms and entry-point authentication.

B. SOLUTION CHARACTERISTICS

The paper characterizes continuous authentication as passive, ongoing identity verification that supplements entry-point authentication and should remain convenient, nonintrusive, and lightweight.

  • B. SOLUTION CHARACTERISTICS: PINs and patterns can fail after entry-point authentication because they do not continuously detect an intruder and may be vulnerable to smudge and shoulder-surfing attacks.The paper proposes continuing authentication while the device is being used.
  • A. Authentication: Authentication strategies include knowledge-based, possession-based, and biometric approaches using physical or behavioral characteristics.The paper distinguishes active authentication, which requires user input, from passive authentication performed during ordinary use.
  • B. SOLUTION CHARACTERISTICS: Continuous authentication passively records user-behavior features during device use and makes background decisions about whether the current user is legitimate.The paper also refers to this approach as implicit, passive, or progressive authentication.
  • B. SOLUTION CHARACTERISTICS: A viable continuous-authentication system should operate continuously, avoid interrupting normal behavior, and use low computational resources.These requirements target fast, convenient, practical, and passive validation.

B. Biometric

This section distinguishes behavioral biometrics from physiological biometrics and surveys their use in continuous smartphone authentication. It also introduces evaluation metrics, smartphone sensors, and interaction-based behavioral signals.

  • Biometric categories: Biometric systems support identification and authentication, while combining multiple primary authentication types may strengthen security.
  • Behavioral biometrics: Behavioral biometrics identify users through distinctive actions such as typing, touching screens, walking, speaking, signing, and handwaving.
  • Evaluation metrics: Authentication systems are evaluated using False Acceptance Rate (FAR) and False Rejection Rate (FRR), alongside accuracy, execution time, and power consumption.
  • Smartphone sensors: Smartphones provide position, motion, and environmental sensors, plus microphones, cameras, touchscreens, GPS, and compasses for behavioral analysis.
  • Smartphone sensors: Motion sensors measure acceleration and rotational forces across three axes, supporting recognition of movements such as walking, sitting, and device orientation.
  • Continuous authentication: Continuous or implicit authentication analyzes device interactions to model when legitimate users are operating smartphones, enabling passive and non-intrusive security.

1) Wave-to-Access:

The reviewed studies use behavioral signals from waving, keystrokes, handwriting, and touchscreen interaction for smartphone authentication, with performance depending on features, classifiers, and operating conditions.

  • 1) Wave-to-Access:: Wave-to-Access uses a smartphone ambient light sensor to analyze hand-waving before allowing calls, and its initial experiment reported an average FNR of 9.5%.The system was implemented on a Motorola Droid X2, with 20 subjects performing ten hand waves each during initial unlocking.
  • 2) OpenSesame:: OpenSesame captures users’ waving patterns and applies SVM classification to distinguish authorized from unauthorized users.The study involved 200 subjects and recorded 389,373 raw tuples, with normal and fast sampling modes.
  • 2) OpenSesame:: Using a window size of 50 reduced average FNR from 20% to 8% and FPR from 42% to 18% in OpenSesame.More training tuples further reduced FNR from 15% to 8% and FPR from 20% to 15%.
  • 2) OpenSesame:: OpenSesame’s FNR stayed near 11% as motion speed increased, while FPR remained around 15%, indicating limited sensitivity to user motion.The tests covered stationary use, walking, running, and vehicle travel.
  • 2) OpenSesame:: OpenSesame required 3 seconds to unlock, longer than a PIN, although participants found the approach easy to use.The evaluation considered user-friendliness, security, and accessibility.
  • B. Keystroke Based Authentication: A combined keystroke-and-handwriting scheme achieved EERs of 2.0% for sentence typing and 13.5% for password entry.The study used separate smartphone experiments with 18 and 16 subjects, respectively.

2) Typing Authentication and Protection (TAP):

The reviewed typing-based approaches use diverse keystroke, touch, motion, and digraph features with multiple classifiers, producing substantially different authentication outcomes across scenarios.

  • 2) Typing Authentication and Protection (TAP):: For TAP, Bayes Net achieved FAR of 10.4%-16.9% and FRR of 11.0% in login comparisons, while post-login Bayes Net achieved FRR of 0.27%.Random Forest achieved the best post-login FAR of 8.93% for 60-character input sequences.
  • 4) Using speed of finger movement:: Speed-and-distance touchscreen features produced scenario-dependent results: Random Forest achieved EER of 26.0% in the first scenario, while k-NN achieved EER of 13.6% in the second.The evaluated features were hold-time, inter-time, distance, and speed.
  • Keystroke-based approaches: KeySens authenticates users from micro-behaviors including key location, finger movement, touch force, and contact area.The study collected 86,000 keypresses and 430,000 touch data points from 13 subjects over three weeks.
  • 7) Thumb-based keyboards for keystroke dynamic authentication:: Thumb-keyboard analysis found inter-keystroke timing more useful than hold time, with average EER of 12.2% versus 36.8%-50.02%.The comparison used a feed-forward multilayer perceptron neural network on 50 subjects’ messages.
  • 9) Using sensors with a virtual software keyboards to identify users:: Sensor-based typing classification reached FPR of 35% and TPR of 58% for non-identifiable users, but TPR of 92% and FPR of 1% for clearly identifiable users.The high false-positive rate for non-identifiable users caused repeated device locking, conflicting with continuous-authentication goals.

C. Touchscreen Based Authentication

Touchscreen authentication studies analyze interaction traces using sensors, gesture features, classifiers, and continuous background monitoring. Reported performance varies with gesture type, training data, and model configuration.

  • Non-Intrusive Tapping: 80-subject tapping experiments using accelerometer, gyroscope, and touchscreen data produced EERs between 3.58% and 7.34% across five PIN inputs.The approach used one-class learning based on nearest-neighbor distance.
  • Methods: Touchscreen studies use inputs including coordinates, timing, pressure, acceleration, touch area, and gesture movement patterns.These measurements support authentication from tapping, sliding, flipping, and other gestures.
  • Graphic Touch Gesture Feature: GTGF evaluated L1 distance, L2 distance, and normalized cross correlation, obtaining 11.28%, 12.38%, and 17.29%, respectively.The study used more than 300 gestures from 30 subjects in the UH-TOUCHv2 dataset.
  • Graphic Touch Gesture Feature: GTGF-A achieved the best fusion-scheme EER at 2.62%, while GTGF-M achieved the worst at 7.81%.The authors attribute the result to tactile pressure and dynamic movement features.
  • Re-Authentication Model: Finger-movement re-authentication runs in the background and compares current gesture patterns with the device owner’s patterns.Its best reported results were FAR of 4% and FRR of 4%, with accuracy affected by block size and training-set size.

5) Touchalytic system continuous authentication:

The reviewed systems combine passive touchscreen or behavioral authentication with contextual information and risk-aware policies. Their evaluations emphasize recognition accuracy, authentication burden, and resource use.

  • Touchalytic system continuous authentication: Touchalytic collects raw touchscreen movements, pressure, finger area, orientation, and screen orientation while users read documents or compare images.The system was designed to examine whether simple touch movements can support continuous authentication.
  • Identity Protection Service: TIPS collects behavioral and contextual gesture features through background services targeting uncontrolled environments, accuracy, and real-time recognition.Its architecture includes a multi-touch driver and a context listener.
  • Identity Protection Service: TIPS reached 91% true-positive and 93% true-negative rates, with average energy usage of 88mW and battery usage below 6.2%.Accuracy improved with longer authentication lengths, while minimizing template size reduced accuracy.
  • Keystroke and Touchscreen Patterns: Combining keystroke and touchscreen features produced an EER of 9%, compared with 29% using hold-time and inter-key metrics alone.The study recorded hold-time, inter-key timing, and finger pressure from repeated phone-number entry.
  • Progressive Authentication: Risk-factor changes traded false authentications against false rejections across private and confidential applications.At F = 20, false rejection for confidential applications was 96.8%, while private-application false rejection was 34.4%.

9) Authentication based on Curve Training:

Curve- and gesture-based systems represent touch behavior through spatial, temporal, pressure, and motion features. Studies evaluate these representations with several classifiers and distance measures across diverse devices and participant groups.

  • Authentication based on Curve Training: Curve Training extracts X-Y coordinates and timestamps as users trace randomly generated curves with indicated start and end points.The study recruited 42 participants.
  • Fingergestures Authentication System: FAST captures finger-motion coordinates, speed, pressure, and direction from gestures including swipes, zooms, taps, and typing.Its evaluation used 53 features per touch gesture and compared users with and without sensor gloves.
  • Fingergestures Authentication System: FAST with Bayes Net achieved FAR of 2.15% and FRR of 1.63% for single-touch gestures using sensor gloves.Without external sensors, the corresponding FAR and FRR were 11.96% and 8.53%.
  • Gesture Authentication: GEAT uses finger velocity, device acceleration, and stroke time across gesture collection, feature extraction, and classification phases.The system recruited 50 subjects using Samsung smartphones over approximately 7–10 days.
  • Gesture Authentication: 0.5% average EER was achieved by GEAT using three gestures and 25 training samples.The authors evaluated GEAT with the EER metric.
  • Multitouch Gesture Authentication: Touch-dynamics validation compared multitouch gestures using feature transformation, pairwise distances, and dissimilarity scores.The study incorporated hand geometry and muscle behavior and used Dynamic Time Warping for gesture distance.

16) Lightweight Touch Dynamics Approach:

Lightweight touch-dynamics and related touchscreen systems reduce processing or model user interaction patterns for continuous validation and intrusion detection. Reported results span classifier selection, error rates, and device resource overhead.

  • Lightweight Touch Dynamics Approach: The lightweight touch-dynamics approach uses eight gestures with varied movements, touch counts, speeds, durations, and pressures.The study involved 50 subjects across 25 sessions on a Nexus One Android phone.
  • Classifier Selection: Classifier selection can vary by user input and experiment, with J48, Naive Bayes, and k-NN selected under different conditions.For one example user, the lowest reported cost value was 1.3221 for Naive Bayes.
  • Lightweight Touch Dynamics Approach: The proposed scheme obtained FRR between 5.87% and 6.65% and FAR between 6.98% and 7.74%.The system was evaluated using FAR and FRR.
  • Multi-Touch Passwords: Multi-touch password authentication evaluated repeated user-selected passwords on an Android Nexus S and achieved an EER of 8%.Ten subjects participated, and each entered a selected password six times.
  • Continuous Touch Validation: Continuous touch validation achieved EER below 10% for all four gesture types, with Slide reaching 0.64%.The approach used separate training and authentication phases with SVM classification.
  • Mobile Intrusion Detection: A hybrid mobile intrusion-detection framework combining host and cloud methods consumed 20–45% CPU and 62–78% memory.It combined SMS profiling, application monitoring, touch logging, and keystroke authentication.

D. Gait Based Authentication

Gait biometrics authenticate users through walking patterns, with smartphone studies concentrating on wearable sensors and cyclic or non-cyclic feature extraction. Evaluations span varied sensors, classifiers, walking conditions, and error metrics.

  • Approach: Smartphone gait authentication concentrates on wearable sensors because machine-vision and floor-sensor approaches are not applicable to smartphones.Wearable devices may be placed at locations including the waist, belt, trouser pockets, or hand, using sensors such as accelerometers and gyroscopes.
  • Feature extraction: Cyclic gait extraction identifies time-series cycles before computing characteristic templates, whereas non-cyclic extraction computes features without prior cycle identification.The non-cyclic method selects walking intervals to capture sensor locations and is described as harder to implement.
  • Hestbek et al.: Hestbek’s study used wearable sensors measuring acceleration in three spatial dimensions and evaluated nine feature sets with SVM classification.The study included 36 participants over sessions averaging 24 days, with normal and fast walking episodes.
  • Hestbek et al.: Haar Transform produced the best accuracy in Hestbek’s experiments after varying interpolation rates, segmentation lengths, and wavelets.Performance was evaluated using False Match Rate, False Non-Match Rate, and Half Total Error Rate.
  • Gafurov et al.: With a backpack, Gafurov’s authentication performance deteriorated from about 7.3% to about 9.3%, while identification recognition declined from 86.3% to 86.2%.The study used accelerometer data from trouser pockets and compared walking with and without a backpack.

3) Extracting Gait Cycle using Piecewise Linear Approximation:

This section reviews gait-cycle extraction and classification methods, including PLA, elastic similarity, fixed-length segmentation, voting, and HMM-based approaches. Reported results vary substantially across walking conditions and evaluation procedures.

  • 3) Extracting Gait Cycle using Piecewise Linear Approximation:: Muaaz and Mayrhofer extracted gait cycles with Piecewise Linear Approximation and classified features using pre-computed data or kernel matrices.The kernel approach used a Gaussian Dynamic Time Warp kernel to construct an elastic similarity measure.
  • 3) Extracting Gait Cycle using Piecewise Linear Approximation:: Muaaz and Mayrhofer evaluated PLA and non-PLA extraction with DTW and GDTW classifiers on data from 51 subjects using Equal Error Rate.The passage reports that results without PLA were slightly higher than those achieved with PLA.
  • Fixed-length segmentation: Nickel’s fixed-segment approach used SVMs and HMMs on phone data collected during normal and fast walking with varied interpolation rates and segment lengths.Segments were 3, 5, or 7.5 seconds with 50% overlap.
  • Fixed-length segmentation: Voting improved HMM EER to 15.77% for normal walking and 14.39% for fast walking, while SVM TER was 20.01% for normal walking.The same passage reports HMM EER of 12.63% under another evaluation condition.

9) Recognition Gait Patterns with Accelerometers:

Accelerometer-based gait recognition studies compare signal representations, sampling strategies, and feature-extraction methods across different walking tasks. Their reported outcomes range from strong recognition results to substantial performance differences between approaches.

  • 9) Recognition Gait Patterns with Accelerometers:: Mantyjarvi et al. compared signal correlation, FFT coefficients, histograms, and higher-order moments for subjects walking at fast, normal, and slow speeds.The study collected accelerometer data from 36 subjects over five days.
  • 9) Recognition Gait Patterns with Accelerometers:: Signal correlation achieved the best reported EER at 7%, followed by FFT coefficients at 10%, higher-order moments at 18%, and histograms at 19%.These values compare the four signal-derived elements within the same study.
  • 9) Recognition Gait Patterns with Accelerometers:: Derawi et al. focused on low-grade acceleration data, unlike studies concentrating on high-grade acceleration.Their method extracted cycles and removed irregular cycles using Dynamic Time Warping before calculating an average cycle.
  • 9) Recognition Gait Patterns with Accelerometers:: Derawi’s approach obtained 20.1% EER compared with 12.9% for Holien’s approach, using 40–50 versus 100 samples per second.The comparison is reported directly in terms of EER and sampling rate.
  • 9) Recognition Gait Patterns with Accelerometers:: Thang et al. reported 79.1% accuracy in the time domain and 92.7% in the frequency domain for accelerometer-based gait recognition.DTW evaluated time-domain similarity, while SVM classified frequency-domain features.

Voice Behavior:

The paper broadens behavioral biometrics beyond gait to voice, signatures, and behavioral profiling, while examining users’ security and privacy concerns. Survey evidence shows that insider access is a significant concern for smartphone users.

  • Voice Behavior:: Voice biometrics identify users through speaking patterns such as accent, inflection, and cultural background, using text-dependent or text-independent features.Text-dependent systems require identical spoken text during enrollment and authentication; text-independent systems do not.
  • Behavioral profiling: Behavioral profiling identifies users through interactions with digital services and applications, including network-based and host-based behavior.Examples include service-provider, Wi-Fi, Bluetooth, application, time, and location patterns.
  • User concerns: Users worry about unauthorized access to applications and private information by both outsiders and insiders, including people familiar with the legitimate user’s behavior.The paper frames user perspectives as necessary for authentication techniques intended for real-world use.
  • User concerns: More than 12% of surveyed users reported unauthorized insider access to smartphone data or applications, and more than 9% reported accessing a smartphone without its owner’s permission.Muslukhov et al. interviewed 22 users and surveyed 724 users.
  • User concerns: The majority of users considered insider risk as critical as threats from outsiders.The study provided empirical evidence that smartphone users regard insider threats as important.
  • User concerns: Chin et al. found greater privacy concern on phones than laptops and recommended user education, stronger security practices, and new application security indicators.These measures were suggested to help users more confidently use mobile applications.

3) Importance of Security Concerns People Have:

The survey examines smartphone continuous authentication through behavioral biometrics, emphasizing evaluation, usability, security, and unresolved research challenges. It also identifies the need to improve accuracy while handling unusual behavior and practical deployment constraints.

  • Continuous authentication using behavioral biometrics is presented as a promising way to improve smartphone security and usability.The survey reviews methods involving handwaving, keystrokes, touchscreen behavior, gait, signatures, voice, and behavioral profiling.
  • Behavioral-biometric studies use features such as timestamps, pressure, finger size, touch location, and gesture type with machine-learning techniques.
  • No single evaluation metric is currently accepted as a standard for comparing behavioral-authentication approaches.The paper notes that proposed systems use a plethora of evaluation metrics.
  • Continuous authentication must balance security and usability because high false-positive rates can repeatedly lock legitimate users out.Repeated validation conflicts with the goal of uninterrupted device use.
  • Systems assuming short-term behavioral consistency must account for abrupt legitimate changes caused by situations such as injury or panic.
  • Accuracy remains an open problem, with proposed improvements including combining multiple touchscreen features and authentication methods.Suggested touchscreen features include single-touch, multitouch, movement, direction, pressure, and touch size.

2) Controlled Environment:

The survey identifies deployment limitations in smartphone behavioral-authentication research, especially laboratory testing, platform concentration, resource use, data availability, and user-behavior coverage. It also discusses application usage and touchscreen behavior as promising continuous-authentication inputs.

  • 2) Controlled Environment:: Most studies collect data under laboratory conditions, which may not reflect authentication performance in realistic mobile contexts.Relevant external variables include using a device while walking, standing, or traveling in a vehicle.
  • 3) Smartphone platform:: Most published methods target Android, while other sensor-equipped platforms such as iOS, Windows Mobile, and Symbian receive less attention.
  • 4) Energy consumption:: Resource consumption is often overlooked even though viable authentication mechanisms should evaluate features, training profiles, computational complexity, CPU, memory, and battery use.
  • 5) Building Corpus:: Machine-learning authentication approaches lack sufficient publicly available data because collecting long-term data from diverse subjects is expensive and raises privacy, policy, and regulatory hurdles.
  • Continuous authentication can combine application usage and touch-based behavior to reduce repeated PIN or pattern entry.The paper links this proposal to widespread app and touchscreen use.
  • The survey compares existing solutions from multiple perspectives and calls for new methods that focus on multiple user characteristics.
  • Application-usage profiling can classify interactions with social, media, and other applications as behavioral-authentication signals.
Loading 1911.04104v1…