Advancing Smartphone Sensor-Based Keystroke Dynamics for Implicit and Active Authentication: Addressing Challenges and Enhancing Usability Control
摘要
Smartphone sensors play a pivotal role in delineating user behaviour, particularly in the context of keystroke dynamics-based implicit and active/continuous authentication, as well as liveness detection. The acquisition of multifaceted sensory data during typing serves as a fundamental source of behavioural attributes, yet the field faces several intricate challenges requiring careful consideration to recalibrate the delicate balance between security and usability. Notable challenges encompass the capricious nature of anomaly detectors when confronted with unavoidable influencing factors, the substantial battery drainage associated with prolonged sensor operation, the computational inefficiency intrinsic to smartphones, and the imperative need for usability control in frequently switching applications and balancing security in both device and application levels, especially in scenarios with varying security requirements. This study endeavours to mitigate these challenges through the implementation of cutting-edge anomaly detection techniques, incorporating four distinct schemes—namely, column medians template formation, synthetic samples, soft biometrics and score-level fusion. The study further leverages advanced sensory patterns, including gyroscope, accelerometer and rotational information, captured during abbreviated typing intervals at a low sampling rate to mitigate battery consumption. In the pursuit of enhanced usability control, a Watchman score is assigned to each running application, dictating security adjustments based on genuineness evaluations of micro-behaviours within predefined temporal windows. A novel rule-based mechanism is introduced to govern device and application security within a continuous authentication mode. This empirical investigation, supported by robust statistical evidence, aspires to yield more precise, energy-efficient, and user-friendly implicit and active user identity verification mechanisms. The findings present an avenue for future exploration and formulation of smartphone user identity verification issues based on the established methodologies and research facets elucidated in this study.