User-Habit-Oriented Authentication Model: Toward Secure, User-Friendly Authentication for Mobile Devices

被引:17
|
作者
Seto, Jamie [1 ]
Wang, Ye [1 ]
Lin, Xiaodong [1 ]
机构
[1] Univ Ontario, Fac Business & Informat Technol, Inst Technol, Oshawa, ON L1H 7K4, Canada
基金
加拿大自然科学与工程研究理事会;
关键词
Authentication; habit-oriented; mobile; theory of mind; security; usability;
D O I
10.1109/TETC.2014.2379991
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Mobile device security has become increasingly important as we become more dependent on mobile devices. One fundamental security problem is user authentication, and if not executed correctly, leaves the mobile user vulnerable to harm like impersonation and unauthorized access. Although many user authentication mechanisms have been presented in the past, studies have shown mobile users preferring usability over security. Furthermore, mobile users often unlock their devices in public spaces, inevitably resulting in a high possibility of user credentials disclosure. Motivated by the above, we introduce a novel user-habit-oriented authentication model, where mobile users can integrate their own habits (or hobbies) with user authentication on mobile devices. The user-habit-oriented authentication turns a tedious security action into an enjoyable experience. In addition, we propose a rhythm-based authentication scheme, providing the first proof of concept toward secure user-habit-oriented authentication for mobile devices. The proposed scheme also takes the first step toward using the theory of mind into security field. Experimental results show that the proposed scheme has high accuracy in terms of false rejection rate. In addition, the proposed scheme is able to protect from attacks caused by credential disclosure, which could be fatal if it was done through the traditional schemes.
引用
收藏
页码:107 / 118
页数:12
相关论文
共 50 条
  • [21] Flexible and Transparent User Authentication for Mobile Devices
    Clarke, Nathan
    Karatzouni, Sevasti
    Furnell, Steven
    [J]. EMERGING CHALLENGES FOR SECURITY, PRIVACY AND TRUST: 24TH IFIP TC 11 INTERNATIONAL INFORMATION SECURITY CONFERENCE, SEC 2009, PROCEEDINGS, 2009, 297 : 1 - 12
  • [22] LEARNING ON A BUDGET FOR USER AUTHENTICATION ON MOBILE DEVICES
    Kolosnjaji, Bojan
    Huefner, Antonia
    Eckert, Claudia
    Zarras, Apostolis
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2018, : 2042 - 2046
  • [23] Fingerprint-based user-friendly interface and pocket-PID for mobile authentication
    Uchida, K
    [J]. 15TH INTERNATIONAL CONFERENCE ON PATTERN RECOGNITION, VOL 4, PROCEEDINGS: APPLICATIONS, ROBOTICS SYSTEMS AND ARCHITECTURES, 2000, : 205 - 209
  • [24] The Authentication Game - Secure User Authentication by Gamification?
    Ebbers, Frank
    Brune, Philipp
    [J]. ADVANCED INFORMATION SYSTEMS ENGINEERING (CAISE 2016), 2016, 9694 : 101 - 115
  • [25] Design and Analysis of a Highly User-Friendly, Secure, Privacy-Preserving, and Revocable Authentication Method
    Sui, Yan
    Zou, Xukai
    Du, Eliza Y.
    Li, Feng
    [J]. IEEE TRANSACTIONS ON COMPUTERS, 2014, 63 (04) : 902 - 916
  • [26] Security analysis and improvement of a user-friendly remote authentication protocol
    Wang, YJ
    Li, JH
    Tie, L
    [J]. APPLIED MATHEMATICS AND COMPUTATION, 2005, 168 (01) : 47 - 50
  • [27] An anonymous and provably secure authentication scheme for mobile user
    Islam, S. K. Hafizul
    Obaidat, Mohammad S.
    Amin, Ruhul
    [J]. INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2016, 29 (09) : 1529 - 1544
  • [28] A Secure User Authentication Protocol for Heterogeneous Mobile Environments
    Hassan, Alzubair
    Hamza, Rafik
    Li, Fagen
    Ali, Awad
    Bashir, Mohammed Bakri
    Alqhtani, Samar M.
    Tawfeeg, Tawfeeg Mohmmed
    Yousif, Adil
    [J]. IEEE ACCESS, 2022, 10 : 69757 - 69770
  • [29] Toward a Secure and Usable User Authentication Mechanism for Mobile Passenger ID Devices for Land/Sea Border Control
    Papaioannou, Maria
    Zachos, Georgios
    Essop, Ismael
    Mantas, Georgios
    Rodriguez, Jonathan
    [J]. IEEE ACCESS, 2022, 10 : 38832 - 38849
  • [30] Risk Estimation for a Secure & Usable User Authentication Mechanism for Mobile Passenger ID Devices
    Papaioannou, Maria
    Mantas, Georgios
    Essop, Aliyah
    Sucasas, Victor
    Aaraj, Najwa
    Rodriguez, Jonathan
    [J]. 2022 IEEE 27TH INTERNATIONAL WORKSHOP ON COMPUTER AIDED MODELING AND DESIGN OF COMMUNICATION LINKS AND NETWORKS (CAMAD), 2022, : 173 - 178