Abstract
Modern smartphones expressed an exponential growth and have become a personal assistant in people’s daily lives, i.e., keeping connected with peers. Users are willing to store their personal data even sensitive information on the phones, making these devices an attractive target for cyber-criminals. Due to the limitations of traditional authentication methods like Personal Identification Number (PIN), research has been moved to the design of touch behavioral authentication on smartphones. However, how to design a robust behavioral authentication in a long-term period remains a challenge due to behavioral inconsistency. In this work, we advocate that touch gestures could become more consistent when users interact with specific applications. In this work, we focus on social networking applications and design a touch behavioral authentication scheme called SocialAuth. In the evaluation, we conduct a user study with 50 participants and demonstrate that touch behavioral deviation under our scheme could be significantly decreased and kept relatively stable even after a long-term period, i.e., a single SVM classifier could achieve an average error rate of about 3.1% and 3.7% before and after two weeks, respectively. Copyright © 2019 IFIP International Federation for Information Processing.
Original language | English |
---|---|
Title of host publication | ICT systems security and privacy protection: 34th IFIP TC 11 International Conference, SEC 2019, Lisbon, Portugal, June 25-27, 2019, proceedings |
Editors | Gurpreet DHILLON, Fredrik KARLSSON, Karin HEDSTRÖM, André ZÚQUETE |
Place of Publication | Cham |
Publisher | Springer |
Pages | 180-193 |
ISBN (Electronic) | 9783030223120 |
ISBN (Print) | 9783030223113 |
DOIs | |
Publication status | Published - 2019 |
Citation
Meng, W., Li, W., Jiang, L., & Zhou, J. (2019). SocialAuth: Designing touch behavioral smartphone user authentication based on social networking applications. In G. Dhillon, F. Karlsson, K. Hedström, & A. Zúquete (Eds.), ICT systems security and privacy protection: 34th IFIP TC 11 International Conference, SEC 2019, Lisbon, Portugal, June 25-27, 2019, proceedings (pp. 180-193). Springer. https://doi.org/10.1007/978-3-030-22312-0_13Keywords
- Behavioral user authentication
- Touch gestures
- Usable security
- Smartphone security
- Social networking
- Machine learning