Multi-sensor authentication to improve smartphone security

Wei Han Lee, Ruby B. Lee

Research output: Chapter in Book/Report/Conference proceedingConference contribution

90 Scopus citations

Abstract

The widespread use of smartphones gives rise to new security and privacy concerns. Smartphone thefts account for the largest percentage of thefts in recent crime statistics. Using a victim's smartphone, the attacker can launch impersonation attacks, which threaten the security of the victim and other users in the network. Our threat model includes the attacker taking over the phone after the user has logged on with his password or pin. Our goal is to design a mechanism for smartphones to better authenticate the current user, continuously and implicitly, and raise alerts when necessary. In this paper, we propose a multi-sensors-based system to achieve continuous and implicit authentication for smartphone users. The system continuously learns the owner's behavior patterns and environment characteristics, and then authenticates the current user without interrupting user-smartphone interactions. Our method can adaptively update a user's model considering the temporal change of user's patterns. Experimental results show that our method is efficient, requiring less than 10 seconds to train the model and 20 seconds to detect the abnormal user, while achieving high accuracy (more than 90%). Also the combination of more sensors provide better accuracy. Furthermore, our method enables adjusting the security level by changing the sampling rate.

Original languageEnglish (US)
Title of host publicationICISSP 2015 - 1st International Conference on Information Systems Security and Privacy, Proceedings
EditorsOlivier Camp, Edgar Weippl, Christophe Bidan, Esma Aimeur
PublisherSciTePress
Pages270-280
Number of pages11
ISBN (Electronic)9789897580819
DOIs
StatePublished - 2015
Event1st International Conference on Information Systems Security and Privacy, ICISSP 2015 - Angers, Loire Valley, France
Duration: Feb 9 2015Feb 11 2015

Publication series

NameICISSP 2015 - 1st International Conference on Information Systems Security and Privacy, Proceedings

Other

Other1st International Conference on Information Systems Security and Privacy, ICISSP 2015
Country/TerritoryFrance
CityAngers, Loire Valley
Period2/9/152/11/15

All Science Journal Classification (ASJC) codes

  • Safety, Risk, Reliability and Quality
  • Computer Networks and Communications
  • Computer Science Applications
  • Information Systems

Keywords

  • Accelerometer
  • Android
  • Authentication
  • Magnetometer
  • Orientation sensor
  • Security
  • Sensors
  • Smartphone
  • Support vector machines

Fingerprint

Dive into the research topics of 'Multi-sensor authentication to improve smartphone security'. Together they form a unique fingerprint.

Cite this