A Secure Mobile Authentication Alternative to Biometrics

12/07/2017
by   Mozhgan Azimpourkivi, et al.
0

Biometrics are widely used for authentication in consumer devices and business settings as they provide sufficiently strong security, instant verification and convenience for users. However, biometrics are hard to keep secret, stolen biometrics pose lifelong security risks to users as they cannot be reset and re-issued, and transactions authenticated by biometrics across different systems are linkable and traceable back to the individual identity. In addition, their cost-benefit analysis does not include personal implications to users, who are least prepared for the imminent negative outcomes, and are not often given equally convenient alternative authentication options. We introduce ai.lock, a secret image based authentication method for mobile devices which uses an imaging sensor to reliably extract authentication credentials similar to biometrics. Despite lacking the regularities of biometric image features, we show that ai.lock consistently extracts features across authentication attempts from general user captured images, to reconstruct credentials that can match and exceed the security of biometrics (EER = 0.71 security of ai.lock against brute force attacks on more than 3.5 billion authentication instances built from more than 250,000 images of real objects, and 100,000 synthetically generated images using a generative adversarial network trained on object images. We show that the ai.lock Shannon entropy is superior to a fingerprint based authentication built into popular mobile devices.

READ FULL TEXT
research
05/20/2021

Combining PIN and Biometric Identifications as Enhancement to User Authentication in Internet Banking

Internet banking (IB) continues to face security concerns arising from i...
research
11/18/2019

"Please enter your PIN" – On the Risk of Bypass Attacks on Biometric Authentication on Mobile Devices

Nowadays, most mobile devices support biometric authentication schemes l...
research
06/29/2018

SemanticLock: An authentication method for mobile devices using semantically-linked images

We introduce SemanticLock, a single factor graphical authentication solu...
research
06/20/2018

Cross-Domain Deep Face Matching for Real Banking Security Systems

Ensuring the security of transactions is currently one of the major chal...
research
05/18/2017

Continuous Implicit Authentication for Mobile Devices based on Adaptive Neuro-Fuzzy Inference System

As mobile devices have become indispensable in modern life, mobile secur...
research
10/08/2022

Study and security analysis of the Spanish identity card

The National Identity Document is a fundamental piece of documentation f...
research
01/20/2019

Ring Oscillator and its application as Physical Unclonable Function (PUF) for Password Management

Mobile and embedded devices are becoming inevitable parts of our daily r...

Please sign up or login with your details

Forgot password? Click here to reset