The impact of application context on privacy and performance of keystroke authentication systems.

Saved in:
Bibliographic Details
Title: The impact of application context on privacy and performance of keystroke authentication systems.
Authors: Balagani, Kiran S.1 kbalagan@nyit.edu, Gasti, Paolo1 pgasti@nyit.edu, Elliott, Aaron2 aaron@aegisresearchlabs.com, Richardson, Azriel3 azriel_richardson@yahoo.com, O’Neal, Mike3
Source: Journal of Computer Security. 2018, Vol. 26 Issue 4, p543-556. 14p.
Subjects: Keystroke timing authentication, Computer access control, Algorithms, Privacy, Biometric identification
Abstract: In this paper, we show that keystroke latencies used in continuous user authentication systems disclose application context, i.e., in which application user is entering text. Using keystroke data collected from 62 subjects, we show that an adversary can infer application context from keystroke latencies with 95.15% accuracy. To prevent leakage from keystroke latencies, and prevent exposure of application context, we develop privacy-preserving authentication protocols in the outsourced authentication model. Our protocols implement two popular matching algorithms designed for keystroke authentication, called Absolute (“A”) and Relative (“R”). With our protocols, the client reveals no information to the server during authentication, besides the authentication result. Our experiments show that these protocols are fast in practice: with 100 keystroke features, authentication was completed in about one second with the “A” protocol, and in 595 ms with the “R” protocol. Further, because the asymptotic cost of our protocols is linear, they can scale to a large number of features. On the other hand, by leveraging application context we were able to reduce HTER from 14.7% with application-agnostic templates, to as low as 5.8% with application-specific templates. [ABSTRACT FROM AUTHOR]
Copyright of Journal of Computer Security is the property of Sage Publications Inc. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
Full text is not displayed to guests.
FullText Links:
  – Type: pdflink
Text:
  Availability: 1
Header DbId: egs
DbLabel: Engineering Source
An: 130599555
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: The impact of application context on privacy and performance of keystroke authentication systems.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Balagani%2C+Kiran+S%2E%22">Balagani, Kiran S.</searchLink><relatesTo>1</relatesTo><i> kbalagan@nyit.edu</i><br /><searchLink fieldCode="AR" term="%22Gasti%2C+Paolo%22">Gasti, Paolo</searchLink><relatesTo>1</relatesTo><i> pgasti@nyit.edu</i><br /><searchLink fieldCode="AR" term="%22Elliott%2C+Aaron%22">Elliott, Aaron</searchLink><relatesTo>2</relatesTo><i> aaron@aegisresearchlabs.com</i><br /><searchLink fieldCode="AR" term="%22Richardson%2C+Azriel%22">Richardson, Azriel</searchLink><relatesTo>3</relatesTo><i> azriel_richardson@yahoo.com</i><br /><searchLink fieldCode="AR" term="%22O’Neal%2C+Mike%22">O’Neal, Mike</searchLink><relatesTo>3</relatesTo>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Journal+of+Computer+Security%22">Journal of Computer Security</searchLink>. 2018, Vol. 26 Issue 4, p543-556. 14p.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Keystroke+timing+authentication%22">Keystroke timing authentication</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+access+control%22">Computer access control</searchLink><br /><searchLink fieldCode="DE" term="%22Algorithms%22">Algorithms</searchLink><br /><searchLink fieldCode="DE" term="%22Privacy%22">Privacy</searchLink><br /><searchLink fieldCode="DE" term="%22Biometric+identification%22">Biometric identification</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: In this paper, we show that keystroke latencies used in continuous user authentication systems disclose application context, i.e., in which application user is entering text. Using keystroke data collected from 62 subjects, we show that an adversary can infer application context from keystroke latencies with 95.15% accuracy. To prevent leakage from keystroke latencies, and prevent exposure of application context, we develop privacy-preserving authentication protocols in the outsourced authentication model. Our protocols implement two popular matching algorithms designed for keystroke authentication, called Absolute (“A”) and Relative (“R”). With our protocols, the client reveals no information to the server during authentication, besides the authentication result. Our experiments show that these protocols are fast in practice: with 100 keystroke features, authentication was completed in about one second with the “A” protocol, and in 595 ms with the “R” protocol. Further, because the asymptotic cost of our protocols is linear, they can scale to a large number of features. On the other hand, by leveraging application context we were able to reduce HTER from 14.7% with application-agnostic templates, to as low as 5.8% with application-specific templates. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Journal of Computer Security is the property of Sage Publications Inc. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=130599555
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.3233/JCS-171017
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 14
        StartPage: 543
    Subjects:
      – SubjectFull: Keystroke timing authentication
        Type: general
      – SubjectFull: Computer access control
        Type: general
      – SubjectFull: Algorithms
        Type: general
      – SubjectFull: Privacy
        Type: general
      – SubjectFull: Biometric identification
        Type: general
    Titles:
      – TitleFull: The impact of application context on privacy and performance of keystroke authentication systems.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Balagani, Kiran S.
      – PersonEntity:
          Name:
            NameFull: Gasti, Paolo
      – PersonEntity:
          Name:
            NameFull: Elliott, Aaron
      – PersonEntity:
          Name:
            NameFull: Richardson, Azriel
      – PersonEntity:
          Name:
            NameFull: O’Neal, Mike
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 07
              Text: 2018
              Type: published
              Y: 2018
          Identifiers:
            – Type: issn-print
              Value: 0926227X
          Numbering:
            – Type: volume
              Value: 26
            – Type: issue
              Value: 4
          Titles:
            – TitleFull: Journal of Computer Security
              Type: main
ResultId 1