Hier finden Sie wissenschaftliche Publikationen aus den Fraunhofer-Instituten.

User identity verification based on touchscreen interaction analysis in web contexts

: Velten, Michael; Schneider, Peter; Wessel, Sascha; Eckert, Claudia


Lopez, J.:
Information security practice and experience. 11th international conference, ISPEC 2015 : Beijing, China, May 5-8, 2015: Proceedings
Cham: Springer International Publishing, 2015 (Lecture Notes in Computer Science 9065)
ISBN: 978-3-319-17532-4 (Print)
ISBN: 978-3-319-17533-1 (Online)
International Conference on Information Security Practice and Experience (ISPEC) <11, 2015, Beijing>
Fraunhofer AISEC ()

The ever-increasing popularity of smartphones amplifies the risk of loss or theft, thus increasing the threat of attackers hijacking critical user accounts. In this paper, we present a framework to secure accounts by continuously verifying user identities based on user interaction behavior with smartphone touchscreens. This enables us to protect user accounts by disabling critical functionality and enforcing a reauthentication in case of suspicious behavior. We take advantage of standard mobile web browser capabilities to remotely capture and analyze touchscreen interactions. This approach is completely transparent for the user and works on everyday smartphones without requiring any special software or privileges on the user’s device. We show how to successfully classify users even on the basis of limited and imprecise touch interaction data as is prevalent in web contexts. We evaluate the performance of our framework and show that the user identification accuracy is higher than 99% after collecting about a dozen touch interactions.