Keystroke-based authentication by key press intervals as a complementary behavioral biometric
Shallen Giroux, Renata Wachowiak-Smolíková, Mark P. Wachowiak
Abstract
Shallen Giroux, Renata Wachowiak-Smolíková, Mark P. Wachowiak
Abstract
Analysis of keystroke dynamics can be useful in protecting personal data because an individual is authenticated not only by password, but also by that individual's keystroke patterns. In this way, intrusion becomes more difficult because the username/password pair, as well as the typing speed and correct keystroke pattern must both be duplicated. The purpose of this paper is to present a keystroke analysis tool that can be incorporated into distributed systems and web-based services. This study also assesses the potential of keystroke analysis as a complementary authentication mechanism. Eleven individuals entered a password into specially developed keystroke analysis software twenty times over a course of four sessions. The data were statistically analyzed to determine keystroke patterns. Tests were performed to verify whether the users could be properly authenticated. Results show that authentication with mean key press timings resulted in very good false acceptance rates, while allowing access to appropriate users.
OpenAlex reports 21 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Analysis of keystroke dynamics can be useful in protecting personal data because an individual is authenticated not only by password, but also by that individual's keystroke patterns. In this way, intrusion becomes more difficult because the username/password pair, as well as the typing speed and correct keystroke pattern must both be duplicated. The purpose of this paper is to present a keystroke analysis tool that can be incorporated into distributed systems and web-based services. This study also assesses the potential of keystroke analysis as a complementary authentication mechanism. Eleven individuals entered a password into specially developed keystroke analysis software twenty times over a course of four sessions. The data were statistically analyzed to determine keystroke patterns. Tests were performed to verify whether the users could be properly authenticated. Results show that authentication with mean key press timings resulted in very good false acceptance rates, while allowing access to appropriate users.
Key concepts: Keystroke dynamics, Keystroke logging, Password, Computer science, Biometrics, Authentication (law), Computer security, Key (lock)