2017Memorial University Research Repository (Memorial University)Open access

Continuous authentication and its application in personal health record systems

Navid Shekoufa

Open full text 1 citations

Abstract

Authenticating users in commercial smartphones is currently a naive process putting the smartphone owner in security risks in events such as unauthorized device sharing, device loss or theft, and session hijacking. With the recent interest of gov- ernmental and health organizations to provide their users with applications that can be run on their smartphones, securing these devices with measures above the cur- rent solutions is imperative. In this research, we propose a continuous authentication module for a Personal Health Record system that monitors its users for authenticity over time via their touch biometrics and denies access to those who can not satisfy authentication criteria. The proposed solution can be used in any smartphone application that is highly sensitive in terms of privacy and security which needs continuous authentication while running. We will also propose a notification module that helps to build transparency for the user about how their shared personal information is used in the system, so they will be more willing to trust our application. The proposed continuous authentication was implemented in an actual Personal Health Record system for Android enabled smartphones to make it more secure and practical to use. The results show an average precision of above 95% in detecting whether a user is the legit owner of a smartphone or not. Finally, we composed an open-source dataset for touch biometrics and made it available to the public. This is the first publicly available dataset related to touch biometrics.

Open-access reader

About this research paper

What this paper is about

Authenticating users in commercial smartphones is currently a naive process putting the smartphone owner in security risks in events such as unauthorized device sharing, device loss or theft, and session hijacking. With the recent interest of gov- ernmental and health organizations to provide their users with applications that can be run on their smartphones, securing these devices with measures above the cur- rent solutions is imperative. In this research, we propose a continuous authentication module for a Personal Health Record system that monitors its users for authenticity over time via their touch biometrics and denies access to those who can not satisfy authentication criteria. The proposed solution can be used in any smartphone application that is highly sensitive in terms of privacy and security which needs continuous authentication while running. We will also propose a notification module that helps to build transparency for the user about how their shared personal information is used in the system, so they will be more willing to trust our application. The proposed continuous authentication was implemented in an actual Personal Health Record system for Android enabled smartphones to make it more secure and practical to use. The results show an average precision of above 95% in detecting whether a user is the legit owner of a smartphone or not. Finally, we composed an open-source dataset for touch biometrics and made it available to the public. This is the first publicly available dataset related to touch biometrics.

Why it matters

OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Authenticating users in commercial smartphones is currently a naive process putting the smartphone owner in security risks in events such as unauthorized device sharing, device loss or theft, and session hijacking. With the recent interest of gov- ernmental and health organizations to provide their users with applications that can be run on their smartphones, securing these devices with measures above the cur- rent solutions is imperative. In this research, we propose a continuous authentication module for a Personal Health Record system that monitors its users for authenticity over time via their touch biometrics and denies access to those who can not satisfy authentication criteria. The proposed solution can be used in any smartphone application that is highly sensitive in terms of privacy and security which needs continuous authentication while running. We will also propose a notification module that helps to build transparency for the user about how their shared personal information is used in the system, so they will be more willing to trust our application. The proposed continuous authentication was implemented in an actual Personal Health Record system for Android enabled smartphones to make it more secure and practical to use. The results show an average precision of above 95% in detecting whether a user is the legit owner of a smartphone or not. Finally, we composed an open-source dataset for touch biometrics and made it available to the public. This is the first publicly available dataset related to touch biometrics.

Key concepts: Biometrics, Android (operating system), Computer security, Computer science, Authentication (law), Transparency (behavior), Internet privacy, Session (web analytics)

Related papers

Back to paper searchBrowse research topicsOriginal source
Continuous authentication and its application in personal health record systems — Research Paper | ScholarLens