Hands-Free one-Time and continuous authentication using glass wearable devices
Dimitrios Damopoulos,Georgios Kambourakis
DOI: https://doi.org/10.1016/j.jisa.2019.02.002
IF: 4.96
2019-06-01
Journal of Information Security and Applications
Abstract:<p>This paper investigates whether glass wearable devices can be used to authenticate end-users, both to grant access (one-time) and to maintain access (continuous), in a hands-free way. We do so by designing and implementing <em>Gauth</em>, a system that enables users to authenticate with a service simply by issuing a voice command, while facing the computer terminal they are going to use to access the service. To achieve this goal, we create a physical communication channel from the terminal to the glass device using machine readable visual codes, say, QR codes, and utilize the device's network adapter to communicate directly with a service. More importantly, we continuously authenticate the user accessing the terminal, exploiting the fact that a user operating a terminal is most likely facing it most of the time. We periodically issue authentication challenges, which are displayed as a QR code on the terminal. This causes the glass device to re-authenticate the user with an appropriate response. We thoroughly evaluate Gauth to determine the technical limits of our approach. We show that even with the relatively low-resolution camera of the Google Glass prototype, QR codes can be consistently processed correctly with an average accuracy of ≈ 88%, and continuous authentication, while strenuous to the battery, is feasible. Finally, we perform a small-scale user study involving students to demonstrate the benefits of our approach. We found that authentication using Gauth takes on average 1.63 s, while using username/password credentials takes 3.85 s and varies greatly depending on the computer-literacy level of the user.</p>
computer science, information systems