论文标题
BiotouchPass:触摸屏生物识别技术的手写密码
BioTouchPass: Handwritten Passwords for Touchscreen Biometrics
论文作者
论文摘要
这项工作通过将生物特征识别信息纳入第二级用户身份验证来增强传统的身份验证系统(PIN)和一次性密码(PIN)和一次性密码(OTP)。在我们建议的方法中,用户在设备的触摸屏上绘制密码的每个数字,而不是像往常一样键入它们。在增加密码长度和注册样本数量时,对我们提出的生物识别系统进行了完整的分析。新的E-Biodigit数据库包括在线手写数字从0到9,已被用手指作为移动设备上的输入获取。该数据库用于此工作中报告的实验中,它与GitHub中的基准结果一起使用。最后,我们讨论了在当前PIN和OTP系统上部署我们提出的方法的具体细节,并以同样的错误率(EERS)来实现结果。当攻击者知道密码时,为4.0%。与传统的PIN和OTP系统相比,这些结果鼓励我们采用我们提出的方法,在同一冒名顶替方案下,攻击将获得100%的成功率。
This work enhances traditional authentication systems based on Personal Identification Numbers (PIN) and One-Time Passwords (OTP) through the incorporation of biometric information as a second level of user authentication. In our proposed approach, users draw each digit of the password on the touchscreen of the device instead of typing them as usual. A complete analysis of our proposed biometric system is carried out regarding the discriminative power of each handwritten digit and the robustness when increasing the length of the password and the number of enrolment samples. The new e-BioDigit database, which comprises on-line handwritten digits from 0 to 9, has been acquired using the finger as input on a mobile device. This database is used in the experiments reported in this work and it is available together with benchmark results in GitHub. Finally, we discuss specific details for the deployment of our proposed approach on current PIN and OTP systems, achieving results with Equal Error Rates (EERs) ca. 4.0% when the attacker knows the password. These results encourage the deployment of our proposed approach in comparison to traditional PIN and OTP systems where the attack would have 100% success rate under the same impostor scenario.