IET Biometrics (Mar 2021)

Password policy characteristics and keystroke biometric authentication

  • Simon Parkinson,
  • Saad Khan,
  • Andrew Crampton,
  • Qing Xu,
  • Weizhi Xie,
  • Na Liu,
  • Kyle Dakin

DOI
https://doi.org/10.1049/bme2.12017
Journal volume & issue
Vol. 10, no. 2
pp. 163 – 178

Abstract

Read online

Abstract Behavioural biometrics have the potential to provide an additional or alternative authentication mechanism to those involving a shared secret (i.e. a password). Keystroke timings are the focus of this study, where key press and release timings are acquired whilst monitoring a user typing a known phrase. Many studies exist in keystroke biometrics, but there is an absence of literature aiming to understand the relationship between characteristics of password policies and the potential of keystroke biometrics. Furthermore, benchmark datasets used in keystroke biometric research do not enable useful insights into the relationship between their capability and password policy. Herein, substitutions of uppercase, numeric, special characters, and their combination of passwords derived from English words are considered. Timings for 42 participants for the same 40 passwords are acquired. A matching system using the Manhattan distance measure with seven different feature sets is implemented, culminating in an Equal Error Rate of between 6% and 11% and accuracy values between 89% and 94%, demonstrating comparable accuracy to other threshold‐based systems. Further analysis suggests that the best feature sets are those containing all timings and trigraph press to press. Evidence also suggests that phrases containing fewer characters have greater accuracy, except for those with special character substitutions.

Keywords