CORMORANT: On Implementing Risk-Aware Multi-Modal Biometric Cross-Device Authentication For Android. Hintze, D.; Füller, M.; Scholz, S.; Findling, R. D.; Muaaz, M.; Kapfer, P.; Nüssler, W.; and Mayrhofer, R. In 17th International Conference on Advances in Mobile Computing and Multimedia, 2019.
CORMORANT: On Implementing Risk-Aware Multi-Modal Biometric Cross-Device Authentication For Android [pdf]Paper  abstract   bibtex   
This paper presents the design and open source implementation of CORMORANT , an Android authentication framework able to increase usability and security of mobile authentication. It uses transparent behavioral and physiological biometrics like gait, face, voice, and keystrokes dynamics to continuously evaluate the user’s identity without explicit interaction. Using signals like location, time of day, and nearby devices to assess the risk of unauthorized access, the required level of confidence in the user’s identity is dynamically adjusted. Authentication results are shared securely, end-to-end encrypted using the Signal messaging protocol, with trusted devices to facilitate cross-device authentication for co-located devices, detected using Bluetooth low energy beacons. CORMORANT is able to reduce the authentication overhead by up to 97% compared to conventional knowledge-based authentication whilst increasing security at the same time. We share our perspective on some of the successes and shortcomings we encountered implementing and evaluating CORMORANT to hope to inform others working on similar projects.
@InProceedings{Hintze_19_CORMORANTImplementingRisk,
  author    = {Daniel Hintze and Matthias F\"uller and Sebastian Scholz and Rainhard Dieter Findling and Muhammad Muaaz and Philipp Kapfer and Wilhelm N\"ussler and Ren\'e Mayrhofer},
  booktitle = {17th International Conference on Advances in Mobile Computing and Multimedia},
  title     = {CORMORANT: On Implementing Risk-Aware Multi-Modal Biometric Cross-Device Authentication For Android},
  year      = {2019},
  abstract  = {This paper presents the design and open source implementation of CORMORANT , an Android authentication framework able to increase usability and security of mobile authentication. It uses transparent behavioral and physiological biometrics like gait, face, voice, and keystrokes dynamics to continuously evaluate the user’s identity without explicit interaction. Using signals like location, time of day, and nearby devices to assess the risk of unauthorized access, the required level of confidence in the user’s identity is dynamically adjusted. Authentication results are shared securely, end-to-end encrypted using the Signal messaging protocol, with trusted devices to facilitate cross-device authentication for co-located devices, detected using Bluetooth low energy beacons. CORMORANT is able to reduce the authentication overhead by up to 97\% compared to conventional knowledge-based authentication whilst increasing security at the same time. We share our perspective on some of the successes and shortcomings we encountered implementing and evaluating CORMORANT to hope to inform others working on similar projects.},
  url_Paper = {http://ambientintelligence.aalto.fi/paper/Hintze_19_CORMORANTImplementingRisk_cameraReady.pdf},
group = {ambience}}
Downloads: 0