Norwegian Computing Center, 0373 Oslo, Norway.
Department of Information Security and Communication Technology, Norwegian University of Science and Technology, 2815 Gjøvik, Norway.
Sensors (Basel). 2021 Sep 6;21(17):5967. doi: 10.3390/s21175967.
Continuous authentication has been proposed as a possible approach for passive and seamless user authentication, using sensor data comprising biometric, behavioral, and context-oriented characteristics. Since these are personal data being transmitted and are outside the control of the user, this approach causes privacy issues. Continuous authentication has security challenges concerning poor matching rates and susceptibility of replay attacks. The security issues are mainly poor matching rates and the problems of replay attacks. In this survey, we present an overview of continuous authentication and comprehensively discusses its different modes, and issues that these modes have related to security, privacy, and usability. A comparison of privacy-preserving approaches dealing with the privacy issues is provided, and lastly recommendations for secure, privacy-preserving, and user-friendly continuous authentication.
连续身份验证被提议作为一种可能的方法,用于被动和无缝的用户身份验证,使用包括生物识别、行为和面向上下文的特征的传感器数据。由于这些是传输的个人数据并且超出用户的控制范围,因此这种方法会引发隐私问题。连续身份验证在匹配率低和易受重播攻击方面存在安全挑战。安全问题主要是匹配率低和重播攻击的问题。在本调查中,我们对连续身份验证进行了概述,并全面讨论了其不同模式,以及这些模式在安全性、隐私性和可用性方面存在的问题。提供了一种针对隐私问题的隐私保护方法的比较,并最终提出了安全、隐私保护和用户友好的连续身份验证的建议。