Conference item
WatchAuth: user authentication and intent recognition in mobile payments using a smartwatch
- Abstract:
- In this paper, we show that the tap gesture, performed when a user ‘taps’ a smartwatch onto an NFC-enabled terminal to make a payment, is a biometric capable of implicitly authenticating the user and simultaneously recognising intent-to-pay. The proposed system can be deployed purely in software on the watch without requiring updates to payment terminals. It is agnostic to terminal type and position and the intent recognition portion does not require any training data from the user. To validate the system, we conduct a user study (n=16) to collect wrist motion data from users as they interact with payment terminals and to collect long-term data from a subset of them (n=9) as they perform daily activities. Based on this data, we identify optimum gesture parameters and develop authentication and intent recognition models, for which we achieve EERs of 0.08 and 0.04, respectively.
- Publication status:
- Published
- Peer review status:
- Peer reviewed
Actions
Access Document
- Files:
-
-
(Preview, Accepted manuscript, 3.2MB, Terms of use)
-
- Publisher copy:
- 10.1109/EuroSP53844.2022.00031
Authors
- Publisher:
- IEEE
- Host title:
- Proceedings of the 7th IEEE European Symposium on Security and Privacy (IEEE 2022)
- Pages:
- 377-391
- Publication date:
- 2022-06-23
- Acceptance date:
- 2022-03-01
- Event title:
- 7th IEEE European Symposium on Security and Privacy (IEEE 2022)
- Event location:
- Genoa
- Event website:
- https://www.ieee-security.org/TC/EuroSP2022/
- Event start date:
- 2022-06-06
- Event end date:
- 2022-06-10
- DOI:
- EISBN:
- 978-1-6654-1614-6
- ISBN:
- 978-1-6654-1615-3
- Language:
-
English
- Keywords:
- Pubs id:
-
1242833
- Local pid:
-
pubs:1242833
- Deposit date:
-
2022-03-09
Terms of use
- Copyright holder:
- Jack Sturgess
- Copyright date:
- 2022
- Rights statement:
- © 2022 Jack Sturgess. Under an IEEE license.
- Notes:
- This paper will be presented at the 7th IEEE European Symposium on Security and Privacy (IEEE 2022), 6th-10th June 2022, Genoa. This is the accepted manuscript version of the article. The final version is available online from IEEE at: https://doi.org/10.1109/EuroSP53844.2022.00031
If you are the owner of this record, you can report an update to it here: Report update to this record