Authentication Beyond Passwords

A strong password contains capital and lowercase letters, numbers and some special characters. Done properly, the result is a password that grants access to computer systems to the proper user. The only problem is the password is hard to remember, and it’s not supposed to be written on yellow sticky notes that can sometimes be found on the bottom of keyboards. And don’t get comfortable with this long password; it has to be changed every 90 days or so.

With DARPA’s new Active Authentication program, program manager Richard Guidorizzi would like to change that. Instead of current authentication systems that force humans to adapt to computers, Guidorizzi wants to make computers adapt to the humans that built them in the first place. He wants researchers who will work in the Active Authentication program to investigate innovative software approaches that determine a computer user’s identity through activities a user normally performs.

This changes how things are currently done by removing the secret a human holds, a cumbersome and hard to remember password, and focuses on making the user the actual password. Guidorizzi puts it a different way.

“My house key will get you into my house, but the dog in my living room knows you’re not me. No amount of holding up my key and saying you’re me is going to convince my dog you’re who you say you are.  My dog knows you don’t look like me, smell like me or act like me. What we want out of this program is to find those things that are unique to you, and not some single aspect of computer security that an adversary can use to compromise your system,” Guidorizzi said.

While these identifying aspects of a person are what we hope to use to grant levels of access to computer systems as appropriate, Active Authentication seeks to make you the key to your access, not to track aspects of who you are. Guidorizzi expects researchers to take special care to ensure this program doesn’t violate privacy laws or allow information about a user’s identity to be misused by others.  He doesn’t want to capture user aspects in a database; he only wants to use this information as the key to user access of their computer systems.

Examples of existing research include work with fingerprints, although deployment of sensors makes this more challenging so this program focuses more on software-based solutions. Mouse tracking has received attention as a tool that can validate a person’s identify while sitting at a computer, suggesting this as a possible candidate for further research. In addition, forensic authorship is a field where people are able to identify an author by language usage.

Guidorizzi hosts Active Authentication’s performers day Nov. 18. Those interested in attending can find additional information here.

Featured

  • TSA Introduces New $45 Fee Option for Travelers Without REAL ID Starting February 1

    The Transportation Security Administration (TSA) announced today that it will refer all passengers who do not present an acceptable form of ID and still want to fly an option to pay a $45 fee to use a modernized alternative identity verification system, TSA Confirm.ID, to establish identity at security checkpoints beginning on February 1, 2026. Read Now

  • The Evolution of IP Camera Intelligence

    As the 30th anniversary of the IP camera approaches in 2026, it is worth reflecting on how far we have come. The first network camera, launched in 1996, delivered one frame every 17 seconds—not impressive by today’s standards, but groundbreaking at the time. It did something that no analog system could: transmit video over a standard IP network. Read Now

  • From Surveillance to Intelligence

    Years ago, it would have been significantly more expensive to run an analytic like that — requiring a custom-built solution with burdensome infrastructure demands — but modern edge devices have made it accessible to everyone. It also saves time, which is a critical factor if a missing child is involved. Video compression technology has played a critical role as well. Over the years, significant advancements have been made in video coding standards — including H.263, MPEG formats, and H.264—alongside compression optimization technologies developed by IP video manufacturers to improve efficiency without sacrificing quality. The open-source AV1 codec developed by the Alliance for Open Media—a consortium including Google, Netflix, Microsoft, Amazon and others — is already the preferred decoder for cloud-based applications, and is quickly becoming the standard for video compression of all types. Read Now

  • Cost: Reactive vs. Proactive Security

    Security breaches often happen despite the availability of tools to prevent them. To combat this problem, the industry is shifting from reactive correction to proactive protection. This article will examine why so many security leaders have realized they must “lead before the breach” – not after. Read Now

  • Achieving Clear Audio

    In today’s ever-changing world of security and risk management, effective communication via an intercom and door entry communication system is a critical communication tool to keep a facility’s staff, visitors and vendors safe. Read Now

New Products

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities