Authentication Beyond Passwords

A strong password contains capital and lowercase letters, numbers and some special characters. Done properly, the result is a password that grants access to computer systems to the proper user. The only problem is the password is hard to remember, and it’s not supposed to be written on yellow sticky notes that can sometimes be found on the bottom of keyboards. And don’t get comfortable with this long password; it has to be changed every 90 days or so.

With DARPA’s new Active Authentication program, program manager Richard Guidorizzi would like to change that. Instead of current authentication systems that force humans to adapt to computers, Guidorizzi wants to make computers adapt to the humans that built them in the first place. He wants researchers who will work in the Active Authentication program to investigate innovative software approaches that determine a computer user’s identity through activities a user normally performs.

This changes how things are currently done by removing the secret a human holds, a cumbersome and hard to remember password, and focuses on making the user the actual password. Guidorizzi puts it a different way.

“My house key will get you into my house, but the dog in my living room knows you’re not me. No amount of holding up my key and saying you’re me is going to convince my dog you’re who you say you are.  My dog knows you don’t look like me, smell like me or act like me. What we want out of this program is to find those things that are unique to you, and not some single aspect of computer security that an adversary can use to compromise your system,” Guidorizzi said.

While these identifying aspects of a person are what we hope to use to grant levels of access to computer systems as appropriate, Active Authentication seeks to make you the key to your access, not to track aspects of who you are. Guidorizzi expects researchers to take special care to ensure this program doesn’t violate privacy laws or allow information about a user’s identity to be misused by others.  He doesn’t want to capture user aspects in a database; he only wants to use this information as the key to user access of their computer systems.

Examples of existing research include work with fingerprints, although deployment of sensors makes this more challenging so this program focuses more on software-based solutions. Mouse tracking has received attention as a tool that can validate a person’s identify while sitting at a computer, suggesting this as a possible candidate for further research. In addition, forensic authorship is a field where people are able to identify an author by language usage.

Guidorizzi hosts Active Authentication’s performers day Nov. 18. Those interested in attending can find additional information here.

Featured

  • UL Solutions Launches Artificial Intelligence Safety Certification Services

    UL Solutions Inc., a global leader in safety science, today announced the launch of artificial intelligence (AI) safety certification services, enabling comprehensive assessments for evaluating the safety of AI-powered products. Read Now

  • ESA Announces Initiative to Introduce the SECURE Act in State Legislatures

    The Electronic Security Association (ESA), the national voice for the electronic security and life safety industry, has announced plans to introduce the SECURE Act in state legislatures across the country beginning in 2025. The proposal, known as Safeguarding Election Candidates Using Reasonable Expenditures, provides a clear framework that allows candidates and elected officials to use campaign funds for professional security services. Read Now

    • Guard Services
  • Ransomware Attacks Rise for the First Time in Six Months

    Ransomware attacks have risen for the first time in six months, increasing by 28% month-on-month to 421 attacks. While overall attack volume remained below 500, the uptick may signal a renewed escalation heading into the year’s most active period for cyber criminals. Read Now

  • Report: 47 Percent of Security Service Providers Are Not Yet Using AI or Automation Tools

    Trackforce, a provider of security workforce management platforms, today announced the launch of its 2025 Physical Security Operations Benchmark Report, an industry-first study that benchmarks both private security service providers and corporate security teams side by side. Based on a survey of over 300 security professionals across the globe, the report provides a comprehensive look at the state of physical security operations. Read Now

    • Guard Services
  • Identity Governance at the Crossroads of Complexity and Scale

    Modern enterprises are grappling with an increasing number of identities, both human and machine, across an ever-growing number of systems. They must also deal with increased operational demands, including faster onboarding, more scalable models, and tighter security enforcement. Navigating these ever-growing challenges with speed and accuracy requires a new approach to identity governance that is built for the future enterprise. Read Now

New Products

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.