User Authentication via Electrical Muscle Stimulation
Authors
Electrical Muscle Stimulation (EMS)Passwords & Authentication
Document Title
User Authentication via Electrical Muscle Stimulation
Document Information
- Subject Area: Biometrics, User Authentication, Human-Computer Interaction Technology
- Keywords: Electrical Muscle Stimulation (EMS), Biometric Authentication, Wearable Devices, Challenge-Response Mechanism, Secure Authentication
Research Background and Problem
Background
- Biometric authentication verifies user identity through unique biological traits (e.g., iris, fingerprint, or voice), offering convenience without the need to remember passwords.
- However, traditional biometric technologies face security issues, such as database leaks or attacks that render the method unusable; for instance, once fingerprint data is stolen, the user can no longer use it for authentication.
- Challenge-response biometric mechanisms have been studied in recent years as a solution to such security vulnerabilities, such as authentication via vibration or brainwave responses.
Research Problem and Challenges
- How to design and implement an authentication system based on Electrical Muscle Stimulation (EMS) that leverages the unique physiological responses of the human body to electrical signals for user identification.
- Challenges: An EMS-based system must utilize physiological differences to ensure personalization while designing a sufficient number of challenges to prevent replay and spoofing attacks.
Research Motivation
- EMS offers a novel direction by leveraging individual differences among users (e.g., skeletal structure, muscle viscoelasticity, skin conductivity) to provide higher authentication security.
- The challenge-response structure can counteract data and model leaks while maintaining flexibility, allowing rapid recovery of security by altering challenges.
Solution
Method and Innovations
-
Basic Architecture:
- Proposed an interactive authentication system named “ElectricAuth.”
- The system sends a set of electrical stimulation signals (challenges) to the user's forearm muscles and uses IMU (Inertial Measurement Unit) sensors to record the user's involuntary finger movements (responses).
- Models physiological responses based on EMS-induced inter-individual differences as identity markers.
-
Innovations and Process:
- Designed a non-repetitive challenge generation mechanism capable of producing 68 million challenges within 1.2 seconds, significantly enhancing system randomness and security.
- Developed a deep learning-based two-stage authentication model:
- Anomaly Detector: Uses unsupervised methods to detect whether the user response belongs to a legitimate user.
- Challenge Classifier: Verifies whether the current response matches the real-time challenge, protecting the system from replay attacks.
-
Implementation Steps:
- Registration Phase: Records the user's unique muscle responses to multiple random EMS challenges and trains a personalized authentication model.
- Verification Phase: Randomly sends challenges and analyzes user responses in real-time to confirm identity.
- Hardware Configuration: The system includes medical-grade EMS devices, motion capture sensors (IMU), and utilizes deep neural networks for real-time response classification.
Research Outcomes
Specific Results
-
Authentication Accuracy:
- ElectricAuth achieved an authentication accuracy of 99.78% for 6-pulse-length challenges across more than 70,000 test samples.
- The system's False Rejection Rate (FRR) was close to 2%, while the False Acceptance Rate (FAR) was 0.17% under a 5% FRR condition.
-
Security Evaluation:
- Impersonation Attacks: The system demonstrated a success rate of only 0.17% against attacks from 12 impersonators during testing.
- Replay Attacks: The system exhibited high resistance to both "record-replay" and "database-leak-replay" attacks (FAR = 0).
- Synthetic Attacks: Even under extreme conditions using online synthetic response simulation attacks, the FAR remained very low (<0.2%).
-
Stability:
- A longitudinal study over 24 days showed the model's robustness to time, humidity, and muscle fatigue conditions, with an average FRR of 2.01% and no significant performance degradation.
-
Technical Feasibility:
- Real-time authentication delay was only 3ms (on a laptop CPU) or 35ms (on embedded devices).
- Tests using depth cameras instead of IMUs achieved a challenge verification accuracy of 99.57%.
Advantages Compared to Existing Solutions
- Enhanced Security: ElectricAuth effectively counters data leaks and replay attacks through the challenge-response mechanism.
- Unique Response Patterns: EMS-induced physiological responses are non-replicable, significantly increasing impersonation failure rates.
- Efficiency: The ability to traverse a vast challenge set accelerates the user registration and authentication process.
- Versatile Application Scenarios: The system has potential for integration into VR/AR or smart wearable devices, suitable for hands-free operation contexts.
Limitations and Future Directions
-
Physical Requirements:
- Initialization requires adjusting electrode positions, improving durability, and periodic maintenance of conductive gel.
- Users must keep both hands free during authentication, making it unsuitable for certain scenarios.
-
Time Consumption:
- Although individual stimulation pulses last only 200µs, complete authentication takes 1.3 seconds, slightly slower than fingerprint recognition.
-
Future Directions:
- Investigate the robustness of EMS over larger challenge sets and longer durations.
- Enhance understanding of physiological mechanisms underlying EMS differences, expanding to more complex postures.
- Optimize performance using advanced EMS hardware (e.g., high-resolution electrode arrays or implantable devices).
Application Scenarios and Outlook
- Applicable in device interactions without the need to remember passwords (e.g., VR, smartwatches, medical devices).
- Suitable for high-security scenarios, especially for assisting individuals with cognitive or motor impairments (e.g., authentication for users with spinal cord injuries).
Research Questions / Practical Problems
Question signals indexed for this paper.
help
Research Questions
3- How can a biometric authentication system based on electrical stimulation leverage the human body's unique physiological responses to electrical stimulation?Category: Biometric Identification, Authentication, and PrivacySimilar questionsarrow_forward
- How can sufficient challenges be generated to ensure replay and spoof resistance in electrical-stimulation authentication systems?Category: Biometric Identification, Authentication, and PrivacySimilar questionsarrow_forward
- How stable are electrical-stimulation biometric authentication systems across diverse environments and time conditions?Category: Biometric Identification, Authentication, and PrivacySimilar questionsarrow_forward
lightbulb
Practical Problems
1- Users' biometric authentication is vulnerable to database leaks and replay attacks.Category: Biometric Identification, Authentication, and PrivacySimilar questionsarrow_forward
No related papers with ≥60% similarity
Based on Jaccard similarity of research subtopics & professions (≥60%)
Quick Actions
AdRecommended
Learn AI Coding at CodeNow
open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3411764.3445441
At a Glance
fact_checkPaper Snapshot
dataset
Source
CHI
calendar_month
Year
2021
emoji_events
Award
No award tagged
group
Authors
6 authors
sell
Subtopics
Electrical Muscle Stimulation (EMS), Passwords & Authentication
work
Professions
—
article
Content Status
Full text indexed
hub
Related Papers
0 related papers