CONTINUOUS BIOMETRIC USER AUTHENTICATION MODELS FOR ENHANCING THE SECURITY OF INFORMATION SYSTEMS
DOI:
https://doi.org/10.28925/2663-4023.2026.34.1306Keywords:
authentication, authentication methods, biometric authentication, wearable devices, multimodal analysis, adaptive cybersecurityAbstract
This paper addresses the problem of enhancing the security of user authentication in information systems based on biometric data acquired from wearable devices. The paper substantiates the expediency of transitioning from one-time (static) identity verification to continuous authentication, in which the legitimacy of the user is confirmed throughout the entire working session. It is shown that one-time identity verification is limited, since after a successful login the open session remains vulnerable to interception and unauthorized use. Fingerprint, heart rate, heart rate variability, blood oxygen saturation, and skin temperature — all available on modern smartwatches — are used as a common set of factors. Four authentication models are proposed and formalized: an adaptive model accounting for contextual risk, an intelligent model based on machine learning, a multimodal authentication model with weighting coefficients, and a context-aware model that additionally takes behavioral factors into account. For each model, a mathematical description and a decision-making scheme are provided, and the advantages and disadvantages are determined in terms of accuracy, spoofing resistance, computational complexity, and the energy consumption of the wearable device. An illustrative numerical example is presented, and an analysis of the models' resistance to the main types of attacks is carried out. A practically reproducible method for selecting weighting coefficients based on the individual error rates of the factors is proposed. A comparative analysis of the models against nine criteria is performed, which makes it possible to reasonably select a model depending on the security requirements, device resources, and operating conditions.
Downloads
References
Lisovskyi, B. V., & Zhuravel, I. M. (2025). User authentication in information systems based on biometric signals from mobile devices. Modern Information Security, 64(4), 116-122. https://doi.org/10.31673/2409-7292.2025.041211
Lisovskyi, B. V., & Zhuravel, I. M. (2025). Principles of collecting physiological biometric data from wearable devices for authentication systems. Modern Information Security, 62(2). https://doi.org/10.31673/2409-7292.2025.022701
Liu, S., et al. (2021). Recent advances in biometrics-based user authentication for wearable devices: A contemporary survey. Digital Signal Processing, 103120. https://doi.org/10.1016/j.dsp.2021.103120
Khan, S., et al. (2020). Biometric systems utilising health data from wearable devices. ACM Computing Surveys, 53(4), 1-29. https://doi.org/10.1145/3400030
Jain, A. K., Ross, A., & Prabhakar, S. (2004). An introduction to biometric recognition. IEEE Transactions on Circuits and Systems for Video Technology, 14(1), 4-20. https://doi.org/10.1109/TCSVT.2003.818349
Biswas, D., et al. (2019). CorNET: Deep learning framework for PPG-based heart rate estimation and biometric identification in ambulant environment. IEEE Transactions on Biomedical Circuits and Systems, 13(2), 282-291. https://doi.org/10.1109/TBCAS.2019.2892297
Tsai, Y.-Y., et al. (2025). Photoplethysmography-based HRV analysis and machine learning for real-time stress quantification in mental health applications. APL Bioengineering, 9(2). https://doi.org/10.1063/5.0256590
Bıçakcı, H. S., Santopietro, M., & Guest, R. (2022). Activity-based electrocardiogram biometric verification using wearable devices. IET Biometrics. https://doi.org/10.1049/bme2.12105
Ross, A., & Jain, A. (2003). Information fusion in biometrics. Pattern Recognition Letters, 24(13), 2115-2125. https://doi.org/10.1016/S0167-8655(03)00079-5
Jain, A., Nandakumar, K., & Ross, A. (2005). Score normalization in multimodal biometric systems. Pattern Recognition, 38(12), 2270-2285. https://doi.org/10.1016/j.patcog.2005.01.012
Dass, S. C., Nandakumar, K., & Jain, A. K. (2005). A principled approach to score level fusion in multimodal biometric systems. Lecture Notes in Computer Science, 1049-1058. https://doi.org/10.1007/11527923_109
Vhaduri, S., & Poellabauer, C. (2019). Multi-modal biometric-based implicit authentication of wearable device users. IEEE Transactions on Information Forensics and Security, 14(12), 3116-3125. https://doi.org/10.1109/TIFS.2019.2911170
Sepczuk, M., & Kotulski, Z. (2018). A new risk-based authentication management model oriented on user's experience. Computers & Security, 73, 17-33. https://doi.org/10.1016/j.cose.2017.10.002
Wiefling, S., Lo Iacono, L., & Dürmuth, M. (2019). Is this really you? An empirical study on risk-based authentication applied in the wild. In ICT systems security and privacy protection (pp. 134-148). Springer. https://doi.org/10.1007/978-3-030-22312-0_10
Han, A. H., & Lee, D. H. (2023). Detecting risky authentication using the OpenID Connect token exchange time. Sensors, 23(19), 8256. https://doi.org/10.3390/s23198256
Pourbemany, J., Zhu, Y., & Bettati, R. (2023). A survey of wearable devices pairing based on biometric signals. IEEE Access, 1. https://doi.org/10.1109/ACCESS.2023.3254499
Bours, P. (2012). Continuous keystroke dynamics: A different perspective towards biometric evaluation. Information Security Technical Report, 17(1-2), 36-43. https://doi.org/10.1016/j.istr.2012.02.001
Mondal, S., & Bours, P. (2017). A study on continuous authentication using a combination of keystroke and mouse biometrics. Neurocomputing, 230, 1-22. https://doi.org/10.1016/j.neucom.2016.11.031
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Богдан Лісовський, Ігор Журавель

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.