ProTego Framework: Securing BYOD Healthcare via Continuous Soft-Keyboard Biometrics

A Framework for BYOD Continuous Authentication: Case Study with Soft-Keyboard Metrics for Healthcare Environment

2020-01-01
Luis de-Marcos, Carlos Cilleruelo, Javier Junquera-Sánchez, José Javier Martínez-Herráiz
Summary
Problem
Method
Results
Takeaways
Abstract

This paper introduces a modular, extensible framework for Continuous Authentication (CA) specifically designed for Bring Your Own Device (BYOD) environments in healthcare. The system utilizes Endpoint Detection and Response (EDR) agents to collect behavioral biometrics, such as soft-keyboard dynamics, and employs AI models to maintain a real-time trustworthiness score for active users.

TL;DR

In the modern healthcare landscape, Bring Your Own Device (BYOD) is a double-edged sword: it offers flexibility but creates massive security vulnerabilities. This paper presents a modular framework for Continuous Authentication (CA) that monitors user behavior (like how they type) to ensure the person holding the phone is actually the authorized doctor or nurse. By combining mobile EDR agents with backend AI models, the ProTego project creates a "trust score" that fluctuates in real-time.

Problem & Motivation: The "Stolen Session" Risk

Traditional security relies on a single point of entry—once you enter your PIN or scan your thumb, the session is trusted until it ends. In a high-pressure hospital environment, a mobile device could be left unattended or snatched.

The authors identify two major gaps in current research:

  1. Integration Complexity: Most CA systems are "siloed" and hard to plug into existing hospital IT infrastructures.
  2. Contextual Rigidity: Older systems aren't flexible enough to handle the sheer variety of sensors (accelerometers, touchscreens, gyroscopes) available on modern personal smartphones.

Methodology: A Modular "Trust" Pipeline

The ProTego framework breaks the authentication process into distinct, interchangeable modules. This prevents "vendor lock-in" and allows for easy updates as AI models improve.

1. The Architecture

The system follows a three-tier structure:

  • EDR Agents: Lightweight clients on the mobile device that sniff raw data (keystrokes, sensor logs).
  • ProTego JBCA API: The central brain that receives data, triggers AI evaluations, and manages OAuth2 tokens.
  • Trust Clients: Third-party services (like a patient database) that check the user's current trust level before granting access to sensitive records.

Framework Architecture

2. The Soft-Keyboard Metric

The proof-of-concept focuses on Keystroke Dynamics. Instead of looking at what the user types (privacy-sensitive), it looks at how they type:

  • Pressing Time: How long a finger stays on a "key."
  • Time Release Next Press: The gap between letting go of one key and hitting the next.
  • Key Velocity: Derived from the combination of time and motion.

Data Transfer Object

Experiments & Results: Handling the Anomaly

Authentication is a classic "unbalanced data" problem: 99% of the time, the user is legitimate. To solve this, the authors tested both supervised and unsupervised learning.

  • Unsupervised Logic: They utilized One-Class SVM and Isolation Forests. These models excel because they don't need to be told what a "thief" looks like; they simply learn the authorized user's "normal" pattern and flag anything else as an anomaly.
  • Real-time Feedback: The system provides a visual "Trust Bar" on the device, allowing the system to automatically log out a user or trigger a SIEM alert if the trust score drops below a specific threshold (e.g., 0.5).

Trust Level Visualization

Critical Insight & Future Outlook

The brilliance of this framework lies in its scalability. By using a Data Transfer Object (DTO) approach, the system treats a "keystroke" the same way it treats a "GPS coordinate" or a "heart rate."

Limitations

  • Battery Consumption: Constant sensor monitoring can drain mobile batteries.
  • Privacy: While the authors discuss DTOs, sending behavioral biometrics to a backend cloud still poses a privacy risk. Future iterations involving Homomorphic Encryption (computing on encrypted data) will be essential for medical compliance (GDPR/HIPAA).

Final Takeaway

The ProTego project moves us closer to a "zero-trust" mobile environment. By turning behavioral nuances into a security layer, organizations can enjoy the cost-benefits of BYOD without sacrificing the integrity of sensitive patient data.

Find Similar Papers

Try Our Examples

  • Search for recent papers using Ensemble Learning or Deep Learning to improve the accuracy of continuous authentication in BYOD healthcare settings.
  • Which original study established the standard metrics for keystroke dynamics (e.g., flight time vs. dwell time), and how does mobile soft-keyboard interaction differ from physical keyboards in those models?
  • Explore research that integrates Federated Learning or Homomorphic Encryption into continuous authentication frameworks to preserve user privacy during biometric data collection.
Contents
ProTego Framework: Securing BYOD Healthcare via Continuous Soft-Keyboard Biometrics
1. TL;DR
2. Problem & Motivation: The "Stolen Session" Risk
3. Methodology: A Modular "Trust" Pipeline
3.1. 1. The Architecture
3.2. 2. The Soft-Keyboard Metric
4. Experiments & Results: Handling the Anomaly
5. Critical Insight & Future Outlook
5.1. Limitations
5.2. Final Takeaway