IoT and behavioural authentication

Access & Identity Management Handbook 2020 Access Control & Identity Management

IoT represents an increasing security risk to compromise your most personal security credentials.

Security begins at home and it begins with you, the individual. IoT represents an increasing security risk to individuals in the form of pervasive, always-on monitoring of your personal activity with a potential compromise of your most personal security credentials.

Consider the four factors of authentication. First and foremost is something you know – a password for example. The second is something you have, such as an access card, key fob or hardware-based token generator. Third is something you are, such as your iris pattern or fingerprint – both are typical biometrics. The fourth factor of authentication is something you do – the way you walk, breathe, speak or any other manner of activity which has a recognisable and unique pattern over time. This latter is called behavioural authentication and while this factor is often tied into general biometrics, it is distinctly different.

It’s not unimaginable at this point that your fourth factor of authentication can be reconstructed from data gathered by IoT devices. Think about how Internet-connected shoes can learn intimate details of their wearer’s gait; or the smartwatch that learns the specific timing of its wearer’s heartbeat. Then there is the speaker-based home assistant that learns the pitch and timbre of the home occupants’ voices.

Post quantum security

The first two factors of authentication rely on a number, key or phrase that is susceptible to brute force attacks to crack the credential. While still a long way off, the immense power of quantum computing will undermine the security of the first two factors of authentication. The advent of quantum computing will mean that technology manufacturers will come to increasingly rely on the third and fourth authentication factors.

When the encryption mechanisms behind passwords and OTPs become insecure, you will certainly find yourself logging into your Internet banking with a passphrase spoken into your microphone. Your typing style, based on flight, sequence and pressure, will become your ongoing signature. These voice and keyboard behaviours are just two patterns that are in use today and will become increasingly important.

Just like you would not be careless with your house keys, it’s important to know the value your habits will one day have. In a situation where the data collected by IoT devices compromises users’ habits, those people would lose the ability to secure their devices and their logins.

For example the first known financial scam using synthesised voice was reported in September 2019[1] when scammers replicated a CEO’s voice to authorise payments totalling R3,6 million from a company. This was done using deep fake (a technique for human image synthesis based on artificial intelligence)-derived AI and various voice recordings of the victim.

Commitment to privacy

There have been some positive developments in the privacy space, following increased scrutiny from legislators in the form of GDPR/PoPIA and general public awareness around exploitation of personal data. The various social media data abuse scandals over the years are also turning public sentiment. People are becoming more aware and protective of their personal data which will extend to behavioural data as well.

Manufacturers of IoT devices are also showing encouraging signs, for example Amazon has added auto delete features to its Alexa range after previously admitting that audio recordings are stored indefinitely[2]. Moreover, Apple changed its policy to no longer retain audio recordings by default. It’s worth taking into serious consideration the fact that Google’s chief of devices and services recommended that one should disclose if one’s home has smart-home devices installed before issuing invitations to guests[3].

As IoT devices proliferate, vendors must commit to transparency about what data they collect and how they use it. A firm legislative effort to curb needless collection of data, especially around sensitive activity and habit patterns, will go a long way to securing the market for a post-password authentication world. Until then, buyers of IoT devices need to read the fine print and make sure they know what behavioural data is being collected and how it is used.


Gregory Dellas

[1] https://threatpost.com/deep-fake-of-ceos-voice-swindles-company-out-of-243k/147982/

[2] https://www.theverge.com/2019/7/3/20681423/amazon-alexa-echo-chris-coons-data-transcripts-recording-privacy

[3] https://www.bbc.com/news/technology-50048144




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

The power of PKI and private sector innovation
Access Control & Identity Management News & Events Government and Parastatal (Industry)
At the recent ID4Africa 2025 Summit in Addis Ababa, the spotlight was firmly on building secure, inclusive, and scalable digital identity ecosystems for the African continent.

Read more...
Biometric security key for phishing-resistant MFA
Products & Solutions Access Control & Identity Management
New FIDO-compliant USB, Bluetooth, and NFC BioKeys with biometric login and centralised management for phishing-resistant, passwordless multifactor authentication (MFA) for enterprise users.

Read more...
Gallagher Security releases OneLink
Gallagher Animal Management Products & Solutions Access Control & Identity Management
Gallagher Security has announced OneLink, a cloud-based solution that makes it faster, easier and more cost-effective to deploy security anywhere in the world, transforming how security can be delivered to remote sites and distributed infrastructure.

Read more...
Suprema unveils BioStar Air
Suprema neaMetrics News & Events Access Control & Identity Management Infrastructure
Suprema launches BioStar Air, the first cloud-based access control platform designed to natively support biometric authentication and feature true zero-on-premise architecture. BioStar Air simplifies deployment and scales effortlessly to secure SMBs, multi-branch companies, and mixed-use buildings.

Read more...
Continuous AML risk monitoring
Access Control & Identity Management Security Services & Risk Management Financial (Industry)
AU10TIX, launched continuous risk monitoring as part of its advanced anti-money laundering (AML) solution, empowering businesses to detect behavioural anomalies and emerging threats as they arise.

Read more...
The future of security: intelligent automation
Access Control & Identity Management AI & Data Analytics IoT & Automation
As the security landscape evolves, businesses are no longer looking for stand-alone solutions, they want connected, intelligent systems that automate, streamline, and protect.

Read more...
Smart automation is changing security
SA Technologies IntelliGuard Access Control & Identity Management
Security has come a long way from manual check-ins, logbooks, and standalone surveillance cameras. With the rise of intelligent automation, security is now faster, smarter, and more connected than ever.

Read more...
The future of security in South Africa
ATG Digital Access Control & Identity Management
Security technology is evolving rapidly, but is local innovation keeping pace? Some global players recognise the potential of South African products for international markets, but can our manufacturers and service providers thrive without external support?

Read more...
Integration enhances estate access control
Access Control & Identity Management
With one-third of residential burglaries starting at the front door, the continued seamless integration of Glovent’s estate management platform with Impro access control software is welcome news for estates.

Read more...
T&A in South Africa’s retail sector
ERS Biometrics Access Control & Identity Management
Using existing systems, ERSBio provides a practical and more cost-effective way for businesses to manage operations, reduce payroll mistakes, and enhance overall efficiency through innovative T&A processes.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.