DARPA Wants a Future With No Passwords

Editor’s Note: This article was originally published in 2012, highlighting early military research into passive biometric authentication. The push towards a password-free future has since become a major trend across the global technology industry.

Imagine a future with no passwords. This is the vision of the Defence Advanced Research Projects Agency (DARPA). The research arm of the US military is sponsoring developers to begin work on software applications that will allow a computer system to identify a user by analysing the way they type, instead of using the traditional password method.

Person typing a password on a computer keyboard

The Problem With Traditional Passwords

The idea dates back to its roots when Morse code was the de facto standard for communications across the world. Passwords like “6To92Js02Da202n” meet the Defence Department’s definition of “strong,” said Richard Guidorizzi, a programme manager at DARPA. “The problem is, they don’t meet human requirements,” he said.

In conventional password-based systems used today, there is no reliable way to verify that the user originally authenticated is the user still in control of the keyboard.

Computer login screen requiring a password

Active Authentication

Move to a world where you sit down at a console, you identify yourself, and you just start working, and the authentication happens in the background, invisible to you, while you continue to do your work without interruptions. No active biometric sensors such as thumbprint scanners or retinal scanners would be used.

The defence agency is hoping to achieve this through its Active Authentication programme.

DARPA is trying to create an authentication system that uses a unique usage fingerprint and constantly monitors how you interact with a device. The system would track characteristics such as the length of key presses, patterns in mouse usage, and the style and language used in emails.

Diagram of key pressure and typing dynamics

Monitoring Typing Patterns

By constantly monitoring these data points, a user would stay logged in simply by using the computer. If they got up to leave and someone else tried to use it, the software would identify them as a different person based on their typing habits and lock them out or modify their access.

It is estimated that only 2 out of every 40,000 people share the exact same typing patterns. DARPA is currently researching how many different metrics it can collect for a user without using any special hardware, although there is no firm timeframe for when a fully working system will be universally deployed.

Close up view of a standard computer keyboard

The authentication platform will be developed with open Application Programming Interfaces (APIs) to allow the integration of other software or hardware biometrics available in the future from other sources.

Perhaps the answer is related to the next stage of research, when they plan to integrate the various biometric data points into a new authentication platform that would work seamlessly on a typical computer within DARPA.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.

Receive our best articles and tips delivered straight to your inbox.