ProTego Framework: Securing BYOD Healthcare via Continuous Soft-Keyboard Biometrics
A Framework for BYOD Continuous Authentication: Case Study with Soft-Keyboard Metrics for Healthcare Environment
This paper introduces a modular, extensible framework for Continuous Authentication (CA) specifically designed for Bring Your Own Device (BYOD) environments in healthcare. The system utilizes Endpoint Detection and Response (EDR) agents to collect behavioral biometrics, such as soft-keyboard dynamics, and employs AI models to maintain a real-time trustworthiness score for active users.
TL;DR
In the modern healthcare landscape, Bring Your Own Device (BYOD) is a double-edged sword: it offers flexibility but creates massive security vulnerabilities. This paper presents a modular framework for Continuous Authentication (CA) that monitors user behavior (like how they type) to ensure the person holding the phone is actually the authorized doctor or nurse. By combining mobile EDR agents with backend AI models, the ProTego project creates a "trust score" that fluctuates in real-time.
Problem & Motivation: The "Stolen Session" Risk
Traditional security relies on a single point of entry—once you enter your PIN or scan your thumb, the session is trusted until it ends. In a high-pressure hospital environment, a mobile device could be left unattended or snatched.
The authors identify two major gaps in current research:
- Integration Complexity: Most CA systems are "siloed" and hard to plug into existing hospital IT infrastructures.
- Contextual Rigidity: Older systems aren't flexible enough to handle the sheer variety of sensors (accelerometers, touchscreens, gyroscopes) available on modern personal smartphones.
Methodology: A Modular "Trust" Pipeline
The ProTego framework breaks the authentication process into distinct, interchangeable modules. This prevents "vendor lock-in" and allows for easy updates as AI models improve.
1. The Architecture
The system follows a three-tier structure:
- EDR Agents: Lightweight clients on the mobile device that sniff raw data (keystrokes, sensor logs).
- ProTego JBCA API: The central brain that receives data, triggers AI evaluations, and manages OAuth2 tokens.
- Trust Clients: Third-party services (like a patient database) that check the user's current trust level before granting access to sensitive records.

2. The Soft-Keyboard Metric
The proof-of-concept focuses on Keystroke Dynamics. Instead of looking at what the user types (privacy-sensitive), it looks at how they type:
- Pressing Time: How long a finger stays on a "key."
- Time Release Next Press: The gap between letting go of one key and hitting the next.
- Key Velocity: Derived from the combination of time and motion.

Experiments & Results: Handling the Anomaly
Authentication is a classic "unbalanced data" problem: 99% of the time, the user is legitimate. To solve this, the authors tested both supervised and unsupervised learning.
- Unsupervised Logic: They utilized One-Class SVM and Isolation Forests. These models excel because they don't need to be told what a "thief" looks like; they simply learn the authorized user's "normal" pattern and flag anything else as an anomaly.
- Real-time Feedback: The system provides a visual "Trust Bar" on the device, allowing the system to automatically log out a user or trigger a SIEM alert if the trust score drops below a specific threshold (e.g., 0.5).

Critical Insight & Future Outlook
The brilliance of this framework lies in its scalability. By using a Data Transfer Object (DTO) approach, the system treats a "keystroke" the same way it treats a "GPS coordinate" or a "heart rate."
Limitations
- Battery Consumption: Constant sensor monitoring can drain mobile batteries.
- Privacy: While the authors discuss DTOs, sending behavioral biometrics to a backend cloud still poses a privacy risk. Future iterations involving Homomorphic Encryption (computing on encrypted data) will be essential for medical compliance (GDPR/HIPAA).
Final Takeaway
The ProTego project moves us closer to a "zero-trust" mobile environment. By turning behavioral nuances into a security layer, organizations can enjoy the cost-benefits of BYOD without sacrificing the integrity of sensitive patient data.
