(In)secure Acoustic Mobile Authentication

(In)secure Acoustic Mobile Authentication
复制标题

DOI:
10.1109/tmc.2021.3053282
复制
发表时间:
2022-09
影响因子:
7.9
通讯作者:
Dianqi Han;Ang Li;Tao Li;Lili Zhang;Yan Zhang;Jiawei Li;Rui Zhang;Yanchao Zhang
Dianqi Han;Ang Li;Tao Li;Lili Zhang;Yan Zhang;Jiawei Li;Rui Zhang;Yanchao Zhang
中科院分区:
计算机科学2区
文献类型:
--
作者:
Dianqi Han;Ang Li;Tao Li;Lili Zhang;Yan Zhang;Jiawei Li;Rui Zhang;Yanchao Zhang

文献摘要

被引文献

相似文献

声学指纹旨在基于由于制造缺陷而唯一的内部麦克风和扬声器来识别移动终端。本文旨在深入了解探索声指纹实现分布式移动的身份认证的安全性。我们的贡献是三方面的。首先,我们提出了一种新的声学指纹仿真攻击,并证明这是一个常见的脆弱性的声学移动的认证系统。其次,我们提出了一个动态的挑战-响应防御安全的声学移动的认证系统对声学指纹仿真攻击。最后,我们彻底调查现有的声学指纹方案,并确定准确,安全,可部署的声学移动的认证系统的最佳选择。
Acoustic fingerprinting aims to identify a mobile device based on its internal microphone(s) and speaker(s) which are unique due to manufacturing imperfection. This paper seeks a thorough understanding of the (in)security of exploring acoustic fingerprints for achieving distributed mobile authentication. Our contributions are threefold. First, we present a new acoustic fingerprint-emulation attack and demonstrate that it is a common vulnerability of acoustic mobile authentication systems. Second, we propose a dynamic challenge-response defense to secure acoustic mobile authentication systems against the acoustic fingerprint-emulation attack. Finally, we thoroughly investigate existing acoustic fingerprinting schemes and identify the best option for accurate, secure, and deployable acoustic mobile authentication systems.