首页> 外文会议>IEEE Global Communications Conference >You Cannot Sense My PINs: A Side-Channel Attack Deterrent Solution Based on Haptic Feedback on Touch-Enabled Devices
【24h】

You Cannot Sense My PINs: A Side-Channel Attack Deterrent Solution Based on Haptic Feedback on Touch-Enabled Devices

机译:您无法感知我的PIN:基于触摸功能的设备上的触觉反馈的旁道攻击防范解决方案

获取原文

摘要

In this paper, we introduce a novel and secure solution to mitigate side-channel attacks to capture the PINs like touchID and other credentials of touch-enabled devices. Our approach can protect haptic feedback enabled devices from potential direct observation techniques such as cameras and motion sense techniques including such as accelerometers in smart-watch. Both attacks use the concept of shoulder surfing in social engineering and were published recently (CCS'14 and CCS'15). Hand-held devices universally employ small vibration motors as an inexpensive way to provide haptic feedback. The strength of the haptic feedback depends on the brand and the device manufacturer. They are usually strong enough to produce sliding movement and make audible noises if the device is resting on the top of a desk when the vibration motor turns. However, when the device is held in the hand the vibration can only be sensed by the holder; it is usually impossible or uncertain for an observer to know when the vibration motor turns. Our proposed solution uses the haptic feedback to inform the internal state of the keypad to the user and takes advantage of the fact that the effect of haptic feedback can be easily cloaked in such a way that direct observation techniques and indirect sensing techniques will fail. We develop an application on Android cell phones to demonstrate it and invite users to test the code. Moreover, we use real smart-watch to sense the vibration of Android cell phones. Our experimental results show that our approach can mitigate the probability of sensing a 4-digit or 6-digit PINs using smart-watch to below practical value. Our approach also can mitigate the probability of recognizing a 4-digit or 6-digit PINs using a camera within 1 meter to below practical value because the user does not need to move his or her hand during the internal states to input different PINs.
机译:在本文中,我们介绍了一种新颖和安全的解决方案来减轻侧面通道攻击,以捕获触摸设备等凭证等凭证等引脚。我们的方法可以保护启用的触觉反馈设备从潜在的直接观察技术,例如摄像机和运动感应技术,包括智能手表中的加速度计。两次攻击都使用社会工程中的肩部冲浪的概念,并发表于最近(CCS'14和CCS'15)。手持设备普遍采用小振动电机作为提供触觉反馈的廉价方式。触觉反馈的强度取决于品牌和设备制造商。它们通常足以产生滑动运动,并且如果设备在振动电机转动时搁置在桌子顶部,则发出声音噪音。然而,当设备保持在手中时,振动只能由支架感测;观察者通常不可能或不确定振动电机转弯时的观察者。我们所提出的解决方案使用触觉反馈来向用户通知键盘的内部状态,并利用触觉反馈的效果可以轻松地覆盖,即直接观察技术和间接传感技术将失败。我们在Android手机上开发一个应用程序,以演示它并邀请用户测试代码。此外,我们使用真正的智能手表来感知Android手机的振动。我们的实验结果表明,我们的方法可以利用智能手表对4位或6位点引脚感测到4位或6位点引脚的可能性。我们的方法还可以减轻在1米范围内使用相机识别4位或6位点引脚的概率,以低于实际值,因为用户不需要在内部状态期间移动他或她的手以输入不同的引脚。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号