首页> 外文OA文献 >Attacks on heartbeat-based security using remote photoplethysmography
【2h】

Attacks on heartbeat-based security using remote photoplethysmography

机译:使用远程光体积描记法攻击基于心跳的安全性

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

The time interval between consecutive heartbeats (interpulse interval, IPI) has previously been suggested for securing mobile-health (mHealth) solutions. This time interval is known to contain a degree of randomness, permitting the generation of a time- and person-specific identifier. It is commonly assumed that only devices trusted by a person can make physical contact with him/her, and that this physical contact allows each device to generate a similar identifier based on its own cardiac recordings. Under these conditions, the identifiers generated by different trusted devices can facilitate secure authentication. Recently, a wide range of techniques have been proposed for measuring heartbeats remotely, a prominent example of which is remote photoplethysmography (rPPG). These techniques may pose a significant threat to heartbeat-based security, as an adversary may pretend being a trusted device by generating a similar identifier without physical contact, thus bypassing one of the core security conditions. In this paper, we assess the feasibility of such remote attacks using state-of-the-art rPPG methods. Our evaluation shows that rPPG has similar accuracy as contact PPG and, thus, forms a substantial threat to heartbeat-based-security systems that permit trusted devices to obtain their identifiers from contact PPG recordings. Conversely, rPPG cannot obtain an accurate representation of an identifier generated from electrical cardiac signals, making the latter invulnerable to state-of-the-art remote attacks.
机译:先前已建议连续两次心跳之间的时间间隔(脉冲间隔,IPI)用于保护移动健康(mHealth)解决方案。已知该时间间隔包含一定程度的随机性,从而允许生成特定于时间和个人的标识符。通常假设只有一个人信任的设备才能与他/她进行物理接触,并且这种物理接触允许每个设备根据其自己的心脏记录生成相似的标识符。在这些条件下,由不同的受信任设备生成的标识符可以促进安全身份验证。近来,已经提出了用于远程测量心跳的多种技术,其中一个突出的例子是远程光电容积描记术(rPPG)。这些技术可能会对基于心跳的安全性构成重大威胁,因为对手可能会通过在没有物理接触的情况下生成类似的标识符来假装是受信任的设备,从而绕过了核心安全条件之一。在本文中,我们使用最新的rPPG方法评估了这种远程攻击的可行性。我们的评估表明,rPPG具有与联系人PPG相似的准确性,因此,对基于心跳的安全系统构成了重大威胁,该系统允许受信设备从联系人PPG记录中获取其标识符。相反,rPPG无法获得从心脏电信号生成的标识符的准确表示,从而使后者不受最新的远程攻击的影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号