跳到主要导航 跳到搜索 跳到主要内容

PressPIN: Enabling Secure PIN Authentication on Mobile Devices via Structure-Borne Sounds

  • Man Zhou
  • , Qian Wang
  • , Xiu Lin
  • , Yi Zhao
  • , Peipei Jiang
  • , Qi Li
  • , Chao Shen
  • , Cong Wang
  • Huazhong University of Science and Technology
  • Wuhan University
  • Tsinghua University
  • City University of Hong Kong

科研成果: 期刊稿件文章同行评审

20 引用 (Scopus)

摘要

PIN authentication is widely used on mobile devices due to its usability and simplicity. However, it is known to be susceptible to shoulder surfing attacks, where an adversary spies the user's PIN by direct human observation or camera-based recording. This paper proposes PressPIN, a novel enhanced PIN authenticator on mobile devices by sensing pressures from the user's finger. Since pressure-sensitive touch screens are unavailable on most phones, we leverage the structure-borne propagation of sounds to estimate the pressure on the screen. When the user inputs the PINs, the pressure is extracted from each number to form the n-bit pressure code, where n corresponds to the length of the PIN sequence. The pressure code is difficult to be inferred by snooping or videotaping, and increases the entropy of passwords. In this way, PressPIN provides a low-cost, user-friendly, and more secure solution resistant to shoulder surfing attacks. Our extensive experiments with 30 participants and three types of smartphones demonstrate that PressPIN can authenticate legitimate users with high accuracy (e.g., as high as 96.7% within two trials), and is robust to various types of attacks (e.g., only 2.5% attack success rate even when the adversary can observe the legitimate user's PIN sequence and finger pressing clearly). Additionally, PressPIN requires no additional hardware (e.g., the pressure sensor) and can be readily integrated into existing authentication systems of mobile devices.

源语言英语
页(从-至)1228-1242
页数15
期刊IEEE Transactions on Dependable and Secure Computing
20
2
DOI
出版状态已出版 - 1 3月 2023

学术指纹

探究 'PressPIN: Enabling Secure PIN Authentication on Mobile Devices via Structure-Borne Sounds' 的科研主题。它们共同构成独一无二的指纹。

引用此