[go: up one dir, main page]
More Web Proxy on the site http://driver.im/ skip to main content
10.1145/2836041.2836053acmotherconferencesArticle/Chapter ViewAbstractPublication PagesmumConference Proceedingsconference-collections
short-paper

Towards device-to-user authentication: protecting against phishing hardware by ensuring mobile device authenticity using vibration patterns

Published: 30 November 2015 Publication History

Abstract

Users usually authenticate to mobile devices before using them (e.g. PIN, password), but devices do not do the same to users. Revealing the authentication secret to a non-authenticated device potentially enables attackers to obtain the secret, by replacing the device with an identical-looking malicious device. The revealed authentication secret could be transmitted to the attackers immediately, who then conveniently authenticate to the real device. Addressing this attack scenario, we analyze different approaches towards mobile device-to-user (D2U) authentication, for which we provide an overview of advantages/drawbacks, potential risks and device authentication data bandwidth estimations. We further analyze vibration as one D2U feedback channel that is unobtrusive and hard to eavesdrop, including a user study to estimate vibration pattern recognition using a setup of ~7 bits per second (b/s). Study findings indicate that users are able to distinguish vibration patterns with median correctness of 97.5% (without taking training effects into account) -- which indicates that vibration could act as authentication feedback channel and should be investigated further in future research.

References

[1]
Joshua Adkins, Genevieve Flaspohler, and Prabal Dutta. 2015. Ving: Bootstrapping the Desktop Area Network with a Vibratory Ping. In The 2nd ACM Workshop on Hot Topics in Wireless (HotWireless'15). Paris, France.
[2]
Lorrie Faith Cranor and Simson Garfinkel. 2008. Security and Usability. O'Reilly Media.
[3]
M. Hansen, R. Hill, and S. Wimberly. 2012. Detecting covert communication on Android. In Local Computer Networks (LCN), 2012 IEEE 37th Conference on. 300-303.
[4]
Robin Heydon. 2012. Bluetooth Low Energy: The Developer's Handbook. Prentice Hall.
[5]
Daniel Hintze, Rainhard Dieter Findling, Sebastian Scholz, and René Mayrhofer. 2014. Mobile Device Usage Characteristics: The Effect of Context and Form Factor on Locked and Unlocked Usage. In Proc. MoMM 2014: 12th International Conference on Advances in Mobile Computing and Multimedia. ACM Press, New York, NY, USA, 105-114.
[6]
Tim Kindberg, Chris Bevan, Eamonn O'Neill, James Mitchell, Jim Grimmett, and Dawn Woodgate. 2009. Authenticating Ubiquitous Services: A Study of Wireless Hotspot Access. In Proceedings of the 11th International Conference on Ubiquitous Computing (UbiComp '09). ACM, New York, NY, USA, 115-124.
[7]
M. Long and D. Durham. 2007. Human Perceivable Authentication: An Economical Solution for Security Associations in Short-Distance Wireless Networking. In Computer Communications and Networks, 2007. ICCCN 2007. Proceedings of 16th International Conference on. 257-264.
[8]
Rene Mayrhofer and Hans Gellersen. 2007. On the Security of Ultrasound as Out-of-band Channel. In Parallel and Distributed Processing Symposium, 2007. IPDPS 2007. IEEE International. IEEE, 1--6.
[9]
R. Mayrhofer and H. Gellersen. 2009. Shake Well Before Use: Intuitive and Secure Pairing of Mobile Devices. Mobile Computing, IEEE Transactions on 8, 6 (2009), 792-806.
[10]
Eric Rescorla. 2000. SSL and TLS: Designing and Building Secure Systems. Addison-Wesley Professional.
[11]
Ronald L. Rivest and Adi Shamir. 1984. How to Expose an Eavesdropper. Commun. ACM 27, 4 (April 1984), 393-394.
[12]
P. C. Roberts, L. P. Benofsky, W. G. Holt, L. H. Johnson, M. J. Bryant, and N. I. Nussbaum. 2009. Systems and methods for demonstrating authenticity of a virtual machine using a security image. (July 21 2009). https://www.google.com/patents/US7565535 US Patent 7,565,535.
[13]
P. C. Roberts, L. P. Benofsky, W. G. Holt, L. H. Johnson, B. M. Willman, and M. J. Bryant. 2010. Systems and methods for determining if applications executing on a computer system are trusted. (May 18 2010). https://www.google.com/patents/US7721094 US Patent 7,721,094.
[14]
Nirupam Roy, Mahanth Gowda, and Romit Roy Choudhury. 2015. Ripple: Communicating through Physical Vibration. In 12th USENIX Symposium on Networked Systems Design and Implementation (NSDI 15). USENIX Association, Oakland, CA, 265--278. httpps://www.usenix.org/conference/nsdi15/technical-sessions/presentation/roy
[15]
Claudio Soriente, Gene Tsudik, and Ersin Uzun. 2008. HAPADEP: Human-Assisted Pure Audio Device Pairing. In Information Security, Tzong-Chen Wu, Chin-Laung Lei, Vincent Rijmen, and Der-Tsai Lee (Eds.). Lecture Notes in Computer Science, Vol. 5222. Springer Berlin Heidelberg, 385-400.
[16]
Emanuel von Zezschwitz, Paul Dunphy, and Alexander De Luca. 2013. Patterns in the wild: a field study of the usability of pattern and pin-based authentication on mobile devices. In Proc. of the 15th international conference on Human-computer interaction with mobile devices and services (MobileHCI '13). ACM, New York, NY, USA, 261-270.
[17]
T. Yonezawa, J. Nakazawa, and H. Tokuda. 2015. Vinteraction: Vibration-based information transfer for smart devices. In Mobile Computing and Ubiquitous Networking (ICMU), 2015 Eighth International Conference on. 155-160.

Cited By

View all
  • (2024)Good Vibes! Towards Phone-to-User Authentication Through Wristwatch VibrationsAdvances in Mobile Computing and Multimedia Intelligence10.1007/978-3-031-78049-3_3(24-30)Online publication date: 2-Dec-2024
  • (2021)LeaD: Learn to Decode Vibration-based Communication for Intelligent Internet of ThingsACM Transactions on Sensor Networks10.1145/344025017:3(1-25)Online publication date: 21-Jun-2021
  • (2020)VibeRingProceedings of the 10th International Conference on the Internet of Things10.1145/3410992.3410995(1-8)Online publication date: 6-Oct-2020
  • Show More Cited By

Index Terms

  1. Towards device-to-user authentication: protecting against phishing hardware by ensuring mobile device authenticity using vibration patterns

      Recommendations

      Comments

      Please enable JavaScript to view thecomments powered by Disqus.

      Information & Contributors

      Information

      Published In

      cover image ACM Other conferences
      MUM '15: Proceedings of the 14th International Conference on Mobile and Ubiquitous Multimedia
      November 2015
      442 pages
      ISBN:9781450336055
      DOI:10.1145/2836041
      Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than the author(s) must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected].

      Sponsors

      • FH OOE: University of Applied Sciences Upper Austria
      • Johannes Kepler Univ Linz: Johannes Kepler Universität Linz

      In-Cooperation

      Publisher

      Association for Computing Machinery

      New York, NY, United States

      Publication History

      Published: 30 November 2015

      Permissions

      Request permissions for this article.

      Check for updates

      Author Tags

      1. feedback
      2. mobile authentication
      3. phishing hardware
      4. vibration

      Qualifiers

      • Short-paper

      Conference

      MUM '15
      Sponsor:
      • FH OOE
      • Johannes Kepler Univ Linz

      Acceptance Rates

      MUM '15 Paper Acceptance Rate 33 of 89 submissions, 37%;
      Overall Acceptance Rate 190 of 465 submissions, 41%

      Contributors

      Other Metrics

      Bibliometrics & Citations

      Bibliometrics

      Article Metrics

      • Downloads (Last 12 months)6
      • Downloads (Last 6 weeks)1
      Reflects downloads up to 15 Jan 2025

      Other Metrics

      Citations

      Cited By

      View all
      • (2024)Good Vibes! Towards Phone-to-User Authentication Through Wristwatch VibrationsAdvances in Mobile Computing and Multimedia Intelligence10.1007/978-3-031-78049-3_3(24-30)Online publication date: 2-Dec-2024
      • (2021)LeaD: Learn to Decode Vibration-based Communication for Intelligent Internet of ThingsACM Transactions on Sensor Networks10.1145/344025017:3(1-25)Online publication date: 21-Jun-2021
      • (2020)VibeRingProceedings of the 10th International Conference on the Internet of Things10.1145/3410992.3410995(1-8)Online publication date: 6-Oct-2020
      • (2018)SYNCVIBE: Fast and Secure Device Pairing through Physical Vibration on Commodity Smartphones2018 IEEE 36th International Conference on Computer Design (ICCD)10.1109/ICCD.2018.00043(234-241)Online publication date: Oct-2018
      • (2017)CondioSensePersonal and Ubiquitous Computing10.1007/s00779-016-0981-121:1(17-29)Online publication date: 1-Feb-2017
      • (2016)Security Challenges of Small Cell as a Service in Virtualized Mobile Edge Computing EnvironmentsInformation Security Theory and Practice10.1007/978-3-319-45931-8_5(70-84)Online publication date: 17-Sep-2016

      View Options

      Login options

      View options

      PDF

      View or Download as a PDF file.

      PDF

      eReader

      View online with eReader.

      eReader

      Media

      Figures

      Other

      Tables

      Share

      Share

      Share this Publication link

      Share on social media