BrutePrint: Expose Smartphone Fingerprint Authentication to Brute-force Attack

05/18/2023
by   Yu Chen, et al.
0

Fingerprint authentication has been widely adopted on smartphones to complement traditional password authentication, making it a tempting target for attackers. The smartphone industry is fully aware of existing threats, and especially for the presentation attack studied by most prior works, the threats are nearly eliminated by liveness detection and attempt limit. In this paper, we study the seemingly impossible fingerprint brute-force attack on off-the-shelf smartphones and propose a generic attack framework. We implement BrutePrint to automate the attack, that acts as a middleman to bypass attempt limit and hijack fingerprint images. Specifically, the bypassing exploits two zero-day vulnerabilities in smartphone fingerprint authentication (SFA) framework, and the hijacking leverages the simplicity of SPI protocol. Moreover, we consider a practical cross-device attack scenario and tackle the liveness and matching problems with neural style transfer (NST). We also propose a method based on neural style transfer to generate valid brute-forcing inputs from arbitrary fingerprint images. A case study shows that we always bypasses liveness detection and attempt limit while 71 evaluate BrutePrint on 10 representative smartphones from top-5 vendors and 3 typical types of applications involving screen lock, payment, and privacy. As all of them are vulnerable to some extent, fingerprint brute-force attack is validated on on all devices except iPhone, where the shortest time to unlock the smartphone without prior knowledge about the victim is estimated at 40 minutes. Furthermore, we suggest software and hardware mitigation measures.

READ FULL TEXT

page 1

page 7

page 8

page 10

research
05/27/2023

Deep Learning based Fingerprint Presentation Attack Detection: A Comprehensive Survey

The vulnerabilities of fingerprint authentication systems have raised se...
research
04/07/2021

A Unified Model for Fingerprint Authentication and Presentation Attack Detection

Typical fingerprint recognition systems are comprised of a spoof detecti...
research
08/02/2017

Fingerprint Extraction Using Smartphone Camera

In the previous decade, there has been a considerable rise in the usage ...
research
12/30/2018

Fingerprint Presentation Attack Detection: Generalization and Efficiency

We study the problem of fingerprint presentation attack detection (PAD) ...
research
12/05/2019

Fingerprint Spoof Generalization

We present a style-transfer based wrapper, called Universal Material Gen...
research
06/12/2017

Portable Trust: biometric-based authentication and blockchain storage for self-sovereign identity systems

We devised a mobile biometric-based authentication system only relying o...
research
08/22/2007

The Fuzzy Vault for fingerprints is Vulnerable to Brute Force Attack

The fuzzy vault approach is one of the best studied and well accepted id...

Please sign up or login with your details

Forgot password? Click here to reset