Study finds fingerprints can be copied by the sound of a finger moving on a scanner
02.03.24A research team from the US and China has identified a fingerprint authentication vulnerability. It is based on the sound of finger friction, the devices can record sound waves and even minor changes in the surface of the finger as it moves over the fingerprint sensor.
Attackers can use the detected audio characteristics to recover fingerprints and create fake fingerprints that can be used to bypass the authentication system.
The attack process could be as follows:
- Data Collection: Attackers can use microphone-enabled chat programs, such as Telegram, Skype, or Discord, to record sounds made by rubbing their fingers against the fingerprint sensor.
- Sound Analysis: The resulting audio recordings are then analyzed to identify characteristic sounds associated with finger movements on the sensor.
- Fingerprint Recovery: Based on audio data, attackers can attempt to recover partial or full fingerprints, which can be used to spoof or bypass authentication systems.
To protect against such attacks, device manufacturers can use various methods, such as improving protection against acoustic eavesdropping and analyzing fingerprint data. It is also recommended to implement biometric authentication methods that are not susceptible to such attacks, for example, facial scanning or iris scanners. It is also important to ensure that biometric data is stored and securely transmitted to prevent leakage and misuse.
The PrintListener attack seems difficult to implement, but scientists managed to overcome a number of problems that prevented them from obtaining the result:
- Weak sounds of finger friction – an algorithm has been developed for localizing the sound of friction based on spectral analysis;
- The dependence of the ability to separate finger patterns from the physiological and behavioral characteristics of the user has been largely overcome thanks to the techniques of minimum redundancy, maximum relevance (mRMR) and adaptive weighting strategy;
- The transition from determining the primary characteristics of fingerprints to the secondary ones is carried out using statistical analysis of the relationships between these characteristics and a heuristic search algorithm.
Don't miss interesting news
Subscribe to our channels and read announcements of high-tech news, tes
Asus Zenbook S 16 (UM5606): new wave
The new Asus Zenbook S 16 laptop is made in an unusual metal case, built on the basis of a fresh AMD platform adapted for AI, and has excellent autonomy. Let’s talk about this premium laptop in more detail
Akash System uses diamonds to cool processors in data centers, space and military equipment development processor
Akash System has signed a memorandum with the US Department of Commerce, expecting $18.2 million in direct funding and $50 million in tax incentives. In addition, the startup has already raised $18 million from venture capitalists.
Bugatti W16 Mistral accelerates to 453.91 km/h and becomes the fastest roadster in the world car
Although Bugatti did not disclose whether any changes were made to the powertrain, the car used the same 8.0-liter W16 engine with four turbines and an output of 1,600 hp.