Feel Vibration: Challenge-Response Mobile Authentication with Covert Channel

Weidong Luo,Bowen Lan,Xinyi Wan,Zhihong Liu,Yong Zeng,Jianfeng Ma
DOI: https://doi.org/10.1109/icct50939.2020.9295824
2020-01-01
Abstract:PIN is widely used as an authentication method on the mobile phone in various public places. However a malicious person nearby may peek into the screen and remember the password. This kind of shoulder surfing attack is more difficult to prevent in modern society. A stronger adversary may use his camera or video surveillance system to record the entry process. In this paper, we present three approaches to solve this problem. Those approaches utilize the phone’s vibration as the covert channel to deliver challenge- response secretly from camera. The experimental results show that those approaches can effectively prevent the shoulder surfing attack, even if the password entry process is completely exposed to the adversary's camera.
What problem does this paper attempt to address?