USENIX Security2023Top-tier venue
InfinityGauntlet: Expose Smartphone Fingerprint Authentication to Brute-force Attack
Yu Chen, Yang Yu, Lidong Zhai
Abstract
Billions of smartphone fingerprint authentications (SFA) occur daily for unlocking, privacy and payment. Existing threats to SFA include presentation attacks (PA) and some case-bycase vulnerabilities. The former need to know the victim's fingerprint information (e.g., latent fingerprints) and can be mitigated by liveness detection and security policies. The latter require additional conditions (e.g., third-party screen protector, root permission) and are only exploitable for individual smartphone models. In this paper, we conduct the first investigation on the general zero-knowledge attack towards SFA where no knowledge about the victim is needed. We propose a novelty fingerprint brute-force attack on off-the-shelf smartphones, named IN-FINITYGAUNTLET. Firstly, we discover design vulnerabilities in SFA systems across various manufacturers, operating systems, and fingerprint types to achieve unlimited authentication attempts. Then, we use SPI MITM to bypass liveness detection and make automatic attempts. Finally, we customize a synthetic fingerprint generator to get a valid brute-force fingerprint dictionary. We design and implement low-cost equipment to launch INFINITYGAUNTLET. A proof-of-concept case study demonstrates that INFINITYGAUNTLET can brute-force attack successfully in less than an hour without any knowledge of the victim. Additionally, empirical analysis on representative smartphones shows the scalability of our work.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3ea25bee-0a25-43a8-9468-2f74cb88a7d3Cited by top-tier papers5
- MaskPrint: Take the Initiative in Fingerprint Protection to Mitigate the Harm of Data BreachYihui Yan, Zhice YangCCS 2024 · 1 citation
- An Empirical Study on Fingerprint API Misuse with Lifecycle Analysis in Real-world Android AppsXin Zhang, Xiaohan Zhang, Zhichen Liu, Bo Zhao et al.NDSS 2025
- Practically Secure Honey Password Vaults: New Design and New Evaluation against Online GuessingHaibo Cheng, Fugeng Huang, Jiahong Yang, Wenting Li et al.USENIX Security 2025
- May the Force Not Be With You: Brute-Force Resistant Biometric Authentication and Key ReconstructionAlexandra Boldyreva, Deep Inder Mohan, Tianxin TangCCS 2025
- OneTouch: Effortless 2FA Scheme to Secure Fingerprint Authentication with Wearable OTP TokenYihui Yan, Zhice YangUSENIX Security 2025
Related papers
- Liveness is Not Enough: Enhancing Fingerprint Authentication with Behavioral Biometrics to Defeat Puppet AttacksCong Wu, Kun He, Jing Chen, Ziming Zhao et al.USENIX Security 2020
- Broken Fingers: On the Usage of the Fingerprint API in AndroidAntonio Bianchi, Yanick Fratantonio, Aravind Machiry, Christopher Kruegel et al.NDSS 2018 · 33 citations
- FakeGuard: Exploring Haptic Response to Mitigate the Vulnerability in Commercial Fingerprint Anti-SpoofingAditya Singh Rathore, Yijie Shen, Chenhan Xu, Jacob Snyderman et al.NDSS 2022
- No Pardon for the Interruption: New Inference Attacks on Android Through Interrupt Timing AnalysisWenrui Diao, Xiangyu Liu, Zhou Li, Kehuan ZhangS&P 2016 · 79 citations
- PHYjacking: Physical Input Hijacking for Zero-Permission Authorization Attacks on AndroidXianbo Wang, Shangcheng Shi, Yikang Chen, Wing Cheong LauNDSS 2022
