USENIX Security2021Top-tier venue
Charger-Surfing: Exploiting a Power Line Side-Channel for Smartphone Information Leakage
Patrick Cronin, Xing Gao, Chengmo Yang, Haining Wang
Abstract
Touchscreen-based mobile devices such as smartphones and tablets are used daily by billions of people for productivity and entertainment. This paper uncovers a new security threat posed by a side-channel leakage through the power line, called Charger-Surfing, which targets these touchscreen devices. We reveal that while a smartphone is charging, its power trace, which can be measured via the USB charging cable, leaks information about the dynamic content on its screen. This information can be utilized to determine the location on the touchscreen where an animation is played by the mobile OS to indicate, for instance, that a button press has been registered. We develop a portable, low cost power trace collection system for the side-channel construction. This leakage channel is thoroughly evaluated on various smartphones running Android or iOS, equipped with the two most commonly used screen technologies (LCD and OLED). We validate the effectiveness of Charger-Surfing by conducting a case study on a passcode unlock screen. Our experiments show that an adversary can exploit Charger-Surfing across a wide range of smartphone models to achieve an average accuracy of 98.7% for single button inference, and an average of 95.1% or 92.8% accuracy on the first attempt when cracking a victim's 4-digit or 6-digit passcode, respectively. The inference accuracy increases to 99.3% (4-digit) or 96.9% (6-digit) within five trials. We further demonstrate the robustness of Charger-Surfing in realistic settings and discuss countermeasures against it.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 52732d08-e5c4-4bb2-b893-bb4c3ce2a85cCited by top-tier papers17
- Wireless Charging Power Side-Channel AttacksAlexander S. La Cour, Khurram K. Afridi, G. Edward SuhCCS 2021 · 40 citations
- Recovering Fingerprints from In-Display Fingerprint Sensors via Electromagnetic Side ChannelTao Ni, Xiaokuan Zhang, Qingchuan ZhaoCCS 2023 · 34 citations
- Password-Stealing without Hacking: Wi-Fi Enabled Practical Keystroke EavesdroppingJingyang Hu, Hongbo Wang, Tianyue Zheng, Jingzhi Hu et al.CCS 2023 · 34 citations
- Exploiting Contactless Side Channels in Wireless Charging Power Banks for User Privacy Inference via Few-shot LearningTao Ni, Jianfeng Li, Xiaokuan Zhang, Chaoshun Zuo et al.MobiCom 2023 · 27 citations
- WIGHT: Wired Ghost Touch Attack on Capacitive TouchscreensYan Jiang, Xiaoyu Ji, Kai Wang, Chen Yan et al.S&P 2022 · 23 citations
Builds on13
- ECDSA Key Extraction from Mobile Devices via Nonintrusive Physical Side ChannelsDaniel Genkin, Lev Pachmanov, Itamar Pipman, Eran Tromer et al.CCS 2016 · 196 citations
- Cracking Android Pattern Lock in Five AttemptsGuixin Ye, Zhanyong Tang, Dingyi Fang, Xiaojiang Chen et al.NDSS 2017 · 123 citations
- PatternListener: Cracking Android Pattern Lock Using Acoustic SignalsMan Zhou, Qian Wang, Jingxiao Yang, Qi Li et al.CCS 2018 · 79 citations
- Face Flashing: a Secure Liveness Detection Protocol based on Light ReflectionsDi Tang, Zhe Zhou, Yinqian Zhang, Kehuan ZhangNDSS 2018 · 78 citations
- Return-Oriented Flush-Reload Side Channels on ARM and Their Implications for Android DevicesXiaokuan Zhang, Yuan Xiao, Yinqian ZhangCCS 2016 · 77 citations
Related papers
- Fast or Secure? Push the Limit of Privacy Leakage Threat via Charging Side-Channel AttacksJiaxin Jiang, Xutong Zhang, Jiahao Li, Leqi Zhao et al.WWW 2026
- Uncovering User Interactions on Smartphones via Contactless Wireless Charging Side ChannelsTao Ni, Xiaokuan Zhang, Chaoshun Zuo, Jianfeng Li et al.S&P 2023
- Periscope: A Keystroke Inference Attack Using Human Coupled Electromagnetic EmanationsWenqiang Jin, Srinivasan Murali, Huadi Zhu, Ming LiCCS 2021 · 34 citations
- No Pardon for the Interruption: New Inference Attacks on Android Through Interrupt Timing AnalysisWenrui Diao, Xiangyu Liu, Zhou Li, Kehuan ZhangS&P 2016 · 79 citations
- Eavesdropping user credentials via GPU side channels on smartphonesBoyuan Yang, Ruirong Chen, Kai Huang, Jun Yang et al.ASPLOS 2022 · 12 citations
