InfinityGauntlet: Expose Smartphone Fingerprint Authentication to Brute-force Attack
Yu Chen, Yang Yu, Lidong Zhai
摘要
Billions of smartphone fingerprint authentications (SFA) occur daily for unlocking, privacy and payment. Existing threats to SFA include presentation attacks (PA) and some case-bycase vulnerabilities. The former need to know the victim's fingerprint information (e.g., latent fingerprints) and can be mitigated by liveness detection and security policies. The latter require additional conditions (e.g., third-party screen protector, root permission) and are only exploitable for individual smartphone models. In this paper, we conduct the first investigation on the general zero-knowledge attack towards SFA where no knowledge about the victim is needed. We propose a novelty fingerprint brute-force attack on off-the-shelf smartphones, named IN-FINITYGAUNTLET. Firstly, we discover design vulnerabilities in SFA systems across various manufacturers, operating systems, and fingerprint types to achieve unlimited authentication attempts. Then, we use SPI MITM to bypass liveness detection and make automatic attempts. Finally, we customize a synthetic fingerprint generator to get a valid brute-force fingerprint dictionary. We design and implement low-cost equipment to launch INFINITYGAUNTLET. A proof-of-concept case study demonstrates that INFINITYGAUNTLET can brute-force attack successfully in less than an hour without any knowledge of the victim. Additionally, empirical analysis on representative smartphones shows the scalability of our work.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- MaskPrint: Take the Initiative in Fingerprint Protection to Mitigate the Harm of Data BreachYihui Yan, Zhice YangCCS 2024 · 被引用 1 次
- An Empirical Study on Fingerprint API Misuse with Lifecycle Analysis in Real-world Android AppsXin Zhang, Xiaohan Zhang, Zhichen Liu, Bo Zhao 等NDSS 2025
- Practically Secure Honey Password Vaults: New Design and New Evaluation against Online GuessingHaibo Cheng, Fugeng Huang, Jiahong Yang, Wenting Li 等USENIX Security 2025
- May the Force Not Be With You: Brute-Force Resistant Biometric Authentication and Key ReconstructionAlexandra Boldyreva, Deep Inder Mohan, Tianxin TangCCS 2025
- OneTouch: Effortless 2FA Scheme to Secure Fingerprint Authentication with Wearable OTP TokenYihui Yan, Zhice YangUSENIX Security 2025
相关 Paper
- Liveness is Not Enough: Enhancing Fingerprint Authentication with Behavioral Biometrics to Defeat Puppet AttacksCong Wu, Kun He, Jing Chen, Ziming Zhao 等USENIX Security 2020
- Broken Fingers: On the Usage of the Fingerprint API in AndroidAntonio Bianchi, Yanick Fratantonio, Aravind Machiry, Christopher Kruegel 等NDSS 2018 · 被引用 33 次
- FakeGuard: Exploring Haptic Response to Mitigate the Vulnerability in Commercial Fingerprint Anti-SpoofingAditya Singh Rathore, Yijie Shen, Chenhan Xu, Jacob Snyderman 等NDSS 2022
- No Pardon for the Interruption: New Inference Attacks on Android Through Interrupt Timing AnalysisWenrui Diao, Xiangyu Liu, Zhou Li, Kehuan ZhangS&P 2016 · 被引用 79 次
- PHYjacking: Physical Input Hijacking for Zero-Permission Authorization Attacks on AndroidXianbo Wang, Shangcheng Shi, Yikang Chen, Wing Cheong LauNDSS 2022
