GhostType: The Limits of Using Contactless Electromagnetic Interference to Inject Phantom Keys into Analog Circuits of Keyboards
Qinhong Jiang, Yanze Ren, Yan Long, Chen Yan, Yumai Sun, Xiaoyu Ji, Kevin Fu, Wenyuan Xu
摘要
Keyboards are the primary peripheral input devices for various critical computer application scenarios. This paper performs a security analysis of the keyboard sensing mechanisms and uncovers a new class of vulnerabilities that can be exploited to induce phantom keys-fake keystrokes injected into keyboards' analog circuits in a contactless way using electromagnetic interference (EMI). Besides regular keystrokes, such phantom keys also include keystrokes that human operators cannot achieve, such as rapidly injecting over 10,000 keys per minute and injecting hidden keys that do not exist on the physical keyboard. The underlying principles of phantom key injections consist in inducing false voltages on keyboard sensing GPIO pins through EMI coupled onto matrix circuits. We investigate the voltage and timing requirements of injection signals both theoretically and empirically to establish the theory of phantom key injection. To validate the threat of keyboard sensing vulnerabilities, we design GhostType that can cause denial-of-service of the keyboard and inject random keystrokes as well as certain targeted keystrokes of the adversary's choice. We have validated GhostType on 48 of 50 off-the-shelf keyboards/keypads from 20 brands, including both membrane/mechanical structures and USB/Bluetooth protocols. Some example consequences of GhostType include completely blocking keyboard operations, crashing and turning off downstream computers, and deleting computer files. Finally, we glean lessons from our investigations and propose countermeasures, including shielding keyboards with metal materials and enhancing the keystroke sensing mechanism.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- From Virtual Touch to Tesla Command: Unlocking Unauthenticated Control Chains From Smart Glasses for Vehicle TakeoverXingli Zhang, Yazhou Tu, Yan Long, Liqun Shan 等S&P 2024 · 被引用 6 次
- RadKey: An LLM-Guided RF Backscatter System for Through-Wall Keystroke InferenceQijun Wang, Chunqi Qian, Huacheng ZengS&P 2026 · 被引用 2 次
- DualStrike: Accurate, Real-time Eavesdropping and Injection of Keystrokes on Commodity KeyboardsXiaomeng Chen, Jike Wang, Zhenyu Chen, Qi Alfred Chen 等NDSS 2026 · 被引用 1 次
- GhostTac: Manipulating Tactile Sensors without Physical ContactKun Wang, Xuancun Lu, Ruochen Zhou, Kai Wang 等CCS 2026
- SoK: Security of Cyber-physical Systems Under Intentional Electromagnetic Interference AttacksQinhong Jiang, Yan Long, Youqian Zhang, Chen Yan 等USENIX Security 2026
它引用的顶会 Paper14
- FirmUSB: Vetting USB Device Firmware using Domain Informed Symbolic ExecutionGrant Hernandez, Farhaan Fowze, Dave (Jing) Tian, Tuba Yavuz 等CCS 2017 · 被引用 98 次
- Trick or Heat?: Manipulating Critical Temperature-Based Control Systems Using Rectification AttacksYazhou Tu, Sara Rampazzi, Bin Hao, Angel Rodriguez 等CCS 2019 · 被引用 87 次
- SoK: A Minimalist Approach to Formalizing Analog Sensor SecurityChen Yan, Hocheol Shin, Connor Bolton, Wenyuan Xu 等S&P 2020 · 被引用 86 次
- SoK: Keylogging Side ChannelsJohn V. MonacoS&P 2018 · 被引用 56 次
- Tap 'n Ghost: A Compilation of Novel Attack Techniques against Smartphone TouchscreensSeita Maruyama, Satohiro Wakabayashi, Tatsuya MoriS&P 2019 · 被引用 39 次
相关 Paper
- GhostTouch: Targeted Attacks on Touchscreens without Physical TouchKai Wang, Richard Mitev, Chen Yan, Xiaoyu Ji 等USENIX Security 2022
- Invisible Finger: Practical Electromagnetic Interference Attack on Touchscreen-based Electronic DevicesHaoqi Shan, Boyi Zhang, Zihao Zhan, Dean Sullivan 等S&P 2022 · 被引用 17 次
- I Know Your Keyboard Input: A Robust Keystroke Eavesdropper Based-on Acoustic SignalsJia-Xuan Bai, Bin Liu, Luchuan SongACM MM 2021 · 被引用 24 次
- KeyDrown: Eliminating Software-Based Keystroke Timing Side-Channel AttacksMichael Schwarz, Moritz Lipp, Daniel Gruss, Samuel Weiser 等NDSS 2018 · 被引用 68 次
- PhantomLiDAR: Cross-modality Signal Injection Attacks against LiDARZizhi Jin, Qinhong Jiang, Xuancun Lu, Chen Yan 等NDSS 2025
