Fingerprints can be reproduced by the sounds of a finger moving on a touchscreen – study

by alex

A research team from the US and China has exposed a new danger associated with biometric authentication. Their work is called “PrintListener: Detecting Fingerprint Authentication Vulnerabilities from Finger Rubbing Sound.” The attack uses the audio characteristics of the user's finger movement to extract fingerprint pattern features.

After tests, the researchers claim that they can successfully recover up to 27.9% of partial fingerprints and 9.3% of full fingerprints within five attempts. This is the first work to use finger sounds to obtain fingerprint information.

Fingerprint biometric authentication is widely accepted and trusted. However, organizations and individuals are becoming increasingly aware that attackers may want to steal their fingerprints, so some have begun to be wary of having their own fingerprints in sight and photographs that show details of their hands.

How attackers can identify fingerprints by sound? Any communication program that works with the microphone on: Telegram, Skype, Discord and the like can become a source of danger.

The PrintListener attack is complex, but the scientists were able to overcome a number of problems that prevented them from obtaining the specified result:

  • Weak sounds of finger friction – an algorithm has been developed for localizing the sound of friction based on spectral analysis
  • The dependence of the ability to separate finger patterns from the physiological and behavioral characteristics of the user has been largely overcome thanks to the techniques of minimum redundancy, maximum relevance (mRMR) and adaptive weighting strategy
  • The transition from determining the primary characteristics of fingerprints to the secondary ones is carried out using statistical analysis of the relationships between these characteristics and a heuristic search algorithm
Chery presented the economical crossover Jetour Shanghai L7

PrintListener uses a series of algorithms to pre-process raw audio signals, which are then used to create target synthetics for PatternMasterPrint (MasterPrint generated by fingerprints with a specific pattern).

Front-end Basic course. Learn how to develop web interfaces and become a competent Front-end developer! Earn $800 for the beginning of your career. Find out about the course

Importantly, PrintListener has undergone numerous experiments “in real-world scenarios” and, as mentioned in the introduction, can facilitate a successful partial fingerprint attack in more than one in four cases and a full fingerprint attack in almost one in ten case. These results significantly outperform fingerprint dictionary attacks.

You may also like

Leave a Comment