Electrocardiogram (ECG)-based authentication has gained popularity recently, but its security measures have not been thoroughly explored. In this paper, we explore dictionary attacks against ECG authentication systems. We attempt to spoof the victim’s ECG model without prior knowledge of the victim’s ECG information. We investigated the feasibility of identifying a “master” collection of ECG signals that may coincide with ECG verification templates saved by authenticated users. Our experiments in four different ECG verification schemes show that these master ECG signals can effectively impersonate the ECG verification profiles of a wide range of users. These findings highlight significant vulnerabilities in current ECG-based authentication systems and can be used to strengthen ECG-based authentication systems.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Exploring the Vulnerability of ECG-Based Authentication Systems Through A Dictionary Attack Approach

  • Bonan Zhang,
  • Chao Chen,
  • Ickjai Lee,
  • Kyungmi Lee,
  • Kok-Leong Ong

摘要

Electrocardiogram (ECG)-based authentication has gained popularity recently, but its security measures have not been thoroughly explored. In this paper, we explore dictionary attacks against ECG authentication systems. We attempt to spoof the victim’s ECG model without prior knowledge of the victim’s ECG information. We investigated the feasibility of identifying a “master” collection of ECG signals that may coincide with ECG verification templates saved by authenticated users. Our experiments in four different ECG verification schemes show that these master ECG signals can effectively impersonate the ECG verification profiles of a wide range of users. These findings highlight significant vulnerabilities in current ECG-based authentication systems and can be used to strengthen ECG-based authentication systems.