An Intersection Attack on the CirclePIN Smartwatch Authentication Mechanism

dc.contributor.authorDjalel Chefrour
dc.contributor.authorYasser Sedira
dc.contributor.authorSamir Chabbi
dc.date.accessioned2024-03-29T14:22:33Z
dc.date.available2024-03-29T14:22:33Z
dc.date.issued2024-04-01
dc.description.abstractWe present a thorough security analysis of a recent smartwatch authentication mechanism called CirclePIN, which was considered resilient to several attacks, including shoulder surfing and video recording. This mechanism avoids the direct entry of the personal identification number (PIN) by using consecutive screens of random colors that fool the attacker. We disclose a vulnerability in CirclePIN inherent to the way in which the users match the random colors to their PINs’ digits and we illustrate how to exploit it with an intersection attack. This attack uses the information extracted from multiple video recordings of legitimate authentication sessions. We prove that it has a high probability of revealing the user PIN with only three video recordings and always succeeds with five. Our proof is twofold. We formulate the theoretical probability of success for the attack as a function of the number of available video recordings. Then, we validate this formula with a simulation of a large number of attacks to compute their experimental probability of success. In our estimation, manual information extraction takes around 1 min per exploitable video recording. So, a complete intersection attack is cost effective in terms of time, as it lasts 5 min or less.
dc.description.sponsorshipAlgerian Ministry of Higher Education and Scientific Research (Grant Number: PRFU C00L07UN410120230002)
dc.identifier.citationD. Chefrour, Y. Sedira and S. Chabbi, "An Intersection Attack on the CirclePIN Smartwatch Authentication Mechanism," in IEEE Internet of Things Journal, vol. 11, no. 7, pp. 12485-12494, 1 April1, 2024, doi: 10.1109/JIOT.2023.3333964.
dc.identifier.issn2327-4662
dc.identifier.urihttps://dspace.univ-soukahras.dz/handle/123456789/3589
dc.language.isoen_US
dc.publisherIEEE Internet of Things Journal
dc.relation.ispartofseries11; 7
dc.titleAn Intersection Attack on the CirclePIN Smartwatch Authentication Mechanism
dc.typeArticle
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
2024iot-chefrour.pdf
Size:
648.48 KB
Format:
Adobe Portable Document Format
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed to upon submission
Description:
Collections