Exploring the Vulnerability of ECG-Based Authentication Systems Through A Dictionary Attack Approach

Conference Publication ResearchOnline@JCU
Zhang, Bonan;Chen, Chao;Lee, Ickjai;Lee, Kyungmi;Ong, Kok-Leong
Abstract

Electrocardiogram (ECG)-based authentication has gained popularity recently, but its security measures have not been thoroughly explored. In this paper, we explore dictionary attacks against ECG authentication systems. We attempt to spoof the victim’s ECG model without prior knowledge of the victim’s ECG information. We investigated the feasibility of identifying a “master” collection of ECG signals that may coincide with ECG verification templates saved by authenticated users. Our experiments in four different ECG verification schemes show that these master ECG signals can effectively impersonate the ECG verification profiles of a wide range of users. These findings highlight significant vulnerabilities in current ECG-based authentication systems and can be used to strengthen ECG-based authentication systems.

Journal

N/A

Publication Name

ICA3PP 2024: 24th International Conference on Algorithms and Architectures for Parallel Processing

Volume

15256

ISBN/ISSN

978-981-96-1551-3

Edition

N/A

Issue

N/A

Pages Count

19

Location

Macau, China

Publisher

Springer Nature

Publisher Url

N/A

Publisher Location

Singapore

Publish Date

N/A

Url

N/A

Date

N/A

EISSN

N/A

DOI

N/A