2019 IEEE 28th International Conference on Enabling Technologies: Infrastructure for Collaborative Enterprises (WETICE) 2GesturePIN: Securing PIN-based Authentication on Smartwatches Meriem Guerar, Luca Verderame Mauro Migliardi Alessio Merlo DIBRIS DEI DIBRIS University of Genova University of Padua University of Genova Genova, Italy Padua, Italy Genova, Italy
[email protected] [email protected] [email protected] Abstract—Smartwatches offer new capabilities to develop so- shoulder surfing and video recording attacks) and can be easily phisticated applications that make daily life easier and more bypassed [2]–[4]. Therefore, such mechanism is currently too convenient for consumers, and are becoming increasingly ubiq- unreliable for security-sensitive operations (e.g, Payment using uitous. The kind of services these devices are capable to provide include applications for mobile payment, ticketing, identification, Samsung pay, Apple pay and Android pay) on smartwatches. access control, etc. While this makes modern smartwatches very The adoption of pattern locks as an alternative to PIN does powerful devices, it also makes them very attractive targets for not provide stronger security guarantees [2], [5]. attackers. PINs and Pattern Lock have been widely used in Although TEE offers a trusted user interface (UI) which smartwatches for user authentication, however, those types of ensures that malware running on the device cannot steal data passwords are not robust against various forms of attacks, such as side channel, phishing, smudge, shoulder surfing and video displayed or typed on the screen, this is not sufficient to recording attacks. In this work, we propose 2GesturePIN, a new prevent data leakage from other components of the device authentication method that allows users to authenticate securely that interact with the TEE (e.g., accelerometer, gyroscope, and to their smartwatches and sensitive services through solely two orientation sensors), as they allow to carry out side channel gestures.