Visible to the public Inferring Mobile Payment Passcodes Leveraging Wearable Devices

TitleInferring Mobile Payment Passcodes Leveraging Wearable Devices
Publication TypeConference Paper
Year of Publication2018
AuthorsWang, Chen, Liu, Jian, Guo, Xiaonan, Wang, Yan, Chen, Yingying
Conference NameProceedings of the 24th Annual International Conference on Mobile Computing and Networking
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-5903-0
KeywordsHuman Behavior, mobile payment passcode inference, passcode input scenarios, pubcrawl, Resiliency, Scalability, Wearable Device, wearables security
AbstractMobile payment has drawn considerable attention due to its convenience of paying via personal mobile devices at anytime and anywhere, and passcodes (i.e., PINs) are the first choice of most consumers to authorize the payment. This work demonstrates a serious security breach and aims to raise the awareness of the public that the passcodes for authorizing transactions in mobile payments can be leaked by exploiting the embedded sensors in wearable devices (e.g., smartwatches). We present a passcode inference system, which examines to what extent the user's PIN during mobile payment could be revealed from a single wrist-worn wearable device under different input scenarios involving either two hands or a single hand. Extensive experiments with 15 volunteers demonstrate that an adversary is able to recover a user's PIN with high success rate within 5 tries under various input scenarios.
URLhttp://doi.acm.org/10.1145/3241539.3267742
DOI10.1145/3241539.3267742
Citation Keywang_inferring_2018