Exploring the Vulnerability of ECG-Based Authentication Systems Through A Dictionary Attack Approach
摘要
Electrocardiogram (ECG)-based authentication has gained popularity recently, but its security measures have not been thoroughly explored. In this paper, we explore dictionary attacks against ECG authentication systems. We attempt to spoof the victim’s ECG model without prior knowledge of the victim’s ECG information. We investigated the feasibility of identifying a “master” collection of ECG signals that may coincide with ECG verification templates saved by authenticated users. Our experiments in four different ECG verification schemes show that these master ECG signals can effectively impersonate the ECG verification profiles of a wide range of users. These findings highlight significant vulnerabilities in current ECG-based authentication systems and can be used to strengthen ECG-based authentication systems.