论文标题
物联网下降锁:无线指纹盗窃使用黑客智能锁
IoT Droplocks: Wireless Fingerprint Theft Using Hacked Smart Locks
论文作者
论文摘要
电子锁可以提供安全性和便利性的功能,指纹读取器在这些产品中越来越常见。当配备无线收音机时,它们成为一个智能锁,并加入了数十亿个物联网设备,使我们的世界扩散。但是,这种功能也可以用来将智能锁转换为指纹收割机,这些收割机在不知情的情况下损害了个人的安全性。我们将其命名为Droplock攻击。本文展示了收获技术的工作原理,表明可以看出现成的智能锁可以进行不可见的修改以执行此类攻击,讨论对智能设备设计和使用的影响,并呼吁更好地制造商和对此问题的公共处理。
Electronic locks can provide security- and convenience-enhancing features, with fingerprint readers an increasingly common feature in these products. When equipped with a wireless radio, they become a smart lock and join the billions of IoT devices proliferating our world. However, such capabilities can also be used to transform smart locks into fingerprint harvesters that compromise an individual's security without their knowledge. We have named this the droplock attack. This paper demonstrates how the harvesting technique works, shows that off-the-shelf smart locks can be invisibly modified to perform such attacks, discusses the implications for smart device design and usage, and calls for better manufacturer and public treatment of this issue.