Android Fingerprint Sensor: Pitfalls and Challenges
Luminita Apostol, Ciprian Dobre · 2018
In the last four years, the number of smartphones capable to read user fingerprints in order to perform authorization and authentication has tripled. Also, after the introduction of biometric payment services, fingerprint scanner driven authentication became more popular and the variety of smartphones equipped with this kind of sensor multiplied. However, the implementation methods are directly handled by manufacturers, who are often making decisions under the pressure of a short time-to-market. Starting from these facts, scholars and industry leading experts started to research the documentation in order to analyze the privacy and security flaws of the existing implementations. the assessment of Android good practice advises has revealed that some devices were not compliant, due to the fact that architecture could be attacked by an adversary both from the external world and by using malicious applications. Most common types of attacks against fingerprint authentication which could be demonstrated were aiming either to confuse the user in order to perform a malicious operation without a proper context or by employing custom-made molds of the user thumb minutiae. This paper analyses former and current issues affecting the fingerprint authentication in mobile devices powered by the Android operating system.