Don’t Speak Anything: Deep Breath-Based Authentication Utilizing Sonar Signals on Smartphones
Kailu Zheng, Jiefan Qiu, Dongfu Zhu, Xiyu Wang, Kejiang Xiao, Xiaofu Chen · 2024
Benefiting from smartphones’ powerful computing and sensing capabilities, biometric authentication is widely used on them to conveniently verify user’s identity. However, most biometric features can be easily acquired or reproduced, making them vulnerable to replay and impersonation attacks. To address these issues, we propose DBreathLock, a non-contact identity authentication system that leverages a smartphone to capture unique biometric features from users’ deep breaths. Specifically, the smartphone emits inaudible frequency-modulated continuous waves (FMCW)-based sonar signals to capture chest-abdominal-joint (C-A-joint) movements, increasing the difficulty of impersonating legitimate users. By analyzing the energy features of CA-joint movements, we develop a Deep Breath Activity Detection (DBAD) method to detect deep breath fragments alongside the capability of resisting advanced replay attacks. To further fortify the resistance to advanced replay attacks, we employ the morphological features of C-A-joint movements and SVC model to recognize these attacks. Following this, we construct mutual information (MI) sequences via calculating the correlation between C-A-joint movements and breath sounds to reduce identity authentication failure caused by physiological changes. Then, a multi-stream identity authentication model is designed to verify legitimate users by fusing the features from C-A-joint movements, deep breath sounds, and MI sequences. Extensive real-world experiments involving 20 users demonstrate that DBreathLock achieves an authentication accuracy of 98.33%. Additionally, it successfully defends against both advanced replay and impersonation attacks.