跳到正文
arXiv:cs.LG· Ryan Swift·· 4 小时前

CPU-Auth:利用 DVFS 侧信道实现设备指纹认证

CPU-Auth: Device Fingerprinting for Authentication via DVFS Side-Channel

AI 导读

CPU-Auth 是一种基于 CPU 物理特性差异的新型认证机制,通过在浏览器内远程测量 DVFS 调频调速器的行为,提取 CPU 唯一属性构建硬件级设备指纹。研究在超过 50,000 条数据轨迹上使用距离度量与深度学习方法评估其性能。该工作是更大研究项目的一部分,本报告仅反映该小组成员所作的贡献。

正文

View PDF HTML (experimental)

Abstract:Lack of effective authentication has resulted in numerous security and privacy breaches, including unauthorized access to protected information, identity theft, and fraud. One approach to mitigating such attacks is Multi-Factor Authentication (MFA), in which users must provide multiple pieces of information for authentication. Some secondary authentication factors include SMS text verification codes, biometrics, and tokens. Each contains at least one notable flaw: SMS is notoriously insecure; biometrics rely upon access to sensitive personal data; and tokens require dependence on third-party providers (e.g. OAuth providers). This work explores CPU-Auth, a novel authentication mechanism based on unique variations in the physical characteristics of the CPU of a computing device. By measuring the behavior of the Dynamic Voltage and Frequency Scaling (DVFS) governor remotely from within a browser, unique properties of the CPU can be leveraged to establish a hardware-based device fingerprint for use in CPU-Auth. The performance of CPU-Auth is evaluated on over 50,000 data traces using distance-based and deep learning methods. CPU-Auth is part of a larger research project, and the results provided in this report reflect only the contributions made to the project by members of this group.
Comments: 13 pages
Subjects: Cryptography and Security (cs.CR); Machine Learning (cs.LG)
Cite as: arXiv:2610.10766 [cs.CR]
  (or arXiv:2610.10766v1 [cs.CR] for this version)
  https://doi.org/10.48550/arXiv.2610.10766

arXiv-issued DOI via DataCite (pending registration)

Submission history

From: Ryan Swift [view email]
[v1] Wed, 7 Oct 2026 18:27:17 UTC (15 KB)

来源:arXiv:cs.LG · arxiv.org