Research Article

Security Analysis and Bypass User Authentication Bound to Device of Windows Hello in the Wild

Figure 4

Detailed protocol flow: setting up the gesture. Mutual authentication is performed between the user and the server, which involves verifying the user with the device and authenticating the device with the Microsoft server. Through this process, the user’s account and the device are bound.