Research Article

Attack Potential Evaluation in Desktop and Smartphone Fingerprint Sensors: Can They Be Attacked by Anyone?

Table 8

Attack potential calculation for cooperative attacks on smartphone fingerprint sensors. Scores assigned according to the classification from Common Criteria [16, p. 429].

ā€‰Preparation phasePAI construction + exercising phaseAttack execution phaseTotal factor ratingScore

Elapsed time<1 day (capture subject is cooperative)<1 day or <1 week (different material difficulty)Few seconds (perform attack)<1 week or <2 weeks1.5

ExpertiseLayman (materials can be obtained at normal stores)Layman (easy to create)Layman (not much expertise needed)Layman0

Knowledge of TOEPublic (well known on the internet that it works)Public (manuals can be found on the internet)Public (no knowledge needed)Public0

Window of opportunityUnnecessary (no access to TOE needed)Easy (access to TOE for practicing)Easy (high chance the PAI will work)Easy1

EquipmentStandard (no equipment needed)Standard (but it is necessary to buy the TOE, which can be expensive)Standard (no equipment needed)Standard2

Overall attack rating4.5 (Basic)

Attack resistanceMinimum