Most electronic devices utilize mechanical keyboards to receive inputs, including sensitive information such as authentication credentials, personal and private data, emails, plans, etc. However, these systems are susceptible to acoustic side-channel attacks. Researchers have successfully developed methods that can extract typed keystrokes from ambient noise. As the prevalence of keyboard-based input systems continues to expand across various computing platforms, and with the improvement of microphone technology, the potential vulnerability to acoustic side-channel attacks also increases. This survey paper thoroughly reviews existing research, explaining why such attacks are feasible, the applicable threat models, and the methodologies employed to launch and enhance these attacks.
翻译:大多数电子设备采用机械键盘接收输入信息,包括认证凭证、个人隐私数据、电子邮件、计划等敏感信息。然而,这些系统容易遭受声学侧信道攻击。研究人员已成功开发出能从环境噪声中提取击键内容的方法。随着键盘输入系统在各种计算平台上的普及以及麦克风技术的改进,针对声学侧信道攻击的潜在脆弱性也随之增加。本综述论文全面回顾了现有研究,阐释了此类攻击为何可行、适用的威胁模型,以及用于发起和优化这些攻击的方法论。