← 资料库索引 ← 论文 原始链接 ↗ 🔍
论文

传感器的工厂校准指纹识别(Factory Calibration Fingerprinting of Sensors,IEEE TIFS) 原文标题:

发表时间:(页面未标注)采集时间:2026-10-09 10:58:24来源:www.cl.cam.ac.uk原文语言:en状态:完整

内容概要总结

本文是发表于 IEEE Transactions on Information Forensics and Security 的论文《Factory Calibration Fingerprinting of Sensors》(即 SensorID 工作,作者 Jiexin Zhang、Alastair R. Beresford、Ian Sheret)。论文提出一种新型指纹识别——工厂校准指纹识别攻击,通过分析现代智能手机中加速度计、陀螺仪、磁力计的传感器输出,恢复出嵌入的每设备工厂校准数据(增益矩阵),从而绕过 iOS/Android 的追踪保护。核心结论与数据:iPhone 6S 的校准指纹估计约 67 比特熵(GYROID 约 42 比特 + MAGID 约 25 比特),极可能全局唯一(由生日问题算得两台 iPhone 6S 相同 SENSORID 几率约 0.0058%);分析来自 11 个厂商的 146 个 Android 设备型号,发现除 Pixel 1/1 XL 外的所有 Google Pixel 可被指纹识别,Pixel 4/4 XL 估计约 57 比特熵(若市场有 1 亿台,全局唯一概率约 97%)。攻击特征:实用(任何网站/应用可发起,无需权限或交互)、高效(<1 秒)、稳健(不随恢复出厂设置或系统更新改变,跨 16 个月测试稳定)。论文还定义了 GYROID、MAGID、ACCID 与 SENSORID 组合(见表 III)。论文披露后 Apple 在 iOS 12.2 添加随机噪声(CVE-2019-8541)、Google 在 Android 11 舍入输出;作者逆向分析表明 Apple 的修复(噪声范围 [-1997, 1997]×2-16 dps)仍可通过模拟退火最大似然搜索恢复增益矩阵,但需至少 50K 样本(200 Hz 下约 4.2 分钟)。

翻译内容

原文内容(English)

⚠ 说明:原文为 PDF(cl.cam.ac.uk/~jz448/publication/TIFS.pdf),直连抓取仅得 2 个文本块(疑似原始文本转储),改用浏览器 UA 下载 PDF 后用 pdftotext 提取全文。属长文,正文主体(摘要至结论)已完整翻译,仅「致谢」与「参考文献」两节([1]–[36] 条)从略。原文含图 1–7 与表 I–VI,表格已按文本还原,图片未纳入文字翻译。 结构对齐说明:原文(content_en)为 pdftotext 纯文本转储,除一处表格行(Table III/IV 表头)被误判为 `#` 标题外无任何 Markdown 标题结构;为与原文结构一致(门禁 V03),译文仅保留文档主标题为一级标题,其余章节标题降为粗体。

IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY 1

传感器的工厂校准指纹识别(Factory Calibration Fingerprinting of Sensors)

Jiexin Zhang, Alastair R. Beresford, and Ian Sheret

摘要

设备指纹识别旨在生成一个独特的签名或指纹,以唯一标识单个计算设备。指纹可能构成隐私关切,因为应用程序和网站可以用它们来追踪用户的在线活动。为保护用户隐私,Android 和 iOS 都纳入了多种防止此类追踪的措施。在本文中,我们提出一种新型的指纹识别,即工厂校准指纹识别,它绕过了现有的追踪保护。我们的攻击仅通过对传感器输出的仔细分析,就从现代智能手机中普遍存在的加速度计、陀螺仪和磁力计传感器里恢复出嵌入的每设备工厂校准数据。我们讨论了每种传感器的工厂校准行为,并表明该校准指纹生成迅速、不随时间或恢复出厂设置而改变,且无需用户任何特殊权限即可用于跨应用和网站追踪用户。我们发现,该校准指纹对 iOS 设备而言极可能是全局唯一的,iPhone 6S 的估计熵为 67 比特。此外,我们分析了来自 11 个厂商的 146 个 Android 设备型号,发现该攻击也适用于较新的 Google Pixel 设备。对于 Pixel 4/4 XL,我们估计校准指纹提供约 57 比特的熵。在我们披露之后,Apple 在 iOS 12.2 中部署了一项缓解措施,Google 在 Android 11 中部署了缓解措施。我们分析了 Apple 的修复,表明该缓解措施并不完美,尽管在大多数威胁模型中很可能是足够的。

I. 引言

当用户访问一个网站时,其 Web 浏览器会向网站提供一系列信息,包括浏览器的名称和版本、屏幕尺寸、已安装的字体等等。表面上,这些信息允许网站提供极佳的用户体验。遗憾的是,同样的信息也可以被用来追踪用户。特别是,这些信息可以被用来生成一个独特的签名或设备指纹,以识别用户。类似地,移动应用开发者也可以利用软件和硬件的特性来生成设备指纹。

意识到对用户隐私的潜在风险,iOS 和 Android 都纳入了防止此类追踪的措施。在 iOS 上,开发者自 iOS 7 起就无法访问 UDID(唯一设备标识符)、IMEI(国际移动设备身份码)以及硬件模块的 MAC 地址。Android O 上也部署了类似的限制;即使用户授予应用诸如 READ_PHONE_STATE 这样的危险权限,开发者也无法获取不可重置的唯一硬件标识符。虽然在 iOS 和 Android 上都仍然可以通过广告标识符来追踪用户,但这种方法有若干缺点。首先,两个平台都允许用户随时重置这个标识符,iOS 还提供了一个选项来限制对该标识符的访问。此外,请求该标识符但不提供任何应用内广告的应用会被 App Store 拒绝。最后但同样重要的是,广告标识符无法从移动浏览器访问。类似地,虽然 Android 仍然允许应用访问 ANDROID_ID,但它无法从网站获取,且其值自 Android 8 起按签名密钥和用户限定范围。同一设备上的不同应用会有不同的 ANDROID_ID 值,而恢复出厂设置或 APK 签名密钥变更也可能改变其值 [1]。因此,它无法被用于跨应用和网站追踪用户。

我们开发了一种新型的指纹识别攻击——工厂校准指纹识别攻击,它可以绕过这些限制。现代移动设备出厂时附带各种嵌入式运动传感器,应用依赖它们来提供丰富功能,包括锻炼追踪和改进的用户交互。嵌入式传感器制造过程中的自然差异意味着每个传感器的输出都是独特的,因此这种自然差异可以被利用来创建设备指纹。

先前的工作直接将机器学习技术应用于传感器数据,试图为智能手机创建设备指纹;这已被证明是无效的(见第 VII 节)。在我们的攻击中,我们不是把传感器输出喂给机器学习算法,而是从陀螺仪、加速度计和磁力计的输出中推断出每设备的工厂校准数据,以构建一个全局唯一的指纹。总体而言,我们的攻击具有以下优势:

  • 实用:该攻击可以由任何网站或任何应用在易受攻击的设备上发起,无需用户明确确认或交互。
  • 高效:该攻击生成指纹耗时不到一秒。
  • 唯一:该攻击为易受攻击的设备生成全局唯一的指纹。
  • 稳健:校准指纹从不改变,即使经过恢复出厂设置。
  • 有效:该攻击提供了一种有效手段,可在用户浏览 Web 以及在其设备上的应用之间切换时追踪用户。

在我们之前的研究中,我们主要聚焦于 iOS 设备,并在 iOS 中可用的陀螺仪和磁力计数据上证明了其有效性 [2]。本文扩展了我们之前的工作:我们呈现了关于 iOS 设备加速度计校准的最新发现(第 III-E 节);我们对流行的 Android 设备型号进行了大规模的工厂校准行为分析(第 III-F 节);我们针对 Google Pixel 手机将校准指纹与 Fingerprintjs2 指纹进行了比较(第 IV-B 节);我们分析了易受攻击的 Pixel 设备的校准指纹并估计了每个型号的熵(第 V-B 节)。

我们遵循了协调披露程序,并于 2018 年 8 月 3 日向 Apple、2018 年 12 月 10 日向 Google 报告了该漏洞。在 iOS 12.2 中,Apple 采纳了我们的建议,向传感器输出添加了随机噪声(CVE-2019-8541),而 Google 决定在 Android 11 中将传感器输出舍入到标称增益的倍数。此外,Apple 默认移除了 Mobile Safari 对运动传感器的访问,并在后续版本中也移除了 WebKit 对运动传感器的访问。然而,在本文中我们表明 Apple 的修复并不完美,因为如果可获取更多传感器数据,仍然可以提取出校准指纹(第 VI 节)。

我们在本文中做出以下贡献:

1)我们引入了一种新的设备指纹识别方法:工厂校准指纹识别攻击。
2)我们描述了如何从近期智能手机上发现的加速度计、磁力计和陀螺仪中提取工厂校准数据。
3)我们证明,磁力计和陀螺仪的工厂校准数据共同构成一个可靠的 iOS 设备指纹,且在恢复出厂设置或操作系统更新后不会改变。
4)我们收集了 870 台 iOS 设备的运动传感器数据,并表明我们的方法可以生成一个全局唯一的标识符;我们表明 iPhone 6S 的校准指纹约有 67 比特的熵。
5)我们将我们的方法实现为一个 iOS 应用,并发现该方法轻量且高效:数据收集和处理通常在总共不到一秒内完成。
6)我们对来自 11 个厂商的 146 个 Android 设备型号的运动传感器校准进行了大规模分析。我们发现,除 Pixel 1/1 XL 之外的所有 Google Pixel 手机都可以被我们的攻击指纹识别;我们表明 Pixel 4/4 XL 的校准指纹约有 57 比特的熵。
7)我们分析了 Apple 的修复,并表明它并不完美:用约 50K 个样本即可提取出确切的指纹。

II. 背景

现代智能手机中使用的运动传感器(包括加速度计、陀螺仪和磁力计)基于 MEMS(微机电系统)技术,使用微加工来模拟机械部件。加速度计和陀螺仪分别测量设备在各个轴上的比力和旋转速度,而磁力计测量相对于设备的地球磁场。这些传感器在现代移动设备中无处不在。尽管 MEMS 技术极大地降低了运动传感器的尺寸和成本,但由于各种类型的误差,MEMS 传感器通常不如其光学对应物精确。一般而言,这些误差可以分为确定性和随机两类:随机误差通常由干扰传感器输出的电子噪声引起,它们随时间变化,必须以随机方式建模;确定性误差由制造缺陷产生,可分为三类:偏置(bias)、比例因子(scaling factor)和非正交失准误差(nonorthogonality misalignment errors)[3], [4]。

校准旨在识别并去除传感器中的确定性误差。许多商用传感器经过工厂校准,其校准参数存储在固件或非易失性存储器中,从而开箱即用即可提供准确的测量 [5]。在移动设备的语境中,每设备校准的主要好处是它允许更准确的姿态估计 [6]。相比之下,低成本智能手机中嵌入的传感器通常校准不佳,因为工厂校准成本高且复杂 [7]。因此,对于单个制造商而言,传感器校准的选择是一个工程权衡。

MEMS 传感器通常通过一个模数转换器(ADC)模块,将模拟测量值转换并存储在数字寄存器中。对于一个三轴运动传感器,令 A = [Ax, Ay, Az]T 为传感器 ADC 输出。考虑所有三种确定性误差,运动传感器的输出可以用以下方程表示 [8]:

Ox   Sx 0 0   1 Nxy Nxz   Ax + Bx
Oy =  0 Sy 0   Nyx 1 Nyz   Ay + By    (1)
Oz   0 0 Sz    Nzx Nzy 1   Az + Bz

这里,Si ∈ S 是比例因子;Nij ∈ N 表示轴 i 与 j 之间的非正交性;Bi ∈ B 是偏置。传感器的灵敏度或增益定义为输出信号与所测量属性之间的比率。传感器的标称增益是传感器的预期工作灵敏度。它是一个单一值,通常在传感器数据表中记录。在本文中我们用 F 表示传感器的标称增益。如果一个传感器是理想的,其比例矩阵 S 和非正交矩阵 N 应分别为 F × I 和 I,其中 I 是单位矩阵。然而,由于误差的存在,比例因子可能高达标称增益的 2% [9]。上述方程可以进一步简化为:

O = G(A + B)    (2)

其中 G = SN 被称为增益矩阵。

已经提出了无数种校准技术,用于在制造过程中计算增益矩阵和偏置向量 [3]。厂商也可以选择只校准偏置向量以降低成本。一旦工厂校准完成,传感器的校准参数将存储在设备内部的非易失性存储器中,且不应随时间改变 [10], [11]。制造商所使用的校准过程的细节并未公开。

III. 攻击方法

本文中攻击者的目标是从智能手机内置的运动传感器中获取一个可靠的指纹。我们的威胁模型如下。我们假设攻击者能够记录来自智能手机的运动传感器样本。如果用户安装了攻击者控制的应用,或访问了攻击者控制的网站(目前仅限加速度计和陀螺仪),攻击者就能做到这一点。此外,我们假设嵌入在应用或网页中的软件能够与攻击者控制的远程服务器通信;这对应用和网页而言通常都是如此。我们首先看 iOS 设备中的陀螺仪;其他传感器和设备的校准指纹识别稍后讨论。

图 1:恢复设备校准指纹的一般步骤
数据收集 → 数据预处理 → ADC 值估计 → 增益矩阵估计 → 有效性检查 → 指纹生成(含"更新 Ĝ / 失败 / 通过"分支)

表 I:iOS 设备陀螺仪估计标称增益

型号标称增益(mdps)
iPhone 5S/6/6 Plus/6S/6S Plus/7/7 Plus/8/8 Plus/SE
iPhone X/XS/XS Max61
iPad Pro 9.7/10.5/12 inch
iPhone 4/4S/5/5C/5S, iPad 3/Mini/Mini 4/Mini Retina/Air/Air 270

iPhone 5S 设备有两种可能的标称增益值。

A. iOS 设备上的陀螺仪校准

我们发现 iOS 设备中陀螺仪的增益矩阵是工厂校准的,并基于陀螺仪输出进一步估计了不同设备型号的标称增益 [2]。特别是,表 I 列出了我们所测量的所有 iOS 设备陀螺仪的标称增益(以 mdps,即毫度/秒计)。估计的 61 mdps 标称增益表明该传感器很可能被配置为 ±2000 dps 的测量范围和 16 位的分辨率(4000/216 ≈ 0.061)。此外,我们发现 iOS 中运动传感器输出的小数部分只有 16 位分辨率。对此有几种可能的原因,但最简单的解释是增益矩阵 G 中的值被存储为一个分辨率 2-16 度/秒(dps)的有符号整数。经过调查,我们发现每一台使用 M 系列运动协处理器的设备(Apple 于 2013 年 9 月随 iPhone 5S 发布)都表现出这种模式。运动协处理器的目的是把传感器数据的收集和处理从 CPU 卸载出去。然而,对于 iPhone 4 和 iPhone 4S 等较旧设备,增益矩阵值的存储精度更高,校准涉及在应用增益后向下截断到 2-16 dps。使用 M 系列运动协处理器的完整设备列表可在线找到。

恢复设备校准指纹的一般步骤如图 1 所示,包括:数据收集、数据预处理、ADC 值估计、增益矩阵估计、有效性检查和指纹生成。

数据收集。 我们通过一个移动应用以最大采样频率从陀螺仪收集少量样本。根据经验,我们发现不到 1 秒内收集的 100 个样本就足够了。我们用 O = [O1, O2, · · · , ON] 表示收集到的数据,其中 Oi = [Oix, Oiy, Oiz]T 是一个 3×1 向量。

数据预处理。 收集数据后,我们通过对所有三个轴的连续输出求差来计算 ΔO。换句话说,ΔO 由以下方程计算:

ΔO = [O2 - O1, O3 - O2, · · · , ON - ON-1]

然后我们只选择一个子集数据 ΔO(i),其中其所有元素的绝对值都低于标称增益的某个倍数:

ΔO(i) = {Oj ∈ ΔO | max(|Oj|) < (i + 0.5)FG}

其中 i 是阈值。我们从 1 开始,每次迭代将其值加倍(即 (i+1) = 2(i)),直到该子集覆盖整个数据集(例如 ΔO(i) = ΔO)。在每次迭代中,我们把 ΔO(i) 喂给下一步并更新 Ĝ 的值。

ADC 值估计。 在这一步,我们旨在恢复 ΔAi,即连续 ADC 输出之间的差。由方程 2 我们有:

ΔAi = Ĝ-1ΔO(i)

其中 Ĝ-1 是增益矩阵 G 的逆。然而,此刻 G 的值是未知的。尽管如此,我们可以用其理想值 G0 = FG × I 来估计 G,其中 FG 是陀螺仪的标称增益。也就是说,在第一次迭代中我们令 Ĝ = G0,其中 Ĝ 是估计的增益矩阵。确定性误差相对较小,因此 Ĝ 应当相对接近 G0。

(图 1 展示了"更新 Ĝ"的迭代回路:若有效性检查失败则重新收集数据,通过则进入指纹生成。)

有效性检查。 为了量化 Ĝ 与 G 真值之间的偏差,我们定义估计误差 Ee ∈ R3×1 如下:

Ee = (ΔO - ĜΔA) / (N - 1)    (取 2-范数)

如果估计误差很小(即 max(Ee) < ε),那么 Ĝ 应当接近真实增益矩阵 G。否则,意味着 ADC 值估计不正确,这很可能是数据收集期间剧烈运动的结果。在这种情况下,我们需要收集另一批数据并重复这些步骤。

指纹生成。 陀螺仪校准指纹 GYROID 的生成,可以根据设备是否具有 M 系列协处理器分为两类。如果设备确实有 M 系列协处理器,GYROID 定义如下:

GYROID = round(Ĝ) - round(G0)    (3)

其中 Ĝ 和 G0 都以 2-16 dps 为单位。换句话说,GYROID 是以 2-16 dps 为单位减去标称增益后的增益矩阵 G。例如,前面例子中 iPhone XS 的 GYROID 为:

         14 -36 -11
GYROID =  11 33 22    (4)
         -4 -25 18

对于使用 M 系列协处理器的设备,我们可以简单地舍入 Ĝ 以获得真实的增益矩阵 G。

B. 来自移动网站的指纹识别

JavaScript 也为 Web 开发者提供了访问融合陀螺仪数据的 API。在本文中,我们称传感器数据是融合的(fused),如果其值是向原始传感器数据应用时变偏置校正的结果。在实践中,通常使用卡尔曼滤波器来组合或融合加速度计和陀螺仪输入,以计算校正后的偏置值。图 2(a) 展示了当设备静止在桌面上时,通过移动版 Safari 从一台 iPad Air 收集的 500 个连续陀螺仪样本。如图 2(a) 所示,融合数据中的量化仍然可见,因为陀螺仪 ADC 输出是整数。然而,由于偏置校正,偏置上被加上了一个缓慢变化的连续分量。图 2(b) 表明,通过减去连续样本,偏置部分几乎可以被消除。因此,我们可以应用第 III-B 节所述的相同技术来恢复增益矩阵。

C. 实用校准指纹识别攻击

要发起校准指纹识别攻击,攻击者可以使用由攻击者编写的应用,或让用户访问攻击者控制的任何网站,从任何设备收集陀螺仪样本。攻击者随后可以从样本生成设备指纹(例如 GYROID)并将其存储在一个数据库中。然后,攻击者可以查询该数据库,以确定某个特定物理设备何时使用某个特定应用或访问某个特定网站。GYROID 在数据库中的生成和查询细节,因收集来源(应用或 Web)和设备型号而异。

具体而言,对于运行在具有 M 系列运动协处理器设备上的应用,它们可以遵循第 III-B 节的步骤来恢复确切的 GYROID。否则,如果设备没有运动协处理器(例如 iPhone 4/4S/5),或者攻击者只能访问融合的陀螺仪数据(例如通过 JavaScript),则有两种选项来确定数据库中的两个 GYROID 条目是否代表同一个物理设备。

  • 选项 1(聚类):攻击者可以直接把估计的增益矩阵 Ĝ 用作 GYROID 并存入数据库。对于每一台相同型号的新设备,他们可以计算其 Ĝ 并比较其 Ĝ 与数据库中那些 Ĝ 之间的欧几里得距离。如果它们接近,那么攻击者就知道它们来自同一台设备(Ĝ 的熵在第 V-A 节讨论)。
  • 选项 2(舍入):攻击者仍然可以使用方程 3 来生成 GYROID。然而,估计的 GYROID 可能与真实值相差最多 ±1(对于 9 个值中的每一个)。因此,攻击者可以存储估计的 GYROID 并执行模糊查询(即接受每个元素 ±1 的波动)。请注意,与选项 1 相比,此选项提供的熵更少。

D. 指纹识别其他运动传感器

磁力计。 我们发现 iOS 设备中的磁力计也可以被指纹识别。与陀螺仪类似,磁力计的原始读数只有 2-16 µT(微特斯拉)的分辨率。在为我们数据集中的每个设备型号减去连续的原始磁力计测量值之后,我们观察到四种模式类型:

  • Type I(灵敏度不同,波动可忽略):Type I 设备每个轴有略微不同的灵敏度。
  • Type II(灵敏度固定,波动中等):Type II 设备每个轴灵敏度相同,但每个簇内存在中等波动。
  • Type III(灵敏度不同,波动中等):Type III 设备每个轴有略微不同的灵敏度,且每个簇内存在中等波动;这种情况下数据的量化很明显。
  • Type IV(灵敏度不同,波动剧烈):Type IV 设备在磁力计输出上表现出剧烈波动。在这种情况下,数据的量化不如其他情况明显。

我们总结了不同 iOS 设备型号的磁力计类型及其估计标称增益,见表 II。

表 II:不同 iOS 设备型号的磁力计类型

类型型号标称增益(µT)
Type IiPhone 4S/5/5C/5S/6/6 Plus、所有 iPad 型号0.35/0.28/0.17
Type IIiPhone 6S/6S Plus/7/7 Plus/SE0.075
Type IIIiPhone 8/8 Plus0.075
Type IViPhone X/XS/XS Max0.075

Type I 设备有三种可能的标称增益值。

总体而言,对四种模式的观察揭示了不同的底层校准程序。对于所有四种类型的设备,我们可以使用第 III-B 节所述的相同方法获得磁力计指纹(即 MAGID)。虽然磁力计的增益矩阵不是以 2-16 µT 分辨率存储的,但攻击者可以使用第 III-D 节讨论的相同技术,通过聚类或舍入来发起攻击。与陀螺仪相比,原始磁力计数据目前在主流浏览器中无法访问。尽管如此,MAGID 为 GYROID 提供了额外的熵。因此,在分析应用时,我们可以把它们组合成一个更细粒度的指纹。

加速度计。 我们在较老一代的 iOS 设备(包括 iPhone 4S 和 iPad Mini)上观察到加速度计有类似的量化模式。例如,图 3 展示了来自一台 iPhone 4S 的 2 000 个加速度计输出之间的连续差值。量化很清楚,因此我们可以应用第 III-B 节所述的相同方法来恢复加速度计指纹。请注意,这些设备不使用 Apple 运动协处理器,因此攻击者需要使用第 III-D 节所述的技术来发起攻击。对于较新版本的 iOS 设备(如图 3 中也展示的 iPhone 5),Apple 使用了更高分辨率的加速度计,从而掩盖了输出中的量化。我们的攻击目前不能直接应用于这些设备。

在本文中,我们把 SENSORID 定义为各种独特传感器校准指纹的组合。就 iOS 设备而言,SENSORID 同时包括 GYROID 和 MAGID。对于较老版本的 iOS 设备(例如 iPhone 4S 和 iPad Mini),SENSORID 还包括加速度计指纹(即 ACCID)。

表 III:SENSORID 组成

SENSORID设备型号
ACCIDiPhone 4S, iPad Mini
GYROIDPixel 2/2 XL/3/3 XL/3a/3a XL/4/4 XL
MAGIDiOS 设备, Pixel 4/4 XL

E. 指纹识别 Android 设备

为研究 Android 设备是否易受类似指纹识别攻击的影响,我们使用四个自动化测试平台,从来自 11 个厂商的 146 个 Android 设备型号收集数据:BQ、Google、HTC、Huawei、LG、Motorola、Nokia、OnePlus、Samsung、Sony 和 Xiaomi(第 IV-B 节)。在我们测试过的所有 Android 设备中,我们发现除 Pixel 1/1 XL 之外的所有 Google Pixel 手机都可以被我们的方法指纹识别;我们没有在 Pixel C 平板上观察到每设备校准行为。此外,我们注意到应用于运动传感器的校准过程因设备型号而异。特别是,我们发现 Google Pixel 4 和 4 XL 中加速度计和陀螺仪的完整增益矩阵都是每设备校准的,而在其他 Pixel 设备中,只有加速度计增益矩阵的主对角线被校准。

图 4 展示了当 Pixel 3 和 Pixel 4 XL 静止在桌面上时收集的 2 000 个加速度计输出之间的连续差值。两种情况下加速度计输出中的量化都很明显。此外,该图表明 Pixel 3 中只有加速度计的比例矩阵被校准(即增益矩阵中只有主对角线元素被校准);在 Pixel 2/2 XL/3 XL/3a/3a XL 中也观察到相同的模式。图 4 还表明 Pixel 4 XL 中增益矩阵的所有 9 个值都被校准;在 Pixel 4 中也观察到相同的模式。除加速度计之外,Google Pixel 4 和 4 XL 中的陀螺仪也是每设备校准的。

除 Pixel 设备之外,我们注意到 Huawei Honor 20 Lite、MediaPad M3 Lite 10 和 MediaPad T3 10 中的加速度计,以及 BQ Aquaris X2 中的陀螺仪,每个轴具有不同的灵敏度。然而,这些型号我们每个都只有一台设备,因此无法确认它们是否为每设备校准。到目前为止,我们测试了 321 台独特设备(146 个独特设备型号);我们在测试过的任何其他 Android 设备型号上都没有观察到每设备校准行为。因此,在本文余下部分我们聚焦于 Google Pixel 设备。是否进行工厂校准的选择取决于各个制造商。对于易受攻击的 Google Pixel 手机,我们可以从 Android 应用和运行在 Android 浏览器上的网站两者提取 SENSORID。就 Google Pixel 4 和 4 XL 而言,SENSORID 同时包括 ACCID 和 GYROID。对于除 Pixel 1 之外的其他 Pixel 型号,SENSORID 只包括 ACCID。总而言之,表 III 列出了其 SENSORID 分别包括 ACCID、GYROID 和 MAGID 的所有设备型号。

IV. 评估

A. 指纹识别 iOS 设备

我们开发了一个网站和一个 iOS 应用来收集传感器数据。iOS 应用以 200 Hz 从运动传感器(加速度计、陀螺仪和磁力计)收集原始数据,且不要求用户以任何特定姿势放置设备。该应用还嵌入了一个 WebView;嵌入的 WebView 和单独的网站都通过 JavaScript 收集融合的加速度计和陀螺仪数据。

对于应用和网站,我们都使用默认配置下的 Fingerprintjs2 [12] 库来生成浏览器指纹,以供评估之用。除志愿者外,我们还从 Amazon Mechanical Turk 和 Prolific 招募参与者来下载应用并贡献传感器数据。此次公开数据收集活动已获得剑桥大学计算机科学与技术系伦理委员会的批准。

迄今为止,SENSORID 应用已从 795 台独特 iOS 设备收集了数据;其中 761 台包含 M 系列运动协处理器。此外,该网站还从另外 75 台设备收集了融合数据。一些用户选择多次参与本研究。因此,每台独特设备可能有不止一条记录。在应用和网站上,我们都要求用户告诉我们他们之前是否从这台设备提交过数据。

使用从 761 台带有 M 系列协处理器的 iOS 设备收集的原始陀螺仪数据,我们能够恢复出确切的 GYROID。对于另外 34 台不含 M 系列协处理器的设备,由于样本量小,我们使用第 III-D 节中的舍入选项来生成 GYROID。基于 GYROID,我们成功识别出由同一台设备提交的多条记录。这一点由用户提供的、关于他们之前是否从这台设备提交过样本的数据以及他们提交时的设备 IP 地址所证实。每台设备的 GYROID 都是不同的。

表 IV:iOS 设备指纹比较

设备数指纹组大小组数
870GYROID1870
795Fingerprintjs21391
102–3696
MAGID451
1775
Fingerprintjs2210
ACCID1308
2–3697
Fingerprintjs2451

表 V:Pixel 设备指纹比较

设备型号指纹组大小组数
Pixel 2/2 XLACCID146
Fingerprintjs2117
Pixel 3/3 XLACCID24
&41
Fingerprintjs252
Pixel 3a/3a XL71
ACCID161
Pixel 4/4 XLGYROID125
28
Fingerprintjs235
51
145
110
21
91
101
141

由于该网站只收集融合的陀螺仪数据,我们选择第 III-D 节中的舍入选项来生成 GYROID。然后,我们把它与我们从原始数据恢复出的 795 台设备的 GYROID 进行比较。结果,我们识别出 3 台同时通过网站和应用提交的设备。该应用还从内置 WebView 收集融合的传感器数据。对于这些数据,我们使用聚类方法来生成一组增益矩阵估计。然后,我们应用多元方差分析(MANOVA)技术来分析这些估计,并成功识别出数据集中的所有 795 台独特设备。特别是,我们还识别出 6 台通过该应用多次提交的设备。结果与我们从原始数据获得的结果相同。

此外,我们应用改进后的方法用舍入选项来指纹识别磁力计。在生成 MAGID 之后,我们按 MAGID 对设备分组,并将结果呈现在表 IV 中。在表中,组大小记录共享同一 MAGID 的不同设备的数量。因此,组大小为 1 意味着该设备在我们数据集中具有唯一的 MAGID。我们发现,10 个大小为 2 的组都是带有 Type I 磁力计的旧设备型号,表明它们相比其他设备在 MAGID 上碰撞的几率更高。原因是 Type I 设备的 MAGID 熵仅由比例矩阵(即 MAGID 中的主对角线元素)提供。尽管如此,MAGID 与 GYROID 正交,因此它们可以组合在一起提供额外的熵。

与对从内置 WebView 收集的数据的分析类似,我们使用第 III-D 节中的聚类选项来分析加速度计指纹,并应用 MANOVA 来识别独特设备。如第 III-E 节所讨论的,我们的攻击仅适用于较老一代的 iOS 设备。在我们的数据集中,这包括 9 台 iPhone 4S 设备和一台 iPad 3。我们对这 10 台设备应用我们的攻击,发现它们都有唯一的 ACCID。iPhone 4S 之前的其他 iOS 设备很可能也可以被我们的方法攻击,但我们没有这些设备的数据来证实。

最后,我们把 GYROID、MAGID、ACCID 与 Fingerprintjs2 的默认配置进行比较,后者利用字体检测、canvas、WebGL 等来指纹识别设备。表 IV 呈现了结果,并表明 GYROID、MAGID 和 ACCID 比传统浏览器指纹识别技术提供更多的熵。虽然 GYROID 对我们数据集中的每台设备都是唯一的,但 135 台 iPhone 7 设备中有 45 台具有相同的 Fingerprintjs2 指纹;这 45 台设备全部来自英国。就 ACCID 而言,它识别出所有 10 台独特设备,而 Fingerprintjs2 为两台 iPhone 4S 设备生成了相同的指纹;这两台设备都来自德国。结果表明 Fingerprintjs2 指纹可能与特定的手机配置相关。

我们还为带有 M 系列运动协处理器的 iOS 设备开发了一个概念验证应用。该应用实现我们的攻击以生成测试设备的 GYROID。代码用 Swift 4.1 编写,XCode 9.4.1。该应用收集 100 个原始陀螺仪样本并尝试生成 GYROID。如果失败(由于手机剧烈晃动),应用会自动再收集 100 个原始样本并重复该过程。总体而言,收集 100 个陀螺仪样本约需 0.5 秒,生成 GYROID 另需 0.01 秒。提取期间的剧烈运动可能需要额外的样本,但任务仍会在几百个样本内完成,耗时几秒。无论如何,生成的 GYROID 始终保持不变。概念验证网页和演示视频可在我们的网站上找到:https://sensorid.cl.cam.ac.uk。

B. 指纹识别 Google Pixel 设备

一般来说,由于市场份额相对较小,很难通过众包平台找到许多拥有 Pixel 设备的人。尽管如此,我们发现大多数在线应用测试平台都提供对 Pixel 设备的访问。因此,我们开发了一个 Android 应用来收集原始运动传感器数据并发回我们的服务器。与我们 iOS 应用所用的方法类似,我们的应用也嵌入了一个 WebView,通过 JavaScript 收集 Web 传感器数据以及由 Fingerprintjs2 生成的指纹。此外,该应用记录 ANDROID_ID,它对于应用签名密钥、用户和设备的每个组合都是唯一的,用于在我们的数据集中识别独特设备。

在我们的实验期间,我们在 AWS Device Farm、Firebase Test Lab、App Centre 和 Sauce Labs 上部署该 Android 应用,以从各种 Android 设备型号收集数据。由于我们只在除 Pixel 1/1 XL 之外的 Pixel 手机上发现每设备校准,我们聚焦于分析这些设备。最终,我们收集了来自 152 台独特 Pixel 设备的数据。

使用原始加速度计数据,我们为每台设备生成 ACCID,并使用聚类来确定两台设备是否具有相同的 ACCID。我们把结果与 Fingerprintjs2 在表 V 中比较。对于 Pixel 4 和 4 XL 设备,我们还计算了它们的 GyroID 并与其他指纹比较。如表所示,ACCID 和 GYROID 都唯一识别出每台 Pixel 设备,而多台设备具有由 Fingerprintjs2 生成的相同指纹。特别是,45 台 Pixel 4/4 XL 设备中有 14 台具有相同的 Fingerprintjs2 指纹。这很可能是因为当两台设备运行相同的 Android 版本时,默认配置下的嵌入式 WebView 不会暴露许多独特特征。如果 Fingerprintjs2 运行在 Android 浏览器中,该指纹很可能具有更多熵。然而,与作为硬件标识符的 SENSORID 不同,Fingerprintjs2 无法在用户跨 Android 浏览器移动时追踪他们。

此外,我们尝试使用通过嵌入式 WebView 中 JavaScript 收集的 Web 传感器数据为每台设备生成 SENSORID。然后我们基于它们的 SENSORID(由 Web 数据生成)使用聚类来区分设备。我们成功地按其 ACCID 识别出所有独特 Pixel 设备。对于 Pixel 4 和 4 XL 手机,我们还能够按其 GYROID 识别出每一台设备。

V. 讨论

在本节中,我们讨论关于本研究有效性的一些可能关切。

A. SENSORID 对 iOS 设备是否唯一?

为研究 SENSORID 有多唯一,我们首先研究所有估计标称增益为 61 mdps 的 iOS 设备的 GYROID。属于此类的设备型号可在表 I 中找到。我们选择这一类有两个原因。首先,此类中的所有设备型号都是包含 M 系列运动协处理器的现代设备,这使得提取其确切增益矩阵成为可能。其次,具有不同默认增益的设备可能具有不同的 GYROID 分布,因此我们选择较大的那一组,共包含 693 台设备。为简单起见,在以下分析中我们把 GYROID 记为 D ∈ Z3×3。

正态性分析。 为检验正态性,我们对 D 中的每个元素同时应用 Kolmogorov-Smirnov 检验和 Shapiro-Wilk 正态性检验。结果表明,D 中的非对角线元素具有很强的正态性,而主对角线元素(D11、D22、D33)在 0.05 显著性水平上被两种检验都拒绝。该结果表明我们可能需要对主对角线元素进行更细粒度的分析。当我们分别对每个设备型号的数据运行正态性检验时,我们发现主对角线元素也表现出很强的正态性。

相关性分析。 为检验相关性,我们对每个 Dij 运行 Pearson 相关检验,发现 D12 和 D13 分别在 0.01 显著性水平上与 D21 和 D31 强相关。因此,我们从熵计算中排除 D21 和 D31,以避免高估。

熵计算。 我们首先计算 D 中非对角线元素(排除 D21 和 D31)的熵。对于每个非对角线元素,我们从数据集中估计正态分布的参数,包括均值 µ 和标准差 σ。从技术上讲,由于每个元素只能是整数,它不是严格的正态分布。尽管如此,它是舍入的结果,因此我们仍可以使用正态分布来估计熵。

一般来说,一个离散随机变量 X 的熵,记作 H(X),可以由下式计算:

H(X) = - Σ P(xi) log2 P(xi)    (5)
     xi ∈ X

其中 P(xi) 是 X 等于 xi 的概率。在我们的情形中,我们把元素 Dij 视为变量 X。那么,由于 16 位分辨率,我们有 xi ∈ {-65535, . . . , 65535}。假设 X ∼ N(µ, σ2) 具有密度函数 f(x),那么我们可以按如下方式计算 P(xi):

        ∫(xi+0.5, xi-0.5) f(x) dx,   若 xi ∈ (-65535, 65535)
P(xi) = ∫(-65534.5, -∞) ... f(x) dx, 若 xi = -65535    (6)
        ∫(+∞, 65534.5) f(x) dx,      若 xi = 65535

通过这个方程,我们计算 D12、D13、D23 和 D32 的熵。对于主对角线元素(即 D11、D22 和 D33),我们按设备类型逐一计算它们的熵。这里,我们以 iPhone 6S 为例计算 GYROID 熵,因为它是我们数据集中最流行的设备型号(127 台设备)。对于这些 iPhone 6S 设备,我们采用类似的方法,同时应用方程 5 和 6 来计算熵。结果,我们估计 iPhone 6S 的 GYROID 约有 42 比特的熵。

通过同样的分析,我们估计 iPhone 6S 的 MAGID 熵。如果攻击者使用舍入选项(第 III-D 节)发起攻击,每个元素可能有 ±1 的不确定性。在这种情况下,我们估计 MAGID 包含约 25 比特的熵。如果攻击者选择聚类选项,MAGID 应具有更多熵。由于我们只有 10 台具有 ACCID 的旧一代 iOS 设备,我们不把 ACCID 纳入 SENSORID 熵计算。我们未观察到 MAGID 与 GYROID 之间强相关的证据。因此,我们估计 iPhone 6S 的 SENSORID 约有 67 比特的熵。

唯一性分析。 2017 年 4 月全球有 728M 台活跃 iPhone,iPhone 6S 设备占其中的 18% [13]。因此,大约有 131M 台 iPhone 6S 设备。由生日问题可知,两台 iPhone 6S 设备具有相同 SENSORID 的几率约为 0.0058%,表明它是一个全局唯一的设备指纹。此外,SENSORID 与其他指纹识别技术正交。因此,攻击者可以把 SENSORID 与其他元数据(例如系统语言)或其他指纹识别技术(例如 canvas 指纹)结合起来,以进一步提高指纹熵。

局限。 Kolmogorov-Smirnov 和 Shapiro-Wilk 正态性检验的结果都表明 D 中的值与正态分布一致,但实际分布在尾部区域可能并非正态分布。例如,制造商可能丢弃在增益矩阵中具有极端值的传感器;这会减少可用的熵。因此我们需要考虑非正态分布是否可能使我们的熵计算失效。

首先,值得一提的是,这种拒绝策略在实践中不太可能;工厂校准的一个关键好处是,具有异常物理增益的传感器在经校准后仍能表现良好。更重要的是,熵的计算由分布的核心形状主导,而我们在那里有丰富的数据。非高斯性可能影响分布的尾部,但这会对计算出的熵产生可忽略的影响。举一个具体的例子:我们发现 D 中的所有值都落在范围 (µ-4σ, µ+4σ) 内。如果我们假设该范围之外的值被丢弃,我们仍估计 iPhone 6S 的 SENSORID 提供约 67 比特的熵。

一个相关的关切是 D 中的值之间可能存在未被检测到的高阶相关性。类似的论点在这种情况下也适用:熵计算由(现在是多变量的)分布的核心主导,我们在那里有丰富的数据,且在那里我们没有看到非独立的证据。在尾部区域,非独立性可能未被检测到,但这会对计算出的熵产生很小的影响。

归根结底,给定来自未知分布的有限样本,熵的计算无法做到绝对严谨,但仍然可以进行彻底的分析,而 SENSORID 的估计熵因非高斯性或非独立性而出现重大错误的可能性极小。

B. Android 设备中的工厂校准

有 root 权限的 Android 手机在启动时可在本地文件系统中访问运动传感器的增益矩阵值。因此我们确认了我们对两台 Pixel 3 设备 ACCID 的不同估计是正确的,以及我们对一台 Pixel 4 设备估计的 ACCID 和 GYROID 值也是正确的。虽然 Pixel 3/4 中的磁力计也有一个完整的增益矩阵,但其值似乎对同一型号的所有设备都相同,因此不提供任何熵。其他 Android 设备中的运动传感器也可能是工厂校准的。如果校准仅限于偏移量(即偏置补偿),那么我们的方法是无效的,因为它针对的是增益矩阵,无法恢复偏置补偿。

为估计易受攻击的 Pixel 设备的 SENSORID 熵,我们把这些设备分为三类:Pixel 2 系列(Pixel 2/2 XL)、Pixel 3 系列(Pixel 3/3 XL/3a/3a XL)和 Pixel 4 系列(Pixel 4/4 XL)。对于每一类,我们分析每个值的正态性以及指纹中各值之间的相关性。对于 Pixel 2 和 3 系列,ACCID 只在前对角线(D11、D22、D33)上具有非零值,因此它比 Pixel 4 系列提供更少的熵。对于 Pixel 4 系列,我们发现 ACCID/GYROID 中某些非对角线值彼此强相关。因此,我们在熵计算中只保留依赖变量中的一个,以避免高估。

使用与我们之前在 iOS 磁力计工作上所用类似的方法,我们基于攻击者选择使用舍入选项发起攻击(每个元素有 ±1 的不确定性)这一假设来估计熵。结果呈现在表 VI 中。此外,我们发现 Pixel 4 系列设备中 GYROID 的非对角线元素与 ACCID 中的非对角线元素强相关。这很可能是因为加速度计和陀螺仪被集成在同一个芯片中(LSM6DSR)。因此,为估计 SENSORID(ACCID 和 GYROID 的组合)的熵,我们简单地把 ACCID 中主对角线变量提供的熵加到 GYROID 提供的熵上。结果,我们估计 SENSORID 提供约 57 比特的熵;精确的熵估计很困难,因为我们只有来自 45 台 Pixel 4/4 XL 设备的数据,而在此前针对 iOS 的研究中我们使用了来自 127 台 iPhone 6S 设备的数据。假设我们的熵估计是准确的,并把此作为生日问题的一个例子来分析,如果市场上有 1 亿台 Pixel 4/4 XL 设备,那么每台设备都具有全局唯一 SensorID 的概率约为 97%。

表 VI:SENSORID 熵估计(Pixel 设备)

指纹设备型号设备数熵(比特)
ACCIDPixel 2/2 XL46~14
ACCIDPixel 3/3 XL/3a/3a XL61~12
ACCIDPixel 4/4 XL45~25
GYROIDPixel 4/4 XL45~45

C. SENSORID 是否与制造批次相关?

为回答这个问题,我们首先研究 SENSORID 与设备国家之间的相关性,后者由用户提交数据时的 IP 地址推断。我们在 0.05 显著性水平上未发现强相关的证据。此外,我们在 Apple Store 从 25 台 iOS 设备收集了陀螺仪数据。其中一些设备具有相似的序列号,这表明它们可能来自同一制造批次。然而,这些设备的 GYROID 差异显著。此外,来自 Apple Store 的设备与我们从其他渠道收集的设备的 GYROID 分布没有显著差异。

D. SENSORID 的一致性

在过去 16 个月中,我们没有观察到测试设备的 SENSORID 有任何变化。我们的数据集包括运行 iOS 9/10/11/12 的 iOS 设备以及运行 Android 8/9/10 的 Pixel 设备。我们测试了指南针校准、恢复出厂设置和更新操作系统;SENSORID 始终保持不变。我们还尝试在不同位置和不同温度下测量传感器数据;我们确认这些因素也不改变 SENSORID。

E. 影响与负责任披露

我们遵循了负责任披露程序,并于 2018 年 8 月 3 日向 Apple、2018 年 12 月 10 日向 Google 报告了该漏洞。特别是,我们提出了两种可能的对策。第一种是向每个 ADC 输出添加一个随机噪声 η ∈ R3×1,来自范围 [-0.5, 0.5] 内的均匀分布。添加的噪声会混淆量化的影响,使攻击变得困难得多。我们提出的第二种方法是把校准后的传感器输出舍入到标称增益的最近倍数。这种方法更实用,因为它不需要访问 ADC 值。

在 iOS 12.2 中,Apple 采纳了我们的建议,向传感器输出添加了随机噪声(CVE-2019-8541)。此外,Apple 默认移除了 Mobile Safari 对运动传感器的访问,并在后续版本中也移除了 WebKit 对运动传感器的访问。最近,Google 在 Android 11 中推送了一项修复,把运动传感器输出舍入到标称增益的最近倍数。

在运行 iOS 12.2 之前的 iOS 版本时,所有带运动传感器的 iOS 设备都可以被此方法指纹识别,包括 iPhone XS 和 iPhone XS Max。SENSORID 既可由应用生成,也可由移动网站生成,且无需用户交互。两个主流 iOS 浏览器(Safari、Chrome、Firefox 和 Opera)以及隐私增强浏览器(Brave 和 Firefox Focus)都易受这种基于校准的指纹识别攻击,即使开启了指纹识别保护模式。对于运行 Android 10 的 Google Pixel 手机,我们注意到一些隐私增强浏览器(包括 Brave 和 Tor Browser)确实默认阻止对运动传感器的访问,而其他浏览器(Chrome、Firefox、Firefox Focus、Opera 和 Duckduckgo)则不阻止。使用阻止运动传感器访问的浏览器可以在 Pixel 手机用户在线浏览时保护他们免受此攻击。最近的一项研究表明,Alexa 前 100K 网站中有 2 653 个访问了运动传感器数据,包括 100 多个将运动传感器数据外泄到远程服务器的网站 [14]。这很麻烦,因为 SENSORID 很可能可以用外泄的数据计算出来,从而实现回溯性设备指纹识别。最新的 iOS 设备始终运行 iOS 12.2 或更高版本,因此所描述的攻击不奏效。尽管如此,一个专门的攻击者可能仍然能够提取该指纹(第 VI 节)。

VI. Apple 的修复

Apple 拒绝分享 iOS 12.2 中所部署修复的细节。因此,我们通过研究运行 iOS 12.2 或更高版本的 iPhone 设备中的陀螺仪输出来逆向工程 Apple 的修复;我们表明所添加的随机噪声并未完全隐藏校准指纹。

图 5:一台 iPhone X 的原始陀螺仪数据直方图(对比 iOS 11.4.1 与 iOS 12.3.1 下 y 轴陀螺仪输出,单位 2-16 dps)

A. 对 Apple 修复的分析

图 5 呈现了从同一台 iPhone X 在两种不同 iOS 版本下收集的 y 轴原始陀螺仪数据的直方图。两种情况下,设备都静止在桌面上。当设备运行 iOS 11.4.1 时,直方图中的量化很清楚,我们可以恢复确切的增益矩阵(第 III-B 节)。为缓解我们的攻击,Apple 在 iOS 12.2 中向陀螺仪输出添加了随机噪声,掩盖了量化信息。图 5 表明所添加的噪声遵循均匀分布,这正是我们向 Apple 提出的对策之一。然而,我们注意到所添加的噪声中有一些特殊性。

为弄清所施加均匀噪声的范围,我们首先获取一台 iOS 设备在运行 iOS 12.2 之前版本时的陀螺仪增益矩阵。然后,我们把该设备更新到最新 iOS 版本,并在设备静止于桌面上时以 200 Hz 采集 20K 个陀螺仪测量值。我们把增益矩阵记为 G,这些陀螺仪输出记为 O。那么,底层的偏置校正 ADC 输出 I(即 I = A + B)可以由下式估计:

I = round(G-1O)    (7)

尽管估计的 ADC 值可能因扰动而不准确,它为我们提供了关于所添加噪声的有用洞见。此外,我们可以通过下式得到噪声估计 N:

N = O - GI

举例来说,图 6 呈现了一台 iPhone XS 估计的陀螺仪噪声直方图。如图 6 所示,大部分估计噪声均匀分布在范围 [-1997, 1997] × 2-16 dps 内。少数离群值很可能是由于方程 7 中 ADC 值估计不准确而产生的。

图 6:估计的陀螺仪噪声直方图(iPhone XS)

我们也测试了其他 iOS 设备并观察到相同的结果。这证实了 Apple 并未如我们所提议的那样向 ADC 值添加范围 [-0.5, 0.5] 内的随机噪声,而是向校准后的信号添加了范围 [-1997, 1997] × 2-16 dps 内的随机噪声。因为该随机噪声的宽度略窄于某些陀螺仪轴的灵敏度,它泄露的信息比我们最初的提议更多。就图 6 中的 iPhone XS 而言,扰动的宽度 3995 低于所有三个轴的灵敏度(分别为 4012、4031 和 4016)。这里我们表明,我们可以通过对噪声数据执行使用模拟退火的最大似然搜索来恢复增益矩阵。

B. 对 Apple 修复的攻击

在本节中,我们首先定义目标函数来量化在给定增益矩阵下观察到这些输出的似然。然后,我们表明可以使用模拟退火从目标函数中估计出确切的增益矩阵。

目标函数。 对于一个候选增益矩阵 G,我们按如下方式估计相应的偏置校正 ADC 输出 I:

I = round(G-1O)

这里我们没有像第 III-B 节那样减去传感器输出来去除偏置,因为那样会扩散噪声(使噪声范围翻倍)并使 ADC 值估计不那么准确。O 和 G 都以 2-16 dps 为单位,因此它们只包含整数值。尽管如此,由于扰动,估计的 I 并不保证正确,这就是为什么我们在图 6 中观察到少数离群值。

然后,我们按如下方式估计干净的陀螺仪输出(即没有添加噪声的):

Õ = GI

估计输出 Õ 与观测输出 O 之间的偏移可以计算为:

Δ = Õ - O

由于添加的噪声均匀分布在范围 [-1997, 1997] × 2-16 dps 内,任何超出此范围的偏移都是由不正确的增益矩阵(即 G ≠ G)或不正确的 ADC 估计(即 I ≠ I)造成的。为量化每个数据样本中的误差,我们定义以下误差函数:

f(i) = max(|Δi| - 1997, 0)

此外,我们为每个数据样本定义与范围相关的似然函数如下:

lr(i) = exp(- f(i) / T )

其中 exp(·) 是自然指数函数,T 是模拟退火中使用的温度变量,随迭代递减。

虽然似然函数 lr(i) 会惩罚偏移超出所添加噪声范围的数据样本,但它没有给我们任何关于该范围内数据分布的信息。一般来说,当设备静止在桌面等平台上时,陀螺仪每个轴的 ADC 输出遵循正态分布(如图 5 所示)。如果设备在数据收集期间移动过,我们可以使用静止位置滤波器来获取具有静止测量的片段。因此,我们可以为每个轴 a ∈ {x, y, z} 拟合一个正态分布 N(µa, σa) 到 Ia。然后,基于该正态分布,我们可以通过下式计算与分布相关的似然函数 ld(Ii):

ld(Ii) = Π pa(Iia)
       a∈{x,y,z}

其中 pa(·) 是正态分布 N(µa, σa) 的概率密度函数,Iia 是轴 a 中的输出 Ii。

最后,我们定义目标函数 L(O|G) 为一个负对数似然函数:

             N
L(O|G) = - Σ log(lr(i) ld(Ii))
            i=1

其中 N 是陀螺仪输出的数量。那么,真实增益矩阵可以通过以下方程估计:

Ĝ = arg min L(O|G)    (8)
     G

模拟退火。 模拟退火是一种用于求解优化问题的概率技术,常用于存在大量局部最优的情况下 [15]。由于方程 8 中的目标函数高度非平滑,我们使用模拟退火来求解这个优化问题。

首先,我们把候选增益矩阵的初始状态设为标称值(即 Ĝ0 = G0),温度参数 T 设为 10。温度 T 将在每次迭代中递减,最终为 0.1。然后,我们计算目标函数 L(O|Ĝ0) 并将其值记为 L0。

在接下来的每一轮 t 中,我们通过向前一状态添加随机扰动来提出一个新的候选增益矩阵:

Ĝt = Ĝt-1 + round(σt Rt)    (9)

这里,Rt 是一个 3×3 矩阵,包含第 t 轮从标准均匀分布中采样的随机浮点值。我们还使用一个步长参数 σt 来控制每一轮的步长;其初始状态设为 5(即 σ0 = 5),以允许开始时更大的步长。

然后,我们计算目标值 Lt 并将其与前一目标值 Lt-1 比较。如果 Lt 低于 Lt-1,我们总是接受该提议并保留 Ĝt 作为增益矩阵的最新估计。否则,我们以一定概率选择接受 Ĝt 或保留 Ĝt-1,以防止陷入局部最小值。如果提议被接受,我们还保留相应的目标值(即 Lt = Lt-1)并略微增大步长(例如 σt+1 = σt × 1.05)以允许更快的探索。否则,步长将略微减小(例如 σt+1 = σt / 1.05)以帮助找到最小值。我们还为 σt 设置一个下界 0.7,以防止步长太小而无法在方程 9 中更新候选增益矩阵。

结果。 我们在我们的 iPhone XS 测试手机上测试该算法;这台 iPhone XS 的 GYROID 如方程 4 所示。特别是,我们首先在设备静止时以 200 Hz 从设备收集 50K 个陀螺仪样本。我们对这些数据运行我们的算法 5K 次迭代,结果如图 7 所示。该图显示估计的 GYROID 在第 3383 轮后稳定下来;稳定后的 GYROID 与我们之前(在添加噪声之前)估计的相同。我们也在一台 iPhone X 上测试了该算法,我们同样能够使用相同的方法和设置恢复出确切的增益矩阵。

图 7:每次迭代估计的 GYROID(iPhone XS)

讨论。 实验表明 Apple 的修复仍然容易受到基于概率的攻击。然而,我们发现攻击者将需要至少 50K 个数据样本。由于近期 iOS 设备中陀螺仪的采样频率为 200 Hz,这意味着当设备静止在平台上时,攻击者需要收集至少 4.2 分钟的陀螺仪输出。此外,我们提出的攻击也是计算密集型的,因此不太可能直接在移动应用内部实现。这些限制使该攻击不那么实用。由于 Apple 还移除了 Safari 和 Webkit 对运动传感器的访问,此类攻击现在只能通过应用进行。

即使 Apple 采纳了我们提议的缓解措施(向 ADC 输出添加范围 [-0.5, 0.5] 内的均匀噪声),这种基于最大似然估计的攻击仍然会奏效。然而,攻击者将需要更多得多的样本。一个设计得更好的噪声方案可能进一步增强安全性,但它可能更难在移动设备中实现,并可能降低用户体验。

VII. 相关工作

设备指纹识别是应用开发者和广告主追踪用户的一项重要技术。IP 地址是用于指纹识别设备的最早标识符之一。然而,动态 IP 分配和网络地址转换的采用,特别是对家用 PC 和移动设备而言,极大地降低了这种方法的效果。Cookie 也常被用于跨网站追踪用户。然而,Cookie 存储在本地,用户可以随时更改。事实上,许多注重隐私的浏览器(如 Brave 和 Safari)默认阻止所有第三方 Cookie。此外,美国和欧洲的法规要求网站在使用 Cookie 之前获得用户许可,这也降低了这种方法的可用性 [16]。

设备中的各种 ID 都可以用作指纹,包括 IMEI、UDID 和硬件模块的 MAC 地址。2011 年的一项研究表明这些标识符在移动应用中被广泛使用 [17]。然而,Apple 和 Google 都采用了更严格的隐私政策,以防止开发者访问这些唯一 ID。此外,许多信息流追踪系统,如 TaintDroid [18] 和 Panorama [19],可以捕获这些恶意行为并将其报告给用户。

被动设备指纹识别。 被动设备指纹识别是通过观察目标设备的网络流量来刻画它的行为。它分析捕获的数据以揭示可指纹识别的模式(例如软件、操作系统或硬件组件)。由于被动指纹识别仅依赖网络流量,它与更多设备兼容、难以被发现,并且可以跨不同浏览器追踪用户。一般来说,大多数被动指纹识别技术依赖机器学习模型来区分设备。Uluagac 等人应用人工神经网络(ANN)根据其流量中的时变行为对设备进行分类 [20]。Neumann 等人评估了从网络流量中提取的若干特征,发现帧到达间隔时间(与硬件状态和已安装应用相关)是设备指纹识别最有效的特征 [21]。机器学习方法通常需要更多的计算资源和大量数据用于训练。因此,被动指纹识别技术通常比主动指纹识别技术具有更长的响应时间。

主动设备指纹识别。 主动指纹识别技术部署嵌入式代码来主动收集关于设备的信息,并使用这些特征来区分不同设备。例如,Fingerprintjs2 [12] 是一个流行的浏览器指纹识别库,它利用浏览器的特征,包括 user-agent、版本、插件、字体和 canvas。Apple 已经意识到浏览器指纹识别的风险。从 macOS Mojave 起,Safari 会清除大多数独特的浏览器数据,只暴露通用配置信息和默认字体 [22]。关于操作系统(例如版本和 root 权限)和系统配置(例如网络和 flash 配置)的信息也可用于识别设备。虽然这些信息无法唯一识别一台设备,但它可以与来自浏览器和嵌入式硬件的其他特征结合以提高精度。

硬件指纹识别。 硬件指纹通常是一致的,因为替换嵌入式硬件通常很困难。某些嵌入式硬件(如运动传感器)可以被运行在 Web 浏览器中的 JavaScript 和安装在智能手机上的移动应用访问,且不需要用户的任何权限。为指纹识别目的而被研究过的硬件模块包括:RF 模块 [23], [24]、运动传感器 [25], [26]、时钟 [27]、相机 [28], [29] 和声学组件 [30], [31]。特别是,数字取证中一个众所周知的硬件指纹是数码相机的光响应非均匀性(PRNU)。PRNU 是制造缺陷和硅晶片不均匀性的结果。估计 PRNU 的经典算法由 Lukáš 等人提出 [32]。与 SENSORID 类似,PRNU 本身对环境条件稳定,且很可能是全局唯一的。然而,PRNU 的确切值无法被提取,且估计的 PRNU 的质量取决于相机中使用的成像处理。最近,Ba 等人提出了一种名为 ABC 的协议,使用其内置相机的 PRNU 来认证智能手机 [33]。根据他们的研究,仅从一张照片估计出的 PRNU 就能高精度地识别源智能手机相机。然而,他们的研究只聚焦于两种带单相机的设备型号。目前尚不清楚多相机设备中的图像融合过程是否会降低性能。此外,访问相机或照片需要用户明确许可,因此它不太实用。除智能手机之外,硬件指纹识别在其他目标上也有应用。特别是,Son 等人使用无人机中嵌入的陀螺仪的加电偏移校准来作为其身份 [34]。然而,这种加电偏移校准不是工厂校准。校准后的偏移在无人机每次开启时被动态计算。因此,它随时间变化并随温度变化。相比之下,我们的工作是第一个恢复存储在持久存储器中、此后不再改变的数字化工厂校准参数的工作。

现有的硬件指纹识别技术大多基于机器学习方法。Bojinov 等人证明,可以使用典型的聚类方法对扬声器-麦克风系统和加速度计两者进行指纹识别 [26]。然而,即使把 UA 字符串整合进他们的模型,他们也只正确识别出数据集中 53% 的设备。Das 等人应用了几种监督机器学习模型,基于陀螺仪和加速度计读数来区分设备 [35]。为提高准确性,他们使用听不见的声音来刺激运动传感器。作为一种对策,他们建议更好地校准运动传感器。然而,他们没有意识到,如果校准过程实现不当,它可能会泄露信息。最近,他们通过在不同分类器之间引入投票方案进一步提高了其准确性 [36]。尽管如此,他们的方法需要大量计算资源,无法在设备本地实现。即便如此,当设备被手持时,他们的方法在开放世界设置中实现的 F1 分数不到 60%。他们还把他们的方法应用于区分 85 台 iPhone 6 设备。当设备被手持时,这些设备中只有 60% 产生唯一指纹,参照生日问题,这表明他们的方法提供约 13 比特的熵。基于他们通过 JavaScript 收集的运动传感器数据,我们在事先不知道设备型号的情况下,基于校准行为正确识别出数据集中的所有 iOS 设备。最近,Das 等人研究了流行网站中的传感器 API 使用情况 [14]。他们表明,Alexa 前 100K 网站中有 2 653 个访问了运动传感器数据,63% 的用于访问运动传感器的脚本也参与了浏览器指纹识别。尽管先前技术已经意识到不同传感器之间的特性,但据我们所知,没有任何一项利用工厂校准来形成设备指纹;本文填补了这一空白。

VIII. 结论

在本文中,我们引入了工厂校准指纹识别攻击:一种仅通过对传感器输出的仔细分析,对带有嵌入式运动传感器的设备进行指纹识别的新方法。我们在 iOS 设备上证明了该攻击的有效性,并发现 M 系列协处理器缺乏精度有助于此类指纹的生成。我们的攻击易于由网站或应用在 1 秒内实施,不需要特殊权限,不需要用户交互,且计算高效。我们的攻击还可以回溯性地应用于历史传感器数据存档。以 iPhone 6S 为例,我们表明 GYROID 包含约 42 比特的熵,MAGID 额外提供 25 比特的熵。此外,我们证明 MAGID 与 GYROID 的组合对 iPhone 6S 而言极可能是全局唯一的,在恢复出厂设置或软件更新后不会改变。对于较老一代的 iOS 设备(如 iPhone 4S 和 iPad Mini),我们可以进一步提取 ACCID 并用它提供额外的熵。除 iOS 设备之外,我们还对市场上流行的 Android 设备型号进行了大型研究,发现除 Pixel 1/1 XL 之外的所有 Google Pixel 手机都可以被我们的攻击指纹识别。我们估计了每个易受攻击的 Pixel 型号的 SENSORID 熵,并表明 Pixel 4/4 XL 提供约 57 比特的熵。

此外,我们分析了 Apple 对我们攻击的修复,并表明即使在修复之后仍有可能提取 GYROID,尽管这样做需要显著更多的数据和计算能力。由于不再可能访问 iOS 浏览器中的运动传感器,发起此攻击的机会被限制在已安装的应用中。

校准指纹的概念具有广泛的适用性。虽然本文主要针对移动设备中的运动传感器,但我们预计其他嵌入式传感器中使用的工厂校准信息也可能被恢复并用作指纹,因此我们预期未来的研究将成功地对其他类型的传感器执行工厂校准指纹识别攻击。

(说明:本文的"致谢"(ACKNOWLEDGEMENT)与"参考文献"(REFERENCES,共 [1]–[36] 条)两节未逐条翻译,属长文从略部分。)

IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY 1

Factory Calibration Fingerprinting of Sensors

Jiexin Zhang, Alastair R. Beresford, and Ian Sheret

Abstract--Device fingerprinting aims to generate a distinctive any time and iOS also provides an option to limit access to
signature, or fingerprint, that uniquely identifies individual com- this identifier. Moreover, apps requesting this identifier but do
puting devices. Fingerprints may be a privacy concern since not serve any in-app advertisements will be rejected by the
apps and websites can use them to track user activity online. App Store. Last but not least, the advertising identifier is not
To protect user privacy, both Android and iOS have included a accessible from mobile browsers. Similarly, although Android
variety of measures to prevent such tracking. In this paper we still allows apps to access the ANDROID_ID, it cannot be
present a new type of fingerprinting, factory calibration finger- obtained from a website and its value is scoped by the signing
printing, that bypasses existing tracking protection. Our attack key and user since Android 8. Different apps on a device will
recovers embedded per-device factory calibration data from the have different values of ANDROID_ID and a factory reset
accelerometer, gyroscope, and magnetometer sensors that are or an APK signing key change may also change its value [1].
pervasive in modern smartphones by careful analysis of the Thus, it cannot be used to track users across apps and websites.
sensor output alone. We discuss the factory calibration behaviour
of each sensor and show that the calibration fingerprint is fast We have developed a new type of fingerprinting attack,
to generate, does not change over time or after a factory reset, the factory calibration fingerprinting attack, which can by-
and can be used to track users across apps and websites without pass these restrictions. Modern mobile devices are shipped
any special permission from the user. We find the calibration with a variety of embedded motion sensors that apps rely
fingerprint is very likely to be globally unique for iOS devices, on to provide rich functionality, including workout tracking,
with an estimated 67 bits of entropy for the iPhone 6S. In and improved user interaction. Natural variation during the
addition, we have analysed 146 Android device models from 11 manufacture of embedded sensors means that the output of
vendors and found the attack also works on recent Google Pixel each sensor is unique and therefore such natural variation may
devices. For Pixel 4/4 XL, we estimate the calibration fingerprint be exploited to create a device fingerprint.
provides about 57 bits of entropy. Following our disclosures,
Apple deployed a mitigation in iOS 12.2 and Google in Android Previous work applies machine learning techniques directly

  1. We analyse Apple's fix and show that the mitigation is to sensor data in an attempt to create device fingerprints for

imperfect although it is likely to be sufficient in most threat smartphones; this has been shown to be ineffective (VII).
models. In our attack, instead of feeding sensor outputs into machine
learning algorithms, we infer the per-device factory calibration
I. INTRODUCTION data from the output of gyroscope, accelerometer, and mag-
netometer to construct a globally unique fingerprint. Overall,
When users visit a website, their web browser provides a our attack has the following advantages:
range of information to the website, including the name and
version of the browser, screen size, fonts installed, and so on. Practical the attack can be launched by any website or
Ostensibly, this information allows the website to provide a any app on a vulnerable device without requiring
great user experience. Unfortunately, this same information Efficient explicit confirmation or interaction by the user.
can also be used to track users. In particular, this information Unique the attack takes less than one second to generate
can be used to generate a distinctive signature, or device Robust a fingerprint.
fingerprint, to identify users. Similarly, mobile app developers Effective the attack generates a globally unique fingerprint
can also generate a device fingerprint using the idiosyncrasies for vulnerable devices.
of software and hardware. the calibration fingerprint never changes, even
after a factory reset.
Realising the potential risk to user privacy, both iOS and the attack provides an effective means to track
Android have included measures to prevent such tracking. On users as they browse across the web and move
iOS, developers do not have access to the UDID (Unique between apps on their device.
Device IDentifier), IMEI (International Mobile Equipment
Identity), and MAC address of hardware modules after iOS In our previous research we have focused mostly on iOS

  1. Similar restrictions are also deployed on Android O; de- devices and demonstrated its effectiveness on gyroscope and

velopers cannot get access non-resettable unique hardware magnetometer data available in iOS [2]. This paper extends our
identifiers even if users grant the app dangerous permissions previous work: we present our latest findings on accelerometer
such as the READ_PHONE_STATE permission. While it is still calibration on iOS devices (III-E); we conduct a large-scale
possible to track users by the advertising identifier on both factory calibration behaviour analysis on popular Android
iOS and Android, this method comes with several drawbacks. device models (III-F); we compare the calibration fingerprint
First, both platforms allow users to reset this identifier at with the Fingerprintjs2 fingerprint for Google Pixel phones
(IV-B); we analyse the calibration fingerprint for vulnerable
J. Zhang and A. Beresford are with the Department of Computer Science Pixel devices and estimate entropy for each model (V-B).
and Technology, University of Cambridge, Cambridge, UK (email: {jz448,
arb33}@cl.cam.ac.uk).

I. Sheret is with Polymath Insight Limited, Stevenage, UK (email:
ian.sheret@polymathinsight.co.uk).
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY 2

We followed a coordinated disclosure procedure and re- Calibration aims to identify and remove the deterministic
ported the vulnerability to Apple on 3rd August 2018 and errors from the sensor. Many commercial sensors are fac-
Google on 10th December 2018. In iOS 12.2, Apple adopted tory calibrated and their calibration parameters are stored in
our suggestion and added random noise to sensor outputs firmware or non-volatile memory, providing accurate measure-
(CVE-2019-8541) while Google decided to round sensor out- ments off the shelf [5]. In the context of mobile devices, the
puts to a multiple of nominal gain in Android 11. In addition, main benefit of per-device calibration is that it allows more
Apple removed access to motion sensors from Mobile Safari accurate attitude estimation [6]. By contrast, sensors embedded
by default and in later versions also removed motion sensor in low-cost smartphones are usually poorly calibrated due to
access from WebKit. However, in this paper we show that the high cost and complexity of factory calibration [7]. For an
Apple's fix is imperfect since a calibration fingerprint can still individual manufacturer, the choice of sensor calibration is,
be extracted if more sensor data is available (VI). therefore, an engineering trade-off.

We make the following contributions in this paper: MEMS sensors usually convert and store the analogue

  1. We introduce a new method of fingerprinting a device: measurement in a digital register through an Analogue-to- Digital Converter (ADC) module. For a triaxial motion sensor, the factory calibration fingerprinting attack. let A = [Ax, Ay, Az]T be the sensor ADC output. Considering
  2. We describe how factory calibration data can be ex- all three kinds of deterministic errors, the output of the motion sensor can be represented by the following equation [8]: tracted from the accelerometer, magnetometer, and gy- roscope found on recent smartphones. Ox Sx 0 0 1 Nxy Nxz Ax + Bx
  3. We demonstrate that the factory calibration data of the magnetometer and gyroscope together form a reliable Oy = 0 Sy 0 Nyx 1 Nyz Ay + By (1) fingerprint for iOS devices that does not change after factory reset or operating system updates. Oz 0 0 Sz Nzx Nzy 1 Az + Bz
  4. We collect motion sensor data from 870 iOS devices and show that our approach can generate a globally unique Here, Si S is the scale factor; Nij N represents the identifier; we show that the calibration fingerprint of the nonorthogonality between axis i and j; and Bi B is the bias. iPhone 6S has about 67 bits of entropy. A sensor's sensitivity, or gain, is defined as the ratio between
  5. We implement our approach as an iOS app and find the the output signal and measured property. A sensor's nominal approach is lightweight and efficient: data collection and gain is the intended operating sensitivity of the sensor. It is a processing typically takes less than one second in total. single value that is usually documented in the sensor datasheet.
  6. We conduct a large-scale analysis on motion sensor We use F to denote a sensor's nominal gain in this paper. calibration in 146 Android device models from 11 If a sensor is ideal, its scale matrix S and nonorthogonality vendors. We find that all Google Pixel phones except matrix N should be F I and I, respectively, where I is an for Pixel 1/1 XL can be fingerprinted by our attack; we identity matrix. However, due to the existence of errors, the show that the calibration fingerprint of the Pixel 4/4 XL scale factors can be as large as 2% of the nominal gain [9]. has about 57 bits of entropy. The above equation can be further simplified as:
  7. We analyse Apple's fix and show that it is imperfect: with ~50K samples the exact fingerprint can be ex- O = G(A + B) (2) tracted. where G = SN is referred to as the gain matrix. II. BACKGROUND A myriad of calibration techniques has been proposed to

Motion sensors used in modern smartphones, including the calculate the gain matrix and bias vector during manufac-
accelerometer, gyroscope, and magnetometer, are based on ture [3]. Vendors can also choose to only calibrate the bias
MEMS (Micro-Electro-Mechanical Systems) technology and vector to lower the cost. Once factory calibration is finished,
use microfabrication to emulate the mechanical parts. The the calibration parameters of the sensor will be stored in non-
accelerometer and gyroscope measure the proper acceleration volatile memory inside the device and should not change over
and rotation speed of a device in each of the axes, respec- time [10], [11]. Details of the calibration process used by
tively, while the magnetometer measures the Earth's magnetic manufacturers are not made public.
field relative to the device. These sensors are pervasive in
modern mobile devices. Although MEMS technology has III. ATTACK METHOD
greatly reduced the size and cost of motion sensors, MEMS
sensors are usually less accurate than their optical counterparts The goal of the adversary in this paper is to obtain a reliable
due to various types of error. In general, these errors can fingerprint from the built-in motion sensors of a smartphone.
be categorised as deterministic and random: random errors Our threat model is as follows. We assume an adversary is
are usually caused by electronic noise interfering with the able to record motion sensor samples from a smartphone. The
output of sensors, which change over time and have to attacker can do this if the user installs an app, or visits a
be modelled stochastically; deterministic errors are produced website (currently accelerometer and gyroscope only), under
by manufacturing imperfections and can be classified into the control of the attacker. Furthermore, we assume that
three categories: bias, scaling factor, and nonorthogonality the software embedded in the app or web page is able to
misalignment errors [3], [4]. communicate with a remote server under the control of the
attacker; this is typically the case for both apps and web pages.
We first look at the gyroscope in iOS devices; the calibration
fingerprinting for other sensors and devices is discussed later.
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY 3

Update G~

~A G~ Failed
Pass

)LQJHUSULQW*HQHUDWLRQ
'DWD&ROOHFWLRQ 'DWD3UHSURFHVVLQJ $'&9DOXH(VWLPDWLRQ *DLQ0DWUL[(VWLPDWLRQ 9DOLGLW\&KHFN

Fig. 1: General steps to recover the device calibration fingerprint

TABLE I: Estimated gyroscope nominal gain for iOS devices Data Collection, Data Preprocessing, ADC Value Estimation,
Gain Matrix Estimation, Validity Check, and Fingerprint Gen-
Model Nominal Gain eration.
(mdps)
Data Collection. We collect a small number of samples
iPhone 5S/6/6 Plus/6S/6S Plus/7/7 Plus/8/8 Plus/SE from the gyroscope through a mobile app at the maximum
sampling frequency. Empirically, we find 100 samples col-
iPhone X/XS/XS Max 61 lected in less than 1 second is sufficient. We use O =
[O1, O2, , ON ] to denote the collected data, where Oi =
iPad Pro 9.7/10.5/12 inch [Oix , Oiy , Oiz ]T is a 3-by-1 vector.

iPhone 4/4S/5/5C/5S, 70 Data Preprocessing. After collecting the data, we calculate
iPad 3/Mini/Mini 4/Mini Retina/Air/Air 2 O by differencing the consecutive outputs for all three axes.
In other words, O is calculated by the following equation:
iPhone 5S devices have two possible nominal gain values.
O = [O2 - O1, O3 - O2, , ON - ON-1]
A. Gyroscope Calibration on iOS devices
Then, we select only a subset of the data, O i , where the
We have found that the gain matrix of the gyroscope in iOS absolute value of all its elements is lower than a multiplication
devices is factory calibrated and further estimated the nominal of the nominal gain:
gain for different device models based on the gyroscope
outputs [2]. In particular, Table I lists the nominal gain (in O i = {Oj O | max(|Oj|) < ( i + 0.5)FG}
mdps, millidegrees per second) of the gyroscope for all the
iOS devices that we have measured. The estimated nominal where i is the threshold. We start i from 1 and double its
gain of 61 mdps indicates that the sensor is likely configured value for each iteration (i.e., i+1 = 2 i) until the subset covers
to a measurement range of 2 000 dps and resolution of 16 the whole dataset (e.g., O i = O). In each iteration, we
bits (4 000/216 0.061). Furthermore, we have found that feed O i to the next step and update the value of G.
the fractional part of motion sensor outputs in iOS only has
16-bit resolution. There are a few possible reasons for this, ADC Value Estimation. In this step, we aim to recover
but the simplest is that the value in the gain matrix G is A i , which is the difference between consecutive ADC
stored as a signed integer with a resolution of 2-16 degrees outputs. From Equation 2 we have:
per second (dps). After investigation, we find that every device
that uses an M-series motion coprocessor, which was released A i = G-1O i
by Apple in September 2013 with the iPhone 5S, shows this
pattern. The purpose of the motion coprocessor is to offload where G-1 is the inverse of the gain matrix G. However,
the collection and processing of sensor data from the CPU. the value of G is unknown at the moment. Nevertheless, we
However, for older devices such as iPhone 4 and iPhone 4S, can estimate G by its ideal value G0 = FG I, where FG is
gain matrix values are stored with more precision and the the nominal gain of the gyroscope. That is to say, we have
calibration involves truncation down to 2-16 dps after the gain G = G0 in the first iteration, where G is the estimated gain
is applied. The complete set of devices that use the M-series matrix. Deterministic errors are comparatively small, and thus
motion coprocessor can be found online.1 G should be relatively close to G0. Since A i only has
integer values, we can estimate A i by:
B. Fingerprinting from Mobile Apps
A i = round(G-1O i )
In general, manufacturing imperfections introduce idiosyn-
crasies across different sensors. If factory calibration is carried where the round() function rounds each element to the
out on a per-device basis, then the calibration matrices may nearest integer. However, since G0 is not equal to G, the
also be unique. Therefore, the gain matrix G may be used as rounded value A i may not be the true value. Therefore, we
a robust device fingerprint. calculate the rounding error Er R3(N-1) by:

The general process to recover the device calibration finger- Er = |A i - G-1O i |
print is illustrated in Fig. 1, which consists of six major steps:
To ensure the estimated values are correct, we require that
1https://en.wikipedia.org/wiki/Apple_motion_coprocessors every value in Ekr , which means the k-th column in Er,
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY 4

be lower than a threshold (e.g., 0.1). If not, we believe 0.4 0.4
Gyroscope Output (deg/s)
the rounding is ambiguous and thus remove both Aki 0.2 Difference between Gyroscope Outputs (deg/s) 0.2
and Oki from the dataset. Once all ambiguous values are
removed, A i can be regarded as a safe estimate of A i . 0.0 0.0
Nevertheless, if the device is moving rapidly (e.g., vigorous
shaking), rounding errors could be accumulated and cause -0.2 -0.2

rounding to an incorrect integer value (i.e., A i = A i ).
Gain Matrix Estimation. After estimating the ADC value

matrix A i , we can update the gain matrix estimate by:

2

G = arg min GA i - O i

G 2 -0.4 -0.4
0 0
2 100 200 300 400 500 100 200 300 400 500
where 2 is the squared Euclidean 2-norm function. Or in
Sequence Sequence

words, we use the least squares solution to GA i = O i Axis x y z Axis x y z

as the gain matrix estimate.

After each update of G, we check if we have processed all (a) Fused gyroscope data (b) After differencing

the output data. If so, we will pass the estimated G to the Fig. 2: Gyroscope data collected via JavaScript (iPad Air)

Validity Check process. Otherwise, the algorithm will go back

to the Data Preprocessing stage with an updated G, and a

new range of data will be processed with i+1 = 2 i. When the device does not contain an M-series coprocessor,
the GYROID is calculated by:
By way of an example, here is the G that we estimated
from an iPhone XS in the units of 2-16 dps: GYROID = G - round(G0)

4012.000000000001 -35.999999999999318 -10.999999999999677 because values in the gain matrix are not simply integers in
11.000000000000174 4030.999999999999 21.999999999999631 the units of 2-16 dps in this case.

-3.999999999999980 -25.000000000000011 4016.000000000000 Summary. In this section we present the general idea and
procedure to generate a calibration fingerprint. Overall, the
These numbers are extremely close to whole integers, calculations are light-weight and are easy to implement. The
indicating that the gain matrix is stored in the units of 2-16 attack works well under normal device interaction (e.g., device
is resting on a desk or held in hand when browsing a webpage);
dps. In fact, we found that all iOS devices with an M-series it typically requires only 100 data samples that can be collected
in less than 1 second to generate the GYROID (IV). If
coprocessor store the gain matrix this way. For these devices, the device is moving vigorously when collecting data, our
approach will detect fast movement, as the Validity Check will
we can simply round G to obtain the true gain matrix G. fail, and keep trying until the movement is reduced. This attack
is therefore practical since people rarely shake their device
Validity Check. To quantify the deviation between G and continuously and vigorously for extended periods.
the true value of G, we define the estimation error Ee R31

as follows:

O - GA

Ee = 2

N -1

If the estimation error is small (i.e., max(Ee) < ), then G C. Fingerprinting from Mobile Websites
should be close to the true gain matrix G. Otherwise, it means
the ADC value estimation is incorrect, which is likely a result JavaScript also provides APIs for web developers to access
of vigorous movement during the data collection. In this case, the fused gyroscope data. In this paper, we state the sensor data
we need to collect another batch of data and repeat the steps. is fused if its value is a result of applying a time-varying bias
correction to the raw sensor data. In practice, it is common to
Fingerprint Generation. The generation of the gyroscope use a Kalman filter to combine, or fuse, the accelerometer and
calibration fingerprint, GYROID, can be categorised into two gyroscope inputs to calculate the corrected bias values. Fig. 2
groups based on whether the device has an M-series copro- (a) presents the 500 sequential gyroscope samples collected
cessor. If the device does have an M-series coprocessor, the from an iPad Air through mobile Safari when the device is
GYROID is defined as follows: at rest on a desk. As shown in Fig. 2 (a), quantisation in the
fused data is still visible because the gyroscope ADC outputs
GYROID = round(G) - round(G0) (3) are integers. However, there is a slowly varying continuous
component added to the bias due to the bias correction. Fig. 2
where both G and G0 are in the units of 2-16 dps. Or in (b) shows that the bias part can be nearly eliminated by
words, the GYROID is the gain matrix G after subtracting the subtracting consecutive samples. Therefore, we can apply the
nominal gain in units of 2-16 dps. For instance, the GYROID same technique described in III-B to recover the gain matrix.

of the iPhone XS in the previous example is:

14 -36 -11

GYROID = 11 33 22 (4)

-4 -25 18
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY 5

D. Practical Calibration Fingerprinting Attacks TABLE II: Magnetometer type of different iOS device models

To launch a calibration fingerprinting attack, an adversary Type Model Nominal Gain (T)
can collect gyroscope samples from any device using an app
written by the attacker or that visits any website under the Type I iPhone 4S/5/5C/5S/6/6 Plus 0.35/0.28/0.17
attacker's control. The attacker can then generate a device All iPad models
fingerprint (e.g., GYROID) from the samples and store it in
a database. Then, the adversary can query the database to Type II iPhone 6S/6S Plus/7/7 Plus/SE 0.075
determine when a particular physical device uses a particular
app or visits a particular website. The details of the generation Type III iPhone 8/8 Plus 0.075
and query of the GYROID in the database differ depending on
the collecting source (app or web) and device model. Type IV iPhone X/XS/XS Max 0.075

Specifically, for apps running on a device with an M-series Type I devices have three possible nominal gain values.
motion coprocessor, they can follow the steps in III-B to
recover the exact GYROID. Otherwise, if the device does not Difference between Accelerometer Outputs (g) iPhone 4S iPhone 5
have a motion coprocessor (e.g., iPhone 4/4S/5) or adversaries
only have access to fused gyroscope data (e.g., via JavaScript), 0.002
there are two options to determine whether two GYROID
entries in the database represent the same physical device. 0.000

Option 1 (Clustering): adversaries can directly use the -0.002
estimated gain matrix G as the GYROID and store it in a
database. For every new device with the same model, they 0 500 1000 1500 2000 0 500 1000 1500 2000
can calculate its G and compare the Euclidean distance
between its G and the ones in the databases. If they are Sequence
close, then adversaries know they came from the same
device (the entropy of G is discussed in V-A). Axis x y z

Option 2 (Rounding): adversaries can still use Equation 3 Fig. 3: Comparison between iPhone 4 and 5 (Accelerometer)
to generate the GYROID. However, the estimated GY-
ROID may deviate from the true one by at most 1 for devices, we can use the same approach described in III-B to
each of the 9 values. Therefore, adversaries can store the obtain the magnetometer fingerprint (i.e., MAGID). Although
estimated GYROID and perform a fuzzy query (i.e. accept the gain matrix of the magnetometer is not stored at 2-16 T
a 1 fluctuation for each element). Note that this option resolution, adversaries can use the same techniques discussed
provides less entropy compared with Option 1. in III-D to launch an attack by either clustering or rounding.
Compared with the gyroscope, the raw magnetometer data is
E. Fingerprinting Other Motion Sensors not currently accessible in major browsers. Nevertheless, the
MAGID provides additional entropy to the GYROID. Thus,
Magnetometer. We found that the magnetometer in iOS we can combine them as a finer-grained fingerprint when
devices can also be fingerprinted. Similar to the gyroscope, the analysing apps.
raw readings from the magnetometer only have a resolution
of 2-16 T (microtesla). After subtracting consecutive raw Accelerometer. We observed a similar quantisation pattern
magnetometer measurements for every device model in our for the accelerometer in older generations of iOS devices,
dataset, we observed four types of pattern: including the iPhone 4S and iPad Mini. For example, Fig. 3
shows the consecutive differences between 2 000 accelerome-
Type I (different sensitivity, negligible fluctuation): Type ter outputs from an iPhone 4S. The quantisation is clear and
I devices have a slightly different sensitivity for each axis. thus we can apply the same approach described in III-B to
recover the accelerometer fingerprint. Note that these devices
Type II (fixed sensitivity, moderate fluctuation): Type II do not use an Apple motion coprocessor, and thus adversaries
devices have the same sensitivity for every axis but there would need to use techniques described in III-D to launch
is a moderate fluctuation within each cluster. the attack. For newer versions of iOS devices, such as the
iPhone 5 also shown in Fig. 3, Apple uses a higher-resolution
Type III (different sensitivity, moderate fluctuation): Type accelerometer that conceals the quantisation in outputs. Our
III devices have a slightly different sensitivity for each attack currently does not directly apply to these devices.
axis and there is a moderate fluctuation within each
cluster; the quantisation of the data is evident in this case. In this paper, we define the SENSORID as a combination
of distinctive sensor calibration fingerprints. In the case of
Type IV (different sensitivity, intense fluctuation): Type iOS devices, the SENSORID includes both the GYROID and
IV devices show an intense fluctuation on the magne- MAGID. For older versions of iOS devices (e.g., iPhone 4S
tometer output. In this case, the quantisation of the data and iPad Mini), the SENSORID also includes the accelerom-
is not as evident as in other cases. eter fingerprint (i.e., ACCID).

We summarise the magnetometer type of different iOS
device models and their estimated nominal gain in Table II.
Overall, the observation of the four patterns reveals the dif-
ferent underlying calibration procedures. For all four types of
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY 6

Difference between Accelerometer Outputs (ms-2) Pixel 3 Pixel 4 XL TABLE III: SENSORID composition
0.06
SENSORID Device Model
0.05 ACCID iPhone 4S, iPad Mini
GYROID Pixel 2/2 XL/3/3 XL/3a/3a XL/4/4 XL
MAGID iOS devices, Pixel 4/4 XL

iOS devices

0.04

0.03 500 1000 1500 2000 0 500 1000 1500 2000 of factory calibration is up to individual manufacturers.
0 For vulnerable Google Pixel phones, we can extract the

Sequence SENSORID from both an Android app and a website running
on an Android browser. In the case of Google Pixel 4 and
Axis x y z 4 XL, the SENSORID includes both the ACCID and GYROID.
For other Pixel models excluding Pixel 1, the SENSORID only
Fig. 4: Comparison between Pixel 3 and 4 XL (Accelerometer) includes the ACCID. In summary, Table III lists all device
models whose SENSORID includes the ACCID, GYROID, and
MAGID, respectively.

F. Fingerprinting Android devices IV. EVALUATION

To study whether Android devices are susceptible to similar A. Fingerprinting iOS Devices
fingerprinting attacks, we used four automated testing plat-
forms to collect data from 146 Android device models from We developed both a website and an iOS app to collect
11 vendors: BQ, Google, HTC, Huawei, LG, Motorola, Nokia, sensor data. The iOS app collects raw data from the motion
OnePlus, Samsung, Sony, and Xiaomi (IV-B). Among all the sensors (accelerometer, gyroscope, and magnetometer) at 200
Android devices we have tested, we found that all Google Hz and does not ask users to put the device in any particular
Pixel phones, other than the Pixel 1/1 XL, can be fingerprinted position. The app also embeds a WebView; the embedded
by our approach; we did not observe per-device calibration WebView and the separate website both collect fused ac-
behaviour on the Pixel C tablet. In addition, we noticed that celerometer and gyroscope data via JavaScript.
the calibration process applied to motion sensors varies across
device models. In particular, we found the full gain matrix For both the app and the website, we use the Finger-
of both the accelerometer and gyroscope in Google Pixel 4 printjs2 [12] library in the default configuration to generate
and 4 XL are per-device calibrated, while only the leading a browser fingerprint for evaluation purposes. In addition to
diagonal of the gain matrix for the accelerometer is calibrated volunteers, we recruited participants from Amazon Mechanical
in other Pixel devices. Turk2 and Prolific3 to download the app and contribute sensor
data. The public data collection exercise has been approved by
Fig. 4 shows the consecutive difference between 2 000 ac- the ethics committee of the Department of Computer Science
celerometer outputs collected from a Pixel 3 and a Pixel 4 XL and Technology at the University of Cambridge.
when they were at rest on a desk. The quantisation in the
accelerometer outputs is clear in both cases. In addition, the To date, the SENSORID app has collected data from 795
figure suggests that only the scale matrix of the accelerometer unique iOS devices; 761 of them contain an M-series motion
is calibrated in Pixel 3 (i.e., only main-diagonal elements in the coprocessor. In addition, the website has collected fused data
gain matrix are calibrated); the same pattern is also observed from another 75 devices. Some users chose to participate in
in Pixel 2/2 XL/3 XL/3a/3a XL. Fig. 4 also suggests that all this study multiple times. Thus, there might be more than
9 values in the gain matrix are calibrated in the Pixel 4 XL; one record for each unique device. On both the app and the
the same pattern is also observed in the Pixel 4. Apart from website, we ask users to tell us whether they have submitted
the accelerometer, the gyroscope in Google Pixel 4 and 4 XL the data from this device before.
is also per-device calibrated.
Using the raw gyroscope data collected from the 761 iOS
In addition to Pixel devices, we have noticed that the devices with an M-series coprocessor, we are able to recover
accelerometer in Huawei Honor 20 Lite, MediaPad M3 Lite the exact GYROID. For the other 34 devices that do not contain
10, and MediaPad T3 10 and the gyroscope in BQ Aquaris an M-series coprocessor, we use the rounding option in III-D
X2 have different sensitivity in each axis. However, we only to generate the GYROID due to the small sample size. Based
have one device for each of these models and thus cannot on the GYROID, we successfully identify multiple records that
confirm whether they are per-device calibrated. So far we are submitted by the same device. This is confirmed by user-
have tested 321 unique devices (146 unique device models); supplied data about whether they have submitted samples from
we did not observe per-device calibration behaviour on any this device before and the device IP address when they submit.
other Android device models we tested. We therefore focus The GYROID of each device is distinct.
on Google Pixel devices in the rest of the paper. The choice
2https://www.mturk.com
3https://prolific.ac
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY 7

TABLE IV: Comparison of iOS device fingerprints TABLE V: Comparison of Pixel device fingerprints

Devices Fingerprint Group Size # Groups Device Model Fingerprint Group Size # Groups

870 GYROID ACCID
1 870 Pixel 2/2 XL 1 46
795 Fingerprintjs2 1 391 Fingerprintjs2 1 17
10 236 96 Pixel 3/3 XL 2 4
MAGID 45 1 & ACCID 4 1
1 775 Fingerprintjs2 5 2
Fingerprintjs2 2 10 Pixel 3a/3a XL 7 1
ACCID 1 308 ACCID 1 61
236 97 Pixel 4/4 XL GYROID 1 25
Fingerprintjs2 45 1 2 8
1 10 Fingerprintjs2 3 5
1 8 5 1
2 1 1 45
1 45
Since the website only collects fused gyroscope data, we 1 10
choose the rounding option in III-D to generate the GYROID. 2 1
Then, we compare it with the GYROID of the 795 devices 9 1
that we recovered from the raw data. As a result, we identify 10 1
3 devices submitted through both the website and the app. 14 1
The app also collects fused sensor data from the built-in
WebView. For this data, we use the clustering approach to device in our dataset, 45 out of 135 iPhone 7 devices have
generate a group of gain matrix estimates. Then, we apply the same Fingerprintjs2 fingerprint; these 45 devices are all
the Multivariate ANalysis Of VAriance (MANOVA) technique from the UK. In the case of ACCID, it identifies all 10 unique
to analyse these estimates and successfully identify all 795 devices, while Fingerprintjs2 generates the same fingerprint
unique devices in the dataset. In particular, we also identify for two iPhone 4S devices; both devices are from Germany.
6 devices that submitted multiple times through the app. The The results indicate that the Fingerprintjs2 fingerprint may be
results are the same as we obtained from the raw data. correlated with a particular handset configuration.

In addition, we apply the improved approach to fingerprint We have also developed a proof of concept app for iOS
the magnetometer with the rounding option. After generating devices with an M-series motion coprocessor. The app imple-
the MAGID, we group devices by their MAGID and present ments our attack to generate the GYROID of the test device.
the results in Table IV. In the table, the group size records The code is written in Swift 4.1 with XCode 9.4.1. The app
the number of different devices sharing the same MAGID. collects 100 raw gyroscope samples and attempts to generate
Therefore, a group of size 1 means the device has a unique the GYROID. If it fails (due to intense shaking of the phone)
MAGID in our dataset. We find that the 10 groups of size the app automatically collects another 100 raw samples and
2 are all old device models with a Type I magnetometer, repeats the process. Overall, it takes about 0.5 seconds to
indicating they have a higher chance of collision on MAGID collect 100 gyroscope samples and another 0.01 seconds to
than others. The reason is that the entropy of the MAGID for generate the GYROID. Vigorous movement during extraction
Type I devices is only provided by the scale matrix (i.e., main- may require additional samples, but the task nevertheless
diagonal elements in MAGID). Nevertheless, the MAGID is completes within a few hundred samples and takes a few
orthogonal to the GYROID, and thus, they can be combined seconds. In any case, the generated GYROID always stays
together to provide additional entropy. the same. A proof-of-concept webpage and demo videos can
be found on our website: https://sensorid.cl.cam.ac.uk.
Similar to the analysis of data collected from the built-in
WebView, we use the clustering option in III-D to analyse B. Fingerprinting Google Pixel devices
the accelerometer fingerprint and apply MANOVA to identify
unique devices. As discussed in III-E, our attack only applies In general, it is difficult to find many people with a Pixel
to the older generations of iOS devices. In our dataset, that device via crowdsourcing platforms due to the relatively small
includes 9 iPhone 4S devices and an iPad 3. We apply our market share. Nevertheless, we found most online app testing
attack on these 10 devices and find that all of them have a platforms provide access to Pixel devices. Therefore, we
unique ACCID. It is likely that other iOS devices prior to developed an Android app to collect raw motion sensor data
iPhone 4S can also be attacked by our approach, but we do and send it back to our server. In a method similar to the one
not have data from these devices to confirm it. used in our iOS app, our app also embeds a WebView that
collect web sensor data via JavaScript as well as a fingerprint
Finally, we compare the GYROID, MAGID, ACCID with generated by Fingerprintjs2. In addition, the app records the
the default configuration of Fingerprintjs2, which utilises font ANDROID_ID that is unique to each combination of the app-
detection, canvas, WebGL, etc to fingerprint devices. Table IV signing key, user, and device to identify unique devices in our
presents the results and demonstrates GYROID, MAGID, dataset.
and ACCID provide more entropy than traditional browser
fingerprinting techniques. While GYROID is unique for every
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY 8

During our experiment, we deployed the Android app on by both tests at the 0.05 significance level. The result suggests
AWS Device Farm4, Firebase Test Lab5, App Centre6, and that we may need a finer-grained analysis for the main-
Sauce Labs7 to collect data from various Android device diagonal elements. When we run a normality test on data from
models. Since we only found per-device calibration on Pixel each device model separately we find that the main-diagonal
phones other than the Pixel 1/1 XL, we focus our analysis on elements also show strong normality.
these devices. By the end, we have collected data from 152
unique Pixel devices. Correlation Analysis. To test for correlation, we run the
Pearson correlation test on each Dij and find that D12 and
Using the raw accelerometer data, we generate the ACCID D13 are strongly correlated with D21 and D31 at the 0.01
for each device and use clustering to determine whether two significance level, respectively. Therefore, we exclude D21 and
devices have the same ACCID. We compare the results with D31 from our entropy calculation to avoid over-estimation.
Fingerprintjs2 in Table V. For Pixel 4 and 4 XL devices,
we also calculate their GyroID and compared it with other Entropy Calculation. We first calculate the entropy of
fingerprints. As shown in the table, both ACCID and GYROID non-diagonal elements in D, excluding D21 and D31. For
uniquely identify every Pixel device while multiple devices each non-diagonal element, we estimate the parameters of
have the same fingerprint generated by Fingerprintjs2. In the normal distribution, including the mean and standard
particular, 14 out of 45 Pixel 4/4 XL devices have the same deviation , from the dataset. Technically, it is not a strict
Fingerprintjs2 fingerprint. This is likely because the embedded normal distribution since each element can only be an integer.
WebView with default configuration does not expose many Nevertheless, it is a result of rounding, and thus we can still
distinctive characteristics when two devices are running the use the normal distribution to estimate the entropy.
same Android version. The fingerprint is likely to have more
entropy if Fingerprintjs2 is running in an Android browser. In general, the entropy of a discrete random variable X,
Nevertheless, unlike SENSORID, which is a hardware iden- which is denoted as H(X), can be calculated by:
tifier, Fingerprintjs2 cannot track users as they move across
Android browsers. H(X) = - P(xi) log2 P(xi) (5)

In addition, we have tried to generate the SENSORID for xi X
each device using the web sensor data collected via JavaScript
in the embedded WebView. We then differentiate devices based where P(xi) is the probability of X being equal to xi. In
on their SENSORID, generated from the web data, using our case, we regard the element Dij as the variable X. Then,
clustering. We successfully identified all unique Pixel devices we have xi {-65535, . . . , 65535} because of the 16-bit
by their ACCID. For Pixel 4 and 4 XL phones, we were also resolution. Suppose X N (, 2) with the density function
able to identify every individual device by their GYROID.
f (x), then we can calculate P(xi) as follows:
V. DISCUSSION
xi+0.5
In this section, we discuss some possible concerns regarding
the validity of this research. f (x) dx, if xi (-65535, 65535)

A. Is SENSORID unique for iOS devices?

To study how unique is SENSORID, we first study the
GYROID of all iOS devices with an estimated nominal gain xi -0.5
of 61 mdps. Device models included in this category can be
found in Table I. We choose this category for two reasons.
First, all device models in this category are modern devices
which contain an M-series motion coprocessor and this makes -65534.5
it possible to extract their exact gain matrix. Second, devices
with different default gain may have a different GYROID
distribution, so we select the larger size group, which contains P(xi) = f (x) dx, if xi = -65535 (6)
693 devices in total. For simplicity, we denote the GYROID
as D Z33 in the following analysis. -

Normality Analysis. To test for normality, we applied
both the Kolmogorov-Smirnov test and the Shapiro-Wilk test +
of normality for each element in D. Results show that the
non-diagonal elements in D have strong normality, while
elements in the main diagonal (D11, D22, D33) are rejected
f (x) dx, if xi = 65535
4https://aws.amazon.com/device-farm
5https://firebase.google.com/docs/test-lab
6https://appcentre.ms
7https://saucelabs.com 65534.5

By this equation, we calculate the entropy of D12, D13,
D23, and D32. For main-diagonal elements (i.e., D11, D22,
and D33), we calculate their entropy on a per device type basis.
Here, we use the iPhone 6S as an example to calculate the

GYROID entropy because it is the most popular device model
in our dataset (127 devices). For these iPhone 6S devices, we
adopt a similar approach and apply both Equation 5 and 6 to

calculate the entropy. As a result, we estimate the GYROID
for iPhone 6S has about 42 bits of entropy.

By the same analysis, we estimate the entropy of the

MAGID for iPhone 6S. If adversaries launch the attack using
the rounding option (III-D), each element could have 1
uncertainty. In this case, we estimate that the MAGID contains
about 25 bits of entropy. The MAGID should have more
entropy if adversaries choose the clustering option. Since we
only have 10 old-generation iOS devices that have an ACCID,
we do not include ACCID into the SENSORID entropy calcula-
tion. We observe no evidence of strong correlation between the

MAGID and GYROID. Therefore, we estimate the SENSORID
for iPhone 6S has around 67 bits of entropy.

Uniqueness Analysis. There were 728M active iPhones
worldwide in April 2017 and the iPhone 6S devices accounted

for 18% of them [13]. Therefore, there were around 131M
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY 9

iPhone 6S devices. From the birthday problem, we know that TABLE VI: SENSORID entropy estimation (Pixel devices)
the chance of two iPhone 6S devices having the same SEN-
SORID is around 0.0058%, suggesting it is a globally unique Fingerprint Device Model # Devices Entropy (bits)
device fingerprint. In addition, the SENSORID is orthogonal ACCID
to other fingerprinting techniques. Therefore, adversaries can GYROID Pixel 2/2 XL 46 ~14
combine the SENSORID with other metadata (e.g., system Pixel 3/3 XL/3a/3a XL 61 ~12
language) or other fingerprinting techniques (e.g., canvas fin- 45 ~25
gerprinting) to further increase the fingerprint entropy. Pixel 4/4 XL
45 ~45
Limitations. Results from both the Kolmogorov-Smirnov Pixel 4/4 XL
and Shapiro-Wilk normality tests suggest that values in D are
consistent with a normal distribution, but it is possible that series (Pixel 2/2 XL), Pixel 3 series (Pixel 3/3 XL/3a/3a XL),
the actual distribution is not normally distributed in the tail and Pixel 4 series (Pixel 4/4 XL). For each category, we anal-
regions. For example, manufacturers may discard sensors that yse the normality of each value and the correlation between
have an extreme value in the gain matrix; this would reduce the values in the fingerprint. For Pixel 2 and 3 series, the ACCID
available entropy. We therefore need to consider whether non- only has non-zero values in the leading diagonal (D11, D22,
normal distributions might invalidate our entropy calculations. D33), and thus it provides less entropy than the Pixel 4 series.
For Pixel 4 series, we find that some off-diagonal values in
Firstly, it is worth mentioning that this kind of rejection the ACCID/GYROID are strongly correlated with each other.
policy is unlikely in practice; one of the key benefits of factory Thus, we only keep one of the dependent variables in the
calibration is that sensors with anomalous physical gains will entropy calculation to avoid over-estimation.
still perform well when calibrated. More importantly, the
calculation of entropy is dominated by the core shape of the Using a similar method to the one used in our previous
distribution, where we have abundant data. Non-Gaussianity work on the iOS magnetometer, we estimate the entropy based
may affect the tails of the distribution, but this would have a on the assumption that adversaries choose to attack using the
negligible effect on the calculated entropy. To give a concrete rounding option, which has 1 uncertainty for each element.
example: we found all values in D fall inside the range Results are presented in Table VI. In addition, we find off-
(-4, +4). If we make the assumption that values outside diagonal elements in GYROID are strongly correlated with off-
this range are discarded, we still estimate the SENSORID diagonal elements in ACCID in Pixel 4 series devices. This
provides around 67 bits of entropy for the iPhone 6S. is likely because the accelerometer and gyroscope are inte-
grated into the same chip (LSM6DSR). Therefore, to estimate
A related concern is there could be undetected higher-order the entropy of SENSORID, the combination of ACCID and
correlations between values in D. A similar argument applies GYROID, we simply add the entropy provided by the main-
in this case: the entropy calculation is dominated by the core diagonal variables in the ACCID to the entropy provided by
of the (now multivariate) distribution, where we have abundant the GYROID. As a result, we estimate the SENSORID provides
data, and where we see no evidence of non-independence. In around 57 bits of entropy; a precise estimate of entropy is
the tail regions, non-independence might go undetected, but difficult since we only have data from 45 Pixel 4/4 XL devices
this would have little impact on the calculated entropy. whereas in our previous study with iOS we used data from
127 iPhone 6S devices. Assuming that our entropy estimate
Ultimately, the calculation of entropy cannot be done with is accurate, and analysing this as an example of the birthday
absolute rigour given a finite number of samples from an un- problem, if there are 100 million Pixel 4/4 XL devices in the
known distribution, but it is still possible to perform a thorough market, then the probability that every device has a globally
analysis, and significant errors in the estimated entropy of unique SensorID is around 97%.
SENSORID due to non-Gaussianity or non-independence are
very unlikely. C. Is SENSORID correlated with the manufacturing batch?

B. Factory calibration in Android devices To answer this question, we first study the correlation
between the SENSORID and the country of the device, which
Rooted Android handsets provide access to the gain matrix is inferred from the IP address when a user submits data.
values for the motion sensors in the local file system on boot. We do not find any evidence of strong correction at the 0.05
We therefore confirmed that our distinct estimates for the significance level. In addition, we collected gyroscope data
ACCID on two Pixel 3 devices were correct as well as our from 25 iOS devices in an Apple Store. Some of these devices
estimated ACCID and GYROID values for a Pixel 4 device. have similar serial numbers, which suggests they may come
While the magnetometer in the Pixel 3/4 also has a full gain from the same manufacturing batch. However, the GYROID
matrix, its values appear to be the same for all devices of of these devices differs significantly. Furthermore, there is no
the same model and thus does not provide any entropy. The significant difference in the GYROID distribution for devices
motion sensors in other Android devices may also be factory from the Apple Store and for devices that we collect otherwise.
calibrated. If the calibration is restricted to offsets (i.e., bias
compensation) then our approach is ineffective since it targets D. Consistency of SENSORID
the gain matrix and cannot recover bias compensation.
We have not observed any change in the SENSORID of
To estimate the entropy of SENSORID for vulnerable Pixel our test devices in the past 16 months. Our dataset includes
devices, we group these devices into three categories: Pixel 2 iOS devices running iOS 9/10/11/12 and Pixel devices running
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY 10

Android 8/9/10. We have tested compass calibration, factory

reset, and updating operating system; the SENSORID always 30

stays the same. We have also tried measuring the sensor data iOS 11.4.1
20

at different locations and under different temperatures; we

confirm that these factors do not change the SENSORID either. 10

Count 0

E. Impact and responsible disclosure 10

We followed a responsible disclosure procedure and re- 5 iOS 12.3.1
ported this vulnerability to Apple on 3rd August 2018 and
Google on 10th December 2018. In particular, we suggested 0
two possible countermeasures. The first is to add a random
noise R31, from the uniform distribution in the range -40000 -30000 -20000 -10000 0
[-0.5, 0.5], to each ADC output. The added noise obfuscates
the effect of quantisation making the attack much harder. Gyroscope Output in y axis (2-16 dps)
The second approach we proposed is to round the calibrated
sensor output to the nearest multiple of the nominal gain. This Fig. 5: Histogram of raw gyroscope data of an iPhone X
approach is more practical to apply since it does not require
access to the ADC values. A. Analysis of Apple's Fix

In iOS 12.2, Apple adopted our suggestion and added Fig. 5 presents the histogram of the raw gyroscope data in
random noise to sensor outputs (CVE-2019-8541). In addition, the y axis collected from the same iPhone X with two different
Apple removed access to motion sensors from Mobile Safari iOS versions. In both cases, the device is at rest on a desk.
by default and in later versions removed motion sensor access When the device is running iOS 11.4.1, the quantisation in the
from WebKit as well. Recently, Google pushed a fix in histogram is clear and we can recover the exact gain matrix
Android 11 that rounds the motion sensor outputs to the (III-B). To mitigate our attack, Apple added random noise to
nearest multiple of the nominal gain. the gyroscope outputs in iOS 12.2, concealing the quantisation
information. Fig. 5 suggests that the added noise follows a
When running an iOS version prior to iOS 12.2, all iOS uniform distribution, which is one of the countermeasures
devices that have motion sensors can be fingerprinted by this we proposed to Apple. However, we notice there are some
approach, including the iPhone XS and iPhone XS Max. A peculiarities in the noise added.
SENSORID can be generated by both apps and mobile web-
sites and requires no user interaction. Both mainstream iOS To figure out the range of the uniform noise applied, we
browsers (Safari, Chrome, Firefox, and Opera) and privacy- first obtain the gyroscope gain matrix of an iOS device when
enhanced browsers (Brave and Firefox Focus) were vulnerable it is running an iOS version before iOS 12.2. Then, we update
to this calibration-based fingerprinting attack, even with the the device to the latest iOS version and take 20K gyroscope
fingerprinting protection mode turned on. For Google Pixel measurements from the device at 200 Hz when the device is
phones running Android 10, we notice that some privacy- at rest on a desk. We denote the gain matrix as G and these
enhanced browsers, including Brave and Tor Browser, do block gyroscope outputs as O. Then, the underlying bias-corrected
access to motion sensors by default while others (Chrome, ADC outputs I (i.e., I = A + B) can be estimated by:
Firefox, Firefox Focus, Opera, and Duckduckgo) do not. Using
a browser that blocks motion sensor access could protect Pixel I = round(G-1O) (7)
phone users from this attack when browsing online. A recent
study shows that motion sensor data is accessed by 2 653 Although the estimated ADC values may not be accurate
of the Alexa top 100K websites, including more than 100 due to perturbation, it gives us useful insights about the added
websites exfiltrating motion sensor data to remote servers [14]. noise. Furthermore, we can get the noise estimate, N, by:
This is troublesome since it is likely that the SENSORID
can be calculated with exfiltrated data, allowing retrospective N = O - GI
device fingerprinting. The latest iOS devices which always
run iOS 12.2 or later so the attack described does not work. By way of an example, Fig. 6 presents the histogram of
Nevertheless, a dedicated attacker may still be able to extract the estimated gyroscope noise of an iPhone XS. As shown in
the fingerprint (VI). the Fig. 6, the majority of the estimated noise are distributed
uniformly in the range [-1997, 1997] 2-16 dps. The small
VI. APPLE'S FIX number of outliers are likely produced due to the inaccurate
estimation of the ADC values in Equation 7.
Apple declined to share the details of the fix deployed in iOS
12.2. Therefore we reverse-engineer Apple's fix by studying We have also tested other iOS devices and observed the
the gyroscope outputs in iPhone devices with iOS 12.2 or later; same result. This confirms that Apple did not add ran-
we show that the random noise applied does not fully conceal dom noise in the range [-0.5, 0.5] to the ADC values as
the calibration fingerprint. we proposed but instead added random noise in the range
[-1997, 1997]2-16 dps to the calibrated signal. Because the
width of the random noise is slightly narrower than the sensi-
tivity of some gyroscope axes, it leaks more information than
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY 11

200 Furthermore, we define the range-related likelihood function
for each data sample as follows:
150

100 f (i)
T
50 lr (i ) = exp(- )

0

Count -2000 -1000 0 1000 2000 where exp() is the natural exponential function and T is
the temperature variable used in simulated annealing that
200 decreases over iterations.

150 Although the likelihood function lr(i) penalises data
samples with an offset beyond the added noise range, it does
100 not give us any information about the distribution of data
within the range. In general, the ADC outputs of the gyroscope
50 in every axis follow a normal distribution when the device is
resting on a platform such as a desk (as shown in Fig. 5). If
0 the device has moved during the data collection, we can use a
stationary position filter to get the segments with stationary
1980 2000 2020 measurements. Therefore, we can fit a normal distribution
N (a, a) to Ia for each axis a {x, y, z}. Then, based
Estimated Gyroscope Noise (2-16 dps) on the normal distribution, we can calculate the distribution-
related likelihood function, ld(Ii), by:
Axis x y z

Fig. 6: Histogram of estimated gyroscope noises (iPhone XS)

our original proposal. In the case of the iPhone XS in Fig. 6, ld(Ii) = pa(Iia )
the width of the perturbation, 3995, is lower than the sensitivity
of all three axes (4012, 4031, and 4016, respectively). Here, we a{x,y,z}
show that we can recover the gain matrix from the noisy data
by performing a maximum likelihood search using simulated where pa() is the probability density function of the normal
annealing. distribution N (a, a) and Iia is the output Ii in the axis a.

B. Attack of Apple's Fix Finally, we define our objective function L(O|G) as a

In this section, we first define the objective function to quan- negative log likelihood function:
tify the likelihood of observing the outputs given a gain matrix.
Then, we show that the exact gain matrix can be estimated N
from the objective function using simulated annealing.
L(O|G) = - log(lr(i)ld(Ii))
Objective Function. For a candidate gain matrix G, we
estimate the corresponding bias-corrected ADC outputs I by: i=1

I = round(G-1O) where N is the number of gyroscope outputs. Then, the true
gain matrix can be estimated by the following equation:
Here, we did not subtract sensor outputs to remove the bias as
we did in III-B because it would spread the noise (double the G = arg min L(O|G) (8)
noise range) and make the ADC value estimation less accurate.
Both the O and G are in the units of 2-16 dps so they only G
contain integer values. Nevertheless, the estimated I is not
guaranteed to be correct due to the perturbation, which is why Simulated Annealing. Simulated annealing is a probabilis-
we observed a few outliers in Fig. 6. tic technique for solving optimisation problems and is often
used in the presence of large numbers of local optima [15].
Then, we estimate the clean gyroscope outputs (i.e., without Since the objective function in Equation 8 is highly non-
added noise) by: smooth, we use simulated annealing to solve this optimisation
problem.
O = GI
First, we set the initial state of the candidate gain matrix
And the offset between the estimated outputs O and observed to the nominal value (i.e., G0 = G0) and the temperature
outputs O can be calculated by: parameter T to 10. The temperature T will decrease in each
iteration and finishes at 0.1. Then, we calculate the objective
function L(O|G0) and denote its value as L0.

In each following round t, we propose a new candidate gain
matrix by adding a random perturbation to the previous state:

=O-O Gt = Gt-1 + round(tRt) (9)

Since the added noise is uniformly distributed in the range Here, Rt is a 3-by-3 matrix that contains random floating-
[-1997, 1997] 2-16 dps, any offset beyond this range is
caused by either an incorrect gain matrix (i.e., G = G) or point values sampled from a standard uniform distribution at
incorrect ADC estimations (i.e., I = I). To quantify the error round t. We also use a step parameter t to control the step
in each data sample, we define the following error function: size at each round; its initial state is set to 5 (i.e., 0 = 5) to

f (i) = max(|| - 1997, 0) allow bigger steps in the beginning.
Then, we calculate the objective value Lt and compare it
i
with the previous objective value Lt-1. If Lt is lower than
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY 12

Value 20 Variable VII. RELATED WORK
D11
0 1000 2000 3000 4000 D12 Device fingerprinting is an important technique for app
D13 developers and advertisers to track their users. The IP address
-20 D21 is one of the earliest identifiers used to fingerprint devices.
D22 However, the adoption of dynamic IP allocation and network
-40 D23 address translation, particularly for home PCs and mobile
0 D31 devices, has greatly reduced the effectiveness of this approach.
D32 Cookies are also commonly used to track users across web-
D33 sites. However, cookies are stored locally and can be changed
by users at any time. In fact, many privacy-focused browsers,
5000 such as Brave and Safari, by default block all third-party
cookies. In addition, regulations in the US and Europe require
Iteration websites to obtain user-permission before using cookies, which
also decreases the usability of this approach [16].
Fig. 7: Estimated GYROID at each iteration (iPhone XS)
A variety of IDs in the device can be used as fingerprints,
Lt-1, we always accept the proposal and keep Gt as the latest including the IMEI, UDID, and MAC address of hardware
estimate of gain matrix. Otherwise, we choose to accept Gt modules. A study in 2011 showed that these identifiers were
or keep Gt-1 probabilistically to prevent getting stuck in a widely used in mobile apps [17]. However, both Apple and
local minimum. If the proposal is accepted, we also keep the Google have adopted more stringent privacy policies to pre-
corresponding object value (i.e., Lt = Lt-1) and increase the vent developers from accessing these unique IDs. Addition-
step size slightly (e.g., t+1 = t 1.05) to allow faster ally, many information flow tracking systems, such as Taint-
exploration. Otherwise, the step size will be decreased slightly Droid [18] and Panorama [19], can capture these malicious
(e.g., t+1 = t/1.05) to help finding the minimum. We also behaviours and report them to users.
set a lower bound for t at 0.7 to prevent the step size being
too small to update the candidate gain matrix in Equation 9. Passive Device Fingerprinting Passive device fingerprint-
ing is the action of characterizing a target device by observing
Result. We test the algorithm on our iPhone XS test handset; its network traffic. It analyses the captured data to reveal
the GYROID of this iPhone XS is shown in Equation 4. In fingerprintable patterns (e.g., the software, operating system,
particular, we first collect 50K gyroscope samples from the or hardware components). Since passive fingerprinting only
device at 200 Hz when it is stationary. We run our algorithm relies on network traffic, it is compatible with more devices,
on this data for 5K iterations and present the result in Fig. 7. difficult to discover, and can track users across different
The figure shows the estimated GYROID stabilises after round browsers. In general, most passive fingerprinting techniques
3383; the stabilised GYROID is the same as the one we rely on machine learning models to differentiate devices.
estimated before noise was added. We have also tested the Uluagac et al. applied Artificial Neural Networks (ANNs)
algorithm on an iPhone X and we were also able to recover to classify devices based on the time-variant behaviour in
the exact gain matrix using the same approach and setups. their traffic [20]. Neumann et al. evaluated several features
extracted from network traffic and found that the frame inter-
Discussion. The experiments show that Apple's fix is still arrival time, which is correlated with the hardware status and
susceptible to probability-based attacks. However, we found installed applications, is the most effective feature for device
that the attacker would need at least 50K data samples. Since fingerprinting [21]. Machine learning approaches usually re-
the sample frequency of the gyroscope in recent iOS devices quire more computing resources and a large amount of data for
is 200 Hz, this means the attacker would need to collect training. Thus, passive fingerprinting techniques usually have
gyroscope output for at least 4.2 minutes when the device a longer response time than active fingerprinting techniques.
is resting on a platform. In addition, the attack we proposed
is also computation-intensive and thus it is unlikely to be Active Device Fingerprinting Active fingerprinting tech-
implemented directly inside a mobile app. These restrictions niques deploy embedded code to actively gather informa-
make the attack less practical. Since Apple has also removed tion about a device and use these characteristics to make a
access to motion sensors from Safari and Webkit such an distinction between different devices. For example, Finger-
attack can now only be conducted via an app. printjs2 [12] is a popular browser fingerprinting library that
utilises the characteristics of a browser, including the user-
Even if Apple had adopted our proposed mitigation (adding agent, version, plugins, fonts, and canvas. Apple has realised
uniform noise in the range [-0.5, 0.5] to ADC outputs) this the risk of browser fingerprinting. From macOS Mojave,
maximum likelihood estimation based attack would still work. Safari scrubs most distinctive browser data, exposing only
However, the attacker would need even more samples. A generic configuration information and default fonts [22]. The
better-designed noise scheme may enhance security further, information about the operating system (e.g., version and root
but it might be harder to implement in mobile devices and permission) and system configurations (e.g., network and flash
could degrade the user experience. configurations) can also be used to identify devices. Although
this information cannot uniquely identify a device, it can be
combined with other features from browsers and embedded
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY 13

hardware to increase precision. held in hand. They also applied their approach to making a
Hardware Fingerprinting Hardware fingerprints are gen- distinction between 85 iPhone 6 devices. When devices were
held in hand, only 60% of these devices produced unique
erally consistent because it is typically difficult to replace fingerprints, which, by reference to the birthday problem, in-
the embedded hardware. Some embedded hardware, such as dicates that their approach provides around 13 bits of entropy.
motion sensors, can be accessed by both JavaScript running in Based on the motion sensor data that they collected through
a web browser and by mobile apps installed on a smartphone JavaScript, we correctly identify all iOS devices in the dataset
and does not require any permission from users. Hardware based on the calibration behaviour without knowing the device
modules that have been studied for fingerprinting purposes model in advance. Most recently, Das et al. studied the sensor
include: RF modules [23], [24], motion sensors [25], [26], API usage in popular websites [14]. They showed that 2 653 of
clocks [27], camera [28], [29], and acoustic components [30], the Alexa top 100K websites accessed motion sensor data and
[31]. In particular, a well-known hardware fingerprint in digital 63% of the scripts for accessing motion sensors also engaged
forensics is the Photo Response Non-Uniformity (PRNU) in browser fingerprinting. Although the prior art has realised
of digital cameras. The PRNU is a result of manufacturing the idiosyncrasies across different sensors, none of them, to
imperfections and inhomogeneity of silicon wafers. The classic the best of our knowledge, has exploited the factory calibration
algorithm to estimate the PRNU was presented by Luks to form a device fingerprint; this paper fills the gap.
et al. [32]. Similar to SENSORID, the PRNU itself is stable to
environmental conditions and is likely to be globally unique. VIII. CONCLUSION
Nevertheless, the exact value of the PRNU cannot be extracted
and the quality of the estimated PRNU is dependent on the In this paper we introduced the factory calibration finger-
imaging processing used in the camera. Recently, Ba et al. printing attack: a new method of fingerprinting devices with
presented a protocol named ABC to authenticate smartphones embedded motion sensors by careful analysis of the sensor
using the PRNU of their built-in camera [33]. According to output alone. We demonstrated the effectiveness of this attack
their study, the PRNU estimated from one photo alone can on iOS devices and found the lack of precision in the M-
identify the source smartphone camera with high accuracy. series coprocessor helps the generation of such a fingerprint.
However, their study only focuses on two device models with Our attack is easy to conduct by a website or an app in
a single camera. It is unclear whether the image fusion process under 1 second, requires no special permissions, does not
in multi-camera devices would degrade the performance. In require user interaction, and is computationally efficient. Our
addition, accessing the camera or photos would require explicit attack can also be applied retrospectively to an historic archive
permission from the user and thus it is less practical. In of sensor data. Using the iPhone 6S as an example, we
addition to smartphones, hardware fingerprinting also has showed that the GYROID contains about 42 bits of entropy
applications on other targets. In particular, Son et al. used and the MAGID provides an additional 25 bits of entropy.
the power-on offset calibration of the gyroscope embedded Furthermore, we demonstrated that the combination of the
in a drone to serve as its identity [34]. However, this power- MAGID and GYROID is very likely to be globally unique for
on offset calibration is not factory calibration. The calibrated iPhone 6S, does not change on factory reset or after a software
offsets are dynamically calculated every time the drone is update. For older generations of iOS devices, such as the
turned on. Thus, it changes over time and varies with tem- iPhone 4S and iPad Mini, we can further extract the ACCID
perature. By comparison, our work is the first to recover the and use it to provide extra entropy. In addition to iOS devices,
factory calibration parameters that are digital values stored in we also conducted a large study of popular Android device
persistent memory and do not change afterwards. models in the market and found that all Google Pixel phones
except for Pixel 1/1 XL can be fingerprinted by our attack.
Existing hardware fingerprinting techniques are mostly We estimate the SENSORID entropy for each vulnerable Pixel
based on machine learning approaches. Bojinov et al. demon- model and show that it provides approximately 57 bits of
strated it is possible to fingerprint both the speakerphone- entropy for Pixel 4/4 XL.
microphone system and the accelerometer using typical clus-
tering approaches [26]. However, they only correctly identified Furthermore, we analysed Apple's fix to our attack and
53% of the devices in their dataset even after integrating showed that it is still possible to extract the GYROID even after
the UA string into their model. Das et al. applied several the fix, although doing so would require significantly more
supervised machine learning models to make a distinction data and computation power. Since it is no longer possible to
between devices based on the gyroscope and accelerometer access the motion sensors in iOS browsers, the opportunity to
readings [35]. To increase accuracy, they used inaudible sound launch this attack is restricted to installed apps.
to stimulate the motion sensors. As a countermeasure, they
suggested to better calibrate the motion sensors. However, they The concept of a calibration fingerprint is widely applica-
did not realise that the calibration process could leak informa- ble. Although this paper mainly targets the motion sensors
tion if not properly implemented. More recently, they further found in mobile devices, we anticipate the factory calibration
improved its accuracy by introducing a voting scheme among information used in other embedded sensors may also be
different classifiers [36]. Nevertheless, their approach requires recovered and used as a fingerprint, and therefore we expect
a lot of computing resources, which cannot be implemented future research will successfully perform factory calibration
locally on the device. Even then, their approach achieved less fingerprinting attacks on other types of sensor.
than 60% F1 score in an open-world setting when devices were
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY 14

ACKNOWLEDGEMENT [19] H. Yin, D. Song, M. Egele, C. Kruegel, and E. Kirda, "Panorama:
capturing system-wide information flow for malware detection and
Jiexin Zhang is supported by the China Scholarship Council. analysis," in Proceedings of the 14th ACM conference on Computer
and communications security (CCS). ACM, 2007, pp. 116127.
Alastair R. Beresford is partly supported by EPSRC under
[20] A. S. Uluagac, S. V. Radhakrishnan, C. Corbett, A. Baca, and R. Beyah,
Grant No.: EP/M020320/1. We would like to thank Nokia "A passive technique for fingerprinting wireless devices with wired-
side observations," in 2013 IEEE Conference on Communications and
Bell Labs for supporting this work and valuable discussions. Network Security (CNS). IEEE, 2013, pp. 305313.

The opinions, findings, and conclusions or recommendations [21] C. Neumann, O. Heen, and S. Onno, "An empirical study of passive
802.11 device fingerprinting," in 2012 32nd International Conference
expressed are those of the authors and do not necessarily on Distributed Computing Systems Workshops (ICDCSW). IEEE, 2012,
pp. 593602.
reflect those of the funders. We thank Matthew Hall, Stephan
[22] L. H. Newman. (2018) Apple just made safari the good
A. Kollmann, Diana A. Vasile, Ricardo Mendes, Andrew Rice, privacy browser. [Online]. Available: https://www.wired.com/story/
apple-safari-privacy-wwdc
and Amanda Prorok for helpful discussion and insight. We also
[23] T. Kohno, A. Broido, and K. C. Claffy, "Remote physical device fin-
thank anonymous reviewers for their feedback on the paper. gerprinting," IEEE Transactions on Dependable and Secure Computing,
vol. 2, no. 2, pp. 93108, 2005.
REFERENCES
[24] V. Brik, S. Banerjee, M. Gruteser, and S. Oh, "Wireless device identi-
[1] G. Hogben. (2017) Changes to device identifiers in android o. fication with radiometric signatures," in Proceedings of the 14th ACM
[Online]. Available: https://android-developers.googleblog.com/2017/ International Conference on Mobile Computing and Networking. ACM,
04/changes-to-device-identifiers-in.html 2008, pp. 116127.

[2] J. Zhang, A. R. Beresford, and I. Sheret, "Sensorid: Sensor calibration [25] S. Dey, N. Roy, W. Xu, R. R. Choudhury, and S. Nelakuditi, "Accelprint:
fingerprinting for smartphones," in 2019 IEEE Symposium on Security imperfections of accelerometers make smartphones trackable," in Pro-
and Privacy (SP). IEEE, 2019, pp. 638655. ceedings of the 2014 Network and Distributed System Security (NDSS)
Symposium, 2014.
[3] S. Poddar, V. Kumar, and A. Kumar, "A comprehensive overview of
inertial sensor calibration techniques," Journal of Dynamic Systems, [26] H. Bojinov, Y. Michalevsky, G. Nakibly, and D. Boneh, "Mobile device
Measurement, and Control, vol. 139, no. 1, p. 011006, 2017. identification via sensor fingerprinting," Computing Research Repository
(CoRR), 2014. [Online]. Available: https://arxiv.org/abs/1408.1416
[4] A. Grammenos, C. Mascolo, and J. Crowcroft, "You are sensing, but
are you biased? a user unaided sensor calibration approach for mobile [27] I. Sanchez-Rola, I. Santos, and D. Balzarotti, "Clock around the clock:
sensing," Proceedings of the ACM on Interactive, Mobile, Wearable and time-based device fingerprinting," in Proceedings of the 2018 ACM
Ubiquitous Technologies (IMWUT), vol. 2, no. 1, p. 11, 2018. SIGSAC Conference on Computer and Communications Security (CCS),
2018, pp. 15021514.
[5] D. Tedaldi, "Imu calibration without mechanical equipment," Ph.D.
dissertation, University of Padova, 2013. [28] J. Fridrich, "Digital image forensics," IEEE Signal Processing Magazine,
vol. 26, no. 2, 2009.
[6] T. Michel, P. Geneves, H. Fourati, and N. Layada, "On attitude
estimation with smartphones," in 2017 IEEE International Conference [29] D. Valsesia, G. Coluccia, T. Bianchi, and E. Magli, "Compressed
on Pervasive Computing and Communications (PerCom). IEEE, 2017, fingerprint matching and camera identification via random projections,"
pp. 267275. IEEE Transactions on Information Forensics and Security, vol. 10, no. 7,
pp. 14721485, 2015.
[7] D. Tedaldi, A. Pretto, and E. Menegatti, "A robust and easy to implement
method for imu calibration without external equipments," in 2014 IEEE [30] A. Das, N. Borisov, and M. Caesar, "Do you hear what i hear?
International Conference on Robotics and Automation (ICRA). IEEE, fingerprinting smart devices through embedded acoustic components,"
2014, pp. 30423049. in Proceedings of the 2014 ACM SIGSAC Conference on Computer and
Communications Security (CCS). ACM, 2014, pp. 441452.
[8] W. Ren, T. Zhang, H. Zhang, L. Wang, Y. Zhou, M. Luan, H. Liu, and
J. Shi, "A research on calibration of low-precision mems inertial sen- [31] Z. Zhou, W. Diao, X. Liu, and K. Zhang, "Acoustic fingerprinting
sors," in 2013 25th Chinese Control and Decision Conference (CCDC). revisited: Generate stable device id stealthily with inaudible sound," in
IEEE, 2013, pp. 32433247. Proceedings of the 2014 ACM SIGSAC Conference on Computer and
Communications Security, 2014, pp. 429440.
[9] I. Frosio, F. Pedersini, and N. A. Borghese, "Autocalibration of mems
accelerometers," IEEE Transactions on Instrumentation and Measure- [32] J. Lukas, J. Fridrich, and M. Goljan, "Digital camera identification from
ment, vol. 58, no. 6, pp. 20342041, 2009. sensor pattern noise," IEEE Transactions on Information Forensics and
Security, vol. 1, no. 2, pp. 205214, 2006.
[10] STMicroelectronics. (2010) L3g4200d: three axis digital output
gyroscope. [Online]. Available: https://www.elecrow.com/download/ [33] Z. Ba, S. Piao, X. Fu, D. Koutsonikolas, A. Mohaisen, and K. Ren,
L3G4200_AN3393.pdf "Abc: Enabling smartphone authentication with built-in camera," in 25th
Annual Network and Distributed System Security Symposium, NDSS
[11] ----. (2009) Lis331dlh: Mems digital output motion sensor. [Online]. 2018, 2018.
Available: http://www.st.com/resource/en/datasheet/lis331dlh.pdf
[34] Y. Son, J. Noh, J. Choi, and Y. Kim, "Gyrosfinger: Fingerprinting drones
[12] Valve. (2018) Modern & flexible browser fingerprinting library. for location tracking based on the outputs of mems gyroscopes," ACM
[Online]. Available: https://github.com/Valve/fingerprintjs2 Transactions on Privacy and Security (TOPS), vol. 21, no. 2, pp. 125,
2018.
[13] J. Dunn. (2018) It looks like apple will have plenty
of iphone owners that could use an upgrade this [35] A. Das, N. Borisov, and M. Caesar, "Tracking mobile web users through
holiday season. [Online]. Available: http://uk.businessinsider.com/ motion sensors: attacks and defenses." in Proceedings of the 2016
apple-iphone-most-popular-model-newzoo-chart-2017-7 Network and Distributed System Security (NDSS) Symposium, 2016.

[14] A. Das, G. Acar, N. Borisov, and A. Pradeep, "The web's sixth sense: [36] A. Das, N. Borisov, and E. Chou, "Every move you make: exploring
a study of scripts accessing smartphone sensors," in Proceedings of practical issues in smartphone motion sensor fingerprinting and counter-
the 2018 ACM SIGSAC Conference on Computer and Communications measures," Proceedings on Privacy Enhancing Technologies Symposium
Security (CCS), 2018. (PETS), vol. 2018, no. 1, pp. 88108, 2018.

[15] S. Kirkpatrick, C. D. Gelatt, and M. P. Vecchi, "Optimization by
simulated annealing," science, vol. 220, no. 4598, pp. 671680, 1983.

[16] Wikipedia. (2002) Privacy and electronic communications directive

  1. [Online]. Available: https://en.wikipedia.org/wiki/Privacy_and_ Electronic_Communications_Directive_2002

[17] W. Enck, D. Octeau, P. D. McDaniel, and S. Chaudhuri, "A study of
android application security." in USENIX Security Symposium, vol. 2,
2011, p. 2.

[18] W. Enck, P. Gilbert, S. Han, V. Tendulkar, B.-G. Chun, L. P. Cox,
J. Jung, P. McDaniel, and A. N. Sheth, "Taintdroid: an information-
flow tracking system for realtime privacy monitoring on smartphones,"
ACM Transactions on Computer Systems (TOCS), vol. 32, no. 2, p. 5,
2014.