Sound-Proof: Usable Two-Factor Authentication Based on Ambient Sound
Nikolaos Karapanos, Claudio Marforio, Claudio Soriente, Srdjan, Capkun

TL;DR
Sound-Proof introduces a user-friendly two-factor authentication method that leverages ambient sound to verify device proximity, eliminating phone interaction and simplifying deployment without compromising security.
Contribution
It presents a novel, deployable two-factor authentication scheme using ambient sound for proximity verification, enhancing usability and ease of deployment compared to existing methods.
Findings
Ambient noise effectively distinguishes device proximity indoors and outdoors.
Users perceive Sound-Proof as more usable than Google 2-Step Verification.
Prototype works seamlessly with current smartphones and browsers.
Abstract
Two-factor authentication protects online accounts even if passwords are leaked. Most users, however, prefer password-only authentication. One reason why two-factor authentication is so unpopular is the extra steps that the user must complete in order to log in. Currently deployed two-factor authentication mechanisms require the user to interact with his phone to, for example, copy a verification code to the browser. Two-factor authentication schemes that eliminate user-phone interaction exist, but require additional software to be deployed. In this paper we propose Sound-Proof, a usable and deployable two-factor authentication mechanism. Sound-Proof does not require interaction between the user and his phone. In Sound-Proof the second authentication factor is the proximity of the user's phone to the device being used to log in. The proximity of the two devices is verified by…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsUser Authentication and Security Systems · Innovative Human-Technology Interaction · Privacy, Security, and Data Protection
