No Free Charge Theorem: a Covert Channel via USB Charging Cable on Mobile Devices
Riccardo Spolaor, Laila Abudahi, Veelasha Moonsamy, Mauro Conti, Radha, Poovendran

TL;DR
This paper demonstrates a novel covert channel attack where malicious charging stations can exfiltrate data from smartphones via USB cables without data transfer, exploiting energy consumption patterns.
Contribution
It introduces the first known method of data exfiltration through a malicious charging station using USB power lines without data transfer permissions.
Findings
Feasibility of data exfiltration via power lines demonstrated
Android prototype successfully leaks sensitive data
Attack does not require user permissions or data transfer mode
Abstract
More and more people are regularly using mobile and battery-powered handsets, such as smartphones and tablets. At the same time, thanks to the technological innovation and to the high user demands, those devices are integrating extensive functionalities and developers are writing battery-draining apps, which results in a surge of energy consumption of these devices. This scenario leads many people to often look for opportunities to charge their devices at public charging stations: the presence of such stations is already prominent around public areas such as hotels, shopping malls, airports, gyms and museums, and is expected to significantly grow in the future. While most of the time the power comes for free, there is no guarantee that the charging station is not maliciously controlled by an adversary, with the intention to exfiltrate data from the devices that are connected to it. In…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · Green IT and Sustainability · User Authentication and Security Systems
