Using a smartphone and audio software to pick a physical lock

Using a smartphone and audio software to pick a physical lock
Figure depicts SpiKey attack scenario. Attacker records the sound of victim’s key insertion to infer the shape, or “secret”, of the key. Credit: DOI: 10.1145/3376897.3377853

A trio of researchers has found a way to pick an ordinary physical lock using a smartphone with special software. The three, Soundarya Ramesh, Harini Ramprasad, and Jun Han, gave a talk at a workshop called HotMobile 2020 at this year's International Workshop on Mobile Computing Systems and Applications, outlining their work.

With traditional locks, such as those found on the front doors of most homes, a person inserts the proper (metal) key and then turns it. Doing so pushes up a series of pins in the lock by a certain amount based on the ridges on the key. When the pins are pushed in a way that matches a preset condition, the tumbler can turn, retracting the metal piece of the assembly from its berth, allowing the door to open. In this new effort, the researchers have found that it is possible to record the sounds made as the key comes into contact with the pins and then as the pins move upward, and use to recreate the conditions that produce the same noises. Those conditions can be used to fabricate a metal key to unlock the door. The result is a system the team calls SpiKey, which involves use of a smartphone to record lock clicks, decipher them and then create a key signature for use in creating a new key.

The researchers acknowledged in their presentation that the weak link in their system is recording the key unlocking the door. Because of its nature, they assume that the recording would have to be done secretly so as to not alert a homeowner that their lock is being picked. They suggest that several possible options for wrongdoers, including walking past while holding a microphone, hiding a microphone nearby, or installing software on the victim's phone. Each has its own risks, they note, which would minimize the likelihood of run-of-the-mill burglars using such an approach. But for high-profile victims, the effort might be worth the risk. They say that they next plan to investigate ways to foil such attacks by modifying traditional locks.

More information: Soundarya Ramesh et al. Listen to Your Key, Proceedings of the 21st International Workshop on Mobile Computing Systems and Applications (2020). DOI: 10.1145/3376897.3377853 . PDF. … -technology/fulltext

© 2020 Science X Network

Citation: Using a smartphone and audio software to pick a physical lock (2020, August 24) retrieved 17 May 2024 from
This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no part may be reproduced without the written permission. The content is provided for information purposes only.

Explore further

Study shows side-channel phone risk via microphone and camera


Feedback to editors