Researchers from the University of Illinois College of Engineering have demonstrated that these fingerprints exist within smartphone sensors, mainly because of imperfections during the hardware manufacturing process.
The researchers focused specifically on the accelerometer, a sensor that tracks three-dimensional movements of the phone - essential for countless applications, including pedometers, sleep monitoring, mobile gaming - but their findings suggest that other sensors could leave equally unique fingerprints.
"When you manufacture the hardware, the factory cannot produce the identical thing in millions. So these imperfections create fingerprints," said Associate Professor Romit Roy Choudhury.
Most applications do not require this level of analysis, yet the data shared with all applications - your favourite game, your pedometer - bear the mark. Should someone want to perform this analysis, they could do so, researchers said.
The study tested more than 100 devices over the course of nine months: 80 standalone accelerometer chips used in popular smartphones, 25 Android phones, and 2 tablets.
The accelerometers in all permutations were selected from different manufacturers, to ensure that the fingerprints weren't simply defects resulting from a particular production line.
"We do not need to know any other information about the phone - no phone number or SIM card number. Just by looking at the data, we can tell you which device it's coming from. It's almost like another identifier," said Dey.
In the real world, this suggests that even when a smartphone application does not have access to location information (by asking "this application would like to use your current location"), there are other means of identifying the user's activities.
To collect the data, the researchers - as with any would-be attacker - needed to sample the accelerometer data.
Each accelerometer was vibrated using a single vibrator motor - like those that buzz when a text message is received - for two-second intervals.
During those periods, the accelerometer detected the movement and the readings were transmitted to a supervised-learning tool, which decoded the fingerprint.
"Even if you erase the app in the phone, or even erase and reinstall all software, the fingerprint still stays inherent. That's a serious threat," Roy said.
You’ve reached your limit of {{free_limit}} free articles this month.
Subscribe now for unlimited access.
Already subscribed? Log in
Subscribe to read the full story →
Smart Quarterly
₹900
3 Months
₹300/Month
Smart Essential
₹2,700
1 Year
₹225/Month
Super Saver
₹3,900
2 Years
₹162/Month
Renews automatically, cancel anytime
Here’s what’s included in our digital subscription plans
Exclusive premium stories online
Over 30 premium stories daily, handpicked by our editors


Complimentary Access to The New York Times
News, Games, Cooking, Audio, Wirecutter & The Athletic
Business Standard Epaper
Digital replica of our daily newspaper — with options to read, save, and share


Curated Newsletters
Insights on markets, finance, politics, tech, and more delivered to your inbox
Market Analysis & Investment Insights
In-depth market analysis & insights with access to The Smart Investor


Archives
Repository of articles and publications dating back to 1997
Ad-free Reading
Uninterrupted reading experience with no advertisements


Seamless Access Across All Devices
Access Business Standard across devices — mobile, tablet, or PC, via web or app
