cs.CROct 7, 2026

CPU-Auth: Device Fingerprinting for Authentication via DVFS Side-Channel

Authors: Ryan Swift

Organizations: University of California, Davis

Abstract

Lack of effective authentication has resulted in numerous security and privacy breaches, including unauthorized access to protected information, identity theft, and fraud. One approach to mitigating such attacks is Multi-Factor Authentication (MFA), in which users must provide multiple pieces of information for authentication. Some secondary authentication factors include SMS text verification codes, biometrics, and tokens. Each contains at least one notable flaw: SMS is notoriously insecure; biometrics rely upon access to sensitive personal data; and tokens require dependence on third-party providers (e.g. OAuth providers). This work explores CPU-Auth, a novel authentication mechanism based on unique variations in the physical characteristics of the CPU of a computing device. By measuring the behavior of the Dynamic Voltage and Frequency Scaling (DVFS) governor remotely from within a browser, unique properties of the CPU can be leveraged to establish a hardware-based device fingerprint for use in CPU-Auth. The performance of CPU-Auth is evaluated on over 50,000 data traces using distance-based and deep learning methods. CPU-Auth is part of a larger research project, and the results provided in this report reflect only the contributions made to the project by members of this group.

Figures & tables

Appendix figures & tables3 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. Scalable Secure Biometric Authentication without Auxiliary Identifiers

    Apr 27, 2026Alexander Bienstock, Daniel Escudero, Antigoni Polychroniadou +5Biometric Identification

  2. ThermalTap: Passive Application Fingerprinting in VR Headsets via Thermal Side Channels

    May 13, 2026Mahsin Bin Akram, A H M Nazmus Sakib, OFM Riaz Rahman Aranya +3Virtual Reality