Imagine a scenario: you approach a secure building, and as your hand hovers near the access control, the door opens automatically. No keys, no PIN codes, and no fingerprints required. Instead, the system identifies you by analyzing how your palm disturbs the surrounding Wi-Fi signals.
This is the core concept of a new study from the Instituto Tecnológico de Aeronáutica (ITA) in Brazil. The research explores how to utilize Wi-Fi Channel State Information (CSI) to achieve a low-cost, contactless biometric access control.
The Core Principle: Making Wi-Fi Signals “Understand” Your Palm
The key to this technology lies in Wi-Fi Channel State Information (CSI). CSI is data that reveals how wireless signals behave as they propagate, bounce, and pass through objects (including the human body).
Everyone’s palm is physically unique—there are subtle differences in palm size, finger length, and finger spacing. When a palm approaches the Wi-Fi transmitter and receiver, these unique physical characteristics interfere with the signals in predictable ways.
The key processes and methods of the experiment are as follows:
-
Hardware Setup: The team used a Raspberry Pi, placed inside a custom acrylic box.
-
Signal Control: They reduced the antenna power of the device to 1dBm to minimize external interference, allowing for precise capture of the minute signal differences caused by the palm.
-
Data Collection: Twenty volunteers (half male and half female) held their right hands 3 centimeters above the box (as shown in the image below). The system recorded the impact of the palm on the CSI data while sending and receiving Wi-Fi signals.
-
Model Training: The team collected thousands of data points and used machine learning algorithms to train the system to accurately distinguish the “signal fingerprints” of different volunteers’ palms.

In a controlled laboratory environment, the system achieved high accuracy. The researchers aim to create a low-cost, user-friendly, and non-invasive access control method that can directly utilize the existing Wi-Fi infrastructure in most buildings.
Three Major Obstacles to “Technology Implementation”
Despite the encouraging laboratory data, security experts warn that deploying this technology in the complex real world will face significant challenges.
Christina Hulka, Executive Director of the Secure Technology Alliance, points out that CSI data is extremely sensitive to environmental changes, which are ubiquitous in reality.
1. Complex Physical Environments
The CSI characteristics are closely related to the multipath reflections of signals off walls, floors, glass, and metal.
-
Obstruction and Interference: Thick concrete walls and large metal objects can block or weaken signals.
-
Environmental Changes: “Even moving a cart or adding a privacy partition can change channel characteristics enough to render the model’s ‘optimal point’ ineffective,” Hulka explains.
-
Human Interference: The human body itself is an excellent radio frequency absorber and reflector. In crowded areas or when people are moving, signals may be blocked, leading to false rejections.
2. “RF Congestion”: Signal Overload
Our living spaces are filled with various wireless signals. Hulka refers to this as the challenge of “RF congestion” (RF-business).
“Bluetooth connections from phones, other Wi-Fi networks, Zigbee traffic, and most connected devices can introduce ‘artifacts’ into the CSI data stream, severely affecting its stability and the confidence of the classifier,” she states.
Hulka adds that there is currently no foolproof solution to this problem.
3. Inconsistency in Hardware
The technology also faces issues with hardware standardization.
“Even minor differences in commercial-grade radio devices or cable stress can lead to shifts in signal phase or amplitude, which the model may misinterpret as drift in identity features,” Hulka points out.
The CISO Perspective: Why Call for Strict Standardization Testing?
For Chief Information Security Officers (CISOs) and security practitioners, a new technology being “nearly perfect” in the lab holds little practical significance. Hulka emphasizes that stricter and more transparent standardization testing must be conducted before trusting this Wi-Fi authentication.
1. Performance Validation (ISO/IEC19795-1)
Security leaders should not only look at data from a single controlled setting. Hulka suggests: “ISO/IEC19795-1 metrics should be reported under conditions across dates and sites (such as different rooms, outdoor environments, and different hardware).” This will truly reflect the system’s usability in real fluctuating environments.
2. Presentation Attack Detection (ISO/IEC30107-3)
More importantly, can the system withstand deception?
Hulka calls for: “Independent labs should be requested to conduct presentation attack detection (PAD) assessments according to ISO/IEC30107-3 standards.” This includes end-to-end system testing using realistic tools (such as 3D-printed palm models or other deceptive means) to evaluate its anti-spoofing capabilities.
Only by placing these critical error rates (such as the success rate of spoofing attacks) alongside core accuracy metrics can security practitioners comprehensively assess the technology’s usability and resilience.
Reference Link:
https://arxiv.org/pdf/2510.22133
Source: GoUpSec
The technologies, ideas, and tools mentioned in the articles published and reprinted by Heibai Zhidao are for educational exchange purposes only, and no one may use them for illegal or profit-making purposes, otherwise, the consequences will be borne by themselves!
If there is any infringement, please contact us to delete the article.
END