Man-in-the-middle attacks on Secure Simple Pairing in Bluetooth standard V5.0 and its countermeasure

被引:40
|
作者
Sun, Da-Zhi [1 ,2 ,3 ]
Mu, Yi [3 ]
Susilo, Willy [3 ]
机构
[1] Tianjin Univ, Sch Comp Sci & Technol, TANK, Tianjin Key Lab Adv Networking, 135 Yaguan Rd,Tianjin Haihe Educ Pk, Tianjin 300350, Peoples R China
[2] Chinese Acad Sci, Inst Informat Engn, State Key Lab Informat Secur, Beijing 100093, Peoples R China
[3] Univ Wollongong, Sch Comp & Informat Technol, Inst Cybersecur & Cryptol, Wollongong, NSW 2522, Australia
关键词
Bluetooth standard; Secure Simple Pairing; Passkey entry; Man-in-the-middle attack; Home network system; USER AUTHENTICATION SCHEME; WIRELESS SENSOR NETWORKS; VULNERABILITIES; PROTOCOL;
D O I
10.1007/s00779-017-1081-6
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Bluetooth devices are widely employed in the home network systems. It is important to secure the home members' Bluetooth devices, because they always store and transmit personal sensitive information. In the Bluetooth standard, Secure Simple Pairing (SSP) is an essential security mechanism for Bluetooth devices. We examine the security of SSP in the recent Bluetooth standard V5.0. The passkey entry association model in SSP is analyzed under the man-in-the-middle (MITM) attacks. Our contribution is twofold. (1) We demonstrate that the passkey entry association model is vulnerable to the MITM attack, once the host reuses the passkey. (2) An improved passkey entry protocol is therefore designed to fix the reusing passkey defect in the passkey entry association model. The improved passkey entry protocol can be easily adapted to the Bluetooth standard, because it only uses the basic cryptographic components existed in the Bluetooth standard. Our research results are beneficial to the security enhancement of Bluetooth devices in the home network systems.
引用
收藏
页码:55 / 67
页数:13
相关论文
共 21 条
  • [1] Man-in-the-middle attacks on Secure Simple Pairing in Bluetooth standard V5.0 and its countermeasure
    Da-Zhi Sun
    Yi Mu
    Willy Susilo
    Personal and Ubiquitous Computing, 2018, 22 : 55 - 67
  • [2] Man-in-the-Middle Attack and Its Countermeasure in Bluetooth Secure Simple Pairing
    Mutchukota, Thrinatha R.
    Panigrahy, Saroj Kumar
    Jena, Sanjay Kumar
    COMPUTER NETWORKS AND INTELLIGENT COMPUTING, 2011, 157 : 367 - 376
  • [3] Practical Man-In-The-Middle Attacks Against Bluetooth Secure Simple Pairing
    Haataja, Keijo
    Toivanen, Pekka
    2008 4TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING, VOLS 1-31, 2008, : 4821 - 4825
  • [4] Two Practical Man-In-The-Middle Attacks on Bluetooth Secure Simple Pairing and Countermeasures
    Haataja, Keijo
    Toivanen, Pekka
    IEEE TRANSACTIONS ON WIRELESS COMMUNICATIONS, 2010, 9 (01) : 384 - 392
  • [5] Nino Man-In-The-Middle attack on Bluetooth Secure Simple Pairing
    Hypponen, Konstantin
    Haataja, Keijo M. J.
    2007 THIRD IEEE/IFIP INTERNATIONAL CONFERENCE IN CENTRAL ASIA ON INTERNET, 2007, : 64 - 68
  • [6] Bluetooth Man-In-The-Middle Attack Based on Secure Simple Pairing using Out of Band Association Model
    Sharmila, D.
    Neelaveni, R.
    Kiruba, K.
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON CONTROL, AUTOMATION, COMMUNICATION AND ENERGY CONSERVATION INCACEC 2009 VOL 1, 2009, : 353 - +
  • [7] On Secure Simple Pairing in Bluetooth Standard v5.0-Part II: Privacy Analysis and Enhancement for Low Energy
    Sun, Da-Zhi
    Sun, Li
    Yang, Ying
    SENSORS, 2019, 19 (15)
  • [8] Mobile Authentication Secure Against Man-In-The-Middle Attacks
    Bicakci, Kemal
    Unal, Devrim
    Ascioglu, Nadir
    Adalier, Oktay
    9TH INTERNATIONAL CONFERENCE ON FUTURE NETWORKS AND COMMUNICATIONS (FNC'14) / THE 11TH INTERNATIONAL CONFERENCE ON MOBILE SYSTEMS AND PERVASIVE COMPUTING (MOBISPC'14) / AFFILIATED WORKSHOPS, 2014, 34 : 323 - 329
  • [9] On Secure Simple Pairing in Bluetooth Standard v5.0-Part I: Authenticated Link Key Security and Its Home Automation and Entertainment Applications
    Sun, Da-Zhi
    Sun, Li
    SENSORS, 2019, 19 (05)
  • [10] Enhancing the Security of Numeric Comparison Secure Simple Pairing in Bluetooth 5.0
    Hou, Dongkun
    Zhang, Jie
    Man, Ka Lok
    2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, : 1622 - 1629