Moon Jaegeun, Jung Im Y, Yoo Jaesoo
School of Electronics Engineering, Kyungpook National University, 80 Daehakro Buk-gu, Daegu 702701, Korea.
School of Information and Communication Engineering, Chungbuk National University, 1 Chungdaero Seowon-gu, Cheongju 28644, Korea.
Sensors (Basel). 2017 Apr 2;17(4):752. doi: 10.3390/s17040752.
Various wireless technologies, such as RF, Bluetooth, and Zigbee, have been applied to sensor communications. However, the applications of Bluetooth-based wireless sensor networks (WSN) have a security issue. In one pairing process during Bluetooth communication, which is known as simple secure pairing (SSP), the devices are required to specify I/O capability or user interference to prevent man-in-the-middle (MITM) attacks. This study proposes an enhanced SSP in which a nonce to be transferred is converted to a corresponding signal interval. The quantization level, which is used to interpret physical signal intervals, is renewed at every connection by the transferred nonce and applied to the next nonce exchange so that the same signal intervals can represent different numbers. Even if attackers eavesdrop on the signals, they cannot understand what is being transferred because they cannot determine the quantization level. Furthermore, the proposed model does not require exchanging passkeys as data, and the devices are secure in the case of using a fixed PIN. Subsequently, the new quantization level is calculated automatically whenever the same devices attempt to connect with each other. Therefore, the pairing process can be protected from MITM attacks and be convenient for users.
各种无线技术,如射频(RF)、蓝牙和Zigbee,已应用于传感器通信。然而,基于蓝牙的无线传感器网络(WSN)的应用存在安全问题。在蓝牙通信的一个配对过程中,即简单安全配对(SSP),设备需要指定I/O能力或用户干扰,以防止中间人(MITM)攻击。本研究提出了一种增强型SSP,其中要传输的随机数被转换为相应的信号间隔。用于解释物理信号间隔的量化级别在每次连接时通过传输的随机数进行更新,并应用于下一次随机数交换,以便相同的信号间隔可以表示不同的数字。即使攻击者窃听信号,他们也无法理解正在传输的内容,因为他们无法确定量化级别。此外,所提出的模型不需要将密钥作为数据进行交换,并且在使用固定PIN的情况下设备是安全的。随后,每当相同的设备试图相互连接时,新的量化级别会自动计算。因此,配对过程可以免受MITM攻击,并且对用户来说很方便。