Tianjin Key Laboratory of Advanced Networking (TANK), Division of Intelligence and Computing, Tianjin University, No. 135, Yaguan Road, Tianjin Haihe Education Park, Tianjin 300350, China.
Sensors (Basel). 2019 Mar 7;19(5):1158. doi: 10.3390/s19051158.
Bluetooth is an important technical standard for short-range and low-power wireless communication. The home automation and entertainment (HAE) systems often make use of Bluetooth technology to link different Bluetooth devices and form Bluetooth networks. The security concerns of the HAE systems are raised due to massive deployment of the Bluetooth devices. The Bluetooth standard mainly depends on the secure simple pairing (SSP) solution to protect the Bluetooth devices. Hence, we investigate the SSP solution according to the Bluetooth standard v5.0. The contributions are threefold. (1) A formal security model is proposed to evaluate SSP's association models and authenticated link key. (2) We formally analyze two SSP protocols and present the security requirements for basic cryptographic modules in these SSP protocols. (3) We discuss the typical SSP applications in the HAE systems. Our results are useful to not only evaluating and designing the SSP protocols but also enhancing the security of the HAE systems in which the Bluetooth access is available.
蓝牙是短距离和低功耗无线通信的重要技术标准。家庭自动化和娱乐 (HAE) 系统通常利用蓝牙技术来连接不同的蓝牙设备并形成蓝牙网络。由于蓝牙设备的大量部署,HAE 系统的安全问题受到关注。蓝牙标准主要依赖于安全简单配对 (SSP) 解决方案来保护蓝牙设备。因此,我们根据蓝牙标准 v5.0 研究了 SSP 解决方案。贡献有三方面。(1)提出了一个正式的安全模型来评估 SSP 的关联模型和认证链路密钥。(2)我们对两个 SSP 协议进行了形式化分析,并提出了这些 SSP 协议中基本密码模块的安全要求。(3)我们讨论了 HAE 系统中典型的 SSP 应用。我们的研究结果不仅有助于评估和设计 SSP 协议,还有助于增强具有蓝牙访问功能的 HAE 系统的安全性。