Sun Da-Zhi, Sun Li, Yang Ying
Tianjin Key Laboratory of Advanced Networking (TANK), Division of Intelligence and Computing, Tianjin University, No. 135, Yaguan Road, Tianjin Haihe Education Park, Tianjin 300350, China.
Standardization Department, China Aero-Polytechnology Establishment, Aviation Industry of China, No. 7, Jingshun Road, Chaoyang District, Beijing 100028, China.
Sensors (Basel). 2019 Jul 24;19(15):3259. doi: 10.3390/s19153259.
Bluetooth low energy devices are very popular in wireless personal area networks. According to the Bluetooth standard specifications, the low energy secure simple pairing (LESSP) protocol is the process by which the pairing devices negotiate the authenticated secret key. To violate the user privacy, the adversary can perhaps link the runs of the LESSP protocol to the targeted device, which usually relates to the specially appointed user. Hence, we investigate deep into the privacy of the LESSP protocol. Our main contributions are threefold: (1) We demonstrate that the LESSP protocol suffers from privacy vulnerability. That is, an adversary without any secret key is able to identify the targeted device by the LESSP protocol. (2) An improvement is therefore proposed to repair the privacy vulnerability in the LESSP protocol. (3) We develop a formal privacy model to evaluate the privacy vulnerabilities in the LESSP protocol and its improved versions. We further prove that our improvement on the LESSP protocol is private under the privacy model. In addition, the performance evaluation shows that our improvement is as efficient as the LESSP protocol. Our research results are beneficial to the privacy enhancement of Bluetooth systems in wireless personal area networks.
低功耗蓝牙设备在无线个人区域网络中非常流行。根据蓝牙标准规范,低功耗安全简单配对(LESSP)协议是配对设备协商认证密钥的过程。为了侵犯用户隐私,攻击者可能会将LESSP协议的运行与目标设备关联起来,而目标设备通常与特定用户相关。因此,我们深入研究了LESSP协议的隐私问题。我们的主要贡献有三点:(1)我们证明LESSP协议存在隐私漏洞。也就是说,没有任何密钥的攻击者能够通过LESSP协议识别目标设备。(2)因此,提出了一种改进方法来修复LESSP协议中的隐私漏洞。(3)我们开发了一个正式的隐私模型来评估LESSP协议及其改进版本中的隐私漏洞。我们进一步证明,在隐私模型下,我们对LESSP协议的改进是私密的。此外,性能评估表明,我们的改进与LESSP协议一样高效。我们的研究结果有利于无线个人区域网络中蓝牙系统的隐私增强。