TSYS School of Computer Science, Columbus State University, Columbus, GA 31907, USA.
Sensors (Basel). 2022 Jan 27;22(3):988. doi: 10.3390/s22030988.
Since its inception in 2013, Bluetooth Low Energy (BLE) has become the standard for short-distance wireless communication in many consumer devices, as well as special-purpose devices. In this study, we analyze the security features available in Bluetooth LE standards and evaluate the features implemented in two BLE wearable devices (a Fitbit heart rate wristband and a Polar heart rate chest wearable) and a BLE keyboard to explore which security features in the BLE standards are implemented in the devices. In this study, we used the ComProbe Bluetooth Protocol Analyzer, along with the ComProbe software to capture the BLE traffic of these three devices. We found that even though the standards provide security mechanisms, because the Bluetooth Special Interest Group does not require that manufacturers fully comply with the standards, some manufacturers fail to implement proper security mechanisms. The circumvention of security in Bluetooth devices could leak private data that could be exploited by rogue actors/hackers, thus creating security, privacy, and, possibly, safety issues for consumers and the public. We propose the design of a Bluetooth Security Facts Label (BSFL) to be included on a Bluetooth/BLE enabled device's commercial packaging and conclude that there should be better mechanisms for informing users about the security and privacy provisions of the devices they acquire and use and to educate the public on protection of their privacy when buying a connected device.
自 2013 年诞生以来,蓝牙低能耗 (BLE) 已成为许多消费类设备以及专用设备短距离无线通信的标准。在本研究中,我们分析了蓝牙 LE 标准中可用的安全功能,并评估了两款蓝牙可穿戴设备(Fitbit 心率腕带和 Polar 心率胸带)和一款蓝牙键盘中实现的功能,以探讨蓝牙标准中的哪些安全功能已在这些设备中实现。在本研究中,我们使用了 ComProbe Bluetooth Protocol Analyzer 以及 ComProbe 软件来捕获这三个设备的 BLE 流量。我们发现,尽管标准提供了安全机制,但由于蓝牙特别兴趣小组不要求制造商完全遵守标准,因此一些制造商未能实施适当的安全机制。蓝牙设备的安全规避可能会泄露私人数据,这些数据可能被恶意行为者/黑客利用,从而给消费者和公众带来安全、隐私和(可能)安全问题。我们提出了设计蓝牙安全事实标签(BSFL)的建议,该标签将包含在蓝牙/ BLE 启用设备的商业包装上,并得出结论,应该有更好的机制来告知用户他们所购买和使用的设备的安全和隐私规定,并教育公众在购买连接设备时保护他们的隐私。