The Bluetooth CYBORG: Analysis of the Full Human-Machine Passkey Entry AKE Protocol
Michael Troncoso, Britta Hale
Abstract
from a device, and adversarial ability to modify communications back from the user to the device (see Figure 1). We reference the Tap n’ Ghost attack as an illustrative example throughout, but it is not the only attack leveraging the UtD communication channel. Touchloggers [12], [16], the StrandHogg vulnerability [24], social engineering, and shoulder-surfing attacks also fall into this category. All such attack vectors are systematically accounted for in our CYBORG model. Bluetooth’s Passkey Entry [10] generates and shares a random value (a passkey ) via the user to effectively achieve Abstract —In this paper, we computationally analyze Passkey Entry in its entirety as a cryptographic authenticated key exchange (AKE) – including user-protocol interactions that are typically ignored as out-of-band. To achieve this, we model the user-to-device channels, as well as the typical device-to-device channel, and adversarial control scenarios in both cases. In particular, we separately capture adversarial control of device displays on the initiating and responding devices as well as adversarial control of user input mechanisms using what we call a CYBORG model. The CYBORG model enables realistic real-world security analysis in light of published attacks on user-mediated protocols such as Bluetooth that leverage malware and device displays. In light of this, we show that all versions of Passkey Entry fail to provide security in our model. Finally, we demonstrate how slight modifications to the protocol would allow it to achieve stronger security guarantees for all current variants of passkey generation, as well as a newly proposed twofold mode of generation we term Dual Passkey Entry . These proof-of-concept modifications point to improved design approaches for user-mediated protocols. Finally, this work points to categories of vulnerabilities, based on compromise type, that could be exploited in Bluetooth Passkey Entry.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- BlueSWAT: A Lightweight State-Aware Security Framework for Bluetooth Low EnergyXijia Che, Yi He, Xuewei Feng, Kun Sun et al.CCS 2024 · 10 citations
- BLERP: BLE Re-Pairing Attacks and DefensesTommaso Sacchetti, Daniele AntonioliNDSS 2026 · 2 citations
- Formal Analysis of BLE Secure Connection Pairing and Revelation of the PE Confusion AttackMin Shi, Yongkang Xiao, Jing Chen, Kun He et al.NDSS 2026
- Rediscovering Method Confusion in Proposed Security Fixes for BluetoothMaximilian von Tschirschnitz, Ludwig Peuckert, Moritz Buhl, Jens GrossklagsNDSS 2025
- Formal Analysis and Patching of BLE-SC PairingMin Shi, Jing Chen, Kun He, Haoran Zhao et al.USENIX Security 2023
Builds on3
- BIAS: Bluetooth Impersonation AttackSDaniele Antonioli, Nils Ole Tippenhauer, Kasper RasmussenS&P 2020 · 90 citations
- The KNOB is Broken: Exploiting Low Entropy in the Encryption Key Negotiation Of Bluetooth BR/EDRDaniele Antonioli, Nils Ole Tippenhauer, Kasper Bonne RasmussenUSENIX Security 2019 · 89 citations
- Tap 'n Ghost: A Compilation of Novel Attack Techniques against Smartphone TouchscreensSeita Maruyama, Satohiro Wakabayashi, Tatsuya MoriS&P 2019 · 39 citations
Related papers
- Extrapolating Formal Analysis to Uncover Attacks in Bluetooth Passkey Entry PairingMohit Kumar Jangid, Yue Zhang, Zhiqiang LinNDSS 2023
- Formal Model-Driven Discovery of Bluetooth Protocol Design VulnerabilitiesJianliang Wu, Ruoyu Wu, Dongyan Xu, Dave Jing Tian et al.S&P 2022 · 36 citations
- Access Your Tesla without Your Awareness: Compromising Keyless Entry System of Model 3Xinyi Xie, Kun Jiang, Rui Dai, Jun Lu et al.NDSS 2023
- Fake It till You Make It: Enhancing Security of Bluetooth Secure Connections via Deferrable AuthenticationMarc Fischlin, Olga SaninaCCS 2024 · 2 citations
- BLUFFS: Bluetooth Forward and Future Secrecy Attacks and DefensesDaniele AntonioliCCS 2023 · 7 citations
