Formal Model-Driven Discovery of Bluetooth Protocol Design Vulnerabilities
Jianliang Wu, Ruoyu Wu, Dongyan Xu, Dave Jing Tian, Antonio Bianchi
Abstract
The Bluetooth protocol suite, including Bluetooth Classic, Bluetooth Low Energy, and Bluetooth Mesh, has become the de facto standard for short-range wireless communications. While formal methods have been applied to Bluetooth security, existing efforts either focus on one configuration of a protocol or one protocol of the suite, without considering other configurations or interactions among protocols. As a result, manual analysis still dominates the state-of-the-art security research of Bluetooth specification. To enable automatic Bluetooth security analysis with formal guarantees, we propose a comprehensive formal model for Bluetooth protocol suite covering both the key sharing phase and the data transmission phase, in all the three Bluetooth protocols, and detecting their design flaws automatically. Our formal model, written in ProVerif, adopts a modular design by abstracting each step within a protocol into an interface and implementing different methods in each step as modules to instantiate the interface, through which all possible configurations of a protocol could be examined. We further abstract different Bluetooth protocols into modules enabling the modeling of their interactions and relax the threat model to allow reasoning about semi-compromised devices. We use this model to formally verify 418 security properties and find 82 violations with attack examples capturing 5 known vulnerabilities and discovering 2 new security issues. Bluetooth SIG confirmed our independent discovery of these 2 new issues, with one issue assigned a CVE and the other issue acknowledged in a security notice. Our model provides one step towards formally verified Bluetooth security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 21e6a69a-d86e-4410-b7a6-7bdf143dbcf4Cited by top-tier papers16
- SoK: The Long Journey of Exploiting and Defending the Legacy of King Harald BluetoothJianliang Wu, Ruoyu Wu, Dongyan Xu, Dave Jing Tian et al.S&P 2024 · 22 citations
- BlueSWAT: A Lightweight State-Aware Security Framework for Bluetooth Low EnergyXijia Che, Yi He, Xuewei Feng, Kun Sun et al.CCS 2024 · 10 citations
- Formal Model-Driven Analysis of Resilience of GossipSub to Attacks from Misbehaving PeersAnkit Kumar, Max von Hippel, Panagiotis Manolios, Cristina Nita-RotaruS&P 2024 · 8 citations
- Finding Traceability Attacks in the Bluetooth Low Energy Specification and Its ImplementationsJianliang Wu, Patrick Traynor, Dongyan Xu, Dave (Jing) Tian et al.USENIX Security 2024 · 6 citations
- Payout Races and Congested Channels: A Formal Analysis of Security in the Lightning NetworkBen Weintraub, Satwik Prabhu Kumble, Cristina Nita-Rotaru, Stefanie RoosCCS 2024 · 5 citations
Builds on8
- Verified Models and Reference Implementations for the TLS 1.3 Standard CandidateKarthikeyan Bhargavan, Bruno Blanchet, Nadim KobeissiS&P 2017 · 233 citations
- Dangerous Skills: Understanding and Mitigating Security Risks of Voice-Controlled Third-Party Functions on Virtual Personal Assistant SystemsNan Zhang, Xianghang Mi, Xuan Feng, XiaoFeng Wang et al.S&P 2019 · 160 citations
- BIAS: Bluetooth Impersonation AttackSDaniele Antonioli, Nils Ole Tippenhauer, Kasper RasmussenS&P 2020 · 90 citations
- The KNOB is Broken: Exploiting Low Entropy in the Encryption Key Negotiation Of Bluetooth BR/EDRDaniele Antonioli, Nils Ole Tippenhauer, Kasper Bonne RasmussenUSENIX Security 2019 · 89 citations
- BadBluetooth: Breaking Android Security Mechanisms via Malicious Bluetooth PeripheralsFenghao Xu, Wenrui Diao, Zhou Li, Jiongyi Chen et al.NDSS 2019 · 51 citations
Related papers
- Extrapolating Formal Analysis to Uncover Attacks in Bluetooth Passkey Entry PairingMohit Kumar Jangid, Yue Zhang, Zhiqiang LinNDSS 2023
- BLEDiff: Scalable and Property-Agnostic Noncompliance Checking for BLE ImplementationsImtiaz Karim, Abdullah Al Ishtiaq, Syed Rafiul Hussain, Elisa BertinoS&P 2023
- BSFuzzer: Context-Aware Semantic Fuzzing for BLE Logic Flaw DetectionTing Yang, Yue Qin, Lan Zhang, Zhiyuan Fu et al.NDSS 2026 · 1 citation
- BLERP: BLE Re-Pairing Attacks and DefensesTommaso Sacchetti, Daniele AntonioliNDSS 2026 · 2 citations
- A Thorough Security Analysis of BLE Proximity Tracking ProtocolsXiaofeng Liu, Chaoshun Zuo, Qinsheng Hou, Pengcheng Ren et al.USENIX Security 2025
