Linking Bluetooth LE & Classic and Implications for Privacy-Preserving Bluetooth-Based Protocols
Norbert Ludant, Tien Dang Vo-Huu, Sashank Narain, Guevara Noubir
Abstract
Bluetooth Low Energy advertisements are increasingly used for proximity privacy-preserving protocols. We investigate information leakage from BLE advertisements. Our analysis, among other things, reveals that the design of today's Bluetooth chips enables the linking of BLE advertisements to Bluetooth Classic (BTC) frames, and to a globally unique identifier (BDADDR). We demonstrate that the inference of the BDADDR from BLE advertisements is robust achieving over 90% reliability across apps, mobile devices, density of devices, and tens of meters away from the victims. We discuss the implications of current chipsets vulnerability on privacy-preserving protocols. The attack, for instance, reveals the BDADDR of devices of infected users of contact-tracing apps. We also discuss how the vulnerability can lead to de-anonymization of victims. Furthermore, current mobile devices do not allow selective disabling of BTC independently of BLE which renders simple countermeasures impractical. We developed several mitigations for the Android OS and the Bluetooth stack and demonstrate their efficacy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7315c49e-4fa7-4d59-a923-957dac4a97afCited by top-tier papers6
- SoK: The Long Journey of Exploiting and Defending the Legacy of King Harald BluetoothJianliang Wu, Ruoyu Wu, Dongyan Xu, Dave Jing Tian et al.S&P 2024 · 22 citations
- When Good Becomes Evil: Tracking Bluetooth Low Energy Devices via Allowlist-based Side Channel and Its CountermeasureYue Zhang, Zhiqiang LinCCS 2022 · 12 citations
- BlueSWAT: A Lightweight State-Aware Security Framework for Bluetooth Low EnergyXijia Che, Yi He, Xuewei Feng, Kun Sun et al.CCS 2024 · 10 citations
- Finding Traceability Attacks in the Bluetooth Low Energy Specification and Its ImplementationsJianliang Wu, Patrick Traynor, Dongyan Xu, Dave (Jing) Tian et al.USENIX Security 2024 · 6 citations
- CrossLink: Breaking Location Privacy by Linking Device Identifiers Across ProtocolsAneet Kumar Dutta, Mihirraj Dixit, Kevin Gni, Wouter Lueks et al.CCS 2026
Builds on4
- Inferring User Routes and Locations Using Zero-Permission Mobile SensorsSashank Narain, Triet D. Vo-Huu, Kenneth Block, Guevara NoubirS&P 2016 · 149 citations
- A Billion Open Interfaces for Eve and Mallory: MitM, DoS, and Tracking Attacks on iOS and macOS Through Apple Wireless Direct LinkMilan Stute, Sashank Narain, Alex Mariotto, Alexander Heinrich et al.USENIX Security 2019 · 59 citations
- An Empirical Assessment of Global COVID-19 Contact Tracing ApplicationsRuoxi Sun, Wei Wang, Minhui Xue, Gareth Tyson et al.ICSE 2021 · 54 citations
- Even Black Cats Cannot Stay Hidden in the Dark: Full-band De-anonymization of Bluetooth Classic DevicesMarco Cominelli, Francesco Gringoli, Paul Patras, Margus Lind et al.S&P 2020 · 29 citations
Related papers
- Evaluating Physical-Layer BLE Location Tracking Attacks on Mobile DevicesHadi Givehchian, Nishant Bhaskar, Eliana Rodriguez Herrera, Héctor Rodrigo López Soto et al.S&P 2022 · 55 citations
- A Study of the Feasibility of Co-located App Attacks against BLE and a Large-Scale Analysis of the Current Application-Layer Security LandscapePallavi Sivakumaran, Jorge BlascoUSENIX Security 2019 · 42 citations
- Deanonymizing Device Identities via Side-channel Attacks in Exclusive-use IoTs & MitigationChristopher Ellis, Yue Zhang, Mohit Kumar Jangid, Shixuan Zhao et al.NDSS 2025
- Blue's Clues: Practical Discovery of Non-Discoverable Bluetooth DevicesTyler Tucker, Hunter Searle, Kevin R. B. Butler, Patrick TraynorS&P 2023
- Automatic Fingerprinting of Vulnerable BLE IoT Devices with Static UUIDs from Mobile AppsChaoshun Zuo, Haohuang Wen, Zhiqiang Lin, Yinqian ZhangCCS 2019 · 77 citations
