USENIX Security2023Top-tier venue
Formal Analysis and Patching of BLE-SC Pairing
Min Shi, Jing Chen, Kun He, Haoran Zhao, Meng Jia, Ruiying Du
Abstract
Bluetooth Low Energy (BLE) is the mainstream Bluetooth standard and BLE Secure Connections (BLC-SC) pairing is a protocol that authenticates two Bluetooth devices and derives a shared secret key between them. Although BLE-SC pairing employs well-studied cryptographic primitives to guarantee its security, a recent study revealed a logic flaw in the protocol.
In this paper, we develop the first comprehensive formal model of the BLE-SC pairing protocol. Our model is compliant with the latest Bluetooth specification version 5.3 and covers all association models in the specification to discover attacks caused by the interplay between different association models. We also partly loosen the perfect cryptography assumption in traditional symbolic analysis approaches by designing a low-entropy key oracle to detect attacks caused by the poorly derived keys. Our analysis confirms two existing attacks and discloses a new attack. We propose a countermeasure to fix the flaws found in the BLE-SC pairing protocol and discuss the backward compatibility. Moreover, we extend our model to verify the countermeasure, and the results demonstrate its effectiveness in our extended model.
Keyboard Input z KeyboardDisplay KeyboardOnly Yes-No Input
DisplayOnly NoInputNoOutput
x: Device has the ability to display a 6-digit number. y: Device does not have the ability to display a 6-digit number. z: Device has a numeric keyboard that can input the digits '0' to '9' and a confirmation. : Device has the ability to indicate "yes" and "no". |: Device does not have the ability to indicate "yes" or "no".
This phase aims to determine the parameters used in the subsequent phases. It can be invoked by the initiating device sending a pairing request or the responding device sending a security request. The following four fields are important to our model. They are sent by the initiating/responding device in the pairing request/response.
• IOCap: This field indicates the specification-defined IO capability used in the LTK generation phase. The Bluetooth specification defines five IO capabilities of the device, as shown in Table 1.
• OOB: This field indicates whether the device has received authentication data using Out-Of-Band (OOB) capabilities, i.e., IO capabilities that are not defined in the specification.
• MITM: This field indicates whether the device requires preventing Man-In-The-Middle (MITM) attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ac906959-8ed2-4fc9-9e89-a50d8db3f730Cited by top-tier papers5
- SoK: The Long Journey of Exploiting and Defending the Legacy of King Harald BluetoothJianliang Wu, Ruoyu Wu, Dongyan Xu, Dave Jing Tian et al.S&P 2024 · 22 citations
- BLERP: BLE Re-Pairing Attacks and DefensesTommaso Sacchetti, Daniele AntonioliNDSS 2026 · 2 citations
- Formal Analysis of BLE Secure Connection Pairing and Revelation of the PE Confusion AttackMin Shi, Yongkang Xiao, Jing Chen, Kun He et al.NDSS 2026
- Rediscovering Method Confusion in Proposed Security Fixes for BluetoothMaximilian von Tschirschnitz, Ludwig Peuckert, Moritz Buhl, Jens GrossklagsNDSS 2025
- BLE Theft Auto: Evaluating the Security of Aftermarket BLE-based Automotive Remote Control SystemsJerry Yu, Yibo Wei, Sumanth Rao, Mohak Vaswani et al.USENIX Security 2026
Builds on15
- A Formal Analysis of 5G AuthenticationDavid A. Basin, Jannik Dreier, Lucca Hirschi, Sasa Radomirovic et al.CCS 2018 · 428 citations
- A Comprehensive Symbolic Analysis of TLS 1.3Cas Cremers, Marko Horvat, Jonathan Hoyland, Sam Scott et al.CCS 2017 · 247 citations
- Component-Based Formal Analysis of 5G-AKA: Channel Assumptions and Session ConfusionCas Cremers, Martin Dehnel-WildNDSS 2019 · 131 citations
- Automated Analysis and Verification of TLS 1.3: 0-RTT, Resumption and Delayed AuthenticationCas Cremers, Marko Horvat, Sam Scott, Thyla van der MerweS&P 2016 · 128 citations
- BIAS: Bluetooth Impersonation AttackSDaniele Antonioli, Nils Ole Tippenhauer, Kasper RasmussenS&P 2020 · 90 citations
Related papers
- Breaking Secure Pairing of Bluetooth Low Energy Using Downgrade AttacksYue Zhang, Jian Weng, Rajib Dey, Yier Jin et al.USENIX Security 2020
- Extrapolating Formal Analysis to Uncover Attacks in Bluetooth Passkey Entry PairingMohit Kumar Jangid, Yue Zhang, Zhiqiang LinNDSS 2023
- Formal Model-Driven Discovery of Bluetooth Protocol Design VulnerabilitiesJianliang Wu, Ruoyu Wu, Dongyan Xu, Dave Jing Tian et al.S&P 2022 · 36 citations
- Method Confusion Attack on Bluetooth PairingMaximilian von Tschirschnitz, Ludwig Peuckert, Fabian Franzen, Jens GrossklagsS&P 2021 · 42 citations
- A Study of the Feasibility of Co-located App Attacks against BLE and a Large-Scale Analysis of the Current Application-Layer Security LandscapePallavi Sivakumaran, Jorge BlascoUSENIX Security 2019 · 42 citations
