BLUFFS: Bluetooth Forward and Future Secrecy Attacks and Defenses
Daniele Antonioli
Abstract
Bluetooth is a pervasive technology for wireless communication. Billions of devices use it in sensitive applications and to exchange private data. The security of Bluetooth depends on the Bluetooth standard and its two security mechanisms: pairing and session establishment. No prior work, including the standard itself, analyzed the future and forward secrecy guarantees of these mechanisms, e.g., if Bluetooth pairing and session establishment defend past and future sessions when the adversary compromises the current. To address this gap, we present six novel attacks, defined as the BLUFFS attacks, breaking Bluetooth sessions' forward and future secrecy. Our attacks enable device impersonation and machine-inthe-middle across sessions by only compromising one session key. The attacks exploit two novel vulnerabilities that we uncover in the Bluetooth standard related to unilateral and repeatable session key derivation. As the attacks affect Bluetooth at the architectural level, they are effective regardless of the victim's hardware and software details (e.g., chip, stack, version, and security mode). We also release BLUFFS, a low-cost toolkit to perform and automatically check the effectiveness of our attacks. The toolkit employs seven original patches to manipulate and monitor Bluetooth session key derivation by dynamically patching a closed-source Bluetooth firmware that we reverse-engineered. We show that our attacks have a critical and large-scale impact on the Bluetooth ecosystem, by evaluating them on seventeen diverse Bluetooth chips (eighteen devices) from popular hardware and software vendors and supporting the most popular Bluetooth versions. Motivated by our empirical findings, we develop and successfully test an enhanced key derivation function for Bluetooth that stops by-design our six attacks and their four root causes. We show how to effectively integrate our fix into the Bluetooth standard and discuss alternative implementation-level mitigations. We responsibly disclosed our contributions to the Bluetooth SIG.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext db483c25-05ba-4fde-8388-6e02dd02abd0Cited by top-tier papers5
- CellularLint: A Systematic Approach to Identify Inconsistent Behavior in Cellular Network SpecificationsMirza Masfiqur Rahman, Imtiaz Karim, Elisa BertinoUSENIX Security 2024 · 17 citations
- BLERP: BLE Re-Pairing Attacks and DefensesTommaso Sacchetti, Daniele AntonioliNDSS 2026 · 2 citations
- BSFuzzer: Context-Aware Semantic Fuzzing for BLE Logic Flaw DetectionTing Yang, Yue Qin, Lan Zhang, Zhiyuan Fu et al.NDSS 2026 · 1 citation
- BLuEMan: A Stateful Simulation-based Fuzzing Framework for Open-Source RTOS Bluetooth Low Energy Protocol StacksWei-Che Kao, Yen-Chia Chen, Yu-Sheng Lin, Yu-Cheng Yang et al.USENIX Security 2025
- OneTouch: Effortless 2FA Scheme to Secure Fingerprint Authentication with Wearable OTP TokenYihui Yan, Zhice YangUSENIX Security 2025
Builds on10
- BIAS: Bluetooth Impersonation AttackSDaniele Antonioli, Nils Ole Tippenhauer, Kasper RasmussenS&P 2020 · 90 citations
- The KNOB is Broken: Exploiting Low Entropy in the Encryption Key Negotiation Of Bluetooth BR/EDRDaniele Antonioli, Nils Ole Tippenhauer, Kasper Bonne RasmussenUSENIX Security 2019 · 89 citations
- FirmXRay: Detecting Bluetooth Link Layer Vulnerabilities From Bare-Metal FirmwareHaohuang Wen, Zhiqiang Lin, Yinqian ZhangCCS 2020 · 47 citations
- Method Confusion Attack on Bluetooth PairingMaximilian von Tschirschnitz, Ludwig Peuckert, Fabian Franzen, Jens GrossklagsS&P 2021 · 42 citations
- Even Black Cats Cannot Stay Hidden in the Dark: Full-band De-anonymization of Bluetooth Classic DevicesMarco Cominelli, Francesco Gringoli, Paul Patras, Margus Lind et al.S&P 2020 · 29 citations
Related papers
- Rediscovering Method Confusion in Proposed Security Fixes for BluetoothMaximilian von Tschirschnitz, Ludwig Peuckert, Moritz Buhl, Jens GrossklagsNDSS 2025
- Blacktooth: Breaking through the Defense of Bluetooth in SilenceMingrui Ai, Kaiping Xue, Bo Luo, Lutong Chen et al.CCS 2022 · 10 citations
- SoK: The Long Journey of Exploiting and Defending the Legacy of King Harald BluetoothJianliang Wu, Ruoyu Wu, Dongyan Xu, Dave Jing Tian et al.S&P 2024 · 22 citations
- BadBluetooth: Breaking Android Security Mechanisms via Malicious Bluetooth PeripheralsFenghao Xu, Wenrui Diao, Zhou Li, Jiongyi Chen et al.NDSS 2019 · 51 citations
- BlueSWAT: A Lightweight State-Aware Security Framework for Bluetooth Low EnergyXijia Che, Yi He, Xuewei Feng, Kun Sun et al.CCS 2024 · 10 citations
