Evaluating Physical-Layer BLE Location Tracking Attacks on Mobile Devices
Hadi Givehchian, Nishant Bhaskar, Eliana Rodriguez Herrera, Héctor Rodrigo López Soto, Christian Dameff, Dinesh Bharadia, Aaron Schulman
Abstract
Mobile devices increasingly function as wireless tracking beacons. Using the Bluetooth Low Energy (BLE) protocol, mobile devices such as smartphones and smartwatches continuously transmit beacons to inform passive listeners about device locations for applications such as digital contact tracing for COVID-19, and even finding lost devices. These applications use cryptographic anonymity that limit an adversary’s ability to use these beacons to stalk a user. However, attackers can bypass these defenses by fingerprinting the unique physical-layer imperfections in the transmissions of specific devices.We empirically demonstrate that there are several key challenges that can limit an attacker’s ability to find a stable physical layer identifier to uniquely identify mobile devices using BLE, including variations in the hardware design of BLE chipsets, transmission power levels, differences in thermal conditions, and limitations of inexpensive radios that can be widely deployed to capture raw physical-layer signals. We evaluated how much each of these factors limits accurate fingerprinting in a large-scale field study of hundreds of uncontrolled BLE devices, revealing that physical-layer identification is a viable, although sometimes unreliable, way for an attacker to track mobile devices.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext fdea20d2-c8ff-462e-8717-c29157ec74f6Cited by top-tier papers13
- SoK: The Long Journey of Exploiting and Defending the Legacy of King Harald BluetoothJianliang Wu, Ruoyu Wu, Dongyan Xu, Dave Jing Tian et al.S&P 2024 · 22 citations
- RECORD: A RECeption-Only Region Determination Attack on LEO Satellite UsersEric Jedermann, Martin Strohmeier, Vincent Lenders, Jens B. SchmittUSENIX Security 2024 · 18 citations
- Practical Obfuscation of BLE Physical-Layer Fingerprints on Mobile DevicesHadi Givehchian, Nishant Bhaskar, Alexander Redding, Han Zhao et al.S&P 2024 · 16 citations
- Digital Security - A Question of Perspective A Large-Scale Telephone Survey with Four At-Risk User GroupsFranziska Herbert, Steffen Becker, Annalina Buckmann, Marvin Kowalewski et al.S&P 2024 · 13 citations
- BlueSWAT: A Lightweight State-Aware Security Framework for Bluetooth Low EnergyXijia Che, Yi He, Xuewei Feng, Kun Sun et al.CCS 2024 · 10 citations
Related papers
- BLE Location Tracking Attacks by Exploiting Frequency Synthesizer ImperfectionYeming Li, Hailong Lin, Jiamei Lv, Yi Gao et al.INFOCOM 2024 · 3 citations
- Linking Bluetooth LE & Classic and Implications for Privacy-Preserving Bluetooth-Based ProtocolsNorbert Ludant, Tien Dang Vo-Huu, Sashank Narain, Guevara NoubirS&P 2021 · 11 citations
- Security and Privacy Analysis of Samsung's Crowd-Sourced Bluetooth Location Tracking SystemTingfeng Yu, James Henderson, Alwen Tiu, Thomas HainesUSENIX Security 2024 · 20 citations
- Automatic Fingerprinting of Vulnerable BLE IoT Devices with Static UUIDs from Mobile AppsChaoshun Zuo, Haohuang Wen, Zhiqiang Lin, Yinqian ZhangCCS 2019 · 77 citations
- PrivacyShield: Relaying BLE Beacons to Counter Unsolicited TrackingFlorian Hofhammer, Daniele Antonioli, Mathias PayerUSENIX Security 2026
