Finding Traceability Attacks in the Bluetooth Low Energy Specification and Its Implementations
Jianliang Wu, Patrick Traynor, Dongyan Xu, Dave (Jing) Tian, Antonio Bianchi
摘要
Bluetooth Low Energy (BLE) provides an efficient and convenient means for connecting a wide range of devices and peripherals. While its designers attempted to make tracking devices difficult through the use of MAC address randomization, a comprehensive analysis of the untraceability for the entire BLE protocol has not previously been conducted. In this paper, we create a formal model for BLE untraceability to reason about additional ways in which the specification allows for user tracking. Our model, implemented using ProVerif, transforms the untraceability problem into a reachability problem, and uncovers four previously unknown issues, namely IRK (Identity Resolving Key) reuse, BD_ADDR (MAC Address of Bluetooth Classic) reuse, CSRK (Connection Signature Resolving Key) reuse, and ID_ADDR (Identity Address) reuse, enabling eight passive or active tracking attacks against BLE. We then build another formal model using Diff-Equivalence (DE) as a comparison to our reachability model. Our evaluation of the two models demonstrates the soundness of our reachability model, whereas the DE model is neither sound nor complete. We further confirm these vulnerabilities in 13 different devices, ranging from embedded systems to laptop computers, with each device having at least 2 of the 4 issues. We finally provide mitigations for both developers and end users. In so doing, we demonstrate that BLE systems remain trackable under several common scenarios.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- BLERP: BLE Re-Pairing Attacks and DefensesTommaso Sacchetti, Daniele AntonioliNDSS 2026 · 被引用 2 次
- WCDCAnalyzer: Scalable Security Analysis of Wi-Fi Certified Device Connectivity ProtocolsZilin Shen, Imtiaz Karim, Elisa BertinoNDSS 2026
- Deanonymizing Device Identities via Side-channel Attacks in Exclusive-use IoTs & MitigationChristopher Ellis, Yue Zhang, Mohit Kumar Jangid, Shixuan Zhao 等NDSS 2025
- Snatcher: Apple Find My Network Exposes Your Lost Devices To StrangersZhenyu Ren, Yanbo Zhang, Boya Liu, Mo LiCCS 2026
它引用的顶会 Paper10
- SoK: Computer-Aided CryptographyManuel Barbosa, Gilles Barthe, Karthik Bhargavan, Bruno Blanchet 等S&P 2021 · 被引用 169 次
- Protecting Privacy of BLE Device UsersKassem Fawaz, Kyu-Han Kim, Kang G. ShinUSENIX Security 2016 · 被引用 111 次
- Automatic Fingerprinting of Vulnerable BLE IoT Devices with Static UUIDs from Mobile AppsChaoshun Zuo, Haohuang Wen, Zhiqiang Lin, Yinqian ZhangCCS 2019 · 被引用 77 次
- Privacy-Preserving and Standard-Compatible AKA Protocol for 5GYuchen Wang, Zhenfeng Zhang, Yongquan XieUSENIX Security 2021 · 被引用 58 次
- A Method for Verifying Privacy-Type Properties: The Unbounded CaseLucca Hirschi, David Baelde, Stéphanie DelauneS&P 2016 · 被引用 49 次
相关 Paper
- Formal Model-Driven Discovery of Bluetooth Protocol Design VulnerabilitiesJianliang Wu, Ruoyu Wu, Dongyan Xu, Dave Jing Tian 等S&P 2022 · 被引用 36 次
- When Good Becomes Evil: Tracking Bluetooth Low Energy Devices via Allowlist-based Side Channel and Its CountermeasureYue Zhang, Zhiqiang LinCCS 2022 · 被引用 12 次
- FirmXRay: Detecting Bluetooth Link Layer Vulnerabilities From Bare-Metal FirmwareHaohuang Wen, Zhiqiang Lin, Yinqian ZhangCCS 2020 · 被引用 47 次
- Linking Bluetooth LE & Classic and Implications for Privacy-Preserving Bluetooth-Based ProtocolsNorbert Ludant, Tien Dang Vo-Huu, Sashank Narain, Guevara NoubirS&P 2021 · 被引用 11 次
- Evaluating Physical-Layer BLE Location Tracking Attacks on Mobile DevicesHadi Givehchian, Nishant Bhaskar, Eliana Rodriguez Herrera, Héctor Rodrigo López Soto 等S&P 2022 · 被引用 55 次
