论文标题

改进了没有I/O功能的BLE设备的身份验证方案

An Improved Authentication Scheme for BLE Devices with no I/O Capabilities

论文作者

Gupta, Chandranshu, Varshney, Gaurav

论文摘要

蓝牙低能(BLE)设备由于低能消耗而变得非常流行,因此电池寿命延长。它们用于智能可穿戴设备,智能家居自动化系统,信标和更多领域。 BLE使用配对机制来达到同行实体身份验证和加密水平。虽然,有一组配对机制可用,但是没有键盘或显示机制的BLE设备(因此使用Just Works配对)仍然很脆弱。在本文中,我们提出和实施,这是一种基于数字证书的基于数字证书的身份验证机制,用于使用Just Works模型。提出的模型是已经存在的配对机制的附加组件,因此可以轻松地将其合并到现有的BLE堆栈中。为了在Just Works配对(设备欺骗)中对抗现有的中型攻击场景,我们提出的模型允许客户和外围设备使用流行的公共密钥基础设施(PKI)来建立同伴实体身份验证和安全的加密隧道进行通信。我们还开发了一个轻巧的BLE构造的数字证书,其中包含资源约束设备所需的裸露字段,从而大大降低了内存(约90 \%降低)和能耗。我们已经使用所提出的配对机制对设备的能源消耗进行了实验,以证明该模型可以轻松部署,而更改芯片的功率需求。使用自动验证工具进行协议测试,已正式验证该模型。

Bluetooth Low Energy (BLE) devices have become very popular because of their Low energy consumption and hence a prolonged battery life. They are being used in smart wearable devices, smart home automation system, beacons and many more areas. BLE uses pairing mechanisms to achieve a level of peer entity authentication as well as encryption. Although, there are a set of pairing mechanisms available but BLE devices having no keyboard or display mechanism (and hence using the Just Works pairing) are still vulnerable. In this paper, we propose and implement, a light-weight digital certificate based authentication mechanism for the BLE devices making use of Just Works model. The proposed model is an add-on to the already existing pairing mechanism and therefore can be easily incorporated in the existing BLE stack. To counter the existing Man-in-The-Middle attack scenario in Just Works pairing (device spoofing), our proposed model allows the client and peripheral to make use of the popular Public Key Infrastructure (PKI) to establish peer entity authentication and a secure cryptographic tunnel for communication. We have also developed a lightweight BLE profiled digital certificate containing the bare minimum fields required for resource constrained devices, which significantly reduces the memory (about 90\% reduction) and energy consumption. We have experimentally evaluated the energy consumption of the device using the proposed pairing mechanism to demonstrate that the model can be easily deployed with less changes to the power requirements of the chips. The model has been formally verified using automatic verification tool for protocol testing.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源