MITM Attack on Bluetooth Pairing in Passkey Entry Mode and Its Countermeasure


KIPS Transactions on Computer and Communication Systems, Vol. 5, No. 12, pp. 481-490, Dec. 2016
10.3745/KTCCS.2016.5.12.481,   PDF Download:
Keywords: Bluetooth, Pairing, Passkey Entry, MITM, IO Capability Exchange
Abstract

Bluetooth utilizes a symmetric key that is exchanged at the first pairing to establish a secure channel. There are four authentication modes which enables device authentication, Just work, Passkey Entry, Out of Band, and Numeric Comparison. Up to now, Just work has been considered as the authentication mode that is vulnerable to Man-In-The-Middle (MITM) Attack. In addition, it is possible to intentionally change any authentication mode to Just work mode, in order to succeed in MITM Attack under Just work mode. However, this kind of attacks have just worked under the assumption that users should not notice that authentication mode was changed. In this paper, We analyze the specification of Secure Simple Pairing, LE Legacy Pairing and LE Secure Connection Pairing. When using Passkey Entry mode on each approach, it seems the MITM attack is possible. Also it offers Passkey Entry MITM attack that does not require assumptions about the user's fault, because it isn't change verification process of the authentication mode unlike traditional attacks. We implement the proposed MITM attacks. Also we presents a scenario in which an attack can be exploited and a countermeasure.


Statistics
Show / Hide Statistics

Statistics (Cumulative Counts from September 1st, 2017)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article
[IEEE Style]
J. Lee, W. Choi, D. Lee, "MITM Attack on Bluetooth Pairing in Passkey Entry Mode and Its Countermeasure," KIPS Transactions on Computer and Communication Systems, vol. 5, no. 12, pp. 481-490, 2016. DOI: 10.3745/KTCCS.2016.5.12.481.

[ACM Style]
Jearyong Lee, Wonsuk Choi, and DongHoon Lee. 2016. MITM Attack on Bluetooth Pairing in Passkey Entry Mode and Its Countermeasure. KIPS Transactions on Computer and Communication Systems, 5, 12, (2016), 481-490. DOI: 10.3745/KTCCS.2016.5.12.481.