Bluetooth Low Energy (BLE) devices have become very popular because of their Low energy consumption and hence a prolonged battery life. They are being used in smart wearable devices, smart home automation system, beacons and many more areas. BLE uses pairing mechanisms to achieve a level of peer entity authentication as well as encryption. Although, there are a set of pairing mechanisms available but BLE devices having no keyboard or display mechanism (and hence using the Just Works pairing) are still vulnerable. In this paper, we propose and implement, a light-weight digital certificate based authentication mechanism for the BLE devices making use of Just Works model. The proposed model is an add-on to the already existing pairing mechanism and therefore can be easily incorporated in the existing BLE stack. To counter the existing Man-in-The-Middle attack scenario in Just Works pairing (device spoofing), our proposed model allows the client and peripheral to make use of the popular Public Key Infrastructure (PKI) to establish peer entity authentication and a secure cryptographic tunnel for communication. We have also developed a lightweight BLE profiled digital certificate containing the bare minimum fields required for resource constrained devices, which significantly reduces the memory (about 90\% reduction) and energy consumption. We have experimentally evaluated the energy consumption of the device using the proposed pairing mechanism to demonstrate that the model can be easily deployed with less changes to the power requirements of the chips. The model has been formally verified using automatic verification tool for protocol testing.
翻译:蓝牙低能(Blueth Blue House)装置因其能源消耗量低而变得非常流行,因此电池寿命延长,因此非常流行。这些装置被用于智能磨损装置、智能家用自动化系统、信标和更多的领域。它们可以使用配对机制来实现对等实体的认证和加密。虽然有一套配对机制可供使用,但没有键盘或显示机制(并因此使用“Just Work”配对机制)的对口装置仍然很脆弱。在本文件中,我们提议和实施一个基于轻量数字证书的认证机制,用于使用“Just Work”模型,用于使用“Just Works”系统, 并且使用智能的配对口装置。我们还开发了一个轻量级数字证书,其中包括现有的配对口机制,因此很容易纳入现有的配对对口机制。为了应对现有的“Just Work”系统配对口系统(Deps Spoofofing)中现有的“人中中人”攻击情景,我们提议的模型允许客户和外围使用流行的公共公用钥匙基础设施模式(PKI)来建立以方便的自动加密通信通信通讯通讯。我们还开发了一个轻巧制化了含有的能源测试工具,我们使用了对等的存储设备。我们用最起码的存储设备。我们用了对质化了对质的能源的核查工具,对质的能源的校对质的校。我们进行了了40。我们对质的校。我们用来了对质的能源的校校。我们对的校对的校对的校对的校的校的校的校的校的校。我们的校对的校对的校对的校对的能源的校对的校对工具,对的校对的校。我们用的校对的校对的校对的校对的校对的校对的校。我们用的校对的校对的校对的校对的能源的校对的校对的校对的校对的校对的校对的校对的校对的校对的校对的校对的校对的校对的校对的校对的校对的校对的校对的校对的校对的校对的校对的能源的能源的校对的校对设备进行了的校对