Notice of Violation of IEEE Publication Principles Bluetooth Man-In-The-Middle attack based on Secure Simple Pairing using Out Of Band association model

D. Sharmila, R. Neelaveni, K Kiruba · International Conference on Control and Automation · 2009

Notice of Violation of IEEE Publication Principles “Bluetooth Man-in-the-Middle Attack Based on Secure Simple Pairing Using Out Of Band Association Model” by D. Sharmila, R. Neelaveni, and K. Kiruba in the Proceedings of the International Conference on Control, Automation, Communication and Energy Conservation, June 2009 After careful and considered review of the content and authorship of this paper by a duly constituted expert committee, this paper has been found to be in violation of IEEE’s Publication Principles. This paper copies substantial text from the original papers listed below. The original text was copied with insufficient attribution (including appropriate references to the original author(s) and/or paper title) and without permission. “Man-In-The-Middle Attacks on Bluetooth: A Comparative Analysis, A Novel Attack, and Countermeasures” by Keijo M.J. Haataja, Kostantin Hypponen in the Proceedings of the 3rd International Symposium on Communications, Control and Signal Processing (ICCSP), March 2008, pp. 1096-1102 “Bluetooth Secure Simple Pairing” by Anindya Bakshi in WirelessDesign Magazine, December 2007 “Simple Pairing Whitepaper” by Core Specific Working Group Bluetooth, SIG, August 2006 As an interconnection technology, Bluetooth has to address all traditional security problems, well known from the distributed networks. Moreover, as Bluetooth networks are formed by the radio links, there are also additional security aspects whose impact is yet not well understood. In this paper, we propose a novel man-in-the-middle (MITM) attack against Bluetooth enabled mobile phone that support simple secure pairing( SSP). The SSP association models such as numeric comparison, just works and passkey entry are found to be not more secure. Here we propose the out of band (OOB) channeling with enhanced security than the previous methods.

Read the paper · More papers on PaperTik