Bypassing Passkey Authentication in Bluetooth Low Energy.
Tomáš Rosa · 2013
This memo describes certain new cryptographic weakness of the passkey-based pairing of Bluetooth LE (BLE or BTLE, also known as Bluetooth Smart; as one prefers). The vulnerability discussed here extends the set of possible attacking scenarios that were already elaborated before by Mike Ryan in [4]. Instead of the passive sniffing attack on pairing secrets, we show how a fraudulent Responder can gracefully bypass passkey authentication, despite it being possibly based on even one-time generated PIN. Such an active attack may become handy in situation where passive sniffing of correct pairing cannot be employed – for instance, because the original Responder device is out of reach or otherwise unwilling to pair again. Or, we may already want to actively impersonate the peripheral device to inject some data into e.g. iPhone Apps, perform MITM, etc. Since the attack runs on the Security Manager layer, it can reuse a lot of the existing network stack that is already in place for this approach. This namely concerns everything bellow HCI [1]. Actually, the whole procedure starting with the authentication bypass and continuing to data injection (which would be a regular communication anyway) can be done using a general Bluetooth 4.0 Smart Ready USB dongle via HCI commands. Furthermore, we shall perhaps emphasize the attack we present here would be possible even if there already was the yet-awaited ephemeral Diffie-Hellman key agreement employed in BLE as, for instance, in Bluetooth BR/EDR Secure