Improvement of Passkey Entry Protocol for Secure Simple Pairing
Sai Swaroop Madugula, Ruizhong Wei · 2023
Bluetooth devices are used extensively in todays world. From simple wireless headsets to maintaining an entire home network, the Bluetooth technology is used everywhere. However, there are still vulnerabilities present in the pairing process of Bluetooth which lead to serious security issues resulting in data theft and manipulation. We scrutinized the passkey entry protocol of Secure Simple Pairing (SSP) in the Bluetooth standard v5.2. In this paper, we propose a simple enhancement for the passkey entry protocol in the authentication stage 1 of Secure Simple Pairing using preexisting cryptographic hash functions and random integer generation present in the protocol. We also introduce a store random nonce method to avoid possible man-in-the-middle attack. The new protocol is more secure and efficient than previous known protocols. Our research mainly focuses on strengthening the passkey entry protocol and protecting the devices against passive eavesdropping and active Man-in-the-middle (MITM) attacks in both Bluetooth Basic Rate/Enhanced Data Rate (BR/EDR) and Bluetooth Low Energy (Bluetooth LE). This method can be used for any device which uses the passkey entry protocol.