Formal Analyzing, Attacking, and Patching of Bluetooth Pairing Protocols
Min Shi, Jing Chen, Kun He, Haoran Zhao, Meng Jia, Ruiying Du · IEEE Internet of Things Journal · 2025
Bluetooth pairing is a protocol that authenticates two Bluetooth devices and derives a shared secret key between them. The Bluetooth standard consists of Bluetooth low energy (BLE) and Bluetooth classic (BC) and the latest pairing protocols in them are BLE secure connections (BLE-SCs) and secure simple pairing with secure connections (SSP-SCs), respectively. Although these two pairing protocols employ well-studied cryptographic primitives to guarantee their security, recent studies disclosed logic flaws in them. In this article, we develop the first comprehensive formal models of BLE-SC and SSP-SC pairing protocols. The models cover all pairing phases of the two protocols and all association models in the specification to discover attacks caused by the interplay between different association models. We also partly loosen the perfect cryptography assumption in traditional symbolic analysis approaches by designing a low-entropy key oracle to detect attacks caused by poorly derived keys. Our analysis confirms two existing attacks and discloses a new attack that we implemented on real-world devices. We propose a countermeasure to fix the flaws found in the BLE-SC and SSP-SC pairing protocols and discuss the backward compatibility. Moreover, we extend our models to verify the countermeasure, and the results demonstrate its effectiveness in our extended models.