RSSI-Based Fingerprinting of Bluetooth Low Energy Devices

被引:1
作者
Gagnon, Guillaume [1 ]
Gambs, Sebastien [1 ]
Cunche, Mathieu [2 ]
机构
[1] Univ Quebec Montreal, Montreal, PQ, Canada
[2] Univ Lyon, CITI Lab, INSA Lyon, INRIA, Lyon, France
来源
PROCEEDINGS OF THE 20TH INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, SECRYPT 2023 | 2023年
基金
加拿大自然科学与工程研究理事会;
关键词
Bluetooth; RSSI; Fingerprinting; Privacy; Unlinkability; PRIVACY;
D O I
10.5220/0012139600003555
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
To prevent tracking, the Bluetooth Low Energy protocol integrates privacy mechanisms such as address randomization. However, as highlighted by previous researches address randomization is not a silver bullet and can be circumvented by exploiting other types of information disclosed by the protocol such as counters or timing. In this work, we propose a novel attack to break address randomization in BLE exploiting side information that has not been considered before: Received Signal Strength Indication (RSSI). More precisely, we demonstrate how RSSI measurements, extracted from received BLE advertising packets, can be used to link together the traces emitted by the same device or re-identify it despite address randomization. The proposed attack leverages the distribution of RSSI to create a fingerprint of devices. An empirical evaluation of the attack on various scenarios demonstrate its effectiveness. For instance in the static context, in which devices remain at the same position, the proposed approach yields a re-identification accuracy of up to 99%, which can even be boosted by increasing the number of receivers controlled by the adversary.
引用
收藏
页码:242 / 253
页数:12
相关论文
共 42 条
[1]   A Survey of COVID-19 Contact Tracing Apps [J].
Ahmed, Nadeem ;
Michelin, Regio A. ;
Xue, Wanli ;
Ruj, Sushmita ;
Malaney, Robert ;
Kanhere, Salil S. ;
Seneviratne, Aruna ;
Hu, Wen ;
Janicke, Helge ;
Jha, Sanjay K. .
IEEE ACCESS, 2020, 8 :134577-134601
[2]  
Android, 2023, Android api reference-advertisingsetparameters
[3]  
Antonioli D, 2019, PROCEEDINGS OF THE 28TH USENIX SECURITY SYMPOSIUM, P1047
[4]  
Apple, 2022, Accessory design guidelines for apple devices
[5]  
Becker Johannes K., 2019, Proceedings on Privacy Enhancing Technologies, V2019, P50, DOI 10.2478/popets-2019-0036
[6]  
Castelluccia C, 2020, ROBERT: ROBust and privacypresERving proximity Tracing
[7]  
Celosia Guillaume, 2020, Proceedings on Privacy Enhancing Technologies, V2020, P26, DOI 10.2478/popets-2020-0003
[8]   Saving Private Addresses: An Analysis of Privacy Issues in the Bluetooth-Low-Energy Advertising Mechanism [J].
Celosia, Guillaume ;
Cunche, Mathieu .
PROCEEDINGS OF THE 16TH EAI INTERNATIONAL CONFERENCE ON MOBILE AND UBIQUITOUS SYSTEMS: COMPUTING, NETWORKING AND SERVICES (MOBIQUITOUS'19), 2019, :444-453
[9]  
Claverie T., 2020, SSTIC, P1
[10]  
Das A. K., 2016, ACM HotMobile