Saving Private Addresses: An Analysis of Privacy Issues in the Bluetooth-Low-Energy Advertising Mechanism

被引:14
作者
Celosia, Guillaume [1 ]
Cunche, Mathieu [1 ]
机构
[1] Univ Lyon, INSA Lyon, INRIA, CITI, F-69621 Villeurbanne, France
来源
PROCEEDINGS OF THE 16TH EAI INTERNATIONAL CONFERENCE ON MOBILE AND UBIQUITOUS SYSTEMS: COMPUTING, NETWORKING AND SERVICES (MOBIQUITOUS'19) | 2019年
基金
欧盟地平线“2020”;
关键词
Bluetooth Low Energy; Privacy; Tracking; Address randomization; LOCATION PRIVACY;
D O I
10.1145/3360774.3360777
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The Bluetooth Low Energy (BLE) protocol is being included in a growing number of connected objects such as fitness trackers and headphones. As part of the service discovery mechanism of BLE, devices announce themselves by broadcasting radio signals called advertisement packets that can be collected with off-the-shelf hardware and software. To avoid the risk of tracking based on those messages, BLE features an address randomization mechanism that substitutes the device address with random temporary pseudonyms, called Private addresses. In this paper, we analyze the privacy issues associated with the advertising mechanism of BLE, leveraging a large dataset of advertisement packets collected in the wild. First, we identified that some implementations fail at following the BLE specifications on the maximum lifetime and the uniform distribution of random identifiers. Furthermore, we found that the payload of the advertisement packet can hamper the randomization mechanism by exposing counters and static identifiers. In particular, we discovered that advertising data of Apple and Microsoft proximity protocols can be used to defeat the address randomization scheme. Finally, we discuss how some elements of advertising data can be leveraged to identify the type of device, exposing the owner to inventory attacks.
引用
收藏
页码:444 / 453
页数:10
相关论文
共 36 条
  • [1] Fingerprinting Bluetooth-Low-Energy Devices Based on the Generic Attribute Profile
    Celosia, Guillaume
    Cunche, Mathieu
    PROCEEDINGS OF THE 2ND INTERNATIONAL ACM WORKSHOP ON SECURITY AND PRIVACY FOR THE INTERNET-OF-THINGS (IOT S&P'19), 2019, : 24 - 31
  • [2] DEMO: Himiko: A Human Interface for Monitoring and Inferring Knowledge on Bluetooth-Low-Energy Objects
    Celosia, Guillaume
    Cunche, Mathieu
    PROCEEDINGS OF THE 2019 CONFERENCE ON SECURITY AND PRIVACY IN WIRELESS AND MOBILE NETWORKS (WISEC '19), 2019, : 292 - 294
  • [3] Accuracy analysis of Bluetooth-Low-Energy ranging and positioning in NLOS environment
    Yang, Deng
    Wang, Jian
    Wang, Minmin
    Han, Houzeng
    Zhang, Yalei
    INTERNATIONAL JOURNAL OF IMAGE AND DATA FUSION, 2020, 11 (04) : 356 - 374
  • [4] A lightweight, wireless Bluetooth-low-energy neuronal recording system for mice
    Idogawa, Shinnosuke
    Yamashita, Koji
    Sanda, Rioki
    Numano, Rika
    Koida, Kowa
    Kawano, Takeshi
    SENSORS AND ACTUATORS B-CHEMICAL, 2021, 331
  • [5] Address Privacy of Bluetooth Low Energy
    Sun, Dazhi
    Tian, Yangguang
    MATHEMATICS, 2022, 10 (22)
  • [6] A survey on Bluetooth Low Energy security and privacy
    Caesar, Matthias
    Pawelke, Tobias
    Steffan, Jan
    Terhorst, Gabriel
    COMPUTER NETWORKS, 2022, 205
  • [7] On Practical Selective Jamming of Bluetooth Low Energy Advertising
    Braeuer, Sebastian
    Zubow, Anatolij
    Zehl, Sven
    Roshandel, Mehran
    Mashhadi-Sohi, Soroush
    2016 IEEE CONFERENCE ON STANDARDS FOR COMMUNICATIONS AND NETWORKING (CSCN), 2016,
  • [8] Advertising semantically described physical items with Bluetooth Low Energy beacons
    Takalo-Mattila, Janne
    Kiljander, Jussi
    Soininen, Juha-Pekka
    2013 2ND MEDITERRANEAN CONFERENCE ON EMBEDDED COMPUTING (MECO), 2013,
  • [9] An Analysis of Bluetooth, Zigbee and Bluetooth Low Energy and Their Use in WBANs
    Georgakakis, Emmanouil
    Nikolidakis, Stefanos A.
    Vergados, Dimitrios D.
    Douligeris, Christos
    WIRELESS MOBILE COMMUNICATION AND HEALTHCARE, 2011, 55 : 168 - 175
  • [10] Security Analysis of Bluetooth Low Energy Based Smart Wristbands
    Zhang, Qiaoyang
    Liang, Zhiyao
    2017 2ND INTERNATIONAL CONFERENCE ON FRONTIERS OF SENSORS TECHNOLOGIES (ICFST), 2017, : 421 - 425