Saving Private Addresses: An Analysis of Privacy Issues in the Bluetooth-Low-Energy Advertising Mechanism

被引:14
作者
Celosia, Guillaume [1 ]
Cunche, Mathieu [1 ]
机构
[1] Univ Lyon, INSA Lyon, INRIA, CITI, F-69621 Villeurbanne, France
来源
PROCEEDINGS OF THE 16TH EAI INTERNATIONAL CONFERENCE ON MOBILE AND UBIQUITOUS SYSTEMS: COMPUTING, NETWORKING AND SERVICES (MOBIQUITOUS'19) | 2019年
基金
欧盟地平线“2020”;
关键词
Bluetooth Low Energy; Privacy; Tracking; Address randomization; LOCATION PRIVACY;
D O I
10.1145/3360774.3360777
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The Bluetooth Low Energy (BLE) protocol is being included in a growing number of connected objects such as fitness trackers and headphones. As part of the service discovery mechanism of BLE, devices announce themselves by broadcasting radio signals called advertisement packets that can be collected with off-the-shelf hardware and software. To avoid the risk of tracking based on those messages, BLE features an address randomization mechanism that substitutes the device address with random temporary pseudonyms, called Private addresses. In this paper, we analyze the privacy issues associated with the advertising mechanism of BLE, leveraging a large dataset of advertisement packets collected in the wild. First, we identified that some implementations fail at following the BLE specifications on the maximum lifetime and the uniform distribution of random identifiers. Furthermore, we found that the payload of the advertisement packet can hamper the randomization mechanism by exposing counters and static identifiers. In particular, we discovered that advertising data of Apple and Microsoft proximity protocols can be used to defeat the address randomization scheme. Finally, we discuss how some elements of advertising data can be leveraged to identify the type of device, exposing the owner to inventory attacks.
引用
收藏
页码:444 / 453
页数:10
相关论文
共 36 条
  • [31] Experimental Analysis of a Bluetooth Low Energy Wake-Up Radio Solution
    Rup, Clement
    Hopp, Quentin
    Mamert, Sebastien
    Turco, Bastien
    Bajic, Eddy
    Mekki, Kais
    SERVICE ORIENTED, HOLONIC AND MULTI-AGENT MANUFACTURING SYSTEMS FOR INDUSTRY OF THE FUTURE, SOHOMA 2023, 2024, 1136 : 409 - 419
  • [32] Power Consumption Analysis of Bluetooth Low Energy Commercial Products and Their Implications for IoT Applications
    Garcia-Espinosa, Eduardo
    Longoria-Gandara, Omar
    Pegueros-Lepe, Ioseth
    Veloz-Guerrero, Arturo
    ELECTRONICS, 2018, 7 (12):
  • [33] Design and energetic analysis of a self-powered Bluetooth Low Energy speed sensor
    Buccolini, Luca
    Pierleoni, Paola
    Conti, Massimo
    2016 IEEE 16TH INTERNATIONAL CONFERENCE ON ENVIRONMENT AND ELECTRICAL ENGINEERING (EEEIC), 2016,
  • [34] Accuracy Analysis of the Indoor Location System Based on Bluetooth Low-Energy RSSI Measurements
    Janczak, Dariusz
    Walendziuk, Wojciech
    Sadowski, Maciej
    Zankiewicz, Andrzej
    Konopko, Krzysztof
    Idzkowski, Adam
    ENERGIES, 2022, 15 (23)
  • [35] Power Consumption Analysis of Bluetooth Low Energy, ZigBee and ANT Sensor Nodes in a Cyclic Sleep Scenario
    Dementyev, Artem
    Hodges, Steve
    Taylor, Stuart
    Smith, Joshua
    2013 IEEE INTERNATIONAL WIRELESS SYMPOSIUM (IWS), 2013,
  • [36] Measurement-Based Latency Evaluation and the Theoretical Analysis for Massive IoT Applications Using Bluetooth Low Energy
    Uchida, Daisuke
    Yonezawa, Yuki
    Akita, Koji
    2023 IEEE 97TH VEHICULAR TECHNOLOGY CONFERENCE, VTC2023-SPRING, 2023,