Two practical man-in-the-middle attacks on bluetooth secure simple pairing and countermeasures

  • Authors:
  • Keijo Haataja;Pekka Toivanen

  • Affiliations:
  • Department of Computer Science, University of Kuopio, Kuopio, Finland;Department of Computer Science, University of Kuopio, Kuopio, Finland

  • Venue:
  • IEEE Transactions on Wireless Communications
  • Year:
  • 2010

Quantified Score

Hi-index 0.01

Visualization

Abstract

We propose two new Man-In-The-Middle (MITM) attacks on Bluetooth Secure Simple Pairing (SSP). The attacks are based on the falsification of information sent during the input/output capabilities exchange and also the fact that the security of the protocol is likely to be limited by the capabilities of the least powerful or the least secure device type. In addition, we devise countermeasures that render the attacks impractical, as well as improvements to the existing Bluetooth SSP in order to make it more secure. Moreover, we provide a comparative analysis of the existing MITM attacks on Bluetooth.