Cracking the Bluetooth PIN

  • Authors:
  • Yaniv Shaked;Avishai Wool

  • Affiliations:
  • Tel Aviv University, Israel;Tel Aviv University, Israel

  • Venue:
  • Proceedings of the 3rd international conference on Mobile systems, applications, and services
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper describes the implementation of an attack on the Bluetooth security mechanism. Specifically, we describe a passive attack, in which an attacker can find the PIN used during the pairing process. We then describe the cracking speed we can achieve through three optimizations methods. Our fastest optimization employs an algebraic representation of a central cryptographic primitive (SAFER+) used in Bluetooth. Our results show that a 4-digit PIN can be cracked in less than 0.3 sec on an old Pentium III 450MHz computer, and in 0.06 sec on a Pentium IV 3Ghz HT computer.