Master-slave system for communication via a Bluetooth Low Energy connection
The proposed master-slave system allows a slave device to securely communicate with multiple master devices in a BLE network using a single request message, maintaining anonymity and identity protection through IRK encryption.
Patent Information
- Application Number
- DE102018202176
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2018-02-13
- Publication Date
- 2025-06-12
- Estimated Expiration
- 2038-02-13
AI Technical Summary
Existing Bluetooth Low Energy (BLE) systems allow a slave device to log in with a single master device only, compromising anonymity when logging in with the same Identity Releasing Key (IRK) to multiple masters.
A master-slave system where the slave device generates a single request message with a header field containing a Detachable Private Address (RPA) and a payload field holding additional identity information, enabling communication with multiple master devices while maintaining anonymity through IRK encryption.
Enables secure communication between a slave device and multiple master devices using a single request message, ensuring the anonymity and identity protection of the slave device across different connections.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
The invention relates to a master-slave system for communication via a Bluetooth low-energy connection. The invention further relates to a master device and to a slave device for communication in such a system. Furthermore, the present invention relates to a motor vehicle, in particular a passenger car, which is a slave device or a master device for communication with a master device or a slave device in a master-slave system.In a wide variety of technical fields, devices can communicate via a Bluetooth connection. To reduce power consumption during communication, for example, Bluetooth Low Energy (BLE) may be used. BLE is an extension of the Bluetooth radio technology. A BLE network includes a master device capable of communicating with multiple slave devices.In the case of BLE, what are known as advertising channels are provided, via which each connection between the devices is initiated. To this end, a device that takes a slave role actively sends a request message, called an advertising packet, periodically over an advertising channel to log in to another device in the BLE network that acts as the master of the BLE network. Based on the request message, the master may verify the authenticity of the slave and then establish communication between the slave device and the master device. An exemplary method is disclosed in US 2016 / 0134709 A1.The slave is logged in with a header field of the request message in which information, which is referred to as a Detachable Private Address (RPA), is stored. This information enables the slave device to send its identity encrypted during the registration phase, so that it is kept secret from other devices. The information is encrypted with a key, the so-called Identity Releasing Key (IRK). This key is transmitted in advance to the master, which can thus decrypt the received information and verify authenticity of the slave.Since the request message can contain only one header field and thus only one RPA information, however, it is only possible for a device to log in with a single request message to a single master, i.e. in a BLE network. Alternatively, the device may log in with the same request message to multiple masters by sending the same message to multiple master devices. In this case, the preservation of the anonymousity is not given, since the device logs on to a plurality of masters using the same IRK key, and this must be distributed beforehand to all possible connection partners.The invention is therefore based on the object of enabling communication between a slave device and a plurality of master devices while protecting the identity of the slave device from other devices.For this purpose, a master-slave system for communication via a Bluetooth low-energy connection is proposed. The master-slave system has at least one slave device and at least one master device which are configured to communicate via the Bluetooth low-energy connection.The slave device has a communication unit and a processing unit, wherein the processing unit of the slave device is configured to generate a first request message having a header field and a payload field, wherein the processing unit of the slave device is further configured to generate a first item of identity information based on a first stored key and to store it as first information in the header field. The information is present in the header field as a Detachable Private Address (RPA). With this first information, the slave device can establish communication with a master device, as was also possible with the previous request messages.In order to additionally carry out communication via a BLE connection with further master devices, the processing unit of the slave device is configured to generate at least one second identity information item different from the first identity information item on the basis of at least one second stored key and to store at least some of the at least one second identity information item as second information item in the payload field of the first request message. The communication unit of the slave device is configured to transmit the generated first request message to the master device via the Bluetooth low-energy connection, in particular via the provided advertising channels.Thus, with a single request message, the communication with one (only one information in the header field) or a plurality of master devices (first information in the header field and further second, i.e. a second, third and further, information in the payload field) can be requested. Alternatively, the slave device may log in with multiple functionalities to a master device. These multiple functionalities are represented by the first, the second and optional further information. For example, the slave device can log on to a master device as an access point for Internet services with a first item of identity information and as a telephone or music service with a second item of identity information.During the request process, the authenticity of the slave device is maintained by the encryption of the identity information with respect to other slave devices or other devices communicating via the same advertising channels. Since the other slave devices and devices are not in possession of the keys, they cannot decrypt the information.The keys used are in particular Identity Resolving Keys (IRK). These are transmitted in advance to the master devices in the master-slave system.Preferably, the encryption is a symmetrical encryption. Both the slave device and a master device are thereby provided with the same key. The keys can be used to ensure a secure, encrypted transmission of data between the slave device and the master devices.The introduction of the IRK keys into the master and slave device can be realized via an initial pairing process. In a Bluetooth system, this process can be performed, for example, by 2-channel authentication, i.e., radio channel in combination with a visual matching of a PIN number) on the two devices to be paired). In a BLE system in vehicle association, other 2-channel methods are also possible, for example (e.g. radio channel in combination with an NFC card, radio channel in connection with an authenticated online connection). In general, the pairing process is distinguished by the realization of a one-time, tap-proof connection, via which the keys necessary for the further communication of the devices to be paired are permanently introduced into the master and slave devices.Depending on how many master devices the slave device would like to communicate with and / or how many functionalities the slave device would like to connect to a master device, one or more items of information can be contained in the payload field. For example, the processing unit of the slave device can be configured to generate further identity information different from the first and the second identity information on the basis of further stored keys and to store at least a part of the further identity information as further information in the payload field of the first request message.More than two items of information, i.e. a second, third, fourth and further items of information, can be stored in the payload field. For example, information may be reduced to a size between 1 and 24 bits. In this way, up to 240 information can be stored in the payload field.According to one embodiment, the master device has a communication unit and a processing unit, wherein the communication unit of the master device is configured to receive the first request message from the communication unit of the slave device via the Bluetooth low energy connection, wherein the processing unit of the master device is configured to decrypt the second and optionally further information contained in the payload field of the first request message as second identity information, to assign it to the slave device and to verify an identity of the slave device.The master device stores a key with which the received information can be decoded.The decryption of the information can be realized by a complete comparison of the identity information transmitted in the payload field. For this purpose, the master device extracts the variable portion of the first identity information (RPA) specified in the address field of the request message, which was created by the slave device by means of a cryptographically secure random number generator. By chaining the extracted portion to each IRK key stored in the master unit and then executing a cryptographic hash function for each resulting chain pair, the master unit generates a set of its own identity information (RPAs) based on the slave device's request message. Subsequently, the master unit compares the self-generated RPAs with the RPAs communicated from the slave device through the request message. If a match occurs between an RPA generated by the master device and an RPA transmitted by the slave device in the request message during the comparison, the corresponding RPA transmitted by the slave device is deemed decoded. The decrypting IRK is here that which serves as the input value of the hash function.After the decryption, the processing unit can assign the second and optionally the further, decrypted identity information(s) to the slave device and verify the identity thereof therewith.After verification of the slave device, the processing unit of the master device can generate a response message for establishing communication with the slave device, wherein the communication unit of the master device is configured to transmit the response message to the slave device, and wherein the communication unit of the slave device is configured to receive the response message and to establish Bluetooth low-energy communication with the master device based on the response message.If the master device was able to authenticate the slave device or has at least received a quantity of identity information sufficient for it, it can send a response message back to the slave device. Based on the response message, the slave device may initiate establishment of the Bluetooth low-energy communication between the slave device and the master device.The master-slave system can have further master devices which are constructed identically to the first master device. This means that the further master device likewise has a communication unit and a processing unit, wherein the communication unit of the further master device is configured to receive the first request message from the communication unit of the slave device via the Bluetooth low energy connection, and wherein the processing unit of the further master devices is configured to decrypt the further information contained in the payload field of the first request message as further identity information and to assign it to the slave device.According to a further embodiment, the processing unit of the slave device is configured to divide the at least one second item of identity information into a plurality of blocks and to store a first subgroup of the blocks as at least second information in the payload field of the first request message.The payload field can have a length of 0 to 41 bytes, for example. In contrast to the first information, the length of which (6 bytes) is fixed, the length of the second information can be varied and contain between 1 and 41 bytes. Other values are also possible. In particular, if the slave device wishes to communicate with a plurality of master devices, the second information can be reduced or compressed in order to accommodate a plurality of information in the payload field.The information can be calculated, for example, as a hash function based on the key and the respective identity information. For the information to be transmitted, in one embodiment, at most the 24 highest bits of the calculated hash function are used.The processing unit of the master device may decide whether the blocks received with the first request message are sufficient for verification of the slave device and, if so, verify the identity of the slave device based on the first subset of the blocks.According to a further embodiment, the processing unit of the slave device is configured to generate a second or more further request messages and to store a second or more further subgroups of the blocks as second or further information in the payload field. The second or the further request messages are preferably sent temporally after the first request message.If the identity of the slave device could not be verified by the master device based on the first request message, the communication unit of the master device can actively request the second request message or passively wait for a further request message and receive it. The processing unit of the master device is configured in this case to verify the identity of the slave device on the basis of the first and the second subset of the blocks.If the slave device could not be verified or if the slave device has not yet received a response message from the master device, the processing unit of the slave device can generate a third request message in which a third subgroup of the blocks is stored as second information in the payload field and send it to the master device.The communication unit of the master device may receive the third request message, and the processing unit of the master device may verify the identity of the slave device based on the first, second, and third subsets of the blocks.This process may continue with further request messages containing further subsets of the second identity information until the master device has enough information to verify the slave device.This means that in addition to the first request message, any number of further request messages can be sent. Each further request message can contain a further subgroup of the identity information. Thus, the slave device can divide the subgroups of single identity information into a plurality of request messages.At the receiving side, the master device may decide how much information it needs via a slave device until it may decide that the slave device is sufficiently authenticated. This may depend, for example, on the functionality which is to be carried out by the communication between the slave device and the master device. For functionalities with little security, such as music services, a small amount of information, and thus a low probability of correct verification, may already suffice. In contrast, for security-relevant functionalities, such as access to personal data, a greater amount of information, and thus a high probability of correct verification, may be required.The processing unit of the master device can therefore decide whether the received information is already sufficient to verify the identity of the slave device or whether further information is required. If the processing unit of the master device has received a sufficient amount of information to verify the slave device, the communication unit of the master device can transmit a message to the slave device that no further information is required. This message can be carried out, for example, within the scope of the response message for establishing communication with the slave device. This response message can also stop the automatic sending of further request messages. Alternatively, the sending of further request messages can be continued.As already explained, the communication unit of the slave device can send a plurality of request messages. According to one embodiment, the communication unit of the slave device is configured to abort a transmission of the request message if a predefined abort event occurs.The communication unit of the slave device can transmit request messages with information until the abort event occurs. Each request message contains a further subgroup of the identity information. Once all subgroups have been sent, the process can begin again with the first subgroup. However, the slave device can generate an almost infinite number of subgroups.The predefined abort event can be, for example, the response message of the master device. If a communication set-up is initiated by the response message, the slave device can stop the sending of the request messages. A further abort event may be a predefined elapsed time period since the beginning of the sending of the first request message. Furthermore, the abort event can be the sending of the last subgroup of the identity information.If the communication is set up with one of a plurality of master devices, the slave device can send further request messages without the information for the master device with which communication is already being carried out. The sending of the request messages is therefore not completely aborted in this case, but rather the request messages are sent only without the information associated with the already connected master device.According to a further aspect, a motor vehicle, in particular a passenger car, is proposed. The motor vehicle can represent either the slave device or the master device in a master-slave system as described above. The corresponding master or slave device for communication with the motor vehicle can be a mobile device, such as a smartphone, tablet PC or the like.Furthermore, a method for communication via a Bluetooth low-energy connection in a master-slave system is proposed. The method comprises the following steps:generating a first request message having a header field and a payload field, wherein a first item of identity information is generated based on a first stored key and is stored as first information in the header field,generating at least one second identity information different from the first identity information based on at least one second stored key and storing at least a portion of the second identity information as second information in the payload field of the first request message, andtransmitting the generated first request message to a master device via the Bluetooth low energy connection.At the receiving side, i.e. in the master device, the first request message can be received. The at least second information contained in the payload field of the first request message can then be decrypted as second identity information, assigned to the slave device and an identity of the slave device verified.The embodiments and features described for the proposed master-slave system apply correspondingly to the proposed method.Furthermore, a computer program product is proposed, which has a program code which is designed to cause a computer to carry out the method as explained above.A computer program product, such as a computer program means, can be provided or supplied, for example, as a storage medium, such as a memory card, USB stick, CD-ROM, DVD, or else in the form of a downloadable file from a server in a network. This can be effected, for example, in a wireless communication network by the transmission of a corresponding file with the computer program product or the computer program means.Further possible implementations of the invention also include combinations, not explicitly mentioned, of features or embodiments described above or below with respect to the exemplary embodiments. In this case, the person skilled in the art will also add individual aspects as improvements or additions to the respective basic form of the invention.Further advantages and advantageous embodiments are specified in the description, the drawings and the claims. In this case, in particular the combinations of the features indicated in the description and in the drawings are purely exemplary, and therefore the features can also be present individually or in a different combination.The invention will be described in more detail below with reference to exemplary embodiments illustrated in the drawings. The exemplary embodiments and the combinations shown in the exemplary embodiments are purely exemplary and are not intended to define the scope of protection of the invention. This is defined solely by the appended claims.The following are shown: FIG. 1 : a master-slave system with one slave device and two master devices; FIG. 2 : shows an example of a request message which is generated by the slave device of FIG. 1 ; and FIG. 3 : shows a schematic flow diagram for establishing a communication in the master-slave system of FIG. 1.In the following, elements that are the same or functionally the same are identified by the same reference numerals.FIG. 1 shows a master-slave system 1 having a slave device 10 and two master devices 20, 30. only one master device 20 or any number of further master devices can also be provided.The slave device 10 includes a communication unit 11 and a processing unit 12. The master devices 20, 30 likewise each have a communication unit 21, 31 and a processing unit 22, 32.In order to start communication with one or both master devices 20, 30 via a Bluetooth low-energy connection, the slave device 10 must first send a request message 40 to the master devices 20, 30. This request message 40 can be sent via advertising channels, as provided for Bluetooth Low Energy, before the actual communication.If only communication with a single master device 20 is desired, the slave device 10 can transmit its own identity in a header field 41 of the request message 40, as shown in FIG. 2. However, if communication is to be established with more than one master device 20, 30, the slave device 10 can transmit a request message 40 containing a plurality of identity information 43, 44.For this purpose, the processing unit 12 generates the request message 40 with the header field 41 and a payload field 42, wherein a first item of identity information, which is generated on the basis of a first key, is stored as first information in the header field 41.In addition, the processing unit 12 generates at least one second and optionally a plurality of identity information different from the first identity information on the basis of a second or further key and stores at least a part of the second identity information as second information 43 in the payload field 42. If the slave device 10 wishes to establish communication with a plurality of master devices 20, 30, the payload field 42 can have up to n identity information 43, 44. Each identity information item is encrypted with its own key. The keys may be exchanged in advance between the slave device 10 and the respective master devices 20, 30.After generating the request message 40, the communication unit 12 transmits the generated request message 40 to the master devices 20, 30 via the advertising channels.In order to be able to store a plurality of items of information 43, 44 in the payload field 42, the processing unit 12 can divide the second and further items of identity information into a plurality of blocks in each case. A first subgroup of the blocks of the second or the further identity information is then stored as second information 43 in the payload field 42 of the first request message 30. Analogously, a first group of blocks of each further identity information is stored as identity information 44 in the payload field 42.Payload field 42 may have a length of 0 to 41 bytes, for example. In contrast to the first information, the length of which (6 bytes) is fixed, the length of the second information 43, 44 can be varied and contain between 1 and 41 bytes. In particular, if the slave device 10 wishes to communicate with a plurality of master devices 20, 30, the second information 43, 44 can be reduced or compressed in order to accommodate a plurality of information 43, 44 in the payload field 42.If only a first subset of the respective identity information is included in the information 43, 44, the processing unit 12 may generate further request messages 40 including the further subsets of the identity information in the information 43, 44.The request messages 40 are received by the communication units 21, 31 of the master devices 20, 30. The processing units 22, 32 examine the information contained in the header field 41 and the payload field 42. If the processing units 22, 32 recognize a second item of information 43, 44 intended for them, the second or the further items of information 43, 44 are decrypted using a stored key as second or further item of identity information and are assigned to the slave device 10.The processing units 22, 32 verify an identity of the slave device 10 based on the second identity information and based on the stored key. If only a subgroup of the identity information has been transmitted, the respective processing unit 22, 32 can decide whether the received information is already sufficient for verifying the slave device 10. If this is not the case, the communication unit 21, 31 of the corresponding master device 20, 30 can receive a further request message 40 which has a second subgroup of the identity information as second information 43, 44 in the payload field 42.Once the processing unit 22, 32 has sufficient information about the identity of the slave device 10 to verify it with a predetermined probability, the processing unit 22, 32 can generate a response message which is transmitted to the slave device 10 by the communication unit 21, 31.When the communication unit 11 of the slave device 10 receives a corresponding response message from one of the master devices 20, it may establish Bluetooth low-energy communication with the corresponding master device 20 based on this response message.The number of request messages 40 required can depend on the respective master device 20, 30. After a predefined abort event, the slave device 10 can abort the transmission of request messages without establishing a communication connection. Such a break event may occur, for example, when all subgroups of the identity information have been transmitted without a response message having been received.The sequence of the communication setup is explained once again in FIG. 3.First, in a first step 51, a request message 40 is generated. As explained above, this request message 40 can contain one or more items of information in a payload field 42 which are each assigned to a master device 20, 30. The reception of the request message 40 by a master device 20 will be described below. This takes place analogously for each further master device 30.In a second step 52, the request message 40 is received and the information 43 contained therein is then decrypted in step 53 as described above. If the master device 20 is not able to decrypt the information 43, the master device 20 can wait for a further request message 40. This may be the case, for example, if the information 43, 44 contained in the request message 40 is not intended for the master device 20 and therefore does not have a corresponding key.If the information 43 has been decrypted, the master device 20 decides in step 54 whether the identity information is sufficient for verifying the slave device 10. This may depend, for example, on the functionality which is to be carried out by the communication between the slave device 10 and the master device 20. For functionalities with little security, such as music services, a small amount of information, and thus a low probability of correct verification, may already suffice. In contrast, for security-relevant functionalities, such as access to personal data, a greater amount of information, and thus a high probability of correct verification, may be required.If the verification is not sufficient, the master device 20 waits for further request messages 40 with further subgroups of the identity information. The method then continues with steps 51 to 54 until the information is sufficient for verification.If this is the case, in step 55 a communication is set up between the slave device 10 and the master device 20. For this purpose, master device 20, as described above, may send a response message to slave device 10 in order to initiate the communication setup.The figures describe that a single request message 40 is used to request communication with a plurality of master devices 20, 30. Alternatively or additionally, the slave device 10 can log in with a plurality of functionalities to a single master device 20. These multiple functionalities are represented by the first and second information. For example, the slave device 10 can log on as an access point for Internet services with a first item of identity information and as a telephone or music service with a second item of identity information to a master device 20 or the master devices 20, 30. The procedure is analogous to that described above, wherein the master devices 20, 30 each decrypt a plurality of items of information with a plurality of keys.The proposed master-slave system allows a slave device not only to request communication with a master device. Rather, the slave device can transmit a request for communication setup to a plurality of master devices simultaneously with a single message.Reference numerals denote reference numerals1 Master-slave system 10 Slave device 11 Communication unit 12 Processing unit 20 Master device 21 Communication unit 22 Processing unit 30 Master device 31 Communication unit 32 Processing unit 40 Request message 41 Header field 42 Payload field 43 Second information 44 n-th information 51- 55 Method steps
Claims
Master-slave system (1) for communication via a Bluetooth low-energy connection, having at least one slave device (10) and at least one master device (20), wherein the slave device (10) and the master device (20) are configured to communicate via the Bluetooth low-energy connection, wherein the slave device (10) has a communication unit (11) and a processing unit (12), wherein the processing unit (11) of the slave device (10) is configured to generate a first request message (40) having a header field (41) and a payload field (42), wherein the processing unit (11) of the slave device (10) is further configured to generate a first identity information based on a first stored key and to store it as first information in the header field (41), and wherein the communication unit (11) of the slave device (10) is configured to transmit the generated first request message (40) to the master device (20) via the Bluetooth low-energy connection, wherein the processing unit (12) of the slave device (10) is configured to generate at least one second identity information different from the first identity information based on at least one second stored key and to store at least a part of the at least one second identity information as at least second information (43) in the payload field (42) of the first request message (40).Master-slave system (1) according to Claim 1, wherein the processing unit (12) of the slave device (10) is configured to generate further identity information different from the first and the second identity information on the basis of further stored keys and to store at least some of the further identity information as further information (44) in the payload field (42) of the first request message (40).Master-slave system (1) according to one of the preceding claims, wherein the master device (20) has a communication unit (21) and a processing unit (22), wherein the communication unit (21) of the master device (20) is configured to receive the first request message (40) from the communication unit (11) of the slave device (10) via the Bluetooth low energy connection, wherein the processing unit (22) of the master device (20) is configured to decrypt the at least one second information (43) contained in the payload field (42) of the first request message (40) as second identity information, to assign it to the slave device (10) and to verify an identity of the slave device (10).Master-slave system (1) according to one of the preceding claims, wherein the processing unit (22) of the master device (20) is configured to generate a response message for establishing communication with the slave device (10) after verification of the slave device (10), that the communication unit (21) of the master device (20) is configured to transmit the response message to the slave device (10) and that the communication unit (11) of the slave device (10) is configured to receive the response message and to establish a Bluetooth low-energy communication with the master device (20) based on the response message.Master-slave system (1) according to one of the preceding claims, wherein the processing unit (12) of the slave device (10) is configured to divide the at least one second item of identity information into a plurality of blocks and to store a first subgroup of the blocks as at least second information (43) in the payload field (42) of the first request message (40).The master-slave system (1) according to claim 5, wherein the processing unit (22) of the master device (20) is configured to decide whether the received blocks are sufficient for verification of the slave device (10), and if so, to verify the identity of the slave device (10) based on the first subset of the blocks.Master-slave system (1) according to Claim 5 or 6, wherein the processing unit (12) of the slave device (10) is configured to generate a second or more further request messages (40) and to store a second or more further subgroups of the blocks as second or further information (43) in the payload field (42).The master-slave system (1) according to claim 7, wherein, if the identity of the slave device (10) is not verified, the communication unit (21) of the master device (20) is configured to request and / or receive the second or further request messages (40), and that the processing unit (22) of the master device (20) is configured to verify the identity of the slave device (10) based on the first and the second or further subset of the blocks.Master-slave system (1) according to one of the preceding claims, wherein the communication unit (11) of the slave device (10) is configured to abort a transmission of the request message if a predefined abort event occurs.Motor vehicle (1), in particular passenger car, which is a slave device (10) or a master device (20) for communication with a master device (20) or a slave device (10) in a master-slave system (1) according to one of the preceding claims.
Citation Information
Patent Citations
Method, apparatus, and computer program product for a node to advertise its presence and service profiles thereof in a wireless environment
US20160134709A1