Authenticator Communication with Application-Level Bluetooth Pairing Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Bluetooth pairing methods lack data security, as all applications on paired devices can access transmitted data, leading to insecurity, and slave devices are passive during connections, with some devices not requiring pairing, making them vulnerable to data theft.
Innovation Solution
A method and system for establishing an application-level Bluetooth pairing connection with bidirectional authentication and encryption using session keys to secure data transmission between a client and an authenticator.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If standard Bluetooth pairing is used, then device connection is established, but data security deteriorates as all applications can access transmitted data
Solution Approach 1:
The patent divides the pairing process into two levels: system-level Bluetooth pairing (for basic connectivity) and application-level pairing (for security). The application-level pairing uses separate key pairs (first key pair for client, second key pair for authenticator) that are independent from the system-level pairing, allowing security to be segmented and controlled at the application layer without affecting overall system connectivity.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism where the client and authenticator exchange and verify identification information (first client identification, first authenticator identification, second client identification, second authenticator identification) derived from their respective key pairs. This intermediary verification process ensures that even though Bluetooth pairing is established, only authorized applications can access data transmission.
2Ease of operation
If system-level Bluetooth pairing is used, then connection is established, but application control deteriorates as slave device is completely passive
Solution Approach 1:
The patent makes the pairing process dynamic by allowing the master device to select which slave device to connect with, rather than having a fixed passive role for the slave device. The bidirectional authentication mechanism enables dynamic verification where either device can initiate authentication, and the process can be terminated or continued based on verification results, providing flexible application-level control over the connection process.
3Reliability
If pairing is required for all devices, then security is improved, but ease of use deteriorates as some devices do not need pairing
Solution Approach 1:
The patent applies security measures locally rather than universally. System-level Bluetooth pairing remains simple and quick for basic connectivity, while application-level pairing with bidirectional authentication is applied only when data security is required. This allows devices to connect conveniently without pairing when security is not needed, while enforcing security measures only for applications that require protected data transmission.
Data Source
AI summary
A method and system for communicating with an authenticator, which belongs to communication technology field. The method includes: the client generates a first client identification, a first authenticator identification and a first session key, broadcasts data including the first client identification according to a preset time interval; the authenticator scans the broadcast data, obtain a third key to verify the first client identification, generates a second authenticator identification and a second session key if the verifying is successful, notifies that the verifying is successful, stops scanning and broadcasts broadcast data including the second authenticator identification; the client stops broadcasting and scans the broadcast data sent from the authenticator, obtains and verifies the second authenticator identification in the broadcast data, establishes the Bluetooth connection with the authenticator if the verifying is successful; the client performs handshake operation and encryption communication operation.


