Secure BLE Beacon ID Generation via Dynamic Pseudorandom Functions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Bluetooth Low Energy (BLE) devices used in location-based services face security threats such as spoofing, piggybacking, and re-programming attacks due to their unselective beacon ID broadcasting, which compromises the effectiveness and efficiency of these services.
Innovation Solution
Implementing a system where BLE devices use a pseudorandom function with a secret shared key to generate an encoded beacon ID that evolves over time, combined with entity authentication and Message Authentication Codes (MAC) to validate beacon IDs, ensuring secure communication and preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If beacon devices broadcast beacon IDs unselectively to provide location-based services, then accessibility and coverage are improved, but security vulnerability increases due to susceptibility to spoofing attacks
Solution Approach 1:
A trusted server acts as an intermediary between beacon devices and mobile devices. The server receives location-based service requests from mobile devices, determines which beacon devices should respond, and returns filtered beacon ID lists to the mobile devices. This intermediary mechanism allows beacon devices to broadcast widely while preventing unauthorized access to beacon information.
2Device complexity
If beacon devices use static beacon IDs for simplicity, then device complexity is reduced, but reliability deteriorates due to inability to prevent spoofing and re-programming attacks
Solution Approach 1:
The system transitions from static beacon IDs to dynamic, time-varying beacon IDs. Each beacon device generates a new beacon ID periodically, and the server tracks these changing IDs along with their corresponding physical locations. Mobile devices receive updated beacon ID lists from the server, ensuring they always have current information. This dynamic approach prevents spoofing and re-programming attacks while maintaining manageable complexity through server coordination.
3Area of stationary object
If beacon devices broadcast to all mobile devices, then service coverage is improved, but loss of information increases due to inability to filter unauthorized access
Solution Approach 1:
The trusted server serves as an information filter and intermediary. It receives location-based service requests from mobile devices, determines which beacon devices should respond based on the request criteria, and returns filtered beacon ID lists to the mobile devices. This ensures that beacon information is selectively shared only with authorized devices, preventing information loss to unauthorized parties while maintaining broad service coverage.
4Reliability
If the system uses frequent beacon ID updates to prevent attacks, then security is improved, but use of energy increases due to continuous communication and computation
Solution Approach 1:
The system implements periodic beacon ID updates rather than continuous updates. Each beacon device generates a new beacon ID at predetermined time intervals, and the server coordinates these updates by tracking which beacon devices have updated and when. This periodic approach maintains security by preventing spoofing and re-programming attacks while significantly reducing energy consumption compared to continuous updates, as devices only communicate and compute at discrete intervals rather than continuously.
Data Source
AI summary
The present disclosure relates to methods and systems for generation of a beacon identifier (ID) for increased security of a system for a location based service. The system includes a beacon device, such as a BLE device, a mobile device, and a server. The beacon device is configured to generate a beacon ID based on a beacon device identifier, such as a unique device identifier, of a beacon device and a time value. In some implementations, generation of the beacon ID includes a pseudorandom function and a shared key that is established between the beacon device and the server.


