BLE Connection Request Encryption for Eavesdropping Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Bluetooth Low Energy (BLE) connection establishment is vulnerable to eavesdropping, as eavesdroppers can intercept timing and hopping pattern information during the connection initiation, allowing them to follow communications between devices.

Innovation Solution

Encrypting control information in connection request packets using cryptographic keys, such as connection entry keys, to secure the establishment of BLE connections, preventing eavesdroppers from accessing the necessary information to follow the communication on data channels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If control information in connection request packets is transmitted in clear text, then the connection establishment process is simple and fast, but eavesdroppers can intercept timing and hopping pattern information to follow communications between devices

Engineering Contradiction:
Improvesecurity of connection establishmentVSAvoidcomplexity of connection establishment process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-establishing a secure link between devices before the actual data communication begins. The secure link is established during the connection establishment phase, allowing subsequent control information to be encrypted and authenticated. This prevents eavesdroppers from intercepting timing and hopping pattern information while maintaining a manageable complexity through structured cryptographic operations.

Inventive Principle:
Principle #10Preliminary action

2Loss of information

If control information is encrypted using cryptographic keys, then eavesdroppers cannot intercept timing and hopping pattern information, but the connection establishment process becomes more complex

Engineering Contradiction:
Improveprotection of timing and hopping pattern informationVSAvoidcomplexity of encryption and decryption operations
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent uses cryptographic keys as intermediaries to protect control information. The secure link acts as an intermediary channel that establishes trusted communication between devices before data exchange begins. This intermediary mechanism ensures that timing and hopping pattern information remains confidential while the cryptographic operations are standardized and manageable through established protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies parameter changes by transforming control information from clear text to encrypted form using cryptographic parameters (keys, initialization vectors, etc.). This parameter transformation protects the confidentiality of timing and hopping pattern information while the complexity is managed through systematic application of cryptographic algorithms with controlled parameter sets.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10003581B2Secure connection establishment
Publication Date: 2018.06.19 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US10003581B2 patent drawing
  • US10003581B2 patent drawing
  • US10003581B2 patent drawing

AI summary

A wireless device implementing secure connection establishment may include at least one processor circuit. The at least one processor circuit may be configured to receive an advertising packet from a device over a first channel and generate, in response to receiving the advertising packet, a connection request packet that comprises control information for establishing a connection with the device over a second channel. The at least one processor circuit may be further configured to encrypt and authenticate at least a portion of the connection request packet based at least in part on a connection entry key previously exchanged with the device and transmit the at least partially encrypted connection request packet over the first channel. The at least one processor circuit may be further configured to establish the connection with the device over the second channel based at least in part on the control information of the connection request packet.