Bluetooth Encryption Key Exchange via Peripheral Output

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Bluetooth connections relying on short PINs for secure pairing are considered insecure, as they can be vulnerable to brute force attacks, and existing security measures may not be sufficient for organizations handling sensitive data.

Innovation Solution

A method and system for securely exchanging an encryption key between a wireless peripheral device and a mobile device using a key-generating algorithm, where the encryption key is output in a user-friendly format and input by the user, allowing for additional security beyond PIN-based pairing, using techniques like AES or DES for data encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If Bluetooth PIN-based pairing is used for device connection, then device pairing and connection is simplified, but security against brute force attacks deteriorates

Engineering Contradiction:
Improvedevice pairingVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication process into two independent parts: (1) Bluetooth pairing using a short PIN for device connection, and (2) separate encryption key exchange through alternative channels (display/keyboard or print/scan) for data security. This segmentation allows each part to optimize for its specific function while mitigating the security weaknesses of PIN-based pairing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary devices and channels for key exchange: a display device and keyboard act as intermediaries to transfer the encryption key from the peripheral device to the computing device, while a printer can serve as an intermediary by printing the key for manual entry or scanning. These intermediaries prevent direct transmission of the key over the potentially insecure Bluetooth channel.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of time

If short PIN codes are used for Bluetooth pairing, then pairing process is simplified and faster, but vulnerability to brute force attacks increases

Engineering Contradiction:
Improvepairing timeVSAvoidbrute force attack vulnerability
Core Design Contradiction:
Loss of timeVSObject-affected harmful factors

Solution Approach 1:

The authentication process is divided into two independent segments: a short PIN for rapid Bluetooth pairing (optimizing for speed) and a separate, longer encryption key exchanged through more secure alternative channels (optimizing for security). This segmentation allows the system to benefit from both quick pairing and enhanced security without compromise.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The encryption key is generated and exchanged through secure alternative channels (display/keyboard or print/scan) before actual data transmission begins. This preliminary key exchange ensures that even if the Bluetooth connection is quickly established using a short PIN, the security foundation is already in place through the more secure key exchange process.

Inventive Principle:
Principle #10Preliminary action

3Extent of automation

If encryption key is transmitted over Bluetooth connection, then key exchange is automated, but security is compromised due to potential connection vulnerabilities

Engineering Contradiction:
Improvekey exchangeVSAvoidsecurity
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent uses intermediary devices (display, keyboard, printer) to facilitate the encryption key exchange process. These intermediaries act as trusted mediators that transfer the key through physical or alternative channels, avoiding direct transmission over the potentially vulnerable Bluetooth connection while maintaining automation through coordinated device interaction.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the electronic/automated key transmission mechanism (Bluetooth data transfer) with alternative exchange mechanisms such as visual display with keyboard input, or physical printing with manual scanning. These substitutions use different transmission modalities that are less susceptible to the security vulnerabilities inherent in wireless Bluetooth communication.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP1855177B1System and method for exchanging encryption keys between a mobile device and a peripheral output device
Publication Date: 2009.11.11 BLACKBERRY LTD
  • EP1855177B1 patent drawingFigure 1
  • EP1855177B1 patent drawingFigure 2
  • EP1855177B1 patent drawingFigure 3

AI summary

Embodiments of a system and method for providing additional security for data being transmitted across a wireless connection that has been established using a known wireless protocol (e.g. Bluetooth) are described. An encryption key is exchanged between a computing device (e.g. a mobile device) and a wireless output peripheral device (e.g. a printer, a headset). In exemplary embodiments, the encryption key is generated at the peripheral output device (336b). Data associated with the encryption key is output at the peripheral output device (340b), which can be input by the user at the computing device (342b). The encryption key is then recovered at the computing device from the input, thereby completing the key exchange (344b). The encryption key can then be used to encrypt and decrypt data transmitted over the established wireless connection, providing additional security (346b).