Bluetooth Access Control via Split Link Key Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Bluetooth pairing procedures are vulnerable to eavesdropping and 'Man in the Middle' attacks, and lack secure access control, allowing unauthorized pairing and access to devices.

Innovation Solution

A method and apparatus for securely controlling access by storing a partial link key and using two secret keys to generate different link key values for establishing secure connections with varying access levels, with a supervisor apparatus providing a second secret key for full access and restricting access when out of range.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If Bluetooth pairing procedure is used to establish secure connection, then devices can be connected wirelessly, but the system is vulnerable to eavesdropping and Man in the Middle attacks

Engineering Contradiction:
Improvewireless connection establishmentVSAvoidsecurity against eavesdropping and attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The link key is segmented into two parts: a first part stored in the wireless device and a second part held by the supervisor apparatus. Both parts are required to generate the complete link key, preventing unauthorized devices from obtaining full access even if they eavesdrop on communications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A supervisor apparatus is introduced as an intermediary between the wireless device and the network device. The supervisor controls whether the second part of the link key is provided, enabling access control and preventing unauthorized pairing attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If standard Bluetooth pairing is allowed, then devices can pair freely, but unauthorized personnel can access and misuse devices

Engineering Contradiction:
Improvedevice pairing flexibilityVSAvoidunauthorized access and misuse
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The first part of the link key is pre-stored in the wireless device during manufacturing or initial setup. The supervisor apparatus holds the second part and controls its release, ensuring that only authorized personnel can complete the pairing process and gain device access.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The supervisor apparatus acts as a gatekeeper that controls the provision of the second link key part. It can determine whether to provide the second part based on authorization checks, preventing unauthorized personnel from accessing devices while allowing legitimate users to pair freely.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If full access is granted to paired devices, then users can access all device functions, but security risks increase from potential misuse

Engineering Contradiction:
Improvedevice functionality accessVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Different levels of access are provided to different devices based on their authorization status. Devices that have been authorized by the supervisor receive full access (first level), while unauthorized devices receive no access or limited access (second level), creating localized security control.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The access level is dynamic and can change based on the supervisor's decisions. The supervisor can provide or revoke the second link key part to dynamically adjust whether a device receives full access or restricted/no access, allowing flexible security management.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9479514B2Method and system for controlling access to wireless apparatuses
Publication Date: 2016.10.25 CERTIS CISCO
  • US9479514B2 patent drawing
  • US9479514B2 patent drawing
  • US9479514B2 patent drawing

AI summary

A system for securely controlling access between two wireless (i.e. Bluetooth-enabled) apparatuses, also comprising a supervisor apparatus. The first apparatus is paired to the second by establishing a secure wireless (i.e. Bluetooth) link. The first apparatus includes a stored partial link key and a link key generator: The first apparatus receives a first secret key from the apparatus user, and may also receive a second secret key from the supervisor apparatus. The link key generator generates either a first link key based upon a stored first partial link key, the first secret key and the second secret key or a second link key based upon the stored first partial link key and the first secret key. An access control module in the second apparatus determines the level of access that the first apparatus is granted based upon the link key used to establish the secure connection—full/restricted access.