Bluetooth Access Control via Split Link Key Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Bluetooth pairing procedures are vulnerable to eavesdropping and 'Man in the Middle' attacks, and lack secure access control, allowing unauthorized pairing and access to devices.
Innovation Solution
A method and apparatus for securely controlling access by storing a partial link key and using two secret keys to generate different link key values for establishing secure connections with varying access levels, with a supervisor apparatus providing a second secret key for full access and restricting access when out of range.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If Bluetooth pairing procedure is used to establish secure connection, then devices can be connected wirelessly, but the system is vulnerable to eavesdropping and Man in the Middle attacks
Solution Approach 1:
The link key is segmented into two parts: a first part stored in the wireless device and a second part held by the supervisor apparatus. Both parts are required to generate the complete link key, preventing unauthorized devices from obtaining full access even if they eavesdrop on communications.
Solution Approach 2:
A supervisor apparatus is introduced as an intermediary between the wireless device and the network device. The supervisor controls whether the second part of the link key is provided, enabling access control and preventing unauthorized pairing attacks.
2Adaptability or versatility
If standard Bluetooth pairing is allowed, then devices can pair freely, but unauthorized personnel can access and misuse devices
Solution Approach 1:
The first part of the link key is pre-stored in the wireless device during manufacturing or initial setup. The supervisor apparatus holds the second part and controls its release, ensuring that only authorized personnel can complete the pairing process and gain device access.
Solution Approach 2:
The supervisor apparatus acts as a gatekeeper that controls the provision of the second link key part. It can determine whether to provide the second part based on authorization checks, preventing unauthorized personnel from accessing devices while allowing legitimate users to pair freely.
3Ease of operation
If full access is granted to paired devices, then users can access all device functions, but security risks increase from potential misuse
Solution Approach 1:
Different levels of access are provided to different devices based on their authorization status. Devices that have been authorized by the supervisor receive full access (first level), while unauthorized devices receive no access or limited access (second level), creating localized security control.
Solution Approach 2:
The access level is dynamic and can change based on the supervisor's decisions. The supervisor can provide or revoke the second link key part to dynamically adjust whether a device receives full access or restricted/no access, allowing flexible security management.
Data Source
AI summary
A system for securely controlling access between two wireless (i.e. Bluetooth-enabled) apparatuses, also comprising a supervisor apparatus. The first apparatus is paired to the second by establishing a secure wireless (i.e. Bluetooth) link. The first apparatus includes a stored partial link key and a link key generator: The first apparatus receives a first secret key from the apparatus user, and may also receive a second secret key from the supervisor apparatus. The link key generator generates either a first link key based upon a stored first partial link key, the first secret key and the second secret key or a second link key based upon the stored first partial link key and the first secret key. An access control module in the second apparatus determines the level of access that the first apparatus is granted based upon the link key used to establish the secure connection—full/restricted access.


