Embedded OOB Key Generation for Secure BLE Pairing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Bluetooth Low Energy (BLE) pairing methods, such as Just Works and Passkey Entry, lack sufficient security for medical devices, and devices without input/output capabilities cannot use Out-of-Band (OOB) pairing, which is needed for secure wireless connections in medical applications.

Innovation Solution

Implementing an embedded OOB key generation method that uses a predefined 128-bit secret key and a secure hashing algorithm like AES-128 or SHA-256, allowing devices to generate an identical 128-bit OOB key without requiring input/output functionality, enabling secure pairing between medical devices and wireless controllers or smartphones.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If OOB pairing method is used to enhance security, then security level is improved, but devices without input/output capabilities cannot use this method

Engineering Contradiction:
Improvesecurity levelVSAvoidcompatibility with devices without IO capabilities
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces the mechanical input/output system (keyboards, displays) with an electromagnetic field-based solution. The wearable device generates and transmits authentication data through its antenna during the pairing process, eliminating the need for physical IO interfaces while maintaining OOB security levels.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent makes the wearable device serve multiple functions: it acts as both a medical device and a wireless communication device with built-in authentication capabilities. The same antenna and processor used for medical data transmission are also used for generating and transmitting pairing authentication data, eliminating the need for separate IO components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If traditional OOB pairing is implemented, then security is improved, but device complexity and cost increase due to required input/output components

Engineering Contradiction:
ImprovesecurityVSAvoidinput/output component requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the wearable device serve multiple functions: it acts as both a medical device and a wireless communication device with built-in authentication capabilities. The same antenna and processor used for medical data transmission are also used for generating and transmitting pairing authentication data, eliminating the need for separate IO components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent replaces the mechanical input/output system (keyboards, displays) with an electromagnetic field-based solution. The wearable device generates and transmits authentication data through its antenna during the pairing process, eliminating the need for physical IO interfaces while maintaining OOB security levels.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If secure pairing methods are implemented, then security against malicious interference is improved, but ease of operation deteriorates due to complex pairing procedures

Engineering Contradiction:
Improveprotection against malicious interferenceVSAvoidpairing procedure simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The wearable device performs authentication data generation and transmission automatically without requiring user intervention. The device autonomously generates cryptographic keys, creates authentication data, and transmits it through its antenna during the pairing process, making secure pairing as simple as bringing devices close together.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The wearable device pre-generates and stores cryptographic keys and authentication data before the pairing process begins. When pairing is initiated, this pre-prepared authentication data is immediately transmitted through the antenna, eliminating the need for complex real-time authentication procedures during pairing.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11751061B2Systems, apparatuses and methods for secure wireless pairing between two devices using embedded out-of-band (OOB) key generation
Publication Date: 2023.09.05 BECTON DICKINSON & CO
  • US11751061B2 patent drawing
  • US11751061B2 patent drawing
  • US11751061B2 patent drawing

AI summary

Devices, systems and methods are provided to implement key generation for secure pairing between first and second devices using embedded out-of-band (OOB) key generation and without requiring the devices to have input/output (IO) capability to enter authentication information. Bluetooth Smart or Low Energy (BLE) OOB pairing option can be used for pairing medical devices with added security of OOB key generation. The OOB key generation comprises providing first and second devices with the same predefined credential and secure hashing algorithm, and making input of the hashing algorithm of the first and second devices the same. The first device transmits unique data to second device (e.g., via BLE advertising) to share and compute a similar input. The first and second devices use the credential and shared data with the hashing function to generate a key that is the same at each of first and second devices.