Embedded OOB Key Generation for Secure BLE Pairing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Bluetooth Low Energy (BLE) pairing methods, such as Just Works and Passkey Entry, lack sufficient security for medical devices, and devices without input/output capabilities cannot use Out-of-Band (OOB) pairing, which is needed for secure wireless connections in medical applications.
Innovation Solution
Implementing an embedded OOB key generation method that uses a predefined 128-bit secret key and a secure hashing algorithm like AES-128 or SHA-256, allowing devices to generate an identical 128-bit OOB key without requiring input/output functionality, enabling secure pairing between medical devices and wireless controllers or smartphones.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If OOB pairing method is used to enhance security, then security level is improved, but devices without input/output capabilities cannot use this method
Solution Approach 1:
The patent replaces the mechanical input/output system (keyboards, displays) with an electromagnetic field-based solution. The wearable device generates and transmits authentication data through its antenna during the pairing process, eliminating the need for physical IO interfaces while maintaining OOB security levels.
Solution Approach 2:
The patent makes the wearable device serve multiple functions: it acts as both a medical device and a wireless communication device with built-in authentication capabilities. The same antenna and processor used for medical data transmission are also used for generating and transmitting pairing authentication data, eliminating the need for separate IO components.
2Reliability
If traditional OOB pairing is implemented, then security is improved, but device complexity and cost increase due to required input/output components
Solution Approach 1:
The patent makes the wearable device serve multiple functions: it acts as both a medical device and a wireless communication device with built-in authentication capabilities. The same antenna and processor used for medical data transmission are also used for generating and transmitting pairing authentication data, eliminating the need for separate IO components.
Solution Approach 2:
The patent replaces the mechanical input/output system (keyboards, displays) with an electromagnetic field-based solution. The wearable device generates and transmits authentication data through its antenna during the pairing process, eliminating the need for physical IO interfaces while maintaining OOB security levels.
3Reliability
If secure pairing methods are implemented, then security against malicious interference is improved, but ease of operation deteriorates due to complex pairing procedures
Solution Approach 1:
The wearable device performs authentication data generation and transmission automatically without requiring user intervention. The device autonomously generates cryptographic keys, creates authentication data, and transmits it through its antenna during the pairing process, making secure pairing as simple as bringing devices close together.
Solution Approach 2:
The wearable device pre-generates and stores cryptographic keys and authentication data before the pairing process begins. When pairing is initiated, this pre-prepared authentication data is immediately transmitted through the antenna, eliminating the need for complex real-time authentication procedures during pairing.
Data Source
AI summary
Devices, systems and methods are provided to implement key generation for secure pairing between first and second devices using embedded out-of-band (OOB) key generation and without requiring the devices to have input/output (IO) capability to enter authentication information. Bluetooth Smart or Low Energy (BLE) OOB pairing option can be used for pairing medical devices with added security of OOB key generation. The OOB key generation comprises providing first and second devices with the same predefined credential and secure hashing algorithm, and making input of the hashing algorithm of the first and second devices the same. The first device transmits unique data to second device (e.g., via BLE advertising) to share and compute a similar input. The first and second devices use the credential and shared data with the hashing function to generate a key that is the same at each of first and second devices.


