Temporary Identity Resolving Key Generation for BLE Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In current wireless communication networks, the exposure of Bluetooth IRKs compromises the security level not only for the IRK itself but also for the RPA generated based on it, thereby jeopardizing the security of BLE communications.
Innovation Solution
An electronic device is configured to generate a temporary IRK and set a validity period for it, then transmit this temporary IRK and its validity period to another device, ensuring secure communication without exposing the permanent IRK.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the permanent IRK is shared through the BLE pairing process, then security authentication is enabled, but the security level is compromised when the IRK is exposed
Solution Approach 1:
The patent segments the IRK functionality by introducing a temporary IRK that is separate from the permanent IRK. The temporary IRK is generated specifically for sharing with third electronic devices, while the permanent IRK remains protected and is only used for authentication with the second electronic device. This segmentation isolates the exposure risk to the temporary IRK, protecting the permanent IRK from compromise.
Solution Approach 2:
The patent introduces a temporary IRK as an intermediary element between the permanent IRK and external devices. Instead of directly sharing the permanent IRK, the system uses the temporary IRK as a mediator that fulfills the identity resolution function while protecting the permanent IRK from exposure. This intermediary mechanism enables secure communication without compromising the core security credential.
2Reliability
If a temporary IRK is generated and shared, then the exposure of permanent IRK is isolated, but the device complexity increases
Solution Approach 1:
The patent applies preliminary action by pre-generating a temporary IRK before any potential exposure scenarios occur. The temporary IRK is created in advance and stored securely, ready to be used when identity resolution with third devices is needed. This preliminary preparation eliminates the need for complex real-time generation and sharing mechanisms, simplifying the overall system while maintaining security.
Data Source
AI summary
According to an embodiment, an electronic device may include a communication circuit and at least one processor operatively connected to the communication circuit, and the at least one processor may be configured to connect, via the communication circuit, a communication with a first external electronic device, receive, from the first external electronic device via the communication circuit, a first packet requesting generation of a temporary identity resolving key (IRK) of the electronic device by a second external electronic device, generate a temporary IRK, set a validity period for the temporary IRK, and transmit, to the first external electronic device via the communication circuit, a second packet including the temporary IRK and the validity period for the temporary IRK.


