Key Laboratory of Aerospace Information Security and Trusted Computing,Ministry of Education,School of Cyber Science and Engineering,Wuhan University,Wuhan 430072,Hubei,China
Bluetooth Mesh is a wireless mesh networking technology. To join a Bluetooth Mesh network, new devices must undergo a provisioning process. The security of the provisioning protocol is the foundation of Bluetooth Mesh network security, but currently there is insufficient research on the security of this protocol, and existing models cannot capture certain attacks that exist in the protocol. Therefore, a formal modeling of the Bluetooth Mesh provisioning protocol is performed using Tamarin Prover, which covers all phases and methods of the provisioning protocol. At the same time, a new method for modeling the AES-CMAC primitive under the symbolic model is proposed with the help of Tamarin Prover’s construction and deconstruction rules and the built-in message theory. The method can accurately describe the properties of AES-CMAC functions with arbitrary message lengths, thus enabling a more fine-grained modeling of the authentication phase. The security properties of the model were verified, and the verification results showed that the proposed formal model could capture the previously identified primitive misuse attacks. Furthermore, with the help of this formal model and the verifications results, a countermeasure plan for the primitive misuse attack is proposed and verified through the formal approach.
① 广播:未配网的新设备广播它的设备标识符(DeviceUUID)以及它是否有OOB数据(OOBInfo)。配网器选择某个广播中的新设备与其建立连接,并在需要的情况下提示用户收集OOB数据。
② 邀请:在收到来自配网器的邀请信息之后,新设备发送它的设备能力信息(pkType、staticOOB、outputOOB、inputOOB)至配网器。这些字段分别表明了新设备能否使用OOB技术交换公钥、在认证阶段是否支持对应的认证方法。配网器会根据双方的能力选择恰当的公钥交换方法和认证方法,并将选择的结果发送给新设备。
③ 公钥交换:该阶段有两种不同的公钥交换方法。一是通过公开的蓝牙信道交换各自的公钥PKp和PKd,双方在每次交换时都会生成一对新的公私钥;另一种方法则是配网器通过合适的OOB技术读取新设备的静态公钥PKd,然后将自己新生成的公钥PKp通过蓝牙信道发送给新设备,之后它们计算出共享秘密ECDHSecret。
BLUETOOTHSIG MESH WORKING GROUP. Mesh Profile 1.0.1[EB/OL]. [2019-01-21].
[2]
BLUETOOTHSIG. 2022 Bluetooth Market Update [EB/OL]. [2022-10-01].
[3]
CLAVERIET, ESTEVESJ L. BlueMirror: Reflections on Bluetooth pairing and provisioning protocols[C]//2021 IEEE Security and Privacy Workshops (SPW). New York: IEEE Press, 2021: 339-351. DOI: 10.1109/SPW53761.2021.00054 .
[4]
The AES-CMAC algorithm: RFC 4493 [S/OL].[2019-01-22].
[5]
MEIERS, SCHMIDTB, CREMERSC, et al. The TAMARIN prover for the symbolic analysis of security protocols[C]//International Conference on Computer Aided Verification. Berlin: Springer, 2013: 696-701.10.1007/978-3-642-39799-8_48. DOI: 10.1007/978-3-642-39799-8_48 .
[6]
CHANGG, SHMATIKOVV. Formal analysis of authentication in Bluetooth device pairing[EB/OL]. [2021-04-18].
[7]
BLANCHETB. Modeling and verifying security protocols with the applied pi calculus and ProVerif[J]. Foundations and Trends in Privacy and Security, 2016, 1(1/2): 1-135. DOI: 10.1561/3300000004 .
[8]
ARAIK, KANEKOT. Formal verification of improved numeric comparison protocol for secure simple paring in Bluetooth using ProVerif[EB/OL]. [2020-07-25].
[9]
YEHT C, PENGJ R, WANGS S, et al. Securing Bluetooth communications[EB/OL]. [2021-03-20].
[10]
SETHIM, PELTONENA, AURAT. Misbinding attacks on secure device pairing and bootstrapping[C]//Proceedings of the 2019 ACM Asia Conference on Computer and Communications Security. New York: ACM, 2019: 453-464. DOI: 10.1145/3321705.3329813 .
[11]
CREMERSC, JACKSOND. Prime, order please! revisiting small subgroup and invalid curve attacks on protocols using Diffie-Hellman[C]//2019 IEEE 32nd Computer Security Foundations Symposium (CSF). New York: IEEE Press, 2019: 78-7815. DOI: 10.1109/CSF.2019.00013 .
[12]
BIHAME, NEUMANNL. Breaking the Bluetooth pairing–the fixed coordinate invalid curve attack[C]//International Conference on Selected Areas in Cryptography. Berlin: Springer, 2020: 250-273. DOI: 10.1007/978-3-030-38471-5_11 .
[13]
TSCHIRSCHNITZM V, PEUCKERTL, FRANZENF, et al. Method confusion attack on Bluetooth pairing[C]//2021 IEEE Symposium on Security and Privacy (SP). New York: IEEE Press, 2021: 1332-1347. DOI: 10.1109/SP40001.2021.00013 .
[14]
WUJ L, WUR Y, XUD Y, et al. Formal model-driven discovery of Bluetooth protocol design vulnerabilities[C]//2022 IEEE Symposium on Security and Privacy (SP). New York: IEEE Press, 2022: 2285-2303. DOI: 10.1109/SP46214.2022.9833777 .
JIAF, YANY, YUANK G, et al. Security analysis of 5G authentication and key agreement protocol[J]. Journal of Tsinghua University (Science and Technology), 2021, 61(11): 1260-1266. DOI: 10.16511/j.cnki.qhdxxb.2021.26.001(Ch ).
[17]
CREMERSC, DEHNEL-WILDM. Component-based formal analysis of 5G-AKA: Channel assumptions and session confusion[C]//Proceedings 2019 Network and Distributed System Security Symposium. Reston: Internet Society, 2019:1-15. DOI: 10.14722/ndss.2019.23394 .
[18]
CREMERSC, HORVATM, HOYLANDJ, et al. A comprehensive symbolic analysis of TLS 1.3[C]//Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security. New York: ACM, 2017: 1773-1788. DOI: 10.1145/3133956.3134063 .
[19]
CREMERSC, KIESLB, MEDINGERN. A formal analysis of IEEE 802.11’sWPA2: Countering the kracks caused by cracking the counters[EB/OL]. [2020-06-13].
[20]
DOLEVD, YAOA. On the security of public key protocols[J]. IEEE Transactions on Information Theory, 1983, 29(2): 198-208. DOI: 10.1109/TIT.1983.1056650 .
[21]
BLUETOOTHSIG CORE SPECIFICATION WORKING GROUP. Core Specification 5.3[EB/OL]. [2021-07-13].
[22]
VAUGHANG V, BLAKEE. GNU M4[EB/OL]. [2021-07-12].
[23]
SCHMIDTB, MEIERS, CREMERSC, et al. Automated analysis of Diffie-Hellman protocols and advanced security properties[C]//2012 IEEE 25th Computer Security Foundations Symposium. New York: IEEE Press, 2012: 78-94. DOI: 10.1109/CSF.2012.25 .
[24]
LOWEG. A hierarchy of authentication specifications[C]//Proceedings 10th Computer Security Foundations Workshop. New York: IEEE Press, 2002: 31-43. DOI: 10.1109/CSFW.1997.596782 .
[25]
BLUETOOTHSIG. Bluetooth SIG statement regarding the ‘impersonation attack in Bluetooth mesh provisioning’ vulnerability [EB/OL]. [2021-05-24].