On the Security of Bluetooth Low Energy in Two Consumer Wearable Heart Rate Monitors/Sensing Devices

被引:9
|
作者
Kurt Peker, Yesem [1 ]
Bello, Gabriel [1 ]
Perez, Alfredo J. [1 ]
机构
[1] Columbus State Univ, TSYS Sch Comp Sci, Columbus, GA 31907 USA
基金
美国国家科学基金会;
关键词
Bluetooth Smart; Bluetooth LE; security; privacy; wearables; fitness trackers; heart rate; BLE keyboards; usable privacy; usable security; PRIVACY;
D O I
10.3390/s22030988
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Since its inception in 2013, Bluetooth Low Energy (BLE) has become the standard for short-distance wireless communication in many consumer devices, as well as special-purpose devices. In this study, we analyze the security features available in Bluetooth LE standards and evaluate the features implemented in two BLE wearable devices (a Fitbit heart rate wristband and a Polar heart rate chest wearable) and a BLE keyboard to explore which security features in the BLE standards are implemented in the devices. In this study, we used the ComProbe Bluetooth Protocol Analyzer, along with the ComProbe software to capture the BLE traffic of these three devices. We found that even though the standards provide security mechanisms, because the Bluetooth Special Interest Group does not require that manufacturers fully comply with the standards, some manufacturers fail to implement proper security mechanisms. The circumvention of security in Bluetooth devices could leak private data that could be exploited by rogue actors/hackers, thus creating security, privacy, and, possibly, safety issues for consumers and the public. We propose the design of a Bluetooth Security Facts Label (BSFL) to be included on a Bluetooth/BLE enabled device's commercial packaging and conclude that there should be better mechanisms for informing users about the security and privacy provisions of the devices they acquire and use and to educate the public on protection of their privacy when buying a connected device.
引用
收藏
页数:14
相关论文
共 50 条
  • [1] Evaluation of Wearable Consumer Heart Rate Monitors Based on Photopletysmography
    Parak, Jakub
    Korhonen, Ilkka
    [J]. 2014 36TH ANNUAL INTERNATIONAL CONFERENCE OF THE IEEE ENGINEERING IN MEDICINE AND BIOLOGY SOCIETY (EMBC), 2014, : 3670 - 3673
  • [2] Security and Privacy Threats for Bluetooth Low Energy in IoT and Wearable Devices: A Comprehensive Survey
    Barua, Arup
    Al Alamin, Md Abdullah
    Hossain, Md Shohrab
    Hossain, Ekram
    [J]. IEEE OPEN JOURNAL OF THE COMMUNICATIONS SOCIETY, 2022, 3 : 251 - 281
  • [3] Bluetooth Heart Rate Monitors for Spaceflight
    Buxton, Roxanne E.
    West, Michael R.
    Kalogera, Kent L.
    Hanson, Andrea M.
    [J]. MEDICINE AND SCIENCE IN SPORTS AND EXERCISE, 2016, 48 (05): : 578 - 578
  • [4] Bluetooth Low Energy Devices Security Testing Framework
    Ray, Apala
    Raj, Vipin
    Oriol, Manuel
    Monot, Aurelien
    Obermeier, Sebastian
    [J]. 2018 IEEE 11TH INTERNATIONAL CONFERENCE ON SOFTWARE TESTING, VERIFICATION AND VALIDATION (ICST), 2018, : 384 - 393
  • [5] Developing a New Security Framework for Bluetooth Low Energy Devices
    Zhang, Qiaoyang
    Liang, Zhiyao
    Cai, Zhiping
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2019, 59 (02): : 457 - 471
  • [6] Evaluating the Accuracy of Wearable Heart Rate Monitors
    Ge, Z.
    Prasad, P. W. C.
    Costadopoulos, N.
    Alsadoon, Abeer
    Singh, A. K.
    Elchouemi, A.
    [J]. 2016 2ND INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATION, & AUTOMATION (ICACCA) (FALL), 2016, : 224 - 229
  • [7] Secure protocol buffers for Bluetooth Low-Energy communication with wearable devices
    Francisco, Miguel C.
    Eisa, Samih
    Pardal, Miguel L.
    [J]. 2021 IEEE 20TH INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS (NCA), 2021,
  • [8] On the security of consumer wearable devices in the Internet of Things
    Tahir, Hasan
    Tahir, Ruhma
    McDonald-Maier, Klaus
    [J]. PLOS ONE, 2018, 13 (04):
  • [9] Securing Bluetooth Low Energy Enabled Industrial Monitors
    del Arroyo, Jose Gutierrez
    Bindewald, Jason
    Ramsey, Benjamin
    [J]. PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2017), 2017, : 167 - 176
  • [10] Accuracy of wearable heart rate monitors in cardiac rehabilitation
    Etiwy, Muhammad
    Akhrass, Zade
    Gillinov, Lauren
    Alashi, Alaa
    Wang, Robert
    Blackburn, Gordon
    Gillinov, Stephen M.
    Phelan, Dermot
    Gillinov, A. Marc
    Houghtaling, Penny L.
    Javadikasgari, Hoda
    Desai, Milind Y.
    [J]. CARDIOVASCULAR DIAGNOSIS AND THERAPY, 2019, 9 (03) : 262 - 271