Security and Privacy Threats for Bluetooth Low Energy in IoT and Wearable Devices: A Comprehensive Survey

被引:39
|
作者
Barua, Arup [1 ]
Al Alamin, Md Abdullah [1 ]
Hossain, Md Shohrab [1 ]
Hossain, Ekram [2 ]
机构
[1] Bangladesh Univ Engn & Technol, Dept Comp Sci & Engn, Dhaka 89120, Bangladesh
[2] Univ Manitoba, Dept Elect & Comp Engn, Winnipeg, MB R3T 2N2, Canada
关键词
Security; Bluetooth; Internet of Things; Privacy; Protocols; Wearable computers; Taxonomy; Bluetooth Low Energy (BLE); BLE vulnerabilities; passive eavesdropping; device fingerprinting; privacy attack; IoT; wearable device; security tools; THINGS IOT; INTERNET; BLE; NETWORKS; CHALLENGES; MANAGEMENT; DESIGN; ATTACK;
D O I
10.1109/OJCOMS.2022.3149732
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Bluetooth Low Energy (BLE) has become the de facto communication protocol for the Internet of Things (IoT) and smart wearable devices for its ultra-low energy consumption, ease of development, good enough network coverage, and data transfer speed. Due to the simplified design of this protocol, there have been lots of security and privacy vulnerabilities. As billions of health care, personal fitness wearable, smart lock, industrial automation devices adopt this technology for communication, its vulnerabilities should be dealt with high priority. Some segregated works on BLE were performed focusing on various vulnerabilities, such as the insecure implementation of encryption, device authentication, user privacy, etc. However, there has been no comprehensive survey on the security vulnerabilities of this protocol. In this survey paper, we present a comprehensive taxonomy for the security and privacy issues of BLE. We present possible attack scenarios for different types of vulnerabilities, classify them according to their severity, and list possible mitigation techniques. We also provide case studies regarding how different vulnerabilities can be exploited in real BLE devices.
引用
收藏
页码:251 / 281
页数:31
相关论文
共 50 条
  • [1] A survey on Bluetooth Low Energy security and privacy
    Caesar, Matthias
    Pawelke, Tobias
    Steffan, Jan
    Terhorst, Gabriel
    [J]. COMPUTER NETWORKS, 2022, 205
  • [2] Security/Privacy of Wearable Fitness Tracking IoT Devices
    Zhou, Wei
    Piramuthu, Selwyn
    [J]. PROCEEDINGS OF THE 2014 9TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI 2014), 2014,
  • [3] A Comprehensive Study of Security and Privacy Guidelines, Threats, and Countermeasures: An IoT Perspective
    Abdul-Ghani, Hezam Akram
    Konstantas, Dimitri
    [J]. JOURNAL OF SENSOR AND ACTUATOR NETWORKS, 2019, 8 (02)
  • [4] Survey on IMD and Wearable Devices Security Threats and Protection Methods
    Yu, Jiaping
    Hou, Bingnan
    [J]. CLOUD COMPUTING AND SECURITY, PT VI, 2018, 11068 : 90 - 101
  • [5] A Taxonomy of IoT: Security and Privacy Threats
    Alsamani, Badr
    Lahza, Husam
    [J]. CONFERENCE PROCEEDINGS OF 2018 INTERNATIONAL CONFERENCE ON INFORMATION AND COMPUTER TECHNOLOGIES (ICICT), 2018, : 72 - 77
  • [6] IoT: Internet of Threats? A Survey of Practical Security Vulnerabilities in Real IoT Devices
    Meneghello, Francesca
    Calore, Matteo
    Zucchetto, Daniel
    Polese, Michele
    Zanella, Andrea
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2019, 6 (05): : 8182 - 8201
  • [7] On the Security of Bluetooth Low Energy in Two Consumer Wearable Heart Rate Monitors/Sensing Devices
    Kurt Peker, Yesem
    Bello, Gabriel
    Perez, Alfredo J.
    [J]. SENSORS, 2022, 22 (03)
  • [8] Data Security and Privacy Preserving Techniques for Wearable Devices: A Survey
    Liu, Qiang
    Li, Tong
    Yu, Yang
    Cai, Zhiping
    Zhou, Tongqing
    [J]. Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2018, 55 (01): : 14 - 29
  • [9] Survey of Vehicle IoT Bluetooth Devices
    Oka, Dennis Kengo
    Furue, Takahiro
    Langenhop, Lennart
    Nishimura, Tomohiro
    [J]. 2014 IEEE 7TH INTERNATIONAL CONFERENCE ON SERVICE-ORIENTED COMPUTING AND APPLICATIONS (SOCA), 2014, : 260 - 264
  • [10] Bluetooth Low Energy Devices Security Testing Framework
    Ray, Apala
    Raj, Vipin
    Oriol, Manuel
    Monot, Aurelien
    Obermeier, Sebastian
    [J]. 2018 IEEE 11TH INTERNATIONAL CONFERENCE ON SOFTWARE TESTING, VERIFICATION AND VALIDATION (ICST), 2018, : 384 - 393