Apparatuses, computer-implemented methods, and computer program products for secure Bluetooth low energy communication
Embodiments of the disclosure provide for improved Bluetooth communication security in vehicles. In the context of a method, the method includes obtaining, from a computing device, at least one feature of a communication specification for a vehicle, wherein: the communication specification defines data sharing protocols between a sensor or computing device aboard the vehicle and a vehicle management system to enable wireless communication by a Bluetooth communication mode without disabling means of the sensor, computing device, or vehicle management system for communication by a second mode. The method includes generating a vulnerability of the communication specification based on the at least one feature; determining a mitigation operation based on the vulnerability; and providing a recommendation comprising the mitigation operation to the at least one computing device to enable modification of the communication specification toward reducing the vulnerability.
1 . A computer-implemented method, comprising:
obtaining, from a first computing device, at least one feature of a communication specification for a vehicle, wherein:
the communication specification defines one or more data sharing protocols between at least one sensor aboard the vehicle and a vehicle management system or at least one computing device aboard the vehicle and the vehicle management system to enable wireless communication by a Bluetooth communication mode without disabling means of the at least one sensor aboard the vehicle, means of the at least one computing device aboard the vehicle, or means of the vehicle management system for communication by a second mode;
generating at least one vulnerability of the communication specification based at least in part on the at least one feature;
generating a respective impact score for a plurality of mitigation operations determined based at least in part on the at least one vulnerability, wherein the impact score indicates a predicted successfulness of the mitigation operation reducing the at least one vulnerability without introducing an additional vulnerability;
generating a ranking of the plurality of mitigation operations based at least in part on the impact scores; and
providing a recommendation comprising a top-ranked subset of mitigation operations from the ranking to the first computing device.
2 . The method of claim 1 , wherein:
the at least one feature comprises chipset configuration.
3 . The method of claim 1 , wherein:
the at least one feature comprises key configuration.
4 . The method of claim 1 , wherein:
the at least one feature comprises encryption configuration.
5 . The method of claim 1 , wherein:
the at least one feature comprises operating system version.
6 . The method of claim 1 , wherein:
the at least one feature comprises at least one supported mode; and
the at least one supported mode comprises at least one of Bluetooth low energy (BLE) or basic rate/enhanced data rate (EDR).
7 . The method of claim 1 , wherein:
the second mode comprises at least one of wired communication, wireless fidelity (WiFi), or satellite communication (SATCOM).
8 . The method of claim 1 , wherein:
the top-ranked subset of mitigation operations from the ranking comprises at least one of adjusting at least one setting of the at least one computing device aboard the vehicle, installing at least one program on the at least one computing device aboard the vehicle, or modifying at least one installed program of the at least one computing device aboard the vehicle.
9 . The method of claim 1 , wherein:
the top-ranked subset of mitigation operations from the ranking comprises at least one of enforcing valid curve points in the Bluetooth communication mode or enforcing encryption in the Bluetooth communication mode.
10 . An apparatus comprising at least one processor and at least one non-transitory memory having computer-coded instructions stored thereon that, in execution with at least one processor, cause the apparatus to:
obtain, from a first computing device, at least one feature of a communication specification for a vehicle, wherein:
the communication specification defines one or more data sharing protocols between at least one sensor aboard the vehicle and a vehicle management system or at least one computing device aboard the vehicle and the vehicle management system to enable wireless communication by a Bluetooth communication mode without disabling means of the at least one sensor aboard the vehicle, means of the at least one computing device aboard the vehicle, or means of the vehicle management system for communication by a second mode;
generate at least one vulnerability of the communication specification based at least in part on the at least one feature;
generate a respective impact score for a plurality of mitigation operations determined based at least in part on the at least one vulnerability, wherein the impact score indicates a predicted successfulness of the mitigation operation reducing the at least one vulnerability without introducing an additional vulnerability;
generate a ranking of the plurality of mitigation operations based at least in part on the impact scores; and
provide a recommendation comprising a top-ranked subset of mitigation operations from the ranking to the first computing device.
11 . The apparatus of claim 10 , wherein:
the at least one vulnerability comprises pairing method confusion.
12 . The apparatus of claim 10 , wherein:
the at least one vulnerability comprises BleedingBit.
13 . The apparatus of claim 10 , wherein:
the at least one vulnerability comprises fixed coordinate invalid curve exploit.
14 . The apparatus of claim 10 , wherein:
the at least one vulnerability comprises SweynTooth.
15 . The apparatus of claim 10 , wherein:
the at least one vulnerability comprises BLURtooth.
16 . The apparatus of claim 10 , wherein:
the at least one vulnerability comprises at least one of bluetooth low energy spoofing attack (BLESA) or InjectaBLE.
17 . The apparatus of claim 10 , wherein:
the at least one vulnerability comprises at least one of key hierarchy enumeration, or key negotiation of Bluetooth (KNOB).
18 . The apparatus of claim 10 , wherein:
the instructions, in execution with the at least one processor, further cause the apparatus to:
modify the communication specification based at least in part on the top-ranked subset of mitigation operations from the ranking.
19 . A computer program product comprising at least one non-transitory computer-readable storage medium having computer program code stored thereon that, in execution with at least one processor, is configured to:
obtain, from a first computing device, at least one feature of a communication specification for a vehicle, wherein:
the communication specification defines one or more data sharing protocols between at least one sensor aboard the vehicle and a vehicle management system or at least one computing device aboard the vehicle and the vehicle management system to enable wireless communication by a Bluetooth communication mode without disabling means of the at least one sensor aboard the vehicle, means of the at least one computing device aboard the vehicle, or means of the vehicle management system for communication by a second mode;
generate at least one vulnerability of the communication specification based at least in part on the at least one feature;
generate a respective impact score for a plurality of mitigation operations determined based at least in part on the at least one vulnerability, wherein the impact score indicates a predicted successfulness of the mitigation operation reducing the at least one vulnerability without introducing an additional vulnerability;
generate a ranking of the plurality of mitigation operations based at least in part on the impact scores; and
provide a recommendation comprising a top-ranked subset of mitigation operations from the ranking to the first computing device.