IP Library Granted Patent US 11,729,612
Granted Patent B2
US 11,729,612 · App. 16/291,160 · Granted Aug 15, 2023

Secure BLE just works pairing method against man-in-the-middle attack

Inventor: Hui Luo (Marlboro, NJ)
Assignee: Cypress Semiconductor Corporation
H04W12/03H04L9/30H04L9/321H04L9/3236H04L9/3247H04L9/3268H04L63/029H04L63/0442H04W12/041H04W12/0431H04W12/069H04W12/50H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,729,612
App. No.
16/291,160
Granted
Aug 15, 2023
Kind
B2
Abstract

A method includes transmitting one or more segments of a security certificate on a wireless advertising channel of a peripheral device, where at least one of the segments of the security certificate identifies an authentication server, participating in a public key exchange between the peripheral device and a host device by transmitting a signed public key of the peripheral device, where the signed public key is signed in the security certificate, and transmitting one or more encrypted messages from the peripheral device to the host device via a first secure connection established based on the public key.

Claims (87)

1. A method, comprising:

transmitting, on a primary wireless advertising channel of a peripheral device, a reference to a secondary wireless advertising channel of the peripheral device;

broadcasting one or more segments of a security certificate on the secondary wireless advertising channel, wherein at least one of the segments of the security certificate identifies an authentication server;

participating in a public key exchange between the peripheral device and the host device by transmitting a signed public key of the peripheral device, wherein the signed public key is signed in the security certificate; and

transmitting one or more encrypted messages from the peripheral device to the host device via a first secure connection separate from the secondary wireless advertising channel, wherein the first secure connection is established based on the public key.

2. The method of claim 1 , wherein:

the at least one of the segments of the security certificate identifies the authentication server by indicating a network address of the authentication server.

3. The method of claim 2 , wherein:

the one or more segments of the security certificate comprise a device identifier for the peripheral device, a public key of the peripheral device, and a digital signature of the authentication server.

4. The method of claim 1 , further comprising, in response to receiving from the peripheral device a network address of the authentication server:

based on the network address, establishing a second secure connection between the host device and the authentication server; and

in response to authenticating the security certificate based on a public key of the authentication server, complete pairing between the peripheral device and the host device.

5. The method of claim 1 , wherein:

the public key exchange is performed in response to the host device authenticating the security certificate based on a public key of the authentication server;

the public key exchange comprises transmitting a randomly generated key from the host device to the peripheral device; and

transmitting the signed public key of the peripheral device is performed in response to receiving the randomly generated key from the host device.

6. The method of claim 5 , wherein:

in response to receiving the one or more segments of the security certificate at the host device, checking a public key database for a public key of the authentication server based on a network address of the authentication server; and

in response to failing to locate a public key of the authentication server in the public key database,

obtaining the public key of the authentication server by establishing a second secure connection with the authentication server.

7. The method of claim 1 , further comprising obtaining the security certificate from the authentication server by:

in response to authenticating a security certificate of the authentication server, establishing a second secure connection between the host device and the authentication server;

establishing a secure tunnel connection between the peripheral device and the authentication server by relaying, via the host device, messages between the peripheral device and the authentication server; and

receiving the security certificate from the authentication server via the secure tunnel connection.

8. The method of claim 1 , further comprising, at the authentication server:

receiving a firmware identifier from the peripheral device;

in response to locating the received firmware identifier in a firmware database, transmitting a set of randomly generated firmware block addresses to the peripheral device;

for each block identified in the set of randomly generated firmware block addresses, receiving a hash associated with the block from the peripheral device; and

in response to validating each of the received hashes, generating the security certificate for the peripheral device.

9. The method of claim 1 , further comprising ceasing communication with the peripheral device in response to one of:

failing to authenticate the security certificate based on a public key of the authentication server;

failing to authenticate the signed public key based on the security certificate; and

failing to authenticate one or more hash values calculated from firmware blocks of the peripheral device, wherein the hash values are received from the peripheral device.

10. A peripheral device, comprising:

a wireless communication interface; and

a processor coupled with the wireless communication interface, wherein the processor is configured to:

on a primary wireless advertising channel of a peripheral device, transmit via the wireless communication interface a reference to a secondary wireless advertising channel of the peripheral device;

broadcast via the wireless communication interface one or more segments of a security certificate on the second wireless advertising channel, wherein at least one of the one or more segments of the security certificate identifies an authentication server;

participating in a public key exchange between the peripheral device and a host device by transmitting via the wireless communication interface a signed public key of the peripheral device, wherein the signed public key is signed in the security certificate; and

transmit via the wireless communication interface one or more encrypted messages from the peripheral device to the host device via a first secure connection separate from the secondary wireless advertising channel, wherein the first secure connection is established based on the public key.

11. The peripheral device of claim 10 , wherein:

the one or more segments of the security certificate indicate a device identifier for the peripheral device, an public key of the peripheral device, a network address of the authentication server and a digital signature of the authentication server.

12. The peripheral device of claim 10 , wherein:

the wireless communication interface is configured to, during the public key exchange, receive a randomly generated key from the host device; and

the processor is further configured to, in response to receiving the randomly generated key from the host device during the public key exchange, transmit via the wireless communication interface the signed public key of the peripheral device via the wireless communication interface.

13. The peripheral device of claim 10 , wherein the processor is further configured to obtain the security certificate from the authentication server by:

establishing a secure tunnel connection between the peripheral device and the authentication server by relaying, via the host device, messages between the peripheral device and the authentication server; and

receiving the security certificate from the authentication server via the secure tunnel connection.

14. A system, comprising:

a first wireless communication interface in a host device, wherein the first wireless communication interface is configured to:

receive a broadcast transmission containing a reference to a secondary wireless advertising channel of the peripheral device on a primary wireless advertising channel of the peripheral device;

based on the reference, receive one or more segments of a security certificate via the secondary wireless advertising channel, wherein at least one of the one or more segments of the security certificate identifies an authentication server; and

a first processor in the host device, wherein the first processor is coupled with the first wireless communication interface and is configured to:

authenticate the security certificate based on a public key of the authentication server;

participate in a public key exchange between the peripheral device and the host device by receiving, via the first wireless communication interface, a signed public key of the peripheral device, wherein the signed public key is signed in the security certificate; and

transmit one or more encrypted messages from the host device to the peripheral device via a first secure connection separate from the secondary wireless advertising channel, wherein the first secure connection is established based on the signed public key.

15. The system of claim 14 , further comprising:

a network interface in the host device, wherein the first processor is coupled with the network interface and is configured to:

in response to receiving the one or more segments of the security certificate, attempt to locate a public key of the authentication server in a public key database based on a network address of the authentication server;

in response to failing to locate a public key of the authentication server in the public key database, obtain the public key by establishing, via the network interface, a second secure connection with the authentication server; and

complete pairing with the peripheral device over the first wireless communication interface in response to authenticating the security certificate based on a public key of the authentication server.

16. The system of claim 14 , wherein the first processor is configured to:

establish, via the network interface, a second secure connection between the host device and the authentication server; and

cease communication with the peripheral device over the first wireless communication interface in response to failing to authenticate the security certificate based on the public key of the authentication server.

17. The system of claim 14 , wherein the first processor is configured to:

establish the first secure connection by computing a pair of keys for the host device in response to authenticating the signed public key of the peripheral device based on the security certificate, and

cease communication with the peripheral device in response to one of failing to authenticate the security certificate based on the public key of the authentication server, and failing to authenticate the signed public key based on the security certificate.

18. The system of claim 14 , further comprising:

a second wireless communication interface in the peripheral device; and

a second processor in the peripheral device, wherein the second processor is coupled with the second wireless communication interface and is configured to:

establish a secure tunnel connection between the peripheral device and the authentication server by relaying, via the host device, messages between the peripheral device and the authentication server; and

receive the security certificate from the authentication server via the secure tunnel connection.

19. The system of claim 14 , further comprising:

a second wireless communication interface; and

a second processor in the peripheral device, wherein the second processor is coupled with the second wireless communication interface and is configured to:

perform the public key exchange by:

receiving, at the second wireless communication interface, a randomly generated key from the host device, and

in response to receiving the randomly generated key from the host device, transmitting the signed public key via the second wireless communication interface; and

establish the first secure connection with the host device by computing a pair of keys for the peripheral device.

20. The system of claim 14 , further comprising:

a network interface in the authentication server, wherein the authentication server is configured to receive a firmware identifier from the peripheral device;

a firmware database configured to store an expected hash value for each of a plurality of firmware block addresses; and

a second processor in the authentication server, wherein the second processor is configured to:

in response to locating in the firmware database a subset of the plurality of firmware block addresses corresponding to the received firmware identifier, transmit a set of one or more randomly selected firmware block addresses from the subset of firmware block addresses to the peripheral device via the network interface,

receive a set of a hash values from the peripheral device, wherein the set of hash values comprises a hash value for each block identified in the set of randomly selected firmware block addresses,

in response to validating the received set of hash values based on the expected hash values, generate the security certificate for the peripheral device, wherein validating the set of hash values comprises comparing each hash value in the set of hash values with a corresponding expected hash value from the firmware database, and

in response to failing to authenticate the received set of hash values, cease communication with the peripheral device.

Assignments (4)
MERGER Recorded Nov 14, 2025
From: CYPRESS SEMICONDUCTOR CORPORATION
To: INFINEON TECHNOLOGIES AMERICAS CORP.
Reel/Frame 073571/0456 →
RELEASE OF SECURITY INTEREST Recorded Mar 16, 2022
From: MUFG UNION BANK, N.A.
To: CYPRESS SEMICONDUCTOR CORPORATION; SPANSION LLC
Reel/Frame 059410/0438 →
SECURITY INTEREST Recorded Jul 31, 2019
From: CYPRESS SEMICONDUCTOR CORPORATION
To: MUFG UNION BANK, N.A.
Reel/Frame 049917/0093 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2019
From: LUO, HUI
To: CYPRESS SEMICONDUCTOR CORPORATION
Reel/Frame 048522/0307 →
Continuity (2)
Provisional Application 62640398 · Mar 8, 2018
Related Publication 20190281449A1 · Sep 12, 2019
Cited By (1)
US 12,513,230