IP Library Granted Patent US 12,284,522
Granted Patent B2
US 12,284,522 · App. 17/506,011 · Granted Apr 22, 2025

Systems and methods for protecting bluetooth low energy devices from address tracking

Inventors: Zhiqiang Lin (Columbus, OH); Yue Zhang (Columbus, OH)
Assignee: Ohio State Innovation Foundation
H04W12/122H04W4/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,284,522
App. No.
17/506,011
Granted
Apr 22, 2025
Kind
B2
Abstract

Bluetooth Address Tracking (BAT) is an allowlist-based side channel attack to track Bluetooth devices, by either passively sniffing the Bluetooth packets, or actively replaying the sniffed ones. Securing addresses of Bluetooth Low Energy (BLE) is described, which uses an interval unpredictable, central and peripheral synchronized random media access control (MAC) address generation scheme to defend against passive BAT attacks, and uses a current timestamp to derive random MAC addresses to defeat active BAT attacks, such that attackers can no longer be able to replay them.

Claims (39)

1. A method of defending against passive Bluetooth Address Tracking (BAT) attacks, the method comprising:

randomizing synchronization between a first device and a second device;

randomizing a time interval between the first device and the second device; and

establishing communication between the first device and the second device in accordance with the time interval,

wherein randomizing synchronization between the first device and the second device is based on a distance between the first device and the second device, and

wherein when the distance between the first device and the second device is less than or equals a predetermined threshold, then the first device and the second device cannot independently start their own randomization.

2. The method of claim 1 , further comprising performing synchronization error correction after randomizing the interval.

3. The method of claim 1 , wherein the first device and the second device are Bluetooth Low Energy (BLE) devices.

4. The method of claim 1 , wherein the first device is a central device and the second device is a peripheral device.

5. The method of claim 1 , wherein when the distance between the first device and the second device is greater than the predetermined threshold, then the first device and the second device can independently start their own randomization.

6. The method of claim 1 , further comprising determining whether the first device and the second device are close to each other or far from each other, and the randomizing synchronization is based on whether the first device and the second device are close to each other or far from each other.

7. A method of defending against active Bluetooth Address Tracking (BAT) attacks, the method comprising:

performing Resolvable Private Address (RPA) generation between a first device and a second device;

performing RPA resolution between the first device and the second device; and

establishing communication between the first device and the second device,

wherein the performing RPA generation comprises generating a one-time only RPA-type media access control (MAC) address using a timestamp.

8. The method of claim 7 , wherein the first device and the second device are Bluetooth Low Energy (BLE) devices.

9. The method of claim 7 , wherein the first device is a central device and the second device is a peripheral device.

10. A method of defending against active Bluetooth Address Tracking (BAT) attacks, the method comprising:

performing Resolvable Private Address (RPA) generation between a first device and a second device;

performing RPA resolution between the first device and the second device; and

establishing communication between the first device and the second device, wherein the performing the RPA resolution comprises obtaining a timestamp and determining whether it is within a range to ensure the MAC address is not replayed by an attacker.

11. The method of claim 10 , wherein the first device and the second device are Bluetooth Low Energy (BLE) devices.

12. The method of claim 10 , wherein the first device is a central device and the second device is a peripheral device.

13. A method of defending against active Bluetooth Address Tracking (BAT) attacks, the method comprising:

performing Resolvable Private Address (RPA) generation between a first device and a second device;

performing RPA resolution between the first device and the second device; and

establishing communication between the first device and the second device, further comprising enabling an allowlist at the first device.

14. The method of claim 13 , wherein the first device and the second device are Bluetooth Low Energy (BLE) devices.

15. The method of claim 13 , wherein the first device is a central device and the second device is a peripheral device.

16. A system for defending against Bluetooth Address Tracking (BAT) attacks, the system comprising:

a passive BAT attack defense module configured to defend against passive BAT attacks to a first device or a second device;

an active BAT attack defense module configured to defend against active BAT attacks to the first device or the second device; and

an allowlist configured to allow communication between the first device and the second device.

17. The system of claim 16 , wherein the first device and the second device are Bluetooth Low Energy (BLE) devices, and wherein the first device is a central device and the second device is a peripheral device.

18. The system of claim 16 , wherein the passive BAT attack defense module is configured to randomize synchronization between the first device and the second device, and randomize an interval between the first device and the second device.

19. The system of claim 18 , wherein randomizing synchronization between the first device and the second device is based on a distance between the first device and the second device, wherein when the distance between the first device and the second device is less than or equals a predetermined threshold, then the first device and the second device cannot independently start their own randomization, and wherein when the distance between the first device and the second device is greater than the predetermined threshold, then the first device and the second device can independently start their own randomization.

20. The system of claim 16 , wherein the active BAT attack defense module is configured to perform Resolvable Private Address (RPA) generation between a first device and a second device, and perform RPA resolution between the first device and the second device.

21. The system of claim 20 , wherein the performing RPA generation comprises generating a one-time only RPA-type media access control (MAC) address using a timestamp, and wherein the performing the RPA resolution comprises obtaining the timestamp and determining whether it is within a range to ensure the MAC address is not replayed by an attacker.

Assignments (2)
CONFIRMATORY LICENSE Recorded May 14, 2025
From: OHIO STATE UNIVERSITY
To: NATIONAL SCIENCE FOUNDATION
Reel/Frame 071275/0339 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 19, 2025
From: LIN, ZHIQIANG; ZHANG, YUE
To: OHIO STATE INNOVATION FOUNDATION
Reel/Frame 070554/0854 →
Continuity (2)
Provisional Application 63093834 · Oct 20, 2020
Related Publication 20220124505A1 · Apr 21, 2022
References Cited (50)
US 9185100B1 · Juels · 2015 [cited by examiner]
US 9749784B1 · Silva · 2017 [cited by examiner]
US 11930435B2 · Fu · 2024 [cited by examiner]
US 20100302011A1 · Cervinka · 2010 [cited by examiner]
US 20150099555A1 · Krishnaswamy · 2015 [cited by examiner]
US 20170302997A1 · Brown · 2017 [cited by examiner]
US 20200322791A1 · Hassan · 2020 [cited by examiner]
US 20220124505A1 · Lin · 2022 [cited by examiner]
US 20220369113A1 · Motos · 2022 [cited by examiner]
B. W. Technology, “The unique bluetooth wristband that makes contact tracing and social distancing alerts,” https://accent-systems.com/covid-19-contact-tracing-solution/, 2020. [cited by applicant]
M. Cominelli, F. Gringoli, P. Patras, M. Lind, and G. Noubir, “Even black cats cannot stay hidden in the dark: Full-band de-anonymization of bluetooth classic devices,” in 2020 IEEE Symposium on Security and Privacy (SP… [cited by applicant]
S. Bluetooth, “Bluetooth core specification version 4.2,” Specification of the Bluetooth System, 2014. [cited by applicant]
Apple Inc., “Accessory Design Guidelines for Apple Devices) ,” https://developer.apple.com/accessories/Accessory-Design-Guidelines.pdf, 2019. [cited by applicant]
S. Bluetooth, “Bluetooth core specification version 4.1,” Specification of the Bluetooth System, 2011. [cited by applicant]
K. Fawaz, K.-H. Kim, and K. G. Shin, “Protecting privacy of ble device users,” in 25th USENIX Security Symposium ( USENIX Security 16), 2016, pp. 1205-1221. [cited by applicant]
R. E. Khoury, “[android m feature spotlight] bluetooth scanning joins wifi to improve location accuracy,” https://www.androidpolice.com/2015/05/29/android-m-feature-spotlight-bluetooth-scanning-joins-wifi-to-improve-loc… [cited by applicant]
S. Bluetooth, “Bluetooth core specification version 5.0,” Specification of the Bluetooth System, 2016. [cited by applicant]
Bluetooth-SIG, “Bluetooth core specification version 4.0,” Specification of the Bluetooth System, 2010. [cited by applicant]
Ronyip, “Mitm attack on “just works” pairing,” 2017 https://www.silabs.com/community/wireless/bluetooth/forum.topic.html/mitm_attac k_on_just-OoG9. [cited by applicant]
D. Johnson, A. Menezes, and S. Vanstone, “The elliptic curve digital signature algorithm (ecdsa),” International journal of information security, vol. 1, No. 1, pp. 36-63, 2001. [cited by applicant]
M. Haase, M. Handy et al., “Bluetrack—imperceptible tracking of bluetooth devices,” in Ubicomp Poster Proceedings, vol. 2, 2004. [cited by applicant]
T. Issoufaly and P. U. Tournoux, “Bleb: Bluetooth low energy botnet for large scale individual tracking,” in 2017 1st International Conference on Next Generation Computing Applications (NextComp). IEEE, 2017, pp. 115-12… [cited by applicant]
Google, “Android 6.0 changes,” https://developer.android.com/about/versions/marshmallow/android-6.0-changes#behavior-hardware-id , 2016. [cited by applicant]
C. Zuo, H. Wen, Z. Lin, and Y. Zhang, “Automatic fingerprinting of vulnerable ble iot devices with static uuids from mobile apps,” in Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security… [cited by applicant]
J. Uher, R. G. Mennecke, and B. S. Farroha, “Denial of sleep attacks in bluetooth low energy wireless sensor networks,” in MILCOM 2016-2016 IEEE Military Communications Conference. IEEE, 2016, pp. 1231-1236. [cited by applicant]
K. Hypponen and K. M. Haataja, ““nino” man-in-themiddle attack on bluetooth secure simple pairing,” in 2007 3rd IEEE/IFIP International Conference in Central Asia on Internet. IEEE, 2007, pp. 1-5. [cited by applicant]
D. Eastlake et al., “Transport layer security (tls) extensions: Extension definitions,” RFC 6066, January, Tech. Rep., 2011. [cited by applicant]
M. Ossmann, “Project ubertooth: Building a better bluetooth adapter,” 2011, shmooCon. [Online]. Available: http://ossmann.blogspot.com/2011/02/project-ubertooth-building-better.html. [cited by applicant]
H. WG, “Hid service specification 1.0,” 2011. [cited by applicant]
Ganesh, “The current psoc ez-serial fw does not support rpa for whitelist,” https://community.cypress.com/thread/51728?start=0&tstart=0, 2020. [cited by applicant]
Cypress, “Cypress official document,” https://cypresssemiconductorco.github.io/btsdk-docs/BT-SDK/20721-B2_Bluetooth/API/, 2020. [cited by applicant]
S. Labs, “Whitelisting (silcon labs official document),” https://docs.silabs.com/bluetooth/3.0/general/adv-and-scanning/whitelisting, 2020. [cited by applicant]
J. K. Becker, D. Li, and D. Starobinski, “Tracking anonymized bluetooth devices,” Proceedings on Privacy Enhancing Technologies, vol. 2019, No. 3, pp. 50-65, 2019. [cited by applicant]
G. Celosia and M. Cunche, “Saving private addresses: an analysis of privacy issues in the bluetooth-lowenergy advertising mechanism,” in Proceedings of the 16th EAI International Conference on Mobile and Ubiquitous Syst… [cited by applicant]
“Discontinued privacy: Personal data leaks in apple bluetooth-low-energy continuity protocols,” Proceedings on Privacy Enhancing Technologies, vol. 2020, No. 1, pp. 26-46, 2020. [cited by applicant]
J. Martin, D. Alpuche, K. Bodeman, L. Brown, E. Fenske, L. Foppe, T. Mayberry, E. Rye, B. Sipes, and S. Teplov, “Handoff all your privacy—a review of apple's bluetooth low energy continuity protocol,” Proceedings on Pri… [cited by applicant]
A. K. Das, P. H. Pathak, C.-N. Chuah, and P. Mohapatra, “Uncovering privacy leakage in ble network traffic of wearable fitness trackers,” in Proceedings of the 17 [cited by applicant]
A. Becker and I. C. Paar, “Bluetooth security & hacks,” Ruhr-Universität Bochum, 2007. [cited by applicant]
Y. Shaked and A. Wool, “Cracking the bluetooth pin,” in Proceedings of the 3rd international conference on Mobile systems, applications, and services. ACM, 2005, pp. 39-50. [cited by applicant]
D. Spill and A. Bittau, “Bluesniff: Eve meets alice and bluetooth.” WOOT, vol. 7, pp. 1-10, 2007. [cited by applicant]
M. Ryan, “Bluetooth: With low energy comes low security,” in Proceedings of the 7th USENIX Conference on Offensive Technologies, ser. WOOT'13. Berkeley, CA, USA: USENIX Association, 2013, pp. 4-4. [Online]. Available: h… [cited by applicant]
T. Rosa, “Bypassing passkey authentication in Bluetooth low energy.” IACR Cryptology ePrint Archive, vol. 2013, p. 309, 2013. [cited by applicant]
D. Kügler, ““man in the middle” attacks on bluetooth,” in International Conference on Financial Cryptography. Springer, 2003, pp. 149-161. [cited by applicant]
K. Haataja and P. Toivanen, “Two practical man-inthe-middle attacks on bluetooth secure simple pairing and countermeasures,” IEEE Transactions on Wireless Communications, vol. 9, No. 1, 2010. [cited by applicant]
D. Antonioli, N. O. Tippenhauer, and K. Rasmussen, “Low entropy key negotiation attacks on bluetooth and bluetooth low energy.” IACR Cryptol. ePrint Arch., vol. 2019, p. 933, 2019. [cited by applicant]
Y. Zhang, J. Weng, R. Dey, Y. Jin, Z. Lin, and X. Fu, “Breaking secure pairing of bluetooth low energy using downgrade attacks,” in 29th {USENIX} Security Symposium ({USENIX} Security 20), 2020, pp. 37-54. [cited by applicant]
D. Antonioli, N. O. Tippenhauer, and K. Rasmussen, “Key negotiation downgrade attacks on bluetooth and bluetooth low energy,” ACM Transactions on Privacy and Security (TOPS), vol. 23, No. 3, pp. 1-28, 2020. [cited by applicant]
D. Antonioli, et al., “Bias: Bluetooth impersonation attacks,” in Proceedings of the IEEE Symposium on Security and Privacy (S&P), 2020. [cited by applicant]
M. Naveed, X. Zhou, S. Demetriou, X.Wang, and C. A. Gunter, “Inside job: Understanding and mitigating the threat of external device mis-binding on android,” in 21st Annual Network and Distributed System Security Symposi… [cited by applicant]
F. Xu, W. Diao, Z. Li, J. Chen, and K. Zhang, “Badbluetooth: Breaking android security mechanisms via malicious bluetooth peripherals,” in Proceedings of the 26th Annual Network and Distributed System Security Symposium… [cited by applicant]