cracking the bluetooth pin by yaniv shaked and avishai wool (2005)

26
Cracking the Bluetooth PIN1 Cracking the Bluetooth PIN Yaniv Shaked and Avishai Wool School of Electrical Engineering Systems Supported in part by a grant from Intel Corporation. Abstract: This paper describes the implementation of an attack on the Bluetooth security mechanism. Specifically , we describe a passive attack, in which an attacker can find the PIN used during the pairing process. We then describe the cracking speed we can achieve through three optimizations methods. Our fastest optimization employs an algebraic representation of a central cryptographic primitive (SAFER+) used in Bluetooth. Our results show that a 4-digit PIN can be cracked in less than 0.3 sec on an old Pentium III 450MHz computer, and in 0.06 sec on a Pentium IV 3Ghz HT computer. 1 Introduction 1.1 Background Bluetooth, a technology used for short range fast communication s, has quickly spread worldwide. Bluetooth technology is used in a large set of wired and wireless devices: mobile phones, PDA's, desktop and mobile PC's, printers, digital cameras, and dozens of other devices. Being wireless, Bluetooth is potentially vulnerable to many attacks. It is very difficult to avoid Bluetooth signals from leaking outside the desired boundaries. The possible damage of a successful wireless attack starts with the ability to eavesdrop on the data transferred during the communication of two devices, and ends with the ability to fully impersonate other devices. The Bluetooth technology has a significant security component, which includes key management, authentication and secrecy. However, the security of the whole system relies on the user's choice of a secret Personal Identification Number (PIN) - which is often much too short. Moreover, the Bluetooth designers invented several new cryptographic primitives, which were incorporated into the system. Cryptographers consider fielding new primitives to be risky, because new cryptograp hy is less tested and may contain hidden flaws. Furthermore , Bluetooth is designed for short-range communica tion (nominal range of about 10m). This short-range is perceived as a security feature, since an attacker is supposed to be quite near the attack target - but recent history with IEEE 802.11 has shown that effective range-exten ders can be built very cheaply [ Reh03]. Finally, as Bluetooth gains popularity on PDAs and laptops, the information that lures attackers grows from cell-phone address books to valuable corporate data. 1.2 Related work http://www.eng.tau.ac.il /~yash/shaked-wool-mobisys05/ (1 of 26)10/14/2007 2:37:49 AM

Upload: dhruv-jain

Post on 08-Apr-2018

220 views

Category:

Documents


0 download

TRANSCRIPT

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 1/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 2/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 3/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 4/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 5/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 6/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 7/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 8/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 9/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 10/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 11/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 12/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 13/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 14/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 15/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 16/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 17/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 18/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 19/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 20/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 21/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 22/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 23/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 24/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 25/26

8/7/2019 Cracking the Bluetooth PIN by Yaniv Shaked and Avishai Wool (2005)

http://slidepdf.com/reader/full/cracking-the-bluetooth-pin-by-yaniv-shaked-and-avishai-wool-2005 26/26