Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:
Bluetooth Security.pdf
Скачиваний:
113
Добавлен:
17.08.2013
Размер:
1.57 Mб
Скачать

9

Key Management Extensions

The Bluetooth specification contains the basic tools needed for the creation of security associations and management of security relations. The main key management features are the pairing procedure and update of link keys. The pairing principle with manual assisted key agreement is most suitable for ad hoc creation of security associations. However, in Chapter 7 it was shown that the pairing mechanism is sensitive to off-line and on-line attacks. Hence, there is also a need for alternative, improved pairing solutions. In this chapter, a few of these highly secure pairing procedures are discussed.

Even if the existing pairing principle is nice for ad hoc creation of secure connections, it gives no flexibility in terms of key agreement. It might very well be the case that the user would like to avoid the pairing procedure and instead use preconfigured security associations based on secret or public keys. Then, alternative, widely used standardized key exchange options working on higher layers in the communication stack are the preferred solution. Once a key is agreed upon, the user can choose to use the Bluetooth link layer authentication and encryption or use encryption and/or authentication on higher layers as well. We discuss different key exchange options for higher layers and how they can be combined with the Bluetooth security mechanisms.

Another issue regarding key management in Bluetooth is that devices must always be manually paired before they can communicate securely. In total, one must do as many pairings as there are pairs of devices that are to communicate. Clearly, it can be quite tedious work to perform all these pairings if several devices are involved, which is likely to be the case, for instance, in a domestic domain. This can be avoided by allowing autonomous trust delegation between Bluetooth units. By autonomous trust delegation we mean that security

139