Hash-Based Secure Simple Pairing for Preventing Man-in-the-Middle Attacks in Mobile Cloud Computing

chen kai,xu haiming,xu zhen,lin dongdai,liu yong
DOI: https://doi.org/10.3969/j.issn.0372-2112.2016.08.005
2016-01-01
Abstract:Bluetooth lowenergy( BLE) is designed for the devices with computational and power limitations. But it has been confirmed that Secure Simple Pairing( SSP) is vulnerable to the MITMattack. We identify the root causes of the problem : the pairing messages being tampered,and the vulnerability of the JW model. In this paper,we propose two hashbased SSP schemes for the devices in Mobile Cloud Computing( MCC). The proposed schemes enhance the SSP security with the help of MCC. Scheme I is applied into the devices which support the PE or OOB model. It uses the hash function to ensure the authenticity and integrity of the pairing messages. Scheme II is suitable for the devices which only support the JW model. It improves the security of the JW model through using the hash array. At the end of this paper,we examine the performance for the proposed schemes,and perform the security analysis to showthat they can provide the MITMprotection against the adversaries with different levels of power.
What problem does this paper attempt to address?