《RSSI-based Fingerprinting of Bluetooth Low Energy Devices》(基于 RSSI 的蓝牙低功耗设备指纹识别) 原文标题:RSSI-based Fingerprinting of Bluetooth Low Energy Devices
内容概要总结
SECRYPT 2023 会议论文(魁北克大学蒙特利尔分校、里昂大学 INSA-Lyon/Inria CITI 实验室)。提出一种击败 BLE 地址随机化的新型攻击:利用此前未被考虑过的旁侧信息——接收信号强度指示(RSSI)。攻击者被动监听 BLE 广播包,把每个标识符对应的 RSSI 序列做成直方图分布(称为「profile/画像」),再以两份画像拼接为特征向量训练分类器,实现同时的「关联(linking)」与「重识别(re-identification)」。
数据来自 Inria 为 BLE 接触追踪方案采集的真实智能手机 RSSI 数据集(6 个场景、15–30 台设备、每场 15 分钟)。核心结果:静态场景下(设备不动)重识别准确率最高达 0.99(HGT 算法,静态 Q1 场景准确率 0.99,匹配类平均精确率/召回率/F1 分别为 1、0.98、0.99);增加受攻击者控制的接收器数量可进一步提升,多接收器场景准确率达 1.00。RF、kNN 表现较差(单攻击者均低于 79% 和 65%)。参数研究表明 nbin 与 nsplit 均 ≥10 即可达 0.97 以上,每发射器至少 90 条 RSSI(每画像仅 6 条)即可达 94% 准确率。但对移动目标效果显著下降(动态场景准确率仅约 0.47–0.54)。论文提出「静默期」与「随机改变发射功率」两类对策。
翻译内容
原文内容(English)
Guillaume Gagnon¹ᵃ、Sébastien Gambs¹ᵇ、Mathieu Cunche²ᶜ
1 魁北克大学蒙特利尔分校(Université du Québec à Montréal),加拿大蒙特利尔
2 里昂大学 INSA-Lyon、Inria、CITI Lab.,法国里昂
a https://orcid.org/0009-0007-1717-7418 b https://orcid.org/0000-0002-7326-7377 c https://orcid.org/0000-0002-0066-8612
关键词:Bluetooth、RSSI、Fingerprinting(指纹识别)、Privacy(隐私)、Unlinkability(不可关联性)。
摘要
为防止被追踪,蓝牙低功耗协议内置了地址随机化等隐私机制。然而,正如以往研究所指出,地址随机化并非银弹,可通过利用协议泄露的其他类型信息(如计数器或时序)来绕过。在本工作中,我们提出一种新型攻击,利用此前未被考虑过的旁侧信息——接收信号强度指示(Received Signal Strength Indication, RSSI)——来攻破 BLE 中的地址随机化。更精确地说,我们展示了如何利用从收到的 BLE 广播包中提取的 RSSI 测量值,把同一设备发出的轨迹关联起来,或在地址随机化的情况下重识别该设备。所提出的攻击利用 RSSI 的分布来创建设备指纹。在多个场景下对攻击进行的实证评估证明了其有效性。例如在静态场景中(设备保持在同一位置),所提方法产生最高达 99% 的重识别准确率,且该表现还可通过增加攻击者控制的接收器数量而进一步提升。
1 引言
蓝牙低功耗(Bluetooth Low Energy, BLE)是蓝牙协议的一个变体,专为资源受限设备中的应用而设计。特别是,BLE 已被嵌入大量设备,如智能手机与平板电脑、耳机、健康与健身追踪器、标签等。2022 年,出货的 BLE 设备超过 30 亿台¹。然而,BLE 与其他无线网络技术一样,面临安全与隐私方面的担忧,例如保护机制被攻破(Antonioli et al., 2019; Mariotto et al., 2019; Claverie and Lopes-Esteves, 2020),或允许个人信息被暴露(Das et al., 2016; Martin et al., 2019; Celosia and Cunche, 2020a; Heinrich et al., 2021)。特别是,追踪是无线设备所有者面临的一大隐私威胁(Gruteser and Grunwald, 2005; O'Hanlon et al., 2014)。为应对这一威胁,BLE 的第一个版本就内置了反追踪机制(SIG, 2010),例如随机地址——即定期更换的、不可关联的标识符。
更近期,在疫情期间,BLE 被用作接触追踪系统的基础(Ahmed et al., 2020),引发了另一组安全与隐私问题(Vaudenay and Vuagnoux, 2020; Ludant et al., 2021)。许多接触追踪协议的一个关键特性是使用临时标识符,它们随 BLE 地址一同轮换。
作为防追踪保护的地址随机化,一直受到严格审视以寻找潜在弱点。特别是,在若干实现中(既有 BLE 也有 Wi-Fi)发现了诸多问题,它们利用了帧的内容(Vanhoef et al., 2016; Martin et al., 2017; Becker et al., 2019)或其时序(Matte et al., 2016)。这些弱点在若干实现中已被部分修复(Fenske et al., 2021)。
攻击者可获取的另一项信息是 RSSI(接收信号强度指示器),它可用于估计无线链路特性,也可用于定位(Jianyong et al., 2014)与距离估计(Larsson, 2015)。然而,迄今为止尚无研究分析如何利用 RSSI 来攻破地址随机化。
在本文中,我们展示攻击者如何通过利用 BLE 设备周期性发送的广播消息中获得的 RSSI 测量值,来攻破 BLE 地址随机化。更精确地说,我们的贡献如下:
- 我们表明,来自 BLE 流量的 RSSI 测量值可用于对设备进行指纹识别,从而完全绕过诸如地址随机化等其他保护机制。
- 我们提出一种基于机器学习方法的新型攻击,其中以 RSSI 测量值的分布作为特征来训练分类器,该分类器能关联多组 RSSI 轨迹,使我们得以唯一识别设备。
- 我们使用在真实环境下、在多样化移动性场景中采集的 RSSI 测量数据集,对攻击进行评估,展示其效率与广泛的适用性。
- 我们研究并讨论影响攻击成功的因素,从而刻画成功攻击所需的条件。
(出版信息:Gagnon, G., Gambs, S. and Cunche, M. RSSI-Based Fingerprinting of Bluetooth Low Energy Devices. DOI: 10.5220/0012139600003555. In Proceedings of the 20th International Conference on Security and Cryptography (SECRYPT 2023), pages 242-253. ISBN: 978-989-758-666-8; ISSN: 2184-7711. Copyright © 2023 by SCITEPRESS - Science and Technology Publications, Lda. Under CC license (CC BY-NC-ND 4.0)。)
2 背景
2.1 蓝牙低功耗(BLE)
蓝牙是一种工作在 2.4 GHz 频段的电信标准,其目标是让种类繁多的电子设备之间实现标准化的短距离通信。BLE 于 2010 年被纳入蓝牙 4.0 标准,能耗比常规蓝牙低 10 倍,最初提供最高 1 Mbit/s 的速率(SIG, 2010)。该协议于 2016 年随规范第 5 版的采用而扩展,除提供约 2 Mbps 的吞吐量外,理论传输距离翻了两番(SIG, 2016)。
2.2 BLE 广播
更具体地说,BLE 工作在 2400 MHz 至 2483.5 MHz 的频率范围内,该范围被划分为 40 个各宽 2 MHz 的信道。在这些信道中,2402 MHz、2426 MHz 与 2480 MHz 三个频率(分别称为信道 37、38 和 39)被保留,仅用作广播信道(SIG, 2016)。BLE 的广播机制在上述广播信道(37、38 和 39)上运作,BLE 设备在此与周围此前未知的设备广播或接收周期性单向通告、扫描请求、扫描响应与连接指示包。特别是,未连接的设备利用该机制以短至 20 ms 的间隔广播通告,以宣告自身存在(SIG, 2021)。
2.3 地址随机化
BLE 设备周期性广播的广播包中包含一个称为 Advertising Address(AdvA,广播地址)的字段,内含一个蓝牙设备地址(BD ADDR),即发送设备的唯一 48 位标识符。遗憾的是,这带来问题:当设备在广播信道上以无线方式宣告自身存在时,范围内的任何人都能读取这一唯一标识符。这显然导致了严重的隐私问题,因为通过某人的设备追踪其行踪成为可能(Issoufaly and Tournoux, 2017)。
为此,蓝牙 LE 隐私(Bluetooth LE Privacy)在 4.0 版中被引入,以增加攻击者追踪设备的难度(Woolley, 2015; SIG, 2010)。它使制造商能够使用随机的 BD ADDR 地址,这些地址会在其自行选择的间隔后自动更换,建议的最大上限为 15 分钟(SIG, 2021)。若干近期研究已实证表明,在运行 iOS、Android 与 Windows 操作系统的常见设备中,该上限通常被默认采用(Becker et al., 2019; Martin et al., 2019; Celosia and Cunche, 2020a)。
2.4 接收信号强度指示
在 BLE 中,RSSI 是对接收端功率电平的度量,以对数刻度上的分贝毫瓦(dBm)量化。更精确地说,RSSI 是与每个收到的帧相关联的一个值,由蓝牙控制器提供给主机。RSSI 值取决于多个因素,包括发射功率、天线增益以及收发端之间的距离。在移动操作系统中,移动应用可获取 RSSI²,因此攻击者可用专用硬件或简单地通过移动应用轻易采集到它。
RSSI 主要用于估计两台设备之间的链路质量,但也可用于自适应调整传输参数(SIG, 2021, p.600)。此外,由于 RSSI 受距离影响很大,它可用于估计设备间距离,或以亚米级精度对设备进行定位(Pau et al., 2021)。特别是,基于 RSSI 的距离估计曾在新冠疫情期间被用于设计接触追踪应用(Ahmed et al., 2020),并为此设计了先进的距离估计模型(Gorce et al., 2020; Leith and Farrell, 2020)。
² https://developer.android.com/reference/android/bluetooth/BluetoothDevice#EXTRA_RSSI
3 相关工作
物理追踪无线设备用户这一威胁在过去十年已被深入研究。
虽然该问题适用于所有类型的无线技术,研究主要聚焦于 Wi-Fi(802.11)、蓝牙与 BLE。多项贡献凸显了通过采集链路层标识符来追踪用户的可行性(O'Hanlon et al., 2014; Issoufaly and Tournoux, 2017)。为应对该问题,地址随机化被引入(Gruteser and Grunwald, 2005),并逐步被集成到 Wi-Fi 与 BLE 技术中。
此后,地址随机化也受到审视,若干攻击已被发表。更精确地说,第一类攻击旨在恢复设备的稳定标识符,例如真实 MAC 地址(Vanhoef et al., 2016; Martin et al., 2017; Martin et al., 2019)。另一类攻击旨在利用各类信息关联消息序列。例如,此类关联已通过序列号(Vanhoef et al., 2016)与其他有状态元素(Martin et al., 2019; Becker et al., 2019; Celosia and Cunche, 2020a; Celosia and Cunche, 2020b; Ludant et al., 2021)完成。关联也通过指纹识别完成,使用可选字段(Vanhoef et al., 2016)、物理层信息(Vo-Huu et al., 2016; Vanhoef et al., 2016; Hua et al., 2018; Nikoofard et al., 2023)或时序(Matte et al., 2016)。在其他情形中,实现被证明存在缺陷,导致攻击者可利用的旁信道来绕过地址随机化(Zhang and Lin, 2022)。其中一些攻击尤其影响接触追踪协议的实现(Ludant et al., 2021)。除地址随机化之外,无线设备可基于硬件不完美性被指纹识别(Yan et al., 2022; Shen et al., 2021; Givehchian et al., 2022),但此类攻击通常需要专用硬件。
在许多无线技术中,尤其是 BLE 中,RSSI 已被用于定位(Jianyong et al., 2014)与距离估计(Larsson, 2015; Gorce et al., 2020)。在 BLE 语境下,遵循基于机器学习的方法,RSSI 可用于室内定位(Jain et al., 2021)。信道状态信息(Channel State Information, CSI)是一种更详细的信息,可用于移动性追踪(Rocamora et al., 2020),性能优于 RSSI,但它需要特定硬件且在 BLE 中不受支持(Iannizzotto et al., 2022)。在接触追踪中,RSSI 也被用于估计距离(Leith and Farrell, 2020; Gorce et al., 2020),但该估计因环境参数的影响而颇具挑战。
4 系统模型与对抗模型
4.1 系统模型
我们考虑这样一个设定:多台蓝牙设备近距离处于同一物理位置,该位置可以是室内或室外。目标设备通常是握持在用户身体不同位置的移动手机(在耳边、在口袋等)。假设蓝牙功能已启用,但无需对设备做进一步的修改或配置。
此外,这些设备彼此不连接,且此前从未通过蓝牙配对过(即,因此不会因这些设备的当前或既往交互而泄露信息)。假设所有这些设备都能接收和发送通告消息、扫描请求、扫描响应或 BLE 规范所定义的、通常经广播信道传输的任何其他消息。此外,这些设备在接收来自附近设备的消息时,能够提取信号的 RSSI 测量值。
4.2 对抗模型
攻击者的目标是在存在地址随机化方案的情况下侵害 BLE 设备的隐私。假设攻击者完全被动,即它不主动发送任何消息来实现目标,而是被动监听广播信道并记录收到的广播包。在实践中,这意味着攻击者控制的接收器遵循蓝牙规范所述的经典 BLE 扫描流程(SIG, 2021, 4.4.3 Scanning state)。
我们将区分两种攻击场景。
单接收器(Single Receiver)。在第一种场景中,攻击者用单台设备在给定时间段内被动窃听附近设备在蓝牙广播信道上的传输。随后,攻击者仅尝试利用从各邻近设备收到的 RSSI 值,在发送端执行 BD ADDR 更换时重建其身份。
多接收器(Multi-Receiver)。第二种场景是多个接收器相互串通(或等价地,攻击者控制多台设备)。在此语境下,攻击者例如可拥有多台同步基站,使其能在同一环境的不同物理位置被动窃听传输。随后,不同监听站采集的 RSSI 值可被组合起来,以在环境中的某台设备发生 BD ADDR 更换时更好地重识别这些不同的发送端。
在这两种场景中,所收消息的性质或内容对攻击者毫无价值;或者更确切地说,所提出的攻击仅利用 RSSI 值,因而与消息内容无关。在此设定下,如果攻击者仅凭从不同发送端收到的消息所获得的一串 RSSI 值,就能把源自同一发送端的所有消息关联起来,则该攻击被视为成功。这例如会使攻击者能够关联设备身份,以判断人们在某地点停留多久,甚至关联这些人在此期间所从事的其他活动。
(图 1:攻击者监听 BLE 广播包,利用 RSSI 重识别使用地址随机化的设备。示意:地址 AA:AA:AA:AA:AA:AA 对应 RSSI -79、-60;CC:CC:CC:CC:CC:CC 对应 -90、-84;BB:BB:BB:BB:BB:BB 对应 -64;DD:DD:DD:DD:DD:DD 对应 -80;经地址轮换后重识别出 = AA:AA:AA:AA:AA:AA、= CC:CC:CC:CC:CC:CC 等。)
5 重识别攻击
我们提出一种新方法,在蓝牙设备的 BD ADDR 更换后对其重识别。该新型攻击攻破了地址随机化机制,但与先前工作不同之处在于,它仅依赖攻击者在通过 BLE 广播信道接收传输时所计算的 RSSI 值。这些 RSSI 值在实施攻击前被攻击者先被动地累积起来。
更精确地说,所提出的攻击利用 RSSI 值序列提取出设备特有的指纹,称为「画像(profile)」,它代表每台发送端在给定环境中的传输模式。在第一个时段帧内采集的 RSSI 画像被用于训练模型,随后该模型可基于在另一时段采集的画像来重识别设备。
5.1 RSSI 采集
该攻击要求攻击者采集邻近 BLE 设备的测量值,这是通过监听 BLE 广播包并记录相关的 RSSI 与地址来完成的。该采集分两个阶段进行,分别称为训练(training)与重识别(re-identification)步骤。第一阶段对应为训练模型而采集数据,而第二阶段收集的数据用于执行攻击本身。如后文 8.1 节详述,我们攻击的优势在于:1)少量 RSSI 测量值就足以实现高攻击成功率;2)对许多 BLE 设备而言,广播间隔处于毫秒量级(Apple, 2022; Android, 2023)。
因此在实践中,即便仅在几分钟内也能采集到大量测量值,因为大多数设备在该时间段内不会更换其地址。结果,攻击者在每个阶段都会有一组标识符,每个标识符关联一串 RSSI 测量值。
5.2 RSSI 画像的生成
与某个标识符关联的 RSSI 序列被用来创建我们所谓的「画像」,它实际上是以直方图表示的 RSSI 值分布。更精确地说,对每个标识符,攻击者收集相应的 RSSI 序列,并通过把可能取值的范围³ 分解为 nbin 个等宽区间(bin),将其分布计算为直方图。最后,对该分布进行归一化,这实际上使画像被表示为一个维度为 nbin 的向量。
所得画像可作为指纹来识别设备。例如,图 2 展示了从单接收器视角看,两台不同设备所对应的两个画像示例。这些分布之间的差异暗示它们可能可用于对设备进行指纹识别。
³ RSSI 的可能取值范围取决于接收器特性。在我们的案例中,取值介于 -23 dBm 与 -104 dBm 之间。
(图 2:在场景 Q1 中由攻击者 I 计算出的发送端 A 与 B 的两个归一化画像。)
5.3 特征向量的生成
在我们的方法中,我们不试图直接重识别一个画像,而是训练一个分类器来识别两份相继的画像是否对应同一身份(即同一设备),若是,则同时输出该设备的身份作为预测标签。用隐私文献的术语来说,我们的目标是同时进行关联(linking)与重识别(re-identification)攻击。因此,在交给学习算法之前,数据需要被预处理为特征向量的形式:由两份拼接的画像(因而含 2 × nbin 个元素)加上一个标签构成。
特征向量通过交叉组合来自同一设备的画像(即为与该设备身份关联的类生成样本)以及来自不同设备的画像(即为负类生成样本,其中两份画像来自不同设备)来生成。因此,一个特征向量通过拼接两份画像和一个标签构成,如下:
v = {hᵢ, hⱼ, ℓᵢ,ⱼ} (1)
其中 hᵢ 与 hⱼ 是分别对应设备 i 与 j 的两份长度为 nbin 的画像,而标签 ℓᵢ,ⱼ 计算如下:
ℓᵢ,ⱼ = i,若 i == j;×,否则。 (2)
两份画像各代表一台设备,而标签表示这些画像是否来自同一设备,若来自同一设备,标签取相应设备标识符的值。用来自两台不同设备的两份画像创建的特征向量称为「非匹配向量(non-matched vector)」,标记为 ×。相反,用来自同一设备的两份画像创建的特征向量称为「匹配向量(matched vector)」,标记为 i,即该设备的标识符。所得数据集由 n_profile = (n_device × n_split)(n_device × n_split − 1) 构成。
5.4 关联攻击
我们重识别攻击的最后一步是关联攻击(linkage attack)。为此,先用 5.1 节所述 RSSI 采集第一阶段收集的数据训练一个机器学习模型。随后,使用该模型,关联攻击以对应两串 RSSI 的一个特征向量为输入,输出一个标签,该标签可以是某设备的标识符 id(表示由设备 id 生成的匹配画像),或 ×(表示来自不同设备的非匹配画像)。
因此,关联攻击产生两项信息。第一项是特征向量是否匹配/非匹配;第二项信息仅在匹配向量的情况下有意义,即设备的标识符⁴。
⁴ 注意该标识符仅是一个化名,并非设备的稳定标识符。
6 数据集
为评估我们的攻击,我们使用了 Inria 在开发基于 BLE 的接触追踪方案⁵ 的背景下采集的一个 RSSI 测量数据集(Castelluccia et al., 2020)。该数据通过在受控环境中运行场景获得,由自愿参与的军事人员充当参与者。所采集数据严格限于实验中涉及的专用设备。此外,如表 1 所示,该数据仅由一系列 RSSI 测量值构成,不含任何个人数据。
⁵ https://gitlab.inria.fr/stopcovid19
该数据集由 Inria 慷慨共享给我们开展本研究,但并未公开可用。
更详细地说,该数据集包含参与者携带的智能手机⁶ 在各种实验场景中发出与采集的 BLE 广播包测量值,这些场景发生在室内与室外、不同类型空间(自由空间、体育馆、会议室、仓库、圆形剧场和地铁)。场景时长为 15 分钟,涉及最多 30 名参与者/智能手机。在一个场景中,每部智能手机既充当发送端又充当接收端,它在执行 BLE 扫描的同时发送 BLE 广播包。
⁶ iPhone 11 Pro Max、Samsung 10 SM-G973F 和 Samsung 10+ SM-G975F。
其中一些场景是静态的,每位参与者被定位在一个网格上。在这些实验中,每位参与者静止站在一个 0.5m × 0.5m 的单元格上(见图 3)。其他场景是动态的,参与者在单元格中保持静止至少 3 分钟后改变其位置与姿态。每个场景还被分为两个密度类别:Low 与 High,分别为每平方米 0.15 与 0.3 名参与者。
(图 3:实验场景 Q1,模拟一个用户保持静止的会议室。I 与 I & L 被用于单接收器和双接收器的静态场景攻击。)
为便于实验,每秒发出的广播包还包含一个能无歧义标识该广播包来源的标识符。使用一个专用应用,每部智能手机记录从其他智能手机收到的广播包,并记录以下信息:到达时间(秒)、RSSI(dBm)、发送端标识符与手机状态。这些数据随后被集中,并辅以额外信息,如发送端的位置以及参与者之间的真实距离。
所得数据集按场景组织,并结构化为记录(record),其中每条记录对应由设备 A 发出、被设备 B 收到的一个广播包。每个场景附有说明,包含环境性质(即室内或室外)与场景类型(即静态或动态)等一般信息。
一条记录包含时间戳、发送端与接收端的身份、它们的坐标、RSSI 值、锁定状态、应用状态与屏幕状态,以及这两台设备之间的真实距离。表 1 给出了一组记录样例。
(表 1:来自某个场景的记录示例。每条记录对应一个广播包,除其他内容外,包含发送端身份、接收端身份、时间戳与 RSSI 值。样例:RSSI -69 / Timestamp 2020-05-18 17:26:39 / Rcv position C3 / Locked FALSE / Screen TRUE / State active / Receiver A / Transmitter O / Trans position D8 / Distance 2.549;RSSI -79 / 2020-05-18 17:26:39 / C16 / FALSE / TRUE / active / I / O / D8 / 4.031;RSSI -74 / 2020-05-18 17:26:40 / H2 / FALSE / TRUE / active / B / O / D8 / 3.605。)
7 评估方法
7.1 场景选择
我们使用的数据集(参见第 6 节)包含多个不同条件下场景的采集。在这些场景中,我们舍弃了记录数⁷ 或设备数不足、或用于数据采集的实验协议缺乏细节的场景。最终选出的六个场景覆盖多样情形,包括涉及 15 至 30 台设备的静态与动态场景。所选场景的细节见表 2。
⁷ 鉴于我们场景 15 分钟的时长、且发送频率至多为 1 次/秒,7900 条记录是最大值。
在本文余下部分,静态场景 G3 将作为贯穿示例,因为它就单接收器收到的消息数而言是理想情形,每台发送端向攻击者 H 发送了 888 到 908 条消息。注意发送端 A 必须从该数据集中移除,因为它只有 505 条与之关联的 RSSI 测量值。在所有其他场景中,每台设备的传输数要低得多,从表 2 的 Nb. Records 列可见。
(表 2:所选场景的规格。Scenario:G3、Q1、C1、H3、E2、F1;Context:Static、Static、Static、Static、Dynamic、Dynamic;Density:Low、Low、High、Low、Low、Low;Nb. Devices:15、15、30、15、15、15;Nb. Records:11694、8227、13821、3411、12053、800;Duration:15m09s、15m06s、15m14s、15m05s、15m07s、15m08s;Devices Types:SM+, IP11 / SM+, IP11 / SM, SM+, IP11 / (空)/ SM / SM+, IP11;Location:Indoor、Indoor、Indoor、Outdoor、Indoor、Outdoor;Details:Small hangar、Meeting room、Gymnasium、(空)、Parking、Small hangar。)(注:原文表中 E2 场景 Details 列为 Parking,F1 为 Small hangar,表中另有一处 SM+ / Parking 的排版信息。)
7.2 记录预处理
由于该数据集最初并非为评估重识别攻击性能而采集,需对其进行预处理以使其符合我们对抗模型的要求。
首先,我们移除不必要的字段,只保留接收端、发送端的身份与 RSSI 值。时间戳列也可省略,因为每台发送端的记录已按时间顺序排列。为反映对抗模型,我们假设其中一个节点扮演攻击者角色,其余被视为可能的目标。给定一个控制接收器 A 的攻击者,他可用的攻击数据就是以 A 为接收端的记录子集。
该数据集中较慢的广播频率导致某些设备从其邻居收到的 RSSI 少于 100 条。为应对这一点,攻击者的选取方式是选择在该场景中从其邻居收到广播消息最多的那些设备。然而,在真实世界设定中(可每几十毫秒进行一次捕获,SIG, 2021, p.2749),这不太可能成为问题。
7.3 序列与画像的创建
在数据集中,设备在场景持续期间保持同一身份。为进行实验,记录集被切分为 nsplit 个大小大致相等的序列。结果,每台设备关联共 nsplit 个可用于训练与评估的 RSSI 测量序列。RSSI 值的时间顺序在切分中得以保留。对其中每个序列,按 5.2 节所述生成一个画像,这意味着给定攻击者对其每台目标设备共有 nsplit 个画像。
7.4 训练与评估设计
为训练和评估我们的模型,需要一组特征向量。如 5.3 节所述,特征向量通过拼接两份画像和一个标签来创建。因此,从先前生成的画像集合(7.3 节)中,我们可以组合来自同一设备的画像以创建匹配向量,并组合来自不同设备的画像以创建非匹配向量。
注意,由于组合原因,可能的非匹配向量数量远超匹配向量数量。为避免得到一个以非匹配向量占绝大多数的不平衡数据集,我们施加一个交叉随机采样比(crossing random sample ratio, CRSR)。CRSR 参数让我们以如下方式控制匹配与非匹配向量之间的比率:
CRSR = #非匹配向量 / #匹配向量 (3)
为反映对攻击者更具挑战性的环境,我们在训练阶段考虑大于 1 的 CRSR。确实,在真实世界场景中,随着设备数量增长,非匹配向量的数量会比匹配向量增长得更快。然而,在评估阶段会构建一个平衡数据集。
对每个场景,可用数据被划分为两个不同的集合:使用 75% 数据的训练集(阶段 1)与由剩余 25% 构成的评估集(阶段 2)。随后从评估集中抽取一个匹配与非匹配等量表示(CRSR = 1)的平衡测试集。虽然两个评估集都被用于评估我们的模型,但下述各节报告的结果使用的是平衡评估集。这使我们能够把准确率(accuracy)作为一个有意义的度量。
7.5 机器学习设置
遵循上述方法,我们训练并测试了若干通常用于此类问题的机器学习算法。
更精确地说,我们选择了两种基于集成的分类方法,即 HistGradientBoostingClassifier(HGT)与 RandomForestClassifier(RF),以及一种 k 近邻算法 KNeighborsClassifier(kNN),均使用 scikit-learn 库。
数据被打乱,我们使用 k = 5 的分层 kFold 交叉验证。
7.6 性能指标
在重识别攻击的语境下,虽然底层任务对应多类(multi-class)设定,但分析可通过计算以下与分类结果相关的量来简化:
- TP(真阳性):一个匹配向量被正确地标记为匹配且对应正确的设备 id。
- TN(真阴性):一个非匹配向量被正确地标记为非匹配(× 标签)。
- FP(假阳性):一个非匹配向量被错误地标记为匹配。
- FN(假阴性):一个匹配向量被错误地标记为非匹配,或被关联到错误的设备 id。
由这些量可计算出若干指标以量化我们攻击方案的性能。更精确地说,准确率定义如下:
Accuracy = (TP+TN) / (TP+TN+FP+FN) (4)
为补充在平衡评估集上获得的准确率结果,我们还考虑了精确率(precision)、召回率(recall)与 F1 分数(F1-score),它们在多类任务语境下提供关于性能的更详细信息(其中 TP、TN、FP、FN 在该类的语境下计算)。
它们定义如下:
Precision = TP / (TP+FP);Recall = TP / (TP+FN) (5)
F1-score = 2 × (Recall × Precision) / (Recall + Precision) (6)
对这三个指标,我们还报告了它们的宏平均(macro average,即每个标签的非加权均值)以及加权平均(weighted average,即每个标签按支持度加权的均值)。
8 评估结果
8.1 单接收器的静态场景
我们的攻击评估首先在一个静态场景中进行,参数 nsplit 与 nbin 分别设为 15 与 10。
作为示例,图 4 以混淆矩阵的形式呈现了在 CRSR 为 5、算法为 HGT 时,应用于场景 Q1 的攻击结果,该矩阵展示了算法做出的预测标签与真实标签的对照。绝大多数点落在对角线上,反映出预测正确。此外,所有预测错误都位于最后一列,这对应算法未能识别出一个匹配向量、并将其错误分类为非匹配的情形。相反,所有匹配的预测都正确识别了设备的身份。表 3 所示 HGT 的性能很高,准确率为 0.99,而匹配类的精确率、召回率与 F1 分数的平均值分别等于 1、0.98 和 0.99。
(图 4:在静态场景 Q1 中由攻击者 I 进行的攻击结果。使用 HGT 算法,评估使用平衡评估集进行。)
(表 3:在静态场景 Q1 中,以 I 为攻击者、使用 HGT 算法的平衡测试分类报告。Class / Prec. / Recall / F1-score / # vectors:A 1.00 1.00 1.00 / 44;B 1.00 0.96 0.98 / 56;C 1.00 1.00 1.00 / 63;D 1.00 0.98 0.99 / 54;E 1.00 0.95 0.97 / 55;F 1.00 1.00 1.00 / 40;G 1.00 1.00 1.00 / 44;J 1.00 0.98 0.99 / 48;K 1.00 0.98 0.99 / 49;L 1.00 0.98 0.99 / 52;M 1.00 1.00 1.00 / 47;N 1.00 0.96 0.98 / 56;O 1.00 1.00 1.00 / 53;matched 平均 1.00 0.98 0.99 / 661;non-matched × 0.98 1.00 0.99 / 661;Accuracy 0.99 / 1322;Macro avg 1.00 0.99 0.99 / 1322;Weighted avg 0.99 0.99 0.99 / 1322。)
学习算法的影响。我们比较了所考虑的三种学习算法的性能:HGT、RF 与 k-NN。在该评估中,nsplit 与 nbin 也分别设为 10 与 15,而 CRSR 设为 5。相关结果见表 4,表明 HGT 明显优于其他算法,准确率始终高于 98%,而在所有单攻击者攻击中,RF 与 k-NN 的准确率均分别低于 79% 与 65%。此外,数据预处理与模型训练的开销极小,使攻击者易于在现场几乎实时地实施攻击。更具体地说,一台标准笔记本电脑预处理一个含至多 30 台设备的数据集耗时不到 20 秒。此外,在预处理后的数据上训练模型最多耗时 5 秒。
CRSR 的影响。为分析 CRSR 参数(此前设为 5)的影响,我们使用 Q1 与 G3 场景、在 CRSR 从 1 到 12 的取值范围内评估了三种算法的性能。图 5 所示评估结果表明 HGT 的准确率优于其他算法。此外,CRSR 显然也影响准确率;就 HGT 而言,最高准确率在取值介于 4 与 5 之间时获得。总体而言,使用 HGT 且 CRSR 为 4 时,在 Q1 与 G3 两个场景下都产生 99% 的准确率。
(图 5:CRSR 变化对 HGT、RF 与 kNN 性能的影响,使用 G3 与 Q1 静态场景的平衡评估集,nsplit = 15 且 nbin = 10。)
直方图分辨率(Nbin)与序列切分(Nsplit)的影响。我们还研究了攻击参数 nbin 与 nsplit(最初分别固定为 10 与 15)如何影响攻击性能。为此,使用场景 G3 数据与 HGT 算法,对 (nbin, nsplit) ∈ [2..20]² 的所有组合、在 CRSR 设为 5 的情况下评估了攻击的准确率。
该评估结果见图 6。总体而言,准确率随 nbin 与 nsplit 二者增大而提高。例如,对这些参数使用最高值 20 可带来准确率 1。尽管如此,nbin 与 nsplit 二者均等于或高于 10 就足以产生 0.97 或以上的准确率。因此,要获得良好性能,需要 RSSI 分布有 10 个取值的分辨率,并至少有 11 个序列(nsplit ≥ 11)。注意 nsplit 参数也控制序列的长度,在所考虑的场景中,nsplit 介于 10 与 20 之间意味着每个序列含 44 到 91 条 RSSI 测量值。
(图 6:nsplit 与 nbin 变化对 HGT 模型性能的影响,使用 G3 的平衡评估集。)
RSSI 测量数量的影响。此前的评估使用了场景中全部可用的 RSSI 测量值。为评估攻击者可获取的 RSSI 测量数量对攻击性能的影响,我们限制了所使用的记录数。如图 7 所示,HGT 再次展现出其优越性:每台发送端至少有 90 条 RSSI 测量值(在 nsplit = 15 时每画像仅 6 条 RSSI),就足以达到 94% 的准确率。
(图 7:RSSI 数量对算法性能的影响,nsplit = 15 且 nbin = 10,使用静态场景 G3 的平衡评估集。)
8.2 多接收器的静态场景
在上一小节中,假设攻击者从单个接收器采集 RSSI 测量值。本节我们考虑控制多个接收器的攻击者。注意拥有多于一个接收器并不会显著改变攻击框架。更精确地说,画像不再由来自一个接收器的值分布构成,而是仅由一系列分布组成,每个分布对应一个接收器。因此,使用 k 个接收器时,所得画像的大小为 k × nbin。
我们使用场景 Q1 的数据进行了性能评估,其中我们选择设备 I 与 L 作为攻击者控制的接收器。此外,我们把 nbin 与 nsplit 设为 10 与 15,并依赖 HGT 算法。该评估结果见图 8。攻击性能很高,仅出现两个错误,使真实身份的准确率与平均 F1 分数为 1.0。
如表 4 所示,增加一个接收器提高了所有场景中所有算法的准确率。随着接收器进一步增加,性能很可能继续提升。
(表 4:使用 HGT、RF 与 kNN 的静态单/多攻击者场景准确率,模型以 nbin = 10、nsplit = 15、CRSR = 5 训练,并使用平衡评估集评估。Scenario:Q1、G3、C1、H3。静态单攻击者 —— HGT/RF/kNN:Q1 0.99 0.79 0.65;G3 0.99 0.69 0.61;C1 0.98 0.69 0.61;H3 0.98 0.65 0.57。静态多攻击者 —— HGT/RF/kNN:Q1 1.00 0.88 0.78;G3 1.00 0.79 0.67;C1 0.99 0.83 0.76;H3 0.99 0.85 0.75。)
8.3 动态场景
此前的评估使用的是接收器(即攻击者)与发送端(即目标)都不移动的场景。我们现在评估在目标与攻击者都移动的动态场景中攻击的性能。更精确地说,我们依赖场景 E2 的数据,其中参与者在场景期间改变位置最多五次。在该实验中,选择设备 H 作为攻击者,因为它几乎静止。更精确地说,它仅在场景中途更换过一次位置,移动到相邻单元格。训练使用 H 位于其第一个位置时采集的数据,而评估使用在其第二个位置采集的数据。对除 A 之外的所有设备,性能都很低,因为攻击者总是未能重识别目标。A 被正确重识别这一事实可解释为:尽管两者都移动了,但 A 始终与接收器 H 相距 2 米。经进一步调查,我们假设:相对距离的小幅变化,加上 A 离接收器近得多这一事实,导致 RSSI 较高因而更稳定,这对我们 RSSI 画像的指纹质量影响要小得多。
(表 5:动态单攻击者场景的算法准确率汇总,模型以 nbin = 10、nsplit = 15、CRSR = 5 训练,并使用平衡评估集评估。Scenario:E2、F1。动态单攻击者 —— HGT/RF/kNN:E2 0.53 0.54 0.52;F1 0.49 0.49 0.47。)
我们还在 F1 场景上测试了该方法,与 E2 不同,F1 发生在室外。在此设定下,我们观察到相同的结果:没有任何发送端能被重识别。我们在动态场景上评估的详细结果见表 5。总体而言,这些结果表明目标与接收器的相对位置显著影响攻击的性能。
9 结论
在本文中,我们引入一种新型攻击,利用收到的 BLE 广播包的 RSSI 测量值来攻破地址随机化。该攻击使用从真实智能手机获得的 RSSI 测量数据集进行评估。所得结果表明,在涉及至多 30 台静止设备的场景中,可获得 0.99 的重识别准确率,且这些表现可通过增加攻击者控制的接收器数量而进一步提升。然而,对移动目标而言,除非其相对移动受限,攻击的成功率会下降。因此我们设想以下对策。
静默期(Silent Period)。我们的评估结果表明,该攻击对移动目标的效率不如对静态目标。因此,由相对位置变化引起的 RSSI 画像变化,可能是降低重识别风险的最简单却有效的对策之一。因此,为在地址随机化语境下防止基于 RSSI 的重识别攻击,重要的是确保设备在启用其新标识符之前已发生显著移动。这一要求进一步说明在轮换地址前需要一段静默期(Leping Huang et al., 2005)。确实,在静默期内,位置变化的幅度必然比没有静默期时更大,且环境也更可能发生变化(人们绕目标移动、设备更换位置等)。在实践中,这意味着与其在更换随机地址前设定固定时长,更好的策略可能是将该更换与位置移动(例如由加速度计检测到)相协调。
修改发射功率(Modifying the Transmitting Power)。由于攻击依赖 RSSI 测量值,另一种自然的对策是在这些值中加入一些噪声,这可通过随机改变蓝牙控制器的发射功率来实现。在 Android 上,可以在 6 档功率设置⁸ 之间更改广播功率。然而,更改发射功率会对服务质量产生负面影响(丢包),并可能增加能耗。
⁸ https://developer.android.com/reference/android/bluetooth/le/AdvertisingSetParameters
作为未来工作,我们设想将该攻击适配到类似无线技术,如经典蓝牙(Bluetooth Classic)或 Wi-Fi(802.11)。我们还希望改进面向动态场景的框架,例如通过使用多接收器或连续重识别策略,而非我们当前所用的两阶段策略。
致谢
本研究得到 ANR PIVOT 项目 ANR-20-CYAL-0002、PEPR Cybersécurité IPOP 项目以及 Inria MAGPIE 联合团队的支持。Sébastien Gambs 得到加拿大研究主席计划(Canada Research Chair)以及 NSERC 发现基金(Discovery Grant)的支持。
参考文献
(以下参考文献条目为原文照录,保留原语言与格式,未作翻译。)
Ahmed, N., Michelin, R. A., Xue, W., Ruj, S., Malaney, R., Kanhere, S. S., Seneviratne, A., Hu, W., Janicke, H., and Jha, S. K. (2020). A Survey of COVID-19 Contact Tracing Apps. IEEE Access, 8:134577-134601.
Android (2023). Android api reference - advertisingsetparameters.
Antonioli, D., Tippenhauer, N. O., and Rasmussen, K. B. (2019). The KNOB is Broken: Exploiting Low Entropy in the Encryption Key Negotiation Of Bluetooth BR/EDR. In USENIX Security Symposium.
Apple (2022). Accessory design guidelines for apple devices.
Becker, J. K., Li, D., and Starobinski, D. (2019). Tracking Anonymized Bluetooth Devices. Proceedings on Privacy Enhancing Technologies.
Castelluccia, C., Bielova, N., Boutet, A., Cunche, M., Lauradoux, C., Métayer, D. L., and Roca, V. (2020). ROBERT: ROBust and privacy-presERving proximity Tracing. Technical report.
Celosia, G. and Cunche, M. (2020a). Discontinued Privacy: Personal Data Leaks in Apple Bluetooth-Low-Energy Continuity Protocols. Proceedings on Privacy Enhancing Technologies, 2020(1):26-46.
Celosia, G. and Cunche, M. (2020b). Saving private addresses: An analysis of privacy issues in the bluetooth-low-energy advertising mechanism. In Proceedings of the 16th EAI International Conference on Mobile and Ubiquitous Systems: Computing, Networking and Services, MobiQuitous '19, pages 444-453. ACM.
Claverie, T. and Lopes-Esteves, J. (2020). Testing for weak key management in Bluetooth Low Energy implementations. In SSTIC.
Das, A. K., Pathak, P. H., Chuah, C.-N., and Mohapatra, P. (2016). Uncovering Privacy Leakage in BLE Network Traffic of Wearable Fitness Trackers. ACM HotMobile.
Fenske, E., Brown, D., Martin, J., Mayberry, T., Ryan, P., and Rye, E. (2021). Three years later: A study of mac address randomization in mobile devices and when it succeeds. Proceedings on Privacy Enhancing Technologies, 2021(3).
Givehchian, H., Bhaskar, N., Herrera, E. R., Soto, H. R. L., Dameff, C., Bharadia, D., and Schulman, A. (2022). Evaluating Physical-Layer BLE Location Tracking Attacks on Mobile Devices. In 2022 IEEE Symposium on Security and Privacy (SP).
Gorce, J.-M., Egan, M., and Gribonval, R. (2020). An efficient algorithm to estimate Covid-19 infectiousness risk from BLE-RSSI measurements. report, Inria Grenoble Rhône-Alpes.
Gruteser, M. and Grunwald, D. (2005). Enhancing Location Privacy in Wireless LAN Through Disposable Interface Identifiers: A Quantitative Analysis. Mobile Networks and Applications, (3).
Heinrich, A., Stute, M., Kornhuber, T., and Hollick, M. (2021). Who Can Find My Devices? Security and Privacy of Apple's Crowd-Sourced Bluetooth Location Tracking System. Proceedings on Privacy Enhancing Technologies, 2021(3).
Hua, J., Sun, H., Shen, Z., Qian, Z., and Zhong, S. (2018). Accurate and efficient wireless device fingerprinting using channel state information. In IEEE INFOCOM 2018-IEEE Conference on Computer Communications. IEEE.
Iannizzotto, G., Milici, M., Nucita, A., and Lo Bello, L. (2022). A Perspective on Passive Human Sensing with Bluetooth. Sensors, 22(9). Number: 9 Publisher: Multidisciplinary Digital Publishing Institute.
Issoufaly, T. and Tournoux, P. U. (2017). BLEB: Bluetooth Low Energy Botnet for large scale individual tracking. In Next Generation Computing Applications. IEEE.
Jain, C., Sashank, G. V. S., N, V., and Markkandan, S. (2021). Low-cost BLE based Indoor Localization using RSSI Fingerprinting and Machine Learning. In WiSPNET.
Jianyong, Z., Haiyong, L., Zili, C., and Zhaohui, L. (2014). RSSI based Bluetooth low energy indoor positioning. In International Conference on Indoor Positioning and Indoor Navigation (IPIN).
Larsson, J. (2015). Distance Estimation and Positioning Based on Bluetooth Low Energy Technology.
Leith, D. J. and Farrell, S. (2020). Coronavirus contact tracing: evaluating the potential of using bluetooth received signal strength for proximity detection. ACM SIGCOMM Computer Communication Review, 50(4).
Leping Huang, Matsuura, K., Yamane, H., and Sezaki, K. (2005). Enhancing wireless location privacy using silent period. In IEEE Wireless Communications and Networking Conference, 2005, volume 2. IEEE.
Ludant, N., Vo-Huu, T. D., Narain, S., and Noubir, G. (2021). Linking bluetooth le & classic and implications for privacy-preserving bluetooth-based protocols. In 2021 IEEE Symposium on Security and Privacy (SP), pages 1318-1331. IEEE.
Mariotto, A., Heinrich, A., Kreitschmann, D., Noubir, G., and Hollick, M. (2019). A Billion Open Interfaces for Eve and Mallory: MitM, DoS, and Tracking Attacks on iOS and macOS Through Apple Wireless Direct Link. USENIX Security.
Martin, J., Alpuche, D., Bodeman, K., Brown, L., Fenske, E., Foppe, L., Mayberry, T., Rye, E., Sipes, B., and Teplov, S. (2019). Handoff All Your Privacy - A Review of Apple's Bluetooth Low Energy Continuity Protocol. Proceedings on Privacy Enhancing Technologies, 2019(4):34-53.
Martin, J., Mayberry, T., Donahue, C., Foppe, L., Brown, L., Riggins, C., Rye, E. C., and Brown, D. (2017). A Study of MAC Address Randomization in Mobile Devices and When it Fails. Proceedings on Privacy Enhancing Technologies, 2017(4).
Matte, C., Cunche, M., Rousseau, F., and Vanhoef, M. (2016). Defeating MAC Address Randomization Through Timing Attacks. In ACM WiSec.
Nikoofard, A., Givehchian, H., Bhaskar, N., Schulman, A., Bharadia, D., and Mercier, P. P. (2023). Protecting Bluetooth User Privacy Through Obfuscation of Carrier Frequency Offset. IEEE Transactions on Circuits and Systems II: Express Briefs, 70(2).
O'Hanlon, P., Wright, J., and Brown, I. (2014). Privacy at the link layer. In STRINT Workshop: A W3C/IAB workshop on Strengthening the Internet Against Pervasive Monitoring (STRINT).
Pau, G., Arena, F., Gebremariam, Y. E., and You, I. (2021). Bluetooth 5.1: An Analysis of Direction Finding Capability for High-Precision Location Services. Sensors, 21(11).
Rocamora, J. M., Wang-Hei Ho, I., Mak, W., and Lau, A. P. (2020). Survey of CSI fingerprinting-based indoor positioning and mobility tracking systems. IET Signal Processing, 14(7).
Shen, G., Zhang, J., Marshall, A., Peng, L., and Wang, X. (2021). Radio Frequency Fingerprint Identification for LoRa Using Spectrogram and CNN. In IEEE INFOCOM.
SIG, B. S. I. G. (2010). Bluetooth core specification 4.0.
SIG, B. S. I. G. (2016). Bluetooth core specification 5.0.
SIG, B. S. I. G. (2021). Bluetooth core specification 5.3.
Vanhoef, M., Matte, C., Cunche, M., Cardoso, L. S., and Piessens, F. (2016). Why MAC Address Randomization is Not Enough: An Analysis of Wi-Fi Network Discovery Mechanisms. In ACM AsiaCCS.
Vaudenay, S. and Vuagnoux, M. (2020). Little Thumb Attack on SwissCovid.
Vo-Huu, T. D., Vo-Huu, T. D., and Noubir, G. (2016). Fingerprinting Wi-Fi Devices Using Software Defined Radios. In ACM WiSec, WiSec '16.
Woolley, M. (2015). Bluetooth technology protecting your privacy.
Yan, W., Voigt, T., and Rohner, C. (2022). RRF: A Robust Radiometric Fingerprint System that Embraces Wireless Channel Diversity. In ACM WiSec.
Zhang, Y. and Lin, Z. (2022). When Good Becomes Evil: Tracking Bluetooth Low Energy Devices via Allowlist-based Side Channel and Its Countermeasure. In ACM CCS.
RSSI-Based Fingerprinting of Bluetooth Low Energy Devices
Guillaume Gagnon1 a, Se´bastien Gambs1 b and Mathieu Cunche2 c
1Universite´ du Que´bec a` Montre´al, Montre´al, Canada 2University of Lyon, INSA-Lyon, Inria, CITI Lab., Lyon, France
Keywords: Bluetooth, RSSI, Fingerprinting, Privacy, Unlinkability.
Abstract:
To prevent tracking, the Bluetooth Low Energy protocol integrates privacy mechanisms such as address randomization. However, as highlighted by previous researches address randomization is not a silver bullet and can be circumvented by exploiting other types of information disclosed by the protocol such as counters or timing. In this work, we propose a novel attack to break address randomization in BLE exploiting side information that has not been considered before: Received Signal Strength Indication (RSSI). More precisely, we demonstrate how RSSI measurements, extracted from received BLE advertising packets, can be used to link together the traces emitted by the same device or re-identify it despite address randomization. The proposed attack leverages the distribution of RSSI to create a fingerprint of devices. An empirical evaluation of the attack on various scenarios demonstrate its effectiveness. For instance in the static context, in which devices remain at the same position, the proposed approach yields a re-identification accuracy of up to 99%, which can even be boosted by increasing the number of receivers controlled by the adversary.
1 INTRODUCTION
Bluetooth Low Energy (BLE) is a variant of the Bluetooth protocol tailored for application in resourceconstrained devices. In particular, BLE has been embedded in a large number of devices such as smartphones and tablets, headphones, health and fitness trackers, tags, etc. In 2022, more than 3 billion BLEenabled devices were shipped1. However, BLE, like other wireless networking technologies, is subject to security and privacy concerns such as breaking of protection mechanisms (Antonioli et al., 2019; Mariotto et al., 2019; Claverie and Lopes-Esteves, 2020) or allowing the exposure of personal information (Das et al., 2016; Martin et al., 2019; Celosia and Cunche, 2020a; Heinrich et al., 2021). In particular, tracking is a major privacy threat for the owner of wireless devices (Gruteser and Grunwald, 2005; O'Hanlon et al., 2014). To counter this threat, anti-tracking mechanisms were included in the first version of BLE (SIG, 2010) such as random addresses, which are unlinkable identifiers periodically renewed.
More recently during the pandemic, BLE has been
a https://orcid.org/0009-0007-1717-7418 b https://orcid.org/0000-0002-7326-7377 c https://orcid.org/0000-0002-0066-8612 1https://www.bluetooth.com/2022-market-update/
used as the basis for contact tracing systems (Ahmed et al., 2020), raising another set of security and privacy issues (Vaudenay and Vuagnoux, 2020; Ludant et al., 2021). A key feature of many contact tracing protocols was the use of temporary identifiers that were rotated along with the BLE address.
Address randomization, used as a protection against tracking, has been under heavy scrutiny to identify potential weaknesses. In particular, a number of issues were identified in several implementations, in BLE but also Wi-Fi, that were leveraging the content of the frame (Vanhoef et al., 2016; Martin et al., 2017; Becker et al., 2019) or their timing (Matte et al., 2016). Those weaknesses have been partially fixed in a number of implementations (Fenske et al., 2021).
Another information available to an attacker is the RSSI (Received Signal Strength Indicator), which can be used to estimate the characteristics of the radio link but also for localization (Jianyong et al., 2014) and distance estimation (Larsson, 2015). Nonetheless, so far no study has analyzed how RSSI could be leveraged to defeat address randomization.
In this paper, we demonstrate how an adversary could defeat the BLE address randomization by leveraging RSSI measurements obtained from advertising messages periodically sent by BLE devices. More precisely, our contributions are the following:
242
Gagnon, G., Gambs, S. and Cunche, M. RSSI-Based Fingerprinting of Bluetooth Low Energy Devices. DOI: 10.5220/0012139600003555 In Proceedings of the 20th International Conference on Security and Cryptography (SECRYPT 2023), pages 242-253 ISBN: 978-989-758-666-8; ISSN: 2184-7711 Copyright c 2023 by SCITEPRESS Science and Technology Publications, Lda. Under CC license (CC BY-NC-ND 4.0)
RSSI-Based Fingerprinting of Bluetooth Low Energy Devices
· We show that RSSI measurements coming from BLE traffic can be used to fingerprint devices, thus completely circumventing other protection mechanisms such as address randomization.
· We propose a novel attack based on a machine learning approach in which the distribution of RSSI measurements is used as features to train a classifier that can link sets of RSSI traces, allowing us to uniquely identify devices.
· We present an evaluation of the attack using a dataset of RSSI measurements collected in a realistic environment under a diverse set of mobility scenarios, demonstrating its efficiency as well as a wide range of applicability.
· We study and discuss the factors influencing the success of the attack, thus characterizing the requirements for a successful attack.
2 BACKGROUND
2.1 Bluetooth Low Energy (BLE)
Bluetooth is a telecommunication standard operating on the 2.4 GHz frequency band, whose objective is to allow a standardized and short-range communication between a wide variety of electronic devices. Integrated into the Bluetooth 4.0 standard in 2010, BLE consumes 10 times less energy than regular Bluetooth and originally offered a speed of up to 1Mbit/s (SIG, 2010). This protocol was extended in 2016 with the adoption of version 5 of the specification, which quadrupled the theoretical transmission range in addition to offering a throughput of approximately 2 Mbps (SIG, 2016).
2.2 BLE Advertising
More specifically, BLE operates in the frequency range between 2400 MHz and 2483.5 MHz, with this range being divided into 40 channels of 2 MHz wide each. Among these channels, the three frequencies of 2402 MHz, 2426 MHz and 2480 MHz, also known respectively as channel 37, 38 and 39, are reserved to serve only as advertising channels (SIG, 2016). The advertising mechanism of BLE operates on the aforementioned advertising channels (37, 38 and 39), in which BLE devices broadcast or receive periodic unidirectional announcements, scan requests, scan responses and connections indications packets with previously unknown devices in the surroundings. In particular, this mechanism is used by unconnected de-
vices to announce their presence in intervals as short as 20 ms (SIG, 2021) using advertising packets.
2.3 Address Randomization
Advertising packets periodically broadcast by BLE devices include a field called Advertising Address (AdvA) containing a Bluetooth device address (BD ADDR), which is the unique 48-bit identifier of the transmitting device. Unfortunately, this is problematic as anyone within range can read this unique identifier when a device announces its presence overthe-air on advertising channels. This obviously led to significant privacy issues, as it becomes possible to track the movements of an individual through his device (Issoufaly and Tournoux, 2017).
For this reason, Bluetooth LE Privacy was introduced in version 4.0 to increase the difficulty for an adversary to track a device (Woolley, 2015; SIG, 2010). It gives manufacturers the ability to use random BD ADDR addresses that will automatically change after an interval of their choosing, with a recommended maximum limit of 15 minutes (SIG, 2021). Several recent researches have empirically demonstrated that this limit is typically used by default in common devices running iOS, Android and Windows operating systems (Becker et al., 2019; Martin et al., 2019; Celosia and Cunche, 2020a).
2.4 Received Signal Strength Indication
In BLE, the RSSI is a measure of the power level at the receiver, which is quantified in decibel-milliwatts (dBm) on a logarithmic scale. More precisely, the RSSI is a value associated to each received frame and that is made available to the host by the Bluetooth controller. The RSSI value depends on multiple factors including the transmitting power, the gain of the antennas as well as the receiver-transmitter distance. In mobile operating systems, the RSSI can be obtained by mobile applications2 and thus it can be easily collected by an adversary with a dedicated hardware or simply through a mobile application.
While, RSSI is mainly used to estimate the link quality between two devices, it can also be leveraged to adapt the transmission parameters (SIG, 2021, p.600). In addition, as the RSSI is highly influenced by the distance, it can be used to estimate distances between devices or to locate them with submeter precision (Pau et al., 2021). In particular, RSSI-based distance estimation has been used to design contact tracing applications during the COVID
2https://developer.android.com/reference/android/ bluetooth/BluetoothDevice#EXTRA RSSI
243
SECRYPT 2023 - 20th International Conference on Security and Cryptography
pandemic (Ahmed et al., 2020), with advanced distance estimation models having been designed for this (Gorce et al., 2020; Leith and Farrell, 2020).
3 RELATED WORK
The threat of physically tracking users of wireless devices has been investigated thoroughly over the past decade.
While this issue applies to all types of wireless technologies, research has mainly focused on Wi-Fi (802.11), Bluetooth and BLE. A number of contributions have highlighted the feasibility of tracking users by collecting link-layer identifiers (O'Hanlon et al., 2014; Issoufaly and Tournoux, 2017). To counter this issue, address randomization has been introduced (Gruteser and Grunwald, 2005) and progressively integrated in Wi-Fi and BLE technologies.
Following this, address randomization has also been scrutinized, with a number of attacks having been published. More precisely, a first class of attacks aim at recovering a stable identifier of the device such as the real MAC address (Vanhoef et al., 2016; Martin et al., 2017; Martin et al., 2019). Another class of attacks aims at linking sequence of messages using various types of information. For instance, this linking has been performed using sequence numbers (Vanhoef et al., 2016) and other stateful elements (Martin et al., 2019; Becker et al., 2019; Celosia and Cunche, 2020a; Celosia and Cunche, 2020b; Ludant et al., 2021). Linking has also been done through fingerprinting, using optional fields (Vanhoef et al., 2016), physical layer information (Vo-Huu et al., 2016; Vanhoef et al., 2016; Hua et al., 2018; Nikoofard et al., 2023) or timing (Matte et al., 2016). In other situations, the implementation has been shown to be flawed, leading to side-channel that can be leveraged by an adversary to circumvent address randomization (Zhang and Lin, 2022). Some of those attacks especially affect the implementation of contact tracing protocols (Ludant et al., 2021). Beyond address randomization, wireless devices can be fingerprinted based on hardware imperfection (Yan et al., 2022; Shen et al., 2021; Givehchian et al., 2022), but those attacks often require specialized hardware.
In many wireless technologies, and especially in BLE, the RSSI has been leveraged for localization (Jianyong et al., 2014) and distance estimation (Larsson, 2015; Gorce et al., 2020). In the context of BLE, RSSI can be used for indoor localization (Jain et al., 2021) following a machine-learning based approach. Channel State Information (CSI) is a more detailed information that can be used for mobil-
ity tracking (Rocamora et al., 2020) with better performances than RSSI, but it requires specific hardware and is not supported in BLE (Iannizzotto et al., 2022). In contact tracing, RSSI has also been used to estimate distance (Leith and Farrell, 2020; Gorce et al., 2020), but this estimation is challenging because of the impact of environmental parameters.
4 SYSTEM AND ADVERSARIAL MODELS
4.1 System Model
We consider a setting in which multiple Bluetooth devices are in close proximity within the same physical location, which can be indoor or outdoor. The targeted devices will generally be mobile phones held in different positions with respect to the body of the user (at the ear, in the pocket, etc.). The Bluetooth functionality is assumed to be enabled but no further modification or configuration of the device is required.
Furthermore, these devices are not connected to each other and have never been paired previously via Bluetooth (i.e., thus no information is leaked because of current or previous interactions of these devices). All these devices are assumed to be capable of receiving and transmitting announcement messages, scan requests, scan responses or any other messages that normally transit on the broadcast channels as defined in the BLE specification. In addition, the devices are capable of extracting the RSSI measurements of the signal when receiving messages from nearby devices.
4.2 Adversary Models
The objective of the adversary is to compromise the privacy of a BLE device despite the presence of an address randomization scheme. The adversary is assumed to be fully passive, in the sense that it does not actively transmit any messages to achieve his goal. Rather, he passively monitors the advertising channels and record the received advertising packets. In practice, this means that the receivers controlled by the adversary are following a classical BLE scanning procedure as described in the Bluetooth specifications (SIG, 2021, 4.4.3 Scanning state).
We will distinguish between two attack scenarios.
Single Receiver. In this first scenario, the adversary passively eavesdrops using a single device on transmissions on Bluetooth broadcast channels by neighboring devices in its close environment for a given
244
RSSI-Based Fingerprinting of Bluetooth Low Energy Devices
Address
RSSI
AA:AA:AA:AA:AA:AA -79
AA:AA:AA:AA:AA:AA -60
CC:CC:CC:CC:CC:CC -90
CC:CC:CC:CC:CC:CC -84
...
...
BB:BB:BB:BB:BB:BB -64
DD:DD:DD:DD:DD:DD -80
AA:AA:AA:AA:AA:AA
Address rotation
BB:BB:BB:BB:BB:BB CC:CC:CC:CC:CC:CC
DD:DD:DD:DD:DD:DD
Reidentification
= AA:AA:AA:AA:AA:AA
BB:BB:BB:BB:BB:BB
= CC:CC:CC:CC:CC:CC
DD:DD:DD:DD:DD:DD
Advertising packets
Figure 1: Adversary monitoring BLE advertising packets, leverages RSSI to re-identify devices using address randomization.
time period. The adversary then attempts to use only the RSSI values received from each of the neighbouring devices to re-establish the identity of the transmitters when they perform a BD ADDR change.
Multi-Receiver. The second scenario is one in which several receivers collude together (or equivalently the adversary controls several devices). In this context, the adversary could for instance own multiple synchronized stations allowing him to passively eavesdrop on transmissions from different physical positions within the same environment. The RSSI values collected by the different listening stations can then be combined to better re-identify the different transmitters that are in this environment when one of them undergoes a BD ADDR change.
In both of these scenarios, the nature or content of the messages received is of no interest to the adversary, or rather the proposed attack only exploit the RSSI values and thus is agnostic to the content of the message. In this setting, an attack is considered successful if the adversary is able to link together all the messages originating from the same transmitter using only a sequence of RSSI values obtained through messages received from different transmitters. This would, for example, enable the adversary to link device identities in an attempt to determine how long people stay at a given location, or even associate other activities conducted by those people during that time.
5 RE-IDENTIFICATION ATTACK
We propose a new approach to re-identify a Bluetooth device after its BD ADDR has changed. This novel attack defeats the address randomization mechanism but differs from previous work in that it only relies on the RSSI values computed by the adversary when
receiving transmissions over BLE broadcast channels. These RSSI values are first passively accumulated by the attacker before conducting the attack.
More precisely, the proposed attack consists of using sequences of RSSI values to extract a devicespecific fingerprint, called a profile, which represents the transmission patterns of each transmitter in a given environment. The RSSI profiles collected during a first-period frame are used to train a model, which can later be used to re-identify devices based on profiles collected during a different period.
5.1 RSSI Collection
The attack requires the collection of measurements from neighboring BLE devices by the adversary, which is done by monitoring BLE advertising packets and recording the RSSI and address associated. This collection is done in two phases, which will refer as the training and re-identification steps. The first phase corresponds to the collection of data for training the model while the data gathered during the second phase is used to perform the attack itself. As detailed later in Section 8.1, the strengths of our attack is that, 1) a small number of RSSI measurements is enough to achieve a high success rate for the attack, and 2) the advertising interval is in the order of ms for many BLE devices (Apple, 2022; Android, 2023).
Thus in practice, a high number of measurements can be collected even only during a few minutes, as most devices will not change their address during that period. As a result, the adversary will have for each phase a set of identifiers to which is associated a sequence of RSSI measurements.
5.2 Generation of RSSI Profiles
The sequence of RSSI associated to an identifier is used to create what we call a profile, which is effec-
245
SECRYPT 2023 - 20th International Conference on Security and Cryptography
tively a distribution of the RSSI values represented as an histogram. More precisely for each identifier, the adversary gathers the corresponding sequence of RSSI and compute their distribution as histogram by decomposing the range of possible values3 in nbin bins of equal sizes. Finally, this distribution is normalized, which effectively leads to profile being represented as a vector of dimension nbin.
The resulting profile can be used as a fingerprint to identify a device. For instance, Figure 2 shows two examples of profiles corresponding to two distinct devices from the point of view of a single receiver. The difference between those distribution hints that they can possibly be used to fingerprint devices.
Figure 2: Two normalized profiles of transmitters A and B computed by the adversary I in the scenario Q1.
5.3 Generation of Feature Vectors
In our approach, we do not attempt to directly reidentify a profile but rather we will train a classifier at recognizing if two subsequent profiles correspond to the same identity (i.e., device) and, if this is the case, to also output as predicted label the identity of the device. To use the terminology from the privacy literature, our aim is to conduct simultaneously a linking but also re-identification attack. As a consequence before it can be given to a learning algorithm, the data needs to be preprocessed to be represented in the form of a feature vector composed of two concatenated profiles (thus 2 × nbin elements) completed by a label.
Feature vectors are generated by crossing profiles from the same device (i.e., to generate examples for the class associated to the identity of this device) and also distinct devices (i.e., to generate examples for the negative class in which the two profiles are from different devices). A feature vector is thus created by concatenating two profiles and a label as follows:
v = {hi, h j, i, j}
(1)
3The range of possible values for the RSSI depends on the receiver characteristics. In our case, the values were comprised between -23 dBm and -104 dBm.
in which hi and h j are two profiles of length nbin corresponding to devices i and j while the label i, j is computed as follows:
i, j =
i, ×,
if i == j otherwise.
(2)
Each of the two profiles represents a device while the label represent whether the profiles are coming from the same device or not, and in case they are, the label takes the value of the corresponding device identifier. A feature vector created with two profiles coming from two distinct devices is called a non-matched vector and is labeled with ×. In contrast, a feature vector created with two profiles from the same device, is called a matched vector and is labeled with i, the identifier of the device. The resulting dataset is composed of npro f ile = (ndevice × nsplit )(ndevice × nsplit - 1).
5.4 Linkage Attack
The final step of our re-identification attack is the linkage attack. To realize this, a machine learning model is first trained using the data collected in the first phase of RSSI collection as described in Section 5.1. Afterwards using this model, the linkage attack takes as input a feature vector corresponding to two sequences of RSSI and outputs a label that can be the identifier id of a device (indicating matched profiles generated by device id) or × (indicating nonmatched profiles coming from different devices).
The linking attack thus produces two elements of information. The first one is whether the feature vector is matched/non-matched while the second information, only meaningful in the case of matched vectors, is the identifier4 of the device.
6 DATASET
To evaluate our attack, we have used a dataset of RSSI measurements collected by Inria in the context of the development5 of a BLE-based contact tracing solution (Castelluccia et al., 2020). This data was obtained by running scenarios in a controlled environment with the participation of voluntary military personnel to fulfill the role of participants. The collected data was strictly limited to the dedicated devices involved in the experiment. In addition, as seen in Table 1 this data is solely composed of series of RSSI measurements and does not include any personal data.
4Note that this identifier is just a pseudonym, and is not a stable identifier of the device.
5https://gitlab.inria.fr/stopcovid19
246
RSSI-Based Fingerprinting of Bluetooth Low Energy Devices
This dataset was gracefully shared by Inria with us to conduct this study but is not publicly available.
In more details, the dataset features measurements of BLE advertising packets emitted and collected by smartphones6 carried by participants in various experimental scenarios that took place indoors and outdoors and in different types of spaces (free space, gymnasium, meeting room, warehouse, amphitheater and metro). Scenarios have a duration of 15 minutes and involve up to 30 participants/smartphones. During a scenario, each smartphone is both acting as an emitter and a receiver as it sends BLE advertising packets while performing BLE scanning.
Some of these scenarios are static with each participants being positioned on a grid. In those experiments, each participant stand still on a 0.5m × 0.5m cell (see Figure 3). Other scenarios are dynamic and involved participant changing their position and gesture after remaining stationary for at least 3 minutes in a cell. Each scenario was also classified into two density categories: Low and High for respectively 0.15 and 0.3 participants per m2.
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20
A
B
C
GO F M
D
E
K
I
F
G
H
C
H
I
A
D
J
K
E
N
L
M
J
L
N
O
P
Q
R
B
S
0.5 x 0.5 m cell
Figure 3: Experimental scenario Q1 emulating a meeting
room in which users remain static. I and I & L were used
for the static context attack with one and two receivers.
For the sake of the experiments, the advertising packets emitted every second also included an identifier that unambiguously identified the source of that advertising packet. Using a dedicated application, each smartphone recorded the advertising packets received from other smartphones and logged the following information : time of arrival (in sec), RSSI (in dBm), transmitter identifier and phone states. Those data were later centralized and enriched with additional information such as the positions of the transmitters and the real distances between participants.
The resulting dataset is organized by scenarios
6iPhone 11 Pro Max, Samsung 10 SM-G973F and Samsung 10+ SM-G975F.
and structured in records, in which each record corresponds to an advertising packet emitted by a device
A and received by device B. Each scenario is accom-
panied by a description including general information such as the nature of the environment (i.e., indoor or outdoor) and the type of scenario (i.e., static or dynamic).
A record includes a timestamp, the identity of the sender and receiver, their coordinates, the RSSI value, the locked state, application state and screen states as well as the real distance between these two devices. A sample of records is presented in Table 1.
7 EVALUATION METHODOLOGY
7.1 Scenario Selection
The dataset we used (cf. Section 6) includes captures from multiple scenarios in different conditions. Amongst these scenarios, we discarded those with an insufficient number of records7, devices or lacking details in the experimental protocol used for data collection. The resulting six selected scenarios cover a diverse set of situations, including static and dynamic scenarios involving between 15 and 30 devices. The details of the selected scenarios are shown in Table 2.
In the rest of the paper, the static scenario G3 will be used as the running example as it is an ideal case in terms of the number of messages received by a single receiver, with each transmitter having sent between
888 and 908 messages to the adversary H . Note that transmitter A had to be removed from that dataset be-
cause it only has 505 RSSI measurements associated to it. In all other scenarios, the number of transmissions per device is much lower as can be seen from the Nb. Records column of Table 2.
7.2 Records Preprocessing
As the dataset was not originally collected to evaluate the performance of a re-identification attack, it needs to be preprocessed to prepare it to match the requirements of our adversary model.
First, we have removed the unnecessary fields to keep only the identity of the receiver(s), transmitters and the RSSI values. The timestamp column can also be omitted since the records of each transmitter are ordered chronologically. To reflect the adversarial
7900 records is the maximum given the 15 minutes duration of our scenario and the transmission frequency being of 1/sec. at best.
247
SECRYPT 2023 - 20th International Conference on Security and Cryptography
Table 1: Examples of records from one of the scenario. Each record corresponds to an advertising packet and includes among other things, the sender's identity, the receiver's identity, a timestamp and the RSSI value.
RSSI
-69 -79 -74
Timestamp
2020-05-18 17:26:39 2020-05-18 17:26:39 2020-05-18 17:26:40
Rcv position
C3 C16 H2
Locked
FALSE FALSE FALSE
Screen
TRUE TRUE TRUE
State
active active active
Receiver
A I B
Transmitter
O O O
Trans position
D8 D8 D8
Distance
2.549 4.031 3.605
Scenario
G3 Q1 C1 H3 E2 F1
Context
Static Static Static Static Dynamic Dynamic
Density
Low Low High Low Low Low
Table 2: Specifications of the selected scenarios.
Nb. Devices
15 15 30 15 15 15
Nb. Records
11694 8227 13821 3411 12053 800
Duration
15m09s 15m06s 15m14s 15m05s 15m07s 15m08s
Devices Types
SM+, IP11 SM+, IP11 SM, SM+, IP11
SM SM+, IP11
SM+
Location
Indoor Indoor Indoor Outdoor Indoor Outdoor
Details
Small hangar Meeting room Gymnasium
Parking Small hangar
Parking
model, we assume that one of the nodes is playing the role of an attacker while the others are considered as possible targets. Given an adversary controlling the
receiver A, the data available to him for the attack is simply the subset of records having A as a receiver.
The slow advertising frequency in the dataset results in some devices having received less than 100 RSSI from their neighbors. To account for this, the adversaries are chosen by selecting those that have received the most advertising messages from their neighbors in that scenario. However, this is less likely to be an issue in a real-world setting in which a capture could be made every few tens of milliseconds (SIG, 2021, p.2749).
7.3 Sequences and Profiles Creation
In the dataset, devices keep the same identity during the duration of the scenario. To conduct our experiments, the set of records is sliced into nsplit sequences of approximately equal size. As a result, each device is associated to a total of nsplit sequences of RSSI measurements that can be used for training and evaluation. The temporal order of the RSSI values is preserved by the split. For each of those sequences, a profile is generated as described in Section 5.2, which means that a given adversary has for each target device a total of nsplit profiles.
7.4 Training and Evaluation Design
To train and evaluate our model, a set of feature vectors is required. As described in Section 5.3, feature vectors are created by concatenating two profiles and a label. Thus, from the set of profiles previously generated (Section 7.3), we can combine profiles from the same device to create matched vectors and profiles from different devices to create non-matched vectors.
Note that for combinatorial reasons, the number of
possible non-matched vectors far exceed the number of matched vectors. To avoid having an imbalanced dataset with a large majority of non-matched vectors, we enforce a crossing random sample ratio (CRSR). The CRSR parameter allows us to control the ratio between the matched and non-matched vectors in the following manner :
#non-matched vectors
CRSR =
(3)
#matched vectors
To reflect a more challenging environment for the
adversary, we consider a CRSR larger than one for the
training phase. Indeed, in a real-world scenario, the
number of non-matched vectors will increase faster
than the number of matched as the number of devices
grows. However, a balanced dataset is built for the
evaluation phase.
For each scenario, the data available is divided
into two distinct sets : the training set for which
75% of data is used (phase 1) and the evaluation set
composed of the remaining 25% (phase 2). A bal-
anced test set in which matched and non-matched
are equally represented (CRSR = 1) is then extracted
from the evaluation set. Although both evaluation sets
are used for the assessment of our models, the bal-
anced evaluation set is the one used for the results re-
ported in the following sections. This allows us to use
accuracy as a meaningful metric.
7.5 Machine Learning Setting
Following the previously described methodology, we have trained and tested several machine learning algorithms typically used for this type of problem.
More precisely, we have selected two ensemblebased classification methods, namely HistGradientBoostingClassifier (HGT) and RandomForestClassifier (RF), as well as a k-nearest algorithm, KNeighborsClassifier (kNN), for which we used the library scikit-learn.
248
RSSI-Based Fingerprinting of Bluetooth Low Energy Devices
The data was shuffled and we used a crossvalidation with a stratified kFold in which k = 5.
7.6 Performance Metrics
In the context of the re-identification attack, while the underlying task corresponds to a multi-class setting, the analysis can be simplified by computing the following quantities related to the outcome of the classification:
· TP (true positive): a matched vector is correctly labeled as matched along the correct device id.
· TN (true negative): a non-matched vector correctly is labeled as non-matched(× label).
· FP (false positive): a non-matched vector is incorrectly labeled as matched.
· FN (false negative): a matched vector is incorrectly labeled as non-matched or associated to an incorrect device id.
From these quantities, several metrics can be
computed to quantify the performance of our attack
scheme. More precisely, the accuracy is defined as
follows:
TP+TN
Accuracy =
(4)
TP+TN +FP+FN
To complement the accuracy results that are ob-
tained with the balanced evaluation set, we have
also considered the precision, recall and F1-score,
that provide more detailed information on the perfor-
mances in the context of multi-class task (with the TP,
TN, FP, and FN being computed in the context of the
class).
They are defined as follows :
TP
TP
Precision =
Recall =
(5)
TP+FP
TP+FN
F1-score = 2 × (Recall × Precision) (6) Recall + Precision
For these three metrics, we have also reported their macro average, which is their unweigthed mean per label, as well as their weighted average, which is the support weighted mean per label.
8 EVALUATION RESULTS
8.1 Static Scenarios with a Single Receiver
The evaluation of our attack was first conducted using a static scenario with parameters nsplit and nbin set respectively to 15 and 10.
As an illustration, Figure 4 presents the result of the attack applied to scenario Q1 with a CRSR of 5 and the algorithm HGT in the form of a confusion matrix displaying the predicted labels made by the algorithm against the true labels. A vast majority of the points falls on the diagonal reflecting a correct prediction. In addition, all the prediction errors are located in the last column, which corresponds to the situation in which the algorithm failed to recognize a matched vector and has classified it incorrectly as non-matched. In contrast, all matched predictions have correctly recognized the identity of the device. The performance of HGT presented in Table 3 is high with an accuracy of 0.99 and precision, recall and F1score having an average value for the matched classes respectively equal to 1, 0.98 and 0.99.
Figure 4: Result of the attack conducted by adversary I in
static scenario Q1. The HGT algorithm was used and the
assessment was performed using a balanced evaluation set.
Table 3: Balanced test classification report on the static sce-
nario Q1 using I as the adversary with the HGT algorithm.
Class
Prec. Recall F1-score # vectors
A 1.00 1.00 1.00
44
B 1.00 0.96 0.98
56
C 1.00 1.00 1.00
63
D 1.00 0.98 0.99
54
E 1.00 0.95 0.97
55
F 1.00 1.00 1.00
40
matched
G 1.00 1.00
1.00
44
J 1.00 0.98 0.99
48
K 1.00 0.98 0.99
49
L 1.00 0.98 0.99
52
M 1.00 1.00 1.00
47
N 1.00 0.96 0.98
56
O 1.00 1.00 1.00
53
avg 1.00 0.98 0.99
661
non-matched × 0.98 1.00
0.99
661
Accuracy
0.99
1322
Macro avg
1.00 0.99 0.99
1322
Weighted avg
0.99 0.99 0.99
1322
249
SECRYPT 2023 - 20th International Conference on Security and Cryptography
Impact of the Learning Algorithm. We have compared the performances of three considered learning algorithms: HGT, RF and k-NN. In this evaluation, the nsplit and nbin were also set to 10 and 15 while CRSR was set to 5. The associated results are presented in Table 4 and demonstrate that HGT clearly outperforms other algorithms with an accuracy always above 98% while RF and k-NN are both below 79% and 65% accuracy for all single adversary attack. Moreover, the costs of data preprocessing and model training are minimal, making it easy for an adversary to conduct the attack almost in real-time on the field. More specifically, it takes less than 20 seconds for a standard laptop to preprocess a dataset containing up to 30 devices. In addition, it takes a maximum of 5 seconds to train the model on the preprocessed data.
Impact of CRSR. With the objective of analyzing the impact of the CRSR parameter (previously set to 5), we evaluated the performances of the three algorithms using a range of values for the CRSR from 1 to 12 using scenarios Q1 and G3. The results of the evaluation presented in Figure 5 shows that HGT has superior accuracy than the other algorithms. In addition, the CRSR has also clearly an impact on the accuracy, with focusing on HGT, the highest accuracy being obtained for values between 4 and 5. Overall, using HGT with a CRSR of 4 yield to an accuracy of 99% for both scenarios Q1 and G3.
G3 data and the HGT algorithm, the accuracy of the attack is evaluated for all the combination of ( nbin, nsplit ) [2..20]2 with a CRSR set to 5.
The results of this evaluation are presented in Figure 6. Overall, the accuracy increases with both nbin and nsplit . For instance, using the highest value 20 for those parameters leads to an accuracy of 1. Nevertheless, having both nbin and nsplit equal or above 10 is enough to yield an accuracy of 0.97 or above. Thus
to obtain good performances, it is necessary to have a
resolution of 10 values for the RSSI distribution and to have at least 11 sequences (nsplit 11). Note that the nsplit parameter also controls the length of the sequences and on the considered scenario, having nsplit between 10 and 20 implies that each sequence con-
tains between 44 and 91 RSSI measurements.
Figure 5: Effects of CRSR variations on performances for HGT, RF and kNN, using the balanced evaluation set of the G3 and Q1 static scenarios with nsplit = 15 and nbin = 10.
Impact of Histogram Resolution (Nbin) and Sequences Slicing (Nsplit ). We have also studied how the parameters of the attack, nbin and nsplit (initially fixed respectively to 10 and 15), impact the performance of the attack. To realize this, using the scenario
Figure 6: Effects of nsplit and nbin variations on HGT model performance with the balanced evaluation set of G3.
Impact of the Quantity of RSSI Measurements. Previous evaluations were using all the RSSI measurements available in a scenario. To evaluate the impact on attack performance of the amount of RSSI measurements available to the adversary, we restricted the number of records used. As can be seen in Figure 7, HGT shows again its superiority as having a minimum of 90 RSSI measurements per transmitter, resulting in only 6 RSSI by profile when using nsplit = 15, is sufficient to achieve a 94% accuracy.
8.2 Static Scenario with Multiple Receivers
In the previous subsection, the adversary was assumed to be collecting RSSI measurements from a single receiver. In this section, we consider an adversary that controls multiple receivers. Note that having more than one receiver does not significantly
250
RSSI-Based Fingerprinting of Bluetooth Low Energy Devices
Figure 7: Effects of the number of RSSI on the performance
of algorithms with nsplit = 15 and nbin = 10 on the balanced evaluation set of the static scenario G3.
change the attack framework. More precisely, instead of having a profile composed of a distribution of values coming from one receiver, the profile is just a sequence of distributions that each correspond to one receiver. Therefore, using k receivers, the resulting size of the profile is k × nbin.
We have performed a performance evaluation using the data from scenario Q1, in which we selected
devices I and L as being the receivers controlled by
the adversary. Furthermore, we set nbin and nsplit to 10 and 15 and we have relied on the HGT algorithm. The results of this evaluation are presented in Figure 8. The performance of the attack is high, with only two errors being made, resulting in an accuracy and average F1-score for true identities of 1.0.
Adding a receiver increased the accuracy of all algorithms in all scenarios as shown in Table 4.
Performance is likely to improve further with additional receivers.
Table 4: Static single and multi-adversary scenario accuracy
using HGT, RF and kNN trained with nbin = 10, nsplit = 15, CRSR = 5 and assessed using a balanced evaluation set.
Scenario Q1 G3 C1 H3
Static Single-adversary HGT RF kNN 0.99 0.79 0.65 0.99 0.69 0.61 0.98 0.69 0.61 0.98 0.65 0.57
Static Multi-adversary HGT RF kNN 1.00 0.88 0.78 1.00 0.79 0.67 0.99 0.83 0.76 0.99 0.85 0.75
8.3 Dynamic Scenario
Previous evaluations were using scenarios in which both the receiver (i.e., the adversary) and the transmitters (i.e., the targets) were not moving. We now assess the performance of our attack in a dynamic scenario in which both the targets and the adversary are
Figure 8: Result of the multi-adversary attack conducted
from the perspective of receivers I and L in the static sce-
nario Q1. The HGT algorithm was used and the assessment is performed using a balanced evaluation set.
moving. More precisely, we rely on the data from the
scenario E2, in which participants were changing po-
sition up to five times during the scenario. In this ex-
periment, device H was selected as the adversary as it
was almost static. More precisely, it only changed its
position once in the middle of the scenario to move to
a neighboring cell. Training was done using data col-
lected by H when it was located at its first position,
while the evaluation was performed with the data col-
lected at its second location. For all devices except A,
the performance is low as the adversary always failed
to re-identify the targets. The fact that A was cor-
rectly re-identified can be explained by, although they
both moved, A was always 2 meters away from the receiver H . After further investigation, we hypothesize
that the combination of a small variation in relative
distance and the fact that A is much closer to the re-
ceiver, result in high and therefore more stable RSSI,
which has a much smaller impact on the quality of the
fingerprint of our RSSI profiles.
Table 5: Summary of dynamic single adversary scenarios
accuracy of algorithms trained with nbin = 10, nsplit = 15, CRSR = 5, and assessed using a balanced evaluation set.
Scenario E2 F1
Dynamic Single-adversary
HGT RF
kNN
0.53 0.54
0.52
0.49 0.49
0.47
We also tested this approach on the F1 scenario, which in contrast to E2 took place outdoor. In this setting, we observed the same results, as none of the transmitters could be re-identified. The detailed results of our evaluations on the dynamic scenarios are presented in Table 5. Overall, those results show that
251
SECRYPT 2023 - 20th International Conference on Security and Cryptography
the relative position of the targets and receiver impact significantly the performance of the attack.
9 CONCLUSION
In this paper, we have introduced a novel attack to defeat address randomization using RSSI measurements of received BLE advertising packets. This attack has been evaluated using a dataset of RSSI measurements obtained from real smartphones. The results obtained showed that, in scenarios involving up to 30 motionless devices, a re-identification accuracy of 0.99 can be obtained, and that those performances can be further improved by increasing the number of receivers controlled by the adversary. However, the success of the attack decreased against mobile targets unless their relative movement is limited. We thus envision the following countermeasures.
Silent Period. The results of our evaluation suggest that our attack is not as efficient against mobile targets as against static ones. Thus, the variations of the RSSI profile induced by a change of relative position might be one of the simplest yet effective countermeasure to reduce the risk of re-identification. Thus to prevent RSSI-based re-identification attacks in the context of address randomization, it is important to ensure that a device has moved significantly before using its new identifier. This requirement further motivates the need for a silent period (Leping Huang et al., 2005) before rotating the address. Indeed, during the silent period, the amplitude of the position change will necessarily be larger than without it, and the environment is also more likely to change (people moving around the target, device changing position, . . . ). In practice, this means than rather than having a fixed duration before changing the random address, a better strategy could be to coordinate this change with a location shift (e.g., detected by the accelerometer).
Modifying the Transmitting Power. Since the attack relies on RSSI measurements, another natural countermeasure is to add some noise in those values, which could be achieved by randomly changing the transmission power of the Bluetooth controller. On Android, it is possible to change the advertising power between 6 power settings8. However, changing the transmission power will have a negative impact on the quality of service with lost packets and also potentially increasing the energy consumption.
8https://developer.android.com/reference/android/ bluetooth/le/AdvertisingSetParameters
As future works, we envision adapting this attack against similar wireless technologies such as Bluetooth Classic or Wi-Fi (802.11). We would also like to improve the framework for dynamic scenarios, for instance by using multiple receivers or a continuous reidentification strategy rather than the two-phase one that we have currently used.
ACKNOWLEDGEMENTS
This research has been supported by the ANR PIVOT project ANR-20-CYAL-0002, PEPR Cyberse´curite´ IPOP project and Inria MAGPIE associated team. Se´bastien Gambs is supported by the Canada Research Chair program as well as a Discovery Grant from NSERC.
REFERENCES
Ahmed, N., Michelin, R. A., Xue, W., Ruj, S., Malaney, R., Kanhere, S. S., Seneviratne, A., Hu, W., Janicke, H., and Jha, S. K. (2020). A Survey of COVID-19 Contact Tracing Apps. IEEE Access, 8:134577134601.
Android (2023). Android api reference - advertisingsetparameters.
Antonioli, D., Tippenhauer, N. O., and Rasmussen, K. B. (2019). The KNOB is Broken: Exploiting Low Entropy in the Encryption Key Negotiation Of Bluetooth BR/EDR. In USENIX Security Symposium.
Apple (2022). Accessory design guidelines for apple devices.
Becker, J. K., Li, D., and Starobinski, D. (2019). Tracking Anonymized Bluetooth Devices. Proceedings on Privacy Enhancing Technologies.
Castelluccia, C., Bielova, N., Boutet, A., Cunche, M., Lauradoux, C., Me´tayer, D. L., and Roca, V. (2020). ROBERT: ROBust and privacy-presERving proximity Tracing. Technical report.
Celosia, G. and Cunche, M. (2020a). Discontinued Privacy: Personal Data Leaks in Apple Bluetooth-LowEnergy Continuity Protocols. Proceedings on Privacy Enhancing Technologies, 2020(1):2646.
Celosia, G. and Cunche, M. (2020b). Saving private addresses: An analysis of privacy issues in the bluetoothlow-energy advertising mechanism. In Proceedings of the 16th EAI International Conference on Mobile and Ubiquitous Systems: Computing, Networking and Services, MobiQuitous '19, pages 444453. ACM.
Claverie, T. and Lopes-Esteves, J. (2020). Testing for weak key management in Bluetooth Low Energy implementations. In SSTIC.
Das, A. K., Pathak, P. H., Chuah, C.-N., and Mohapatra, P. (2016). Uncovering Privacy Leakage in BLE Network Traffic ofWearable Fitness Trackers. ACM HotMobile.
252
RSSI-Based Fingerprinting of Bluetooth Low Energy Devices
Fenske, E., Brown, D., Martin, J., Mayberry, T., Ryan, P., and Rye, E. (2021). Three years later: A study of mac address randomization in mobile devices and when it succeeds. Proceedings on Privacy Enhancing Technologies, 2021(3).
Givehchian, H., Bhaskar, N., Herrera, E. R., Soto, H. R. L., Dameff, C., Bharadia, D., and Schulman, A. (2022). Evaluating Physical-Layer BLE Location Tracking Attacks on Mobile Devices. In 2022 IEEE Symposium on Security and Privacy (SP).
Gorce, J.-M., Egan, M., and Gribonval, R. (2020). An efficient algorithm to estimate Covid-19 infectiousness risk from BLE-RSSI measurements. report, Inria Grenoble Rho^ne-Alpes.
Gruteser, M. and Grunwald, D. (2005). Enhancing Location Privacy in Wireless LAN Through Disposable Interface Identifiers: A Quantitative Analysis. Mobile Networks and Applications, (3).
Heinrich, A., Stute, M., Kornhuber, T., and Hollick, M. (2021). Who Can Find My Devices? Security and Privacy of Apple's Crowd-Sourced Bluetooth Location Tracking System. Proceedings on Privacy Enhancing Technologies, 2021(3).
Hua, J., Sun, H., Shen, Z., Qian, Z., and Zhong, S. (2018). Accurate and efficient wireless device fingerprinting using channel state information. In IEEE INFOCOM 2018-IEEE Conference on Computer Communications. IEEE.
Iannizzotto, G., Milici, M., Nucita, A., and Lo Bello, L. (2022). A Perspective on Passive Human Sensing with Bluetooth. Sensors, 22(9). Number: 9 Publisher: Multidisciplinary Digital Publishing Institute.
Issoufaly, T. and Tournoux, P. U. (2017). BLEB: Bluetooth Low Energy Botnet for large scale individual tracking. In Next Generation Computing Applications. IEEE.
Jain, C., Sashank, G. V. S., N, V., and Markkandan, S. (2021). Low-cost BLE based Indoor Localization using RSSI Fingerprinting and Machine Learning. In WiSPNET.
Jianyong, Z., Haiyong, L., Zili, C., and Zhaohui, L. (2014). RSSI based Bluetooth low energy indoor positioning. In International Conference on Indoor Positioning and Indoor Navigation (IPIN).
Larsson, J. (2015). Distance Estimation and Positioning Based on Bluetooth Low Energy Technology.
Leith, D. J. and Farrell, S. (2020). Coronavirus contact tracing: evaluating the potential of using bluetooth received signal strength for proximity detection. ACM SIGCOMM Computer Communication Review, 50(4).
Leping Huang, Matsuura, K., Yamane, H., and Sezaki, K. (2005). Enhancing wireless location privacy using silent period. In IEEE Wireless Communications and Networking Conference, 2005, volume 2. IEEE.
Ludant, N., Vo-Huu, T. D., Narain, S., and Noubir, G. (2021). Linking bluetooth le & classic and implications for privacy-preserving bluetooth-based protocols. In 2021 IEEE Symposium on Security and Privacy (SP), pages 13181331. IEEE.
Mariotto, A., Heinrich, A., Kreitschmann, D., Noubir, G., and Hollick, M. (2019). A Billion Open Interfaces for
Eve and Mallory: MitM, DoS, and Tracking Attacks on iOS and macOS Through Apple Wireless Direct Link. USENIX Security.
Martin, J., Alpuche, D., Bodeman, K., Brown, L., Fenske, E., Foppe, L., Mayberry, T., Rye, E., Sipes, B., and Teplov, S. (2019). Handoff All Your Privacy A Review of Apple's Bluetooth Low Energy Continuity Protocol. Proceedings on Privacy Enhancing Technologies, 2019(4):3453.
Martin, J., Mayberry, T., Donahue, C., Foppe, L., Brown, L., Riggins, C., Rye, E. C., and Brown, D. (2017). A Study of MAC Address Randomization in Mobile Devices and When it Fails. Proceedings on Privacy Enhancing Technologies, 2017(4).
Matte, C., Cunche, M., Rousseau, F., and Vanhoef, M. (2016). Defeating MAC Address Randomization Through Timing Attacks. In ACM WiSec.
Nikoofard, A., Givehchian, H., Bhaskar, N., Schulman, A., Bharadia, D., and Mercier, P. P. (2023). Protecting Bluetooth User Privacy Through Obfuscation of Carrier Frequency Offset. IEEE Transactions on Circuits and Systems II: Express Briefs, 70(2).
O'Hanlon, P., Wright, J., and Brown, I. (2014). Privacy at the link layer. In STRINT Workshop: A W3C/IAB workshop on Strengthening the Internet Against Pervasive Monitoring (STRINT).
Pau, G., Arena, F., Gebremariam, Y. E., and You, I. (2021). Bluetooth 5.1: An Analysis of Direction Finding Capability for High-Precision Location Services. Sensors, 21(11).
Rocamora, J. M., Wang-Hei Ho, I., Mak, W., and Lau, A. P. (2020). Survey of CSI fingerprinting-based indoor positioning and mobility tracking systems. IET Signal Processing, 14(7).
Shen, G., Zhang, J., Marshall, A., Peng, L., and Wang, X. (2021). Radio Frequency Fingerprint Identification for LoRa Using Spectrogram and CNN. In IEEE INFOCOM.
SIG, B. S. I. G. (2010). Bluetooth core specification 4.0.
SIG, B. S. I. G. (2016). Bluetooth core specification 5.0.
SIG, B. S. I. G. (2021). Bluetooth core specification 5.3.
Vanhoef, M., Matte, C., Cunche, M., Cardoso, L. S., and Piessens, F. (2016). Why MAC Address Randomization is Not Enough: An Analysis of Wi-Fi Network Discovery Mechanisms. In ACM AsiaCCS.
Vaudenay, S. and Vuagnoux, M. (2020). Little Thumb Attack on SwissCovid.
Vo-Huu, T. D., Vo-Huu, T. D., and Noubir, G. (2016). Fingerprinting Wi-Fi Devices Using Software Defined Radios. In ACM WiSec, WiSec '16.
Woolley, M. (2015). Bluetooth technology protecting your privacy.
Yan, W., Voigt, T., and Rohner, C. (2022). RRF: A Robust Radiometric Fingerprint System that Embraces Wireless Channel Diversity. In ACM WiSec.
Zhang, Y. and Lin, Z. (2022). When Good Becomes Evil: Tracking Bluetooth Low Energy Devices via Allowlist-based Side Channel and Its Countermeasure. In ACM CCS.
253