Secure BLE Communication Between Android Devices and Embedded Systems for IoT Applications
摘要
Data privacy is an important key in current Internet of Things (IoT) communications. In this work, a novel mechanism for secure Bluetooth Low Energy communications between Android and IoT devices is proposed, based on a literature review about vulnerabilities and potential attacks over this protocol. The vulnerabilities and attacks found in the literature were analyzed and, with this basis, a mechanism was proposed that includes a series of application-level security measures to ensure secure communication. This mechanism involves the generation, sharing, and renewal of both symmetric and asymmetric security keys, as well as time and authenticity control by applying timestamps, unique keys, among other measures. As a result, according to the methodology, the proposal provides resistance against 71.43% of the attacks found in the analyzed works. The remaining 28.57% of attacks, not covered by the present proposal, do not impact the privacy or authenticity of the transmitted data, ensuring secure communication.