{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T02:45:38Z","timestamp":1783392338652,"version":"3.54.6"},"publisher-location":"New York, NY, USA","reference-count":49,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,5,30]],"date-time":"2022-05-30T00:00:00Z","timestamp":1653868800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"DARPA","award":["HR001119S0089-AMP-FP-034"],"award-info":[{"award-number":["HR001119S0089-AMP-FP-034"]}]},{"DOI":"10.13039\/501100000781","name":"European Research Council","doi-asserted-by":"publisher","award":["grant No. 850868,"],"award-info":[{"award-number":["grant No. 850868,"]}],"id":[{"id":"10.13039\/501100000781","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,5,30]]},"DOI":"10.1145\/3488932.3523258","type":"proceedings-article","created":{"date-parts":[[2022,5,24]],"date-time":"2022-05-24T04:23:26Z","timestamp":1653366206000},"page":"196-207","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":25,"title":["BLURtooth"],"prefix":"10.1145","author":[{"given":"Daniele","family":"Antonioli","sequence":"first","affiliation":[{"name":"EURECOM, Biot, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nils Ole","family":"Tippenhauer","sequence":"additional","affiliation":[{"name":"CISPA Helmholtz Center for Information Security, Saarbr\u00fccken, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kasper","family":"Rasmussen","sequence":"additional","affiliation":[{"name":"University of Oxford, Oxford, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mathias","family":"Payer","sequence":"additional","affiliation":[{"name":"EPFL, Lausanne, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,5,30]]},"reference":[{"key":"e_1_3_2_2_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/2906388.2906403"},{"key":"e_1_3_2_2_2_1","volume-title":"Proceedings of the USENIX Security Symposium. USENIX.","author":"Antonioli Daniele","year":"2019","unstructured":"Daniele Antonioli , Nils Ole Tippenhauer , and Kasper Rasmussen . 2019 a. The KNOB is Broken: Exploiting Low Entropy in the Encryption Key Negotiation of Bluetooth BR\/EDR . In Proceedings of the USENIX Security Symposium. USENIX. Daniele Antonioli, Nils Ole Tippenhauer, and Kasper Rasmussen. 2019 a. The KNOB is Broken: Exploiting Low Entropy in the Encryption Key Negotiation of Bluetooth BR\/EDR. In Proceedings of the USENIX Security Symposium. USENIX."},{"key":"e_1_3_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23367"},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00093"},{"key":"e_1_3_2_2_5_1","volume-title":"Nils Ole Tippenhauer, and Kasper Rasmussen. 2020 b. Key Negotiation Downgrade Attacks on Bluetooth and Bluetooth Low Energy. Transactions on Privacy and Security (TOPS)","author":"Antonioli Daniele","year":"2020","unstructured":"Daniele Antonioli , Nils Ole Tippenhauer, and Kasper Rasmussen. 2020 b. Key Negotiation Downgrade Attacks on Bluetooth and Bluetooth Low Energy. Transactions on Privacy and Security (TOPS) ( 2020 ). https:\/\/doi.org\/10.1145\/3394497 10.1145\/3394497 Daniele Antonioli, Nils Ole Tippenhauer, and Kasper Rasmussen. 2020 b. Key Negotiation Downgrade Attacks on Bluetooth and Bluetooth Low Energy. Transactions on Privacy and Security (TOPS) (2020). https:\/\/doi.org\/10.1145\/3394497"},{"key":"e_1_3_2_2_6_1","unstructured":"AOSP. 2020. Fluoride Bluetooth stack. https:\/\/chromium.googlesource.com\/aosp\/platform\/system\/bt\/\/master\/README.md Accessed: 2020-01--27.  AOSP. 2020. Fluoride Bluetooth stack. https:\/\/chromium.googlesource.com\/aosp\/platform\/system\/bt\/\/master\/README.md Accessed: 2020-01--27."},{"key":"e_1_3_2_2_7_1","unstructured":"Python Cryptographic Authority. 2019. Python cryptography. https:\/\/cryptography.io\/en\/latest\/ Accessed: 2019-02-04.  Python Cryptographic Authority. 2019. Python cryptography. https:\/\/cryptography.io\/en\/latest\/ Accessed: 2019-02-04."},{"key":"e_1_3_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.45"},{"key":"e_1_3_2_2_9_1","unstructured":"Eli Biham and Lior Neumann. 2018. Breaking the Bluetooth Pairing--Fixed Coordinate Invalid Curve Attack. http:\/\/www.cs.technion.ac.il\/ biham\/BT\/bt-fixed-coordinate-invalid-curve-attack.pdf.  Eli Biham and Lior Neumann. 2018. Breaking the Bluetooth Pairing--Fixed Coordinate Invalid Curve Attack. http:\/\/www.cs.technion.ac.il\/ biham\/BT\/bt-fixed-coordinate-invalid-curve-attack.pdf."},{"key":"e_1_3_2_2_10_1","unstructured":"Bluetooth SIG. 2019 a. Bluetooth Core Specification v5.2. https:\/\/www.bluetooth.org\/docman\/handlers\/downloaddoc.ashx?doc_id=478726 Accessed: 2020-01--27.  Bluetooth SIG. 2019 a. Bluetooth Core Specification v5.2. https:\/\/www.bluetooth.org\/docman\/handlers\/downloaddoc.ashx?doc_id=478726 Accessed: 2020-01--27."},{"key":"e_1_3_2_2_11_1","unstructured":"Bluetooth SIG. 2019 b. Bluetooth Markets. https:\/\/www.bluetooth.com\/markets\/.  Bluetooth SIG. 2019 b. Bluetooth Markets. https:\/\/www.bluetooth.com\/markets\/."},{"key":"e_1_3_2_2_12_1","volume-title":"2020 a. Bluetooth Market Update","author":"Bluetooth","year":"2020","unstructured":"Bluetooth SIG. 2020 a. Bluetooth Market Update 2020 . https:\/\/www.bluetooth.com\/bluetooth-resources\/2020-bmu\/. Bluetooth SIG. 2020 a. Bluetooth Market Update 2020. https:\/\/www.bluetooth.com\/bluetooth-resources\/2020-bmu\/."},{"key":"e_1_3_2_2_13_1","unstructured":"Bluetooth SIG. 2020 b. Bluetooth SIG Statement Regarding BLURtooth. https:\/\/www.bluetooth.com\/learn-about-bluetooth\/key-attributes\/bluetooth-security\/blurtooth\/.  Bluetooth SIG. 2020 b. Bluetooth SIG Statement Regarding BLURtooth. https:\/\/www.bluetooth.com\/learn-about-bluetooth\/key-attributes\/bluetooth-security\/blurtooth\/."},{"key":"e_1_3_2_2_14_1","unstructured":"Bluetooth SIG. 2021 a. Bluetooth Core Specification v5.3. https:\/\/www.bluetooth.org\/DocMan\/handlers\/DownloadDoc.ashx?doc_id=521059 Accessed: 2021-11-15.  Bluetooth SIG. 2021 a. Bluetooth Core Specification v5.3. https:\/\/www.bluetooth.org\/DocMan\/handlers\/DownloadDoc.ashx?doc_id=521059 Accessed: 2021-11-15."},{"key":"e_1_3_2_2_15_1","volume-title":"2021 b. Bluetooth Market Update","author":"Bluetooth","year":"2021","unstructured":"Bluetooth SIG. 2021 b. Bluetooth Market Update 2021 . https:\/\/www.bluetooth.com\/bluetooth-resources\/2021-bmu\/?utm_campaign=bmu&utm_source=internal&utm_medium=web&utm_content=2021bmu-resourcepopup. Bluetooth SIG. 2021 b. Bluetooth Market Update 2021. https:\/\/www.bluetooth.com\/bluetooth-resources\/2021-bmu\/?utm_campaign=bmu&utm_source=internal&utm_medium=web&utm_content=2021bmu-resourcepopup."},{"key":"e_1_3_2_2_16_1","unstructured":"BlueZ. 2014. Bluetooth 4.2 features going to the 3.19 kernel release. https:\/\/tinyurl.com\/q9dzh2h Accessed: 2020-01-27.  BlueZ. 2014. Bluetooth 4.2 features going to the 3.19 kernel release. https:\/\/tinyurl.com\/q9dzh2h Accessed: 2020-01-27."},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338507.3358617"},{"key":"e_1_3_2_2_18_1","unstructured":"Cypress. 2019 a. BLE and Bluetooth. https:\/\/www.cypress.com\/products\/ble-bluetooth Accessed: 2020-01-27.  Cypress. 2019 a. BLE and Bluetooth. https:\/\/www.cypress.com\/products\/ble-bluetooth Accessed: 2020-01-27."},{"key":"e_1_3_2_2_19_1","unstructured":"Cypress. 2019 b. CYW920819EVB-02 Evaluation Kit. https:\/\/www.cypress.com\/documentation\/development-kitsboards\/cyw920819evb-02-evaluation-kit Accessed: 2019-11-16.  Cypress. 2019 b. CYW920819EVB-02 Evaluation Kit. https:\/\/www.cypress.com\/documentation\/development-kitsboards\/cyw920819evb-02-evaluation-kit Accessed: 2019-11-16."},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2010.3"},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45537-X_3"},{"key":"e_1_3_2_2_22_1","unstructured":"Garbelini Matheus and Chattopadhyay Sudipta and Wang Chundong. 2020. SweynTooth: Unleashing Mayhem over Bluetooth Low Energy. https:\/\/asset-group.github.io\/disclosures\/sweyntooth\/sweyntooth.pdf Accessed: 2020-04-08.  Garbelini Matheus and Chattopadhyay Sudipta and Wang Chundong. 2020. SweynTooth: Unleashing Mayhem over Bluetooth Low Energy. https:\/\/asset-group.github.io\/disclosures\/sweyntooth\/sweyntooth.pdf Accessed: 2020-04-08."},{"key":"e_1_3_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/1321400.1321402"},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/TWC.2010.01.090935"},{"key":"e_1_3_2_2_25_1","volume-title":"Proceedings of the International Conference in Central Asia on Internet. IEEE, 1--5.","author":"Hypponen Konstantin","year":"2007","unstructured":"Konstantin Hypponen and Keijo MJ Haataja . 2007 . Nino man-in-the-middle attack on Bluetooth secure simple pairing . In Proceedings of the International Conference in Central Asia on Internet. IEEE, 1--5. Konstantin Hypponen and Keijo MJ Haataja. 2007. Nino man-in-the-middle attack on Bluetooth secure simple pairing. In Proceedings of the International Conference in Central Asia on Internet. IEEE, 1--5."},{"key":"e_1_3_2_2_26_1","unstructured":"Intel. 2019. Intel Wireless Solutions. https:\/\/www.intel.com\/content\/www\/us\/en\/products\/wireless.html Accessed: 2020-01--27.  Intel. 2019. Intel Wireless Solutions. https:\/\/www.intel.com\/content\/www\/us\/en\/products\/wireless.html Accessed: 2020-01--27."},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45353-9_14"},{"key":"e_1_3_2_2_28_1","volume-title":"Black Hat USA Conference.","author":"Jasek S\u0142awomir","year":"2016","unstructured":"S\u0142awomir Jasek . 2016 . Gattacking Bluetooth smart devices . Black Hat USA Conference. S\u0142awomir Jasek. 2016. Gattacking Bluetooth smart devices. Black Hat USA Conference."},{"key":"e_1_3_2_2_29_1","volume-title":"Proceedings of the International Workshop on Selected Areas in Cryptography. Springer, 76--93","author":"Jonsson Jakob","year":"2002","unstructured":"Jakob Jonsson . 2002 . On the security of CTRCBC-MAC . In Proceedings of the International Workshop on Selected Areas in Cryptography. Springer, 76--93 . Jakob Jonsson. 2002. On the security of CTRCBC-MAC. In Proceedings of the International Workshop on Selected Areas in Cryptography. Springer, 76--93."},{"key":"e_1_3_2_2_30_1","volume-title":"Proceedings of the Advanced Encryption Standard Candidate Conference. NIST, 155--167","author":"Kelsey John","year":"1999","unstructured":"John Kelsey , Bruce Schneier , and David Wagner . 1999 . Key schedule weaknesses in SAFER . In Proceedings of the Advanced Encryption Standard Candidate Conference. NIST, 155--167 . John Kelsey, Bruce Schneier, and David Wagner. 1999. Key schedule weaknesses in SAFER. In Proceedings of the Advanced Encryption Standard Candidate Conference. NIST, 155--167."},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30182-0_29"},{"key":"e_1_3_2_2_32_1","volume-title":"Las Vegas, Nevada","author":"Lindell Andrew Y","year":"2008","unstructured":"Andrew Y Lindell . 2008. Attacks on the pairing protocol of Bluetooth v2.1. Black Hat USA , Las Vegas, Nevada ( 2008 ). Andrew Y Lindell. 2008. Attacks on the pairing protocol of Bluetooth v2.1. Black Hat USA, Las Vegas, Nevada (2008)."},{"key":"e_1_3_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/3307334.3326089"},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.5121\/ijdps.2012.3110"},{"key":"e_1_3_2_2_35_1","unstructured":"Michael Ossmann. 2019. Project Ubertooth. https:\/\/github.com\/greatscottgadgets\/ubertooth Accessed: 2019-10-21.  Michael Ossmann. 2019. Project Ubertooth. https:\/\/github.com\/greatscottgadgets\/ubertooth Accessed: 2019-10-21."},{"key":"e_1_3_2_2_36_1","first-page":"121","article-title":"Guide to Bluetooth security","volume":"800","author":"Padgette John","year":"2017","unstructured":"John Padgette . 2017 . Guide to Bluetooth security . NIST Special Publication , Vol. 800 (2017), 121 . John Padgette. 2017. Guide to Bluetooth security. NIST Special Publication, Vol. 800 (2017), 121.","journal-title":"NIST Special Publication"},{"key":"e_1_3_2_2_37_1","unstructured":"Qualcomm. 2019. Expand the potential of Bluetooth. https:\/\/www.qualcomm.com\/products\/bluetooth Accessed: 2020-01-27.  Qualcomm. 2019. Expand the potential of Bluetooth. https:\/\/www.qualcomm.com\/products\/bluetooth Accessed: 2020-01-27."},{"key":"e_1_3_2_2_38_1","volume-title":"Evaluation of some blockcipher modes of operation. Cryptography Research and Evaluation Committees (CRYPTREC) for the Government of Japan","author":"Rogaway Phillip","year":"2011","unstructured":"Phillip Rogaway . 2011. Evaluation of some blockcipher modes of operation. Cryptography Research and Evaluation Committees (CRYPTREC) for the Government of Japan ( 2011 ). Phillip Rogaway. 2011. Evaluation of some blockcipher modes of operation. Cryptography Research and Evaluation Committees (CRYPTREC) for the Government of Japan (2011)."},{"key":"e_1_3_2_2_39_1","first-page":"4","volume-title":"Proceedings of USENIX Workshop on Offensive Technologies (WOOT)","volume":"13","author":"Ryan Mike","year":"2013","unstructured":"Mike Ryan . 2013 . Bluetooth: With Low Energy Comes Low Security . In Proceedings of USENIX Workshop on Offensive Technologies (WOOT) , Vol. 13 . USENIX, 4 - 4 . Mike Ryan. 2013. Bluetooth: With Low Energy Comes Low Security. In Proceedings of USENIX Workshop on Offensive Technologies (WOOT), Vol. 13. USENIX, 4-4."},{"key":"e_1_3_2_2_40_1","unstructured":"Ben Seri and Gregory Vishnepolsky. 2017. The Attack Vector BlueBorne Exposes Almost Every Connected Device. https:\/\/armis.com\/blueborne\/ Accessed: 2018-01--26.  Ben Seri and Gregory Vishnepolsky. 2017. The Attack Vector BlueBorne Exposes Almost Every Connected Device. https:\/\/armis.com\/blueborne\/ Accessed: 2018-01--26."},{"key":"e_1_3_2_2_41_1","volume-title":"BLEEDINGBIT: The hidden Attack Surface within BLE chips. https:\/\/armis.com\/bleedingbit\/, Accessed: 2019-07-24.","author":"Seri Ben","year":"2019","unstructured":"Ben Seri , Gregory Vishnepolsky , and Dor Zusman . 2019 . BLEEDINGBIT: The hidden Attack Surface within BLE chips. https:\/\/armis.com\/bleedingbit\/, Accessed: 2019-07-24. Ben Seri, Gregory Vishnepolsky, and Dor Zusman. 2019. BLEEDINGBIT: The hidden Attack Surface within BLE chips. https:\/\/armis.com\/bleedingbit\/, Accessed: 2019-07-24."},{"key":"e_1_3_2_2_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/1067170.1067176"},{"key":"e_1_3_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00779-017-1081-6"},{"key":"e_1_3_2_2_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00013"},{"key":"e_1_3_2_2_45_1","volume-title":"Proceedings of International Workshop on Security Protocols. Springer, 31--45","author":"Wong Ford-Long","year":"2005","unstructured":"Ford-Long Wong , Frank Stajano , and Jolyon Clulow . 2005 . Repairing the Bluetooth pairing protocol . In Proceedings of International Workshop on Security Protocols. Springer, 31--45 . Ford-Long Wong, Frank Stajano, and Jolyon Clulow. 2005. Repairing the Bluetooth pairing protocol. In Proceedings of International Workshop on Security Protocols. Springer, 31--45."},{"key":"e_1_3_2_2_46_1","unstructured":"Joshua Wright. 2018. I Can Hear You Now - Eavesdropping on Bluetooth Headsets. https:\/\/www.willhackforsushi.com\/presentations\/icanhearyounow-sansns2007.pdf Accessed: 2018-10-30.  Joshua Wright. 2018. I Can Hear You Now - Eavesdropping on Bluetooth Headsets. https:\/\/www.willhackforsushi.com\/presentations\/icanhearyounow-sansns2007.pdf Accessed: 2018-10-30."},{"key":"e_1_3_2_2_47_1","volume-title":"14th USENIX Workshop on Offensive Technologies (WOOT).","author":"Wu Jianliang","year":"2020","unstructured":"Jianliang Wu , Yuhong Nan , Vireshwar Kumar , Dave Jing Tian , Antonio Bianchi , Mathias Payer , and Dongyan Xu . 2020 . BLESA: Spoofing Attacks against Reconnections in Bluetooth Low Energy . In 14th USENIX Workshop on Offensive Technologies (WOOT). Jianliang Wu, Yuhong Nan, Vireshwar Kumar, Dave Jing Tian, Antonio Bianchi, Mathias Payer, and Dongyan Xu. 2020. BLESA: Spoofing Attacks against Reconnections in Bluetooth Low Energy. In 14th USENIX Workshop on Offensive Technologies (WOOT)."},{"key":"e_1_3_2_2_48_1","unstructured":"Apple WWDC. 2019. What's New in Core Bluetooth. https:\/\/developer.apple.com\/videos\/play\/wwdc2019\/901 Accessed: 2020-01-27.  Apple WWDC. 2019. What's New in Core Bluetooth. https:\/\/developer.apple.com\/videos\/play\/wwdc2019\/901 Accessed: 2020-01-27."},{"key":"e_1_3_2_2_49_1","volume-title":"Breaking Secure Pairing of Bluetooth Low Energy Using Downgrade Attacks. In 29th USENIX Security Symposium (USENIX Security 20)","author":"Zhang Yue","year":"2020","unstructured":"Yue Zhang , Jian Weng , Rajib Dey , Yier Jin , Zhiqiang Lin , and Xinwen Fu . 2020 . Breaking Secure Pairing of Bluetooth Low Energy Using Downgrade Attacks. In 29th USENIX Security Symposium (USENIX Security 20) . 37--54. Yue Zhang, Jian Weng, Rajib Dey, Yier Jin, Zhiqiang Lin, and Xinwen Fu. 2020. Breaking Secure Pairing of Bluetooth Low Energy Using Downgrade Attacks. In 29th USENIX Security Symposium (USENIX Security 20). 37--54."}],"event":{"name":"ASIA CCS '22: ACM Asia Conference on Computer and Communications Security","location":"Nagasaki Japan","acronym":"ASIA CCS '22","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2022 ACM on Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3488932.3523258","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/abs\/10.1145\/3488932.3523258","content-type":"text\/html","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3488932.3523258","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3488932.3523258","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:31:27Z","timestamp":1750188687000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3488932.3523258"}},"subtitle":["Exploiting Cross-Transport Key Derivation in Bluetooth Classic and Bluetooth Low Energy"],"short-title":[],"issued":{"date-parts":[[2022,5,30]]},"references-count":49,"alternative-id":["10.1145\/3488932.3523258","10.1145\/3488932"],"URL":"https:\/\/doi.org\/10.1145\/3488932.3523258","relation":{},"subject":[],"published":{"date-parts":[[2022,5,30]]},"assertion":[{"value":"2022-05-30","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}