ORSHIN Attack Defense Framework

Key Negotiation of Bluetooth (KNOB) on BC

Description

Key Negotiation of Bluetooth (KNOB) on BC

Risk Assesment: 8.1

CWE

310

327

CVE

9506

Attack Surfaces

Controller Implementation (MITRE EMB3D PID-11)

Session (MITRE EMB3D PID-41)

Security Manager Protocol (MITRE EMB3D PID-4113)

Pairing

MagicPairing

Entropy Negotiation (MITRE EMB3D PID-4113)

Attack Vectors

Entropy downgrade (MITRE EMB3D TID-411)

Key brute force (MITRE EMB3D TID-317)

Defenses

Mutually authenticated entropy negotiation, Integrity protect entropy negotiation with the pairing key