Security standardization can improve product security while maintaining interoperability across manufacturers. We examine whether this holds true for the Internet-of-Things (IoT) by analyzing Bluetooth LE (BLE), a widely adopted industry standard. We also survey the international standardization landscape for IoT security, finding that Smart Home security will soon be addressed by dedicated ISO 27xxx standards. To assess real-world compliance, we developed an automated sniffing tool that analyzes the BLE pairing process between IoT devices and their companion smartphone apps, identifying whether devices use the security mechanisms prescribed by the BLE standard. Our results are concerning: fewer than 5% of tested devices implemented a secure pairing method as specified by the standard. Most devices either used weaker standard mechanisms or none at all. Notably, some manufacturers went further in the wrong direction – rather than using the secure pairing mechanisms built into the smartphone’s operating system, they replicated or simulated higher-security pairing within their own proprietary app protocols. This approach undermines the very purpose of standardization and suggests that regulatory pressure, such as the emerging EU framework, may be necessary to drive meaningful security compliance in the IoT ecosystem.
更多
查看译文
关键词
Bluetooth,Standardization,Cybersecurity,Internet-of-Things,Security,European Cyber Resilience Act (EU CRA),ETSI EN 303 645,European Radio Equipment Directive (EU RED)