论文标题
演示:从Broadcom和Cypress芯片中提取物理层的广告信息
DEMO: Extracting Physical-Layer BLE Advertisement Information from Broadcom and Cypress Chips
论文作者
论文摘要
多个计划建议利用蓝牙低能(BLE)广告进行接触跟踪和SARS-COV-2暴露通知。该演示显示了一个研究工具来分析BLE广告;如果供应商普遍启用,未发现的功能可以改善每个人的曝光通知。我们将BLE和柏树芯片上BLE广告的固件内部实现反向设计,并展示了如何在接收器上提取更多的物理层信息。经过分析的固件可用于数亿个设备,例如所有iPhone,欧洲三星Galaxy S系列和Raspberry Pis。
Multiple initiatives propose utilizing Bluetooth Low Energy (BLE) advertisements for contact tracing and SARS-CoV-2 exposure notifications. This demo shows a research tool to analyze BLE advertisements; if universally enabled by the vendors, the uncovered features could improve exposure notifications for everyone. We reverse-engineer the firmware-internal implementation of BLE advertisements on Broadcom and Cypress chips and show how to extract further physical-layer information at the receiver. The analyzed firmware works on hundreds of millions of devices, such as all iPhones, the European Samsung Galaxy S series, and Raspberry Pis.