{"id":"https://openalex.org/W4226525216","doi":"https://doi.org/10.1109/sp46214.2022.9833639","title":"Attacks on Wireless Coexistence: Exploiting Cross-Technology Performance Features for Inter-Chip Privilege Escalation","display_name":"Attacks on Wireless Coexistence: Exploiting Cross-Technology Performance Features for Inter-Chip Privilege Escalation","publication_year":2022,"publication_date":"2022-05-01","ids":{"openalex":"https://openalex.org/W4226525216","doi":"https://doi.org/10.1109/sp46214.2022.9833639"},"language":"en","primary_location":{"id":"doi:10.1109/sp46214.2022.9833639","is_oa":false,"landing_page_url":"https://doi.org/10.1109/sp46214.2022.9833639","pdf_url":null,"source":{"id":"https://openalex.org/S4363606603","display_name":"2022 IEEE Symposium on Security and Privacy (SP)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 IEEE Symposium on Security and Privacy (SP)","raw_type":"proceedings-article"},"type":"preprint","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5016475244","display_name":"Jiska Classen","orcid":null},"institutions":[{"id":"https://openalex.org/I31512782","display_name":"Technical University of Darmstadt","ror":"https://ror.org/05n911h24","country_code":"DE","type":"education","lineage":["https://openalex.org/I31512782"]}],"countries":["DE"],"is_corresponding":true,"raw_author_name":"Jiska Classen","raw_affiliation_strings":["Technical University of Darmstadt, Secure Mobile Networking Lab"],"affiliations":[{"raw_affiliation_string":"Technical University of Darmstadt, Secure Mobile Networking Lab","institution_ids":["https://openalex.org/I31512782"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5034071044","display_name":"Francesco Gringoli","orcid":"https://orcid.org/0000-0003-2621-582X"},"institutions":[{"id":"https://openalex.org/I30667456","display_name":"Brescia University","ror":"https://ror.org/015ahgd08","country_code":"US","type":"education","lineage":["https://openalex.org/I30667456"]},{"id":"https://openalex.org/I79940851","display_name":"University of Brescia","ror":"https://ror.org/02q2d2610","country_code":"IT","type":"education","lineage":["https://openalex.org/I79940851"]}],"countries":["IT","US"],"is_corresponding":false,"raw_author_name":"Francesco Gringoli","raw_affiliation_strings":["University of Brescia, CNIT"],"affiliations":[{"raw_affiliation_string":"University of Brescia, CNIT","institution_ids":["https://openalex.org/I30667456","https://openalex.org/I79940851"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5024917024","display_name":"Martin Hermann","orcid":"https://orcid.org/0000-0003-2213-3448"},"institutions":[{"id":"https://openalex.org/I31512782","display_name":"Technical University of Darmstadt","ror":"https://ror.org/05n911h24","country_code":"DE","type":"education","lineage":["https://openalex.org/I31512782"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Michael Hermann","raw_affiliation_strings":["Technical University of Darmstadt, Secure Mobile Networking Lab"],"affiliations":[{"raw_affiliation_string":"Technical University of Darmstadt, Secure Mobile Networking Lab","institution_ids":["https://openalex.org/I31512782"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5042405070","display_name":"Matthias Hollick","orcid":"https://orcid.org/0000-0002-9163-5989"},"institutions":[{"id":"https://openalex.org/I31512782","display_name":"Technical University of Darmstadt","ror":"https://ror.org/05n911h24","country_code":"DE","type":"education","lineage":["https://openalex.org/I31512782"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Matthias Hollick","raw_affiliation_strings":["Technical University of Darmstadt, Secure Mobile Networking Lab"],"affiliations":[{"raw_affiliation_string":"Technical University of Darmstadt, Secure Mobile Networking Lab","institution_ids":["https://openalex.org/I31512782"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5016475244"],"corresponding_institution_ids":["https://openalex.org/I31512782"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.02973721,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1229","last_page":"1245"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12801","display_name":"Bluetooth and Wireless Communication Technologies","score":0.9937999844551086,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12801","display_name":"Bluetooth and Wireless Communication Technologies","score":0.9937999844551086,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11932","display_name":"Wireless Body Area Networks","score":0.9782000184059143,"subfield":{"id":"https://openalex.org/subfields/2204","display_name":"Biomedical Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11504","display_name":"Advanced Authentication Protocols Security","score":0.9692000150680542,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/bluetooth","display_name":"Bluetooth","score":0.6146225929260254},{"id":"https://openalex.org/keywords/wireless","display_name":"Wireless","score":0.5760049819946289},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5696969628334045},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.5332035422325134},{"id":"https://openalex.org/keywords/chip","display_name":"Chip","score":0.5317125916481018},{"id":"https://openalex.org/keywords/wireless-network","display_name":"Wireless network","score":0.4982419013977051},{"id":"https://openalex.org/keywords/embedded-system","display_name":"Embedded system","score":0.4344877600669861},{"id":"https://openalex.org/keywords/schedule","display_name":"Schedule","score":0.42466384172439575},{"id":"https://openalex.org/keywords/telecommunications","display_name":"Telecommunications","score":0.20384371280670166},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.17520928382873535}],"concepts":[{"id":"https://openalex.org/C546215728","wikidata":"https://www.wikidata.org/wiki/Q39531","display_name":"Bluetooth","level":3,"score":0.6146225929260254},{"id":"https://openalex.org/C555944384","wikidata":"https://www.wikidata.org/wiki/Q249","display_name":"Wireless","level":2,"score":0.5760049819946289},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5696969628334045},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.5332035422325134},{"id":"https://openalex.org/C165005293","wikidata":"https://www.wikidata.org/wiki/Q1074500","display_name":"Chip","level":2,"score":0.5317125916481018},{"id":"https://openalex.org/C108037233","wikidata":"https://www.wikidata.org/wiki/Q11375","display_name":"Wireless network","level":3,"score":0.4982419013977051},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.4344877600669861},{"id":"https://openalex.org/C68387754","wikidata":"https://www.wikidata.org/wiki/Q7271585","display_name":"Schedule","level":2,"score":0.42466384172439575},{"id":"https://openalex.org/C76155785","wikidata":"https://www.wikidata.org/wiki/Q418","display_name":"Telecommunications","level":1,"score":0.20384371280670166},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.17520928382873535}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/sp46214.2022.9833639","is_oa":false,"landing_page_url":"https://doi.org/10.1109/sp46214.2022.9833639","pdf_url":null,"source":{"id":"https://openalex.org/S4363606603","display_name":"2022 IEEE Symposium on Security and Privacy (SP)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 IEEE Symposium on Security and Privacy (SP)","raw_type":"proceedings-article"},{"id":"pmh:oai:tubiblio.ulb.tu-darmstadt.de:130936","is_oa":false,"landing_page_url":"http://tubiblio.ulb.tu-darmstadt.de/130936/","pdf_url":null,"source":{"id":"https://openalex.org/S4377196390","display_name":"TUbilio (Technical University of Darmstadt)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I31512782","host_organization_name":"Technische Universit\u00e4t Darmstadt","host_organization_lineage":["https://openalex.org/I31512782"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"Konferenzver\u00f6ffentlichung"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320321707","display_name":"EWE","ror":"https://ror.org/040gfwf91"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":21,"referenced_works":["https://openalex.org/W2095937454","https://openalex.org/W2157116240","https://openalex.org/W2162598825","https://openalex.org/W2163563130","https://openalex.org/W2891841929","https://openalex.org/W2942826212","https://openalex.org/W2963311060","https://openalex.org/W3024280588","https://openalex.org/W3032388105","https://openalex.org/W3044899990","https://openalex.org/W3162484944","https://openalex.org/W4381739157","https://openalex.org/W6640935840","https://openalex.org/W6752073170","https://openalex.org/W6765984322","https://openalex.org/W6778035576","https://openalex.org/W6779448139","https://openalex.org/W6780211247","https://openalex.org/W6782650952","https://openalex.org/W6790165530","https://openalex.org/W6969723355"],"related_works":["https://openalex.org/W4354479","https://openalex.org/W194988","https://openalex.org/W13047049","https://openalex.org/W1908891","https://openalex.org/W6801819","https://openalex.org/W2483745","https://openalex.org/W15897748","https://openalex.org/W9974131","https://openalex.org/W14467583","https://openalex.org/W16402234"],"abstract_inverted_index":{"Modern":[0],"mobile":[1],"devices":[2],"feature":[3],"multiple":[4],"wireless":[5,21,41,145],"technologies,":[6],"such":[7,35],"as":[8,25,36],"Bluetooth,":[9],"Wi-Fi,":[10],"and":[11,33,69,73,85,107],"LTE.":[12],"Each":[13],"of":[14,92,120],"them":[15,47],"is":[16],"implemented":[17],"within":[18],"a":[19,99,111,117],"separate":[20],"chip,":[22],"sometimes":[23],"packaged":[24],"combo":[26],"chips.":[27],"However,":[28],"these":[29],"chips":[30,72,88,146],"share":[31],"components":[32],"resources,":[34,55],"the":[37,130,133,153,158],"same":[38],"antenna":[39],"or":[40],"spectrum.":[42],"Wireless":[43],"coexistence":[44,63,80],"interfaces":[45,64],"enable":[46,116],"to":[48,57,132,149,156],"schedule":[49],"packets":[50],"without":[51],"collisions":[52],"despite":[53],"shared":[54],"essential":[56],"maximizing":[58],"networking":[59],"performance.":[60],"Today\u2019s":[61],"hardwired":[62],"hinder":[65],"clear":[66],"security":[67],"boundaries":[68],"separation":[70],"between":[71],"chip":[74,101,125],"components.":[75],"This":[76],"paper":[77],"shows":[78],"practical":[79],"attacks":[81,115,160],"on":[82,110,161],"Broadcom,":[83],"Cypress,":[84],"Silicon":[86],"Labs":[87],"deployed":[89],"in":[90],"billions":[91],"devices.":[93],"For":[94],"example,":[95],"we":[96],"demonstrate":[97],"that":[98],"Bluetooth":[100],"can":[102],"directly":[103],"extract":[104],"network":[105],"passwords":[106],"manipulate":[108],"traffic":[109],"Wi-Fi":[112],"chip.":[113],"Coexistence":[114],"novel":[118],"type":[119],"lateral":[121],"privilege":[122],"escalation":[123],"across":[124],"boundaries.":[126],"We":[127],"responsibly":[128],"disclosed":[129],"vulnerabilities":[131],"vendors.":[134],"Yet,":[135],"only":[136],"partial":[137],"fixes":[138],"were":[139],"released":[140],"for":[141],"existing":[142],"hardware":[143],"since":[144],"would":[147],"need":[148],"be":[150],"redesigned":[151],"from":[152],"ground":[154],"up":[155],"prevent":[157],"presented":[159],"coexistence.":[162]},"counts_by_year":[],"updated_date":"2026-04-09T08:11:56.329763","created_date":"2022-05-05T00:00:00"}
