{"id":"https://openalex.org/W4288057724","doi":"https://doi.org/10.1109/sp46214.2022.9833777","title":"Formal Model-Driven Discovery of Bluetooth Protocol Design Vulnerabilities","display_name":"Formal Model-Driven Discovery of Bluetooth Protocol Design Vulnerabilities","publication_year":2022,"publication_date":"2022-05-01","ids":{"openalex":"https://openalex.org/W4288057724","doi":"https://doi.org/10.1109/sp46214.2022.9833777"},"language":"en","primary_location":{"id":"doi:10.1109/sp46214.2022.9833777","is_oa":false,"landing_page_url":"https://doi.org/10.1109/sp46214.2022.9833777","pdf_url":null,"source":{"id":"https://openalex.org/S4363606603","display_name":"2022 IEEE Symposium on Security and Privacy (SP)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 IEEE Symposium on Security and Privacy (SP)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101102768","display_name":"Jianliang Wu","orcid":null},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Jianliang Wu","raw_affiliation_strings":["Purdue University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5085131806","display_name":"Ruoyu Wu","orcid":"https://orcid.org/0000-0003-1122-3894"},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ruoyu Wu","raw_affiliation_strings":["Purdue University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5108280598","display_name":"Dongyan Xu","orcid":null},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Dongyan Xu","raw_affiliation_strings":["Purdue University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5015662045","display_name":"Dave Tian","orcid":"https://orcid.org/0000-0002-7506-9593"},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Dave Jing Tian","raw_affiliation_strings":["Purdue University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5028194244","display_name":"Antonio Bianchi","orcid":"https://orcid.org/0000-0002-2862-5286"},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Antonio Bianchi","raw_affiliation_strings":["Purdue University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":5.7815,"has_fulltext":false,"cited_by_count":32,"citation_normalized_percentile":{"value":0.97994467,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":98,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"2285","last_page":"2303"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12801","display_name":"Bluetooth and Wireless Communication Technologies","score":0.9986000061035156,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12801","display_name":"Bluetooth and Wireless Communication Technologies","score":0.9986000061035156,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11504","display_name":"Advanced Authentication Protocols Security","score":0.9923999905586243,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11800","display_name":"User Authentication and Security Systems","score":0.9869999885559082,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/bluetooth","display_name":"Bluetooth","score":0.9080423712730408},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8417627811431885},{"id":"https://openalex.org/keywords/protocol","display_name":"Protocol (science)","score":0.5757140517234802},{"id":"https://openalex.org/keywords/cryptographic-protocol","display_name":"Cryptographic protocol","score":0.4960046708583832},{"id":"https://openalex.org/keywords/modular-design","display_name":"Modular design","score":0.46957656741142273},{"id":"https://openalex.org/keywords/suite","display_name":"Suite","score":0.43985283374786377},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.4364880919456482},{"id":"https://openalex.org/keywords/wireless","display_name":"Wireless","score":0.4306897819042206},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.36904168128967285},{"id":"https://openalex.org/keywords/cryptography","display_name":"Cryptography","score":0.278875470161438},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.16881009936332703}],"concepts":[{"id":"https://openalex.org/C546215728","wikidata":"https://www.wikidata.org/wiki/Q39531","display_name":"Bluetooth","level":3,"score":0.9080423712730408},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8417627811431885},{"id":"https://openalex.org/C2780385302","wikidata":"https://www.wikidata.org/wiki/Q367158","display_name":"Protocol (science)","level":3,"score":0.5757140517234802},{"id":"https://openalex.org/C33884865","wikidata":"https://www.wikidata.org/wiki/Q1254335","display_name":"Cryptographic protocol","level":3,"score":0.4960046708583832},{"id":"https://openalex.org/C101468663","wikidata":"https://www.wikidata.org/wiki/Q1620158","display_name":"Modular design","level":2,"score":0.46957656741142273},{"id":"https://openalex.org/C79581498","wikidata":"https://www.wikidata.org/wiki/Q1367530","display_name":"Suite","level":2,"score":0.43985283374786377},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4364880919456482},{"id":"https://openalex.org/C555944384","wikidata":"https://www.wikidata.org/wiki/Q249","display_name":"Wireless","level":2,"score":0.4306897819042206},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.36904168128967285},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.278875470161438},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.16881009936332703},{"id":"https://openalex.org/C95457728","wikidata":"https://www.wikidata.org/wiki/Q309","display_name":"History","level":0,"score":0.0},{"id":"https://openalex.org/C71924100","wikidata":"https://www.wikidata.org/wiki/Q11190","display_name":"Medicine","level":0,"score":0.0},{"id":"https://openalex.org/C166957645","wikidata":"https://www.wikidata.org/wiki/Q23498","display_name":"Archaeology","level":1,"score":0.0},{"id":"https://openalex.org/C142724271","wikidata":"https://www.wikidata.org/wiki/Q7208","display_name":"Pathology","level":1,"score":0.0},{"id":"https://openalex.org/C204787440","wikidata":"https://www.wikidata.org/wiki/Q188504","display_name":"Alternative medicine","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/sp46214.2022.9833777","is_oa":false,"landing_page_url":"https://doi.org/10.1109/sp46214.2022.9833777","pdf_url":null,"source":{"id":"https://openalex.org/S4363606603","display_name":"2022 IEEE Symposium on Security and Privacy (SP)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 IEEE Symposium on Security and Privacy (SP)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.4300000071525574}],"awards":[],"funders":[{"id":"https://openalex.org/F4320337345","display_name":"Office of Naval Research","ror":"https://ror.org/00rk2pe57"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":42,"referenced_works":["https://openalex.org/W58703277","https://openalex.org/W146244851","https://openalex.org/W1490223983","https://openalex.org/W1985605613","https://openalex.org/W2029693536","https://openalex.org/W2029851387","https://openalex.org/W2061719810","https://openalex.org/W2064815039","https://openalex.org/W2108978217","https://openalex.org/W2123542192","https://openalex.org/W2130899669","https://openalex.org/W2259422394","https://openalex.org/W2544274814","https://openalex.org/W2554653394","https://openalex.org/W2618267215","https://openalex.org/W2652625053","https://openalex.org/W2799174307","https://openalex.org/W2933347941","https://openalex.org/W2933426098","https://openalex.org/W2947213621","https://openalex.org/W2954594758","https://openalex.org/W2960944180","https://openalex.org/W3015314850","https://openalex.org/W3020872719","https://openalex.org/W3038161846","https://openalex.org/W3081908344","https://openalex.org/W3102401280","https://openalex.org/W3153757948","https://openalex.org/W3158714349","https://openalex.org/W3178268869","https://openalex.org/W4287661859","https://openalex.org/W4289702168","https://openalex.org/W6602393588","https://openalex.org/W6605925781","https://openalex.org/W6692256458","https://openalex.org/W6750412548","https://openalex.org/W6756158088","https://openalex.org/W6761413925","https://openalex.org/W6764631947","https://openalex.org/W6776297955","https://openalex.org/W6782385920","https://openalex.org/W6782650952"],"related_works":["https://openalex.org/W4220926637","https://openalex.org/W2362681120","https://openalex.org/W2376320007","https://openalex.org/W4376643979","https://openalex.org/W2322402661","https://openalex.org/W2389079374","https://openalex.org/W2372429262","https://openalex.org/W3088304681","https://openalex.org/W2159180878","https://openalex.org/W2282990539"],"abstract_inverted_index":{"The":[0],"Bluetooth":[1,5,7,11,30,68,73,86,104,160,208,242],"protocol":[2,41,44,87,128,152],"suite,":[3,47],"including":[4],"Classic,":[6],"Low":[8],"Energy,":[9],"and":[10,95,106,132,170,191,202,225],"Mesh,":[12],"has":[13],"become":[14],"the":[15,46,63,91,96,102,143,165,172,226],"de":[16],"facto":[17],"standard":[18],"for":[19,85],"short-range":[20],"wireless":[21],"communications.":[22],"While":[23],"formal":[24,77,83,113],"methods":[25,135],"have":[26],"been":[27],"applied":[28],"to":[29,141,175,185],"security,":[31],"existing":[32],"efforts":[33],"either":[34],"focus":[35],"on":[36],"one":[37,43,220,237],"configuration":[38],"of":[39,45,67,150,167,214],"a":[40,57,81,119,127,151,223,231],"or":[42,52],"without":[48],"considering":[49],"other":[50,227],"configurations":[51,149],"interactions":[53,169],"among":[54],"protocols.":[55],"As":[56],"result,":[58],"manual":[59],"analysis":[60,75],"still":[61],"dominates":[62],"state-of-the-art":[64],"security":[65,74,189,206,232],"research":[66],"specification.":[69],"To":[70],"enable":[71],"automatic":[72],"with":[76,195,219],"guarantees,":[78],"we":[79],"propose":[80],"comprehensive":[82],"model":[84,174,184,235],"suite":[88],"covering":[89],"both":[90],"key":[92],"sharing":[93],"phase":[94],"data":[97],"transmission":[98],"phase,":[99],"in":[100,116,136,230],"all":[101,147],"three":[103],"protocols,":[105],"detecting":[107],"their":[108,168],"design":[109,121],"flaws":[110],"automatically.":[111],"Our":[112,234],"model,":[114],"written":[115],"ProVerif,":[117],"adopts":[118],"modular":[120],"by":[122],"abstracting":[123],"each":[124,137],"step":[125,138,238],"within":[126],"into":[129,162],"an":[130],"interface":[131],"implementing":[133],"different":[134,159],"as":[139],"modules":[140,163],"instantiate":[142],"interface,":[144],"through":[145],"which":[146],"possible":[148],"could":[153],"be":[154],"examined.":[155],"We":[156,181],"further":[157],"abstract":[158],"protocols":[161],"enabling":[164],"modeling":[166],"relax":[171],"threat":[173],"allow":[176],"reasoning":[177],"about":[178],"semi-compromised":[179],"devices.":[180],"use":[182],"this":[183],"formally":[186,240],"verify":[187],"418":[188],"properties":[190],"find":[192],"82":[193],"violations":[194],"attack":[196],"examples":[197],"capturing":[198],"5":[199],"known":[200],"vulnerabilities":[201],"discovering":[203],"2":[204,216],"new":[205,217],"issues.":[207],"SIG":[209],"confirmed":[210],"our":[211],"independent":[212],"discovery":[213],"these":[215],"issues,":[218],"issue":[221,228],"assigned":[222],"CVE":[224],"acknowledged":[229],"notice.":[233],"provides":[236],"towards":[239],"verified":[241],"security.":[243]},"counts_by_year":[{"year":2026,"cited_by_count":5},{"year":2025,"cited_by_count":11},{"year":2024,"cited_by_count":9},{"year":2023,"cited_by_count":7}],"updated_date":"2026-06-20T22:02:38.213706","created_date":"2025-10-10T00:00:00"}
