Uppsats
Unauthenticated and Unencrypted : An Experimental Security Analysis of BLE Communication in a Low-Cost Consumer Smartwatch
Yrkesexamen på avancerad nivå
Blekinge Tekniska Högskola/Institutionen för datavetenskap
Publicerad: 2026
Språk: Engelska
Nyckelord
klicka för att sökaSammanfattning
Background. Consumer smartwatches are increasingly used for continuous healthmonitoring, transmitting sensitive physiological data via Bluetooth Low Energy(BLE). While BLE is widely adopted for its low power consumption, it can introducesecurity vulnerabilities, particularly in low-cost devices where protective measuresmay be constrained by cost and design priorities. Empirical research examining thereal-world security of affordable consumer smartwatches from lesser-known manufac-turers remains limited. Objectives. This thesis experimentally investigates the security of BLE commu-nication in a low-cost consumer smartwatch, identifies exploitable vulnerabilities,evaluates their feasibility under realistic threat conditions, and assesses mitigationstrategies appropriate for resource-constrained devices. Methods. An experimental case study was conducted on the Philippe Palmer SmartWatch LP43 (ZL54CJ), using passive BLE traffic capture with a Nordic Semicon-ductor nRF52840 dongle and Wireshark, custom Python scripts for unauthenticateddevice interaction and protocol fuzzing, and BLE advertisement spoofing. Mitigationstrategies were evaluated through comparative analysis of BLE pairing methods. Results. The observed communication was transmitted without encryption de-spite reporting hardware support for LE Encryption, and used Just Works pairingproviding no authentication. Unauthenticated connections were established from astandard laptop, the proprietary Moyoung protocol was partially reverse engineeredfrom plaintext traffic, and commands were injected without pairing or bonding. Con-firmed attack outcomes included remotely powering off the device, triggering healthmeasurements, and spoofing the device identity such that the companion applicationaccepted a rogue peripheral as legitimate. A layered mitigation approach combiningauthenticated pairing, mandatory encryption, and GATT-level access control wasidentified as both effective and feasible for the device’s hardware capabilities. Conclusions. BLE communication in the tested device can be compromised exten-sively under realistic conditions using standard tools. The vulnerabilities reflect im-plementation decisions rather than hardware limitations, as the device supports bothencryption and display-based authenticated pairing. Remediation through firmwareupdate is technically feasible. The findings contribute device-specific empirical evi-dence to an underexplored area of wearable security research and highlight potentialcompliance challenges under the EU Cyber Resilience Act.
Information
- Författare
- Andersson, Gabriella, Andersen, Rasmus
- Lärosäte / institution
- Blekinge Tekniska Högskola/Institutionen för datavetenskap
- Publiceringsdatum
- 2026
- Uppsatstyp
- Yrkesexamen på avancerad nivå
- Språk
- Engelska
Utforska vidare
Liknande uppsatser
Uppsatser med liknande ämnen och nyckelord.
Yrkesexamen på grundnivå, Jönköping University/JTH, Avdelningen för datateknik och informatik
Mohamed, Faiza, Mahmoudi, Somaye
Publicerad: 2026