Skip to content

Repository files navigation

ZigBear 🐻

A Zigbee security research toolkit for the RaspBee, nRF52840 and CC2531 radio modules.

In order to develop and test improved network join procedures using asymmetric encryption, a custom proof of concept protocol based on the IEEE 802.15.4 standard was developed and is also included in the toolkit.

Flashing the firmware

The radio modules need to be flashed with our custom firmware, prior to using it with ZigBear.

The instructions, on how to do this, vary depending on the chosen transceiver.

RaspBee

To remotely flash the firmware of a RaspBee module, execute

$ make remote-install-firmware

On the host, docker is required for compilation of µracoli.

On the RaspberryPi, GCFFlasher_internal is required (included in the installation of deCONZ).

The SSH target for the RaspBee can be configure in the Makefile.

nRF52840

To flash a nRF52840 dongle, the nRF Connect software is required.

Detailed instructions on how to flash using nRF Connect, can be found here.

CC2531

To flash a CC2531 dongle, the CC Debugger from Texas Instruments is required.

Detailed instructions on how to flash using the CC Debugger can be found here.

Launching ZigBear

To launch the ZigBear Python CLI locally, simply execute

$ make run

Requires python3, pipenv and optionally tkinter for the virtual lamp

Remote execution on RaspberryPi

To remotely execute ZigBear via SSH on a RaspberryPi + RaspBee, execute

$ make remote-run

Requires python3 and pipenv on the RaspberryPi.

Usage

The ZigBear CLI can be either preconfigured using command line arguments

usage: __main__.py [-h] [-L [LOG_FILE]] [-l {DEBUG,INFO,WARN,ERROR}]
[-c {nrf,cc2531,raspbee,socket}] [-d DEVICE] [-C CHANNEL]
[-w WIRESHARK_HOST] [-r RECEIVE_PORT] [-t TARGET_PORT]
ZigBear CLI
optional arguments:
-h, --help show this help message and exit
Logging:
-L [LOG_FILE], --log-file [LOG_FILE]
Log output to LOG_FILE. If -L is specified but
LOG_FILE is omitted, "zigbear.log" will be used. If
the argument is omitted altogether, logging will not
take place at all.
-l {DEBUG,INFO,WARN,ERROR}, --log-level {DEBUG,INFO,WARN,ERROR}
Log messages of severity LOG_LEVEL or higher. Only
makes sense if -L is also specified (Default: INFO)
ZigBear:
-c {nrf,cc2531,raspbee,socket}, --connector {nrf,cc2531,raspbee,socket}
configure connector type
-d DEVICE, --device DEVICE
transceive from DEVICE (Default: /dev/ttyACM0)
-C CHANNEL, --channel CHANNEL
radio channel for listening and sending (Default: 25)
-w WIRESHARK_HOST, --wireshark-host WIRESHARK_HOST
wireshark host (Default: 127.0.0.1)
-r RECEIVE_PORT, --receive-port RECEIVE_PORT
receive port for the socket connector (Default: 8080)
-t TARGET_PORT, --target-port TARGET_PORT
target port for the socket connector (Default: 9090)

or interactively configured using the CLI commands after launching ZigBear

Select a connector

To select the connector for your hardware, execute

connector <connector> 

<connector> must be one of the following options:

  • nrf
  • cc2531
  • raspbee
  • socket

Select a channel

After selecting a connector you can choose a radio channel

channel <number>

<number> must be between and including 11 and 25.

Send raw data

With the selected channel you can now start to transmit raw data (hexadecimal string) using the send command

send <hexadecimalString>

Custom protocol

An application communicates with our custom protocol stack, which consists of the following layers.

Protocol Stack

The MAC Layer communicates via one of the connectors with the hardware and vice versa.

MAC Layer

The MAC layer of the IEEE 802.15.4 protocol is used. This layer sends and receives data directly using one of the radio connectors.

Network Layer

The Network Layer has several tasks. One is the partitioning of packages which exceed the maximum size of 80 byte. Another task is to send ACK packages. A retry mechanism is implemented to send packages again if no response was received.

Security Layer

The Security Layer handles encryption and decryption of packages.

For the encryption and decryption of packets, that are exchanged between devices that share a network key, the symmetric encoding AES-GCM is used. Advanced Encryption Standard (AES) is a block cipher which decodes 16 byte blocks with byte substitution, permutations and transformations. For these operations a key with a length of 128, 192 or 256 Bit is used.

As AES-GCM is an authenticated encryption algorithm, it is also capable of providing integrity via the authentication tag, that is produced as a result of it. If an encrypted message has an invalid authentication tag, it will not be decrypted or relayed to the application layer.

To exchange the network key the Elliptic Curve Diffie-Hellman (ECDH) algorithm is used. The communication partners exchange their public keys and calculate a shared key using their private keys. This shared key is passed through HKDF to turn it into a cryptographically stronger key.

Key Exchange

The exchange of the actual network key is encrypted using the key derived from the shared key. This secure channel could also be used for negotiating different details of the connection in the future. After the network key is exchaged, any keys relating to that exchange are dropped by both communication partners. A new set of keys has to be generated for each exchange, thus providing forward secrecy for key exchanges.

Application Layer

The Application Layer offers a socket interface for the development of high level applications. It consists of a Session and a Listener class where Session has methods to send a network key and a initiation package and Listener has methods to register and connect to a broadcast. Both can send and receive packages.

Example application

The projects comes with a virtual lamp as an example application for our custom protocol. By sending messages between two ZigBear instances, where one acts as device and the other one as coordinator, the "lamp" (a colored GUI window) can be switched off, on or set to specific brightness values.

To test the lamp in combination with a coordinator, follow these steps:

  • Launch two instances of ZigBear from the project directory with
$ make run
  • Use UDP connector (socket), for simplicity.
  • Enter inverse send and receive ports on the two clients.
  • Launch one client into device mode and the other into coordinator mode.
  • Enter info on the device client to display its random address (in the following steps named as <device_address>).
  • Perform the following commands on the coordinator client to pair it with the device client.
initiate <device_address> sendkey <device_address>
  • Start the virtual lamp example application on the device client with the command lamp
  • Control the lamp by sending on of the following commands from the coordinator client to the device client:
toggle <device_address>
brightness <device_address> <brightness>

Future enhancements

Development of ZigBear is on-going, and there is still much to do.

Some of the things that could be interesting to work on, in no particular order, are listed below:

  • ZigBee Light Link attacks
  • Automated network join attacks
  • Remote factory reset attacks
  • Remote firmware update attacks
  • Formal verification of custom protocol
  • Authorization for custom protocol

Resources

Inspirations

About

🐝 Zigbee security research toolkit for the RaspBee, nRF52840 and CC2531 radio modules.

Topics

Resources

Stars

40 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
GitHub - philippnormann/zigbear: 🐝 Zigbee security research toolkit for the RaspBee, nRF52840 and CC2531 radio modules. · GitHub
Skip to content

Repository files navigation

ZigBear 🐻

A Zigbee security research toolkit for the RaspBee, nRF52840 and CC2531 radio modules.

In order to develop and test improved network join procedures using asymmetric encryption, a custom proof of concept protocol based on the IEEE 802.15.4 standard was developed and is also included in the toolkit.

Flashing the firmware

The radio modules need to be flashed with our custom firmware, prior to using it with ZigBear.

The instructions, on how to do this, vary depending on the chosen transceiver.

RaspBee

To remotely flash the firmware of a RaspBee module, execute

$ make remote-install-firmware

On the host, docker is required for compilation of µracoli.

On the RaspberryPi, GCFFlasher_internal is required (included in the installation of deCONZ).

The SSH target for the RaspBee can be configure in the Makefile.

nRF52840

To flash a nRF52840 dongle, the nRF Connect software is required.

Detailed instructions on how to flash using nRF Connect, can be found here.

CC2531

To flash a CC2531 dongle, the CC Debugger from Texas Instruments is required.

Detailed instructions on how to flash using the CC Debugger can be found here.

Launching ZigBear

To launch the ZigBear Python CLI locally, simply execute

$ make run

Requires python3, pipenv and optionally tkinter for the virtual lamp

Remote execution on RaspberryPi

To remotely execute ZigBear via SSH on a RaspberryPi + RaspBee, execute

$ make remote-run

Requires python3 and pipenv on the RaspberryPi.

Usage

The ZigBear CLI can be either preconfigured using command line arguments

usage: __main__.py [-h] [-L [LOG_FILE]] [-l {DEBUG,INFO,WARN,ERROR}]
[-c {nrf,cc2531,raspbee,socket}] [-d DEVICE] [-C CHANNEL]
[-w WIRESHARK_HOST] [-r RECEIVE_PORT] [-t TARGET_PORT]
ZigBear CLI
optional arguments:
-h, --help show this help message and exit
Logging:
-L [LOG_FILE], --log-file [LOG_FILE]
Log output to LOG_FILE. If -L is specified but
LOG_FILE is omitted, "zigbear.log" will be used. If
the argument is omitted altogether, logging will not
take place at all.
-l {DEBUG,INFO,WARN,ERROR}, --log-level {DEBUG,INFO,WARN,ERROR}
Log messages of severity LOG_LEVEL or higher. Only
makes sense if -L is also specified (Default: INFO)
ZigBear:
-c {nrf,cc2531,raspbee,socket}, --connector {nrf,cc2531,raspbee,socket}
configure connector type
-d DEVICE, --device DEVICE
transceive from DEVICE (Default: /dev/ttyACM0)
-C CHANNEL, --channel CHANNEL
radio channel for listening and sending (Default: 25)
-w WIRESHARK_HOST, --wireshark-host WIRESHARK_HOST
wireshark host (Default: 127.0.0.1)
-r RECEIVE_PORT, --receive-port RECEIVE_PORT
receive port for the socket connector (Default: 8080)
-t TARGET_PORT, --target-port TARGET_PORT
target port for the socket connector (Default: 9090)

or interactively configured using the CLI commands after launching ZigBear

Select a connector

To select the connector for your hardware, execute

connector <connector> 

<connector> must be one of the following options:

  • nrf
  • cc2531
  • raspbee
  • socket

Select a channel

After selecting a connector you can choose a radio channel

channel <number>

<number> must be between and including 11 and 25.

Send raw data

With the selected channel you can now start to transmit raw data (hexadecimal string) using the send command

send <hexadecimalString>

Custom protocol

An application communicates with our custom protocol stack, which consists of the following layers.

Protocol Stack

The MAC Layer communicates via one of the connectors with the hardware and vice versa.

MAC Layer

The MAC layer of the IEEE 802.15.4 protocol is used. This layer sends and receives data directly using one of the radio connectors.

Network Layer

The Network Layer has several tasks. One is the partitioning of packages which exceed the maximum size of 80 byte. Another task is to send ACK packages. A retry mechanism is implemented to send packages again if no response was received.

Security Layer

The Security Layer handles encryption and decryption of packages.

For the encryption and decryption of packets, that are exchanged between devices that share a network key, the symmetric encoding AES-GCM is used. Advanced Encryption Standard (AES) is a block cipher which decodes 16 byte blocks with byte substitution, permutations and transformations. For these operations a key with a length of 128, 192 or 256 Bit is used.

As AES-GCM is an authenticated encryption algorithm, it is also capable of providing integrity via the authentication tag, that is produced as a result of it. If an encrypted message has an invalid authentication tag, it will not be decrypted or relayed to the application layer.

To exchange the network key the Elliptic Curve Diffie-Hellman (ECDH) algorithm is used. The communication partners exchange their public keys and calculate a shared key using their private keys. This shared key is passed through HKDF to turn it into a cryptographically stronger key.

Key Exchange

The exchange of the actual network key is encrypted using the key derived from the shared key. This secure channel could also be used for negotiating different details of the connection in the future. After the network key is exchaged, any keys relating to that exchange are dropped by both communication partners. A new set of keys has to be generated for each exchange, thus providing forward secrecy for key exchanges.

Application Layer

The Application Layer offers a socket interface for the development of high level applications. It consists of a Session and a Listener class where Session has methods to send a network key and a initiation package and Listener has methods to register and connect to a broadcast. Both can send and receive packages.

Example application

The projects comes with a virtual lamp as an example application for our custom protocol. By sending messages between two ZigBear instances, where one acts as device and the other one as coordinator, the "lamp" (a colored GUI window) can be switched off, on or set to specific brightness values.

To test the lamp in combination with a coordinator, follow these steps:

  • Launch two instances of ZigBear from the project directory with
$ make run
  • Use UDP connector (socket), for simplicity.
  • Enter inverse send and receive ports on the two clients.
  • Launch one client into device mode and the other into coordinator mode.
  • Enter info on the device client to display its random address (in the following steps named as <device_address>).
  • Perform the following commands on the coordinator client to pair it with the device client.
initiate <device_address> sendkey <device_address>
  • Start the virtual lamp example application on the device client with the command lamp
  • Control the lamp by sending on of the following commands from the coordinator client to the device client:
toggle <device_address>
brightness <device_address> <brightness>

Future enhancements

Development of ZigBear is on-going, and there is still much to do.

Some of the things that could be interesting to work on, in no particular order, are listed below:

  • ZigBee Light Link attacks
  • Automated network join attacks
  • Remote factory reset attacks
  • Remote firmware update attacks
  • Formal verification of custom protocol
  • Authorization for custom protocol

Resources

Inspirations

About

🐝 Zigbee security research toolkit for the RaspBee, nRF52840 and CC2531 radio modules.

Topics

Resources

Stars

40 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - philippnormann/zigbear: 🐝 Zigbee security research toolkit for the RaspBee, nRF52840 and CC2531 radio modules. · GitHub
Skip to content

Repository files navigation

ZigBear 🐻

A Zigbee security research toolkit for the RaspBee, nRF52840 and CC2531 radio modules.

In order to develop and test improved network join procedures using asymmetric encryption, a custom proof of concept protocol based on the IEEE 802.15.4 standard was developed and is also included in the toolkit.

Flashing the firmware

The radio modules need to be flashed with our custom firmware, prior to using it with ZigBear.

The instructions, on how to do this, vary depending on the chosen transceiver.

RaspBee

To remotely flash the firmware of a RaspBee module, execute

$ make remote-install-firmware

On the host, docker is required for compilation of µracoli.

On the RaspberryPi, GCFFlasher_internal is required (included in the installation of deCONZ).

The SSH target for the RaspBee can be configure in the Makefile.

nRF52840

To flash a nRF52840 dongle, the nRF Connect software is required.

Detailed instructions on how to flash using nRF Connect, can be found here.

CC2531

To flash a CC2531 dongle, the CC Debugger from Texas Instruments is required.

Detailed instructions on how to flash using the CC Debugger can be found here.

Launching ZigBear

To launch the ZigBear Python CLI locally, simply execute

$ make run

Requires python3, pipenv and optionally tkinter for the virtual lamp

Remote execution on RaspberryPi

To remotely execute ZigBear via SSH on a RaspberryPi + RaspBee, execute

$ make remote-run

Requires python3 and pipenv on the RaspberryPi.

Usage

The ZigBear CLI can be either preconfigured using command line arguments

usage: __main__.py [-h] [-L [LOG_FILE]] [-l {DEBUG,INFO,WARN,ERROR}]
[-c {nrf,cc2531,raspbee,socket}] [-d DEVICE] [-C CHANNEL]
[-w WIRESHARK_HOST] [-r RECEIVE_PORT] [-t TARGET_PORT]
ZigBear CLI
optional arguments:
-h, --help show this help message and exit
Logging:
-L [LOG_FILE], --log-file [LOG_FILE]
Log output to LOG_FILE. If -L is specified but
LOG_FILE is omitted, "zigbear.log" will be used. If
the argument is omitted altogether, logging will not
take place at all.
-l {DEBUG,INFO,WARN,ERROR}, --log-level {DEBUG,INFO,WARN,ERROR}
Log messages of severity LOG_LEVEL or higher. Only
makes sense if -L is also specified (Default: INFO)
ZigBear:
-c {nrf,cc2531,raspbee,socket}, --connector {nrf,cc2531,raspbee,socket}
configure connector type
-d DEVICE, --device DEVICE
transceive from DEVICE (Default: /dev/ttyACM0)
-C CHANNEL, --channel CHANNEL
radio channel for listening and sending (Default: 25)
-w WIRESHARK_HOST, --wireshark-host WIRESHARK_HOST
wireshark host (Default: 127.0.0.1)
-r RECEIVE_PORT, --receive-port RECEIVE_PORT
receive port for the socket connector (Default: 8080)
-t TARGET_PORT, --target-port TARGET_PORT
target port for the socket connector (Default: 9090)

or interactively configured using the CLI commands after launching ZigBear

Select a connector

To select the connector for your hardware, execute

connector <connector> 

<connector> must be one of the following options:

  • nrf
  • cc2531
  • raspbee
  • socket

Select a channel

After selecting a connector you can choose a radio channel

channel <number>

<number> must be between and including 11 and 25.

Send raw data

With the selected channel you can now start to transmit raw data (hexadecimal string) using the send command

send <hexadecimalString>

Custom protocol

An application communicates with our custom protocol stack, which consists of the following layers.

Protocol Stack

The MAC Layer communicates via one of the connectors with the hardware and vice versa.

MAC Layer

The MAC layer of the IEEE 802.15.4 protocol is used. This layer sends and receives data directly using one of the radio connectors.

Network Layer

The Network Layer has several tasks. One is the partitioning of packages which exceed the maximum size of 80 byte. Another task is to send ACK packages. A retry mechanism is implemented to send packages again if no response was received.

Security Layer

The Security Layer handles encryption and decryption of packages.

For the encryption and decryption of packets, that are exchanged between devices that share a network key, the symmetric encoding AES-GCM is used. Advanced Encryption Standard (AES) is a block cipher which decodes 16 byte blocks with byte substitution, permutations and transformations. For these operations a key with a length of 128, 192 or 256 Bit is used.

As AES-GCM is an authenticated encryption algorithm, it is also capable of providing integrity via the authentication tag, that is produced as a result of it. If an encrypted message has an invalid authentication tag, it will not be decrypted or relayed to the application layer.

To exchange the network key the Elliptic Curve Diffie-Hellman (ECDH) algorithm is used. The communication partners exchange their public keys and calculate a shared key using their private keys. This shared key is passed through HKDF to turn it into a cryptographically stronger key.

Key Exchange

The exchange of the actual network key is encrypted using the key derived from the shared key. This secure channel could also be used for negotiating different details of the connection in the future. After the network key is exchaged, any keys relating to that exchange are dropped by both communication partners. A new set of keys has to be generated for each exchange, thus providing forward secrecy for key exchanges.

Application Layer

The Application Layer offers a socket interface for the development of high level applications. It consists of a Session and a Listener class where Session has methods to send a network key and a initiation package and Listener has methods to register and connect to a broadcast. Both can send and receive packages.

Example application

The projects comes with a virtual lamp as an example application for our custom protocol. By sending messages between two ZigBear instances, where one acts as device and the other one as coordinator, the "lamp" (a colored GUI window) can be switched off, on or set to specific brightness values.

To test the lamp in combination with a coordinator, follow these steps:

  • Launch two instances of ZigBear from the project directory with
$ make run
  • Use UDP connector (socket), for simplicity.
  • Enter inverse send and receive ports on the two clients.
  • Launch one client into device mode and the other into coordinator mode.
  • Enter info on the device client to display its random address (in the following steps named as <device_address>).
  • Perform the following commands on the coordinator client to pair it with the device client.
initiate <device_address> sendkey <device_address>
  • Start the virtual lamp example application on the device client with the command lamp
  • Control the lamp by sending on of the following commands from the coordinator client to the device client:
toggle <device_address>
brightness <device_address> <brightness>

Future enhancements

Development of ZigBear is on-going, and there is still much to do.

Some of the things that could be interesting to work on, in no particular order, are listed below:

  • ZigBee Light Link attacks
  • Automated network join attacks
  • Remote factory reset attacks
  • Remote firmware update attacks
  • Formal verification of custom protocol
  • Authorization for custom protocol

Resources

Inspirations

About

🐝 Zigbee security research toolkit for the RaspBee, nRF52840 and CC2531 radio modules.

Topics

Resources

Stars

40 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - philippnormann/zigbear: 🐝 Zigbee security research toolkit for the RaspBee, nRF52840 and CC2531 radio modules. · GitHub
Skip to content

Repository files navigation

ZigBear 🐻

A Zigbee security research toolkit for the RaspBee, nRF52840 and CC2531 radio modules.

In order to develop and test improved network join procedures using asymmetric encryption, a custom proof of concept protocol based on the IEEE 802.15.4 standard was developed and is also included in the toolkit.

Flashing the firmware

The radio modules need to be flashed with our custom firmware, prior to using it with ZigBear.

The instructions, on how to do this, vary depending on the chosen transceiver.

RaspBee

To remotely flash the firmware of a RaspBee module, execute

$ make remote-install-firmware

On the host, docker is required for compilation of µracoli.

On the RaspberryPi, GCFFlasher_internal is required (included in the installation of deCONZ).

The SSH target for the RaspBee can be configure in the Makefile.

nRF52840

To flash a nRF52840 dongle, the nRF Connect software is required.

Detailed instructions on how to flash using nRF Connect, can be found here.

CC2531

To flash a CC2531 dongle, the CC Debugger from Texas Instruments is required.

Detailed instructions on how to flash using the CC Debugger can be found here.

Launching ZigBear

To launch the ZigBear Python CLI locally, simply execute

$ make run

Requires python3, pipenv and optionally tkinter for the virtual lamp

Remote execution on RaspberryPi

To remotely execute ZigBear via SSH on a RaspberryPi + RaspBee, execute

$ make remote-run

Requires python3 and pipenv on the RaspberryPi.

Usage

The ZigBear CLI can be either preconfigured using command line arguments

usage: __main__.py [-h] [-L [LOG_FILE]] [-l {DEBUG,INFO,WARN,ERROR}]
[-c {nrf,cc2531,raspbee,socket}] [-d DEVICE] [-C CHANNEL]
[-w WIRESHARK_HOST] [-r RECEIVE_PORT] [-t TARGET_PORT]
ZigBear CLI
optional arguments:
-h, --help show this help message and exit
Logging:
-L [LOG_FILE], --log-file [LOG_FILE]
Log output to LOG_FILE. If -L is specified but
LOG_FILE is omitted, "zigbear.log" will be used. If
the argument is omitted altogether, logging will not
take place at all.
-l {DEBUG,INFO,WARN,ERROR}, --log-level {DEBUG,INFO,WARN,ERROR}
Log messages of severity LOG_LEVEL or higher. Only
makes sense if -L is also specified (Default: INFO)
ZigBear:
-c {nrf,cc2531,raspbee,socket}, --connector {nrf,cc2531,raspbee,socket}
configure connector type
-d DEVICE, --device DEVICE
transceive from DEVICE (Default: /dev/ttyACM0)
-C CHANNEL, --channel CHANNEL
radio channel for listening and sending (Default: 25)
-w WIRESHARK_HOST, --wireshark-host WIRESHARK_HOST
wireshark host (Default: 127.0.0.1)
-r RECEIVE_PORT, --receive-port RECEIVE_PORT
receive port for the socket connector (Default: 8080)
-t TARGET_PORT, --target-port TARGET_PORT
target port for the socket connector (Default: 9090)

or interactively configured using the CLI commands after launching ZigBear

Select a connector

To select the connector for your hardware, execute

connector <connector> 

<connector> must be one of the following options:

  • nrf
  • cc2531
  • raspbee
  • socket

Select a channel

After selecting a connector you can choose a radio channel

channel <number>

<number> must be between and including 11 and 25.

Send raw data

With the selected channel you can now start to transmit raw data (hexadecimal string) using the send command

send <hexadecimalString>

Custom protocol

An application communicates with our custom protocol stack, which consists of the following layers.

Protocol Stack

The MAC Layer communicates via one of the connectors with the hardware and vice versa.

MAC Layer

The MAC layer of the IEEE 802.15.4 protocol is used. This layer sends and receives data directly using one of the radio connectors.

Network Layer

The Network Layer has several tasks. One is the partitioning of packages which exceed the maximum size of 80 byte. Another task is to send ACK packages. A retry mechanism is implemented to send packages again if no response was received.

Security Layer

The Security Layer handles encryption and decryption of packages.

For the encryption and decryption of packets, that are exchanged between devices that share a network key, the symmetric encoding AES-GCM is used. Advanced Encryption Standard (AES) is a block cipher which decodes 16 byte blocks with byte substitution, permutations and transformations. For these operations a key with a length of 128, 192 or 256 Bit is used.

As AES-GCM is an authenticated encryption algorithm, it is also capable of providing integrity via the authentication tag, that is produced as a result of it. If an encrypted message has an invalid authentication tag, it will not be decrypted or relayed to the application layer.

To exchange the network key the Elliptic Curve Diffie-Hellman (ECDH) algorithm is used. The communication partners exchange their public keys and calculate a shared key using their private keys. This shared key is passed through HKDF to turn it into a cryptographically stronger key.

Key Exchange

The exchange of the actual network key is encrypted using the key derived from the shared key. This secure channel could also be used for negotiating different details of the connection in the future. After the network key is exchaged, any keys relating to that exchange are dropped by both communication partners. A new set of keys has to be generated for each exchange, thus providing forward secrecy for key exchanges.

Application Layer

The Application Layer offers a socket interface for the development of high level applications. It consists of a Session and a Listener class where Session has methods to send a network key and a initiation package and Listener has methods to register and connect to a broadcast. Both can send and receive packages.

Example application

The projects comes with a virtual lamp as an example application for our custom protocol. By sending messages between two ZigBear instances, where one acts as device and the other one as coordinator, the "lamp" (a colored GUI window) can be switched off, on or set to specific brightness values.

To test the lamp in combination with a coordinator, follow these steps:

  • Launch two instances of ZigBear from the project directory with
$ make run
  • Use UDP connector (socket), for simplicity.
  • Enter inverse send and receive ports on the two clients.
  • Launch one client into device mode and the other into coordinator mode.
  • Enter info on the device client to display its random address (in the following steps named as <device_address>).
  • Perform the following commands on the coordinator client to pair it with the device client.
initiate <device_address> sendkey <device_address>
  • Start the virtual lamp example application on the device client with the command lamp
  • Control the lamp by sending on of the following commands from the coordinator client to the device client:
toggle <device_address>
brightness <device_address> <brightness>

Future enhancements

Development of ZigBear is on-going, and there is still much to do.

Some of the things that could be interesting to work on, in no particular order, are listed below:

  • ZigBee Light Link attacks
  • Automated network join attacks
  • Remote factory reset attacks
  • Remote firmware update attacks
  • Formal verification of custom protocol
  • Authorization for custom protocol

Resources

Inspirations

About

🐝 Zigbee security research toolkit for the RaspBee, nRF52840 and CC2531 radio modules.

Topics

Resources

Stars

40 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' GitHub - philippnormann/zigbear: 🐝 Zigbee security research toolkit for the RaspBee, nRF52840 and CC2531 radio modules. · GitHub
Skip to content

Repository files navigation

ZigBear 🐻

A Zigbee security research toolkit for the RaspBee, nRF52840 and CC2531 radio modules.

In order to develop and test improved network join procedures using asymmetric encryption, a custom proof of concept protocol based on the IEEE 802.15.4 standard was developed and is also included in the toolkit.

Flashing the firmware

The radio modules need to be flashed with our custom firmware, prior to using it with ZigBear.

The instructions, on how to do this, vary depending on the chosen transceiver.

RaspBee

To remotely flash the firmware of a RaspBee module, execute

$ make remote-install-firmware

On the host, docker is required for compilation of µracoli.

On the RaspberryPi, GCFFlasher_internal is required (included in the installation of deCONZ).

The SSH target for the RaspBee can be configure in the Makefile.

nRF52840

To flash a nRF52840 dongle, the nRF Connect software is required.

Detailed instructions on how to flash using nRF Connect, can be found here.

CC2531

To flash a CC2531 dongle, the CC Debugger from Texas Instruments is required.

Detailed instructions on how to flash using the CC Debugger can be found here.

Launching ZigBear

To launch the ZigBear Python CLI locally, simply execute

$ make run

Requires python3, pipenv and optionally tkinter for the virtual lamp

Remote execution on RaspberryPi

To remotely execute ZigBear via SSH on a RaspberryPi + RaspBee, execute

$ make remote-run

Requires python3 and pipenv on the RaspberryPi.

Usage

The ZigBear CLI can be either preconfigured using command line arguments

usage: __main__.py [-h] [-L [LOG_FILE]] [-l {DEBUG,INFO,WARN,ERROR}]
[-c {nrf,cc2531,raspbee,socket}] [-d DEVICE] [-C CHANNEL]
[-w WIRESHARK_HOST] [-r RECEIVE_PORT] [-t TARGET_PORT]
ZigBear CLI
optional arguments:
-h, --help show this help message and exit
Logging:
-L [LOG_FILE], --log-file [LOG_FILE]
Log output to LOG_FILE. If -L is specified but
LOG_FILE is omitted, "zigbear.log" will be used. If
the argument is omitted altogether, logging will not
take place at all.
-l {DEBUG,INFO,WARN,ERROR}, --log-level {DEBUG,INFO,WARN,ERROR}
Log messages of severity LOG_LEVEL or higher. Only
makes sense if -L is also specified (Default: INFO)
ZigBear:
-c {nrf,cc2531,raspbee,socket}, --connector {nrf,cc2531,raspbee,socket}
configure connector type
-d DEVICE, --device DEVICE
transceive from DEVICE (Default: /dev/ttyACM0)
-C CHANNEL, --channel CHANNEL
radio channel for listening and sending (Default: 25)
-w WIRESHARK_HOST, --wireshark-host WIRESHARK_HOST
wireshark host (Default: 127.0.0.1)
-r RECEIVE_PORT, --receive-port RECEIVE_PORT
receive port for the socket connector (Default: 8080)
-t TARGET_PORT, --target-port TARGET_PORT
target port for the socket connector (Default: 9090)

or interactively configured using the CLI commands after launching ZigBear

Select a connector

To select the connector for your hardware, execute

connector <connector> 

<connector> must be one of the following options:

  • nrf
  • cc2531
  • raspbee
  • socket

Select a channel

After selecting a connector you can choose a radio channel

channel <number>

<number> must be between and including 11 and 25.

Send raw data

With the selected channel you can now start to transmit raw data (hexadecimal string) using the send command

send <hexadecimalString>

Custom protocol

An application communicates with our custom protocol stack, which consists of the following layers.

Protocol Stack

The MAC Layer communicates via one of the connectors with the hardware and vice versa.

MAC Layer

The MAC layer of the IEEE 802.15.4 protocol is used. This layer sends and receives data directly using one of the radio connectors.

Network Layer

The Network Layer has several tasks. One is the partitioning of packages which exceed the maximum size of 80 byte. Another task is to send ACK packages. A retry mechanism is implemented to send packages again if no response was received.

Security Layer

The Security Layer handles encryption and decryption of packages.

For the encryption and decryption of packets, that are exchanged between devices that share a network key, the symmetric encoding AES-GCM is used. Advanced Encryption Standard (AES) is a block cipher which decodes 16 byte blocks with byte substitution, permutations and transformations. For these operations a key with a length of 128, 192 or 256 Bit is used.

As AES-GCM is an authenticated encryption algorithm, it is also capable of providing integrity via the authentication tag, that is produced as a result of it. If an encrypted message has an invalid authentication tag, it will not be decrypted or relayed to the application layer.

To exchange the network key the Elliptic Curve Diffie-Hellman (ECDH) algorithm is used. The communication partners exchange their public keys and calculate a shared key using their private keys. This shared key is passed through HKDF to turn it into a cryptographically stronger key.

Key Exchange

The exchange of the actual network key is encrypted using the key derived from the shared key. This secure channel could also be used for negotiating different details of the connection in the future. After the network key is exchaged, any keys relating to that exchange are dropped by both communication partners. A new set of keys has to be generated for each exchange, thus providing forward secrecy for key exchanges.

Application Layer

The Application Layer offers a socket interface for the development of high level applications. It consists of a Session and a Listener class where Session has methods to send a network key and a initiation package and Listener has methods to register and connect to a broadcast. Both can send and receive packages.

Example application

The projects comes with a virtual lamp as an example application for our custom protocol. By sending messages between two ZigBear instances, where one acts as device and the other one as coordinator, the "lamp" (a colored GUI window) can be switched off, on or set to specific brightness values.

To test the lamp in combination with a coordinator, follow these steps:

  • Launch two instances of ZigBear from the project directory with
$ make run
  • Use UDP connector (socket), for simplicity.
  • Enter inverse send and receive ports on the two clients.
  • Launch one client into device mode and the other into coordinator mode.
  • Enter info on the device client to display its random address (in the following steps named as <device_address>).
  • Perform the following commands on the coordinator client to pair it with the device client.
initiate <device_address> sendkey <device_address>
  • Start the virtual lamp example application on the device client with the command lamp
  • Control the lamp by sending on of the following commands from the coordinator client to the device client:
toggle <device_address>
brightness <device_address> <brightness>

Future enhancements

Development of ZigBear is on-going, and there is still much to do.

Some of the things that could be interesting to work on, in no particular order, are listed below:

  • ZigBee Light Link attacks
  • Automated network join attacks
  • Remote factory reset attacks
  • Remote firmware update attacks
  • Formal verification of custom protocol
  • Authorization for custom protocol

Resources

Inspirations

About

🐝 Zigbee security research toolkit for the RaspBee, nRF52840 and CC2531 radio modules.

Topics

Resources

Stars

40 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - philippnormann/zigbear: 🐝 Zigbee security research toolkit for the RaspBee, nRF52840 and CC2531 radio modules. · GitHub
Skip to content

Repository files navigation

ZigBear 🐻

A Zigbee security research toolkit for the RaspBee, nRF52840 and CC2531 radio modules.

In order to develop and test improved network join procedures using asymmetric encryption, a custom proof of concept protocol based on the IEEE 802.15.4 standard was developed and is also included in the toolkit.

Flashing the firmware

The radio modules need to be flashed with our custom firmware, prior to using it with ZigBear.

The instructions, on how to do this, vary depending on the chosen transceiver.

RaspBee

To remotely flash the firmware of a RaspBee module, execute

$ make remote-install-firmware

On the host, docker is required for compilation of µracoli.

On the RaspberryPi, GCFFlasher_internal is required (included in the installation of deCONZ).

The SSH target for the RaspBee can be configure in the Makefile.

nRF52840

To flash a nRF52840 dongle, the nRF Connect software is required.

Detailed instructions on how to flash using nRF Connect, can be found here.

CC2531

To flash a CC2531 dongle, the CC Debugger from Texas Instruments is required.

Detailed instructions on how to flash using the CC Debugger can be found here.

Launching ZigBear

To launch the ZigBear Python CLI locally, simply execute

$ make run

Requires python3, pipenv and optionally tkinter for the virtual lamp

Remote execution on RaspberryPi

To remotely execute ZigBear via SSH on a RaspberryPi + RaspBee, execute

$ make remote-run

Requires python3 and pipenv on the RaspberryPi.

Usage

The ZigBear CLI can be either preconfigured using command line arguments

usage: __main__.py [-h] [-L [LOG_FILE]] [-l {DEBUG,INFO,WARN,ERROR}]
[-c {nrf,cc2531,raspbee,socket}] [-d DEVICE] [-C CHANNEL]
[-w WIRESHARK_HOST] [-r RECEIVE_PORT] [-t TARGET_PORT]
ZigBear CLI
optional arguments:
-h, --help show this help message and exit
Logging:
-L [LOG_FILE], --log-file [LOG_FILE]
Log output to LOG_FILE. If -L is specified but
LOG_FILE is omitted, "zigbear.log" will be used. If
the argument is omitted altogether, logging will not
take place at all.
-l {DEBUG,INFO,WARN,ERROR}, --log-level {DEBUG,INFO,WARN,ERROR}
Log messages of severity LOG_LEVEL or higher. Only
makes sense if -L is also specified (Default: INFO)
ZigBear:
-c {nrf,cc2531,raspbee,socket}, --connector {nrf,cc2531,raspbee,socket}
configure connector type
-d DEVICE, --device DEVICE
transceive from DEVICE (Default: /dev/ttyACM0)
-C CHANNEL, --channel CHANNEL
radio channel for listening and sending (Default: 25)
-w WIRESHARK_HOST, --wireshark-host WIRESHARK_HOST
wireshark host (Default: 127.0.0.1)
-r RECEIVE_PORT, --receive-port RECEIVE_PORT
receive port for the socket connector (Default: 8080)
-t TARGET_PORT, --target-port TARGET_PORT
target port for the socket connector (Default: 9090)

or interactively configured using the CLI commands after launching ZigBear

Select a connector

To select the connector for your hardware, execute

connector <connector> 

<connector> must be one of the following options:

  • nrf
  • cc2531
  • raspbee
  • socket

Select a channel

After selecting a connector you can choose a radio channel

channel <number>

<number> must be between and including 11 and 25.

Send raw data

With the selected channel you can now start to transmit raw data (hexadecimal string) using the send command

send <hexadecimalString>

Custom protocol

An application communicates with our custom protocol stack, which consists of the following layers.

Protocol Stack

The MAC Layer communicates via one of the connectors with the hardware and vice versa.

MAC Layer

The MAC layer of the IEEE 802.15.4 protocol is used. This layer sends and receives data directly using one of the radio connectors.

Network Layer

The Network Layer has several tasks. One is the partitioning of packages which exceed the maximum size of 80 byte. Another task is to send ACK packages. A retry mechanism is implemented to send packages again if no response was received.

Security Layer

The Security Layer handles encryption and decryption of packages.

For the encryption and decryption of packets, that are exchanged between devices that share a network key, the symmetric encoding AES-GCM is used. Advanced Encryption Standard (AES) is a block cipher which decodes 16 byte blocks with byte substitution, permutations and transformations. For these operations a key with a length of 128, 192 or 256 Bit is used.

As AES-GCM is an authenticated encryption algorithm, it is also capable of providing integrity via the authentication tag, that is produced as a result of it. If an encrypted message has an invalid authentication tag, it will not be decrypted or relayed to the application layer.

To exchange the network key the Elliptic Curve Diffie-Hellman (ECDH) algorithm is used. The communication partners exchange their public keys and calculate a shared key using their private keys. This shared key is passed through HKDF to turn it into a cryptographically stronger key.

Key Exchange

The exchange of the actual network key is encrypted using the key derived from the shared key. This secure channel could also be used for negotiating different details of the connection in the future. After the network key is exchaged, any keys relating to that exchange are dropped by both communication partners. A new set of keys has to be generated for each exchange, thus providing forward secrecy for key exchanges.

Application Layer

The Application Layer offers a socket interface for the development of high level applications. It consists of a Session and a Listener class where Session has methods to send a network key and a initiation package and Listener has methods to register and connect to a broadcast. Both can send and receive packages.

Example application

The projects comes with a virtual lamp as an example application for our custom protocol. By sending messages between two ZigBear instances, where one acts as device and the other one as coordinator, the "lamp" (a colored GUI window) can be switched off, on or set to specific brightness values.

To test the lamp in combination with a coordinator, follow these steps:

  • Launch two instances of ZigBear from the project directory with
$ make run
  • Use UDP connector (socket), for simplicity.
  • Enter inverse send and receive ports on the two clients.
  • Launch one client into device mode and the other into coordinator mode.
  • Enter info on the device client to display its random address (in the following steps named as <device_address>).
  • Perform the following commands on the coordinator client to pair it with the device client.
initiate <device_address> sendkey <device_address>
  • Start the virtual lamp example application on the device client with the command lamp
  • Control the lamp by sending on of the following commands from the coordinator client to the device client:
toggle <device_address>
brightness <device_address> <brightness>

Future enhancements

Development of ZigBear is on-going, and there is still much to do.

Some of the things that could be interesting to work on, in no particular order, are listed below:

  • ZigBee Light Link attacks
  • Automated network join attacks
  • Remote factory reset attacks
  • Remote firmware update attacks
  • Formal verification of custom protocol
  • Authorization for custom protocol

Resources

Inspirations

About

🐝 Zigbee security research toolkit for the RaspBee, nRF52840 and CC2531 radio modules.

Topics

Resources

Stars

40 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - philippnormann/zigbear: 🐝 Zigbee security research toolkit for the RaspBee, nRF52840 and CC2531 radio modules. · GitHub
Skip to content

Repository files navigation

ZigBear 🐻

A Zigbee security research toolkit for the RaspBee, nRF52840 and CC2531 radio modules.

In order to develop and test improved network join procedures using asymmetric encryption, a custom proof of concept protocol based on the IEEE 802.15.4 standard was developed and is also included in the toolkit.

Flashing the firmware

The radio modules need to be flashed with our custom firmware, prior to using it with ZigBear.

The instructions, on how to do this, vary depending on the chosen transceiver.

RaspBee

To remotely flash the firmware of a RaspBee module, execute

$ make remote-install-firmware

On the host, docker is required for compilation of µracoli.

On the RaspberryPi, GCFFlasher_internal is required (included in the installation of deCONZ).

The SSH target for the RaspBee can be configure in the Makefile.

nRF52840

To flash a nRF52840 dongle, the nRF Connect software is required.

Detailed instructions on how to flash using nRF Connect, can be found here.

CC2531

To flash a CC2531 dongle, the CC Debugger from Texas Instruments is required.

Detailed instructions on how to flash using the CC Debugger can be found here.

Launching ZigBear

To launch the ZigBear Python CLI locally, simply execute

$ make run

Requires python3, pipenv and optionally tkinter for the virtual lamp

Remote execution on RaspberryPi

To remotely execute ZigBear via SSH on a RaspberryPi + RaspBee, execute

$ make remote-run

Requires python3 and pipenv on the RaspberryPi.

Usage

The ZigBear CLI can be either preconfigured using command line arguments

usage: __main__.py [-h] [-L [LOG_FILE]] [-l {DEBUG,INFO,WARN,ERROR}]
[-c {nrf,cc2531,raspbee,socket}] [-d DEVICE] [-C CHANNEL]
[-w WIRESHARK_HOST] [-r RECEIVE_PORT] [-t TARGET_PORT]
ZigBear CLI
optional arguments:
-h, --help show this help message and exit
Logging:
-L [LOG_FILE], --log-file [LOG_FILE]
Log output to LOG_FILE. If -L is specified but
LOG_FILE is omitted, "zigbear.log" will be used. If
the argument is omitted altogether, logging will not
take place at all.
-l {DEBUG,INFO,WARN,ERROR}, --log-level {DEBUG,INFO,WARN,ERROR}
Log messages of severity LOG_LEVEL or higher. Only
makes sense if -L is also specified (Default: INFO)
ZigBear:
-c {nrf,cc2531,raspbee,socket}, --connector {nrf,cc2531,raspbee,socket}
configure connector type
-d DEVICE, --device DEVICE
transceive from DEVICE (Default: /dev/ttyACM0)
-C CHANNEL, --channel CHANNEL
radio channel for listening and sending (Default: 25)
-w WIRESHARK_HOST, --wireshark-host WIRESHARK_HOST
wireshark host (Default: 127.0.0.1)
-r RECEIVE_PORT, --receive-port RECEIVE_PORT
receive port for the socket connector (Default: 8080)
-t TARGET_PORT, --target-port TARGET_PORT
target port for the socket connector (Default: 9090)

or interactively configured using the CLI commands after launching ZigBear

Select a connector

To select the connector for your hardware, execute

connector <connector> 

<connector> must be one of the following options:

  • nrf
  • cc2531
  • raspbee
  • socket

Select a channel

After selecting a connector you can choose a radio channel

channel <number>

<number> must be between and including 11 and 25.

Send raw data

With the selected channel you can now start to transmit raw data (hexadecimal string) using the send command

send <hexadecimalString>

Custom protocol

An application communicates with our custom protocol stack, which consists of the following layers.

Protocol Stack

The MAC Layer communicates via one of the connectors with the hardware and vice versa.

MAC Layer

The MAC layer of the IEEE 802.15.4 protocol is used. This layer sends and receives data directly using one of the radio connectors.

Network Layer

The Network Layer has several tasks. One is the partitioning of packages which exceed the maximum size of 80 byte. Another task is to send ACK packages. A retry mechanism is implemented to send packages again if no response was received.

Security Layer

The Security Layer handles encryption and decryption of packages.

For the encryption and decryption of packets, that are exchanged between devices that share a network key, the symmetric encoding AES-GCM is used. Advanced Encryption Standard (AES) is a block cipher which decodes 16 byte blocks with byte substitution, permutations and transformations. For these operations a key with a length of 128, 192 or 256 Bit is used.

As AES-GCM is an authenticated encryption algorithm, it is also capable of providing integrity via the authentication tag, that is produced as a result of it. If an encrypted message has an invalid authentication tag, it will not be decrypted or relayed to the application layer.

To exchange the network key the Elliptic Curve Diffie-Hellman (ECDH) algorithm is used. The communication partners exchange their public keys and calculate a shared key using their private keys. This shared key is passed through HKDF to turn it into a cryptographically stronger key.

Key Exchange

The exchange of the actual network key is encrypted using the key derived from the shared key. This secure channel could also be used for negotiating different details of the connection in the future. After the network key is exchaged, any keys relating to that exchange are dropped by both communication partners. A new set of keys has to be generated for each exchange, thus providing forward secrecy for key exchanges.

Application Layer

The Application Layer offers a socket interface for the development of high level applications. It consists of a Session and a Listener class where Session has methods to send a network key and a initiation package and Listener has methods to register and connect to a broadcast. Both can send and receive packages.

Example application

The projects comes with a virtual lamp as an example application for our custom protocol. By sending messages between two ZigBear instances, where one acts as device and the other one as coordinator, the "lamp" (a colored GUI window) can be switched off, on or set to specific brightness values.

To test the lamp in combination with a coordinator, follow these steps:

  • Launch two instances of ZigBear from the project directory with
$ make run
  • Use UDP connector (socket), for simplicity.
  • Enter inverse send and receive ports on the two clients.
  • Launch one client into device mode and the other into coordinator mode.
  • Enter info on the device client to display its random address (in the following steps named as <device_address>).
  • Perform the following commands on the coordinator client to pair it with the device client.
initiate <device_address> sendkey <device_address>
  • Start the virtual lamp example application on the device client with the command lamp
  • Control the lamp by sending on of the following commands from the coordinator client to the device client:
toggle <device_address>
brightness <device_address> <brightness>

Future enhancements

Development of ZigBear is on-going, and there is still much to do.

Some of the things that could be interesting to work on, in no particular order, are listed below:

  • ZigBee Light Link attacks
  • Automated network join attacks
  • Remote factory reset attacks
  • Remote firmware update attacks
  • Formal verification of custom protocol
  • Authorization for custom protocol

Resources

Inspirations

About

🐝 Zigbee security research toolkit for the RaspBee, nRF52840 and CC2531 radio modules.

Topics

Resources

Stars

40 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); GitHub - philippnormann/zigbear: 🐝 Zigbee security research toolkit for the RaspBee, nRF52840 and CC2531 radio modules. · GitHub
Skip to content

Repository files navigation

ZigBear 🐻

A Zigbee security research toolkit for the RaspBee, nRF52840 and CC2531 radio modules.

In order to develop and test improved network join procedures using asymmetric encryption, a custom proof of concept protocol based on the IEEE 802.15.4 standard was developed and is also included in the toolkit.

Flashing the firmware

The radio modules need to be flashed with our custom firmware, prior to using it with ZigBear.

The instructions, on how to do this, vary depending on the chosen transceiver.

RaspBee

To remotely flash the firmware of a RaspBee module, execute

$ make remote-install-firmware

On the host, docker is required for compilation of µracoli.

On the RaspberryPi, GCFFlasher_internal is required (included in the installation of deCONZ).

The SSH target for the RaspBee can be configure in the Makefile.

nRF52840

To flash a nRF52840 dongle, the nRF Connect software is required.

Detailed instructions on how to flash using nRF Connect, can be found here.

CC2531

To flash a CC2531 dongle, the CC Debugger from Texas Instruments is required.

Detailed instructions on how to flash using the CC Debugger can be found here.

Launching ZigBear

To launch the ZigBear Python CLI locally, simply execute

$ make run

Requires python3, pipenv and optionally tkinter for the virtual lamp

Remote execution on RaspberryPi

To remotely execute ZigBear via SSH on a RaspberryPi + RaspBee, execute

$ make remote-run

Requires python3 and pipenv on the RaspberryPi.

Usage

The ZigBear CLI can be either preconfigured using command line arguments

usage: __main__.py [-h] [-L [LOG_FILE]] [-l {DEBUG,INFO,WARN,ERROR}]
[-c {nrf,cc2531,raspbee,socket}] [-d DEVICE] [-C CHANNEL]
[-w WIRESHARK_HOST] [-r RECEIVE_PORT] [-t TARGET_PORT]
ZigBear CLI
optional arguments:
-h, --help show this help message and exit
Logging:
-L [LOG_FILE], --log-file [LOG_FILE]
Log output to LOG_FILE. If -L is specified but
LOG_FILE is omitted, "zigbear.log" will be used. If
the argument is omitted altogether, logging will not
take place at all.
-l {DEBUG,INFO,WARN,ERROR}, --log-level {DEBUG,INFO,WARN,ERROR}
Log messages of severity LOG_LEVEL or higher. Only
makes sense if -L is also specified (Default: INFO)
ZigBear:
-c {nrf,cc2531,raspbee,socket}, --connector {nrf,cc2531,raspbee,socket}
configure connector type
-d DEVICE, --device DEVICE
transceive from DEVICE (Default: /dev/ttyACM0)
-C CHANNEL, --channel CHANNEL
radio channel for listening and sending (Default: 25)
-w WIRESHARK_HOST, --wireshark-host WIRESHARK_HOST
wireshark host (Default: 127.0.0.1)
-r RECEIVE_PORT, --receive-port RECEIVE_PORT
receive port for the socket connector (Default: 8080)
-t TARGET_PORT, --target-port TARGET_PORT
target port for the socket connector (Default: 9090)

or interactively configured using the CLI commands after launching ZigBear

Select a connector

To select the connector for your hardware, execute

connector <connector> 

<connector> must be one of the following options:

  • nrf
  • cc2531
  • raspbee
  • socket

Select a channel

After selecting a connector you can choose a radio channel

channel <number>

<number> must be between and including 11 and 25.

Send raw data

With the selected channel you can now start to transmit raw data (hexadecimal string) using the send command

send <hexadecimalString>

Custom protocol

An application communicates with our custom protocol stack, which consists of the following layers.

Protocol Stack

The MAC Layer communicates via one of the connectors with the hardware and vice versa.

MAC Layer

The MAC layer of the IEEE 802.15.4 protocol is used. This layer sends and receives data directly using one of the radio connectors.

Network Layer

The Network Layer has several tasks. One is the partitioning of packages which exceed the maximum size of 80 byte. Another task is to send ACK packages. A retry mechanism is implemented to send packages again if no response was received.

Security Layer

The Security Layer handles encryption and decryption of packages.

For the encryption and decryption of packets, that are exchanged between devices that share a network key, the symmetric encoding AES-GCM is used. Advanced Encryption Standard (AES) is a block cipher which decodes 16 byte blocks with byte substitution, permutations and transformations. For these operations a key with a length of 128, 192 or 256 Bit is used.

As AES-GCM is an authenticated encryption algorithm, it is also capable of providing integrity via the authentication tag, that is produced as a result of it. If an encrypted message has an invalid authentication tag, it will not be decrypted or relayed to the application layer.

To exchange the network key the Elliptic Curve Diffie-Hellman (ECDH) algorithm is used. The communication partners exchange their public keys and calculate a shared key using their private keys. This shared key is passed through HKDF to turn it into a cryptographically stronger key.

Key Exchange

The exchange of the actual network key is encrypted using the key derived from the shared key. This secure channel could also be used for negotiating different details of the connection in the future. After the network key is exchaged, any keys relating to that exchange are dropped by both communication partners. A new set of keys has to be generated for each exchange, thus providing forward secrecy for key exchanges.

Application Layer

The Application Layer offers a socket interface for the development of high level applications. It consists of a Session and a Listener class where Session has methods to send a network key and a initiation package and Listener has methods to register and connect to a broadcast. Both can send and receive packages.

Example application

The projects comes with a virtual lamp as an example application for our custom protocol. By sending messages between two ZigBear instances, where one acts as device and the other one as coordinator, the "lamp" (a colored GUI window) can be switched off, on or set to specific brightness values.

To test the lamp in combination with a coordinator, follow these steps:

  • Launch two instances of ZigBear from the project directory with
$ make run
  • Use UDP connector (socket), for simplicity.
  • Enter inverse send and receive ports on the two clients.
  • Launch one client into device mode and the other into coordinator mode.
  • Enter info on the device client to display its random address (in the following steps named as <device_address>).
  • Perform the following commands on the coordinator client to pair it with the device client.
initiate <device_address> sendkey <device_address>
  • Start the virtual lamp example application on the device client with the command lamp
  • Control the lamp by sending on of the following commands from the coordinator client to the device client:
toggle <device_address>
brightness <device_address> <brightness>

Future enhancements

Development of ZigBear is on-going, and there is still much to do.

Some of the things that could be interesting to work on, in no particular order, are listed below:

  • ZigBee Light Link attacks
  • Automated network join attacks
  • Remote factory reset attacks
  • Remote firmware update attacks
  • Formal verification of custom protocol
  • Authorization for custom protocol

Resources

Inspirations

About

🐝 Zigbee security research toolkit for the RaspBee, nRF52840 and CC2531 radio modules.

Topics

Resources

Stars

40 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages