<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Suggest bonding model where central is exposed to public and lacks meaningful IO, the peripheral is private and has good IO, and NFC isn&amp;#39;t available</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/39482/suggest-bonding-model-where-central-is-exposed-to-public-and-lacks-meaningful-io-the-peripheral-is-private-and-has-good-io-and-nfc-isn-t-available</link><description>Nordic Semiconductor-ites and fellow forum members have yet to steer me wrong so here we go. 
 My product has 52832 on both sides. The central and its 21col x 2 row LCD display are publicly viewable and accessible... and irrelevant because I can&amp;#39;t touch</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Wed, 17 Oct 2018 17:53:19 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/39482/suggest-bonding-model-where-central-is-exposed-to-public-and-lacks-meaningful-io-the-peripheral-is-private-and-has-good-io-and-nfc-isn-t-available" /><item><title>RE: Suggest bonding model where central is exposed to public and lacks meaningful IO, the peripheral is private and has good IO, and NFC isn't available</title><link>https://devzone.nordicsemi.com/thread/153336?ContentTypeID=1</link><pubDate>Wed, 17 Oct 2018 17:53:19 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:8cbf98f9-6ca5-4574-a16b-c24a9d9a067b</guid><dc:creator>howard n2wx</dc:creator><description>&lt;p&gt;Thank you. I was afraid that&amp;#39;d be the answer.&amp;nbsp; I&amp;#39;m going to need to authenticate the peripheral in some other way because the central&amp;#39;s physical security can&amp;#39;t be assured.&amp;nbsp; Seems I need to persuade the hardware guys into giving me some i/o on the central, perhaps a physical key lock, so that I can inhibit pairing unless the key is in the lock when the devices are introduced to each other.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Suggest bonding model where central is exposed to public and lacks meaningful IO, the peripheral is private and has good IO, and NFC isn't available</title><link>https://devzone.nordicsemi.com/thread/153307?ContentTypeID=1</link><pubDate>Wed, 17 Oct 2018 15:17:29 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:e5a266ed-68b7-4936-bb79-e18bb9ee699a</guid><dc:creator>Sigurd</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;Without any&amp;nbsp;IO Capabilities on the central side you are limited to &amp;quot;Just Works&amp;quot; bonding. See &lt;a href="https://infocenter.nordicsemi.com/topic/com.nordic.infocenter.sdk5.v15.2.0/lib_pm_usage.html?cp=4_0_0_3_2_7_2_1#lib_pm_usage_security"&gt;this link&lt;/a&gt; on how the Peer Manager should be configured for that. See &lt;a href="https://www.digikey.com/eewiki/display/Wireless/A+Basic+Introduction+to+BLE+Security"&gt;this link&lt;/a&gt; for a introduction to BLE security.&lt;/p&gt;
&lt;p&gt;Relation Between Pairing Methods and I/O capabilities(from BLE spec 4.2 [Vol 3, Part H] page 611):&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt=" " src="https://devzone.nordicsemi.com/resized-image/__size/640x480/__key/communityserver-discussions-components-files/4/pastedimage1539789074942v1.png" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt=" " src="https://devzone.nordicsemi.com/resized-image/__size/640x480/__key/communityserver-discussions-components-files/4/pastedimage1539789301276v2.png" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>