<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>OOB Provisioning and OOB Authentication</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/43856/oob-provisioning-and-oob-authentication</link><description>I am trying to understand the provisioning process as defined in the Bluetooth Mesh Profile v1.01 specification. In particular, I don&amp;#39;t understand the following paragraph 5 
 After the provisioning bearer is established, the Provisioner establishes a</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Thu, 21 Feb 2019 09:05:49 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/43856/oob-provisioning-and-oob-authentication" /><item><title>RE: OOB Provisioning and OOB Authentication</title><link>https://devzone.nordicsemi.com/thread/172248?ContentTypeID=1</link><pubDate>Thu, 21 Feb 2019 09:05:49 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:3cfec533-71ca-422b-b4ab-673543d9567a</guid><dc:creator>Joakim Jakobsen</dc:creator><description>&lt;p&gt;Hi.&lt;/p&gt;
[quote user=""]I have no idea what &amp;quot;enables the authentication&amp;quot; means. Is that statement redundant?[/quote]
&lt;p&gt;It wouldn&amp;#39;t say redundant, but the two statements might be a little repetitive.&lt;/p&gt;
&lt;p&gt;___________________________________________________&lt;/p&gt;
&lt;p&gt;The OOB methods are steps that can happen after the public key exchange. I really recommend you to read through section &amp;quot;5.4.2 Provisioning behavior&amp;quot; in the Mesh Profile specification. The subsections correspond to the various stages that provisioning goes through. Section 5.4.2.3 is the public key exchange, and section 5.4.2.4 (called &amp;quot;Authentication&amp;quot;) is the one where the Static/Output/Input OOB methods can be applied.&lt;/p&gt;
[quote user=""]Can my devices generate their OOB information from the MAC and a private algorithm and this be used for both initial key exchange and authentication?[/quote]
&lt;p&gt;&amp;nbsp;I don&amp;#39;t see why that shouldn&amp;#39;t be possible, but i don&amp;#39;t think this is something that is supported in our SDK. &lt;/p&gt;
&lt;p&gt;I think using a 128-bit randomly generated Static OOB value should be considered as a secure way to provision your device.&lt;/p&gt;
&lt;p&gt;Best regards.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>