Hi,
I have a question about Bluetooth mesh secure provisioning, as it is described in the spec section 5.4.3.
The spec states that either
1) both OOB public key exchange and static OOB authentication
2) OOB input/output authentication
is needed for secure provisioning. What I don't understand is why in the first case the static OOB data is not enough, and what makes static OOB data different from input/output OOB in this regard. Put in a different way: why is OOB public key exchange needed in the first case, but not the second?
Additional question:
Can option 1 be done using the serial interface as a provisioner? How would i provide the OOB keys to the provisioner?
I see a command for setting the key-pair. Is that the correct one to use in this circumstance?