<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Controlling that BLE is encrypted - using Wireshark and nRF 52 DK</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/67184/controlling-that-ble-is-encrypted---using-wireshark-and-nrf-52-dk</link><description>Hi, 
 I am using nRF 52 DK as a sniffer and monitoring the BLE traffic on Wireshark. The goal of this is to ensure that the communication is encrypted. 
 I can see that in the package there is a flag called &amp;quot;encrypted&amp;quot; - see picture below. 
 Is there</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Wed, 11 Nov 2020 14:25:53 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/67184/controlling-that-ble-is-encrypted---using-wireshark-and-nrf-52-dk" /><item><title>RE: Controlling that BLE is encrypted - using Wireshark and nRF 52 DK</title><link>https://devzone.nordicsemi.com/thread/279523?ContentTypeID=1</link><pubDate>Wed, 11 Nov 2020 14:25:53 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:986ecea6-b484-44ff-a31a-c3b70b19fac5</guid><dc:creator>Kenneth</dc:creator><description>&lt;p&gt;Not aware of any video in specific no, but just start Wireshark with the initial connection and bonding should do. You may need to do an erase all of the flash first to ensure that previous bonding information is gone.&lt;/p&gt;
&lt;p&gt;Best regards,&lt;br /&gt;Kenneth&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Controlling that BLE is encrypted - using Wireshark and nRF 52 DK</title><link>https://devzone.nordicsemi.com/thread/279482?ContentTypeID=1</link><pubDate>Wed, 11 Nov 2020 12:19:36 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:04b2f8c8-6c5f-4044-8194-5136cd09cf5a</guid><dc:creator>Hussain</dc:creator><description>&lt;p&gt;Do you have any video or tutorial for this thing. As I want to see the LTK for just works pairing via nrf52 dk sniffer&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Controlling that BLE is encrypted - using Wireshark and nRF 52 DK</title><link>https://devzone.nordicsemi.com/thread/278019?ContentTypeID=1</link><pubDate>Mon, 02 Nov 2020 10:36:40 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:2fdcd62a-2d11-4b94-b906-71e9a002adae</guid><dc:creator>Kenneth</dc:creator><description>&lt;p&gt;If you are sniffing the bonding procedure when using &amp;quot;just works&amp;quot; pairing you should be able to get the LTK in one of the decrypted packets. In other bonding procedures (e.g MITM and passkey) you will not be able to sniff the LTK when using nRF Sniffer no.&lt;/p&gt;
&lt;p&gt;Best regards,&lt;br /&gt;Kenneth&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Controlling that BLE is encrypted - using Wireshark and nRF 52 DK</title><link>https://devzone.nordicsemi.com/thread/277990?ContentTypeID=1</link><pubDate>Mon, 02 Nov 2020 09:31:52 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:55583de8-e109-40bf-8caf-096455d1c5bd</guid><dc:creator>Hussain</dc:creator><description>&lt;p&gt;Hi ,&lt;/p&gt;
&lt;p&gt;I want to ask you that is there a way to know about LTK in sniffing and we can see in wireshark.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Controlling that BLE is encrypted - using Wireshark and nRF 52 DK</title><link>https://devzone.nordicsemi.com/thread/275024?ContentTypeID=1</link><pubDate>Thu, 15 Oct 2020 09:53:32 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:c07c398f-c19f-41ad-b773-2c145901b77f</guid><dc:creator>Kenneth</dc:creator><description>&lt;p&gt;Sorry no, but the fields are directly related to the BLE spec (which describe the actual implementation of link layer roles, crc, mic and encryption).&lt;/p&gt;
&lt;p&gt;Best regards,&lt;br /&gt;Kenneth&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Controlling that BLE is encrypted - using Wireshark and nRF 52 DK</title><link>https://devzone.nordicsemi.com/thread/274996?ContentTypeID=1</link><pubDate>Thu, 15 Oct 2020 07:49:15 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:fc79710e-48d8-46a5-b6b9-7bcaad78fca4</guid><dc:creator>Hussain</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;Is there a reference to some document regarding these explanation? which can be used as a reference.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Controlling that BLE is encrypted - using Wireshark and nRF 52 DK</title><link>https://devzone.nordicsemi.com/thread/274874?ContentTypeID=1</link><pubDate>Wed, 14 Oct 2020 11:57:23 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:8b34cb52-9d0c-4648-bbd9-949b2f67d915</guid><dc:creator>Kenneth</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;The sniffer will do the decryption in hardware (to meet the timing requirements). So Wireshark will only have access to the decrypted data. So you will need to refer to the flags if the link is encrypted or not:&lt;/p&gt;
&lt;p&gt;&lt;span&gt;crc - w&lt;/span&gt;&lt;span&gt;as the CRC received by the sniffer OK.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;direction -&amp;nbsp;Only relevant during connection. True -&amp;gt; Master to Slave, False -&amp;gt; Slave to Master&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;encrypted -&amp;nbsp;has the packet been encrypted.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;mic&amp;nbsp;-&amp;nbsp;&lt;/span&gt;&lt;span&gt;the message integriy check OK. Only relevant in encrypted state.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Best regards,&lt;br /&gt;Kenneth&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>