Certificate Based Authentication and Pairing (CBAP)
Certificate Based Authentication and Pairing or CBAP helps streamline the authentication and pairing process in Bluetooth LE devices. With built-in security features, it eliminates the need to manually authenticate devices using QR codes, passkeys, or NFC based pairings, and automatically authenticates connection by signing the pairing data with their own secret key.
Why CBAP?
Fast and Secure Connection Between Thousands of Devices
Eliminates manual intervention which not only speeds up the authentication process but also improves security by mitigating human error.
Ensures the Device is From a Trusted Manufacturer
Enables one-way (phone-to-device) or two-way (device-to-device) authenticated connections only with a trusted manufacturer.
Proof of Identity
and Eligibility
Matches identity of the device and checks eligibility through stored authentication certificate.
Pairing with CBAP ensures authenticated communication, minimizing man-in-the-middle threats.
Parameter | Just Works | Numerical Comparison / Passkey | OOB | CBAP |
Manual Intervention | None | Visual comparison of numbers | Physical proximity between devices | None |
Security Level | Low | High | High | Very High |
Man-in-the-Middle Protection | None | Yes | Yes | Yes |
Counterfeit Protection | None | None | None | Present |
Automation | Possible | Not Possible | Not Possible | Possible |
Back Channel for Authentication | Not Possible | Not Possible | Required | Not Required |
Cost of Large-scale Operation | Low | High | High | Low |
Silicon Labs CBAP Solutions
Silicon Labs is an industry leader in Bluetooth LE solutions, and we can help you implement Certificate Based Authentication and Pairing to ensure top-tier security for your devices without requiring any user interaction. Currently, certificate-based authentication and pairing is supported on Secure Vault-High and Secure Vault-Mid devices.
Secure Vault-High
Wireless Gecko Series 2 devices are the next evolution of Wireless Gecko devices bringing high performance, low power, and secure solutions to the Internet of Things. Designed to increase processing capability, improve RF performance and lower active current, the devices also provide the highest level of IoT device security. The EFR32BG21 devices are also designed to support Silicon Labs' enhanced security option, Secure Vault. Learn more about Silicon Labs' security portfolio.
EFR32BG21 devices are 2.4 GHz wireless SOCs optimized for line-powered Bluetooth Low Energy and Bluetooth mesh applications, including connected lighting, smart plugs, gateways and voice assistants. An 80 MHz ARM® Cortex®-M33 core provides plenty of processing capability while an integrated security subsystem provides leading security features that greatly reduce the risk of IoT security breaches and compromised intellectual property. With better than -104.3 dBm sensitivity and up to +20 dBm output power, the EFR32BG21 family uses Simplicity Studio 5 development tools, providing easy migration and fast time-to-market with development kits, SDKs, mobile apps, our energy profiler and patented network analyzer.
The EFR32BG24 Wireless SoCs are ideal for IOT wireless connectivity using Bluetooth Low Energy and Bluetooth mesh for smart home, lighting, and portable medical products. With AECQ-100 qualification, support for Channel Sounding, and key features like high performance 2.4 GHz RF, low current consumption, an AI/ML hardware accelerator and Secure Vault™, IoT device makers can create the smart, robust, and energy-efficient products that are secure from remote and local cyber-attacks. An ARM Cortex®-M33 running up to 78 MHz and up to 1.5 MB of Flash and 256 kB of RAM provides resources for demanding applications while leaving room for future growth. Target applications include gateways/hubs, sensors, switches, door locks, smart plugs, LED lighting, luminaires, blood glucose meters and pulse oximeters.
The EFR32FG28 SoC is an ideal dual band Sub-GHz + 2.4 GHz Bluetooth LE SoC solution for IoT applications in smart homes, security, lighting, building automation, and metering. This dual band solution combines a high-performance Sub-GHz radio that provides long range capabilities and a Bluetooth radio for increased design flexibility. The large memory footprint and increased IO count allows for design consolidation and Secure Vault™ gives flexibility to choose the security level that meets your product’s needs.
Secure Vault-Mid Devices through TrustZone
Wireless Gecko Series 2 devices are the next evolution of Wireless Gecko devices bringing high performance, low power, and secure solutions to the Internet of Things. Designed to increase processing capability, improve RF performance and lower active current, the devices also provide the highest level of IoT device security. The EFR32BG21 devices are also designed to support Silicon Labs' enhanced security option, Secure Vault. Learn more about Silicon Labs' security portfolio.
EFR32BG21 devices are 2.4 GHz wireless SOCs optimized for line-powered Bluetooth Low Energy and Bluetooth mesh applications, including connected lighting, smart plugs, gateways and voice assistants. An 80 MHz ARM® Cortex®-M33 core provides plenty of processing capability while an integrated security subsystem provides leading security features that greatly reduce the risk of IoT security breaches and compromised intellectual property. With better than -104.3 dBm sensitivity and up to +20 dBm output power, the EFR32BG21 family uses Simplicity Studio 5 development tools, providing easy migration and fast time-to-market with development kits, SDKs, mobile apps, our energy profiler and patented network analyzer.
EFR32BG22 and EFR32BG22E Bluetooth low energy (LE) wireless SoC solutions are part of the Wireless Gecko Series 2 platform. These devices are designed with a strong focus on energy efficiency, offering best-in-class ultra-low transmit and receive power, and a high-performance, low-power Arm® Cortex®-M33 core delivers industry-leading energy efficiency that can extend coin cell battery life up to ten years. Where BG22 allows you to create energy-efficient applications, the BG22E – ‘E’ denoting Energy Conservation – takes this a step further by enhancing battery longevity and supporting designs that eliminate the need for batteries altogether. Our BG22 and BG22E family's are the ideal market leading SoCs for Ambient IoT or Energy Harvesting devices. Target applications include Bluetooth mesh low-power nodes, smart door locks, personal healthcare and fitness devices. Asset tracking tags, beacons and indoor navigation also benefit from the SoCs' versatile Bluetooth Angle of Arrival (AoA) and Angle of Departure (AoD) capabilities and sub-one-meter location accuracy.
The EFR32BG24 Wireless SoCs are ideal for IOT wireless connectivity using Bluetooth Low Energy and Bluetooth mesh for smart home, lighting, and portable medical products. With AECQ-100 qualification, support for Channel Sounding, and key features like high performance 2.4 GHz RF, low current consumption, an AI/ML hardware accelerator and Secure Vault™, IoT device makers can create the smart, robust, and energy-efficient products that are secure from remote and local cyber-attacks. An ARM Cortex®-M33 running up to 78 MHz and up to 1.5 MB of Flash and 256 kB of RAM provides resources for demanding applications while leaving room for future growth. Target applications include gateways/hubs, sensors, switches, door locks, smart plugs, LED lighting, luminaires, blood glucose meters and pulse oximeters.
The EFR32BG27 family of wireless SoCs opens up new possibilities by offering an ultra-small WLCSP package (2.3 mm x 2.6 mm) capable of running on button cell batteries. Now device makers can address applications with extremely small form-factor requirements without sacrificing performance and security. The BG27 Bluetooth SoC features an integrated DCDC boost that allows operation down to 0.8 volts, enabling support for single-cell alkaline and 1.5-volt button cell batteries that are typically used in medical applications for battery-operated patches and continuous glucose monitoring (CGM) devices. Additionally, the wakeup pin on the BG27 allows products in a warehouse or transit to remain off for months, consuming less than 20 nA, ensuring the battery remains fully charged for use. The integrated coulomb counter enables accurate battery level monitoring to avoid unexpected battery depletion for critical applications. Target applications include connected medical devices, wearables, sensors, switches, smart locks, and both commercial and LED lighting.
The EFR32FG28 SoC is an ideal dual band Sub-GHz + 2.4 GHz Bluetooth LE SoC solution for IoT applications in smart homes, security, lighting, building automation, and metering. This dual band solution combines a high-performance Sub-GHz radio that provides long range capabilities and a Bluetooth radio for increased design flexibility. The large memory footprint and increased IO count allows for design consolidation and Secure Vault™ gives flexibility to choose the security level that meets your product’s needs.
How is CBAP Implemented?
1. The authenticator device verfies that the target device comes from a trusted manufacturer by authenticating its device certificate using the CA certificate.
2. The devices begin OOB pairing with data sent from the target device signed by private key and authenticated using the public key in the device certificate.
3. Pairing completes successfully with authenticated, encrypted communication between devices.
CBAP with CPMS
CBAP enabled devices can utilize certificates injected by CPMS during manufacturing.
Learn how Silicon Labs can help customize your wireless hardware and MCUs with advanced security and unique certificates using Custom Part Manufacturing Service (CPMS).
Application Note
Certificate-Based Bluetooth Authentication and Pairing
This application note describes the theoretical background of certificate-based authentication and pairing, and demonstrates the usage of the related sample applications that can be found in Silicon Labs’ Bluetooth SDK.