Bluetooth SSP: Just Works vs Passkey vs OOB vs Numeric Comparison
Advertisement
Based on the Bluetooth Core Specification, Secure Simple Pairing (SSP) was introduced initially in Bluetooth 2.1 to drastically improve both the security and the user experience of pairing Bluetooth devices.
Before SSP, Bluetooth used “Legacy Pairing,” which relied on users entering a PIN code. This was often insecure (e.g. using “0000”) and vulnerable to passive eavesdropping. SSP solved this by using Elliptic Curve Diffie Hellman (ECDH) public key cryptography to encrypt the link, meaning all SSP methods protect against passive eavesdropping.
To protect against Man-in-the-Middle (MITM) attacks (where a malicious device secretly relays and alters the connection between two legitimate devices), SSP uses four distinct Association Models. The Bluetooth system automatically selects the correct model based on the Input/Output (I/O) capabilities of the two devices (e.g. whether they have a screen, a keyboard or neither).
Numeric Comparison
Scenario: Both devices have a display capable of showing a 6-digit number, and buttons to select “Yes” or “No” (e.g. pairing a Smartphone to a Car Infotainment system or a PC).
-
How it works: The two devices communicate and independently generate a 6-digit number (ranging from 000000 to 999999). This number is displayed on both screens. The user is asked to verify that the numbers match and press “Yes” on both devices.
-
Security: Provides high MITM protection.
-
Key Distinction: Unlike legacy PIN pairing, the 6-digit number displayed here is not the encryption key, nor is it an input to generate the key. It is simply a cryptographic artifact used to prove that both devices are talking directly to each other and not through a proxy.
Just Works
Scenario: At least one device has very limited or no screen/keyboard capabilities (e.g. pairing a Smartphone to a basic wireless earbud, fitness tracker or wireless speaker).
-
How it works: Under the hood, this uses the exact same cryptographic protocol as Numeric Comparison. However, because the accessory cannot display a number or take a “Yes/No” input, the step where the user compares the numbers is skipped entirely. The devices simply pair automatically (though the phone may prompt the user with a generic “Pair with this device?” pop-up).
-
Security: Because there is no user verification, “Just Works” provides NO protection against MITM attacks. However, because it still uses ECDH cryptography, it does provide complete protection against passive eavesdropping.
Passkey Entry
Scenario: One device has a screen, and the other device has a numeric keypad or keyboard (e.g., pairing a PC/Tablet to a Bluetooth keyboard).
-
How it works: The device with the display shows a randomly generated 6-digit number. The user must type this exact 6-digit number into the device with the keyboard and press “Enter”.
-
Security: Provides high MITM protection. Just like Numeric Comparison, typing this passkey is simply a way to mathematically prove to both devices that they are communicating with the intended target, preventing a MITM attacker from intercepting the pairing.
Out of Band (OOB)
Scenario: Both devices feature an alternative wireless communication technology, almost always NFC (Near Field Communication).
-
How it works: Instead of discovering the device over the Bluetooth radio and verifying numbers, the user simply “taps” the two devices together. The cryptographic information and Bluetooth addresses required for pairing are exchanged securely over the NFC connection. Once exchanged, the Bluetooth radios take over and finalize the encrypted connection.
-
Security: Excellent MITM protection, but this protection relies entirely on the security of the OOB channel. Because NFC requires the devices to be practically touching (within centimeters), it is physically nearly impossible for an attacker to insert themselves as a Man-in-the-Middle.
Comparison between Bluetooth Secure Simple Pairing (SSP) models
| Feature | Just Works | Numeric Comparison | Passkey Entry | Out of Band (OOB) |
|---|---|---|---|---|
| I/O Capability Needed | None (NoInputNoOutput) on at least one device. | Display + “Yes/No” buttons on both devices. | One Display device + One Keyboard device. | NFC (or other OOB radio) on both devices. |
| User Action Required | None (or just clicking “Pair” on the phone). | Read 6 digits on both screens, confirm they match. | Read 6 digits on one screen, type them on the other. | Physically tap the two devices together. |
| Passive Eavesdropping Protection? | Yes (Uses ECDH cryptography). | Yes (Uses ECDH cryptography). | Yes (Uses ECDH cryptography). | Yes (Uses ECDH cryptography). |
| Man-in-the-Middle (MITM) Protection? | No. An attacker could theoretically spoof the connection. | Yes. The visual check prevents proxy attacks. | Yes. Typing the code prevents proxy attacks. | Yes. Relies on the extreme short-range physics of NFC. |
| Typical Use Case | Headsets, mice, basic smart home sensors. | Phone to Car, Phone to PC, PC to PC. | Bluetooth Keyboards. | Quick pair headphones, tap to pair speakers. |
Summary
The brilliance of Secure Simple Pairing is that it decoupled encryption from authentication. Even in the “Just Works” scenario where the user enters no passwords and does no verification, the resulting Bluetooth connection is still heavily encrypted and immune to someone trying to sniff the data out of the air; a massive upgrade over the pre-2007 legacy Bluetooth standards.
References & Further Reading
- Bluetooth SIG : Bluetooth Core Specification Version 6.3, May 5, 2026.
- Bluetooth SIG : Bluetooth Technology Overview
Continue Learning Bluetooth Basic Concepts
- What are new features in Bluetooth 6.3 Version
- Bluetooth GATT Vs. ATT Vs. GAP : Key Comparison
- Bluetooth Service Vs. Characteristic Vs. Descriptor
- Bluetooth pairing Vs. Bonding Phase
- Bluetooth Notifications Vs. Indications
- Bluetooth Channel Sounding Vs. RSSI
- Bluetooth Direction Finding Methods : AoA Vs. AoD
- Bluetooth Error Codes Guide : Meanings, Causes & Fixes
- Bluetooth L2CAP and HCI : Key Differences
Continue Learning Bluetooth Technology
- Bluetooth Basics Tutorial
- Bluetooth Low Energy (BLE) Basics Tutorial
- Bluetooth Protocol Stack & Device State Diagram
- Bluetooth Physical Layer Modules
- Bluetooth MAC Layer Overview
- Bluetooth Channel Frequency List
- Bluetooth Network Security
- Bluetooth Low Energy (BLE) Connection Establishment Procedure
- Bluetooth Profiles: HFP, HSP, A2DP, AVRCP, PBAP & MAP
- Bluetooth Mesh Node Types & Protocol Stack Layer Functions
