Context
An app connects via BLE 5.0 to a device for simple configuration/to get some information of the device. (Used as a service tool)
It is not allowed to communicate with the device without some kind of registration before. Therefore, one can scan the QR code of the device and ask for an app id and pin (during startup of the device or when a button was pressed)
It is ok to connect at Bluetooth stack level and see all services and characteristics, as long as the service implementation doesn't do anything useful if the central is "unknown", which I have problems with of how to lock this at application level.
It is my first project with Bluetooth/Ble/Gatt-Server/Dbus and app development.
My setup
The Peripheral
I have implemented a Gatt-Server, using Python3/DBus and Bluez 5.50 (ControllerMode = le only) on a Raspberry Pi4
I have started with the following example that illustrates:
- How to read out the cpu temp of the Pi
- How to write to the Gatt-Server (Switch between Celsius and Farenheit)
- How to notify when the temp changes
https://github.com/Douglas6/cputemp/blob/master/cputemp.py
I also got some ideas from the following documentation of Apple:
Characteristics permissions
- Only write (with response) to exec. some commands
- Only notify to receive data
For pairing:
- I used a simple Bluez agent example with the option
NoInputNoOutput. As central, I only got a questions if I want to pair with the device, when it is for the first time. There is no code, that I have to accept (which is what I want).
The Central
I have an iOS app, use Swift5 and CoreBluetooth
From central perspective and a bit like illustrated in the documentation of the Apple Notifications Center Service:
- I have a characteristic to write a command to (Read data of attribute x)
- I have a characteristic for being notified (if data changes or I have asked for)
My basic communication process (which works good for me so far)
- App connects to Pi (simple pairing without pin code)
- App reads all services, characteristics and enables notifications for characteristics with notify flag
- App provides an auth code (extracted from a scanned qr code) and receives an app id and a pin number and store it for the next time
- Ask for attribute x and receives notification with current value of attributes x
My problems, thoughts and questions
A second central is being notified with the information of attribute x as well, when it activates notification for that specific characteristic. Central B uses a free app which scans all available services / characteristics.. (I use LightBlue for Mac or Beacon Grabber for iPhone). Central B just paired with the Raspberry Pi and doesn't need to provide something else..
- So far, I have no context about connected devices within my implementations of services and characteristics. I know, that I can read which device writes to a characteristic by reading out
dbus.ObjectPath('/org/bluez/hci0....
I can remember that info and ask if device X has a valid id an pin, otherwise I won't do anything.
I also can trigger notification only when a known device asks for. But that does not solve the problem completely.
I can only (maybe..) allow one central connection to avoid my problem (but not to solve it)
Is there a way to notify only a specific device?
Is there a better approach to handle that?
Can I force a disconnect to the central, which is not registered?
Are there better approaches to achieve some kind of security at this level?
I'm happy about some ideas and opinions.
Thanks!