Figure 1.
BLE private-address resolution as a capacity and DoS scheduling problem: bonded, benign unknown, and attack advertisements share cache, resolving-list, and host-fallback work paths.
Figure 1.
BLE private-address resolution as a capacity and DoS scheduling problem: bonded, benign unknown, and attack advertisements share cache, resolving-list, and host-fallback work paths.
Figure 2.
BLE privacy boundary and admissible scheduling signals: P3 excludes bonded-membership predicates and uses only receiver-local state and visible stream repetition before resolving. The red X marks indicate signals or actions that are forbidden before resolution under the privacy boundary.
Figure 2.
BLE privacy boundary and admissible scheduling signals: P3 excludes bonded-membership predicates and uses only receiver-local state and visible stream repetition before resolving. The red X marks indicate signals or actions that are forbidden before resolution under the privacy boundary.
Figure 3.
Related-work positioning map: P3-Persist occupies the bounded-work, no-oracle scheduling corner that prior privacy, security, cache, and generic limiter work do not jointly cover. The X-axis is the privacy-admissible use of RPA stream structure before resolving (none/generic/RPA-specific); the Y-axis is the degree of post-miss resolving-work control (none/partial/bounded).
Figure 3.
Related-work positioning map: P3-Persist occupies the bounded-work, no-oracle scheduling corner that prior privacy, security, cache, and generic limiter work do not jointly cover. The X-axis is the privacy-admissible use of RPA stream structure before resolving (none/generic/RPA-specific); the Y-axis is the degree of post-miss resolving-work control (none/partial/bounded).
Figure 4.
P3 resolving workflow: non-RPA, cache, and resolving-list fast paths are preserved, while cache/RL misses pass through the general budget and then the persistence reserve before host fallback.
Figure 4.
P3 resolving workflow: non-RPA, cache, and resolving-list fast paths are preserved, while cache/RL misses pass through the general budget and then the persistence reserve before host fallback.
Figure 5.
Running example timeline: after budget exhaustion, a repeated legitimate RPA value earns reserve admission and then moves to the positive-cache path, while unique attack values remain denied.
Figure 5.
Running example timeline: after budget exhaustion, a repeated legitimate RPA value earns reserve admission and then moves to the positive-cache path, while unique attack values remain denied.
Figure 6.
Proposition-to-evidence roadmap: each analytical bound is linked to the simulation table or figure that tests the corresponding work, service, or adaptive-attacker claim. Arrows read as “claim is tested by metric, and metric is evidenced by artifact”.
Figure 6.
Proposition-to-evidence roadmap: each analytical bound is linked to the simulation table or figure that tests the corresponding work, service, or adaptive-attacker claim. Arrows read as “claim is tested by metric, and metric is evidenced by artifact”.
Figure 7.
Same flood-suppression regime, different legitimate-traffic cost. Three panels compare BudgetDoS, P3-NoPersist, and P3-Persist under medium and heavy flood: (a) legitimate resolution rate (%), (b) false defer rate (%), and (c) attack amplification (×103 AES-equivalent/min). P3-Persist moves almost vertically, raising legitimate resolution while staying in the same approximately 45k AES-equivalent/min work band.
Figure 7.
Same flood-suppression regime, different legitimate-traffic cost. Three panels compare BudgetDoS, P3-NoPersist, and P3-Persist under medium and heavy flood: (a) legitimate resolution rate (%), (b) false defer rate (%), and (c) attack amplification (×103 AES-equivalent/min). P3-Persist moves almost vertically, raising legitimate resolution while staying in the same approximately 45k AES-equivalent/min work band.
Figure 8.
Experimental campaign roadmap: workload families, generator scripts, summary artifacts, and evidence roles are linked so each reported table and figure has a reproducible source.
Figure 8.
Experimental campaign roadmap: workload families, generator scripts, summary artifacts, and evidence roles are linked so each reported table and figure has a reproducible source.
Figure 9.
Heavy-flood attack-work and service trade-off at 10,000 attack RPAs/min: the left panel reports attack-triggered AES-equivalent amplification on a log scale, while the right panel reports legitimate resolution on the same main statistical-extension runs. P3-Persist remains in the bounded-work band while recovering legitimate service. Source artifacts: ‘run_m10_statistical_extension.py’, the main heavy-flood result family, and the corresponding figure-source CSVs listed in
Table 12.
Figure 9.
Heavy-flood attack-work and service trade-off at 10,000 attack RPAs/min: the left panel reports attack-triggered AES-equivalent amplification on a log scale, while the right panel reports legitimate resolution on the same main statistical-extension runs. P3-Persist remains in the bounded-work band while recovering legitimate service. Source artifacts: ‘run_m10_statistical_extension.py’, the main heavy-flood result family, and the corresponding figure-source CSVs listed in
Table 12.
Figure 10.
Budget tuning frontier: the x-axis varies the unresolved-work budget per window and the y-axis reports attack-work reduction and legitimate-resolution trade-offs under medium and heavy flood.
Figure 10.
Budget tuning frontier: the x-axis varies the unresolved-work budget per window and the y-axis reports attack-work reduction and legitimate-resolution trade-offs under medium and heavy flood.
Figure 11.
Bonded-device scale versus resolving work: the left panel reports total AES-equivalent attempts and the right panel reports StaticRL-normalized work, including the matched P3-Persist supplemental curve and showing where N > C creates host-fallback pressure.
Figure 11.
Bonded-device scale versus resolving work: the left panel reports total AES-equivalent attempts and the right panel reports StaticRL-normalized work, including the matched P3-Persist supplemental curve and showing where N > C creates host-fallback pressure.
Figure 12.
Resolving-list capacity sensitivity: the top panels show all methods on the shared AES-equivalent scale, and the bottom panels zoom into the bounded schedulers to separate BudgetDoS, P3-NoPersist, and the P3-Persist main method.
Figure 12.
Resolving-list capacity sensitivity: the top panels show all methods on the shared AES-equivalent scale, and the bottom panels zoom into the bounded schedulers to separate BudgetDoS, P3-NoPersist, and the P3-Persist main method.
Figure 13.
Direct capacity-expansion boundary: service improves as C grows, but only the theoretical upper bound (C = N) removes host fallback completely; low-capacity controllers still need scheduling.
Figure 13.
Direct capacity-expansion boundary: service improves as C grows, but only the theoretical upper bound (C = N) removes host fallback completely; low-capacity controllers still need scheduling.
Figure 14.
Method and ablation evidence: the left panel reports heavy-flood AES-equivalent work by method, while the right panel reports legitimate service recovery after adding persistence reserve.
Figure 14.
Method and ablation evidence: the left panel reports heavy-flood AES-equivalent work by method, while the right panel reports legitimate service recovery after adding persistence reserve.
Figure 15.
P3-Persist sensitivity over four factors, each panel reporting legitimate resolution (%) with the bounded attack work annotated: (
a) persistence reserve size
R, (
b) persistence threshold
k, (
c) duplicate-filter boundary (unique stress, repeated no-filter, repeated 60 s filter), and (
d) repeated-address rate pressure (10 k vs. 20 k attack RPAs/min). Legitimate resolution is tracked while attack work remains bounded in
Table 18. Source artifacts: ‘run_m10_statistical_extension.py’, ‘run_m11_adaptive_adversary.py’, statistical-extension summaries, adaptive-sweep summaries, and figure-source CSVs listed in
Table 12.
Figure 15.
P3-Persist sensitivity over four factors, each panel reporting legitimate resolution (%) with the bounded attack work annotated: (
a) persistence reserve size
R, (
b) persistence threshold
k, (
c) duplicate-filter boundary (unique stress, repeated no-filter, repeated 60 s filter), and (
d) repeated-address rate pressure (10 k vs. 20 k attack RPAs/min). Legitimate resolution is tracked while attack work remains bounded in
Table 18. Source artifacts: ‘run_m10_statistical_extension.py’, ‘run_m11_adaptive_adversary.py’, statistical-extension summaries, adaptive-sweep summaries, and figure-source CSVs listed in
Table 12.
Figure 16.
Legitimate path mix: stacked path fractions show whether legitimate events resolve through RL, cache, host scan, budget skip, or defer under benign reuse and heavy flood.
Figure 16.
Legitimate path mix: stacked path fractions show whether legitimate events resolve through RL, cache, host scan, budget skip, or defer under benign reuse and heavy flood.
Figure 17.
Seed-level legitimate-resolution rates: each point is a simulation seed and the intervals are Student-t 95% CIs for the headline persistence comparisons. Source artifacts: ‘plot_legit_ci.py’, ‘
Figure 13_legit_rate_ci’ outputs, and
Table 17 statistical-extension summary CSVs.
Figure 17.
Seed-level legitimate-resolution rates: each point is a simulation seed and the intervals are Student-t 95% CIs for the headline persistence comparisons. Source artifacts: ‘plot_legit_ci.py’, ‘
Figure 13_legit_rate_ci’ outputs, and
Table 17 statistical-extension summary CSVs.
Table 1.
Comparison of representative BLE privacy/security and scheduling approaches against P3.
Table 1.
Comparison of representative BLE privacy/security and scheduling approaches against P3.
| Approach (Representative Work) | Problem/Threat Focus | Manages RL Capacity | Bounded Host Work | Privacy-Safe Scheduler Use | Δ vs. P3 |
|---|
| RPA/address tracking analysis (Becker et al. [24]; Celosia and Cunche [7]) | Passive tracking via payload and address carry-over | No | No | N/A | Motivates why RPA matters; does not study resolving-load DoS or RL scheduling |
| Specification/allowlist traceability (Wu et al. [18]; Zhang and Lin [13]) | Linkability from specification/implementation and allowlist behavior | No | No | N/A | Sets the no-membership-oracle constraint P3 must respect; proposes no scheduler |
| User-side privacy protection (Fawaz et al. [25]) | Protecting BLE broadcast privacy at the user side | No | No | Yes | Protects broadcast privacy; not receiver-side resolving-list/AES work |
| Spoofing and state-aware defense (BlueShield [29]; BlueSWAT [31]) | Spoofing detection/lightweight state security | No | No | Yes | Different attack surface; not resolving-layer work amplification |
| Implementation/link DoS (SweynTooth [27]; BLESA [28]) | Crash, reconnection and packet-crafting DoS | No | No | N/A | Different DoS layer; P3 targets RPA-resolving work |
| Large-scale BLE scanning (BLEB [26]) | Botnet-scale tracking and scanning | No | No | N/A | Supplies high-density flooding motivation; not a receiver-side defense |
| BLE security surveys (Lacava et al. [6]; Ghori et al. [30]) | Taxonomy of BLE threats and procedures | No | No | N/A | Background context; no RPA-resolving-list scheduling algorithm |
| Open-stack cache and RL (Zephyr [11]; Nordic NCS [21]) | prpa_cache, host key lookup, capacity-bounded RL | fixed config only | No | Yes | Cache/RL exists; used as the ZephyrCache/StaticRL baselines, not claimed as novelty |
| Generic rate limiting, token bucket, and early dropping (RFC 2697 [22]; RED [34]) | Bounding or shedding work at an interface | No | generic | N/A | Budget idea is generic and content-blind; P3 binds it to the unknown-RPA-resolving queue and adds persistence-aware service recovery |
| Probabilistic prefilter (Bloom filter [19]) | Compact set-membership testing | No | No | No (unsafe here) | Cannot classify an unknown RPA without IRK/AES work; P3 deliberately avoids any prefilter |
| P3 (this work) | RPA-flooding resolving DoS under RL-capacity limits | Yes (activity-based admission) | Yes (unresolved-RPA + persistence reserve) | Initial-decision constraint only | Uses address repetition under Proposition 0’s initial-decision identity-label-invariance constraint: same unique-flood bound as rate limiting (Proposition 1), arbitrary-attack bound under B + R (Proposition 2), much higher legitimate service (Proposition 3), explicitly reported adaptive reserve-pressure boundaries (Proposition 4), and an empirical service–work trade-off within the evaluated admissible bounded-work class (Design Rationale 5) |
Table 2.
Main notation used in the theoretical model. Italic symbols denote model variables.
Table 2.
Main notation used in the theoretical model. Italic symbols denote model variables.
| Symbol | Definition |
|---|
| N | Number of bonded identities and locally stored IRKs. |
| C | Controller resolving-list capacity, with 0 ≤ C ≤ N. |
| I | Set of bonded identities/IRKs stored by the receiver. |
| RLt | Set of identities loaded into the controller resolving list at time t, with |RLt| ≤ C. |
| Kt | Positive RPA cache at time t, containing only previously resolved RPA-to-identity mappings. |
| et | Advertising event observed at time t. |
| rv(et) | Visible over-the-air RPA value carried by event et. |
| zt | Post-decision event class used only for evaluation labels, not a scheduler input. |
| Ew | Set of advertising events observed in budget window w. |
| h(et) | Host resolving admission indicator after cache and resolving-list misses. |
| a(et) | AES-equivalent attempts charged to event et. |
| B | General unresolved-work budget per window. |
| R | Persistence reserve per window for repeated visible RPA values. |
| W | Budget-window length in seconds. |
| k | Persistence threshold; reserve admission requires at least k prior denials for the same rv. |
| D(rv) | Receiver-local cumulative denial counter for visible value rv; reserve usage, not this denial history, is reset by window. |
| uw, rw | General-budget and reserve counters used in window w. |
| qi | Expected observation probability of bonded identity i in the idealized allocation model. |
| xi | Binary resolving-list allocation variable for identity i. |
Table 3.
Terminology for the P3 method family and baselines.
Table 3.
Terminology for the P3 method family and baselines.
| Term | Meaning in This Manuscript | Role |
|---|
| P3 | Method identifier for the persistence-aware BLE RPA-resolving scheduler family | Design family |
| P3-Persist | Main evaluated P3 instance with unresolved-work budget and persistence reserve | Proposed method |
| P3-NoPersist | P3 ablation without the persistence reserve | Ablation |
| BudgetDoS | Budget-only unresolved-work limiter | Baseline |
| AdaptiveRateLimit | Generic fixed-window unresolved-work limiter | Baseline |
Table 4.
Baseline definitions.
Table 4.
Baseline definitions.
| Method | Role |
|---|
| FullScan-Host | Host scans all bonded IRKs; worst-case complete host fallback baseline. |
| StaticRL | Fixed resolving-list assignment without dynamic admission. |
| ZephyrCache | Cache-only practical baseline inspired by open stack behavior. |
| LRU-RL | Recency-based resolving-list replacement. |
| Freq-RL | Frequency-based resolving-list replacement. |
| Random-RL | Deterministic-seed random resolving-list replacement used as a low-cost admission baseline. |
| RSSIHint | RSSI-based defer hints without full P3 budget/admission. Implemented in code as TrustOnly; host fallback is charged conservatively in the AES metric. |
| BudgetDoS | Unknown-RPA budget without full P3 combination. |
| AdaptiveRateLimit | Generic unresolved-work limiter implemented as a fixed-window counter (threshold B host scans per W-second window, reset at each window boundary); shares the limiter core of BudgetDoS but without P3 admission/cache state. |
| Oracle-Offline | Non-deployable upper bound that suppresses known attack events using labels unavailable to a real receiver. |
| P3-Persist | Proposed full method with persistence-aware reserve after general budget exhaustion. |
| P3-NoPersist | Pre-persistence ablation without persistence reserve: capacity-aware resolving-list admission, positive-cache fast path, activity metadata, RSSI defer hint, and unresolved-work budget. |
| P3-NoCache/NoBudget/NoTrust/NoRL | Module-disabled variants for ablation. |
Table 5.
Algorithm-to-simulator mapping.
Table 5.
Algorithm-to-simulator mapping.
| Manuscript Step | Simulator Artifact | Reproducibility Role |
|---|
| Traffic generation and labels | Traffic generator (generate_events) | Generates legitimate, benign unknown, non-RPA, and attack events; labels are used for metrics after decisions. |
| Cache hit/insert | Positive-cache state (get_cache, put_cache) | Models positive-only RPA cache behavior for ZephyrCache and P3 cache-enabled variants. |
| Resolving-list admission | RL admission update (maybe_update_rl) | Updates RL entries only after positive matches; activity_counts drives P3/Freq-style replacement. |
| Unknown-work budget | Budget gate and denial action (budget_allows, budget_denial_action) | Enforces budget_perwindow and records budget_skip/defer decisions. |
| Persistence-aware reserve | Reserve gate over visible RPA values (persistence_reserve_allows, rpa_value) | Grants bounded post-budget host scans to repeated over-the-air RPA values without using identity labels. |
| Duplicate-filter boundary | Duplicate filter (duplicate_filtered, duplicate_filterwindow_s) | Optional repeated-address boundary experiment; default 0 preserves all prior results, while enabled runs suppress unresolved same-window repeats before resolving. |
| Event resolution | Per-event resolver (resolve_event) | Applies cache, RL, budget, host scan, and decision accounting for each method. |
| Summary metrics | Summary aggregator (summarize) | Produces AES-equivalent attempts, attack amplification, legitimate resolution, false defer, and model-level delay fields. |
Table 6.
P3 parameters and defaults.
Table 6.
P3 parameters and defaults.
| Symbol/Parameter | Meaning | Main/Replication Value or Range | Decision Role |
|---|
| N | Stored bonded identities | 16–1024 in the main campaign, 512 in long-window and long-window validation runs | Host candidate-set size |
| C/rl_capacity | Controller resolving-list capacity | 8, 16, 32 in the main campaign; 8, 16, 32, 64, 512 in the direct-expansion capacity check; RL = 8 headline | Fast-path capacity |
| K/zephyr_cache_size | Positive RPA cache size | 64 entries | Reuse recent successful resolutions |
| Cache TTL | Time-based expiration | Not enabled; bounded by RPA epoch and LRU capacity | Avoids claiming an unmeasured TTL policy |
| B/budget_perwindow | Unknown-work budget | 100 per window; budget sensitivity also tests larger budgets | Caps full host work after fast-path misses |
| W/budget_window_s | Budget refresh window | 60 s window | Resets budget counters |
| R/persist_reserve | Persistence reserve per window | 200 in the headline persistence comparison; sensitivity {50, 100, 200, 400} | Bounds post-budget host scans for repeated-address values |
| k/persist_k | Persistence threshold | 1 in headline; sensitivity {1, 2, 3} | Requires reappearance before reserve admission |
| D [rv] | Denial counter for visible RPA value | Receiver-local dictionary | Tracks persistence without resolving identity |
| duplicate_filterwindow_s/Δ | Optional duplicate-filter window | 0 (off) by default; 60 s window in the repeated-address boundary experiment | Suppresses unresolved same-window repeated-address values before resolving |
| activity_count_i | Implemented admission score | Count of positive observations for identity i | Ranks RL replacement; maintained as host-order metadata but not credited in AES cost |
| RSSI defer threshold | Internal hint only | −78 dBm in the simulator | Chooses defer rather than skip for some budget-denied events; not an identity signal |
| rssi_noise_db | RSSI noise level | 0, 3, 6, 10 dB sensitivity | Tests robustness of RSSI-derived scheduling hints |
| unique_attack_rpa | Attack address-epoch mode | true for headline stress runs; true/false in the duplicate-filtering boundary check | Separates worst-case unique-address stress from repeated-address model sensitivity |
| Seeds | Random workload seeds | Main campaign: 20260530–20260603; original long-window replication: 20260610–20260612; statistical extension: 20260610–20260629 | Replication and traceability |
Table 7.
Worked example: persistence-aware recovery of one legitimate RPA.
Table 7.
Worked example: persistence-aware recovery of one legitimate RPA.
| Event | t (ms) | Traffic Class | RPA Value | RSSI (dBm) | First Decisive Step | Action | AES | Matched |
|---|
| #382 | 126,533 | Legitimate bonded | Ldev_0000:1 | −65.04 | Budget exhausted; first denial records D [rv] = 1 | defer | 0 | no |
| #397 | 131,336 | Legitimate bonded | Ldev_0000:1 | −67.59 | Same value reappears; D [rv] ≥ k grants reserve | host_scan | 20 | yes |
| #403 | 132,139 | Legitimate bonded | Ldev_0000:1 | −71.85 | Positive cache after reserve resolution | cache_hit | 0 | yes |
| #430 | 141,211 | Legitimate bonded | Ldev_0000:1 | −54.23 | Same-epoch repeat remains on the cache path | cache_hit | 0 | yes |
| #6 | 2195 | Attack | A6 | −83.12 | Unique value denied after budget exhaustion | budget_skip | 0 | no |
| #8 | 3175 | Attack | A12 | −75.94 | Unique value denied after budget exhaustion | defer | 0 | no |
Table 8.
Worked example aggregate outcome for P3-Persist.
Table 8.
Worked example aggregate outcome for P3-Persist.
| Run | Method | Total AES | Attack Amplification | Legit Rate | False Defer |
|---|
| paperwalkthrough_persist | P3-Persist | 487 | 93.4314 | 0.8763 | 0.1237 |
Table 9.
P3-Persist versus budget-only limiting at the same amplification target in Table 16.
Table 9.
P3-Persist versus budget-only limiting at the same amplification target in Table 16.
| Dimension | BudgetDoS/AdaptiveRateLimit | P3-Persist | Δ That Matters |
|---|
| Budget placement | After cache/RL misses | After cache/RL misses | Same flood-suppression core |
| Post-budget admission | None; denied events are dropped by policy | Repeated rpa_value may earn reserve after k denials | New BLE-RPA-specific admission signal |
| Privacy input | No identity classifier | Address repetition only, no identity classifier | Supports initial-decision identity-label invariance; later modeled behavior is reported separately |
| Medium flood, 20-seed statistical extension | AdaptiveRateLimit legit 0.6235 [0.6176, 0.6293]; BudgetDoS 0.5776 [0.5596, 0.5955] | 0.9569 [0.9559, 0.9580] legit, false defer 0.0484 | Same ~44k–45k amp, much higher legitimate service; paired p < 0.01 |
| Heavy flood, 20-seed statistical extension | AdaptiveRateLimit legit 0.5910 [0.5861, 0.5959]; BudgetDoS 0.5663 [0.5351, 0.5975] | 0.9557 [0.9547, 0.9567] legit, false defer 0.0497 | Fixes the strongest-stress weakness of pre-persistence P3; paired p < 0.01 |
| Attacker counter-strategy | Unique and repeated addresses are treated alike by the limiter | Unique addresses cannot earn reserve; repeated values may earn bounded reserve, and duplicate filtering may improve service without eliminating cross-window reserve pressure | Produces an explicit B + R work bound and a measured service–work trade-off, not a universal repeated-address dilemma |
Table 10.
Model-to-stack correspondence.
Table 10.
Model-to-stack correspondence.
| Simulator Concept | BLE/Zephyr-NCS Correspondence | Boundary |
|---|
| Resolving list RL | Controller resolving list, e.g., CONFIG_BT_CTLR_RL_SIZE in Zephyr/NCS [11,21] | Capacity is modeled; closed vendor-controller timing is not. |
| Positive RPA cache K | Controller peer RPA cache and host per-key RPA cache [11,21] | Only positive matches are cached; unknown-miss caching is not modeled. |
| Host candidate set I∖RL | Host key pool searched by IRK matching, represented by Zephyr bt_keys_find_irk() code path [11] | AES-equivalent attempts model work, not measured CPU cycles. |
| Budget window (B, W) | Receiver-local unresolved-work control before repeated full host scans | Not a BLE protocol field and not externally queryable. |
| rpa_value repetition | Over-the-air RPA value within an epoch | Used only as repetition evidence; not an identity predicate. |
| Persistence reserve (R, k) | Receiver-local post-budget admission for repeated-address values | Not advertised to peers and not a per-address membership response. |
| activity_count_i | Host-side scheduling metadata derived from positive matches | Does not authenticate a device. |
| RSSI defer hint | Scanner-observed signal used only for internal scheduling | Not an identity predicate and not a security decision. |
Table 11.
Complexity and model-level state.
Table 11.
Complexity and model-level state.
| Method | Per-Event Resolving Cost After Fast-Path Miss | Additional Modeled State |
|---|
| FullScan-Host | O(N) | None beyond stored IRKs |
| StaticRL | O(N–C) after RL miss | Fixed RL entries |
| ZephyrCache | O(1) cache hit, O(N–C) miss | 64 × 16 B positive cache entries |
| P3-NoPersist | O(1) cache/RL/budget check, bounded host scan when admitted | Cache + RL metadata + per-identity counters/timestamps + budget + RSSI defer hint |
| P3-Persist | O(1) cache/RL/budget/reserve check, bounded host scan when admitted | P3-NoPersist state + denial counters + persistence reserve state |
Table 12.
Simulated datasets and experiment artifacts.
Table 12.
Simulated datasets and experiment artifacts.
| Dataset/Artifact Family and Generator | Runs | Summary Rows | Key Configuration | Purpose and Parameter Basis |
|---|
| Main simulation campaign (run_m3_matrix.py) | 420 | 3360 | 5 seeds; 300 s; N = 16…1024; C = {8, 16, 32}; attack {0, 100, 1000, 10,000}/min | RQ1/RQ2; RL = 8 anchor [11], attack feasibility [26], RSSI range [29] |
| Sensitivity sweeps (run_m3_matrix.py) | 80 | 640 | One-factor sweeps for background, activity skew, RPA rotation, RSSI noise | Sensitivity; RSSI noise anchored by [29] |
| Ablation (run_m3_ablation.sh) | 15 | 120 | P3 module-disabled variants | RQ3 module contribution |
| Long-window replication (run_m4_replication.py) | 9 | 54 | 3 seeds; 1800 s; 300 s warmup; N = 512 | Replication continuity |
| Budget sensitivity (run_m4_budget_sensitivity.py) | 36 | 108 | B = {100, 250, 500, 1000, 2500, 5000}; 1800 s; medium/heavy flood | Trade-off curve; token-bucket analogy [22] |
| Long-window validation (run_m6_review_closure_experiments.py) | 60 configs | 48 | 5 seeds; added baselines, capacity expansion, duplicate boundary | Boundary checks; rate limiting [22], Bloom counter-case [19] |
| Persistence-comparison suite (run_m8_algorithm_novelty_experiments.py) | 60 | 135 | 5 seeds; P3-Persist, P3-NoPersist, reserve/threshold sensitivity, attacker dilemma, duplicate-filter boundary | Persistence-aware evidence; RPA epoch semantics [8], rate limiting [22] |
| Statistical extension (run_m10_statistical_extension.py) | 280 | 580 | 20 seeds; 1800 s; headline persistence, reserve/threshold sensitivity, attacker dilemma, 10,000/20,000 min rate-independence check | Paired tests and Proposition 2 stress validation |
| Adaptive-adversary sweep (run_m11_adaptive_adversary.py) | 480 | 960 | 20 seeds; 1800 s; 12 attack strategies over unique, legacy repeated, and representative (m,r,p) pools with Δ = {0,60} | Proposition 4 boundary validation; reports the worst swept reserve-pressure point |
| Paired modeled-observable privacy suite (run_m12_privacy_sidechannel.py) | 240 variants | 720 | 120 visible-trace-matched pairs; 3 loads × Δ = {0, 60} × 20 seeds; P3-Persist, P3-NoPersist, BudgetDoS | Initial-decision identity-label invariance audit and modeled external/internal distinguishability boundary |
| Joint robustness suite (run_m13_joint_robustness.py) | 600 | 1800 | epoch = {1,5,15 min} × observation loss = {0, 0.2, 0.4} × benign density = {100, 1000, 5000}/min; 20 seeds; three controls | Offered/observed service, false defer, work bound, and repeated-benign boundary |
| Adaptive local refinement (run_m14_adaptive_refinement.py) | 1280 | 1480 | 168-strategy 5-seed screen plus 11-strategy Δ = {0, 60}, 20-seed confirmation; BudgetDoS paired on top five | Dense local best-response search, r-effect audit, tied-region confirmation, and cap-distance audit |
| Worked-example traces (paperwalkthrough*.json + rpa_sim.py) | 2 | 577 events × 3 methods; 591 events × 1 method | seed 20260603; pre-persistence trace plus P3-Persist trace with N = 24, C = 4, B = 5, R = 40, k = 1; traces enabled | Running example and persistence trigger trace |
Table 13.
Public BLE datasets considered and why they do not directly support resolving-layer DoS evaluation.
Table 13.
Public BLE datasets considered and why they do not directly support resolving-layer DoS evaluation.
| Public Dataset | Content | Why Not Directly Usable Here |
|---|
| MIT Lincoln Laboratory BLE exposure-notification data collection report [35] | RSSI under controlled proximity scenarios | Proximity RSSI only; no IRK/resolving-list state, no unknown-RPA flooding, no host resolving-work labels [36] |
| Indoor BLE localization dataset [37] | RSSI fingerprints from devices to fixed anchors | Localization labels; does not expose private-address resolution or AES-equivalent matching cost |
| BLEBeacon dataset [38] | Beacon advertisement RSSI, timestamps, IDs | Occupancy/tracking traces; no resolving-list capacity pressure or attacker-injected RPA work [39] |
| BLE RSSI variability measurements [40] | RSSI vs. distance, orientation, and interference [41] | Used here only to anchor RSSI parameter ranges; not a resolution-workload dataset |
Table 14.
Main reduction numbers (RL = 8 headline; attack-amplification metric; mean ± SD over seven bonded-device scales and five seeds, n = 35 per attack-rate row).
Table 14.
Main reduction numbers (RL = 8 headline; attack-amplification metric; mean ± SD over seven bonded-device scales and five seeds, n = 35 per attack-rate row).
| Attack RPAs/min | Traffic Interpretation | StaticRL Mean ± SD | P3-NoPersist Mean ± SD | Reduction |
|---|
| 0 | No injected attack | 0.00 ± 0.00 | 0.00 ± 0.00 | 0.0% |
| 100 | Low stress | 28,602.51 ± 35,607.16 | 12,002.80 ± 13,736.49 | 58.0% |
| 1000 | Medium flood, 16.7/s | 284,074.69 ± 348,379.74 | 24,597.14 ± 29,519.86 | 91.3% |
| 10,000 | Heavy upper stress-test, 166.7/s | 2,818,840.11 ± 3,441,379.85 | 27,758.97 ± 33,787.36 | 99.0% |
Table 15.
Long-window validation summary for
N = 512 and RL = 8 (1800 s runs; 300 s warmup;
n = 3 seed means). The complete method-by-scenario table is provided as
Supplementary Table S1.
Table 15.
Long-window validation summary for
N = 512 and RL = 8 (1800 s runs; 300 s warmup;
n = 3 seed means). The complete method-by-scenario table is provided as
Supplementary Table S1.
| Scenario | Method | Attack/Min | Attack Amplification | Legit Rate | False Defer |
|---|
| heavy_flood | BudgetDoS | 10,000 | 45,192.00 | 0.5233 | 0.4767 |
| heavy_flood | P3-NoPersist | 10,000 | 45,198.72 | 0.5602 | 0.4403 |
| medium_flood | BudgetDoS | 1000 | 43,874.88 | 0.5809 | 0.4191 |
| medium_flood | P3-NoPersist | 1000 | 44,593.92 | 0.7554 | 0.2459 |
| normal_capacity | BudgetDoS | 0 | 0.00 | 0.8814 | 0.1186 |
| normal_capacity | P3-NoPersist | 0 | 0.00 | 0.9855 | 0.0234 |
Table 16.
Budget sensitivity trade-off (N = 512, RL = 8, 1800 s medium/heavy flood scenarios; metric rows are n = 3 seed means per budget/scenario pair).
Table 16.
Budget sensitivity trade-off (N = 512, RL = 8, 1800 s medium/heavy flood scenarios; metric rows are n = 3 seed means per budget/scenario pair).
| Scenario | Budget/ Window | Attack/Min | Reduction vs. StaticRL | Legit Rate | False Defer |
|---|
| medium_flood | 100 | 1000 | 91.1% | 0.7554 | 0.2459 |
| medium_flood | 250 | 1000 | 77.5% | 0.8707 | 0.1326 |
| medium_flood | 500 | 1000 | 54.9% | 0.9365 | 0.0683 |
| medium_flood | 1000 | 1000 | 9.7% | 0.9896 | 0.0171 |
| medium_flood | 2500 | 1000 | 0.0% | 1.0000 | 0.0072 |
| medium_flood | 5000 | 1000 | 0.0% | 1.0000 | 0.0072 |
| heavy_flood | 100 | 10,000 | 99.1% | 0.5602 | 0.4403 |
| heavy_flood | 250 | 10,000 | 97.7% | 0.6392 | 0.3617 |
| heavy_flood | 500 | 10,000 | 95.5% | 0.7089 | 0.2929 |
| heavy_flood | 1000 | 10,000 | 90.9% | 0.7708 | 0.2317 |
| heavy_flood | 2500 | 10,000 | 77.3% | 0.8752 | 0.1277 |
| heavy_flood | 5000 | 10,000 | 54.6% | 0.9403 | 0.0642 |
Table 17.
Persistence baselines and upper bound (N = 512, RL = 8, 1800 s medium/heavy flood scenarios; statistical rows use n = 20 seeds unless marked as an oracle or deterministic boundary). The pre-persistence P3 path is reported once as P3-NoPersist to avoid duplicate equal-by-construction rows.
Table 17.
Persistence baselines and upper bound (N = 512, RL = 8, 1800 s medium/heavy flood scenarios; statistical rows use n = 20 seeds unless marked as an oracle or deterministic boundary). The pre-persistence P3 path is reported once as P3-NoPersist to avoid duplicate equal-by-construction rows.
| Scenario | Method | Attack Amplification Mean ± SD [95% CI] | Legit Rate Mean [95% CI] | False Defer Mean [95% CI] |
|---|
| medium_flood | Random-RL | 504,557.42 ± 3220.32 [503,050.27, 506,064.58] | 1.0000 [1.0000, 1.0000] | 0.0000 [0.0000, 0.0000] |
| medium_flood | AdaptiveRateLimit | 44,059.68 ± 314.67 [43,912.41, 44,206.95] | 0.6235 [0.6176, 0.6293] | 0.3765 [0.3707, 0.3824] |
| medium_flood | BudgetDoS | 43,898.40 ± 301.05 [43,757.50, 44,039.30] | 0.5776 [0.5596, 0.5955] | 0.4224 [0.4045, 0.4404] |
| medium_flood | P3-NoPersist | 44,641.30 ± 301.53 [44,500.17, 44,782.42] | 0.7536 [0.7467, 0.7605] | 0.2481 [0.2413, 0.2549] |
| medium_flood | P3-Persist | 45,227.95 ± 280.60 [45,096.63, 45,359.28] | 0.9569 [0.9559, 0.9580] | 0.0484 [0.0470, 0.0498] |
| medium_flood | Oracle-Offline | 0.00 ± 0.00 [0.00, 0.00] | 1.0000 [1.0000, 1.0000] | 0.0000 [0.0000, 0.0000] |
| heavy_flood | Random-RL | 5,038,527.31 ± 9489.79 [5,034,085.95, 5,042,968.67] | 1.0000 [1.0000, 1.0000] | 0.0000 [0.0000, 0.0000] |
| heavy_flood | AdaptiveRateLimit | 45,658.37 ± 338.96 [45,499.73, 45,817.01] | 0.5910 [0.5861, 0.5959] | 0.4090 [0.4041, 0.4139] |
| heavy_flood | BudgetDoS | 45,648.29 ± 350.53 [45,484.23, 45,812.34] | 0.5663 [0.5351, 0.5975] | 0.4337 [0.4025, 0.4649] |
| heavy_flood | P3-NoPersist | 45,650.30 ± 342.78 [45,489.88, 45,810.73] | 0.5718 [0.5550, 0.5886] | 0.4284 [0.4116, 0.4452] |
| heavy_flood | P3-Persist | 45,765.22 ± 339.36 [45,606.39, 45,924.04] | 0.9557 [0.9547, 0.9567] | 0.0497 [0.0487, 0.0508] |
| heavy_flood | Oracle-Offline | 0.00 ± 0.00 [0.00, 0.00] | 1.0000 [1.0000, 1.0000] | 0.0000 [0.0000, 0.0000] |
Table 18.
Persistence-reserve sensitivity and attacker-strategy boundaries for N = 512 and RL = 8 (1800 s scenarios; statistical and confirmation rows use n = 20 seeds unless explicitly identified as the five-seed adaptive-refinement screen). For the headline setting B = 100, R = 200, W = 60, and C = 8, the arbitrary-flood cap is 60 (B + R)(N–C)/W = 151,200 AES-equivalent attempts/min.
Table 18.
Persistence-reserve sensitivity and attacker-strategy boundaries for N = 512 and RL = 8 (1800 s scenarios; statistical and confirmation rows use n = 20 seeds unless explicitly identified as the five-seed adaptive-refinement screen). For the headline setting B = 100, R = 200, W = 60, and C = 8, the arbitrary-flood cap is 60 (B + R)(N–C)/W = 151,200 AES-equivalent attempts/min.
| Experiment | Setting | Attack Amplification Mean ± SD | Legit Rate | False Defer | Interpretation |
|---|
| Reserve sensitivity | R = 50, k = 1, heavy unique flood | 45,765.22 ± 339.36 | 0.9557 | 0.0497 | Active set fits within even small reserve in this workload |
| Reserve sensitivity | R = 100, k = 1, heavy unique flood | 45,765.22 ± 339.36 | 0.9557 | 0.0497 | Same bound and service |
| Reserve sensitivity | R = 200, k = 1, heavy unique flood | 45,765.22 ± 339.36 | 0.9557 | 0.0497 | Headline setting |
| Reserve sensitivity | R = 400, k = 1, heavy unique flood | 45,765.22 ± 339.36 | 0.9557 | 0.0497 | No extra benefit once active repeats are covered |
| Threshold sensitivity | R = 200, k = 2, heavy unique flood | 45,754.13 ± 344.90 | 0.9086 | 0.0956 | More conservative threshold remains above all baselines |
| Threshold sensitivity | R = 200, k = 3, heavy unique flood | 45,745.06 ± 340.87 | 0.8657 | 0.1369 | Higher threshold trades service for stricter persistence |
| Attacker dilemma | unique-address attack, R = 200, k = 1 | 45,765.22 ± 339.36 | 0.9557 | 0.0497 | Unique flood cannot earn reserve |
| Attacker dilemma | repeated-address attack, duplicate filter OFF, R = 200, k = 1, 10,000/min | 146,163.02 ± 374.44 | 0.6411 | 0.3595 | Reserve can be pressured, but work remains bounded by B + R |
| Attacker dilemma | repeated-address attack, duplicate filter OFF, R = 200, k = 1, 20,000/min | 148,493.52 ± 209.70 | 0.5924 | 0.4078 | Mean remains below the 151,200 AES/min cap; 20 k/10 k seed-paired ratio mean is 1.016 |
| Attacker dilemma | repeated-address attack, duplicate filter ON (60 s Δ), R = 200, k = 1 | 504.00 ± 0.00 | 0.9433 | 0.0621 | Duplicate filtering removes high-rate repeats before reserve pressure |
| Adaptive sweep | Earlier coarse-grid reference, duplicate filter ON (m = 256, r = 1, p = 120 s) | 128,962.51 ± 49.59 | 0.9286 | 0.0767 | Reproduced historical point; rank 82/168 in the denser adaptive-refinement screen |
| Adaptive refinement | Confirmed tied-region representative, duplicate filter ON (m = 320, r = 1, p = 75 s) | 146,196.29 ± 380.58 | 0.6749 | 0.3256 | Highest confirmed mean; 96.69% of cap; 95% CI 146,018.17–146,374.41; duplicate-filtered attack fraction 0.9706 |
| Adaptive refinement | Same confirmed tied-region strategy under BudgetDoS, duplicate filter ON | 45,644.26 ± 351.86 | 0.0788 | 0.9212 | Lower work but sheds almost all legitimate traffic; paired comparator for the safety–service trade-off |
Table 19.
Direct resolving-list expansion check.
Table 19.
Direct resolving-list expansion check.
| C | StaticRL Attack Amp | No-Reserve Attack Amp | No-Reserve Legit Rate | No-Reserve False Defer |
|---|
| 8 | 504,181.44 | 44,537.47 | 0.7662 | 0.2355 |
| 16 | 496,178.56 | 44,005.12 | 0.8020 | 0.1996 |
| 32 | 480,172.80 | 42,862.08 | 0.8560 | 0.1453 |
| 64 | 448,161.28 | 40,384.51 | 0.9280 | 0.0725 |
| 512 | 0.00 | 0.00 | 1.0000 | 0.0000 |
Table 20.
Correctness and delay-model boundary.
Table 20.
Correctness and delay-model boundary.
| Claim | Value | Boundary |
|---|
| Legitimate resolution rate | P3-Persist persistence-suite flood rows: 0.9569 medium, 0.9557 heavy | Simulation result, not protocol proof |
| False defer legitimate rate | P3-Persist persistence-suite flood rows: 0.0484 medium, 0.0497 heavy | Budget/reserve trade-off, not a zero-cost claim |
| Delay/latency | Not claimed from current simulator | Requires queueing or firmware/trace measurement |
Table 21.
Legitimate-resolution path mix in representative runs.
Table 21.
Legitimate-resolution path mix in representative runs.
| Representative Run | Method | RL Hit Rate | Cache Hit Rate | Host Scan Rate | Budget Skip Rate | Defer Rate | Interpretation |
|---|
| N = 128, RL = 8, no flood | StaticRL | 0.740 | 0.000 | 0.260 | 0.000 | 0.000 | No cache reuse; many legitimate events still pay host fallback |
| N = 128, RL = 8, no flood | ZephyrCache | 0.010 | 0.950 | 0.040 | 0.000 | 0.000 | Practical cache reuse eliminates most repeated host scans |
| N = 128, RL = 8, no flood | P3-NoPersist | 0.000 | 0.950 | 0.050 | 0.000 | 0.000 | P3 preserves the same benign fast path as ZephyrCache |
| N = 1024, RL = 8, 10,000 attack RPAs/min | StaticRL | 0.540 | 0.000 | 0.460 | 0.000 | 0.000 | Flood keeps legitimate traffic on the most expensive path |
| N = 1024, RL = 8, 10,000 attack RPAs/min | BudgetDoS | 0.384 | 0.000 | 0.007 | 0.609 | 0.000 | Budget stops host work, but denied events are uniformly dropped |
| N = 1024, RL = 8, 10,000 attack RPAs/min | P3-NoPersist | 0.000 | 0.555 | 0.007 | 0.026 | 0.412 | Same bounded host work, but denied legitimate events shift from pure drop to defer |
Table 22.
Overhead summary.
Table 22.
Overhead summary.
| Item | P3-Persist Model Estimate | Interpretation |
|---|
| Positive cache | 1024 B | 64 entries × 16 B |
| RL metadata | 32 B at RL = 8 | 4 B per resolving-list entry |
| Activity/last-seen state | 4096 B at N = 512 | 8 B per bonded identity in long-window replication |
| Budget state | 64 B | Window id, used count and counters |
| Persistence reserve state | 1600 B at R = 200 | Denial/reserve accounting for repeated-address values |
| RSSI defer hint | 16 B | Internal scheduling hint only |
| Energy | AES-equivalent estimate only | No measured current claim |
| Measured power | Not claimed | Requires PPK2 or equivalent instrumentation |
Table 23.
nRF5340 DK auxiliary evidence.
Table 23.
nRF5340 DK auxiliary evidence.
| Item | Value | Interpretation |
|---|
| DK enumeration | Public text omits device SNR | Board is reachable for auxiliary validation |
| Role | BLE observer/scanner context | Supports RSSI/noisy-advertising parameter interpretation |
| Boundary | Not a P3 hardware implementation | Not a real attack-defense or power measurement |
Table 24.
Paired modeled-observable privacy audit (20 paired seeds per load/filter condition; external proxy = modeled defer rate, mean delay, and p95 delay).
Table 24.
Paired modeled-observable privacy audit (20 paired seeds per load/filter condition; external proxy = modeled defer rate, mean delay, and p95 delay).
| Load | Δ (s) | P3-Persist AUC | P3-NoPersist AUC | BudgetDoS AUC | Initial Paired Audit |
|---|
| No attack | 0 | 1.0 | 1.0 | 0.5 | All initial decisions matched |
| No attack | 60 | 0.5 | 0.5 | 0.5 | All initial decisions matched |
| Medium flood | 0 | 1.0 | 1.0 | 0.5 | All initial decisions matched |
| Medium flood | 60 | 0.5 | 0.5 | 0.5 | All initial decisions matched |
| Heavy flood | 0 | 0.5 | 0.5 | 0.5 | All initial decisions matched |
| Heavy flood | 60 | 0.5 | 0.5 | 0.5 | All initial decisions matched |
Table 25.
P3-Persist joint epoch–loss–benign boundary (20 seeds; offered rate uses generated legitimate events, observed rate uses observed legitimate events).
Table 25.
P3-Persist joint epoch–loss–benign boundary (20 seeds; offered rate uses generated legitimate events, observed rate uses observed legitimate events).
| Condition | Offered Legit Rate | Observed Legit Rate | Observed False Defer | Attack AES/min | Interpretation |
|---|
| epoch 15 min, loss 0, density 100, unique benign, attacked | 0.955313 | 0.955313 | 0.050653 | 49,783.104 | Lowest-pressure attacked main-cell reference |
| epoch 5 min, loss 0, density 100, unique benign, attacked | 0.853841 | 0.853841 | 0.153106 | 49,708.512 | Shorter epoch reduces service without changing the work conclusion |
| epoch 1 min, loss 0.4, density 5000, unique benign, attacked | 0.402741 | 0.671334 | 0.333547 | 33,477.696 | Adverse unique-benign boundary; dual denominators diverge |
| epoch 1 min, loss 0.4, density 5000, repeated benign, attacked | 0.345137 | 0.575279 | 0.425083 | 33,466.608 | Repeated benign values consume reserve and further reduce service |
| epoch 1 min, loss 0.4, density 5000, unique benign, no attack | 0.406062 | 0.674463 | 0.330103 | 0 | Epoch/loss/background pressure dominates this boundary |
Table 26.
Threats and mitigations.
Table 26.
Threats and mitigations.
| Threat | Mitigation in Manuscript |
|---|
| Simulation abstraction | Claims limited to AES-equivalent work in modeled settings. |
| RPA repetition model | Legitimate persistence follows same-epoch RPA semantics; unique/repeated background and dense adaptive attack variants are tested in the joint robustness and adaptive-refinement experiments, but real-stack traces remain future work. |
| Short RPA rotation and loss | The joint robustness experiment tests 1/5/15 min epochs and 0/20/40% modeled observation loss; the report offered and observed service separately, limiting service recovery to tested conditions. |
| Benign unknown density | The joint robustness experiment tests 100/1000/5000 RPA/min unique-benign traffic and a repeated-benign adverse control; repeated benign reserve pressure is disclosed rather than treated as a tuning-only concern. |
| Deployment premise | Scope narrowed to N > C retained-bond centrals; beacon-only, single-user, and N ≤ C deployments are excluded. |
| Energy estimate | Report AES-equivalent estimate, not measured current. |
| Hardware evidence | Keep nRF5340 DK as scanner-context record only; not validation. |
| Correctness | Report model-bounded observation, not formal proof. |
| Privacy boundary | The paired modeled-observable privacy audit supports matched initial pre-resolution decisions for identical visible traces but finds later modeled distinguishability in some conditions; no real end-to-end side-channel-free claim is made. |