Silicon Labs
  • ⟵ Back
    Products
    Tech Talks 2025 Webinar Series: Empowering IoT Innovation
    WirelessWireless
    Amazon Sidewalk
    Bluetooth
    Matter
    Multiprotocol
    Proprietary
    Thread
    Wi-Fi
    Wi-SUN
    Z-Wave
    Zigbee
    TechnologyTechnology
    Channel Sounding
    Energy Harvesting
    LPWAN
    Machine Learning
    Security
    Non-WirelessNon-Wireless
    MCUs
    Sensors
    USB Bridges
    Power Management
    ServicesServices
    Custom Part Manufacturing
    Developer Services
    SDK Extended Maintenance Service
  • ⟵ Back
    Applications
    Smart HomeSmart Home
    Appliances
    Entertainment Devices
    Hubs, Panel and Access Points
    LED Lighting
    Security Cameras
    Sensors
    Smart Locks
    Switches
    Industrial IoTIndustrial IoT
    Access Control
    Asset Tracking
    Battery-Powered Tools
    Circuit Breakers
    Commercial Lighting
    Electric Submetering
    Factory Automation
    Human Machine Interface
    Industrial Wearables
    Predictive Maintenance
    Process Automation
    Smart HVAC
    Smart CitiesSmart Cities
    Battery Storage
    EV Charging Stations
    Smart Agriculture
    Smart Buildings
    Smart Metering
    Smart Solar PV System
    Street Lighting
    Smart RetailSmart Retail
    Commercial Lighting
    Direction Finding
    Electronic Shelf Labels
    Loss Prevention
    Wi-Fi Access Points
    Connected HealthConnected Health
    Portable Medical Devices
    Smart Hospitals
    Smart Wearable Devices
  • ⟵ Back
    Ecosystems
    Tech Talks 2025 Webinar Series: Empowering IoT Innovation
    Ecosystem PartnersEcosystem Partners
    Amazon Sidewalk
    Google Home
    Bluetooth Developer Journey
    Bluetooth Mesh Developer Journey
    Matter Developer Journey
    Wi-Fi Developer Journey
  • ⟵ Back
    Resources
    Simplicity Studio 5
    Fast track IoT development
    Developer ToolsDeveloper Tools
    Software Documentation
    Release Notes
    GitHub
    Technical Resource Library
    Simplicity Studio
    Mobile Apps
    Software Development Kits
    Hardware Development Kits
    Gateways
    RTOS
    Content and TrainingContent and Training
    Tech Talks 2025 Webinar Series
    Works With 2024 On-Demand
    IoT for Good Developer Stories
    Blog
    Case Studies
    Whitepapers
    Training Library
    Webinars
    SupportSupport
    Community
    Partner Network
    Channel & Distribution
    Quality and Packaging
    How to Buy
    Submit a Ticket
    Report a Security Issue
  • ⟵ Back
    Company
    Tech Talks 2025 Webinar Series: Empowering IoT Innovation
    CompanyCompany
    Careers
    Environmental, Social & Governance
    Community Commitment
    Diversity, Equity and Inclusion
    Environmental Sustainability
    Quality
    Management Team
    Supply Chain Responsibility
    News & EventsNews & Events
    Blog
    News Room
    Events
    Investor RelationsInvestor Relations
    Annual Report & Proxies
    Board of Directors
    Quarterly Results
    SEC Filings
    OfficesOffices
    Hyderabad
    Other Global Offices
    Contact Us
English
  • English
  • 简体中文
  • 日本語
Ask AI
AskAI
Ask AI
//
Wireless // Bluetooth // Certificate Based Authentication and Pairing (CBAP)

Certificate Based Authentication and Pairing (CBAP)

Certificate Based Authentication and Pairing or CBAP helps streamline the authentication and pairing process in Bluetooth LE devices. With built-in security features, it eliminates the need to manually authenticate devices using QR codes, passkeys, or NFC based pairings, and automatically authenticates connection by signing the pairing data with their own secret key.

Why CBAP?

Fast and Secure Connection Between Thousands of Devices

Eliminates manual intervention which not only speeds up the authentication process but also improves security by mitigating human error.

Ensures the Device is From a Trusted Manufacturer

Enables one-way (phone-to-device) or two-way (device-to-device) authenticated connections only with a trusted manufacturer.

Proof of Identity
and Eligibility

Matches identity of the device and checks eligibility through stored authentication certificate.

Pairing with CBAP ensures authenticated communication, minimizing man-in-the-middle threats.

Parameter Just Works Numerical Comparison / Passkey OOB CBAP
Manual Intervention None Visual comparison of numbers Physical proximity between devices None
Security Level Low High High Very High
Man-in-the-Middle Protection None Yes Yes Yes
Counterfeit Protection None None None Present
Automation Possible Not Possible Not Possible Possible
Back Channel for Authentication Not Possible Not Possible Required Not Required
Cost of Large-scale Operation Low High High Low



Silicon Labs CBAP Solutions

Silicon Labs is an industry leader in Bluetooth LE solutions, and we can help you implement Certificate Based Authentication and Pairing to ensure top-tier security for your devices without requiring any user interaction. Currently, certificate-based authentication and pairing is supported on Secure Vault-High and Secure Vault-Mid devices.

Secure Vault-High

EFR32BG21 Series 2 Bluetooth Low Energy (SoC) - EFR32BG21
EFR32BG21 devices are 2.4 GHz wireless SOCs optimized for line-powered Bluetooth Low Energy and Bluetooth mesh applications, including connected lighting, smart plugs, gateways and voice assistants.
More Information
EFR32BG21 Series 2 Bluetooth Low Energy (SoC) - EFR32BG21

Wireless Gecko Series 2 devices are the next evolution of Wireless Gecko devices bringing high performance, low power, and secure solutions to the Internet of Things. Designed to increase processing capability, improve RF performance and lower active current, the devices also provide the highest level of IoT device security. The EFR32BG21 devices are also designed to support Silicon Labs' enhanced security option, Secure Vault. Learn more about Silicon Labs' security portfolio.

EFR32BG21 devices are 2.4 GHz wireless SOCs optimized for line-powered Bluetooth Low Energy and Bluetooth mesh applications, including connected lighting, smart plugs, gateways and voice assistants. An 80 MHz ARM® Cortex®-M33 core provides plenty of processing capability while an integrated security subsystem provides leading security features that greatly reduce the risk of IoT security breaches and compromised intellectual property. With better than -104.3 dBm sensitivity and up to +20 dBm output power, the EFR32BG21 family uses Simplicity Studio 5 development tools, providing easy migration and fast time-to-market with development kits, SDKs, mobile apps, our energy profiler and patented network analyzer.

Visit EFR32BG21 Series 2 Bluetooth Low Energy SoC Family
X
Key Specs
Bluetooth 5.4 & Bluetooth mesh Support
Highest level of IoT Security
Secure Vault™
EFR32BG24 Series 2 Bluetooth Low Energy SoC - EFR32BG24
The BG24 family of 2.4 GHz wireless SoCs and modules feature the large flash and RAM capacities and PSA Level 3 Secure Vault protection, ideal for home, medical, and industrial applications.
More Information
EFR32BG24 Series 2 Bluetooth Low Energy SoC - EFR32BG24

The EFR32BG24 Wireless SoCs are ideal for IOT wireless connectivity using Bluetooth Low Energy and Bluetooth mesh for smart home, lighting, and portable medical products. With AECQ-100 qualification, support for Channel Sounding, and key features like high performance 2.4 GHz RF, low current consumption, an AI/ML hardware accelerator and Secure Vault™, IoT device makers can create the smart, robust, and energy-efficient products that are secure from remote and local cyber-attacks. An ARM Cortex®-M33 running up to 78 MHz and up to 1.5 MB of Flash and 256 kB of RAM provides resources for demanding applications while leaving room for future growth. Target applications include gateways/hubs, sensors, switches, door locks, smart plugs, LED lighting, luminaires, blood glucose meters and pulse oximeters.

Visit EFR32BG24 Series 2 Bluetooth LE SoC Family
X
Key Specs
Supports Bluetooth 6.0, Bluetooth mesh & Proprietary
Ideal for low-power battery-powered IoT devices
EFR32FG28 Sub-GHz Wireless + 2.4 GHz BLE SoCs
The FG28 dual band Sub-GHz + 2.4 GHz Bluetooth LE SoC solution combines a high-performance Sub-GHz radio that provides long range capabilities and a Bluetooth radio for increased design flexibility.
More Information
EFR32FG28 Sub-GHz Wireless + 2.4 GHz BLE SoCs

The EFR32FG28 SoC is an ideal dual band Sub-GHz + 2.4 GHz Bluetooth LE SoC solution for IoT applications in smart homes, security, lighting, building automation, and metering. This dual band solution combines a high-performance Sub-GHz radio that provides long range capabilities and a Bluetooth radio for increased design flexibility. The large memory footprint and increased IO count allows for design consolidation and Secure Vault™ gives flexibility to choose the security level that meets your product’s needs.

Visit EFR32FG28 Sub-GHz Wireless + 2.4 GHz BLE SoCs Family
X
Key Specs
Up to 1024 kB of Flash and 256 kB of RAM
Sub-GHz and Bluetooth LE Support

Secure Vault-Mid Devices through TrustZone

EFR32BG21 Series 2 Bluetooth Low Energy (SoC) - EFR32BG21
EFR32BG21 devices are 2.4 GHz wireless SOCs optimized for line-powered Bluetooth Low Energy and Bluetooth mesh applications, including connected lighting, smart plugs, gateways and voice assistants.
More Information
EFR32BG21 Series 2 Bluetooth Low Energy (SoC) - EFR32BG21

Wireless Gecko Series 2 devices are the next evolution of Wireless Gecko devices bringing high performance, low power, and secure solutions to the Internet of Things. Designed to increase processing capability, improve RF performance and lower active current, the devices also provide the highest level of IoT device security. The EFR32BG21 devices are also designed to support Silicon Labs' enhanced security option, Secure Vault. Learn more about Silicon Labs' security portfolio.

EFR32BG21 devices are 2.4 GHz wireless SOCs optimized for line-powered Bluetooth Low Energy and Bluetooth mesh applications, including connected lighting, smart plugs, gateways and voice assistants. An 80 MHz ARM® Cortex®-M33 core provides plenty of processing capability while an integrated security subsystem provides leading security features that greatly reduce the risk of IoT security breaches and compromised intellectual property. With better than -104.3 dBm sensitivity and up to +20 dBm output power, the EFR32BG21 family uses Simplicity Studio 5 development tools, providing easy migration and fast time-to-market with development kits, SDKs, mobile apps, our energy profiler and patented network analyzer.

Visit EFR32BG21 Series 2 Bluetooth Low Energy SoC Family
X
Key Specs
Bluetooth 5.4 & Bluetooth mesh Support
Highest level of IoT Security
Secure Vault™
EFR32BG22 Series 2 Bluetooth Low Energy (SoC)
The BG22 is the lowest-power Bluetooth LE device in our portfolio, bringing an ideal balance of features, power efficiency, and power consumption to battery-powered IoT devices.
More Information
EFR32BG22 Series 2 Bluetooth Low Energy (SoC)

EFR32BG22 and EFR32BG22E Bluetooth low energy (LE) wireless SoC solutions are part of the Wireless Gecko Series 2 platform. These devices are designed with a strong focus on energy efficiency, offering best-in-class ultra-low transmit and receive power, and a high-performance, low-power Arm® Cortex®-M33 core delivers industry-leading energy efficiency that can extend coin cell battery life up to ten years. Where BG22 allows you to create energy-efficient applications, the BG22E – ‘E’ denoting Energy Conservation – takes this a step further by enhancing battery longevity and supporting designs that eliminate the need for batteries altogether. Our BG22 and BG22E family's are the ideal market leading SoCs for Ambient IoT or Energy Harvesting devices. Target applications include Bluetooth mesh low-power nodes, smart door locks, personal healthcare and fitness devices. Asset tracking tags, beacons and indoor navigation also benefit from the SoCs' versatile Bluetooth Angle of Arrival (AoA) and Angle of Departure (AoD) capabilities and sub-one-meter location accuracy.

Visit EFR32BG22 Series 2 Bluetooth Low Energy SoC Family
X
Key Specs
Supports Bluetooth 5.4 & Bluetooth mesh
Ideal for ultra-low-power battery-powered or battery-less IoT devices
EFR32BG24 Series 2 Bluetooth Low Energy SoC - EFR32BG24
The BG24 family of 2.4 GHz wireless SoCs and modules feature the large flash and RAM capacities and PSA Level 3 Secure Vault protection, ideal for home, medical, and industrial applications.
More Information
EFR32BG24 Series 2 Bluetooth Low Energy SoC - EFR32BG24

The EFR32BG24 Wireless SoCs are ideal for IOT wireless connectivity using Bluetooth Low Energy and Bluetooth mesh for smart home, lighting, and portable medical products. With AECQ-100 qualification, support for Channel Sounding, and key features like high performance 2.4 GHz RF, low current consumption, an AI/ML hardware accelerator and Secure Vault™, IoT device makers can create the smart, robust, and energy-efficient products that are secure from remote and local cyber-attacks. An ARM Cortex®-M33 running up to 78 MHz and up to 1.5 MB of Flash and 256 kB of RAM provides resources for demanding applications while leaving room for future growth. Target applications include gateways/hubs, sensors, switches, door locks, smart plugs, LED lighting, luminaires, blood glucose meters and pulse oximeters.

Visit EFR32BG24 Series 2 Bluetooth LE SoC Family
X
Key Specs
Supports Bluetooth 6.0, Bluetooth mesh & Proprietary
Ideal for low-power battery-powered IoT devices
EFR32BG27 Series 2 Bluetooth Low Energy SoC
The BG27 family of Bluetooth LE and Bluetooth mesh SoCs are available with DCDC Boost in WLCSP packaging for small form factor applications, from medical devices to wearables and beyond.
More Information
EFR32BG27 Series 2 Bluetooth Low Energy SoC

The EFR32BG27 family of wireless SoCs opens up new possibilities by offering an ultra-small WLCSP package (2.3 mm x 2.6 mm) capable of running on button cell batteries. Now device makers can address applications with extremely small form-factor requirements without sacrificing performance and security. The BG27 Bluetooth SoC features an integrated DCDC boost that allows operation down to 0.8 volts, enabling support for single-cell alkaline and 1.5-volt button cell batteries that are typically used in medical applications for battery-operated patches and continuous glucose monitoring (CGM) devices. Additionally, the wakeup pin on the BG27 allows products in a warehouse or transit to remain off for months, consuming less than 20 nA, ensuring the battery remains fully charged for use. The integrated coulomb counter enables accurate battery level monitoring to avoid unexpected battery depletion for critical applications. Target applications include connected medical devices, wearables, sensors, switches, smart locks, and both commercial and LED lighting.

Visit EFR32BG27 Series 2 Small Bluetooth LE SoC Family
X
Key Specs
Supports Bluetooth 5.4, Bluetooth mesh & Proprietary
Ideal for low-power battery-powered IoT devices
EFR32FG28 Sub-GHz Wireless + 2.4 GHz BLE SoCs
The FG28 dual band Sub-GHz + 2.4 GHz Bluetooth LE SoC solution combines a high-performance Sub-GHz radio that provides long range capabilities and a Bluetooth radio for increased design flexibility.
More Information
EFR32FG28 Sub-GHz Wireless + 2.4 GHz BLE SoCs

The EFR32FG28 SoC is an ideal dual band Sub-GHz + 2.4 GHz Bluetooth LE SoC solution for IoT applications in smart homes, security, lighting, building automation, and metering. This dual band solution combines a high-performance Sub-GHz radio that provides long range capabilities and a Bluetooth radio for increased design flexibility. The large memory footprint and increased IO count allows for design consolidation and Secure Vault™ gives flexibility to choose the security level that meets your product’s needs.

Visit EFR32FG28 Sub-GHz Wireless + 2.4 GHz BLE SoCs Family
X
Key Specs
Up to 1024 kB of Flash and 256 kB of RAM
Sub-GHz and Bluetooth LE Support


How is CBAP Implemented?

1. The authenticator device verfies that the target device comes from a  trusted manufacturer by authenticating its device certificate using the CA certificate.



2. The devices begin OOB pairing with data sent from the target device signed by private key and authenticated using the public key in the device certificate.



3. Pairing completes successfully with authenticated, encrypted communication between devices.

Watch Now

How Certificate Based Authentication and Pairing (CBAP) is Implemented

CBAP with CPMS

CBAP enabled devices can utilize certificates injected by CPMS during manufacturing.

Learn how Silicon Labs can help customize your wireless hardware and MCUs with advanced security and unique certificates using Custom Part Manufacturing Service (CPMS).

Get Started with CPMS
Application Note

Certificate-Based Bluetooth Authentication and Pairing

This application note describes the theoretical background of certificate-based authentication and pairing, and demonstrates the usage of the related sample applications that can be found in Silicon Labs’ Bluetooth SDK.

Download Now
Silicon Labs
Stay Connected With Us
Plug into the latest on Silicon Labs products, including product releases and resources, documentation updates, PCN notifications, upcoming events, and more.
  • About Us
  • Careers
  • Community
  • Contact Us
  • Cookies
  • Corporate Responsibility
  • Investor Relations
  • Press Room
  • Privacy and Terms
  • Site Feedback
Copyright © Silicon Laboratories. All rights reserved.
Also of Interest:
  • Third Party Accreditation
  • Extending Bluetooth with Mesh Networking
  • Level 3 PSA Certification What it is and Why it Matters

Your File Will Start Downloading Shortly

Thank you for downloading .

If you have any issues downloading, please contact sales support or product technical support.

Close
Loading Results
Close

Please select at least one column.