Encrypted Advertising Data core API#
Provides simple to use API for Advertising, Periodic Advertising and Scan Response data encryption and decryption that is compatible with the Bluetooth Core Encrypted Advertisement Data (EAD) enhancement. For the usage of the APIs defined in sl_bt_ead_core.h please see esl_core_encrypt_message(void *msg, uint8_t *len) and esl_core_decrypt_message(void *msg, uint8_t *len) functions in esl_tag_crypto.c within ESL Tag core component.
Modules#
Typedefs#
Functions#
Macros#
EAD Randomizer size.
EAD Key Material size.
EAD Session Key size.
EAD Nonce size.
EAD IV size.
EAD Message Integrity Check size.
Advertising Data - header length field size.
Advertising Data - header AD Type field size.
Advertising Data header size, Core Ver.5.3, Vol 3. Part C, Fig.11.1.
EAD Message full packet size overhead.
EAD Message packet size overhead without the length field.
Encrypted Data AD Type.
B1 block, octet 2 (header) for EAD encryption, CSS d11, Part A, 1.23.3.
EAD Key Material Characteristics UUID.
Typedef Documentation#
Function Documentation#
sl_bt_ead_store_key#
sl_status_t sl_bt_ead_store_key (psa_key_usage_t key_usage, psa_key_lifetime_t lifetime, sl_bt_ead_key_material_p key_material, psa_key_id_t * key_id)
| Type | Direction | Argument Name | Description | 
|---|---|---|---|
| psa_key_usage_t | [in] | key_usage | set PSA_KEY_USAGE_ENCRYPT and/or PSA_KEY_USAGE_DECRYPT depending on expected usage. Other psa_key_usage_t flags can be used also, if needed. | 
| psa_key_lifetime_t | [in] | lifetime | use PSA_KEY_LIFETIME_VOLATILE or set custom PSA lifetime e.g., PSA_KEY_LIFETIME_FROM_PERSISTENCE_AND_LOCATION( PSA_KEY_PERSISTENCE_DEFAULT, 0x01) on devices with secure key storage (HSE-SVH). Value ignored if RADIOAES is used, and please also note that keys with persistent lifetime may reduce the throughput of cryptography. | 
| sl_bt_ead_key_material_p | N/A | key_material | key_material Pointer to the input key material in plain text format as described in Core v5.4, Vol 3, Part C, Section 12.6, that is replaced by key_id on successful key storage when PSA / TZ is used. Otherwise, only the key endianness is changed in- place and the key remains as plain text in RAM (that is, for the RadioAES use case). | 
| psa_key_id_t * | N/A | key_id | key_id Pointer to the requested key_id value for persistent keys. For volatile keys, the requested ID is ignored and then the pointed value changes to the resulting key_id on successful key import. Set the initial pointed value to PSA_KEY_ID_NULL if any resulting ID is acceptable for you for a persistent key, or request a specific value in the range of 0x0001-0x4000 but make sure the ID in't used for any other purpose because an already existing key with that ID will be overwritten. The pointed key_id value will be set to 0 if RadioAES is selected. | 
Store the key from EAD Key material Note
- In case of unsuccessful return, the original input key material will remain untouched, and therefore, as it's still sensitive data, the caller shall take care of handling it securely (e.g., to sanitize). 
Returns
- sl_status_t 
sl_bt_ead_delete_key#
sl_status_t sl_bt_ead_delete_key (sl_bt_ead_key_material_p key_material)
| Type | Direction | Argument Name | Description | 
|---|---|---|---|
| sl_bt_ead_key_material_p | [in] | key_material | Pointer to the key material to destroy. | 
Delete EAD key material from both volatile and, if applicable, non-volatile storage. Returns
- sl_status_t 
sl_bt_ead_randomizer_update#
sl_status_t sl_bt_ead_randomizer_update (sl_bt_ead_nonce_p nonce)
| Type | Direction | Argument Name | Description | 
|---|---|---|---|
| sl_bt_ead_nonce_p | N/A | nonce | nonce - Pointer to the EAD Nonce struct to be updated | 
Update the Randomizer field of the EAD Nonce value with newly generated value Returns
- sl_status_t 
sl_bt_ead_randomizer_set#
sl_status_t sl_bt_ead_randomizer_set (sl_bt_ead_randomizer_t randomizer, sl_bt_ead_nonce_p nonce)
| Type | Direction | Argument Name | Description | 
|---|---|---|---|
| sl_bt_ead_randomizer_t | [in] | randomizer | - Value to be set in the Nonce | 
| sl_bt_ead_nonce_p | [out] | nonce | - Pointer to the EAD Nonce struct to be updated | 
Set the Randomizer field of the EAD Nonce value manually to a given value Note
- Falls back to sl_bt_ead_randomizer_update() if Randomizer is NULL 
Returns
- sl_status_t 
sl_bt_ead_session_init#
sl_status_t sl_bt_ead_session_init (sl_bt_ead_key_material_p key_material, sl_bt_ead_randomizer_t randomizer, sl_bt_ead_nonce_p nonce)
| Type | Direction | Argument Name | Description | 
|---|---|---|---|
| sl_bt_ead_key_material_p | N/A | key_material | key_material - Pointer to the key material in the higher layer | 
| sl_bt_ead_randomizer_t | [in] | randomizer | - Pointer to the desired Randomizer value type or NULL. The Nonce will get a new random value during the invocation if NULL is passed. | 
| sl_bt_ead_nonce_p | [out] | nonce | - Pointer to the complete EAD Nonce structure. This can be omitted by advanced users by passing it as NULL, in which case only the session key is prepared. Although passing the nonce is the recommended use case, omitting it can still be useful for efficient in-place decryption when used with sl_bt_ead_unpack_decrypt(). | 
(Re)initialize the entire Nonce value with the IV from the key material given Note
- According to the Supplement to the Bluetooth Core Specification v11 Part A, Section 1.23.3: the session key shall be set to a value determined by a higher layer specification or otherwise negotiated between the devices that are sending and receiving the encrypted AD type. Any session keys with at least 128 bits of entropy may be used. sl_bt_ead_store_key() has to be called once on the key material after said key negotiation before the session init invocation! 
Returns
- sl_status_t 
sl_bt_ead_encrypt#
sl_status_t sl_bt_ead_encrypt (sl_bt_ead_key_material_p key_material, sl_bt_ead_nonce_p nonce, uint8_t length, uint8_t * data, sl_bt_ead_mic_t mic)
| Type | Direction | Argument Name | Description | 
|---|---|---|---|
| sl_bt_ead_key_material_p | [in] | key_material | - Pointer to the key material in the higher layer | 
| sl_bt_ead_nonce_p | [in] | nonce | - Pointer to the complete EAD Nonce structure | 
| uint8_t | [in] | length | - Length of the data to be encrypted | 
| uint8_t * | N/A | data | data - Pointer to the original message, contains encrypted message on success. | 
| sl_bt_ead_mic_t | [out] | mic | - Pointer to the mic storage space | 
Encrypt message in-place using EAD encryption Returns
- sl_status_t 
sl_bt_ead_decrypt#
sl_status_t sl_bt_ead_decrypt (sl_bt_ead_key_material_p key_material, sl_bt_ead_nonce_p nonce, sl_bt_ead_mic_t mic, uint8_t length, uint8_t * data)
| Type | Direction | Argument Name | Description | 
|---|---|---|---|
| sl_bt_ead_key_material_p | [in] | key_material | - Pointer to the key material in the higher layer | 
| sl_bt_ead_nonce_p | [in] | nonce | - Pointer to the (received!) Nonce structure | 
| sl_bt_ead_mic_t | [in] | mic | - Message integrity check value of the given message | 
| uint8_t | [in] | length | - Length of the data to be decrypted | 
| uint8_t * | N/A | data | data - Pointer to the encrypted message, contains decrypted message on success. | 
Decrypt message in-place that is encrypted with EAD Returns
- sl_status_t 
sl_bt_ead_unpack_decrypt#
sl_status_t sl_bt_ead_unpack_decrypt (sl_bt_ead_key_material_p key_material, uint8_t ** data, uint8_t * length)
| Type | Direction | Argument Name | Description | 
|---|---|---|---|
| sl_bt_ead_key_material_p | [in] | key_material | - Pointer to the key material in the higher layer | 
| uint8_t ** | N/A | data | data - Reference of the pointer to the full encrypted message in Advertising, Periodic Advertising, and Scan Response data format specified by Core v5.3, Vol 3, Part C, Section 11. Will be updated to the address to the decrypted message on success. | 
| uint8_t * | [out] | length | - Length of the decrypted data | 
Unpack advertising data that is encrypted with EAD and decrypt the message in place. Note
- : This function obfuscates the input data since every operation is done in place for the best possible speed. If the input data memory is allocated on the heap, then its original address and size has to be kept for proper deallocation. Consequently, it's also the caller's responsibility to make a copy of the resulting decrypted message if needed, before freeing up the storage space. Using this method instead of calling sl_bt_ead_unpack_ad_data and then sl_bt_ead_decrypt can be slightly faster, but also requires more care when used. 
Returns
- sl_status_t 
sl_bt_ead_pack_ad_data#
sl_status_t sl_bt_ead_pack_ad_data (sl_bt_ead_ad_structure_p ad_info, uint8_t * size, uint8_t * pack_buf)
| Type | Direction | Argument Name | Description | 
|---|---|---|---|
| sl_bt_ead_ad_structure_p | [in] | ad_info | - Pointer to the AD Data structure to be packed | 
| uint8_t * | N/A | size | size - In: size of the EAD Data buffer, out: packed length | 
| uint8_t * | [out] | pack_buf | - Pointer to the complete EAD Data buffer | 
Pack encrypted EAD AD_Data to Advertising, Periodic Advertising, and Scan Response data format specified by Core v5.3, Vol 3, Part C, Section 11 Returns
- sl_status_t 
sl_bt_ead_unpack_ad_data#
sl_status_t sl_bt_ead_unpack_ad_data (uint8_t * packed_data, sl_bt_ead_ad_structure_p ad_info)
| Type | Direction | Argument Name | Description | 
|---|---|---|---|
| uint8_t * | [in] | packed_data | - Pointer to the incoming EAD Data | 
| sl_bt_ead_ad_structure_p | N/A | ad_info | ad_info - Pointer to the AD Data struct for unpacked results. The 'length' parameter in the struct must be pre-set to the 'ad_data' buffer size. | 
Unpack encrypted EAD Data from Advertising, Periodic Advertising, and Scan Response data format specified by Core v5.3, Vol 3, Part C, Section 11 Returns
- sl_status_t