Multiple encryption key support for encrypted advertisement data
Techniques and systems are provided for wireless communications. For instances, a process can include: encrypting first data for broadcast based on a first cryptographic key; attaching a first key identifier for the first cryptographic key to the encrypted first data to generate a first payload value; encrypting the first payload value based on a second cryptographic key and a randomizer value; attaching the randomizer value to the encrypted first payload value to generate advertisement data; and broadcasting the advertisement data.
1 . A method for wireless communications by a network device, comprising:
encrypting first data for broadcast based on a first cryptographic key;
attaching a first key identifier for the first cryptographic key to the encrypted first data to generate a first payload value;
attaching a vendor specific type value to the first payload value;
encrypting second data for broadcast based on a third cryptographic key;
attaching a second key identifier for the third cryptographic key and the vendor specific type value to the encrypted second data to generate a second payload value;
attaching the second payload value to the first payload value;
encrypting the first payload value and second payload value based on a second cryptographic key and a randomizer value;
attaching the randomizer value to the encrypted first payload value and second payload value to generate advertisement data; and
broadcasting the advertisement data.
2 . The method of claim 1 , wherein the advertisement data further includes an advertisement type value indicating the advertisement data includes an encrypted payload.
3 . The method of claim 1 , wherein the first key identifier differs from the second key identifier and the first cryptographic key differs from the third cryptographic key.
4 . The method of claim 3 , further comprising:
determining a length of the vendor specific type value, the first key identifier, and the encrypted first data; and
attaching the determined length to the first payload value; and wherein encrypting the first payload value based on the second cryptographic key further comprises encrypting the first payload value, vendor specific type value, and determined length based on the second cryptographic key.
5 . The method of claim 1 , further comprising determining the first key identifier.
6 . The method of claim 1 , wherein the first data is further encrypted based on the randomizer value.
7 . A method for wireless communications by a wireless device, comprising:
receiving broadcast advertisement data;
decrypting a first payload value of the broadcast advertisement data using a first cryptographic key and a randomizer value of the broadcast advertisement data;
retrieving first key material based on a first key identifier obtained from the decrypted first payload value;
obtaining a second cryptographic key based on the retrieved first key material;
decrypting a second payload value using the second cryptographic key, the second payload value obtained from the decrypted first payload value;
decrypting the second payload value of the broadcast advertisement data using the first cryptographic key and the randomizer value;
retrieving second key material based on a second key identifier obtained from the decrypted second payload value;
obtaining a third cryptographic key based on the retrieved second key material; and
decrypting a third payload value using the third cryptographic key and the randomizer value, the third payload value obtained from the decrypted first payload value.
8 . The method of claim 7 , wherein the advertisement data further includes an advertisement type value indicating the advertisement data includes an encrypted payload.
9 . The method of claim 7 , wherein the first key identifier differs from the second key identifier and the first cryptographic key differs from the third cryptographic key.
10 . The method of claim 7 , wherein the first key material and second key material are stored on the wireless device.
11 . The method of claim 7 , further comprising obtaining the first key identifier from the decrypted first payload value based on a vendor specific type value in the decrypted first payload value.
12 . The method of claim 11 , wherein obtaining the second cryptographic key comprises retrieving the second cryptographic key using the first key identifier.
13 . An apparatus for wireless communications, the apparatus comprising:
at least one memory; and
at least one processor coupled to the at least one memory, the at least one processor being configured to:
encrypt first data for broadcast based on a first cryptographic key;
attach a first key identifier for the first cryptographic key to the encrypted first data to generate a first payload value;
attach a vendor specific type value to the first payload value;
encrypt second data for broadcast based on a third cryptographic key;
attach a second key identifier for the third cryptographic key and the vendor specific type value to the encrypted second data to generate a second payload value;
attach the second payload value to the first payload value;
encrypt the first payload value and second payload value based on a second cryptographic key and a randomizer value;
attach the randomizer value to the encrypted first payload value and second payload value to generate advertisement data; and
broadcast the advertisement data.
14 . The apparatus of claim 13 , wherein the advertisement data further includes an advertisement type value indicating the advertisement data includes an encrypted payload.
15 . The apparatus of claim 13 , wherein the first key identifier differs from the second key identifier and the first cryptographic key differs from the third cryptographic key.
16 . The apparatus of claim 15 , wherein the at least one processor is further configured to:
determine a length of the vendor specific type value, the first key identifier, and the encrypted first data; and
attach the determined length to the first payload value; and wherein encrypting the first payload value based on the second cryptographic key further comprises encrypting the first payload value, vendor specific type value, and determined length based on the second cryptographic key.
17 . The apparatus of claim 13 , wherein the at least one processor is further configured to determine the first key identifier.
18 . The apparatus of claim 13 , wherein the first data is further encrypted based on the randomizer value.
19 . An apparatus for wireless communications, comprising:
at least one memory; and
at least one processor coupled to the at least one memory, the at least one processor being configured to:
receive broadcast advertisement data;
decrypt a first payload value of the broadcast advertisement data using a first cryptographic key and a randomizer value of the broadcast advertisement data;
retrieve first key material based on a first key identifier obtained from the decrypted first payload value;
obtain a second cryptographic key based on the retrieved first key material;
decrypt a second payload value using the second cryptographic key, the second payload value obtained from the decrypted first payload value;
decrypt the second payload value of the broadcast advertisement data using the first cryptographic key and the randomizer value;
retrieve second key material based on a second key identifier obtained from the decrypted second payload value;
obtain a third cryptographic key based on the retrieved second key material; and
decrypt a third payload value using the third cryptographic key and the randomizer value, the third payload value obtained from the decrypted first payload value.
20 . The apparatus of claim 19 , wherein the advertisement data further includes an advertisement type value indicating the advertisement data includes an encrypted payload.
21 . The apparatus of claim 19 , wherein the first key identifier differs from the second key identifier and the first cryptographic key differs from the third cryptographic key.
22 . The apparatus of claim 19 , wherein the first key material and second key material are stored on the apparatus.
23 . The apparatus of claim 19 , wherein the at least one processor is further configured to obtain the first key identifier from the decrypted first payload value based on a vendor specific type value in the decrypted first payload value.
24 . The apparatus of claim 23 , wherein, to obtain the second cryptographic key, the at least one processor is further configured to retrieve the second cryptographic key using the first key identifier.