mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-03 03:31:41 +03:00
feat(esp_wifi): Add ESP-IDF specific changes for OWE-Only SoftAP
1) Add Support for OWE in wifi driver for SoftAP mode. 2) Add some changes in 4-Way Handshake to support OWE in softAP. 3) Add some restructuring changes.
This commit is contained in:
@@ -200,7 +200,7 @@ void *hostap_init(void)
|
|||||||
esp_wifi_ap_set_group_mgmt_cipher_internal(cipher_type_map_supp_to_public(auth_conf->group_mgmt_cipher));
|
esp_wifi_ap_set_group_mgmt_cipher_internal(cipher_type_map_supp_to_public(auth_conf->group_mgmt_cipher));
|
||||||
|
|
||||||
#ifdef CONFIG_OWE_SOFTAP
|
#ifdef CONFIG_OWE_SOFTAP
|
||||||
if (authmode == WIFI_AUTH_OWE) {
|
if (authmode == WIFI_AUTH_OWE && esp_wifi_ap_get_owe_config_internal()) {
|
||||||
auth_conf->wpa_key_mgmt = WPA_KEY_MGMT_OWE;
|
auth_conf->wpa_key_mgmt = WPA_KEY_MGMT_OWE;
|
||||||
}
|
}
|
||||||
#endif /* CONFIG_OWE_SOFTAP */
|
#endif /* CONFIG_OWE_SOFTAP */
|
||||||
@@ -375,67 +375,27 @@ u16 esp_send_assoc_resp(struct hostapd_data *hapd, const u8 *addr,
|
|||||||
u16 status_code, bool omit_rsnxe, int subtype)
|
u16 status_code, bool omit_rsnxe, int subtype)
|
||||||
{
|
{
|
||||||
#define ASSOC_RESP_LENGTH 20
|
#define ASSOC_RESP_LENGTH 20
|
||||||
u8 buf[ASSOC_RESP_LENGTH];
|
|
||||||
wifi_mgmt_frm_req_t *reply = NULL;
|
wifi_mgmt_frm_req_t *reply = NULL;
|
||||||
int send_len = 0;
|
|
||||||
|
|
||||||
int res = WLAN_STATUS_SUCCESS;
|
int res = WLAN_STATUS_SUCCESS;
|
||||||
|
|
||||||
|
#ifdef CONFIG_OWE_SOFTAP
|
||||||
|
if ((hapd->conf->wpa_key_mgmt & WPA_KEY_MGMT_OWE) && esp_wifi_ap_get_owe_config_internal()) {
|
||||||
|
int owe_ie_len = 0;
|
||||||
|
u8 *owe_ie = NULL;
|
||||||
|
owe_ie = owe_build_assoc_resp_dhie(hapd, addr, &owe_ie_len);
|
||||||
|
if (owe_ie_len <= 0 || !owe_ie) {
|
||||||
|
wpa_printf(MSG_ERROR, "%s : error creating dhie for assoc resp %d ", __func__, owe_ie_len);
|
||||||
|
}
|
||||||
|
esp_wifi_set_appie_internal(WIFI_APPIE_ASSOC_RESP, owe_ie, owe_ie_len, 0);
|
||||||
|
}
|
||||||
|
#else
|
||||||
|
u8 buf[ASSOC_RESP_LENGTH];
|
||||||
|
int send_len = 0;
|
||||||
|
|
||||||
if (!omit_rsnxe) {
|
if (!omit_rsnxe) {
|
||||||
send_len = esp_wifi_build_rsnxe(hapd, buf, ASSOC_RESP_LENGTH);
|
send_len = esp_wifi_build_rsnxe(hapd, buf, ASSOC_RESP_LENGTH);
|
||||||
}
|
}
|
||||||
#ifdef CONFIG_OWE_SOFTAP
|
|
||||||
#define OWE_DH_GROUP 19
|
|
||||||
#define OWE_DHIE_LEN 37
|
|
||||||
if ((hapd->conf->wpa_key_mgmt & WPA_KEY_MGMT_OWE)) {
|
|
||||||
struct wpabuf *pub;
|
|
||||||
struct sta_info *sta = ap_get_sta(hapd, addr);
|
|
||||||
if (!sta) {
|
|
||||||
return WLAN_STATUS_UNSPECIFIED_FAILURE;
|
|
||||||
}
|
|
||||||
|
|
||||||
struct wpabuf *owe_buf = wpabuf_alloc(hapd->wpa_auth->wpa_ie_len);
|
|
||||||
if (!owe_buf) {
|
|
||||||
wpa_printf(MSG_ERROR, "Memory allocation failed for OWE IE");
|
|
||||||
return WLAN_STATUS_UNSPECIFIED_FAILURE;
|
|
||||||
}
|
|
||||||
|
|
||||||
u8 *pos, buf[128];
|
|
||||||
int res;
|
|
||||||
int owe_ie_len = 0;
|
|
||||||
|
|
||||||
pos = buf;
|
|
||||||
|
|
||||||
pos = wpa_auth_write_assoc_resp_owe(sta->wpa_sm, pos,
|
|
||||||
buf + sizeof(buf) - pos);
|
|
||||||
|
|
||||||
wpabuf_resize(&owe_buf, pos - buf);
|
|
||||||
wpabuf_put_data(owe_buf, buf, pos - buf);
|
|
||||||
owe_ie_len = pos - buf;
|
|
||||||
|
|
||||||
pub = crypto_ecdh_get_pubkey(sta->owe_ecdh, 0);
|
|
||||||
if (!pub) {
|
|
||||||
res = WLAN_STATUS_UNSPECIFIED_FAILURE;
|
|
||||||
return res;
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
wpa_hexdump_buf(MSG_DEBUG, "Own public key", pub);
|
|
||||||
|
|
||||||
wpabuf_resize(&owe_buf, OWE_DHIE_LEN);
|
|
||||||
wpabuf_put_u8(owe_buf, WLAN_EID_EXTENSION);
|
|
||||||
wpabuf_put_u8(owe_buf, 1 + 2 + wpabuf_len(pub));
|
|
||||||
wpabuf_put_u8(owe_buf, WLAN_EID_EXT_OWE_DH_PARAM);
|
|
||||||
wpabuf_put_le16(owe_buf, IANA_SECP256R1);
|
|
||||||
wpabuf_put_buf(owe_buf, pub);
|
|
||||||
wpabuf_free(pub);
|
|
||||||
|
|
||||||
wpa_hexdump_buf(MSG_DEBUG, "OWE: Buffer", owe_buf);
|
|
||||||
owe_ie_len = wpabuf_len(owe_buf);
|
|
||||||
|
|
||||||
esp_wifi_set_appie_internal(WIFI_APPIE_ASSOC_RESP, (uint8_t *)wpabuf_head(owe_buf), owe_ie_len, 0);
|
|
||||||
}
|
|
||||||
#else
|
|
||||||
esp_wifi_set_appie_internal(WIFI_APPIE_ASSOC_RESP, buf, send_len, 0);
|
esp_wifi_set_appie_internal(WIFI_APPIE_ASSOC_RESP, buf, send_len, 0);
|
||||||
#endif /* CONFIG_OWE_SOFTAP */
|
#endif /* CONFIG_OWE_SOFTAP */
|
||||||
|
|
||||||
@@ -483,7 +443,8 @@ uint8_t wpa_status_to_reason_code(int status)
|
|||||||
|
|
||||||
bool hostap_new_assoc_sta(struct sta_info *sta, uint8_t *bssid, u8 *wpa_ie,
|
bool hostap_new_assoc_sta(struct sta_info *sta, uint8_t *bssid, u8 *wpa_ie,
|
||||||
u8 wpa_ie_len, u8 *rsnxe, uint16_t rsnxe_len,
|
u8 wpa_ie_len, u8 *rsnxe, uint16_t rsnxe_len,
|
||||||
bool *pmf_enable, int subtype, uint8_t *pairwise_cipher, uint8_t *reason, uint8_t *rsn_selection_ie, uint8_t *owe_dh, uint8_t owe_ie_len)
|
bool *pmf_enable, int subtype, uint8_t *pairwise_cipher,
|
||||||
|
uint8_t *reason, uint8_t *rsn_selection_ie, uint8_t *owe_dh, uint8_t owe_ie_len)
|
||||||
{
|
{
|
||||||
struct hostapd_data *hapd = (struct hostapd_data*)esp_wifi_get_hostap_private_internal();
|
struct hostapd_data *hapd = (struct hostapd_data*)esp_wifi_get_hostap_private_internal();
|
||||||
enum wpa_validate_result res = WPA_IE_OK;
|
enum wpa_validate_result res = WPA_IE_OK;
|
||||||
@@ -534,12 +495,16 @@ bool hostap_new_assoc_sta(struct sta_info *sta, uint8_t *bssid, u8 *wpa_ie,
|
|||||||
status = wpa_res_to_status_code(res);
|
status = wpa_res_to_status_code(res);
|
||||||
|
|
||||||
#ifdef CONFIG_OWE_SOFTAP
|
#ifdef CONFIG_OWE_SOFTAP
|
||||||
if (hapd->conf->wpa_key_mgmt == WPA_KEY_MGMT_OWE) {
|
uint8_t owe_enabled = esp_wifi_ap_get_owe_config_internal();
|
||||||
status = owe_process_assoc_req(sta, owe_dh, owe_ie_len);
|
if (hapd->conf->wpa_key_mgmt & WPA_KEY_MGMT_OWE &&
|
||||||
if (status != WLAN_STATUS_SUCCESS) {
|
sta->wpa_sm->wpa_key_mgmt == WPA_KEY_MGMT_OWE &&
|
||||||
return status;
|
owe_dh && owe_enabled) {
|
||||||
|
status = owe_process_assoc_req(hapd, sta, owe_dh, owe_ie_len);
|
||||||
|
if (status != WLAN_STATUS_SUCCESS) {
|
||||||
|
wpa_printf(MSG_ERROR, "OWE : Failed to process assoc req status %d", status);
|
||||||
|
return false;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
|
||||||
#endif /* CONFIG_OWE_SOFTAP */
|
#endif /* CONFIG_OWE_SOFTAP */
|
||||||
|
|
||||||
send_resp:
|
send_resp:
|
||||||
|
|||||||
@@ -312,4 +312,6 @@ void esp_wifi_set_sigma_internal(bool flag);
|
|||||||
void esp_wifi_ap_set_group_mgmt_cipher_internal(wifi_cipher_type_t cipher);
|
void esp_wifi_ap_set_group_mgmt_cipher_internal(wifi_cipher_type_t cipher);
|
||||||
uint8_t esp_wifi_op_class_supported_internal(uint8_t op_class, uint8_t min_chan, uint8_t max_chan, uint8_t inc, uint8_t bw, channel_bitmap_t *non_pref_channels);
|
uint8_t esp_wifi_op_class_supported_internal(uint8_t op_class, uint8_t min_chan, uint8_t max_chan, uint8_t inc, uint8_t bw, channel_bitmap_t *non_pref_channels);
|
||||||
bool esp_wifi_is_wpa3_compatible_mode_enabled(uint8_t if_index);
|
bool esp_wifi_is_wpa3_compatible_mode_enabled(uint8_t if_index);
|
||||||
|
uint8_t esp_wifi_ap_get_owe_config_internal();
|
||||||
|
|
||||||
#endif /* _ESP_WIFI_DRIVER_H_ */
|
#endif /* _ESP_WIFI_DRIVER_H_ */
|
||||||
|
|||||||
@@ -397,7 +397,8 @@ int hostapd_setup_wpa_psk(struct hostapd_bss_config *conf);
|
|||||||
struct sta_info;
|
struct sta_info;
|
||||||
bool hostap_new_assoc_sta(struct sta_info *sta, uint8_t *bssid, uint8_t *wpa_ie,
|
bool hostap_new_assoc_sta(struct sta_info *sta, uint8_t *bssid, uint8_t *wpa_ie,
|
||||||
u8 wpa_ie_len, u8 *rsnxe, uint16_t rsnxe_len,
|
u8 wpa_ie_len, u8 *rsnxe, uint16_t rsnxe_len,
|
||||||
bool *pmf_enable, int subtype, uint8_t *pairwise_cipher, uint8_t *reason, uint8_t *rsn_selection_ie, uint8_t *owe_dh, uint8_t owe_ie_len);
|
bool *pmf_enable, int subtype, uint8_t *pairwise_cipher,
|
||||||
|
uint8_t *reason, uint8_t *rsn_selection_ie, uint8_t *owe_dh, uint8_t owe_ie_len);
|
||||||
bool wpa_ap_remove(u8* bssid);
|
bool wpa_ap_remove(u8* bssid);
|
||||||
|
|
||||||
#endif /* HOSTAPD_CONFIG_H */
|
#endif /* HOSTAPD_CONFIG_H */
|
||||||
|
|||||||
@@ -775,96 +775,169 @@ u16 wpa_res_to_status_code(enum wpa_validate_result res)
|
|||||||
}
|
}
|
||||||
|
|
||||||
#ifdef CONFIG_OWE_SOFTAP
|
#ifdef CONFIG_OWE_SOFTAP
|
||||||
|
#include "ap/wpa_auth_i.h"
|
||||||
#include "crypto/crypto.h"
|
#include "crypto/crypto.h"
|
||||||
#define OWE_DH_GROUP 19
|
#define OWE_DH_GRP19 19
|
||||||
|
#define OWE_DHIE_LEN 37
|
||||||
uint16_t owe_process_assoc_req(struct sta_info *sta, const uint8_t *owe_dh,
|
uint16_t owe_process_assoc_req(struct sta_info *sta, const uint8_t *owe_dh,
|
||||||
uint8_t owe_dh_len)
|
uint8_t owe_dh_len)
|
||||||
{
|
{
|
||||||
struct wpabuf *secret, *pub, *hkey;
|
|
||||||
int res;
|
|
||||||
u8 prk[SHA256_MAC_LEN], pmkid[SHA256_MAC_LEN];
|
|
||||||
const char *info = "OWE Key Generation";
|
|
||||||
const u8 *addr[2];
|
|
||||||
size_t len[2];
|
|
||||||
|
|
||||||
if (WPA_GET_LE16(owe_dh + 3) != OWE_DH_GROUP)
|
const u8 *addr[2];
|
||||||
return WLAN_STATUS_FINITE_CYCLIC_GROUP_NOT_SUPPORTED;
|
size_t len[2];
|
||||||
|
struct wpabuf *hkey, *pub, *secret;
|
||||||
|
const char *info = "OWE Key Generation";
|
||||||
|
u8 prk[SHA256_MAC_LEN];
|
||||||
|
u8 pmkid[SHA256_MAC_LEN];
|
||||||
|
int res;
|
||||||
|
|
||||||
crypto_ecdh_deinit(sta->owe_ecdh);
|
if (!owe_dh) {
|
||||||
sta->owe_ecdh = crypto_ecdh_init(OWE_DH_GROUP);
|
wpa_printf(MSG_ERROR, "OWE: Invalid DH data received");
|
||||||
if (!sta->owe_ecdh)
|
return WLAN_STATUS_UNSPECIFIED_FAILURE;
|
||||||
return WLAN_STATUS_FINITE_CYCLIC_GROUP_NOT_SUPPORTED;
|
}
|
||||||
|
|
||||||
secret = crypto_ecdh_set_peerkey(sta->owe_ecdh, 0, owe_dh + 5,
|
// Set the group ID from DH param
|
||||||
owe_dh_len - 3);
|
sta->owe_group = WPA_GET_LE16(owe_dh + 3);
|
||||||
if (!secret) {
|
if (sta->owe_group != OWE_DH_GRP19)
|
||||||
wpa_printf(MSG_DEBUG, "OWE: Invalid peer DH public key");
|
return WLAN_STATUS_FINITE_CYCLIC_GROUP_NOT_SUPPORTED;
|
||||||
return WLAN_STATUS_UNSPECIFIED_FAILURE;
|
|
||||||
}
|
|
||||||
wpa_hexdump_buf_key(MSG_DEBUG, "OWE: DH shared secret", secret);
|
|
||||||
|
|
||||||
/* prk = HKDF-extract(C | A | group, z) */
|
crypto_ecdh_deinit(sta->owe_ecdh);
|
||||||
|
sta->owe_ecdh = crypto_ecdh_init(OWE_DH_GRP19);
|
||||||
|
if (!sta->owe_ecdh) {
|
||||||
|
wpa_printf(MSG_ERROR, "OWE: Error initializing ECDH for STA");
|
||||||
|
return WLAN_STATUS_UNSPECIFIED_FAILURE;
|
||||||
|
}
|
||||||
|
|
||||||
pub = crypto_ecdh_get_pubkey(sta->owe_ecdh, 0);
|
// Set up the DH shared secret
|
||||||
if (!pub) {
|
secret = crypto_ecdh_set_peerkey(sta->owe_ecdh, 0, owe_dh + 5, owe_dh_len - 3);
|
||||||
wpabuf_clear_free(secret);
|
// secret = wpabuf_zeropad(secret, OWE_PRIME_LEN);
|
||||||
return WLAN_STATUS_UNSPECIFIED_FAILURE;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* PMKID = Truncate-128(Hash(C | A)) */
|
if (!secret) {
|
||||||
addr[0] = owe_dh + 5;
|
wpa_printf(MSG_ERROR, "OWE: Invalid peer DH public key");
|
||||||
len[0] = owe_dh_len - 3;
|
return WLAN_STATUS_UNSPECIFIED_FAILURE;
|
||||||
addr[1] = wpabuf_head(pub);
|
}
|
||||||
len[1] = wpabuf_len(pub);
|
wpa_hexdump_buf_key(MSG_DEBUG, "OWE: DH shared secret", secret);
|
||||||
res = sha256_vector(2, addr, len, pmkid);
|
|
||||||
if (res < 0) {
|
|
||||||
wpabuf_free(pub);
|
|
||||||
wpabuf_clear_free(secret);
|
|
||||||
return WLAN_STATUS_UNSPECIFIED_FAILURE;
|
|
||||||
}
|
|
||||||
|
|
||||||
hkey = wpabuf_alloc(owe_dh_len - 3 + wpabuf_len(pub) + 2);
|
/* prk = HKDF-extract(C | A | group, z) */
|
||||||
if (!hkey) {
|
|
||||||
wpabuf_free(pub);
|
|
||||||
wpabuf_clear_free(secret);
|
|
||||||
return WLAN_STATUS_UNSPECIFIED_FAILURE;
|
|
||||||
}
|
|
||||||
|
|
||||||
wpabuf_put_data(hkey, owe_dh + 5, owe_dh_len - 3); /* C */
|
pub = crypto_ecdh_get_pubkey(sta->owe_ecdh, 0);
|
||||||
wpabuf_put_buf(hkey, pub); /* A */
|
pub = wpabuf_zeropad(pub, 32);
|
||||||
wpabuf_free(pub);
|
if (!pub) {
|
||||||
wpabuf_put_le16(hkey, OWE_DH_GROUP); /* group */
|
wpabuf_clear_free(secret);
|
||||||
res = hmac_sha256(wpabuf_head(hkey), wpabuf_len(hkey),
|
wpa_printf(MSG_ERROR, "OWE: Failed to retrieve public key");
|
||||||
wpabuf_head(secret), wpabuf_len(secret), prk);
|
return WLAN_STATUS_UNSPECIFIED_FAILURE;
|
||||||
wpabuf_clear_free(hkey);
|
}
|
||||||
wpabuf_clear_free(secret);
|
|
||||||
if (res < 0)
|
|
||||||
return WLAN_STATUS_UNSPECIFIED_FAILURE;
|
|
||||||
|
|
||||||
wpa_hexdump_key(MSG_DEBUG, "OWE: prk", prk, SHA256_MAC_LEN);
|
/* PMKID = Truncate-128(Hash(C | A)) */
|
||||||
|
addr[0] = owe_dh + 5;
|
||||||
|
addr[1] = wpabuf_head(pub);
|
||||||
|
len[0] = owe_dh_len - 3;
|
||||||
|
len[1] = wpabuf_len(pub);
|
||||||
|
|
||||||
/* PMK = HKDF-expand(prk, "OWE Key Generation", n) */
|
res = sha256_vector(2, addr, len, pmkid);
|
||||||
|
if (res < 0) {
|
||||||
|
wpabuf_free(pub);
|
||||||
|
wpabuf_clear_free(secret);
|
||||||
|
wpa_printf(MSG_ERROR, "OWE: PMKID calculation failed");
|
||||||
|
return WLAN_STATUS_UNSPECIFIED_FAILURE;
|
||||||
|
}
|
||||||
|
|
||||||
os_free(sta->owe_pmk);
|
hkey = wpabuf_alloc(owe_dh_len - 3 + wpabuf_len(pub) + 2);
|
||||||
sta->owe_pmk = os_malloc(PMK_LEN);
|
if (!hkey) {
|
||||||
if (!sta->owe_pmk) {
|
wpabuf_free(pub);
|
||||||
os_memset(prk, 0, SHA256_MAC_LEN);
|
wpabuf_clear_free(secret);
|
||||||
return WLAN_STATUS_UNSPECIFIED_FAILURE;
|
wpa_printf(MSG_ERROR, "OWE: Memory allocation failed for hkey buffer");
|
||||||
}
|
return WLAN_STATUS_UNSPECIFIED_FAILURE;
|
||||||
|
}
|
||||||
|
|
||||||
res = hmac_sha256_kdf(prk, SHA256_MAC_LEN, NULL, (const u8 *) info,
|
wpa_hexdump(MSG_DEBUG, "Peer public key", owe_dh+5, owe_dh_len-3);
|
||||||
os_strlen(info), sta->owe_pmk, PMK_LEN);
|
wpabuf_put_data(hkey, owe_dh + 5, owe_dh_len - 3); /* C */
|
||||||
os_memset(prk, 0, SHA256_MAC_LEN);
|
wpabuf_put_buf(hkey, pub); /* A */
|
||||||
if (res < 0) {
|
wpabuf_free(pub);
|
||||||
os_free(sta->owe_pmk);
|
wpabuf_put_le16(hkey, sta->owe_group); /* group */
|
||||||
sta->owe_pmk = NULL;
|
|
||||||
return WLAN_STATUS_UNSPECIFIED_FAILURE;
|
|
||||||
}
|
|
||||||
|
|
||||||
wpa_hexdump_key(MSG_DEBUG, "OWE: PMK", sta->owe_pmk, PMK_LEN);
|
res = hmac_sha256(wpabuf_head(hkey), wpabuf_len(hkey),
|
||||||
wpa_hexdump(MSG_DEBUG, "OWE: PMKID", pmkid, PMKID_LEN);
|
wpabuf_head(secret), wpabuf_len(secret), prk);
|
||||||
/* TODO: Add PMKSA cache entry */
|
wpabuf_clear_free(hkey);
|
||||||
|
wpabuf_clear_free(secret);
|
||||||
|
|
||||||
return WLAN_STATUS_SUCCESS;
|
if (res < 0) {
|
||||||
|
wpa_printf(MSG_ERROR, "OWE: HMAC-SHA256 failed");
|
||||||
|
return WLAN_STATUS_UNSPECIFIED_FAILURE;
|
||||||
|
}
|
||||||
|
wpa_hexdump_key(MSG_DEBUG, "OWE: prk", prk, SHA256_MAC_LEN);
|
||||||
|
|
||||||
|
/* PMK = HKDF-expand(prk, "OWE Key Generation", n) */
|
||||||
|
os_free(sta->owe_pmk);
|
||||||
|
sta->owe_pmk = os_malloc(SHA256_MAC_LEN);
|
||||||
|
if (!sta->owe_pmk) {
|
||||||
|
os_memset(prk, 0, SHA256_MAC_LEN);
|
||||||
|
return WLAN_STATUS_UNSPECIFIED_FAILURE;
|
||||||
|
}
|
||||||
|
|
||||||
|
res = hmac_sha256_kdf(prk, SHA256_MAC_LEN, NULL, (const u8 *)info,
|
||||||
|
os_strlen(info), sta->owe_pmk, SHA256_MAC_LEN);
|
||||||
|
os_memset(prk, 0, SHA256_MAC_LEN);
|
||||||
|
if (res < 0) {
|
||||||
|
os_free(sta->owe_pmk);
|
||||||
|
sta->owe_pmk = NULL;
|
||||||
|
wpa_printf(MSG_ERROR, "OWE: HMAC-SHA256 KDF failed");
|
||||||
|
return WLAN_STATUS_UNSPECIFIED_FAILURE;
|
||||||
|
}
|
||||||
|
|
||||||
|
wpa_hexdump_key(MSG_DEBUG, "OWE: PMK", sta->owe_pmk, PMK_LEN);
|
||||||
|
wpa_hexdump(MSG_DEBUG, "OWE: PMKID", pmkid, PMKID_LEN);
|
||||||
|
|
||||||
|
return WLAN_STATUS_SUCCESS;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
|
uint8_t *owe_build_assoc_resp_dhie(struct hostapd_data *hapd, const u8 *bssid, int *owe_ie_len)
|
||||||
|
{
|
||||||
|
|
||||||
|
struct wpabuf *pub;
|
||||||
|
struct sta_info *sta = ap_get_sta(hapd, bssid);
|
||||||
|
if (!sta) {
|
||||||
|
return NULL;
|
||||||
|
}
|
||||||
|
|
||||||
|
struct wpabuf *owe_buf = wpabuf_alloc(hapd->wpa_auth->wpa_ie_len);
|
||||||
|
if (!owe_buf) {
|
||||||
|
wpa_printf(MSG_ERROR, "Memory allocation failed for OWE IE");
|
||||||
|
return NULL;
|
||||||
|
}
|
||||||
|
|
||||||
|
u8 *pos, buf[128];
|
||||||
|
|
||||||
|
pos = buf;
|
||||||
|
|
||||||
|
pos = wpa_auth_write_assoc_resp_owe(hapd, sta->wpa_sm, pos,
|
||||||
|
buf + sizeof(buf) - pos);
|
||||||
|
|
||||||
|
wpabuf_resize(&owe_buf, pos - buf);
|
||||||
|
wpabuf_put_data(owe_buf, buf, pos - buf);
|
||||||
|
*owe_ie_len = pos - buf;
|
||||||
|
|
||||||
|
pub = crypto_ecdh_get_pubkey(sta->owe_ecdh, 0);
|
||||||
|
if (!pub) {
|
||||||
|
return NULL;
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
wpa_hexdump_buf(MSG_DEBUG, "Own public key", pub);
|
||||||
|
|
||||||
|
wpabuf_resize(&owe_buf, OWE_DHIE_LEN);
|
||||||
|
wpabuf_put_u8(owe_buf, WLAN_EID_EXTENSION);
|
||||||
|
wpabuf_put_u8(owe_buf, 1 + 2 + wpabuf_len(pub));
|
||||||
|
wpabuf_put_u8(owe_buf, WLAN_EID_EXT_OWE_DH_PARAM);
|
||||||
|
wpabuf_put_le16(owe_buf, IANA_SECP256R1);
|
||||||
|
wpabuf_put_buf(owe_buf, pub);
|
||||||
|
wpabuf_free(pub);
|
||||||
|
|
||||||
|
wpa_hexdump_buf(MSG_DEBUG, "OWE: Buffer", owe_buf);
|
||||||
|
*owe_ie_len = wpabuf_len(owe_buf);
|
||||||
|
|
||||||
|
return (uint8_t *)wpabuf_head(owe_buf);
|
||||||
|
}
|
||||||
|
|
||||||
#endif /* CONFIG_OWE_SOFTAP */
|
#endif /* CONFIG_OWE_SOFTAP */
|
||||||
|
|||||||
@@ -17,7 +17,9 @@ int handle_auth_sae(struct hostapd_data *hapd, struct sta_info *sta,
|
|||||||
u16 auth_transaction, u16 status);
|
u16 auth_transaction, u16 status);
|
||||||
u16 wpa_res_to_status_code(enum wpa_validate_result res);
|
u16 wpa_res_to_status_code(enum wpa_validate_result res);
|
||||||
#ifdef CONFIG_OWE_SOFTAP
|
#ifdef CONFIG_OWE_SOFTAP
|
||||||
uint16_t owe_process_assoc_req(struct sta_info *sta, const uint8_t *owe_dh,
|
uint16_t owe_process_assoc_req(struct sta_info *sta, const u8 *owe_dh,
|
||||||
uint8_t owe_dh_len);
|
u8 owe_dh_len);
|
||||||
#endif
|
uint8_t *owe_build_assoc_resp_dhie(struct hostapd_data *hapd, const u8 *bssid, int *owe_ie_len);
|
||||||
|
#endif /* CONFIG_OWE_SOFTAP */
|
||||||
|
|
||||||
#endif /* IEEE802_11_H */
|
#endif /* IEEE802_11_H */
|
||||||
|
|||||||
@@ -70,8 +70,9 @@ struct sta_info {
|
|||||||
#endif /* CONFIG_SAE */
|
#endif /* CONFIG_SAE */
|
||||||
#endif /* ESP_SUPPLICANT */
|
#endif /* ESP_SUPPLICANT */
|
||||||
#ifdef CONFIG_OWE_SOFTAP
|
#ifdef CONFIG_OWE_SOFTAP
|
||||||
u8 *owe_pmk;
|
u16 owe_group;
|
||||||
struct crypto_ecdh *owe_ecdh;
|
u8 *owe_pmk;
|
||||||
|
struct crypto_ecdh *owe_ecdh;
|
||||||
#endif /* CONFIG_OWE_SOFTAP */
|
#endif /* CONFIG_OWE_SOFTAP */
|
||||||
|
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -136,8 +136,9 @@ static inline const u8 * wpa_auth_get_psk(struct wpa_authenticator *wpa_auth,
|
|||||||
return NULL;
|
return NULL;
|
||||||
}
|
}
|
||||||
|
|
||||||
#ifdef CONFIG_SAE
|
#if defined(CONFIG_SAE) || defined(CONFIG_OWE_SOFTAP)
|
||||||
struct sta_info *sta = ap_get_sta(hapd, addr);
|
struct sta_info *sta = ap_get_sta(hapd, addr);
|
||||||
|
#ifdef CONFIG_SAE
|
||||||
if (sta && sta->auth_alg == WLAN_AUTH_SAE) {
|
if (sta && sta->auth_alg == WLAN_AUTH_SAE) {
|
||||||
if (!sta->sae || prev_psk)
|
if (!sta->sae || prev_psk)
|
||||||
return NULL;
|
return NULL;
|
||||||
@@ -155,7 +156,7 @@ static inline const u8 * wpa_auth_get_psk(struct wpa_authenticator *wpa_auth,
|
|||||||
return sta->owe_pmk;
|
return sta->owe_pmk;
|
||||||
}
|
}
|
||||||
#endif /* CONFIG_OWE_SOFTAP */
|
#endif /* CONFIG_OWE_SOFTAP */
|
||||||
|
#endif /* defined(CONFIG_SAE) || defined(CONFIG_OWE_SOFTAP) */
|
||||||
|
|
||||||
return (u8*)hostapd_get_psk(hapd->conf, addr, prev_psk);
|
return (u8*)hostapd_get_psk(hapd->conf, addr, prev_psk);
|
||||||
}
|
}
|
||||||
@@ -1472,7 +1473,8 @@ SM_STATE(WPA_PTK, INITIALIZE)
|
|||||||
wpa_remove_ptk(sm);
|
wpa_remove_ptk(sm);
|
||||||
wpa_auth_set_eapol(sm->wpa_auth, sm->addr, WPA_EAPOL_portValid, 0);
|
wpa_auth_set_eapol(sm->wpa_auth, sm->addr, WPA_EAPOL_portValid, 0);
|
||||||
sm->TimeoutCtr = 0;
|
sm->TimeoutCtr = 0;
|
||||||
if (wpa_key_mgmt_wpa_psk(sm->wpa_key_mgmt)) {
|
if (wpa_key_mgmt_wpa_psk(sm->wpa_key_mgmt) ||
|
||||||
|
sm->wpa_key_mgmt == WPA_KEY_MGMT_OWE) {
|
||||||
wpa_auth_set_eapol(sm->wpa_auth, sm->addr,
|
wpa_auth_set_eapol(sm->wpa_auth, sm->addr,
|
||||||
WPA_EAPOL_authorized, 0);
|
WPA_EAPOL_authorized, 0);
|
||||||
}
|
}
|
||||||
@@ -1782,7 +1784,8 @@ SM_STATE(WPA_PTK, PTKCALCNEGOTIATING)
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (!wpa_key_mgmt_wpa_psk(sm->wpa_key_mgmt) ||
|
if (!wpa_key_mgmt_wpa_psk(sm->wpa_key_mgmt) ||
|
||||||
wpa_key_mgmt_sae(sm->wpa_key_mgmt)) {
|
wpa_key_mgmt_sae(sm->wpa_key_mgmt) ||
|
||||||
|
sm->wpa_key_mgmt != WPA_KEY_MGMT_OWE) {
|
||||||
wpa_printf( MSG_DEBUG, "wpa_key_mgmt=%x", sm->wpa_key_mgmt);
|
wpa_printf( MSG_DEBUG, "wpa_key_mgmt=%x", sm->wpa_key_mgmt);
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
@@ -2253,7 +2256,8 @@ SM_STEP(WPA_PTK)
|
|||||||
wpa_auth_get_eapol(sm->wpa_auth, sm->addr,
|
wpa_auth_get_eapol(sm->wpa_auth, sm->addr,
|
||||||
WPA_EAPOL_keyRun) > 0)
|
WPA_EAPOL_keyRun) > 0)
|
||||||
SM_ENTER(WPA_PTK, INITPMK);
|
SM_ENTER(WPA_PTK, INITPMK);
|
||||||
else if (wpa_key_mgmt_wpa_psk(sm->wpa_key_mgmt)
|
else if (wpa_key_mgmt_wpa_psk(sm->wpa_key_mgmt) ||
|
||||||
|
(sm->wpa_key_mgmt == WPA_KEY_MGMT_OWE)
|
||||||
/* FIX: && 802.1X::keyRun */)
|
/* FIX: && 802.1X::keyRun */)
|
||||||
SM_ENTER(WPA_PTK, INITPSK);
|
SM_ENTER(WPA_PTK, INITPSK);
|
||||||
break;
|
break;
|
||||||
|
|||||||
@@ -12,6 +12,7 @@
|
|||||||
#include "common/defs.h"
|
#include "common/defs.h"
|
||||||
#include "common/eapol_common.h"
|
#include "common/eapol_common.h"
|
||||||
#include "common/wpa_common.h"
|
#include "common/wpa_common.h"
|
||||||
|
#include "ap/hostapd.h"
|
||||||
|
|
||||||
#ifdef _MSC_VER
|
#ifdef _MSC_VER
|
||||||
#pragma pack(push, 1)
|
#pragma pack(push, 1)
|
||||||
@@ -329,5 +330,7 @@ static inline bool wpa_auth_pmf_enabled(struct wpa_auth_config *conf)
|
|||||||
}
|
}
|
||||||
u8 * wpa_auth_write_assoc_resp_owe(struct wpa_state_machine *sm,
|
u8 * wpa_auth_write_assoc_resp_owe(struct wpa_state_machine *sm,
|
||||||
u8 *pos, size_t max_len);
|
u8 *pos, size_t max_len);
|
||||||
|
uint8_t *wpa_auth_write_assoc_resp_owe(struct hostapd_data *hapd, struct wpa_state_machine *sm,
|
||||||
|
u8 *pos, size_t max_len);
|
||||||
|
|
||||||
#endif /* WPA_AUTH_H */
|
#endif /* WPA_AUTH_H */
|
||||||
|
|||||||
@@ -870,15 +870,14 @@ int wpa_auth_uses_mfp(struct wpa_state_machine *sm)
|
|||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
#ifdef CONFIG_OWE_SOFTAP
|
uint8_t *wpa_auth_write_assoc_resp_owe(struct hostapd_data *hapd, struct wpa_state_machine *sm,
|
||||||
u8 * wpa_auth_write_assoc_resp_owe(struct wpa_state_machine *sm,
|
|
||||||
u8 *pos, size_t max_len)
|
u8 *pos, size_t max_len)
|
||||||
|
|
||||||
{
|
{
|
||||||
int res;
|
int res;
|
||||||
|
|
||||||
res = wpa_write_rsn_ie(&sm->wpa_auth->conf, pos, max_len, NULL);
|
res = wpa_write_rsn_ie(&hapd->wpa_auth->conf, pos, max_len, NULL);
|
||||||
if (res < 0)
|
if (res < 0)
|
||||||
return pos;
|
return pos;
|
||||||
return pos + res;
|
return pos + res;
|
||||||
}
|
}
|
||||||
#endif /* CONFIG_OWE_SOFTAP */
|
|
||||||
|
|||||||
@@ -987,7 +987,7 @@ int wpa_eapol_key_mic(const u8 *key, size_t key_len, int akmp, int ver,
|
|||||||
os_memcpy(mic, hash, 24);
|
os_memcpy(mic, hash, 24);
|
||||||
break;
|
break;
|
||||||
#endif /* CONFIG_SUITEB192 */
|
#endif /* CONFIG_SUITEB192 */
|
||||||
#ifdef CONFIG_OWE_STA
|
#if defined(CONFIG_OWE_STA) || defined(CONFIG_OWE_SOFTAP)
|
||||||
case WPA_KEY_MGMT_OWE:
|
case WPA_KEY_MGMT_OWE:
|
||||||
wpa_printf(MSG_DEBUG,
|
wpa_printf(MSG_DEBUG,
|
||||||
"WPA: EAPOL-Key MIC using HMAC-SHA%u (AKM-defined - OWE)",
|
"WPA: EAPOL-Key MIC using HMAC-SHA%u (AKM-defined - OWE)",
|
||||||
@@ -1003,7 +1003,7 @@ int wpa_eapol_key_mic(const u8 *key, size_t key_len, int akmp, int ver,
|
|||||||
os_memcpy(mic, hash, key_len);
|
os_memcpy(mic, hash, key_len);
|
||||||
break;
|
break;
|
||||||
|
|
||||||
#endif /* CONFIG_OWE_STA */
|
#endif /* CONFIG_OWE_STA || CONFIG_OWE_SOFTAP */
|
||||||
#ifdef CONFIG_DPP
|
#ifdef CONFIG_DPP
|
||||||
case WPA_KEY_MGMT_DPP:
|
case WPA_KEY_MGMT_DPP:
|
||||||
wpa_printf(MSG_DEBUG,
|
wpa_printf(MSG_DEBUG,
|
||||||
|
|||||||
Reference in New Issue
Block a user