feat(esp_wifi): NAN Pairing Improvements and bugfixes

- Route NAN pairing bootstrap via NPBA receive path
- extend datapath_req wait time to fit secured M1-M4 handshake
- Plug ND-PMK derived from KDK into NDP
- prefers paired-peer cached ND-PMK (from PASN pairing complete), when available
- carry ND-PMK metadata in pairing install callback
- Extend PASN key-installed callback payload to include role, mapped NDP CSID
  and derived ND-PMK so the NAN layer can populate paired-peer security cache.

Co-authored-by: Akshat Agrawal <akshat.agrawal@espressif.com>
Co-authored-by: Sarvesh Bodakhe <sarvesh.bodakhe@espressif.com>
This commit is contained in:
Nachiket Kukade
2026-05-22 11:30:00 +05:30
committed by Sarvesh Bodakhe
co-authored by Akshat Agrawal Sarvesh Bodakhe
parent 9f361f478d
commit 0f8d4b74a0
18 changed files with 659 additions and 403 deletions
+7 -8
View File
@@ -356,12 +356,10 @@ menu "Wi-Fi"
config ESP_WIFI_PASN_SUPPORT
bool "Enable PASN support"
depends on ESP_WIFI_NAN_PAIRING
default y if ESP_WIFI_NAN_PAIRING
default n
help
Enable PASN for Wi-Fi NAN; the supplicant exposes CONFIG_PASN when this is on.
This option is only available when "NAN-Sync pairing bootstrapping"
(ESP_WIFI_NAN_PAIRING) is enabled, because NAN PASN builds on that path.
Pre-Association Security Negotiation (PASN) for Wi-Fi NAN.
The wpa_supplicant exposes CONFIG_PASN when this is on.
config ESP_WIFI_SLP_IRAM_OPT
bool "WiFi SLP IRAM speed optimization"
@@ -628,12 +626,13 @@ menu "Wi-Fi"
config ESP_WIFI_NAN_PAIRING
bool "Enable NAN Pairing"
depends on ESP_WIFI_NAN_SYNC_ENABLE
depends on ESP_WIFI_NAN_SECURITY && IDF_EXPERIMENTAL_FEATURES && ESP_WIFI_MBEDTLS_CRYPTO
select ESP_WIFI_PASN_SUPPORT
default n
help
Enable NAN Pairing support. This allows devices to establish
secure pairing using bootstrapping methods like PIN code or
opportunistic pairing as defined in Wi-Fi Aware specification.
secure pairing using bootstrapping methods like PIN code.
Requires PASN in wpa_supplicant (ESP_WIFI_PASN_SUPPORT)
config ESP_WIFI_MBEDTLS_CRYPTO
bool "Use MbedTLS crypto APIs"