mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 03:00:34 +03:00
feat(wifi): add NAN group data and management frame protection
Add Wi-Fi Aware group-key support to secured NDPs so group-addressed traffic can be protected, for interop with iOS/macOS peers: - GTK (NCS-GTK-CCM-128) protects group-addressed data. - IGTK/BIGTK (BIP) protect group management traffic - multicast SDFs, Beacons. Capabilities are advertised in the CSIA IE: group_data_prot maps to GTKSA, group_mgmt_prot to IGTKSA/BIGTKSA. The CSIA cannot encode IGTK/BIGTK without GTK (WiFi Aware spec 9.5.21.2, Table 122), so enabling group_mgmt_prot forces group_data_prot on for every secured service. Expose per-service group_data_prot and device-global group_mgmt_prot.
This commit is contained in:
@@ -35,6 +35,16 @@ menu "Example Configuration"
|
||||
the same credential (passphrase or PMK).
|
||||
Disable to advertise an open (unencrypted) service.
|
||||
|
||||
config EXAMPLE_NAN_GROUP_DATA_PROT
|
||||
bool "Protect group-addressed datapath traffic (ND-GTK)"
|
||||
depends on EXAMPLE_NAN_SECURITY_ENABLED
|
||||
default y
|
||||
help
|
||||
Negotiate and install an ND-GTK so group-addressed (multicast/
|
||||
broadcast) frames on the NAN datapath are encrypted. This is
|
||||
required for IPv6 over the secured datapath (Neighbor Discovery,
|
||||
MLD). Both peers must enable this for group keys to be exchanged.
|
||||
|
||||
choice EXAMPLE_NAN_SECURITY_METHOD
|
||||
prompt "Security Method"
|
||||
depends on EXAMPLE_NAN_SECURITY_ENABLED
|
||||
|
||||
@@ -133,6 +133,9 @@ void wifi_nan_publish(void)
|
||||
};
|
||||
#ifdef CONFIG_EXAMPLE_NAN_SECURITY_ENABLED
|
||||
wifi_nan_discovery_security_params_t security_cfg = {
|
||||
#ifdef CONFIG_EXAMPLE_NAN_GROUP_DATA_PROT
|
||||
.group_data_prot = 1, /* distribute/accept ND-GTK for group-addressed data */
|
||||
#endif
|
||||
.num_credentials = 1,
|
||||
.creds = {
|
||||
{
|
||||
|
||||
@@ -45,6 +45,16 @@ menu "Example Configuration"
|
||||
(passphrase or PMK) and sets up an encrypted NDP.
|
||||
Disable to discover open (unencrypted) services.
|
||||
|
||||
config EXAMPLE_NAN_GROUP_DATA_PROT
|
||||
bool "Protect group-addressed datapath traffic (ND-GTK)"
|
||||
depends on EXAMPLE_NAN_SECURITY_ENABLED
|
||||
default y
|
||||
help
|
||||
Negotiate and install an ND-GTK so group-addressed (multicast/
|
||||
broadcast) frames on the NAN datapath are encrypted. This is
|
||||
required for IPv6 over the secured datapath (Neighbor Discovery,
|
||||
MLD). Both peers must enable this for group keys to be exchanged.
|
||||
|
||||
choice EXAMPLE_NAN_SECURITY_METHOD
|
||||
prompt "Security Method"
|
||||
depends on EXAMPLE_NAN_SECURITY_ENABLED
|
||||
|
||||
@@ -227,6 +227,9 @@ void wifi_nan_subscribe(void)
|
||||
};
|
||||
#ifdef CONFIG_EXAMPLE_NAN_SECURITY_ENABLED
|
||||
wifi_nan_discovery_security_params_t security_cfg = {
|
||||
#ifdef CONFIG_EXAMPLE_NAN_GROUP_DATA_PROT
|
||||
.group_data_prot = 1, /* distribute/accept ND-GTK for group-addressed data */
|
||||
#endif
|
||||
.num_credentials = 1,
|
||||
.creds = {
|
||||
{
|
||||
|
||||
Reference in New Issue
Block a user