feat(wifi): add NAN group data and management frame protection

Add Wi-Fi Aware group-key support to secured NDPs so group-addressed
traffic can be protected, for interop with iOS/macOS peers:

- GTK (NCS-GTK-CCM-128) protects group-addressed data.
- IGTK/BIGTK (BIP) protect group management traffic - multicast SDFs,
  Beacons.

Capabilities are advertised in the CSIA IE: group_data_prot maps to GTKSA,
group_mgmt_prot to IGTKSA/BIGTKSA. The CSIA cannot encode IGTK/BIGTK
without GTK (WiFi Aware spec 9.5.21.2, Table 122), so enabling group_mgmt_prot
forces group_data_prot on for every secured service.

Expose per-service group_data_prot and device-global group_mgmt_prot.
This commit is contained in:
Sarvesh Bodakhe
2026-07-04 00:05:20 +08:00
committed by BOT
parent cd16349be9
commit 310b3d6571
11 changed files with 1052 additions and 89 deletions
@@ -35,6 +35,16 @@ menu "Example Configuration"
the same credential (passphrase or PMK).
Disable to advertise an open (unencrypted) service.
config EXAMPLE_NAN_GROUP_DATA_PROT
bool "Protect group-addressed datapath traffic (ND-GTK)"
depends on EXAMPLE_NAN_SECURITY_ENABLED
default y
help
Negotiate and install an ND-GTK so group-addressed (multicast/
broadcast) frames on the NAN datapath are encrypted. This is
required for IPv6 over the secured datapath (Neighbor Discovery,
MLD). Both peers must enable this for group keys to be exchanged.
choice EXAMPLE_NAN_SECURITY_METHOD
prompt "Security Method"
depends on EXAMPLE_NAN_SECURITY_ENABLED
@@ -133,6 +133,9 @@ void wifi_nan_publish(void)
};
#ifdef CONFIG_EXAMPLE_NAN_SECURITY_ENABLED
wifi_nan_discovery_security_params_t security_cfg = {
#ifdef CONFIG_EXAMPLE_NAN_GROUP_DATA_PROT
.group_data_prot = 1, /* distribute/accept ND-GTK for group-addressed data */
#endif
.num_credentials = 1,
.creds = {
{
@@ -45,6 +45,16 @@ menu "Example Configuration"
(passphrase or PMK) and sets up an encrypted NDP.
Disable to discover open (unencrypted) services.
config EXAMPLE_NAN_GROUP_DATA_PROT
bool "Protect group-addressed datapath traffic (ND-GTK)"
depends on EXAMPLE_NAN_SECURITY_ENABLED
default y
help
Negotiate and install an ND-GTK so group-addressed (multicast/
broadcast) frames on the NAN datapath are encrypted. This is
required for IPv6 over the secured datapath (Neighbor Discovery,
MLD). Both peers must enable this for group keys to be exchanged.
choice EXAMPLE_NAN_SECURITY_METHOD
prompt "Security Method"
depends on EXAMPLE_NAN_SECURITY_ENABLED
@@ -227,6 +227,9 @@ void wifi_nan_subscribe(void)
};
#ifdef CONFIG_EXAMPLE_NAN_SECURITY_ENABLED
wifi_nan_discovery_security_params_t security_cfg = {
#ifdef CONFIG_EXAMPLE_NAN_GROUP_DATA_PROT
.group_data_prot = 1, /* distribute/accept ND-GTK for group-addressed data */
#endif
.num_credentials = 1,
.creds = {
{