mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 11:10:54 +03:00
feat(wifi): NAN encrypted datapath (Wi-Fi Aware M1-M4 handshake)
Implement the NAN Data Path encrypted datapath per Wi-Fi Aware v4.0 (§7.1.3.5, §9.5.16): - Responder + initiator sides of the M1-M4 Shared-Key Descriptor exchange, with MIC compute/verify, PTK derivation, and PMK/PMKID derivation via PBKDF2-SHA256 over passphrase or pre-shared PMK. - CSIA / SCIA attribute build + parse, NCS-SK-128 cipher suite. - Per-NDL security context on ndl_info::security_ctx; per-svc PMK cache. - ndp_response_indication callback for initiator peer-NDI binding. - host<->blob ABI migrated from 27 direct esp_nan_* externs to a single nan_secure_dp_funcs callback struct in esp_private/wifi.h. - nan_security.c split out of nan_app.c (~340 lines de-duplicated into shared M1-M4 helpers). - CONFIG_ESP_WIFI_NAN_ENCRYPTED_DATAPATH gates the secure path so non- security builds compile out the crypto/handshake code. - ROM patch (esp32s31): mask ieee80211_encap_esfbuf to match the c5/c6/c61 pattern for NAN-capable chips. Hardening: PMK stack copies zeroized on every return, NDP attribute parsers bounds-checked, CSID range-checked before shifting, NDL slot reuse only when handshake state is IDLE, get_csia/scia_len aligned with their builders on empty input. API surface: NDP security types moved out of esp_wifi_types_generic.h into esp_private/wifi.h (internal-only). security pointer dropped from struct ndp_cb_peer_info. Discovery-side wifi_nan_security_type_t and the NDP Info callbacks removed (subsumed by csid_bitmap and SSI respectively).
This commit is contained in:
@@ -593,6 +593,23 @@ menu "Wi-Fi"
|
||||
help
|
||||
Enable Wi-Fi Aware: Synchronization feature (NAN-Sync).
|
||||
|
||||
config ESP_WIFI_NAN_SECURITY
|
||||
bool "Enable Wi-Fi Aware: Encrypted Pairwise Datapath (NDP Security)"
|
||||
depends on ESP_WIFI_NAN_SYNC_ENABLE && IDF_EXPERIMENTAL_FEATURES && ESP_WIFI_MBEDTLS_CRYPTO
|
||||
select MBEDTLS_PKCS5_C
|
||||
select MBEDTLS_SHA256_C
|
||||
default n
|
||||
help
|
||||
Enable encrypted pairwise datapath for Wi-Fi Aware (NAN).
|
||||
Adds PBKDF2 key derivation (mbedTLS PKCS#5), 4-way handshake (M1-M4),
|
||||
PTK derivation, and CCMP key installation for secured NAN
|
||||
data links. Disable to save code size when only open
|
||||
datapaths are needed.
|
||||
|
||||
Requires ESP_WIFI_MBEDTLS_CRYPTO + MBEDTLS_PKCS5_C + MBEDTLS_SHA256_C
|
||||
for ND-PMK derivation via pbkdf2_sha256() (MBEDTLS_MD_C is pulled in
|
||||
transitively by MBEDTLS_PKCS5_C).
|
||||
|
||||
config ESP_WIFI_NAN_USD_ENABLE
|
||||
bool "Enable Wi-Fi Aware: Unsynchronized service discovery (NAN-USD)"
|
||||
depends on IDF_EXPERIMENTAL_FEATURES
|
||||
|
||||
Reference in New Issue
Block a user