feat(nan): Add support for NAN Pairing Verification

- Add nira attr and verification for pasn auth frames
- Refine key clearing and pairing complete logic for pasn verify
- Add NIRA own-service resolution, cached NIK checks, and dynamic
  pairing IE construction for bootstrap vs verify paths.
- Replace NAN bootstrap events by private callbacks
This commit is contained in:
Sajia
2026-07-04 00:05:20 +08:00
committed by BOT
parent 0d8cb4445d
commit bf5907d066
18 changed files with 1641 additions and 533 deletions
@@ -106,6 +106,7 @@ struct nan_cb_peer_info {
uint16_t ssi_len; /**< SSI length in bytes */
wifi_nan_peer_sdf_security_t *peer_security_params; /**< Peer's discovery security params parsed from SDF */
nan_vendor_ie_t *vendor_ie; /**< Vendor-specific IE, if any */
bool nira_verified; /**< true when received NIRA tag verified against cached NIK */
};
/* NDP Peer info parsed from NAF. */
@@ -196,6 +197,7 @@ struct nan_sync_callbacks {
uint32_t (* get_nira_len)(void);
int (* construct_nira)(uint8_t *frm);
bool (*verify_nira)(uint8_t *peer_mac, uint8_t *nira_attr, uint16_t nira_attr_len);
bool (*peer_nik_cached)(uint8_t *peer_mac);
};
/* Host helpers for NAN encrypted-datapath, registered via
@@ -1201,6 +1203,19 @@ uint32_t esp_nan_get_nira_len(void);
*/
int esp_nan_construct_nira(uint8_t *frm);
/**
* @brief Construct a NAN Cipher Suite Info Attribute (CSIA)
*
* @param[out] frm Buffer to write the attribute to
* @param[in] pub_id Publish service instance id
* @param[in] own_csid_bitmap Locally supported cipher suite bitmap
* @param[in] peer_csid_bitmap Peer cipher suite bitmap, or 0 to use own bitmap
*
* @return Number of bytes written, or 0 on failure/no cipher suite
*/
int esp_nan_construct_csia(uint8_t *frm, uint8_t pub_id,
uint16_t own_csid_bitmap, uint16_t peer_csid_bitmap);
/**
* @brief Verify a received NAN Identity Resolution Attribute (NIRA)
*
@@ -1212,6 +1227,24 @@ int esp_nan_construct_nira(uint8_t *frm);
*/
bool esp_nan_verify_nira(uint8_t *peer_mac, uint8_t *nira_attr, uint16_t nira_attr_len);
/**
* @brief Verify a received NIRA and resolve the matched own service id
*
* Behaves like @ref esp_nan_verify_nira but additionally outputs the local
* service instance id the verifying NIK maps to, used to anchor a pairing
* verify-session flag. @p own_inst_id is set to 0 when the identity does not
* resolve to an active local service.
*
* @param[in] peer_mac NMI of the sender
* @param[in] nira_attr NIRA attribute buffer
* @param[in] nira_attr_len Attribute length in bytes
* @param[out] own_inst_id Resolved own service instance id (0 if none)
*
* @return true if the tag matches, false otherwise
*/
bool esp_nan_verify_nira_get_own_svc(uint8_t *peer_mac, uint8_t *nira_attr,
uint16_t nira_attr_len, uint8_t *own_inst_id);
/**
* @brief Get the time information from the MAC clock. The time is precise only if modem sleep or light sleep is not enabled.
*
@@ -1305,8 +1305,6 @@ typedef enum {
WIFI_EVENT_DPP_URI_READY, /**< DPP URI is ready through Bootstrapping */
WIFI_EVENT_DPP_CFG_RECVD, /**< DPP Configuration Response; payload is wifi_event_dpp_config_received_t */
WIFI_EVENT_DPP_FAILED, /**< DPP failed */
WIFI_EVENT_NAN_BOOTSTRAP_INDICATION, /**< Received NAN Pairing Bootstrapping Request from a Peer */
WIFI_EVENT_NAN_BOOTSTRAP_COMPLETED, /**< NAN Pairing Bootstrapping completed (success/failure) */
WIFI_EVENT_NAN_PAIRING_INDICATION, /**< Received NAN Pairing indication (reserved) */
WIFI_EVENT_NAN_PAIRING_CONFIRM, /**< NAN pairing completed after NIK follow-up exchange */
WIFI_EVENT_NAN_CLUSTER_JOIN, /**< Posted when the device joins, starts, or merges into a NAN cluster */
@@ -1637,38 +1635,6 @@ typedef struct {
uint8_t init_ndi[6]; /**< Initiator's NAN Data Interface MAC */
} wifi_event_ndp_terminated_t;
/**
* @brief Argument structure for WIFI_EVENT_NAN_BOOTSTRAP_INDICATION event
*
* Posted when a NAN Pairing Bootstrapping Request is received from a peer.
* The application should respond using esp_wifi_nan_bootstrap_response().
*/
typedef struct {
uint8_t peer_svc_id; /**< Peer's service instance id */
uint8_t own_svc_id; /**< Own service instance id */
uint8_t peer_nmi[6]; /**< Peer's NAN Management Interface MAC */
uint16_t selected_method; /**< Bootstrapping method selected by initiator (one WIFI_NAN_BOOTSTRAP_* bit) */
uint8_t is_comeback; /**< 1 if this is a comeback retry with cookie */
uint32_t cookie; /**< Comeback cookie from initiator (0 if none) */
} wifi_event_nan_bootstrap_indication_t;
/**
* @brief Argument structure for WIFI_EVENT_NAN_BOOTSTRAP_COMPLETED event
*
* Posted when a NAN Pairing Bootstrapping Response is received,
* or when the bootstrapping handshake completes/fails.
*/
typedef struct {
uint8_t status; /**< 0=Accepted, 1=Rejected, 2=Comeback (wifi_nan_pairing_status_t) */
uint8_t peer_svc_id; /**< Peer's service instance id */
uint8_t own_svc_id; /**< Own service instance id */
uint8_t peer_nmi[6]; /**< Peer's NAN Management Interface MAC */
uint16_t matched_method; /**< Matched bootstrapping method, one WIFI_NAN_BOOTSTRAP_* bit (valid if accepted) */
uint8_t reason_code; /**< Rejection reason (valid if rejected) */
uint16_t comeback_after; /**< Comeback deferral time in TUs (valid if comeback) */
uint32_t cookie; /**< Comeback cookie from responder (0 if none) */
} wifi_event_nan_bootstrap_complete_t;
/**
* @brief Argument structure for WIFI_EVENT_NAN_PAIRING_CONFIRM event
*/