feat(ble/bluedroid): move Encrypted Advertising Data APIs into the host

Provide esp_ble_ead_encrypt/decrypt in Bluedroid and group the GAP Key
Material characteristic under the same EAD Kconfig menu.
This commit is contained in:
zhiweijian
2026-09-08 16:07:44 +08:00
parent b10ae7f167
commit f5e9e2496a
29 changed files with 423 additions and 841 deletions
@@ -25,6 +25,10 @@ The Bluetooth LE API in ESP-IDF is organized into the following parts:
Discovers and accesses services on remote servers (central role)
- :doc:`Bluetooth Low Energy Encrypted Advertising Data <esp_ble_ead>`
Encrypts and decrypts advertising payloads with AES-CCM (Bluetooth Core Specification 5.4)
.. only:: SOC_BLUFI_SUPPORTED
- :doc:`Bluetooth Low Energy BluFi <esp_blufi>`
@@ -41,4 +45,5 @@ Each part typically includes an **Overview**, **Application Examples**, and **AP
Bluetooth Low Energy GATT Define <esp_gatt_defs>
Bluetooth Low Energy GATT Server <esp_gatts>
Bluetooth Low Energy GATT Client <esp_gattc>
Bluetooth Low Energy Encrypted Advertising Data <esp_ble_ead>
:SOC_BLUFI_SUPPORTED: Bluetooth Low Energy BluFi <esp_blufi>
@@ -0,0 +1,31 @@
Encrypted Advertising Data (EAD)
================================
:link_to_translation:`zh_CN:[中文]`
Overview
--------
Encrypted Advertising Data (EAD) was introduced in Bluetooth Core Specification 5.4. It allows a device to encrypt one or more advertising structures with AES-CCM, so that only peers that hold the corresponding session key and IV can recover the plaintext.
The Bluedroid host exposes this as a pair of synchronous APIs in ``esp_ble_ead.h``. Encryption and decryption are performed in the host and do not require a controller feature bit.
These APIs are compiled when ``CONFIG_BT_BLE_FEAT_ENC_ADV_DATA`` is enabled.
The GAP Key Material characteristic (UUID 0x2B88, ``CONFIG_BT_GATTS_KEY_MATERIAL_CHAR``) is the standard way for a peripheral to publish the session key and IV. Enabling that option also selects the EAD APIs. Call :cpp:func:`esp_ble_gap_set_key_material` to set the value so a peer can read it over an encrypted GATT connection, then decrypt with :cpp:func:`esp_ble_ead_decrypt`.
A central that already has a pre-shared key only needs ``CONFIG_BT_BLE_FEAT_ENC_ADV_DATA``.
Application Examples
--------------------
- :example:`bluetooth/bluedroid/ble/ble_enc_adv_data/enc_adv_data_prph` demonstrates encrypting advertising data and exposing Key Material through the GAP service.
- :example:`bluetooth/bluedroid/ble/ble_enc_adv_data/enc_adv_data_cent` demonstrates scanning for encrypted advertising data and decrypting it after reading, or using, the Key Material.
In menuconfig, see ``Bluedroid Options`` > ``Encrypted Advertising Data (EAD)``.
API Reference
-------------
.. include-build-file:: inc/esp_ble_ead.inc
@@ -10,6 +10,8 @@ Application Examples
- :example:`bluetooth/bluedroid/ble/gatt_security_server` demonstrates how to use ESP BLE security APIs on {IDF_TARGET_NAME} to establish a secure connection and encrypt communication with peer devices while acting as a GATT server.
- :example:`bluetooth/bluedroid/ble/ble_enc_adv_data/enc_adv_data_prph` demonstrates Encrypted Advertising Data and how to publish Key Material with :cpp:func:`esp_ble_gap_set_key_material`. See also :doc:`esp_ble_ead`.
API Reference
-------------