feat(ble/bluedroid): Support bluedroid encrypted advertising data

This commit is contained in:
zhiweijian
2026-01-05 10:49:16 +08:00
parent 6b754fbfcf
commit fe7b658652
35 changed files with 2945 additions and 0 deletions
+10
View File
@@ -384,6 +384,16 @@ config BT_GATTS_SECURITY_LEVELS_CHAR
help
Enable LE GATT Security Levels Characteristic
config BT_GATTS_KEY_MATERIAL_CHAR
bool "Enable Encrypted Data Key Material Characteristic"
depends on BT_GATTS_ENABLE
default n
help
Enable the Encrypted Data Key Material characteristic in GAP service.
This characteristic allows advertising data to be decrypted and authenticated
using the key material (session key + IV) as defined in Bluetooth Core
Specification Version 5.4. The characteristic requires encrypted link to read.
menuconfig BT_GATTC_ENABLE
bool "Include GATT client module(GATTC)"
depends on BT_BLE_ENABLED
@@ -440,6 +440,28 @@ esp_err_t esp_ble_gap_get_device_name(void)
return (btc_transfer_context(&msg, NULL, 0, NULL, NULL) == BT_STATUS_SUCCESS ? ESP_OK : ESP_FAIL);
}
#if (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
esp_err_t esp_ble_gap_set_key_material(const uint8_t session_key[16], const uint8_t iv[8])
{
btc_msg_t msg = {0};
btc_ble_gap_args_t arg;
ESP_BLUEDROID_STATUS_CHECK(ESP_BLUEDROID_STATUS_ENABLED);
if (session_key == NULL || iv == NULL) {
return ESP_ERR_INVALID_ARG;
}
msg.sig = BTC_SIG_API_CALL;
msg.pid = BTC_PID_GAP_BLE;
msg.act = BTC_GAP_BLE_ACT_SET_KEY_MATERIAL;
memcpy(arg.set_key_material.session_key, session_key, 16);
memcpy(arg.set_key_material.iv, iv, 8);
return (btc_transfer_context(&msg, &arg, sizeof(btc_ble_gap_args_t), NULL, NULL) == BT_STATUS_SUCCESS ? ESP_OK : ESP_FAIL);
}
#endif // (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
esp_err_t esp_ble_gap_get_local_used_addr(esp_bd_addr_t local_used_addr, uint8_t * addr_type)
{
if(esp_bluedroid_get_status() != (ESP_BLUEDROID_STATUS_ENABLED)) {
@@ -3120,6 +3120,25 @@ esp_err_t esp_ble_gap_set_device_name(const char *name);
*/
esp_err_t esp_ble_gap_get_device_name(void);
#if defined(CONFIG_BT_GATTS_KEY_MATERIAL_CHAR) && CONFIG_BT_GATTS_KEY_MATERIAL_CHAR
/**
* @brief Set the Encrypted Data Key Material in GAP service
*
* This function sets the session key and IV that will be exposed
* through the Key Material characteristic (UUID 0x2B88) in the GAP service.
* The Key Material allows central devices to decrypt encrypted advertising data.
*
* @param[in] session_key - 16-byte (128-bit) session key for AES-CCM encryption
* @param[in] iv - 8-byte (64-bit) initialization vector
*
* @return
* - ESP_OK : success
* - other : failed
*
*/
esp_err_t esp_ble_gap_set_key_material(const uint8_t session_key[16], const uint8_t iv[8]);
#endif // CONFIG_BT_GATTS_KEY_MATERIAL_CHAR
/**
* @brief This function is called to get local used address and address type.
* uint8_t *esp_bt_dev_get_address(void) get the public address
@@ -5406,6 +5406,22 @@ void bta_dm_ble_config_local_icon (tBTA_DM_MSG *p_data)
BTM_BleConfigLocalIcon (p_data->ble_local_icon.icon);
}
#if (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
/*******************************************************************************
**
** Function bta_dm_ble_set_key_material
**
** Description This function sets the Encrypted Data Key Material.
**
**
*******************************************************************************/
void bta_dm_ble_set_key_material (tBTA_DM_MSG *p_data)
{
BTM_BleSetKeyMaterial (p_data->ble_key_material.session_key,
p_data->ble_key_material.iv);
}
#endif
#if (BLE_HOST_BLE_OBSERVE_EN == TRUE)
/*******************************************************************************
**
@@ -2223,6 +2223,41 @@ void BTA_DmBleConfigLocalIcon(uint16_t icon)
}
}
#if (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
/*******************************************************************************
**
** Function BTA_DmBleSetKeyMaterial
**
** Description Set the Encrypted Data Key Material in GAP service
**
** Parameters: session_key - 16-byte session key (must not be NULL)
** iv - 8-byte initialization vector (must not be NULL)
**
** Returns void
**
*******************************************************************************/
void BTA_DmBleSetKeyMaterial(const uint8_t *session_key, const uint8_t *iv)
{
tBTA_DM_API_KEY_MATERIAL *p_msg;
if (session_key == NULL || iv == NULL) {
APPL_TRACE_ERROR("%s: NULL pointer parameter", __func__);
return;
}
if ((p_msg = (tBTA_DM_API_KEY_MATERIAL *) osi_malloc(sizeof(tBTA_DM_API_KEY_MATERIAL))) != NULL) {
memset(p_msg, 0, sizeof(tBTA_DM_API_KEY_MATERIAL));
p_msg->hdr.event = BTA_DM_API_KEY_MATERIAL_EVT;
memcpy(p_msg->session_key, session_key, 16);
memcpy(p_msg->iv, iv, 8);
bta_sys_sendmsg(p_msg);
} else {
APPL_TRACE_ERROR("%s: failed to allocate memory", __func__);
}
}
#endif
#if (BLE_HOST_BLE_MULTI_ADV_EN == TRUE)
/*******************************************************************************
**
@@ -170,6 +170,9 @@ const tBTA_DM_ACTION bta_dm_action[BTA_DM_MAX_EVT] = {
bta_dm_ble_config_local_privacy, /* BTA_DM_API_LOCAL_PRIVACY_EVT */
#endif
bta_dm_ble_config_local_icon, /* BTA_DM_API_LOCAL_ICON_EVT */
#if (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
bta_dm_ble_set_key_material, /* BTA_DM_API_KEY_MATERIAL_EVT */
#endif
#if (BLE_42_ADV_EN == TRUE)
bta_dm_ble_set_adv_params_all, /* BTA_DM_API_BLE_ADV_PARAM_All_EVT */
bta_dm_ble_set_adv_config, /* BTA_DM_API_BLE_SET_ADV_CONFIG_EVT */
@@ -159,6 +159,9 @@ enum {
BTA_DM_API_LOCAL_PRIVACY_EVT,
#endif
BTA_DM_API_LOCAL_ICON_EVT,
#if (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
BTA_DM_API_KEY_MATERIAL_EVT,
#endif
/*******This event added by Yulong at 2016/10/20 to
support setting the ble advertising param by the APP******/
@@ -853,6 +856,14 @@ typedef struct {
uint16_t icon;
} tBTA_DM_API_LOCAL_ICON;
#if (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
typedef struct {
BT_HDR hdr;
uint8_t session_key[16];
uint8_t iv[8];
} tBTA_DM_API_KEY_MATERIAL;
#endif
/* set scan parameter for BLE connections */
typedef struct {
BT_HDR hdr;
@@ -1900,6 +1911,9 @@ typedef union {
tBTA_DM_API_ENABLE_PRIVACY ble_remote_privacy;
tBTA_DM_API_LOCAL_PRIVACY ble_local_privacy;
tBTA_DM_API_LOCAL_ICON ble_local_icon;
#if (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
tBTA_DM_API_KEY_MATERIAL ble_key_material;
#endif
tBTA_DM_API_BLE_ADV_PARAMS_ALL ble_set_adv_params_all;
tBTA_DM_API_SET_ADV_CONFIG ble_set_adv_data;
tBTA_DM_API_SET_ADV_CONFIG_RAW ble_set_adv_data_raw;
@@ -2504,6 +2518,9 @@ extern void bta_dm_ble_stop_advertising(tBTA_DM_MSG *p_data);
#endif // #if (BLE_HOST_STOP_ADV_UNUSED == TRUE)
extern void bta_dm_ble_config_local_privacy (tBTA_DM_MSG *p_data);
extern void bta_dm_ble_config_local_icon (tBTA_DM_MSG *p_data);
#if (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
extern void bta_dm_ble_set_key_material (tBTA_DM_MSG *p_data);
#endif
extern void bta_dm_ble_set_adv_params_all(tBTA_DM_MSG *p_data);
extern void bta_dm_ble_set_adv_config (tBTA_DM_MSG *p_data);
extern void bta_dm_ble_set_adv_config_raw (tBTA_DM_MSG *p_data);
@@ -2939,6 +2939,22 @@ extern void BTA_DmBleConfigLocalPrivacy(BOOLEAN privacy_enable, tBTA_SET_LOCAL_P
*******************************************************************************/
extern void BTA_DmBleConfigLocalIcon(uint16_t icon);
#if (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
/*******************************************************************************
**
** Function BTA_DmBleSetKeyMaterial
**
** Description Set the Encrypted Data Key Material in GAP service
**
** Parameters: session_key - 16-byte session key
** iv - 8-byte initialization vector
**
** Returns void
**
*******************************************************************************/
extern void BTA_DmBleSetKeyMaterial(const uint8_t *session_key, const uint8_t *iv);
#endif
/*******************************************************************************
**
** Function BTA_DmBleEnableRemotePrivacy
@@ -3187,6 +3187,11 @@ void btc_gap_ble_call_handler(btc_msg_t *msg)
BTA_DmBleGapCsProcEnable(arg_5->cs_procedure_enable_params.conn_handle, arg_5->cs_procedure_enable_params.config_id, arg_5->cs_procedure_enable_params.enable);
break;
#endif // (BT_BLE_FEAT_CHANNEL_SOUNDING == TRUE)
#if (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
case BTC_GAP_BLE_ACT_SET_KEY_MATERIAL:
BTA_DmBleSetKeyMaterial(arg->set_key_material.session_key, arg->set_key_material.iv);
break;
#endif
default:
break;
}
@@ -160,6 +160,9 @@ typedef enum {
BTC_GAP_BLE_CS_SET_PROCEDURE_PARAMS,
BTC_GAP_BLE_CS_PROCEDURE_ENABLE,
#endif // (BT_BLE_FEAT_CHANNEL_SOUNDING == TRUE)
#if (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
BTC_GAP_BLE_ACT_SET_KEY_MATERIAL,
#endif
} btc_gap_ble_act_t;
/* btc_ble_gap_args_t */
@@ -215,6 +218,13 @@ typedef union {
struct cfg_local_icon_args {
uint16_t icon;
} cfg_local_icon;
#if (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
//BTC_GAP_BLE_ACT_SET_KEY_MATERIAL
struct set_key_material_args {
uint8_t session_key[16];
uint8_t iv[8];
} set_key_material;
#endif
//BTC_GAP_BLE_ACT_UPDATE_WHITE_LIST
struct update_white_list_args {
bool add_remove;
@@ -610,6 +610,12 @@
#define UC_BT_GATTS_SECURITY_LEVELS_CHAR FALSE
#endif
#ifdef CONFIG_BT_GATTS_KEY_MATERIAL_CHAR
#define UC_BT_GATTS_KEY_MATERIAL_CHAR CONFIG_BT_GATTS_KEY_MATERIAL_CHAR
#else
#define UC_BT_GATTS_KEY_MATERIAL_CHAR FALSE
#endif
#ifdef CONFIG_BT_BLE_ACT_SCAN_REP_ADV_SCAN
#define UC_BT_BLE_ACT_SCAN_REP_ADV_SCAN CONFIG_BT_BLE_ACT_SCAN_REP_ADV_SCAN
#else
@@ -828,6 +828,12 @@
#define BT_GATTS_SECURITY_LEVELS_CHAR FALSE
#endif
#if (UC_BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
#define BT_GATTS_KEY_MATERIAL_CHAR TRUE
#else
#define BT_GATTS_KEY_MATERIAL_CHAR FALSE
#endif
#ifdef UC_BT_BLE_ACT_SCAN_REP_ADV_SCAN
#define BTM_BLE_ACTIVE_SCAN_REPORT_ADV_SCAN_RSP_INDIVIDUALLY UC_BT_BLE_ACT_SCAN_REP_ADV_SCAN
#endif
@@ -1164,6 +1164,39 @@ void BTM_BleConfigLocalIcon(uint16_t icon)
#endif
}
#if (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
/*******************************************************************************
**
** Function BTM_BleSetKeyMaterial
**
** Description Set the Encrypted Data Key Material in GAP service
**
** Parameters session_key: 16-byte session key (must not be NULL)
** iv: 8-byte initialization vector (must not be NULL)
**
** Returns void
**
*******************************************************************************/
void BTM_BleSetKeyMaterial(const uint8_t *session_key, const uint8_t *iv)
{
#if (defined(GAP_INCLUDED) && GAP_INCLUDED == TRUE && GATTS_INCLUDED == TRUE)
tGAP_BLE_ATTR_VALUE p_value;
if (session_key == NULL || iv == NULL) {
BTM_TRACE_ERROR("%s: NULL pointer parameter", __func__);
return;
}
memset(&p_value, 0, sizeof(tGAP_BLE_ATTR_VALUE));
memcpy(p_value.key_material.session_key, session_key, GAP_KEY_MATERIAL_SESSION_KEY_SIZE);
memcpy(p_value.key_material.iv, iv, GAP_KEY_MATERIAL_IV_SIZE);
GAP_BleAttrDBUpdate(GATT_UUID_GAP_KEY_MATERIAL, &p_value);
#else
BTM_TRACE_ERROR("%s\n", __func__);
#endif
}
#endif
/*******************************************************************************
**
** Function BTM_BleConfigConnParams
@@ -262,6 +262,13 @@ tGATT_STATUS gap_read_attr_value (UINT16 handle, tGATT_VALUE *p_value, BOOLEAN i
p_value->len = 2;
break;
#endif // (BT_GATTS_SECURITY_LEVELS_CHAR == TRUE)
#if (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
case GATT_UUID_GAP_KEY_MATERIAL:
ARRAY_TO_STREAM(p, p_db_attr->attr_value.key_material.session_key, GAP_KEY_MATERIAL_SESSION_KEY_SIZE);
ARRAY_TO_STREAM(p, p_db_attr->attr_value.key_material.iv, GAP_KEY_MATERIAL_IV_SIZE);
p_value->len = GAP_KEY_MATERIAL_SIZE;
break;
#endif // (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
}
return GATT_SUCCESS;
}
@@ -481,6 +488,20 @@ void gap_attr_db_init(void)
p_db_attr++;
#endif // (BT_GATTS_SECURITY_LEVELS_CHAR == TRUE)
#if (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
/* Add Encrypted Data Key Material Characteristic
* Per Bluetooth spec: readable only when authenticated and authorized,
* requires encrypted link to read.
*/
uuid.len = LEN_UUID_16;
uuid.uu.uuid16 = p_db_attr->uuid = GATT_UUID_GAP_KEY_MATERIAL;
p_db_attr->handle = GATTS_AddCharacteristic(service_handle, &uuid,
GATT_PERM_READ_ENCRYPTED, GATT_CHAR_PROP_BIT_READ,
NULL, NULL);
memset(&p_db_attr->attr_value.key_material, 0, sizeof(tGAP_BLE_KEY_MATERIAL));
p_db_attr++;
#endif // (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
/* start service now */
memset (&app_uuid.uu.uuid128, 0x81, LEN_UUID_128);
@@ -512,6 +533,11 @@ void GAP_BleAttrDBUpdate(UINT16 attr_uuid, tGAP_BLE_ATTR_VALUE *p_value)
GAP_TRACE_EVENT("GAP_BleAttrDBUpdate attr_uuid=0x%04x\n", attr_uuid);
if (p_value == NULL) {
GAP_TRACE_ERROR("GAP_BleAttrDBUpdate: NULL pointer parameter");
return;
}
for (i = 0; i < GAP_MAX_CHAR_NUM; i ++, p_db_attr ++) {
if (p_db_attr->uuid == attr_uuid) {
GAP_TRACE_EVENT("Found attr_uuid=0x%04x\n", attr_uuid);
@@ -540,6 +566,13 @@ void GAP_BleAttrDBUpdate(UINT16 attr_uuid, tGAP_BLE_ATTR_VALUE *p_value)
break;
#endif // (BT_GATTS_SECURITY_LEVELS_CHAR == TRUE)
#if (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
case GATT_UUID_GAP_KEY_MATERIAL:
memcpy(&p_db_attr->attr_value.key_material, &p_value->key_material,
sizeof(tGAP_BLE_KEY_MATERIAL));
break;
#endif // (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
}
break;
}
@@ -93,7 +93,11 @@ typedef struct {
#if BLE_INCLUDED == TRUE
#if (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
#define GAP_MAX_CHAR_NUM 6
#else
#define GAP_MAX_CHAR_NUM 5
#endif
typedef struct {
UINT16 handle;
@@ -2948,6 +2948,22 @@ BOOLEAN BTM_BleConfigPrivacy(BOOLEAN enable, tBTM_SET_LOCAL_PRIVACY_CBACK *set_l
*******************************************************************************/
void BTM_BleConfigLocalIcon(uint16_t icon);
#if (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
/*******************************************************************************
**
** Function BTM_BleSetKeyMaterial
**
** Description Set the Encrypted Data Key Material in GAP service
**
** Parameters session_key: 16-byte session key
** iv: 8-byte initialization vector
**
** Returns void
**
*******************************************************************************/
void BTM_BleSetKeyMaterial(const uint8_t *session_key, const uint8_t *iv);
#endif
/*******************************************************************************
**
** Function BTM_BleConfigConnParams
@@ -113,6 +113,17 @@ typedef struct {
UINT16 sp_tout;
} tGAP_BLE_PREF_PARAM;
#if (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
#define GAP_KEY_MATERIAL_SESSION_KEY_SIZE 16 /* 128-bit session key */
#define GAP_KEY_MATERIAL_IV_SIZE 8 /* 64-bit IV */
#define GAP_KEY_MATERIAL_SIZE (GAP_KEY_MATERIAL_SESSION_KEY_SIZE + GAP_KEY_MATERIAL_IV_SIZE)
typedef struct {
UINT8 session_key[GAP_KEY_MATERIAL_SESSION_KEY_SIZE];
UINT8 iv[GAP_KEY_MATERIAL_IV_SIZE];
} tGAP_BLE_KEY_MATERIAL;
#endif // (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
typedef union {
tGAP_BLE_PREF_PARAM conn_param;
BD_ADDR reconn_bda;
@@ -122,6 +133,9 @@ typedef union {
#if (BT_GATTS_SECURITY_LEVELS_CHAR == TRUE)
UINT16 security_level;
#endif // (BT_GATTS_SECURITY_LEVELS_CHAR == TRUE)
#if (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
tGAP_BLE_KEY_MATERIAL key_material;
#endif // (BT_GATTS_KEY_MATERIAL_CHAR == TRUE)
} tGAP_BLE_ATTR_VALUE;
@@ -53,6 +53,7 @@
#define GATT_UUID_GAP_CENTRAL_ADDR_RESOL 0x2AA6
#define GATT_UUID_GAP_GATT_SECURITY_LEVELS 0x2BF5
#define GATT_UUID_GAP_KEY_MATERIAL 0x2B88 /* Encrypted Data Key Material */
/* Attribute Profile Attribute UUID */
#define GATT_UUID_GATT_SRV_CHGD 0x2A05