• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 /*
2  * Fundamental types and constants relating to WPA
3  *
4  * Copyright (C) 1999-2019, Broadcom.
5  *
6  *      Unless you and Broadcom execute a separate written software license
7  * agreement governing use of this software, this software is licensed to you
8  * under the terms of the GNU General Public License version 2 (the "GPL"),
9  * available at http://www.broadcom.com/licenses/GPLv2.php, with the
10  * following added to such license:
11  *
12  *      As a special exception, the copyright holders of this software give you
13  * permission to link this software with independent modules, and to copy and
14  * distribute the resulting executable under terms of your choice, provided that
15  * you also meet, for each linked independent module, the terms and conditions
16  * of the license of that module.  An independent module is a module which is
17  * not derived from this software.  The special exception does not apply to any
18  * modifications of the software.
19  *
20  *      Notwithstanding the above, under no circumstances may you combine this
21  * software in any way with any other Broadcom software provided under a license
22  * other than the GPL, without Broadcom's express prior written consent.
23  *
24  *
25  * <<Broadcom-WL-IPTag/Open:>>
26  *
27  * $Id: wpa.h 822438 2019-05-29 17:13:44Z $
28  */
29 
30 #ifndef _proto_wpa_h_
31 #define _proto_wpa_h_
32 
33 #include <typedefs.h>
34 #include <ethernet.h>
35 
36 /* This marks the start of a packed structure section. */
37 #include <packed_section_start.h>
38 
39 /* Reason Codes */
40 
41 /* 13 through 23 taken from IEEE Std 802.11i-2004 */
42 #define DOT11_RC_INVALID_WPA_IE 13     /* Invalid info. element */
43 #define DOT11_RC_MIC_FAILURE 14        /* Michael failure */
44 #define DOT11_RC_4WH_TIMEOUT 15        /* 4-way handshake timeout */
45 #define DOT11_RC_GTK_UPDATE_TIMEOUT 16 /* Group key update timeout */
46 #define DOT11_RC_WPA_IE_MISMATCH                                               \
47     17 /* WPA IE in 4-way handshake differs from                               \
48         * (re-)assoc. request/probe response                                   \
49         */
50 #define DOT11_RC_INVALID_MC_CIPHER 18 /* Invalid multicast cipher */
51 #define DOT11_RC_INVALID_UC_CIPHER 19 /* Invalid unicast cipher */
52 #define DOT11_RC_INVALID_AKMP                                                  \
53     20 /* Invalid authenticated key management protocol */
54 #define DOT11_RC_BAD_WPA_VERSION 21 /* Unsupported WPA version */
55 #define DOT11_RC_INVALID_WPA_CAP 22 /* Invalid WPA IE capabilities */
56 #define DOT11_RC_8021X_AUTH_FAIL 23 /* 802.1X authentication failure */
57 
58 #define WPA2_PMKID_LEN 16
59 
60 /* WPA IE fixed portion */
61 typedef BWL_PRE_PACKED_STRUCT struct {
62     uint8 tag;      /* TAG */
63     uint8 length;   /* TAG length */
64     uint8 oui[3];   /* IE OUI */
65     uint8 oui_type; /* OUI type */
66     BWL_PRE_PACKED_STRUCT struct {
67         uint8 low;
68         uint8 high;
69     } BWL_POST_PACKED_STRUCT version; /* IE version */
70 } BWL_POST_PACKED_STRUCT wpa_ie_fixed_t;
71 #define WPA_IE_OUITYPE_LEN 4
72 #define WPA_IE_FIXED_LEN 8
73 #define WPA_IE_TAG_FIXED_LEN 6
74 
75 #define BIP_OUI_TYPE WPA2_OUI "\x06"
76 
77 typedef BWL_PRE_PACKED_STRUCT struct {
78     uint8 tag;    /* TAG */
79     uint8 length; /* TAG length */
80     BWL_PRE_PACKED_STRUCT struct {
81         uint8 low;
82         uint8 high;
83     } BWL_POST_PACKED_STRUCT version; /* IE version */
84 } BWL_POST_PACKED_STRUCT wpa_rsn_ie_fixed_t;
85 #define WPA_RSN_IE_FIXED_LEN 4
86 #define WPA_RSN_IE_TAG_FIXED_LEN 2
87 typedef uint8 wpa_pmkid_t[WPA2_PMKID_LEN];
88 
89 #define WFA_OSEN_IE_FIXED_LEN 6
90 
91 /* WPA suite/multicast suite */
92 typedef BWL_PRE_PACKED_STRUCT struct {
93     uint8 oui[3];
94     uint8 type;
95 } BWL_POST_PACKED_STRUCT wpa_suite_t, wpa_suite_mcast_t;
96 #define WPA_SUITE_LEN 4
97 
98 /* WPA unicast suite list/key management suite list */
99 typedef BWL_PRE_PACKED_STRUCT struct {
100     BWL_PRE_PACKED_STRUCT struct {
101         uint8 low;
102         uint8 high;
103     } BWL_POST_PACKED_STRUCT count;
104     wpa_suite_t list[1];
105 } BWL_POST_PACKED_STRUCT wpa_suite_ucast_t, wpa_suite_auth_key_mgmt_t;
106 #define WPA_IE_SUITE_COUNT_LEN 2
107 typedef BWL_PRE_PACKED_STRUCT struct {
108     BWL_PRE_PACKED_STRUCT struct {
109         uint8 low;
110         uint8 high;
111     } BWL_POST_PACKED_STRUCT count;
112     wpa_pmkid_t list[1];
113 } BWL_POST_PACKED_STRUCT wpa_pmkid_list_t;
114 
115 /* WPA cipher suites */
116 #define WPA_CIPHER_NONE 0    /* None */
117 #define WPA_CIPHER_WEP_40 1  /* WEP (40-bit) */
118 #define WPA_CIPHER_TKIP 2    /* TKIP: default for WPA */
119 #define WPA_CIPHER_AES_OCB 3 /* AES (OCB) */
120 #define WPA_CIPHER_AES_CCM 4 /* AES (CCM) */
121 #define WPA_CIPHER_WEP_104 5 /* WEP (104-bit) */
122 #define WPA_CIPHER_BIP 6     /* WEP (104-bit) */
123 #define WPA_CIPHER_TPK 7     /* Group addressed traffic not allowed */
124 #ifdef BCMCCX
125 #define WPA_CIPHER_CKIP 8     /* KP with no MIC */
126 #define WPA_CIPHER_CKIP_MMH 9 /* KP with MIC ("CKIP/MMH", "CKIP+CMIC") */
127 #define WPA_CIPHER_WEP_MMH 10 /* MIC with no KP ("WEP/MMH", "CMIC") */
128 
129 #define IS_CCX_CIPHER(cipher)                                                  \
130     ((cipher) == WPA_CIPHER_CKIP || (cipher) == WPA_CIPHER_CKIP_MMH ||         \
131      (cipher) == WPA_CIPHER_WEP_MMH)
132 #endif /* BCMCCX */
133 
134 #define WPA_CIPHER_AES_GCM 8       /* AES (GCM) */
135 #define WPA_CIPHER_AES_GCM256 9    /* AES (GCM256) */
136 #define WPA_CIPHER_CCMP_256 10     /* CCMP-256 */
137 #define WPA_CIPHER_BIP_GMAC_128 11 /* BIP_GMAC_128 */
138 #define WPA_CIPHER_BIP_GMAC_256 12 /* BIP_GMAC_256 */
139 #define WPA_CIPHER_BIP_CMAC_256 13 /* BIP_CMAC_256 */
140 
141 #ifdef BCMWAPI_WAI
142 #define WAPI_CIPHER_NONE WPA_CIPHER_NONE
143 #define WAPI_CIPHER_SMS4 11
144 
145 #define WAPI_CSE_WPI_SMS4 1
146 #endif /* BCMWAPI_WAI */
147 
148 #define IS_WPA_CIPHER(cipher)                                                  \
149     ((cipher) == WPA_CIPHER_NONE || (cipher) == WPA_CIPHER_WEP_40 ||           \
150      (cipher) == WPA_CIPHER_WEP_104 || (cipher) == WPA_CIPHER_TKIP ||          \
151      (cipher) == WPA_CIPHER_AES_OCB || (cipher) == WPA_CIPHER_AES_CCM ||       \
152      (cipher) == WPA_CIPHER_AES_GCM || (cipher) == WPA_CIPHER_AES_GCM256 ||    \
153      (cipher) == WPA_CIPHER_CCMP_256 || (cipher) == WPA_CIPHER_TPK)
154 
155 #define IS_WPA_BIP_CIPHER(cipher)                                              \
156     ((cipher) == WPA_CIPHER_BIP || (cipher) == WPA_CIPHER_BIP_GMAC_128 ||      \
157      (cipher) == WPA_CIPHER_BIP_GMAC_256 ||                                    \
158      (cipher) == WPA_CIPHER_BIP_CMAC_256)
159 
160 #ifdef BCMWAPI_WAI
161 #define IS_WAPI_CIPHER(cipher)                                                 \
162     ((cipher) == WAPI_CIPHER_NONE || (cipher) == WAPI_CSE_WPI_SMS4)
163 
164 /* convert WAPI_CSE_WPI_XXX to WAPI_CIPHER_XXX */
165 #define WAPI_CSE_WPI_2_CIPHER(cse)                                             \
166     ((cse) == WAPI_CSE_WPI_SMS4 ? WAPI_CIPHER_SMS4 : WAPI_CIPHER_NONE)
167 
168 #define WAPI_CIPHER_2_CSE_WPI(cipher)                                          \
169     ((cipher) == WAPI_CIPHER_SMS4 ? WAPI_CSE_WPI_SMS4 : WAPI_CIPHER_NONE)
170 #endif /* BCMWAPI_WAI */
171 
172 #define IS_VALID_AKM(akm)                                                      \
173     ((akm) == RSN_AKM_NONE || (akm) == RSN_AKM_UNSPECIFIED ||                  \
174      (akm) == RSN_AKM_PSK || (akm) == RSN_AKM_FBT_1X ||                        \
175      (akm) == RSN_AKM_FBT_PSK || (akm) == RSN_AKM_MFP_1X ||                    \
176      (akm) == RSN_AKM_MFP_PSK || (akm) == RSN_AKM_SHA256_1X ||                 \
177      (akm) == RSN_AKM_SHA256_PSK || (akm) == RSN_AKM_TPK ||                    \
178      (akm) == RSN_AKM_SAE_PSK || (akm) == RSN_AKM_SAE_FBT ||                   \
179      (akm) == RSN_AKM_FILS_SHA256 || (akm) == RSN_AKM_FILS_SHA384 ||           \
180      (akm) == RSN_AKM_OWE || (akm) == RSN_AKM_SUITEB_SHA256_1X ||              \
181      (akm) == RSN_AKM_SUITEB_SHA384_1X)
182 
183 #define IS_VALID_BIP_CIPHER(cipher)                                            \
184     ((cipher) == WPA_CIPHER_BIP || (cipher) == WPA_CIPHER_BIP_GMAC_128 ||      \
185      (cipher) == WPA_CIPHER_BIP_GMAC_256 ||                                    \
186      (cipher) == WPA_CIPHER_BIP_CMAC_256)
187 
188 #define WPA_IS_FT_AKM(akm)                                                     \
189     ((akm) == RSN_AKM_FBT_SHA256 || (akm) == RSN_AKM_FBT_SHA384)
190 
191 #define WPA_IS_FILS_AKM(akm)                                                   \
192     ((akm) == RSN_AKM_FILS_SHA256 || (akm) == RSN_AKM_FILS_SHA384)
193 
194 #define WPA_IS_FILS_FT_AKM(akm)                                                \
195     ((akm) == RSN_AKM_FBT_SHA256_FILS || (akm) == RSN_AKM_FBT_SHA384_FILS)
196 
197 /* WPA TKIP countermeasures parameters */
198 #define WPA_TKIP_CM_DETECT 60 /* multiple MIC failure window (seconds) */
199 #define WPA_TKIP_CM_BLOCK 60  /* countermeasures active window (seconds) */
200 
201 /* RSN IE defines */
202 #define RSN_CAP_LEN 2 /* Length of RSN capabilities field (2 octets) */
203 
204 /* RSN Capabilities defined in 802.11i */
205 #define RSN_CAP_PREAUTH 0x0001
206 #define RSN_CAP_NOPAIRWISE 0x0002
207 #define RSN_CAP_PTK_REPLAY_CNTR_MASK 0x000C
208 #define RSN_CAP_PTK_REPLAY_CNTR_SHIFT 2
209 #define RSN_CAP_GTK_REPLAY_CNTR_MASK 0x0030
210 #define RSN_CAP_GTK_REPLAY_CNTR_SHIFT 4
211 #define RSN_CAP_1_REPLAY_CNTR 0
212 #define RSN_CAP_2_REPLAY_CNTRS 1
213 #define RSN_CAP_4_REPLAY_CNTRS 2
214 #define RSN_CAP_16_REPLAY_CNTRS 3
215 #define RSN_CAP_MFPR 0x0040
216 #define RSN_CAP_MFPC 0x0080
217 #define RSN_CAP_SPPC 0x0400
218 #define RSN_CAP_SPPR 0x0800
219 
220 /* WPA capabilities defined in 802.11i */
221 #define WPA_CAP_4_REPLAY_CNTRS RSN_CAP_4_REPLAY_CNTRS
222 #define WPA_CAP_16_REPLAY_CNTRS RSN_CAP_16_REPLAY_CNTRS
223 #define WPA_CAP_REPLAY_CNTR_SHIFT RSN_CAP_PTK_REPLAY_CNTR_SHIFT
224 #define WPA_CAP_REPLAY_CNTR_MASK RSN_CAP_PTK_REPLAY_CNTR_MASK
225 
226 /* WPA capabilities defined in 802.11zD9.0 */
227 #define WPA_CAP_PEER_KEY_ENABLE (0x1 << 1) /* bit 9 */
228 
229 /* WPA Specific defines */
230 #define WPA_CAP_LEN                                                            \
231     RSN_CAP_LEN /* Length of RSN capabilities in RSN IE (2 octets) */
232 #define WPA_PMKID_CNT_LEN 2 /* Length of RSN PMKID count (2 octests) */
233 
234 #define WPA_CAP_WPA2_PREAUTH RSN_CAP_PREAUTH
235 
236 #define WPA2_PMKID_COUNT_LEN 2
237 
238 /* RSN dev type in rsn_info struct */
239 typedef enum { DEV_NONE = 0, DEV_STA = 1, DEV_AP = 2 } device_type_t;
240 
241 typedef uint32 rsn_akm_mask_t; /* RSN_AKM_... see 802.11.h */
242 typedef uint8 rsn_cipher_t;    /* WPA_CIPHER_xxx */
243 typedef uint32 rsn_ciphers_t;  /* mask of rsn_cipher_t */
244 typedef uint8 rsn_akm_t;
245 typedef uint8 auth_ie_type_mask_t;
246 
247 /* Old location for this structure. Moved to bcmwpa.h */
248 #ifndef RSN_IE_INFO_STRUCT_RELOCATED
249 typedef struct rsn_ie_info {
250     uint8 version;
251     rsn_cipher_t g_cipher;
252     uint8 p_count;
253     uint8 akm_count;
254     uint8 pmkid_count;
255     rsn_akm_t sta_akm; /* single STA akm */
256     uint16 caps;
257     rsn_ciphers_t p_ciphers;
258     rsn_akm_mask_t akms;
259     uint8 pmkids_offset; /* offset into the IE */
260     rsn_cipher_t g_mgmt_cipher;
261     device_type_t dev_type;  /* AP or STA */
262     rsn_cipher_t sta_cipher; /* single STA cipher */
263     uint16 key_desc;         /* key descriptor version as STA */
264     int parse_status;
265     uint16 mic_len; /* unused. keep for ROM compatibility. */
266     auth_ie_type_mask_t
267         auth_ie_type;  /* bit field of WPA, WPA2 and (not yet) CCX WAPI */
268     uint8 pmk_len;     /* EAPOL PMK */
269     uint8 kck_mic_len; /* EAPOL MIC (by KCK) */
270     uint8 kck_len;     /* EAPOL KCK */
271     uint8 kek_len;     /* EAPOL KEK */
272     uint8 tk_len;      /* EAPOL TK */
273     uint8 ptk_len;     /* EAPOL PTK */
274     uint8 kck2_len;    /* EAPOL KCK2 */
275     uint8 kek2_len;    /* EAPOL KEK2 */
276 } rsn_ie_info_t;
277 #endif /* RSN_IE_INFO_STRUCT_RELOCATED */
278 
279 #ifdef BCMWAPI_WAI
280 #define WAPI_CAP_PREAUTH RSN_CAP_PREAUTH
281 
282 /* Other WAI definition */
283 #define WAPI_WAI_REQUEST 0x00F1
284 #define WAPI_UNICAST_REKEY 0x00F2
285 #define WAPI_STA_AGING 0x00F3
286 #define WAPI_MUTIL_REKEY 0x00F4
287 #define WAPI_STA_STATS 0x00F5
288 
289 #define WAPI_USK_REKEY_COUNT 0x4000000 /* 0xA00000 */
290 #define WAPI_MSK_REKEY_COUNT 0x4000000 /* 0xA00000 */
291 #endif                                 /* BCMWAPI_WAI */
292 
293 /* This marks the end of a packed structure section. */
294 #include <packed_section_end.h>
295 
296 #endif /* _proto_wpa_h_ */
297