1/* 2 * Fundamental types and constants relating to WPA 3 * 4 * Copyright (C) 2015, Broadcom Corporation. All Rights Reserved. 5 * 6 * Permission to use, copy, modify, and/or distribute this software for any 7 * purpose with or without fee is hereby granted, provided that the above 8 * copyright notice and this permission notice appear in all copies. 9 * 10 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES 11 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF 12 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY 13 * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES 14 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION 15 * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN 16 * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. 17 * 18 * $Id: wpa.h 450927 2014-01-23 14:13:36Z $ 19 */ 20 21#ifndef _proto_wpa_h_ 22#define _proto_wpa_h_ 23 24#include <typedefs.h> 25#include <proto/ethernet.h> 26 27 28/* This marks the start of a packed structure section. */ 29#include <packed_section_start.h> 30 31/* Reason Codes */ 32 33/* 13 through 23 taken from IEEE Std 802.11i-2004 */ 34#define DOT11_RC_INVALID_WPA_IE 13 /* Invalid info. element */ 35#define DOT11_RC_MIC_FAILURE 14 /* Michael failure */ 36#define DOT11_RC_4WH_TIMEOUT 15 /* 4-way handshake timeout */ 37#define DOT11_RC_GTK_UPDATE_TIMEOUT 16 /* Group key update timeout */ 38#define DOT11_RC_WPA_IE_MISMATCH 17 /* WPA IE in 4-way handshake differs from 39 * (re-)assoc. request/probe response 40 */ 41#define DOT11_RC_INVALID_MC_CIPHER 18 /* Invalid multicast cipher */ 42#define DOT11_RC_INVALID_UC_CIPHER 19 /* Invalid unicast cipher */ 43#define DOT11_RC_INVALID_AKMP 20 /* Invalid authenticated key management protocol */ 44#define DOT11_RC_BAD_WPA_VERSION 21 /* Unsupported WPA version */ 45#define DOT11_RC_INVALID_WPA_CAP 22 /* Invalid WPA IE capabilities */ 46#define DOT11_RC_8021X_AUTH_FAIL 23 /* 802.1X authentication failure */ 47 48#define WPA2_PMKID_LEN 16 49 50/* WPA IE fixed portion */ 51typedef BWL_PRE_PACKED_STRUCT struct 52{ 53 uint8 tag; /* TAG */ 54 uint8 length; /* TAG length */ 55 uint8 oui[3]; /* IE OUI */ 56 uint8 oui_type; /* OUI type */ 57 BWL_PRE_PACKED_STRUCT struct { 58 uint8 low; 59 uint8 high; 60 } BWL_POST_PACKED_STRUCT version; /* IE version */ 61} BWL_POST_PACKED_STRUCT wpa_ie_fixed_t; 62#define WPA_IE_OUITYPE_LEN 4 63#define WPA_IE_FIXED_LEN 8 64#define WPA_IE_TAG_FIXED_LEN 6 65 66typedef BWL_PRE_PACKED_STRUCT struct { 67 uint8 tag; /* TAG */ 68 uint8 length; /* TAG length */ 69 BWL_PRE_PACKED_STRUCT struct { 70 uint8 low; 71 uint8 high; 72 } BWL_POST_PACKED_STRUCT version; /* IE version */ 73} BWL_POST_PACKED_STRUCT wpa_rsn_ie_fixed_t; 74#define WPA_RSN_IE_FIXED_LEN 4 75#define WPA_RSN_IE_TAG_FIXED_LEN 2 76typedef uint8 wpa_pmkid_t[WPA2_PMKID_LEN]; 77 78#define WFA_OSEN_IE_FIXED_LEN 6 79 80/* WPA suite/multicast suite */ 81typedef BWL_PRE_PACKED_STRUCT struct 82{ 83 uint8 oui[3]; 84 uint8 type; 85} BWL_POST_PACKED_STRUCT wpa_suite_t, wpa_suite_mcast_t; 86#define WPA_SUITE_LEN 4 87 88/* WPA unicast suite list/key management suite list */ 89typedef BWL_PRE_PACKED_STRUCT struct 90{ 91 BWL_PRE_PACKED_STRUCT struct { 92 uint8 low; 93 uint8 high; 94 } BWL_POST_PACKED_STRUCT count; 95 wpa_suite_t list[1]; 96} BWL_POST_PACKED_STRUCT wpa_suite_ucast_t, wpa_suite_auth_key_mgmt_t; 97#define WPA_IE_SUITE_COUNT_LEN 2 98typedef BWL_PRE_PACKED_STRUCT struct 99{ 100 BWL_PRE_PACKED_STRUCT struct { 101 uint8 low; 102 uint8 high; 103 } BWL_POST_PACKED_STRUCT count; 104 wpa_pmkid_t list[1]; 105} BWL_POST_PACKED_STRUCT wpa_pmkid_list_t; 106 107/* WPA cipher suites */ 108#define WPA_CIPHER_NONE 0 /* None */ 109#define WPA_CIPHER_WEP_40 1 /* WEP (40-bit) */ 110#define WPA_CIPHER_TKIP 2 /* TKIP: default for WPA */ 111#define WPA_CIPHER_AES_OCB 3 /* AES (OCB) */ 112#define WPA_CIPHER_AES_CCM 4 /* AES (CCM) */ 113#define WPA_CIPHER_WEP_104 5 /* WEP (104-bit) */ 114#define WPA_CIPHER_BIP 6 /* WEP (104-bit) */ 115#define WPA_CIPHER_TPK 7 /* Group addressed traffic not allowed */ 116 117 118#define IS_WPA_CIPHER(cipher) ((cipher) == WPA_CIPHER_NONE || \ 119 (cipher) == WPA_CIPHER_WEP_40 || \ 120 (cipher) == WPA_CIPHER_WEP_104 || \ 121 (cipher) == WPA_CIPHER_TKIP || \ 122 (cipher) == WPA_CIPHER_AES_OCB || \ 123 (cipher) == WPA_CIPHER_AES_CCM || \ 124 (cipher) == WPA_CIPHER_TPK) 125 126 127/* WPA TKIP countermeasures parameters */ 128#define WPA_TKIP_CM_DETECT 60 /* multiple MIC failure window (seconds) */ 129#define WPA_TKIP_CM_BLOCK 60 /* countermeasures active window (seconds) */ 130 131/* RSN IE defines */ 132#define RSN_CAP_LEN 2 /* Length of RSN capabilities field (2 octets) */ 133 134/* RSN Capabilities defined in 802.11i */ 135#define RSN_CAP_PREAUTH 0x0001 136#define RSN_CAP_NOPAIRWISE 0x0002 137#define RSN_CAP_PTK_REPLAY_CNTR_MASK 0x000C 138#define RSN_CAP_PTK_REPLAY_CNTR_SHIFT 2 139#define RSN_CAP_GTK_REPLAY_CNTR_MASK 0x0030 140#define RSN_CAP_GTK_REPLAY_CNTR_SHIFT 4 141#define RSN_CAP_1_REPLAY_CNTR 0 142#define RSN_CAP_2_REPLAY_CNTRS 1 143#define RSN_CAP_4_REPLAY_CNTRS 2 144#define RSN_CAP_16_REPLAY_CNTRS 3 145#define RSN_CAP_MFPR 0x0040 146#define RSN_CAP_MFPC 0x0080 147#define RSN_CAP_SPPC 0x0400 148#define RSN_CAP_SPPR 0x0800 149 150/* WPA capabilities defined in 802.11i */ 151#define WPA_CAP_4_REPLAY_CNTRS RSN_CAP_4_REPLAY_CNTRS 152#define WPA_CAP_16_REPLAY_CNTRS RSN_CAP_16_REPLAY_CNTRS 153#define WPA_CAP_REPLAY_CNTR_SHIFT RSN_CAP_PTK_REPLAY_CNTR_SHIFT 154#define WPA_CAP_REPLAY_CNTR_MASK RSN_CAP_PTK_REPLAY_CNTR_MASK 155 156/* WPA capabilities defined in 802.11zD9.0 */ 157#define WPA_CAP_PEER_KEY_ENABLE (0x1 << 1) /* bit 9 */ 158 159/* WPA Specific defines */ 160#define WPA_CAP_LEN RSN_CAP_LEN /* Length of RSN capabilities in RSN IE (2 octets) */ 161#define WPA_PMKID_CNT_LEN 2 /* Length of RSN PMKID count (2 octests) */ 162 163#define WPA_CAP_WPA2_PREAUTH RSN_CAP_PREAUTH 164 165#define WPA2_PMKID_COUNT_LEN 2 166 167 168/* This marks the end of a packed structure section. */ 169#include <packed_section_end.h> 170 171#endif /* _proto_wpa_h_ */ 172