[border-agent] introduce BorderAgent::EphemeralKeyManager (#11166)

This commit introduces the `BorderAgent::EphemeralKeyManager` class,
which manages the use of the ephemeral key by the Border Agent.

The `EphemeralKeyManager` uses its own DTLS transport and CoAP secure
sessions. This allows the `EphemeralKeyManager` and the `BorderAgent`
service (which uses PSKc) to be enabled and used in parallel.
Previously, a single transport and session was shared between these
functions, requiring the normal BA service (with PSKc) to be stopped
before the ephemeral key could be used.

This is a fundamental change and improvement to the ephemeral key and
Border Agent functionality. Therefore some existing `otBorderAgent`
APIs need to be modified. For example, `otBorderAgentGetState()`,
which returned the Border Agent state to indicate whether there were
any active sessions, is no longer meaningful, as different
sessions/transports are now used for PSKc and ephemeral key, and
there can be multiple sessions. This commit intentionally renames and
changes the `otBorderAgent` public APIs, specifically all those
related to ephemeral key use, to highlight the fundamental change in
behavior. While this can cause backward incompatibility, it requires
app layer code that used the previous APIs to be updated to take into
account the new behavior.

This commit also updates `nexus/test_border_agent`, adding new tests
to validate the new behavior (e.g., BA service and ephemeral key
parallel sessions). It also includes and validates the Border Agent
counter updates under different scenarios (this enhances and replaces
`test_ephemeral_key_counters.py`).
This commit is contained in:
Abtin Keshavarzian
2025-02-04 09:34:08 -05:00
committed by GitHub
parent c5458354da
commit bdb394eb3b
16 changed files with 1035 additions and 903 deletions
-6
View File
@@ -181,12 +181,6 @@ expect ": InvalidState"
send "ba port\n"
expect "Done"
send "ba state\n"
expect "Done"
send "ba disconnect\n"
expect "Done"
send "prefix meshlocal fd00:dead:beef:cafe::/96\n"
expect_line "Error 7: InvalidArgs"
send "prefix meshlocal fd00:dead:beef:cafe::/64\n"
@@ -1,123 +0,0 @@
#!/usr/bin/env python3
#
# Copyright (c) 2024, The OpenThread Authors.
# All rights reserved.
#
# Redistribution and use in source and binary forms, with or without
# modification, are permitted provided that the following conditions are met:
# 1. Redistributions of source code must retain the above copyright
# notice, this list of conditions and the following disclaimer.
# 2. Redistributions in binary form must reproduce the above copyright
# notice, this list of conditions and the following disclaimer in the
# documentation and/or other materials provided with the distribution.
# 3. Neither the name of the copyright holder nor the
# names of its contributors may be used to endorse or promote products
# derived from this software without specific prior written permission.
#
# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS 'AS IS'
# AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
# IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
# ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE
# LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
# CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
# SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
# INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
# CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
# ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
# POSSIBILITY OF SUCH DAMAGE.
#
import logging
import unittest
import config
import thread_cert
# Test description:
# This test verifies the counters of ephemeral key activations/deactivations.
#
# Topology:
# --------------
# |
# BR1
#
BR1 = 1
class EphemeralKeyCountersTest(thread_cert.TestCase):
USE_MESSAGE_FACTORY = False
TOPOLOGY = {
BR1: {
'name': 'BR_1',
'is_otbr': True,
'version': '1.4',
'network_name': 'ot-br1',
},
}
def test(self):
br1 = self.nodes[BR1]
counters = br1.get_border_agent_counters()
self.assertEqual(counters['epskcActivation'], 0)
self.assertEqual(counters['epskcApiDeactivation'], 0)
self.assertEqual(counters['epskcTimeoutDeactivation'], 0)
self.assertEqual(counters['epskcMaxAttemptDeactivation'], 0)
self.assertEqual(counters['epskcDisconnectDeactivation'], 0)
self.assertEqual(counters['epskcInvalidBaStateError'], 0)
self.assertEqual(counters['epskcInvalidArgsError'], 0)
self.assertEqual(counters['epskcStartSecureSessionError'], 0)
self.assertEqual(counters['epskcSecureSessionSuccess'], 0)
self.assertEqual(counters['epskcSecureSessionFailure'], 0)
self.assertEqual(counters['epskcCommissionerPetition'], 0)
self.assertEqual(counters['pskcSecureSessionSuccess'], 0)
self.assertEqual(counters['pskcSecureSessionFailure'], 0)
self.assertEqual(counters['pskcCommissionerPetition'], 0)
self.assertEqual(counters['mgmtActiveGet'], 0)
self.assertEqual(counters['mgmtPendingGet'], 0)
# activate epskc before border agent is up returns an error
br1.set_epskc('123456789')
counters = br1.get_border_agent_counters()
self.assertEqual(counters['epskcActivation'], 0)
self.assertEqual(counters['epskcInvalidBaStateError'], 1)
br1.set_active_dataset(updateExisting=True, network_name='ot-br1')
br1.start()
self.simulator.go(config.BORDER_ROUTER_STARTUP_DELAY)
self.assertEqual('leader', br1.get_state())
# activate epskc and let it timeout
br1.set_epskc('123456789', 10)
self.simulator.go(1)
counters = br1.get_border_agent_counters()
self.assertEqual(counters['epskcActivation'], 1)
self.assertEqual(counters['epskcApiDeactivation'], 0)
self.assertEqual(counters['epskcTimeoutDeactivation'], 1)
# activate epskc and clear it
br1.set_epskc('123456789', 10000)
self.simulator.go(1)
br1.clear_epskc()
counters = br1.get_border_agent_counters()
self.assertEqual(counters['epskcActivation'], 2)
self.assertEqual(counters['epskcApiDeactivation'], 1)
self.assertEqual(counters['epskcTimeoutDeactivation'], 1)
# set epskc with invalid passcode
br1.set_epskc('123')
self.simulator.go(1)
counters = br1.get_border_agent_counters()
self.assertEqual(counters['epskcActivation'], 2)
self.assertEqual(counters['epskcApiDeactivation'], 1)
self.assertEqual(counters['epskcTimeoutDeactivation'], 1)
self.assertEqual(counters['epskcInvalidArgsError'], 1)
if __name__ == '__main__':
unittest.main()
@@ -106,13 +106,13 @@ class PublishMeshCopService(thread_cert.TestCase):
lifetime = 500_000
ephemeral_key = br1.activate_ephemeral_key_mode(lifetime)
self.assertEqual(len(ephemeral_key), 9)
self.assertEqual(br1.get_ephemeral_key_state(), 'active')
self.assertEqual(br1.get_ephemeral_key_state(), 'Started')
# check Meshcop-e service
self.check_meshcop_e_service(host, True)
# deactivate ePSKc mode in force
br1.deactivate_ephemeral_key_mode(retain_active_session=False)
self.assertEqual(br1.get_ephemeral_key_state(), 'inactive')
self.assertEqual(br1.get_ephemeral_key_state(), 'Stopped')
self.simulator.go(10)
# check Meshcop-e service
self.check_meshcop_e_service(host, False)
@@ -121,13 +121,13 @@ class PublishMeshCopService(thread_cert.TestCase):
lifetime = 0
ephemeral_key = br1.activate_ephemeral_key_mode(lifetime)
self.assertEqual(len(ephemeral_key), 9)
self.assertEqual(br1.get_ephemeral_key_state(), 'active')
self.assertEqual(br1.get_ephemeral_key_state(), 'Started')
# check Meshcop-e service
self.check_meshcop_e_service(host, True)
# deactivate ePSKc mode NOT in force
br1.deactivate_ephemeral_key_mode(retain_active_session=True)
self.assertEqual(br1.get_ephemeral_key_state(), 'inactive')
self.assertEqual(br1.get_ephemeral_key_state(), 'Stopped')
self.simulator.go(10)
# check Meshcop-e service
self.check_meshcop_e_service(host, False)
+1 -11
View File
@@ -1456,16 +1456,6 @@ class NodeImpl:
self.send_command(cmd)
return int(self._expect_command_output()[0])
def set_epskc(self, keystring: str, timeout=120000, port=0):
cmd = 'ba ephemeralkey set ' + keystring + ' ' + str(timeout) + ' ' + str(port)
self.send_command(cmd)
self._expect(r"(Done|Error .*)")
def clear_epskc(self):
cmd = 'ba ephemeralkey clear'
self.send_command(cmd)
self._expect_done()
def get_border_agent_counters(self):
cmd = 'ba counters'
self.send_command(cmd)
@@ -1934,7 +1924,7 @@ class NodeImpl:
def get_ephemeral_key_state(self):
cmd = 'ba ephemeralkey'
states = [r'inactive', r'active']
states = [r'Disabled', r'Stopped', r'Started', r'Connected', r'Accepted']
self.send_command(cmd)
return self._expect_result(states)