Sign ITS messages on the ESP32-C5 with vanetza-idf, over USB or BLE

obu-firmware is now a port of the colleague's standalone VRU station
(microbu-esp32c5/firmware, kept beside this repository and gitignored): the
vanetza-idf C-ITS stack with the TS 103 097 security entity, credentials in
NVS, the station-link v1 protocol over the native USB port (frame type 0x10
in the existing 0xAA55 framing) and over a BLE GATT peripheral, and its
ITS-G5 radio adapter. The phone still builds CAM and VAM; the board adds
GeoNetworking/BTP and signs with the provisioned authorization ticket. The
private key never leaves the board. Builds with ESP-IDF 6.0.2 only, which
vanetza-idf pins for the radio's private driver ABI. The previous C firmware
stays on disk unbuilt; a full-flash backup of the bench board is kept in
firmware-backups/ (gitignored).

Changed against the colleague's firmware, marked MicrOBU: in the sources:
- Reception unchanged for the app. vanetza-idf drops what it cannot verify
  (unsigned traffic, every RSU), so each captured frame also goes through the
  previous gn_unwrap.c and reaches the phone as link opcode V2X_RX (0x85),
  whose body is the old SERIAL_MSG_V2X_RX payload.
- Unsigned transmission still possible, with the previous geonet.c header;
  the phone chooses per message.
- Console on UART0 (CH343 port); the native USB port carries only link frames.
- BLE advertising pauses while the USB link is in use: BLE and ITS-G5 share
  one RF front end.
- NVS 80 KB (app at 0x20000). At 24 KB, with Wi-Fi settings the previous
  firmware left behind, the BLE bond could not be stored and the phone had to
  pair on every connection.
- Bench fixes: the radio queue is drained before the first PoTi (no RX and
  ~177 queue drops before); the station loop waited pdMS_TO_TICKS(5) = 0
  ticks at 100 Hz and starved the idle task; the 2.4 KB RX capture buffer is
  off the Wi-Fi task stack; BLE notifications longer than the MTU are dropped
  instead of cut short, MTU 517; serial writes are skipped with no USB host.
- Manual country policy and TX-power read-back from the previous radio setup;
  logs for BLE encryption changes and the number of stored bonds.

Verified on the bench board (COM3) with the phone over USB and BLE: CAM and
VAM, signed and unsigned, go out; reception of the sim car and the RSU's
CAM/SPATEM/MAPEM continues; the board survives app restarts and reconnects.
See docs/06-signed-its-vam-ble.md.
This commit is contained in:
Ashin Walpola
2026-09-23 17:27:54 +02:00
parent 7285fa19b7
commit d2fd222a62
31 changed files with 4837 additions and 1022 deletions
+58
View File
@@ -0,0 +1,58 @@
#pragma once
#include "link_protocol.hpp"
#include <cstdint>
#include <functional>
namespace microbu::ble {
using Receiver = std::function<void(link::Bytes)>;
/// @brief A set of counters for tracking BLE message traffic.
struct Counters {
std::uint32_t rx_messages = 0;
std::uint32_t tx_messages = 0;
std::uint32_t tx_failed = 0;
std::uint32_t malformed = 0;
};
/**
* @brief Starts a simple, bonded BLE GATT peripheral on the NimBLE host.
* Uses structured ETSI C-ITS Station Service & Characteristics:
* Service: 0000C175-BA5E-4C17-8000-00805F9B34FB
* BTP-DATA.request: 0000C176-BA5E-4C17-8000-00805F9B34FB (Write, Authenticated/Encrypted)
* BTP-DATA.indication: 0000C177-BA5E-4C17-8000-00805F9B34FB (Notify, Authenticated/Encrypted)
* PoTi Fix Update: 0000C178-BA5E-4C17-8000-00805F9B34FB (Write, Authenticated/Encrypted)
* Station Status: 0000C179-BA5E-4C17-8000-00805F9B34FB (Read / Notify, Authenticated/Encrypted)
* SF-SAP Identity: 0000C17A-BA5E-4C17-8000-00805F9B34FB (Notify, Authenticated/Encrypted)
* Station Configure: 0000C17B-BA5E-4C17-8000-00805F9B34FB (Write, Authenticated/Encrypted)
* Result: 0000C17C-BA5E-4C17-8000-00805F9B34FB (Notify, Authenticated/Encrypted)
*
* Fixed passkey bonding: 123456.
* Single ATT message transmission/reception up to 512 bytes without fragmentation chunk delays.
* @param receiver Invoked with each decoded station-link message written by the phone.
* @return false if the NimBLE host or GATT service failed to start.
*/
bool start(Receiver receiver);
/**
* @brief Sends one complete station-link message via GATT notification.
* Dispatches immediately without queuing delay.
* @param message Encoded station-link message to notify.
* @return false if not connected/subscribed or the notification could not be sent.
*/
bool write(const link::Bytes& message);
/// @return true if a phone is connected.
bool connected();
/// @brief MicrOBU: allows or stops advertising (an existing connection is never dropped). Called
/// with false while the phone uses the USB link, so BLE takes no airtime from ITS-G5.
void set_advertising_allowed(bool allowed);
/// @return true while advertising is allowed (see set_advertising_allowed).
bool advertising_allowed();
/// @return true if the phone has subscribed to notifications.
bool is_subscribed();
/// @return Current message/error counters.
Counters counters();
} // namespace microbu::ble