nfc_worker.c 20 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473
  1. #include "nfc_worker_i.h"
  2. #include <api-hal.h>
  3. #include "nfc_protocols/emv_decoder.h"
  4. #include "nfc_protocols/mifare_ultralight.h"
  5. #define NFC_WORKER_TAG "nfc worker"
  6. /***************************** NFC Worker API *******************************/
  7. NfcWorker* nfc_worker_alloc(osMessageQueueId_t message_queue) {
  8. NfcWorker* nfc_worker = furi_alloc(sizeof(NfcWorker));
  9. nfc_worker->message_queue = message_queue;
  10. // Worker thread attributes
  11. nfc_worker->thread_attr.name = "nfc_worker";
  12. nfc_worker->thread_attr.stack_size = 8192;
  13. nfc_worker->callback = NULL;
  14. nfc_worker->context = NULL;
  15. // Initialize rfal
  16. nfc_worker->error = api_hal_nfc_init();
  17. if(nfc_worker->error == ERR_NONE) {
  18. api_hal_nfc_start_sleep();
  19. nfc_worker_change_state(nfc_worker, NfcWorkerStateReady);
  20. } else {
  21. nfc_worker_change_state(nfc_worker, NfcWorkerStateBroken);
  22. }
  23. return nfc_worker;
  24. }
  25. void nfc_worker_free(NfcWorker* nfc_worker) {
  26. furi_assert(nfc_worker);
  27. free(nfc_worker);
  28. }
  29. NfcWorkerState nfc_worker_get_state(NfcWorker* nfc_worker) {
  30. return nfc_worker->state;
  31. }
  32. ReturnCode nfc_worker_get_error(NfcWorker* nfc_worker) {
  33. return nfc_worker->error;
  34. }
  35. void nfc_worker_start(
  36. NfcWorker* nfc_worker,
  37. NfcWorkerState state,
  38. NfcWorkerCallback callback,
  39. void* context) {
  40. furi_assert(nfc_worker);
  41. furi_assert(nfc_worker->state == NfcWorkerStateReady);
  42. nfc_worker->callback = callback;
  43. nfc_worker->context = context;
  44. nfc_worker_change_state(nfc_worker, state);
  45. nfc_worker->thread = osThreadNew(nfc_worker_task, nfc_worker, &nfc_worker->thread_attr);
  46. }
  47. void nfc_worker_stop(NfcWorker* nfc_worker) {
  48. furi_assert(nfc_worker);
  49. if(nfc_worker->state == NfcWorkerStateBroken) {
  50. return;
  51. }
  52. nfc_worker_change_state(nfc_worker, NfcWorkerStateStop);
  53. }
  54. void nfc_worker_change_state(NfcWorker* nfc_worker, NfcWorkerState state) {
  55. nfc_worker->state = state;
  56. }
  57. /***************************** NFC Worker Thread *******************************/
  58. void nfc_worker_task(void* context) {
  59. NfcWorker* nfc_worker = context;
  60. api_hal_power_insomnia_enter();
  61. api_hal_nfc_exit_sleep();
  62. if(nfc_worker->state == NfcWorkerStateDetect) {
  63. nfc_worker_detect(nfc_worker);
  64. } else if(nfc_worker->state == NfcWorkerStateEmulate) {
  65. nfc_worker_emulate(nfc_worker);
  66. } else if(nfc_worker->state == NfcWorkerStateReadEMV) {
  67. nfc_worker_read_emv(nfc_worker);
  68. } else if(nfc_worker->state == NfcWorkerStateEmulateEMV) {
  69. nfc_worker_field(nfc_worker);
  70. } else if(nfc_worker->state == NfcWorkerStateReadMfUltralight) {
  71. nfc_worker_read_mf_ultralight(nfc_worker);
  72. nfc_worker_emulate_emv(nfc_worker);
  73. } else if(nfc_worker->state == NfcWorkerStateField) {
  74. }
  75. api_hal_nfc_deactivate();
  76. nfc_worker_change_state(nfc_worker, NfcWorkerStateReady);
  77. api_hal_power_insomnia_exit();
  78. osThreadExit();
  79. }
  80. void nfc_worker_detect(NfcWorker* nfc_worker) {
  81. rfalNfcDevice* dev_list;
  82. rfalNfcDevice* dev;
  83. uint8_t dev_cnt;
  84. NfcMessage message;
  85. while(nfc_worker->state == NfcWorkerStateDetect) {
  86. message.found = false;
  87. if(api_hal_nfc_detect(&dev_list, &dev_cnt, 1000, true)) {
  88. // Process first found device
  89. dev = &dev_list[0];
  90. message.found = true;
  91. message.nfc_detect_data.uid_len = dev->nfcidLen;
  92. memcpy(message.nfc_detect_data.uid, dev->nfcid, dev->nfcidLen);
  93. if(dev->type == RFAL_NFC_LISTEN_TYPE_NFCA) {
  94. message.nfc_detect_data.device = NfcDeviceNfca;
  95. message.nfc_detect_data.atqa[0] = dev->dev.nfca.sensRes.anticollisionInfo;
  96. message.nfc_detect_data.atqa[1] = dev->dev.nfca.sensRes.platformInfo;
  97. message.nfc_detect_data.sak = dev->dev.nfca.selRes.sak;
  98. // TODO check protocols
  99. } else if(dev->type == RFAL_NFC_LISTEN_TYPE_NFCB) {
  100. message.nfc_detect_data.device = NfcDeviceNfcb;
  101. } else if(dev->type == RFAL_NFC_LISTEN_TYPE_NFCF) {
  102. message.nfc_detect_data.device = NfcDeviceNfcf;
  103. } else if(dev->type == RFAL_NFC_LISTEN_TYPE_NFCV) {
  104. message.nfc_detect_data.device = NfcDeviceNfcv;
  105. }
  106. }
  107. if(nfc_worker->callback) {
  108. nfc_worker->callback(nfc_worker->context);
  109. }
  110. furi_check(
  111. osMessageQueuePut(nfc_worker->message_queue, &message, 0, osWaitForever) == osOK);
  112. osDelay(100);
  113. }
  114. }
  115. void nfc_worker_emulate(NfcWorker* nfc_worker) {
  116. while(nfc_worker->state == NfcWorkerStateEmulate) {
  117. if(api_hal_nfc_listen(ApiHalNfcEmulateParamsMifare, 100)) {
  118. FURI_LOG_I(NFC_WORKER_TAG, "Reader detected");
  119. api_hal_nfc_deactivate();
  120. }
  121. osDelay(10);
  122. }
  123. }
  124. void nfc_worker_read_emv(NfcWorker* nfc_worker) {
  125. ReturnCode err;
  126. rfalNfcDevice* dev_list;
  127. EmvApplication emv_app = {};
  128. uint8_t dev_cnt = 0;
  129. uint8_t tx_buff[255] = {};
  130. uint16_t tx_len = 0;
  131. uint8_t* rx_buff;
  132. uint16_t* rx_len;
  133. NfcMessage message = {.found = false};
  134. while(nfc_worker->state == NfcWorkerStateReadEMV) {
  135. if(nfc_worker->callback) {
  136. nfc_worker->callback(nfc_worker->context);
  137. }
  138. furi_check(
  139. osMessageQueuePut(nfc_worker->message_queue, &message, 0, osWaitForever) == osOK);
  140. memset(&emv_app, 0, sizeof(emv_app));
  141. if(api_hal_nfc_detect(&dev_list, &dev_cnt, 1000, false)) {
  142. // Card was found. Check that it supports EMV
  143. if(dev_list[0].rfInterface == RFAL_NFC_INTERFACE_ISODEP) {
  144. FURI_LOG_I(NFC_WORKER_TAG, "Send select PPSE command");
  145. tx_len = emv_prepare_select_ppse(tx_buff);
  146. err = api_hal_nfc_data_exchange(tx_buff, tx_len, &rx_buff, &rx_len, false);
  147. if(err != ERR_NONE) {
  148. FURI_LOG_E(NFC_WORKER_TAG, "Error during selection PPSE request: %d", err);
  149. message.found = false;
  150. api_hal_nfc_deactivate();
  151. continue;
  152. }
  153. FURI_LOG_I(
  154. NFC_WORKER_TAG, "Select PPSE response received. Start parsing response");
  155. if(emv_decode_ppse_response(rx_buff, *rx_len, &emv_app)) {
  156. FURI_LOG_I(NFC_WORKER_TAG, "Select PPSE responce parced");
  157. } else {
  158. FURI_LOG_E(NFC_WORKER_TAG, "Can't find pay application");
  159. message.found = false;
  160. api_hal_nfc_deactivate();
  161. continue;
  162. }
  163. FURI_LOG_I(NFC_WORKER_TAG, "Starting application ...");
  164. tx_len = emv_prepare_select_app(tx_buff, &emv_app);
  165. err = api_hal_nfc_data_exchange(tx_buff, tx_len, &rx_buff, &rx_len, false);
  166. if(err != ERR_NONE) {
  167. FURI_LOG_E(
  168. NFC_WORKER_TAG, "Error during application selection request: %d", err);
  169. message.found = false;
  170. api_hal_nfc_deactivate();
  171. continue;
  172. }
  173. FURI_LOG_I(
  174. NFC_WORKER_TAG,
  175. "Select application response received. Start parsing response");
  176. if(emv_decode_select_app_response(rx_buff, *rx_len, &emv_app)) {
  177. FURI_LOG_I(NFC_WORKER_TAG, "Card name: %s", emv_app.name);
  178. memcpy(message.nfc_emv_data.name, emv_app.name, sizeof(emv_app.name));
  179. } else {
  180. FURI_LOG_E(NFC_WORKER_TAG, "Can't read card name");
  181. message.found = false;
  182. api_hal_nfc_deactivate();
  183. continue;
  184. }
  185. FURI_LOG_I(NFC_WORKER_TAG, "Starting Get Processing Options command ...");
  186. tx_len = emv_prepare_get_proc_opt(tx_buff, &emv_app);
  187. err = api_hal_nfc_data_exchange(tx_buff, tx_len, &rx_buff, &rx_len, false);
  188. if(err != ERR_NONE) {
  189. FURI_LOG_E(
  190. NFC_WORKER_TAG, "Error during Get Processing Options command: %d", err);
  191. message.found = false;
  192. api_hal_nfc_deactivate();
  193. continue;
  194. }
  195. if(emv_decode_get_proc_opt(rx_buff, *rx_len, &emv_app)) {
  196. FURI_LOG_I(NFC_WORKER_TAG, "Card number parsed");
  197. message.found = true;
  198. memcpy(
  199. message.nfc_emv_data.number,
  200. emv_app.card_number,
  201. sizeof(emv_app.card_number));
  202. api_hal_nfc_deactivate();
  203. continue;
  204. } else {
  205. // Mastercard doesn't give PAN / card number as GPO response
  206. // Iterate over all files found in application
  207. bool pan_found = false;
  208. for(uint8_t i = 0; (i < emv_app.afl.size) && !pan_found; i += 4) {
  209. uint8_t sfi = emv_app.afl.data[i] >> 3;
  210. uint8_t record_start = emv_app.afl.data[i + 1];
  211. uint8_t record_end = emv_app.afl.data[i + 2];
  212. // Iterate over all records in file
  213. for(uint8_t record = record_start; record <= record_end; ++record) {
  214. tx_len = emv_prepare_read_sfi_record(tx_buff, sfi, record);
  215. err = api_hal_nfc_data_exchange(
  216. tx_buff, tx_len, &rx_buff, &rx_len, false);
  217. if(err != ERR_NONE) {
  218. FURI_LOG_E(
  219. NFC_WORKER_TAG,
  220. "Error reading application sfi %d, record %d",
  221. sfi,
  222. record);
  223. }
  224. if(emv_decode_read_sfi_record(rx_buff, *rx_len, &emv_app)) {
  225. pan_found = true;
  226. break;
  227. }
  228. }
  229. }
  230. if(pan_found) {
  231. FURI_LOG_I(NFC_WORKER_TAG, "Card PAN found");
  232. message.found = true;
  233. memcpy(
  234. message.nfc_emv_data.number,
  235. emv_app.card_number,
  236. sizeof(emv_app.card_number));
  237. } else {
  238. FURI_LOG_E(NFC_WORKER_TAG, "Can't read card number");
  239. message.found = false;
  240. }
  241. api_hal_nfc_deactivate();
  242. }
  243. } else {
  244. // Can't find EMV card
  245. FURI_LOG_W(NFC_WORKER_TAG, "Card doesn't support EMV");
  246. message.found = false;
  247. api_hal_nfc_deactivate();
  248. }
  249. } else {
  250. // Can't find EMV card
  251. FURI_LOG_W(NFC_WORKER_TAG, "Can't find any cards");
  252. message.found = false;
  253. api_hal_nfc_deactivate();
  254. }
  255. osDelay(20);
  256. }
  257. }
  258. void nfc_worker_emulate_emv(NfcWorker* nfc_worker) {
  259. ReturnCode err;
  260. uint8_t tx_buff[255] = {};
  261. uint16_t tx_len = 0;
  262. uint8_t* rx_buff;
  263. uint16_t* rx_len;
  264. while(nfc_worker->state == NfcWorkerStateEmulateEMV) {
  265. if(api_hal_nfc_listen(ApiHalNfcEmulateParamsEMV, 1000)) {
  266. FURI_LOG_I(NFC_WORKER_TAG, "POS terminal detected");
  267. // Read data from POS terminal
  268. err = api_hal_nfc_data_exchange(NULL, 0, &rx_buff, &rx_len, false);
  269. if(err == ERR_NONE) {
  270. FURI_LOG_I(NFC_WORKER_TAG, "Received Select PPSE");
  271. } else {
  272. FURI_LOG_E(NFC_WORKER_TAG, "Error in 1st data exchange: select PPSE");
  273. api_hal_nfc_deactivate();
  274. continue;
  275. }
  276. FURI_LOG_I(NFC_WORKER_TAG, "Transive SELECT PPSE ANS");
  277. tx_len = emv_select_ppse_ans(tx_buff);
  278. err = api_hal_nfc_data_exchange(tx_buff, tx_len, &rx_buff, &rx_len, false);
  279. if(err == ERR_NONE) {
  280. FURI_LOG_I(NFC_WORKER_TAG, "Received Select APP");
  281. } else {
  282. FURI_LOG_E(NFC_WORKER_TAG, "Error in 2nd data exchange: select APP");
  283. api_hal_nfc_deactivate();
  284. continue;
  285. }
  286. FURI_LOG_I(NFC_WORKER_TAG, "Transive SELECT APP ANS");
  287. tx_len = emv_select_app_ans(tx_buff);
  288. err = api_hal_nfc_data_exchange(tx_buff, tx_len, &rx_buff, &rx_len, false);
  289. if(err == ERR_NONE) {
  290. FURI_LOG_I(NFC_WORKER_TAG, "Received PDOL");
  291. } else {
  292. FURI_LOG_E(NFC_WORKER_TAG, "Error in 3rd data exchange: receive PDOL");
  293. api_hal_nfc_deactivate();
  294. continue;
  295. }
  296. FURI_LOG_I(NFC_WORKER_TAG, "Transive PDOL ANS");
  297. tx_len = emv_get_proc_opt_ans(tx_buff);
  298. err = api_hal_nfc_data_exchange(tx_buff, tx_len, &rx_buff, &rx_len, false);
  299. if(err == ERR_NONE) {
  300. FURI_LOG_I(NFC_WORKER_TAG, "Received PDOL");
  301. }
  302. api_hal_nfc_deactivate();
  303. } else {
  304. FURI_LOG_W(NFC_WORKER_TAG, "Can't find reader");
  305. }
  306. osDelay(20);
  307. }
  308. }
  309. void nfc_worker_read_mf_ultralight(NfcWorker* nfc_worker) {
  310. ReturnCode err;
  311. rfalNfcDevice* dev_list;
  312. uint8_t dev_cnt = 0;
  313. uint8_t tx_buff[255] = {};
  314. uint16_t tx_len = 0;
  315. uint8_t* rx_buff;
  316. uint16_t* rx_len;
  317. MfUltralightRead mf_ul_read;
  318. // Update screen before start searching
  319. NfcMessage message = {.found = false};
  320. while(nfc_worker->state == NfcWorkerStateReadMfUltralight) {
  321. if(nfc_worker->callback) {
  322. nfc_worker->callback(nfc_worker->context);
  323. }
  324. furi_check(
  325. osMessageQueuePut(nfc_worker->message_queue, &message, 0, osWaitForever) == osOK);
  326. api_hal_nfc_deactivate();
  327. memset(&mf_ul_read, 0, sizeof(mf_ul_read));
  328. if(api_hal_nfc_detect(&dev_list, &dev_cnt, 1000, false)) {
  329. if(dev_list[0].type == RFAL_NFC_LISTEN_TYPE_NFCA &&
  330. mf_ul_check_card_type(
  331. dev_list[0].dev.nfca.sensRes.anticollisionInfo,
  332. dev_list[0].dev.nfca.sensRes.platformInfo,
  333. dev_list[0].dev.nfca.selRes.sak)) {
  334. // Get Mifare Ultralight version
  335. FURI_LOG_I(
  336. NFC_WORKER_TAG, "Found Mifare Ultralight tag. Trying to get tag version");
  337. tx_len = mf_ul_prepare_get_version(tx_buff);
  338. err = api_hal_nfc_data_exchange(tx_buff, tx_len, &rx_buff, &rx_len, false);
  339. if(err == ERR_NONE) {
  340. mf_ul_parse_get_version_response(rx_buff, &mf_ul_read);
  341. FURI_LOG_I(
  342. NFC_WORKER_TAG,
  343. "Mifare Ultralight Type: %d, Pages: %d",
  344. mf_ul_read.type,
  345. mf_ul_read.pages_to_read);
  346. } else if(err == ERR_TIMEOUT) {
  347. FURI_LOG_W(
  348. NFC_WORKER_TAG,
  349. "Card doesn't respond to GET VERSION command. Reinit card and set default read parameters");
  350. err = ERR_NONE;
  351. mf_ul_set_default_version(&mf_ul_read);
  352. // Reinit device
  353. api_hal_nfc_deactivate();
  354. if(!api_hal_nfc_detect(&dev_list, &dev_cnt, 1000, false)) {
  355. FURI_LOG_E(NFC_WORKER_TAG, "Lost connection. Restarting search");
  356. message.found = false;
  357. continue;
  358. }
  359. } else {
  360. FURI_LOG_E(
  361. NFC_WORKER_TAG,
  362. "Error getting Mifare Ultralight version. Error code: %d",
  363. err);
  364. message.found = false;
  365. continue;
  366. }
  367. // Dump Mifare Ultralight card
  368. FURI_LOG_I(NFC_WORKER_TAG, "Trying to read pages");
  369. if(mf_ul_read.support_fast_read) {
  370. // Read card with FAST_READ command
  371. tx_len = mf_ul_prepare_fast_read(tx_buff, 0x00, mf_ul_read.pages_to_read - 1);
  372. err = api_hal_nfc_data_exchange(tx_buff, tx_len, &rx_buff, &rx_len, false);
  373. if(err == ERR_NONE) {
  374. FURI_LOG_I(
  375. NFC_WORKER_TAG,
  376. "Fast read pages %d - %d succeed",
  377. 0,
  378. mf_ul_read.pages_to_read - 1);
  379. memcpy(mf_ul_read.dump, rx_buff, mf_ul_read.pages_to_read * 4);
  380. mf_ul_read.pages_readed = mf_ul_read.pages_to_read;
  381. } else {
  382. FURI_LOG_E(NFC_WORKER_TAG, "Fast read failed");
  383. message.found = false;
  384. continue;
  385. }
  386. } else {
  387. // READ card with READ command (4 pages at a time)
  388. for(uint8_t page = 0; page < mf_ul_read.pages_to_read; page += 4) {
  389. tx_len = mf_ul_prepare_read(tx_buff, page);
  390. err = api_hal_nfc_data_exchange(tx_buff, tx_len, &rx_buff, &rx_len, false);
  391. if(err == ERR_NONE) {
  392. FURI_LOG_I(
  393. NFC_WORKER_TAG, "Read pages %d - %d succeed", page, page + 3);
  394. memcpy(&mf_ul_read.dump[page * 4], rx_buff, 4 * 4);
  395. mf_ul_read.pages_readed += 4;
  396. } else {
  397. FURI_LOG_W(
  398. NFC_WORKER_TAG, "Read pages %d - %d failed", page, page + 3);
  399. }
  400. }
  401. }
  402. // Fill message for nfc application
  403. message.found = true;
  404. message.nfc_mifare_ul_data.nfc_data.uid_len = dev_list[0].dev.nfca.nfcId1Len;
  405. message.nfc_mifare_ul_data.nfc_data.atqa[0] =
  406. dev_list[0].dev.nfca.sensRes.anticollisionInfo;
  407. message.nfc_mifare_ul_data.nfc_data.atqa[1] =
  408. dev_list[0].dev.nfca.sensRes.platformInfo;
  409. message.nfc_mifare_ul_data.nfc_data.sak = dev_list[0].dev.nfca.selRes.sak;
  410. memcpy(
  411. message.nfc_mifare_ul_data.nfc_data.uid,
  412. dev_list[0].dev.nfca.nfcId1,
  413. message.nfc_mifare_ul_data.nfc_data.uid_len);
  414. memcpy(message.nfc_mifare_ul_data.man_block, mf_ul_read.dump, 4 * 3);
  415. memcpy(message.nfc_mifare_ul_data.otp, &mf_ul_read.dump[4 * 3], 4);
  416. for(uint8_t i = 0; i < mf_ul_read.pages_readed * 4; i += 4) {
  417. printf("Page %2d: ", i / 4);
  418. for(uint8_t j = 0; j < 4; j++) {
  419. printf("%02X ", mf_ul_read.dump[i + j]);
  420. }
  421. printf("\r\n");
  422. }
  423. } else {
  424. message.found = false;
  425. FURI_LOG_W(NFC_WORKER_TAG, "Tag does not support Mifare Ultralight");
  426. }
  427. } else {
  428. message.found = false;
  429. FURI_LOG_W(NFC_WORKER_TAG, "Can't find any tags");
  430. }
  431. osDelay(100);
  432. }
  433. }
  434. void nfc_worker_field(NfcWorker* nfc_worker) {
  435. api_hal_nfc_field_on();
  436. while(nfc_worker->state == NfcWorkerStateField) {
  437. osDelay(50);
  438. }
  439. api_hal_nfc_field_off();
  440. }