nfc_worker.c 29 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709
  1. #include "nfc_worker_i.h"
  2. #include <furi_hal.h>
  3. #include <lib/nfc_protocols/nfc_util.h>
  4. #include <lib/nfc_protocols/emv.h>
  5. #include <lib/nfc_protocols/mifare_common.h>
  6. #include <lib/nfc_protocols/mifare_ultralight.h>
  7. #include <lib/nfc_protocols/mifare_classic.h>
  8. #include <lib/nfc_protocols/mifare_desfire.h>
  9. #include <lib/nfc_protocols/nfca.h>
  10. #include "helpers/nfc_mf_classic_dict.h"
  11. #include "helpers/nfc_debug_pcap.h"
  12. #define TAG "NfcWorker"
  13. /***************************** NFC Worker API *******************************/
  14. NfcWorker* nfc_worker_alloc() {
  15. NfcWorker* nfc_worker = malloc(sizeof(NfcWorker));
  16. // Worker thread attributes
  17. nfc_worker->thread = furi_thread_alloc();
  18. furi_thread_set_name(nfc_worker->thread, "NfcWorker");
  19. furi_thread_set_stack_size(nfc_worker->thread, 8192);
  20. furi_thread_set_callback(nfc_worker->thread, nfc_worker_task);
  21. furi_thread_set_context(nfc_worker->thread, nfc_worker);
  22. nfc_worker->callback = NULL;
  23. nfc_worker->context = NULL;
  24. nfc_worker->storage = furi_record_open("storage");
  25. // Initialize rfal
  26. while(furi_hal_nfc_is_busy()) {
  27. osDelay(10);
  28. }
  29. nfc_worker_change_state(nfc_worker, NfcWorkerStateReady);
  30. return nfc_worker;
  31. }
  32. void nfc_worker_free(NfcWorker* nfc_worker) {
  33. furi_assert(nfc_worker);
  34. furi_thread_free(nfc_worker->thread);
  35. furi_record_close("storage");
  36. free(nfc_worker);
  37. }
  38. NfcWorkerState nfc_worker_get_state(NfcWorker* nfc_worker) {
  39. return nfc_worker->state;
  40. }
  41. void nfc_worker_start(
  42. NfcWorker* nfc_worker,
  43. NfcWorkerState state,
  44. NfcDeviceData* dev_data,
  45. NfcWorkerCallback callback,
  46. void* context) {
  47. furi_assert(nfc_worker);
  48. furi_assert(dev_data);
  49. while(furi_hal_nfc_is_busy()) {
  50. osDelay(10);
  51. }
  52. nfc_worker->callback = callback;
  53. nfc_worker->context = context;
  54. nfc_worker->dev_data = dev_data;
  55. nfc_worker_change_state(nfc_worker, state);
  56. furi_thread_start(nfc_worker->thread);
  57. }
  58. void nfc_worker_stop(NfcWorker* nfc_worker) {
  59. furi_assert(nfc_worker);
  60. if(nfc_worker->state == NfcWorkerStateBroken || nfc_worker->state == NfcWorkerStateReady) {
  61. return;
  62. }
  63. furi_hal_nfc_stop();
  64. nfc_worker_change_state(nfc_worker, NfcWorkerStateStop);
  65. furi_thread_join(nfc_worker->thread);
  66. }
  67. void nfc_worker_change_state(NfcWorker* nfc_worker, NfcWorkerState state) {
  68. nfc_worker->state = state;
  69. }
  70. /***************************** NFC Worker Thread *******************************/
  71. int32_t nfc_worker_task(void* context) {
  72. NfcWorker* nfc_worker = context;
  73. furi_hal_nfc_exit_sleep();
  74. if(nfc_worker->state == NfcWorkerStateDetect) {
  75. nfc_worker_detect(nfc_worker);
  76. } else if(nfc_worker->state == NfcWorkerStateEmulate) {
  77. nfc_worker_emulate(nfc_worker);
  78. } else if(nfc_worker->state == NfcWorkerStateReadEMVApp) {
  79. nfc_worker_read_emv_app(nfc_worker);
  80. } else if(nfc_worker->state == NfcWorkerStateReadEMVData) {
  81. nfc_worker_read_emv(nfc_worker);
  82. } else if(nfc_worker->state == NfcWorkerStateEmulateApdu) {
  83. nfc_worker_emulate_apdu(nfc_worker);
  84. } else if(nfc_worker->state == NfcWorkerStateReadMifareUltralight) {
  85. nfc_worker_read_mifare_ultralight(nfc_worker);
  86. } else if(nfc_worker->state == NfcWorkerStateEmulateMifareUltralight) {
  87. nfc_worker_emulate_mifare_ul(nfc_worker);
  88. } else if(nfc_worker->state == NfcWorkerStateReadMifareClassic) {
  89. nfc_worker_mifare_classic_dict_attack(nfc_worker);
  90. } else if(nfc_worker->state == NfcWorkerStateEmulateMifareClassic) {
  91. nfc_worker_emulate_mifare_classic(nfc_worker);
  92. } else if(nfc_worker->state == NfcWorkerStateReadMifareDesfire) {
  93. nfc_worker_read_mifare_desfire(nfc_worker);
  94. }
  95. furi_hal_nfc_sleep();
  96. nfc_worker_change_state(nfc_worker, NfcWorkerStateReady);
  97. return 0;
  98. }
  99. void nfc_worker_detect(NfcWorker* nfc_worker) {
  100. nfc_device_data_clear(nfc_worker->dev_data);
  101. NfcDeviceData* dev_data = nfc_worker->dev_data;
  102. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  103. while(nfc_worker->state == NfcWorkerStateDetect) {
  104. if(furi_hal_nfc_detect(nfc_data, 1000)) {
  105. // Process first found device
  106. if(nfc_data->type == FuriHalNfcTypeA) {
  107. if(mf_ul_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  108. dev_data->protocol = NfcDeviceProtocolMifareUl;
  109. } else if(mf_classic_check_card_type(
  110. nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  111. dev_data->protocol = NfcDeviceProtocolMifareClassic;
  112. } else if(mf_df_check_card_type(
  113. nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  114. dev_data->protocol = NfcDeviceProtocolMifareDesfire;
  115. } else if(nfc_data->interface == FuriHalNfcInterfaceIsoDep) {
  116. dev_data->protocol = NfcDeviceProtocolEMV;
  117. } else {
  118. dev_data->protocol = NfcDeviceProtocolUnknown;
  119. }
  120. }
  121. // Notify caller and exit
  122. if(nfc_worker->callback) {
  123. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  124. }
  125. break;
  126. }
  127. furi_hal_nfc_sleep();
  128. osDelay(100);
  129. }
  130. }
  131. void nfc_worker_emulate(NfcWorker* nfc_worker) {
  132. FuriHalNfcTxRxContext tx_rx = {};
  133. nfc_debug_pcap_prepare_tx_rx(&tx_rx, nfc_worker->storage, true);
  134. FuriHalNfcDevData* data = &nfc_worker->dev_data->nfc_data;
  135. NfcReaderRequestData* reader_data = &nfc_worker->dev_data->reader_data;
  136. while(nfc_worker->state == NfcWorkerStateEmulate) {
  137. if(furi_hal_nfc_listen(data->uid, data->uid_len, data->atqa, data->sak, true, 100)) {
  138. if(furi_hal_nfc_tx_rx(&tx_rx, 100)) {
  139. reader_data->size = tx_rx.rx_bits / 8;
  140. if(reader_data->size > 0) {
  141. memcpy(reader_data->data, tx_rx.rx_data, reader_data->size);
  142. if(nfc_worker->callback) {
  143. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  144. }
  145. }
  146. } else {
  147. FURI_LOG_E(TAG, "Failed to get reader commands");
  148. }
  149. }
  150. }
  151. }
  152. void nfc_worker_read_emv_app(NfcWorker* nfc_worker) {
  153. FuriHalNfcTxRxContext tx_rx = {};
  154. nfc_debug_pcap_prepare_tx_rx(&tx_rx, nfc_worker->storage, false);
  155. EmvApplication emv_app = {};
  156. NfcDeviceData* result = nfc_worker->dev_data;
  157. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  158. nfc_device_data_clear(result);
  159. while(nfc_worker->state == NfcWorkerStateReadEMVApp) {
  160. if(furi_hal_nfc_detect(nfc_data, 1000)) {
  161. // Card was found. Check that it supports EMV
  162. if(nfc_data->interface == FuriHalNfcInterfaceIsoDep) {
  163. result->protocol = NfcDeviceProtocolEMV;
  164. if(emv_search_application(&tx_rx, &emv_app)) {
  165. // Notify caller and exit
  166. result->emv_data.aid_len = emv_app.aid_len;
  167. memcpy(result->emv_data.aid, emv_app.aid, emv_app.aid_len);
  168. if(nfc_worker->callback) {
  169. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  170. }
  171. }
  172. } else {
  173. FURI_LOG_W(TAG, "Card doesn't support EMV");
  174. }
  175. } else {
  176. FURI_LOG_D(TAG, "Can't find any cards");
  177. }
  178. furi_hal_nfc_sleep();
  179. osDelay(20);
  180. }
  181. }
  182. void nfc_worker_read_emv(NfcWorker* nfc_worker) {
  183. FuriHalNfcTxRxContext tx_rx = {};
  184. nfc_debug_pcap_prepare_tx_rx(&tx_rx, nfc_worker->storage, false);
  185. EmvApplication emv_app = {};
  186. NfcDeviceData* result = nfc_worker->dev_data;
  187. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  188. nfc_device_data_clear(result);
  189. while(nfc_worker->state == NfcWorkerStateReadEMVData) {
  190. if(furi_hal_nfc_detect(nfc_data, 1000)) {
  191. // Card was found. Check that it supports EMV
  192. if(nfc_data->interface == FuriHalNfcInterfaceIsoDep) {
  193. result->protocol = NfcDeviceProtocolEMV;
  194. if(emv_read_bank_card(&tx_rx, &emv_app)) {
  195. result->emv_data.number_len = emv_app.card_number_len;
  196. memcpy(
  197. result->emv_data.number, emv_app.card_number, result->emv_data.number_len);
  198. result->emv_data.aid_len = emv_app.aid_len;
  199. memcpy(result->emv_data.aid, emv_app.aid, emv_app.aid_len);
  200. if(emv_app.name_found) {
  201. memcpy(result->emv_data.name, emv_app.name, sizeof(emv_app.name));
  202. }
  203. if(emv_app.exp_month) {
  204. result->emv_data.exp_mon = emv_app.exp_month;
  205. result->emv_data.exp_year = emv_app.exp_year;
  206. }
  207. if(emv_app.country_code) {
  208. result->emv_data.country_code = emv_app.country_code;
  209. }
  210. if(emv_app.currency_code) {
  211. result->emv_data.currency_code = emv_app.currency_code;
  212. }
  213. // Notify caller and exit
  214. if(nfc_worker->callback) {
  215. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  216. }
  217. break;
  218. }
  219. } else {
  220. FURI_LOG_W(TAG, "Card doesn't support EMV");
  221. }
  222. } else {
  223. FURI_LOG_D(TAG, "Can't find any cards");
  224. }
  225. furi_hal_nfc_sleep();
  226. osDelay(20);
  227. }
  228. }
  229. void nfc_worker_emulate_apdu(NfcWorker* nfc_worker) {
  230. FuriHalNfcTxRxContext tx_rx = {};
  231. nfc_debug_pcap_prepare_tx_rx(&tx_rx, nfc_worker->storage, true);
  232. FuriHalNfcDevData params = {
  233. .uid = {0xCF, 0x72, 0xd4, 0x40},
  234. .uid_len = 4,
  235. .atqa = {0x00, 0x04},
  236. .sak = 0x20,
  237. .type = FuriHalNfcTypeA,
  238. };
  239. while(nfc_worker->state == NfcWorkerStateEmulateApdu) {
  240. if(furi_hal_nfc_listen(params.uid, params.uid_len, params.atqa, params.sak, false, 300)) {
  241. FURI_LOG_D(TAG, "POS terminal detected");
  242. if(emv_card_emulation(&tx_rx)) {
  243. FURI_LOG_D(TAG, "EMV card emulated");
  244. }
  245. } else {
  246. FURI_LOG_D(TAG, "Can't find reader");
  247. }
  248. furi_hal_nfc_sleep();
  249. osDelay(20);
  250. }
  251. }
  252. void nfc_worker_read_mifare_ultralight(NfcWorker* nfc_worker) {
  253. FuriHalNfcTxRxContext tx_rx = {};
  254. nfc_debug_pcap_prepare_tx_rx(&tx_rx, nfc_worker->storage, false);
  255. MfUltralightReader reader = {};
  256. MfUltralightData data = {};
  257. NfcDeviceData* result = nfc_worker->dev_data;
  258. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  259. while(nfc_worker->state == NfcWorkerStateReadMifareUltralight) {
  260. if(furi_hal_nfc_detect(nfc_data, 300)) {
  261. if(nfc_data->type == FuriHalNfcTypeA &&
  262. mf_ul_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  263. FURI_LOG_D(TAG, "Found Mifare Ultralight tag. Start reading");
  264. if(mf_ul_read_card(&tx_rx, &reader, &data)) {
  265. result->protocol = NfcDeviceProtocolMifareUl;
  266. result->mf_ul_data = data;
  267. // Notify caller and exit
  268. if(nfc_worker->callback) {
  269. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  270. }
  271. break;
  272. } else {
  273. FURI_LOG_D(TAG, "Failed reading Mifare Ultralight");
  274. }
  275. } else {
  276. FURI_LOG_W(TAG, "Tag is not Mifare Ultralight");
  277. }
  278. } else {
  279. FURI_LOG_D(TAG, "Can't find any tags");
  280. }
  281. furi_hal_nfc_sleep();
  282. osDelay(100);
  283. }
  284. }
  285. void nfc_worker_emulate_mifare_ul(NfcWorker* nfc_worker) {
  286. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  287. MfUltralightEmulator emulator = {};
  288. mf_ul_prepare_emulation(&emulator, &nfc_worker->dev_data->mf_ul_data);
  289. while(nfc_worker->state == NfcWorkerStateEmulateMifareUltralight) {
  290. emulator.auth_success = false;
  291. if(emulator.data.type >= MfUltralightTypeNTAGI2C1K) {
  292. // Sector index needs to be reset
  293. emulator.curr_sector = 0;
  294. }
  295. furi_hal_nfc_emulate_nfca(
  296. nfc_data->uid,
  297. nfc_data->uid_len,
  298. nfc_data->atqa,
  299. nfc_data->sak,
  300. mf_ul_prepare_emulation_response,
  301. &emulator,
  302. 5000);
  303. // Check if data was modified
  304. if(emulator.data_changed) {
  305. nfc_worker->dev_data->mf_ul_data = emulator.data;
  306. if(nfc_worker->callback) {
  307. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  308. }
  309. emulator.data_changed = false;
  310. }
  311. }
  312. }
  313. void nfc_worker_mifare_classic_dict_attack(NfcWorker* nfc_worker) {
  314. furi_assert(nfc_worker->callback);
  315. FuriHalNfcTxRxContext tx_rx_ctx = {};
  316. nfc_debug_pcap_prepare_tx_rx(&tx_rx_ctx, nfc_worker->storage, false);
  317. MfClassicAuthContext auth_ctx = {};
  318. MfClassicReader reader = {};
  319. uint64_t curr_key = 0;
  320. uint16_t curr_sector = 0;
  321. uint8_t total_sectors = 0;
  322. NfcWorkerEvent event;
  323. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  324. // Open dictionary
  325. nfc_worker->dict_stream = file_stream_alloc(nfc_worker->storage);
  326. if(!nfc_mf_classic_dict_open_file(nfc_worker->dict_stream)) {
  327. event = NfcWorkerEventNoDictFound;
  328. nfc_worker->callback(event, nfc_worker->context);
  329. nfc_mf_classic_dict_close_file(nfc_worker->dict_stream);
  330. stream_free(nfc_worker->dict_stream);
  331. return;
  332. }
  333. // Detect Mifare Classic card
  334. while(nfc_worker->state == NfcWorkerStateReadMifareClassic) {
  335. if(furi_hal_nfc_detect(nfc_data, 300)) {
  336. if(mf_classic_get_type(
  337. nfc_data->uid,
  338. nfc_data->uid_len,
  339. nfc_data->atqa[0],
  340. nfc_data->atqa[1],
  341. nfc_data->sak,
  342. &reader)) {
  343. total_sectors = mf_classic_get_total_sectors_num(&reader);
  344. if(reader.type == MfClassicType1k) {
  345. event = NfcWorkerEventDetectedClassic1k;
  346. } else {
  347. event = NfcWorkerEventDetectedClassic4k;
  348. }
  349. nfc_worker->callback(event, nfc_worker->context);
  350. break;
  351. }
  352. } else {
  353. event = NfcWorkerEventNoCardDetected;
  354. nfc_worker->callback(event, nfc_worker->context);
  355. }
  356. }
  357. if(nfc_worker->state == NfcWorkerStateReadMifareClassic) {
  358. bool card_removed_notified = false;
  359. bool card_found_notified = false;
  360. // Seek for mifare classic keys
  361. for(curr_sector = 0; curr_sector < total_sectors; curr_sector++) {
  362. FURI_LOG_I(TAG, "Sector: %d ...", curr_sector);
  363. event = NfcWorkerEventNewSector;
  364. nfc_worker->callback(event, nfc_worker->context);
  365. mf_classic_auth_init_context(&auth_ctx, reader.cuid, curr_sector);
  366. bool sector_key_found = false;
  367. while(nfc_mf_classic_dict_get_next_key(nfc_worker->dict_stream, &curr_key)) {
  368. furi_hal_nfc_sleep();
  369. if(furi_hal_nfc_activate_nfca(300, &reader.cuid)) {
  370. if(!card_found_notified) {
  371. if(reader.type == MfClassicType1k) {
  372. event = NfcWorkerEventDetectedClassic1k;
  373. } else {
  374. event = NfcWorkerEventDetectedClassic4k;
  375. }
  376. nfc_worker->callback(event, nfc_worker->context);
  377. card_found_notified = true;
  378. card_removed_notified = false;
  379. }
  380. FURI_LOG_D(
  381. TAG,
  382. "Try to auth to sector %d with key %04lx%08lx",
  383. curr_sector,
  384. (uint32_t)(curr_key >> 32),
  385. (uint32_t)curr_key);
  386. if(mf_classic_auth_attempt(&tx_rx_ctx, &auth_ctx, curr_key)) {
  387. sector_key_found = true;
  388. if((auth_ctx.key_a != MF_CLASSIC_NO_KEY) &&
  389. (auth_ctx.key_b != MF_CLASSIC_NO_KEY))
  390. break;
  391. }
  392. } else {
  393. // Notify that no tag is availalble
  394. FURI_LOG_D(TAG, "Can't find tags");
  395. if(!card_removed_notified) {
  396. event = NfcWorkerEventNoCardDetected;
  397. nfc_worker->callback(event, nfc_worker->context);
  398. card_removed_notified = true;
  399. card_found_notified = false;
  400. }
  401. }
  402. if(nfc_worker->state != NfcWorkerStateReadMifareClassic) break;
  403. osDelay(1);
  404. }
  405. if(nfc_worker->state != NfcWorkerStateReadMifareClassic) break;
  406. if(sector_key_found) {
  407. // Notify that keys were found
  408. if(auth_ctx.key_a != MF_CLASSIC_NO_KEY) {
  409. FURI_LOG_I(
  410. TAG,
  411. "Sector %d key A: %04lx%08lx",
  412. curr_sector,
  413. (uint32_t)(auth_ctx.key_a >> 32),
  414. (uint32_t)auth_ctx.key_a);
  415. event = NfcWorkerEventFoundKeyA;
  416. nfc_worker->callback(event, nfc_worker->context);
  417. }
  418. if(auth_ctx.key_b != MF_CLASSIC_NO_KEY) {
  419. FURI_LOG_I(
  420. TAG,
  421. "Sector %d key B: %04lx%08lx",
  422. curr_sector,
  423. (uint32_t)(auth_ctx.key_b >> 32),
  424. (uint32_t)auth_ctx.key_b);
  425. event = NfcWorkerEventFoundKeyB;
  426. nfc_worker->callback(event, nfc_worker->context);
  427. }
  428. // Add sectors to read sequence
  429. mf_classic_reader_add_sector(&reader, curr_sector, auth_ctx.key_a, auth_ctx.key_b);
  430. }
  431. nfc_mf_classic_dict_reset(nfc_worker->dict_stream);
  432. }
  433. }
  434. if(nfc_worker->state == NfcWorkerStateReadMifareClassic) {
  435. FURI_LOG_I(TAG, "Found keys to %d sectors. Start reading sectors", reader.sectors_to_read);
  436. uint8_t sectors_read =
  437. mf_classic_read_card(&tx_rx_ctx, &reader, &nfc_worker->dev_data->mf_classic_data);
  438. if(sectors_read) {
  439. event = NfcWorkerEventSuccess;
  440. nfc_worker->dev_data->protocol = NfcDeviceProtocolMifareClassic;
  441. FURI_LOG_I(TAG, "Successfully read %d sectors", sectors_read);
  442. } else {
  443. event = NfcWorkerEventFail;
  444. FURI_LOG_W(TAG, "Failed to read any sector");
  445. }
  446. nfc_worker->callback(event, nfc_worker->context);
  447. }
  448. nfc_mf_classic_dict_close_file(nfc_worker->dict_stream);
  449. stream_free(nfc_worker->dict_stream);
  450. }
  451. void nfc_worker_emulate_mifare_classic(NfcWorker* nfc_worker) {
  452. FuriHalNfcTxRxContext tx_rx = {};
  453. nfc_debug_pcap_prepare_tx_rx(&tx_rx, nfc_worker->storage, true);
  454. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  455. MfClassicEmulator emulator = {
  456. .cuid = nfc_util_bytes2num(&nfc_data->uid[nfc_data->uid_len - 4], 4),
  457. .data = nfc_worker->dev_data->mf_classic_data,
  458. .data_changed = false,
  459. };
  460. NfcaSignal* nfca_signal = nfca_signal_alloc();
  461. tx_rx.nfca_signal = nfca_signal;
  462. while(nfc_worker->state == NfcWorkerStateEmulateMifareClassic) {
  463. if(furi_hal_nfc_listen(
  464. nfc_data->uid, nfc_data->uid_len, nfc_data->atqa, nfc_data->sak, true, 300)) {
  465. mf_classic_emulator(&emulator, &tx_rx);
  466. }
  467. }
  468. if(emulator.data_changed) {
  469. nfc_worker->dev_data->mf_classic_data = emulator.data;
  470. if(nfc_worker->callback) {
  471. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  472. }
  473. emulator.data_changed = false;
  474. }
  475. nfca_signal_free(nfca_signal);
  476. }
  477. void nfc_worker_read_mifare_desfire(NfcWorker* nfc_worker) {
  478. FuriHalNfcTxRxContext tx_rx = {};
  479. nfc_debug_pcap_prepare_tx_rx(&tx_rx, nfc_worker->storage, false);
  480. NfcDeviceData* result = nfc_worker->dev_data;
  481. nfc_device_data_clear(result);
  482. MifareDesfireData* data = &result->mf_df_data;
  483. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  484. while(nfc_worker->state == NfcWorkerStateReadMifareDesfire) {
  485. furi_hal_nfc_sleep();
  486. if(!furi_hal_nfc_detect(nfc_data, 300)) {
  487. osDelay(100);
  488. continue;
  489. }
  490. memset(data, 0, sizeof(MifareDesfireData));
  491. if(nfc_data->type != FuriHalNfcTypeA ||
  492. !mf_df_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  493. FURI_LOG_D(TAG, "Tag is not DESFire");
  494. osDelay(100);
  495. continue;
  496. }
  497. FURI_LOG_D(TAG, "Found DESFire tag");
  498. result->protocol = NfcDeviceProtocolMifareDesfire;
  499. // Get DESFire version
  500. tx_rx.tx_bits = 8 * mf_df_prepare_get_version(tx_rx.tx_data);
  501. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  502. FURI_LOG_W(TAG, "Bad exchange getting version");
  503. continue;
  504. }
  505. if(!mf_df_parse_get_version_response(tx_rx.rx_data, tx_rx.rx_bits / 8, &data->version)) {
  506. FURI_LOG_W(TAG, "Bad DESFire GET_VERSION response");
  507. continue;
  508. }
  509. tx_rx.tx_bits = 8 * mf_df_prepare_get_free_memory(tx_rx.tx_data);
  510. if(furi_hal_nfc_tx_rx_full(&tx_rx)) {
  511. data->free_memory = malloc(sizeof(MifareDesfireFreeMemory));
  512. memset(data->free_memory, 0, sizeof(MifareDesfireFreeMemory));
  513. if(!mf_df_parse_get_free_memory_response(
  514. tx_rx.rx_data, tx_rx.rx_bits / 8, data->free_memory)) {
  515. FURI_LOG_D(TAG, "Bad DESFire GET_FREE_MEMORY response (normal for pre-EV1 cards)");
  516. free(data->free_memory);
  517. data->free_memory = NULL;
  518. }
  519. }
  520. tx_rx.tx_bits = 8 * mf_df_prepare_get_key_settings(tx_rx.tx_data);
  521. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  522. FURI_LOG_D(TAG, "Bad exchange getting key settings");
  523. } else {
  524. data->master_key_settings = malloc(sizeof(MifareDesfireKeySettings));
  525. memset(data->master_key_settings, 0, sizeof(MifareDesfireKeySettings));
  526. if(!mf_df_parse_get_key_settings_response(
  527. tx_rx.rx_data, tx_rx.rx_bits / 8, data->master_key_settings)) {
  528. FURI_LOG_W(TAG, "Bad DESFire GET_KEY_SETTINGS response");
  529. free(data->master_key_settings);
  530. data->master_key_settings = NULL;
  531. continue;
  532. }
  533. MifareDesfireKeyVersion** key_version_head =
  534. &data->master_key_settings->key_version_head;
  535. for(uint8_t key_id = 0; key_id < data->master_key_settings->max_keys; key_id++) {
  536. tx_rx.tx_bits = 8 * mf_df_prepare_get_key_version(tx_rx.tx_data, key_id);
  537. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  538. FURI_LOG_W(TAG, "Bad exchange getting key version");
  539. continue;
  540. }
  541. MifareDesfireKeyVersion* key_version = malloc(sizeof(MifareDesfireKeyVersion));
  542. memset(key_version, 0, sizeof(MifareDesfireKeyVersion));
  543. key_version->id = key_id;
  544. if(!mf_df_parse_get_key_version_response(
  545. tx_rx.rx_data, tx_rx.rx_bits / 8, key_version)) {
  546. FURI_LOG_W(TAG, "Bad DESFire GET_KEY_VERSION response");
  547. free(key_version);
  548. continue;
  549. }
  550. *key_version_head = key_version;
  551. key_version_head = &key_version->next;
  552. }
  553. }
  554. tx_rx.tx_bits = 8 * mf_df_prepare_get_application_ids(tx_rx.tx_data);
  555. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  556. FURI_LOG_W(TAG, "Bad exchange getting application IDs");
  557. } else {
  558. if(!mf_df_parse_get_application_ids_response(
  559. tx_rx.rx_data, tx_rx.rx_bits / 8, &data->app_head)) {
  560. FURI_LOG_W(TAG, "Bad DESFire GET_APPLICATION_IDS response");
  561. }
  562. }
  563. for(MifareDesfireApplication* app = data->app_head; app; app = app->next) {
  564. tx_rx.tx_bits = 8 * mf_df_prepare_select_application(tx_rx.tx_data, app->id);
  565. if(!furi_hal_nfc_tx_rx_full(&tx_rx) ||
  566. !mf_df_parse_select_application_response(tx_rx.rx_data, tx_rx.rx_bits / 8)) {
  567. FURI_LOG_W(TAG, "Bad exchange selecting application");
  568. continue;
  569. }
  570. tx_rx.tx_bits = 8 * mf_df_prepare_get_key_settings(tx_rx.tx_data);
  571. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  572. FURI_LOG_W(TAG, "Bad exchange getting key settings");
  573. } else {
  574. app->key_settings = malloc(sizeof(MifareDesfireKeySettings));
  575. memset(app->key_settings, 0, sizeof(MifareDesfireKeySettings));
  576. if(!mf_df_parse_get_key_settings_response(
  577. tx_rx.rx_data, tx_rx.rx_bits / 8, app->key_settings)) {
  578. FURI_LOG_W(TAG, "Bad DESFire GET_KEY_SETTINGS response");
  579. free(app->key_settings);
  580. app->key_settings = NULL;
  581. continue;
  582. }
  583. MifareDesfireKeyVersion** key_version_head = &app->key_settings->key_version_head;
  584. for(uint8_t key_id = 0; key_id < app->key_settings->max_keys; key_id++) {
  585. tx_rx.tx_bits = 8 * mf_df_prepare_get_key_version(tx_rx.tx_data, key_id);
  586. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  587. FURI_LOG_W(TAG, "Bad exchange getting key version");
  588. continue;
  589. }
  590. MifareDesfireKeyVersion* key_version = malloc(sizeof(MifareDesfireKeyVersion));
  591. memset(key_version, 0, sizeof(MifareDesfireKeyVersion));
  592. key_version->id = key_id;
  593. if(!mf_df_parse_get_key_version_response(
  594. tx_rx.rx_data, tx_rx.rx_bits / 8, key_version)) {
  595. FURI_LOG_W(TAG, "Bad DESFire GET_KEY_VERSION response");
  596. free(key_version);
  597. continue;
  598. }
  599. *key_version_head = key_version;
  600. key_version_head = &key_version->next;
  601. }
  602. }
  603. tx_rx.tx_bits = 8 * mf_df_prepare_get_file_ids(tx_rx.tx_data);
  604. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  605. FURI_LOG_W(TAG, "Bad exchange getting file IDs");
  606. } else {
  607. if(!mf_df_parse_get_file_ids_response(
  608. tx_rx.rx_data, tx_rx.rx_bits / 8, &app->file_head)) {
  609. FURI_LOG_W(TAG, "Bad DESFire GET_FILE_IDS response");
  610. }
  611. }
  612. for(MifareDesfireFile* file = app->file_head; file; file = file->next) {
  613. tx_rx.tx_bits = 8 * mf_df_prepare_get_file_settings(tx_rx.tx_data, file->id);
  614. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  615. FURI_LOG_W(TAG, "Bad exchange getting file settings");
  616. continue;
  617. }
  618. if(!mf_df_parse_get_file_settings_response(
  619. tx_rx.rx_data, tx_rx.rx_bits / 8, file)) {
  620. FURI_LOG_W(TAG, "Bad DESFire GET_FILE_SETTINGS response");
  621. continue;
  622. }
  623. switch(file->type) {
  624. case MifareDesfireFileTypeStandard:
  625. case MifareDesfireFileTypeBackup:
  626. tx_rx.tx_bits = 8 * mf_df_prepare_read_data(tx_rx.tx_data, file->id, 0, 0);
  627. break;
  628. case MifareDesfireFileTypeValue:
  629. tx_rx.tx_bits = 8 * mf_df_prepare_get_value(tx_rx.tx_data, file->id);
  630. break;
  631. case MifareDesfireFileTypeLinearRecord:
  632. case MifareDesfireFileTypeCyclicRecord:
  633. tx_rx.tx_bits = 8 * mf_df_prepare_read_records(tx_rx.tx_data, file->id, 0, 0);
  634. break;
  635. }
  636. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  637. FURI_LOG_W(TAG, "Bad exchange reading file %d", file->id);
  638. continue;
  639. }
  640. if(!mf_df_parse_read_data_response(tx_rx.rx_data, tx_rx.rx_bits / 8, file)) {
  641. FURI_LOG_W(TAG, "Bad response reading file %d", file->id);
  642. continue;
  643. }
  644. }
  645. }
  646. // Notify caller and exit
  647. if(nfc_worker->callback) {
  648. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  649. }
  650. break;
  651. }
  652. }