nfc_worker.c 23 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580
  1. #include "nfc_worker_i.h"
  2. #include <furi_hal.h>
  3. #include <platform.h>
  4. #include "parsers/nfc_supported_card.h"
  5. #define TAG "NfcWorker"
  6. /***************************** NFC Worker API *******************************/
  7. NfcWorker* nfc_worker_alloc() {
  8. NfcWorker* nfc_worker = malloc(sizeof(NfcWorker));
  9. // Worker thread attributes
  10. nfc_worker->thread = furi_thread_alloc();
  11. furi_thread_set_name(nfc_worker->thread, "NfcWorker");
  12. furi_thread_set_stack_size(nfc_worker->thread, 8192);
  13. furi_thread_set_callback(nfc_worker->thread, nfc_worker_task);
  14. furi_thread_set_context(nfc_worker->thread, nfc_worker);
  15. nfc_worker->callback = NULL;
  16. nfc_worker->context = NULL;
  17. nfc_worker->storage = furi_record_open(RECORD_STORAGE);
  18. // Initialize rfal
  19. while(furi_hal_nfc_is_busy()) {
  20. furi_delay_ms(10);
  21. }
  22. nfc_worker_change_state(nfc_worker, NfcWorkerStateReady);
  23. if(furi_hal_rtc_is_flag_set(FuriHalRtcFlagDebug)) {
  24. nfc_worker->debug_pcap_worker = nfc_debug_pcap_alloc(nfc_worker->storage);
  25. }
  26. return nfc_worker;
  27. }
  28. void nfc_worker_free(NfcWorker* nfc_worker) {
  29. furi_assert(nfc_worker);
  30. furi_thread_free(nfc_worker->thread);
  31. furi_record_close(RECORD_STORAGE);
  32. if(nfc_worker->debug_pcap_worker) nfc_debug_pcap_free(nfc_worker->debug_pcap_worker);
  33. free(nfc_worker);
  34. }
  35. NfcWorkerState nfc_worker_get_state(NfcWorker* nfc_worker) {
  36. return nfc_worker->state;
  37. }
  38. void nfc_worker_start(
  39. NfcWorker* nfc_worker,
  40. NfcWorkerState state,
  41. NfcDeviceData* dev_data,
  42. NfcWorkerCallback callback,
  43. void* context) {
  44. furi_assert(nfc_worker);
  45. furi_assert(dev_data);
  46. while(furi_hal_nfc_is_busy()) {
  47. furi_delay_ms(10);
  48. }
  49. nfc_worker->callback = callback;
  50. nfc_worker->context = context;
  51. nfc_worker->dev_data = dev_data;
  52. nfc_worker_change_state(nfc_worker, state);
  53. furi_thread_start(nfc_worker->thread);
  54. }
  55. void nfc_worker_stop(NfcWorker* nfc_worker) {
  56. furi_assert(nfc_worker);
  57. if(nfc_worker->state == NfcWorkerStateBroken || nfc_worker->state == NfcWorkerStateReady) {
  58. return;
  59. }
  60. furi_hal_nfc_stop();
  61. nfc_worker_change_state(nfc_worker, NfcWorkerStateStop);
  62. furi_thread_join(nfc_worker->thread);
  63. }
  64. void nfc_worker_change_state(NfcWorker* nfc_worker, NfcWorkerState state) {
  65. nfc_worker->state = state;
  66. }
  67. /***************************** NFC Worker Thread *******************************/
  68. int32_t nfc_worker_task(void* context) {
  69. NfcWorker* nfc_worker = context;
  70. furi_hal_nfc_exit_sleep();
  71. if(nfc_worker->state == NfcWorkerStateRead) {
  72. nfc_worker_read(nfc_worker);
  73. } else if(nfc_worker->state == NfcWorkerStateUidEmulate) {
  74. nfc_worker_emulate_uid(nfc_worker);
  75. } else if(nfc_worker->state == NfcWorkerStateEmulateApdu) {
  76. nfc_worker_emulate_apdu(nfc_worker);
  77. } else if(nfc_worker->state == NfcWorkerStateMfUltralightEmulate) {
  78. nfc_worker_emulate_mf_ultralight(nfc_worker);
  79. } else if(nfc_worker->state == NfcWorkerStateMfClassicEmulate) {
  80. nfc_worker_emulate_mf_classic(nfc_worker);
  81. } else if(nfc_worker->state == NfcWorkerStateReadMfUltralightReadAuth) {
  82. nfc_worker_mf_ultralight_read_auth(nfc_worker);
  83. } else if(nfc_worker->state == NfcWorkerStateMfClassicDictAttack) {
  84. nfc_worker_mf_classic_dict_attack(nfc_worker);
  85. }
  86. furi_hal_nfc_sleep();
  87. nfc_worker_change_state(nfc_worker, NfcWorkerStateReady);
  88. return 0;
  89. }
  90. static bool nfc_worker_read_mf_ultralight(NfcWorker* nfc_worker, FuriHalNfcTxRxContext* tx_rx) {
  91. bool read_success = false;
  92. MfUltralightReader reader = {};
  93. MfUltralightData data = {};
  94. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, tx_rx, false);
  95. do {
  96. // Read card
  97. if(!furi_hal_nfc_detect(&nfc_worker->dev_data->nfc_data, 200)) break;
  98. if(!mf_ul_read_card(tx_rx, &reader, &data)) break;
  99. // Copy data
  100. nfc_worker->dev_data->mf_ul_data = data;
  101. read_success = true;
  102. } while(false);
  103. return read_success;
  104. }
  105. static bool nfc_worker_read_mf_classic(NfcWorker* nfc_worker, FuriHalNfcTxRxContext* tx_rx) {
  106. furi_assert(nfc_worker->callback);
  107. bool read_success = false;
  108. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, tx_rx, false);
  109. do {
  110. // Try to read supported card
  111. FURI_LOG_I(TAG, "Try read supported card ...");
  112. for(size_t i = 0; i < NfcSupportedCardTypeEnd; i++) {
  113. if(nfc_supported_card[i].protocol == NfcDeviceProtocolMifareClassic) {
  114. if(nfc_supported_card[i].verify(nfc_worker, tx_rx)) {
  115. if(nfc_supported_card[i].read(nfc_worker, tx_rx)) {
  116. read_success = true;
  117. nfc_supported_card[i].parse(nfc_worker->dev_data);
  118. }
  119. }
  120. }
  121. }
  122. if(read_success) break;
  123. // Try to read card with key cache
  124. FURI_LOG_I(TAG, "Search for key cache ...");
  125. if(nfc_worker->callback(NfcWorkerEventReadMfClassicLoadKeyCache, nfc_worker->context)) {
  126. FURI_LOG_I(TAG, "Load keys cache success. Start reading");
  127. uint8_t sectors_read =
  128. mf_classic_update_card(tx_rx, &nfc_worker->dev_data->mf_classic_data);
  129. uint8_t sectors_total =
  130. mf_classic_get_total_sectors_num(nfc_worker->dev_data->mf_classic_data.type);
  131. FURI_LOG_I(TAG, "Read %d sectors out of %d total", sectors_read, sectors_total);
  132. read_success = (sectors_read == sectors_total);
  133. }
  134. } while(false);
  135. return read_success;
  136. }
  137. static bool nfc_worker_read_mf_desfire(NfcWorker* nfc_worker, FuriHalNfcTxRxContext* tx_rx) {
  138. bool read_success = false;
  139. MifareDesfireData* data = &nfc_worker->dev_data->mf_df_data;
  140. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, tx_rx, false);
  141. do {
  142. if(!furi_hal_nfc_detect(&nfc_worker->dev_data->nfc_data, 300)) break;
  143. if(!mf_df_read_card(tx_rx, data)) break;
  144. read_success = true;
  145. } while(false);
  146. return read_success;
  147. }
  148. static bool nfc_worker_read_bank_card(NfcWorker* nfc_worker, FuriHalNfcTxRxContext* tx_rx) {
  149. bool read_success = false;
  150. EmvApplication emv_app = {};
  151. EmvData* result = &nfc_worker->dev_data->emv_data;
  152. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, tx_rx, false);
  153. do {
  154. // Read card
  155. if(!furi_hal_nfc_detect(&nfc_worker->dev_data->nfc_data, 300)) break;
  156. if(!emv_read_bank_card(tx_rx, &emv_app)) break;
  157. // Copy data
  158. // TODO Set EmvData to reader or like in mifare ultralight!
  159. result->number_len = emv_app.card_number_len;
  160. memcpy(result->number, emv_app.card_number, result->number_len);
  161. result->aid_len = emv_app.aid_len;
  162. memcpy(result->aid, emv_app.aid, result->aid_len);
  163. if(emv_app.name_found) {
  164. memcpy(result->name, emv_app.name, sizeof(emv_app.name));
  165. }
  166. if(emv_app.exp_month) {
  167. result->exp_mon = emv_app.exp_month;
  168. result->exp_year = emv_app.exp_year;
  169. }
  170. if(emv_app.country_code) {
  171. result->country_code = emv_app.country_code;
  172. }
  173. if(emv_app.currency_code) {
  174. result->currency_code = emv_app.currency_code;
  175. }
  176. read_success = true;
  177. } while(false);
  178. return read_success;
  179. }
  180. static bool nfc_worker_read_nfca(NfcWorker* nfc_worker, FuriHalNfcTxRxContext* tx_rx) {
  181. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  182. bool card_read = false;
  183. furi_hal_nfc_sleep();
  184. if(mf_ul_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  185. FURI_LOG_I(TAG, "Mifare Ultralight / NTAG detected");
  186. nfc_worker->dev_data->protocol = NfcDeviceProtocolMifareUl;
  187. card_read = nfc_worker_read_mf_ultralight(nfc_worker, tx_rx);
  188. } else if(mf_classic_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  189. FURI_LOG_I(TAG, "Mifare Classic detected");
  190. nfc_worker->dev_data->protocol = NfcDeviceProtocolMifareClassic;
  191. nfc_worker->dev_data->mf_classic_data.type =
  192. mf_classic_get_classic_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak);
  193. card_read = nfc_worker_read_mf_classic(nfc_worker, tx_rx);
  194. } else if(mf_df_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  195. FURI_LOG_I(TAG, "Mifare DESFire detected");
  196. nfc_worker->dev_data->protocol = NfcDeviceProtocolMifareDesfire;
  197. if(!nfc_worker_read_mf_desfire(nfc_worker, tx_rx)) {
  198. FURI_LOG_I(TAG, "Unknown card. Save UID");
  199. nfc_worker->dev_data->protocol = NfcDeviceProtocolUnknown;
  200. }
  201. card_read = true;
  202. } else if(nfc_data->interface == FuriHalNfcInterfaceIsoDep) {
  203. FURI_LOG_I(TAG, "ISO14443-4 card detected");
  204. nfc_worker->dev_data->protocol = NfcDeviceProtocolEMV;
  205. if(!nfc_worker_read_bank_card(nfc_worker, tx_rx)) {
  206. FURI_LOG_I(TAG, "Unknown card. Save UID");
  207. nfc_worker->dev_data->protocol = NfcDeviceProtocolUnknown;
  208. }
  209. card_read = true;
  210. } else {
  211. nfc_worker->dev_data->protocol = NfcDeviceProtocolUnknown;
  212. card_read = true;
  213. }
  214. return card_read;
  215. }
  216. void nfc_worker_read(NfcWorker* nfc_worker) {
  217. furi_assert(nfc_worker);
  218. furi_assert(nfc_worker->callback);
  219. nfc_device_data_clear(nfc_worker->dev_data);
  220. NfcDeviceData* dev_data = nfc_worker->dev_data;
  221. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  222. FuriHalNfcTxRxContext tx_rx = {};
  223. NfcWorkerEvent event = 0;
  224. bool card_not_detected_notified = false;
  225. while(nfc_worker->state == NfcWorkerStateRead) {
  226. if(furi_hal_nfc_detect(nfc_data, 300)) {
  227. // Process first found device
  228. nfc_worker->callback(NfcWorkerEventCardDetected, nfc_worker->context);
  229. card_not_detected_notified = false;
  230. if(nfc_data->type == FuriHalNfcTypeA) {
  231. if(nfc_worker_read_nfca(nfc_worker, &tx_rx)) {
  232. if(dev_data->protocol == NfcDeviceProtocolMifareUl) {
  233. event = NfcWorkerEventReadMfUltralight;
  234. break;
  235. } else if(dev_data->protocol == NfcDeviceProtocolMifareClassic) {
  236. event = NfcWorkerEventReadMfClassicDone;
  237. break;
  238. } else if(dev_data->protocol == NfcDeviceProtocolMifareDesfire) {
  239. event = NfcWorkerEventReadMfDesfire;
  240. break;
  241. } else if(dev_data->protocol == NfcDeviceProtocolEMV) {
  242. event = NfcWorkerEventReadBankCard;
  243. break;
  244. } else if(dev_data->protocol == NfcDeviceProtocolUnknown) {
  245. event = NfcWorkerEventReadUidNfcA;
  246. break;
  247. }
  248. } else {
  249. if(dev_data->protocol == NfcDeviceProtocolMifareClassic) {
  250. event = NfcWorkerEventReadMfClassicDictAttackRequired;
  251. break;
  252. }
  253. }
  254. } else if(nfc_data->type == FuriHalNfcTypeB) {
  255. event = NfcWorkerEventReadUidNfcB;
  256. break;
  257. } else if(nfc_data->type == FuriHalNfcTypeF) {
  258. event = NfcWorkerEventReadUidNfcF;
  259. break;
  260. } else if(nfc_data->type == FuriHalNfcTypeV) {
  261. event = NfcWorkerEventReadUidNfcV;
  262. break;
  263. }
  264. } else {
  265. if(!card_not_detected_notified) {
  266. nfc_worker->callback(NfcWorkerEventNoCardDetected, nfc_worker->context);
  267. card_not_detected_notified = true;
  268. }
  269. }
  270. furi_hal_nfc_sleep();
  271. furi_delay_ms(100);
  272. }
  273. // Notify caller and exit
  274. if(event > NfcWorkerEventReserved) {
  275. nfc_worker->callback(event, nfc_worker->context);
  276. }
  277. }
  278. void nfc_worker_emulate_uid(NfcWorker* nfc_worker) {
  279. FuriHalNfcTxRxContext tx_rx = {};
  280. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx, true);
  281. FuriHalNfcDevData* data = &nfc_worker->dev_data->nfc_data;
  282. NfcReaderRequestData* reader_data = &nfc_worker->dev_data->reader_data;
  283. // TODO add support for RATS
  284. // Now remove bit 6 in SAK to support ISO-14443A-3 emulation
  285. // Need to save ATS to support ISO-14443A-4 emulation
  286. uint8_t sak = data->sak;
  287. FURI_BIT_CLEAR(sak, 5);
  288. while(nfc_worker->state == NfcWorkerStateUidEmulate) {
  289. if(furi_hal_nfc_listen(data->uid, data->uid_len, data->atqa, sak, true, 100)) {
  290. if(furi_hal_nfc_tx_rx(&tx_rx, 100)) {
  291. reader_data->size = tx_rx.rx_bits / 8;
  292. if(reader_data->size > 0) {
  293. memcpy(reader_data->data, tx_rx.rx_data, reader_data->size);
  294. if(nfc_worker->callback) {
  295. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  296. }
  297. }
  298. } else {
  299. FURI_LOG_E(TAG, "Failed to get reader commands");
  300. }
  301. }
  302. }
  303. }
  304. void nfc_worker_emulate_apdu(NfcWorker* nfc_worker) {
  305. FuriHalNfcTxRxContext tx_rx = {};
  306. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx, true);
  307. FuriHalNfcDevData params = {
  308. .uid = {0xCF, 0x72, 0xd4, 0x40},
  309. .uid_len = 4,
  310. .atqa = {0x00, 0x04},
  311. .sak = 0x20,
  312. .type = FuriHalNfcTypeA,
  313. };
  314. while(nfc_worker->state == NfcWorkerStateEmulateApdu) {
  315. if(furi_hal_nfc_listen(params.uid, params.uid_len, params.atqa, params.sak, false, 300)) {
  316. FURI_LOG_D(TAG, "POS terminal detected");
  317. if(emv_card_emulation(&tx_rx)) {
  318. FURI_LOG_D(TAG, "EMV card emulated");
  319. }
  320. } else {
  321. FURI_LOG_D(TAG, "Can't find reader");
  322. }
  323. furi_hal_nfc_sleep();
  324. furi_delay_ms(20);
  325. }
  326. }
  327. void nfc_worker_emulate_mf_ultralight(NfcWorker* nfc_worker) {
  328. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  329. MfUltralightEmulator emulator = {};
  330. mf_ul_prepare_emulation(&emulator, &nfc_worker->dev_data->mf_ul_data);
  331. while(nfc_worker->state == NfcWorkerStateMfUltralightEmulate) {
  332. mf_ul_reset_emulation(&emulator, true);
  333. furi_hal_nfc_emulate_nfca(
  334. nfc_data->uid,
  335. nfc_data->uid_len,
  336. nfc_data->atqa,
  337. nfc_data->sak,
  338. mf_ul_prepare_emulation_response,
  339. &emulator,
  340. 5000);
  341. // Check if data was modified
  342. if(emulator.data_changed) {
  343. nfc_worker->dev_data->mf_ul_data = emulator.data;
  344. if(nfc_worker->callback) {
  345. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  346. }
  347. emulator.data_changed = false;
  348. }
  349. }
  350. }
  351. void nfc_worker_mf_classic_dict_attack(NfcWorker* nfc_worker) {
  352. furi_assert(nfc_worker);
  353. furi_assert(nfc_worker->callback);
  354. MfClassicData* data = &nfc_worker->dev_data->mf_classic_data;
  355. NfcMfClassicDictAttackData* dict_attack_data =
  356. &nfc_worker->dev_data->mf_classic_dict_attack_data;
  357. uint32_t total_sectors = mf_classic_get_total_sectors_num(data->type);
  358. uint64_t key = 0;
  359. FuriHalNfcTxRxContext tx_rx = {};
  360. bool card_found_notified = true;
  361. bool card_removed_notified = false;
  362. // Load dictionary
  363. MfClassicDict* dict = dict_attack_data->dict;
  364. if(!dict) {
  365. FURI_LOG_E(TAG, "Dictionary not found");
  366. nfc_worker->callback(NfcWorkerEventNoDictFound, nfc_worker->context);
  367. return;
  368. }
  369. FURI_LOG_D(TAG, "Start Dictionary attack, Key Count %d", mf_classic_dict_get_total_keys(dict));
  370. for(size_t i = 0; i < total_sectors; i++) {
  371. FURI_LOG_I(TAG, "Sector %d", i);
  372. nfc_worker->callback(NfcWorkerEventNewSector, nfc_worker->context);
  373. uint8_t block_num = mf_classic_get_sector_trailer_block_num_by_sector(i);
  374. if(mf_classic_is_sector_read(data, i)) continue;
  375. bool is_key_a_found = mf_classic_is_key_found(data, i, MfClassicKeyA);
  376. bool is_key_b_found = mf_classic_is_key_found(data, i, MfClassicKeyB);
  377. uint16_t key_index = 0;
  378. while(mf_classic_dict_get_next_key(dict, &key)) {
  379. if(++key_index % NFC_DICT_KEY_BATCH_SIZE == 0) {
  380. nfc_worker->callback(NfcWorkerEventNewDictKeyBatch, nfc_worker->context);
  381. }
  382. furi_hal_nfc_sleep();
  383. if(furi_hal_nfc_activate_nfca(200, NULL)) {
  384. furi_hal_nfc_sleep();
  385. if(!card_found_notified) {
  386. nfc_worker->callback(NfcWorkerEventCardDetected, nfc_worker->context);
  387. card_found_notified = true;
  388. card_removed_notified = false;
  389. }
  390. FURI_LOG_D(
  391. TAG,
  392. "Try to auth to sector %d with key %04lx%08lx",
  393. i,
  394. (uint32_t)(key >> 32),
  395. (uint32_t)key);
  396. if(!is_key_a_found) {
  397. is_key_a_found = mf_classic_is_key_found(data, i, MfClassicKeyA);
  398. if(mf_classic_authenticate(&tx_rx, block_num, key, MfClassicKeyA)) {
  399. mf_classic_set_key_found(data, i, MfClassicKeyA, key);
  400. nfc_worker->callback(NfcWorkerEventFoundKeyA, nfc_worker->context);
  401. }
  402. furi_hal_nfc_sleep();
  403. }
  404. if(!is_key_b_found) {
  405. is_key_b_found = mf_classic_is_key_found(data, i, MfClassicKeyB);
  406. if(mf_classic_authenticate(&tx_rx, block_num, key, MfClassicKeyB)) {
  407. mf_classic_set_key_found(data, i, MfClassicKeyB, key);
  408. nfc_worker->callback(NfcWorkerEventFoundKeyB, nfc_worker->context);
  409. }
  410. }
  411. if(is_key_a_found && is_key_b_found) break;
  412. if(nfc_worker->state != NfcWorkerStateMfClassicDictAttack) break;
  413. } else {
  414. if(!card_removed_notified) {
  415. nfc_worker->callback(NfcWorkerEventNoCardDetected, nfc_worker->context);
  416. card_removed_notified = true;
  417. card_found_notified = false;
  418. }
  419. if(nfc_worker->state != NfcWorkerStateMfClassicDictAttack) break;
  420. }
  421. }
  422. if(nfc_worker->state != NfcWorkerStateMfClassicDictAttack) break;
  423. mf_classic_read_sector(&tx_rx, data, i);
  424. mf_classic_dict_rewind(dict);
  425. }
  426. if(nfc_worker->state == NfcWorkerStateMfClassicDictAttack) {
  427. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  428. } else {
  429. nfc_worker->callback(NfcWorkerEventAborted, nfc_worker->context);
  430. }
  431. }
  432. void nfc_worker_emulate_mf_classic(NfcWorker* nfc_worker) {
  433. FuriHalNfcTxRxContext tx_rx = {};
  434. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx, true);
  435. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  436. MfClassicEmulator emulator = {
  437. .cuid = nfc_util_bytes2num(&nfc_data->uid[nfc_data->uid_len - 4], 4),
  438. .data = nfc_worker->dev_data->mf_classic_data,
  439. .data_changed = false,
  440. };
  441. NfcaSignal* nfca_signal = nfca_signal_alloc();
  442. tx_rx.nfca_signal = nfca_signal;
  443. rfal_platform_spi_acquire();
  444. furi_hal_nfc_listen_start(nfc_data);
  445. while(nfc_worker->state == NfcWorkerStateMfClassicEmulate) {
  446. if(furi_hal_nfc_listen_rx(&tx_rx, 300)) {
  447. mf_classic_emulator(&emulator, &tx_rx);
  448. }
  449. }
  450. if(emulator.data_changed) {
  451. nfc_worker->dev_data->mf_classic_data = emulator.data;
  452. if(nfc_worker->callback) {
  453. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  454. }
  455. emulator.data_changed = false;
  456. }
  457. nfca_signal_free(nfca_signal);
  458. rfal_platform_spi_release();
  459. }
  460. void nfc_worker_mf_ultralight_read_auth(NfcWorker* nfc_worker) {
  461. furi_assert(nfc_worker);
  462. furi_assert(nfc_worker->callback);
  463. MfUltralightData* data = &nfc_worker->dev_data->mf_ul_data;
  464. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  465. FuriHalNfcTxRxContext tx_rx = {};
  466. MfUltralightReader reader = {};
  467. mf_ul_reset(data);
  468. uint32_t key = 0;
  469. uint16_t pack = 0;
  470. while(nfc_worker->state == NfcWorkerStateReadMfUltralightReadAuth) {
  471. furi_hal_nfc_sleep();
  472. if(furi_hal_nfc_detect(nfc_data, 300) && nfc_data->type == FuriHalNfcTypeA) {
  473. if(mf_ul_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  474. nfc_worker->callback(NfcWorkerEventCardDetected, nfc_worker->context);
  475. if(data->auth_method == MfUltralightAuthMethodManual) {
  476. nfc_worker->callback(NfcWorkerEventMfUltralightPassKey, nfc_worker->context);
  477. key = nfc_util_bytes2num(data->auth_key, 4);
  478. } else if(data->auth_method == MfUltralightAuthMethodAmeebo) {
  479. key = mf_ul_pwdgen_amiibo(nfc_data);
  480. } else if(data->auth_method == MfUltralightAuthMethodXiaomi) {
  481. key = mf_ul_pwdgen_xiaomi(nfc_data);
  482. } else {
  483. FURI_LOG_E(TAG, "Incorrect auth method");
  484. break;
  485. }
  486. data->auth_success = mf_ultralight_authenticate(&tx_rx, key, &pack);
  487. if(!data->auth_success) {
  488. // Reset card
  489. furi_hal_nfc_sleep();
  490. if(!furi_hal_nfc_activate_nfca(300, NULL)) {
  491. nfc_worker->callback(NfcWorkerEventFail, nfc_worker->context);
  492. break;
  493. }
  494. }
  495. mf_ul_read_card(&tx_rx, &reader, data);
  496. if(data->auth_success) {
  497. MfUltralightConfigPages* config_pages = mf_ultralight_get_config_pages(data);
  498. if(config_pages != NULL) {
  499. config_pages->auth_data.pwd.value = REVERSE_BYTES_U32(key);
  500. config_pages->auth_data.pack.value = pack;
  501. }
  502. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  503. break;
  504. } else {
  505. nfc_worker->callback(NfcWorkerEventFail, nfc_worker->context);
  506. break;
  507. }
  508. } else {
  509. nfc_worker->callback(NfcWorkerEventWrongCardDetected, nfc_worker->context);
  510. furi_delay_ms(10);
  511. }
  512. } else {
  513. nfc_worker->callback(NfcWorkerEventNoCardDetected, nfc_worker->context);
  514. furi_delay_ms(10);
  515. }
  516. }
  517. }