passy_reader.c 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459
  1. #include "passy_reader.h"
  2. #define TAG "PassyReader"
  3. static uint8_t passport_aid[] = {0xA0, 0x00, 0x00, 0x02, 0x47, 0x10, 0x01};
  4. static uint8_t select_header[] = {0x00, 0xA4, 0x04, 0x0C};
  5. static uint8_t get_challenge[] = {0x00, 0x84, 0x00, 0x00, 0x08};
  6. static uint8_t SW_success[] = {0x90, 0x00};
  7. size_t asn1_length(uint8_t data[3]) {
  8. if(data[0] <= 0x7F) {
  9. return data[0];
  10. } else if(data[0] == 0x81) {
  11. return data[1];
  12. } else if(data[0] == 0x82) {
  13. return (data[1] << 8) | data[2];
  14. }
  15. return 0;
  16. }
  17. PassyReader* passy_reader_alloc(Passy* passy, Iso14443_4bPoller* iso14443_4b_poller) {
  18. PassyReader* passy_reader = malloc(sizeof(PassyReader));
  19. memset(passy_reader, 0, sizeof(PassyReader));
  20. passy_reader->iso14443_4b_poller = iso14443_4b_poller;
  21. passy_reader->DG1 = passy->DG1;
  22. passy_reader->tx_buffer = bit_buffer_alloc(PASSY_READER_MAX_BUFFER_SIZE);
  23. passy_reader->rx_buffer = bit_buffer_alloc(PASSY_READER_MAX_BUFFER_SIZE);
  24. char passport_number[11];
  25. memset(passport_number, 0, sizeof(passport_number));
  26. memcpy(passport_number, passy->passport_number, strlen(passy->passport_number));
  27. passport_number[strlen(passy->passport_number)] = passy_checksum(passy->passport_number);
  28. FURI_LOG_I(TAG, "Passport number: %s", passport_number);
  29. char date_of_birth[8];
  30. memset(date_of_birth, 0, sizeof(date_of_birth));
  31. memcpy(date_of_birth, passy->date_of_birth, strlen(passy->date_of_birth));
  32. date_of_birth[strlen(passy->date_of_birth)] = passy_checksum(passy->date_of_birth);
  33. FURI_LOG_I(TAG, "Date of birth: %s", date_of_birth);
  34. char date_of_expiry[8];
  35. memset(date_of_expiry, 0, sizeof(date_of_expiry));
  36. memcpy(date_of_expiry, passy->date_of_expiry, strlen(passy->date_of_expiry));
  37. date_of_expiry[strlen(passy->date_of_expiry)] = passy_checksum(passy->date_of_expiry);
  38. FURI_LOG_I(TAG, "Date of expiry: %s", date_of_expiry);
  39. passy_save_mrz_info(passy);
  40. passy_reader->secure_messaging = secure_messaging_alloc(
  41. (uint8_t*)passport_number, (uint8_t*)date_of_birth, (uint8_t*)date_of_expiry);
  42. return passy_reader;
  43. }
  44. void passy_reader_free(PassyReader* passy_reader) {
  45. furi_assert(passy_reader);
  46. bit_buffer_free(passy_reader->tx_buffer);
  47. bit_buffer_free(passy_reader->rx_buffer);
  48. if(passy_reader->secure_messaging) {
  49. secure_messaging_free(passy_reader->secure_messaging);
  50. }
  51. free(passy_reader);
  52. }
  53. NfcCommand passy_reader_select_application(PassyReader* passy_reader) {
  54. NfcCommand ret = NfcCommandContinue;
  55. BitBuffer* tx_buffer = passy_reader->tx_buffer;
  56. BitBuffer* rx_buffer = passy_reader->rx_buffer;
  57. Iso14443_4bPoller* iso14443_4b_poller = passy_reader->iso14443_4b_poller;
  58. Iso14443_4bError error;
  59. bit_buffer_append_bytes(tx_buffer, select_header, sizeof(select_header));
  60. bit_buffer_append_byte(tx_buffer, sizeof(passport_aid));
  61. bit_buffer_append_bytes(tx_buffer, passport_aid, sizeof(passport_aid));
  62. bit_buffer_append_byte(tx_buffer, 0x00); // Le
  63. error = iso14443_4b_poller_send_block(iso14443_4b_poller, tx_buffer, rx_buffer);
  64. if(error != Iso14443_4bErrorNone) {
  65. FURI_LOG_W(TAG, "iso14443_4b_poller_send_block error %d", error);
  66. return NfcCommandStop;
  67. }
  68. bit_buffer_reset(tx_buffer);
  69. passy_log_bitbuffer(TAG, "NFC response", rx_buffer);
  70. // Check SW
  71. size_t length = bit_buffer_get_size_bytes(rx_buffer);
  72. const uint8_t* data = bit_buffer_get_data(rx_buffer);
  73. if(length < 2) {
  74. FURI_LOG_W(TAG, "Invalid response length %d", length);
  75. return NfcCommandStop;
  76. }
  77. if(memcmp(data + length - 2, SW_success, sizeof(SW_success)) != 0) {
  78. FURI_LOG_W(TAG, "Invalid SW %02x %02x", data[length - 2], data[length - 1]);
  79. return NfcCommandStop;
  80. }
  81. return ret;
  82. }
  83. NfcCommand passy_reader_get_challenge(PassyReader* passy_reader) {
  84. NfcCommand ret = NfcCommandContinue;
  85. BitBuffer* tx_buffer = passy_reader->tx_buffer;
  86. BitBuffer* rx_buffer = passy_reader->rx_buffer;
  87. Iso14443_4bPoller* iso14443_4b_poller = passy_reader->iso14443_4b_poller;
  88. Iso14443_4bError error;
  89. bit_buffer_append_bytes(tx_buffer, get_challenge, sizeof(get_challenge));
  90. error = iso14443_4b_poller_send_block(iso14443_4b_poller, tx_buffer, rx_buffer);
  91. if(error != Iso14443_4bErrorNone) {
  92. FURI_LOG_W(TAG, "iso14443_4b_poller_send_block error %d", error);
  93. return NfcCommandStop;
  94. }
  95. bit_buffer_reset(tx_buffer);
  96. passy_log_bitbuffer(TAG, "NFC response", rx_buffer);
  97. // Check SW
  98. size_t length = bit_buffer_get_size_bytes(rx_buffer);
  99. const uint8_t* data = bit_buffer_get_data(rx_buffer);
  100. if(length < 2) {
  101. FURI_LOG_W(TAG, "Invalid response length %d", length);
  102. return NfcCommandStop;
  103. }
  104. if(memcmp(data + length - 2, SW_success, sizeof(SW_success)) != 0) {
  105. FURI_LOG_W(TAG, "Invalid SW %02x %02x", data[length - 2], data[length - 1]);
  106. return NfcCommandStop;
  107. }
  108. SecureMessaging* secure_messaging = passy_reader->secure_messaging;
  109. const uint8_t* rnd_icc = data;
  110. memcpy(secure_messaging->rndICC, rnd_icc, 8);
  111. return ret;
  112. }
  113. NfcCommand passy_reader_authenticate(PassyReader* passy_reader) {
  114. NfcCommand ret = NfcCommandContinue;
  115. BitBuffer* tx_buffer = passy_reader->tx_buffer;
  116. BitBuffer* rx_buffer = passy_reader->rx_buffer;
  117. Iso14443_4bPoller* iso14443_4b_poller = passy_reader->iso14443_4b_poller;
  118. Iso14443_4bError error;
  119. // TODO: move into secure_messaging
  120. SecureMessaging* secure_messaging = passy_reader->secure_messaging;
  121. uint8_t S[32];
  122. memset(S, 0, sizeof(S));
  123. uint8_t eifd[32];
  124. memcpy(S, secure_messaging->rndIFD, sizeof(secure_messaging->rndIFD));
  125. memcpy(
  126. S + sizeof(secure_messaging->rndIFD),
  127. secure_messaging->rndICC,
  128. sizeof(secure_messaging->rndICC));
  129. memcpy(
  130. S + sizeof(secure_messaging->rndIFD) + sizeof(secure_messaging->rndICC),
  131. secure_messaging->Kifd,
  132. sizeof(secure_messaging->Kifd));
  133. uint8_t iv[8];
  134. memset(iv, 0, sizeof(iv));
  135. mbedtls_des3_context ctx;
  136. mbedtls_des3_init(&ctx);
  137. mbedtls_des3_set2key_enc(&ctx, secure_messaging->KENC);
  138. mbedtls_des3_crypt_cbc(&ctx, MBEDTLS_DES_ENCRYPT, sizeof(S), iv, S, eifd);
  139. mbedtls_des3_free(&ctx);
  140. passy_log_buffer(TAG, "S", S, sizeof(S));
  141. passy_log_buffer(TAG, "eifd", eifd, sizeof(eifd));
  142. uint8_t mifd[8];
  143. passy_mac(secure_messaging->KMAC, eifd, sizeof(eifd), mifd, false);
  144. passy_log_buffer(TAG, "mifd", mifd, sizeof(mifd));
  145. uint8_t authenticate_header[] = {0x00, 0x82, 0x00, 0x00};
  146. bit_buffer_append_bytes(tx_buffer, authenticate_header, sizeof(authenticate_header));
  147. bit_buffer_append_byte(tx_buffer, sizeof(eifd) + sizeof(mifd));
  148. bit_buffer_append_bytes(tx_buffer, eifd, sizeof(eifd));
  149. bit_buffer_append_bytes(tx_buffer, mifd, sizeof(mifd));
  150. bit_buffer_append_byte(tx_buffer, 0x28); // Le
  151. passy_log_bitbuffer(TAG, "NFC transmit", tx_buffer);
  152. error = iso14443_4b_poller_send_block(iso14443_4b_poller, tx_buffer, rx_buffer);
  153. if(error != Iso14443_4bErrorNone) {
  154. FURI_LOG_W(TAG, "iso14443_4b_poller_send_block error %d", error);
  155. return NfcCommandStop;
  156. }
  157. bit_buffer_reset(tx_buffer);
  158. passy_log_bitbuffer(TAG, "NFC response", rx_buffer);
  159. // Check SW
  160. size_t length = bit_buffer_get_size_bytes(rx_buffer);
  161. const uint8_t* data = bit_buffer_get_data(rx_buffer);
  162. if(length < 2) {
  163. FURI_LOG_W(TAG, "Invalid response length %d", length);
  164. return NfcCommandStop;
  165. }
  166. if(memcmp(data + length - 2, SW_success, sizeof(SW_success)) != 0) {
  167. FURI_LOG_W(TAG, "Invalid SW %02x %02x", data[length - 2], data[length - 1]);
  168. return NfcCommandStop;
  169. }
  170. const uint8_t* mac = data + length - 2 - 8;
  171. uint8_t calculated_mac[8];
  172. passy_mac(secure_messaging->KMAC, (uint8_t*)data, length - 8 - 2, calculated_mac, false);
  173. if(memcmp(mac, calculated_mac, sizeof(calculated_mac)) != 0) {
  174. FURI_LOG_W(TAG, "Invalid MAC");
  175. return NfcCommandStop;
  176. }
  177. uint8_t decrypted[32];
  178. do {
  179. uint8_t iv[8];
  180. memset(iv, 0, sizeof(iv));
  181. mbedtls_des3_context ctx;
  182. mbedtls_des3_init(&ctx);
  183. mbedtls_des3_set2key_dec(&ctx, secure_messaging->KENC);
  184. mbedtls_des3_crypt_cbc(&ctx, MBEDTLS_DES_DECRYPT, length - 2 - 8, iv, data, decrypted);
  185. mbedtls_des3_free(&ctx);
  186. } while(false);
  187. passy_log_buffer(TAG, "decrypted", decrypted, sizeof(decrypted));
  188. uint8_t* rnd_icc = decrypted;
  189. uint8_t* rnd_ifd = decrypted + 8;
  190. uint8_t* Kicc = decrypted + 16;
  191. if(memcmp(rnd_icc, secure_messaging->rndICC, sizeof(secure_messaging->rndICC)) != 0) {
  192. FURI_LOG_W(TAG, "Invalid rndICC");
  193. return NfcCommandStop;
  194. }
  195. memcpy(secure_messaging->Kicc, Kicc, sizeof(secure_messaging->Kicc));
  196. memcpy(secure_messaging->SSC + 0, rnd_icc + 4, 4);
  197. memcpy(secure_messaging->SSC + 4, rnd_ifd + 4, 4);
  198. return ret;
  199. }
  200. NfcCommand passy_reader_select_file(PassyReader* passy_reader, uint16_t file_id) {
  201. NfcCommand ret = NfcCommandContinue;
  202. BitBuffer* tx_buffer = passy_reader->tx_buffer;
  203. BitBuffer* rx_buffer = passy_reader->rx_buffer;
  204. Iso14443_4bPoller* iso14443_4b_poller = passy_reader->iso14443_4b_poller;
  205. Iso14443_4bError error;
  206. uint8_t select_0101[] = {0x00, 0xa4, 0x02, 0x0c, 0x02, 0x00, 0x00};
  207. select_0101[5] = (file_id >> 8) & 0xFF;
  208. select_0101[6] = file_id & 0xFF;
  209. secure_messaging_wrap_apdu(
  210. passy_reader->secure_messaging, select_0101, sizeof(select_0101), tx_buffer);
  211. passy_log_bitbuffer(TAG, "NFC transmit", tx_buffer);
  212. error = iso14443_4b_poller_send_block(iso14443_4b_poller, tx_buffer, rx_buffer);
  213. if(error != Iso14443_4bErrorNone) {
  214. FURI_LOG_W(TAG, "iso14443_4b_poller_send_block error %d", error);
  215. return NfcCommandStop;
  216. }
  217. bit_buffer_reset(tx_buffer);
  218. passy_log_bitbuffer(TAG, "NFC response", rx_buffer);
  219. // Check SW
  220. size_t length = bit_buffer_get_size_bytes(rx_buffer);
  221. const uint8_t* data = bit_buffer_get_data(rx_buffer);
  222. if(length < 2) {
  223. FURI_LOG_W(TAG, "Invalid response length %d", length);
  224. return NfcCommandStop;
  225. }
  226. if(memcmp(data + length - 2, SW_success, sizeof(SW_success)) != 0) {
  227. FURI_LOG_W(TAG, "Invalid SW %02x %02x", data[length - 2], data[length - 1]);
  228. return NfcCommandStop;
  229. }
  230. secure_messaging_unwrap_rapdu(passy_reader->secure_messaging, rx_buffer);
  231. passy_log_bitbuffer(TAG, "NFC response (decrypted)", rx_buffer);
  232. return ret;
  233. }
  234. NfcCommand passy_reader_read_binary(
  235. PassyReader* passy_reader,
  236. uint8_t offset,
  237. uint8_t Le,
  238. uint8_t* output_buffer) {
  239. NfcCommand ret = NfcCommandContinue;
  240. BitBuffer* tx_buffer = passy_reader->tx_buffer;
  241. BitBuffer* rx_buffer = passy_reader->rx_buffer;
  242. Iso14443_4bPoller* iso14443_4b_poller = passy_reader->iso14443_4b_poller;
  243. Iso14443_4bError error;
  244. uint8_t read_binary[] = {0x00, 0xB0, 0x00, offset, Le};
  245. secure_messaging_wrap_apdu(
  246. passy_reader->secure_messaging, read_binary, sizeof(read_binary), tx_buffer);
  247. passy_log_bitbuffer(TAG, "NFC transmit", tx_buffer);
  248. error = iso14443_4b_poller_send_block(iso14443_4b_poller, tx_buffer, rx_buffer);
  249. if(error != Iso14443_4bErrorNone) {
  250. FURI_LOG_W(TAG, "iso14443_4b_poller_send_block error %d", error);
  251. return NfcCommandStop;
  252. }
  253. bit_buffer_reset(tx_buffer);
  254. passy_log_bitbuffer(TAG, "NFC response", rx_buffer);
  255. // Check SW
  256. size_t length = bit_buffer_get_size_bytes(rx_buffer);
  257. const uint8_t* data = bit_buffer_get_data(rx_buffer);
  258. if(length < 2) {
  259. FURI_LOG_W(TAG, "Invalid response length %d", length);
  260. return NfcCommandStop;
  261. }
  262. if(memcmp(data + length - 2, SW_success, sizeof(SW_success)) != 0) {
  263. FURI_LOG_W(TAG, "Invalid SW %02x %02x", data[length - 2], data[length - 1]);
  264. return NfcCommandStop;
  265. }
  266. secure_messaging_unwrap_rapdu(passy_reader->secure_messaging, rx_buffer);
  267. passy_log_bitbuffer(TAG, "NFC response (decrypted)", rx_buffer);
  268. const uint8_t* decrypted_data = bit_buffer_get_data(rx_buffer);
  269. memcpy(output_buffer, decrypted_data, Le);
  270. return ret;
  271. }
  272. NfcCommand passy_reader_state_machine(Passy* passy, PassyReader* passy_reader) {
  273. furi_assert(passy_reader);
  274. NfcCommand ret = NfcCommandContinue;
  275. do {
  276. ret = passy_reader_select_application(passy_reader);
  277. if(ret != NfcCommandContinue) {
  278. view_dispatcher_send_custom_event(passy->view_dispatcher, PassyCustomEventReaderError);
  279. break;
  280. }
  281. ret = passy_reader_get_challenge(passy_reader);
  282. if(ret != NfcCommandContinue) {
  283. view_dispatcher_send_custom_event(passy->view_dispatcher, PassyCustomEventReaderError);
  284. break;
  285. }
  286. ret = passy_reader_authenticate(passy_reader);
  287. if(ret != NfcCommandContinue) {
  288. view_dispatcher_send_custom_event(passy->view_dispatcher, PassyCustomEventReaderError);
  289. break;
  290. }
  291. FURI_LOG_I(TAG, "Mututal authentication success");
  292. secure_messaging_calculate_session_keys(passy_reader->secure_messaging);
  293. view_dispatcher_send_custom_event(
  294. passy->view_dispatcher, PassyCustomEventReaderAuthenticated);
  295. ret = passy_reader_select_file(passy_reader, 0x0101);
  296. if(ret != NfcCommandContinue) {
  297. view_dispatcher_send_custom_event(passy->view_dispatcher, PassyCustomEventReaderError);
  298. break;
  299. }
  300. bit_buffer_reset(passy->DG1);
  301. uint8_t header[4];
  302. ret = passy_reader_read_binary(passy_reader, 0x00, 0x04, header);
  303. if(ret != NfcCommandContinue) {
  304. view_dispatcher_send_custom_event(passy->view_dispatcher, PassyCustomEventReaderError);
  305. break;
  306. }
  307. size_t body_size = asn1_length(header + 1);
  308. uint8_t body_offset = 0x04;
  309. do {
  310. view_dispatcher_send_custom_event(
  311. passy->view_dispatcher, PassyCustomEventReaderReading);
  312. uint8_t chunk[0x20];
  313. uint8_t Le = MIN(sizeof(chunk), (size_t)(body_size - body_offset));
  314. ret = passy_reader_read_binary(passy_reader, body_offset, Le, chunk);
  315. if(ret != NfcCommandContinue) {
  316. view_dispatcher_send_custom_event(
  317. passy->view_dispatcher, PassyCustomEventReaderError);
  318. break;
  319. }
  320. bit_buffer_append_bytes(passy_reader->DG1, chunk, sizeof(chunk));
  321. body_offset += sizeof(chunk);
  322. } while(body_offset < body_size);
  323. passy_log_bitbuffer(TAG, "DG1", passy_reader->DG1);
  324. ret = passy_reader_select_file(passy_reader, 0x0102);
  325. if(ret != NfcCommandContinue) {
  326. view_dispatcher_send_custom_event(passy->view_dispatcher, PassyCustomEventReaderError);
  327. break;
  328. }
  329. ret = passy_reader_read_binary(passy_reader, 0x00, 0x04, header);
  330. if(ret != NfcCommandContinue) {
  331. view_dispatcher_send_custom_event(passy->view_dispatcher, PassyCustomEventReaderError);
  332. break;
  333. }
  334. body_size = asn1_length(header + 1);
  335. FURI_LOG_I(TAG, "DG2 length: %d", body_size);
  336. // Everything done
  337. ret = NfcCommandStop;
  338. view_dispatcher_send_custom_event(passy->view_dispatcher, PassyCustomEventReaderSuccess);
  339. } while(false);
  340. return ret;
  341. }
  342. NfcCommand passy_reader_poller_callback(NfcGenericEvent event, void* context) {
  343. furi_assert(event.protocol == NfcProtocolIso14443_4b);
  344. Passy* passy = context;
  345. NfcCommand ret = NfcCommandContinue;
  346. const Iso14443_4bPollerEvent* iso14443_4b_event = event.event_data;
  347. Iso14443_4bPoller* iso14443_4b_poller = event.instance;
  348. FURI_LOG_D(TAG, "iso14443_4b_event->type %i", iso14443_4b_event->type);
  349. PassyReader* passy_reader = passy_reader_alloc(passy, iso14443_4b_poller);
  350. if(iso14443_4b_event->type == Iso14443_4bPollerEventTypeReady) {
  351. view_dispatcher_send_custom_event(passy->view_dispatcher, PassyCustomEventReaderDetected);
  352. nfc_device_set_data(
  353. passy->nfc_device, NfcProtocolIso14443_4b, nfc_poller_get_data(passy->poller));
  354. ret = passy_reader_state_machine(passy, passy_reader);
  355. furi_thread_set_current_priority(FuriThreadPriorityLowest);
  356. } else if(iso14443_4b_event->type == Iso14443_4bPollerEventTypeError) {
  357. Iso14443_4bPollerEventData* data = iso14443_4b_event->data;
  358. Iso14443_4bError error = data->error;
  359. FURI_LOG_W(TAG, "Iso14443_4bError %i", error);
  360. switch(error) {
  361. case Iso14443_4bErrorNone:
  362. break;
  363. case Iso14443_4bErrorNotPresent:
  364. break;
  365. case Iso14443_4bErrorProtocol:
  366. ret = NfcCommandStop;
  367. break;
  368. case Iso14443_4bErrorTimeout:
  369. break;
  370. }
  371. }
  372. passy_reader_free(passy_reader);
  373. return ret;
  374. }