mifare_ultralight.h 6.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243
  1. #pragma once
  2. #include <furi_hal_nfc.h>
  3. // Largest tag is NTAG I2C Plus 2K, both data sectors plus SRAM
  4. #define MF_UL_MAX_DUMP_SIZE ((238 + 256 + 16) * 4)
  5. #define MF_UL_TEARING_FLAG_DEFAULT (0xBD)
  6. #define MF_UL_HALT_START (0x50)
  7. #define MF_UL_GET_VERSION_CMD (0x60)
  8. #define MF_UL_READ_CMD (0x30)
  9. #define MF_UL_FAST_READ_CMD (0x3A)
  10. #define MF_UL_WRITE (0xA2)
  11. #define MF_UL_FAST_WRITE (0xA6)
  12. #define MF_UL_COMP_WRITE (0xA0)
  13. #define MF_UL_READ_CNT (0x39)
  14. #define MF_UL_INC_CNT (0xA5)
  15. #define MF_UL_AUTH (0x1B)
  16. #define MF_UL_READ_SIG (0x3C)
  17. #define MF_UL_CHECK_TEARING (0x3E)
  18. #define MF_UL_READ_VCSL (0x4B)
  19. #define MF_UL_SECTOR_SELECT (0xC2)
  20. #define MF_UL_ACK (0xa)
  21. #define MF_UL_NAK_INVALID_ARGUMENT (0x0)
  22. #define MF_UL_NAK_AUTHLIM_REACHED (0x4)
  23. #define MF_UL_NTAG203_COUNTER_PAGE (41)
  24. typedef enum {
  25. MfUltralightAuthMethodManual,
  26. MfUltralightAuthMethodAmeebo,
  27. MfUltralightAuthMethodXiaomi,
  28. } MfUltralightAuthMethod;
  29. // Important: order matters; some features are based on positioning in this enum
  30. typedef enum {
  31. MfUltralightTypeUnknown,
  32. MfUltralightTypeNTAG203,
  33. // Below have config pages and GET_VERSION support
  34. MfUltralightTypeUL11,
  35. MfUltralightTypeUL21,
  36. MfUltralightTypeNTAG213,
  37. MfUltralightTypeNTAG215,
  38. MfUltralightTypeNTAG216,
  39. // Below also have sector select
  40. // NTAG I2C's *does not* have regular config pages, so it's a bit of an odd duck
  41. MfUltralightTypeNTAGI2C1K,
  42. MfUltralightTypeNTAGI2C2K,
  43. // NTAG I2C Plus has stucture expected from NTAG21x
  44. MfUltralightTypeNTAGI2CPlus1K,
  45. MfUltralightTypeNTAGI2CPlus2K,
  46. // Keep last for number of types calculation
  47. MfUltralightTypeNum,
  48. } MfUltralightType;
  49. typedef enum {
  50. MfUltralightSupportNone = 0,
  51. MfUltralightSupportFastRead = 1 << 0,
  52. MfUltralightSupportTearingFlags = 1 << 1,
  53. MfUltralightSupportReadCounter = 1 << 2,
  54. MfUltralightSupportIncrCounter = 1 << 3,
  55. MfUltralightSupportSignature = 1 << 4,
  56. MfUltralightSupportFastWrite = 1 << 5,
  57. MfUltralightSupportCompatWrite = 1 << 6,
  58. MfUltralightSupportAuth = 1 << 7,
  59. MfUltralightSupportVcsl = 1 << 8,
  60. MfUltralightSupportSectorSelect = 1 << 9,
  61. // NTAG21x only has counter 2
  62. MfUltralightSupportSingleCounter = 1 << 10,
  63. // ASCII mirror is not a command, but handy to have as a flag
  64. MfUltralightSupportAsciiMirror = 1 << 11,
  65. // NTAG203 counter that's in memory rather than through a command
  66. MfUltralightSupportCounterInMemory = 1 << 12,
  67. } MfUltralightFeatures;
  68. typedef enum {
  69. MfUltralightMirrorNone,
  70. MfUltralightMirrorUid,
  71. MfUltralightMirrorCounter,
  72. MfUltralightMirrorUidCounter,
  73. } MfUltralightMirrorConf;
  74. typedef struct {
  75. uint8_t header;
  76. uint8_t vendor_id;
  77. uint8_t prod_type;
  78. uint8_t prod_subtype;
  79. uint8_t prod_ver_major;
  80. uint8_t prod_ver_minor;
  81. uint8_t storage_size;
  82. uint8_t protocol_type;
  83. } MfUltralightVersion;
  84. typedef struct {
  85. uint8_t sn0[3];
  86. uint8_t btBCC0;
  87. uint8_t sn1[4];
  88. uint8_t btBCC1;
  89. uint8_t internal;
  90. uint8_t lock[2];
  91. uint8_t otp[4];
  92. } MfUltralightManufacturerBlock;
  93. typedef struct {
  94. MfUltralightType type;
  95. MfUltralightVersion version;
  96. uint8_t signature[32];
  97. uint32_t counter[3];
  98. uint8_t tearing[3];
  99. bool has_auth;
  100. MfUltralightAuthMethod auth_method;
  101. uint8_t auth_key[4];
  102. bool auth_success;
  103. uint16_t curr_authlim;
  104. uint16_t data_size;
  105. uint8_t data[MF_UL_MAX_DUMP_SIZE];
  106. uint16_t data_read;
  107. } MfUltralightData;
  108. typedef struct __attribute__((packed)) {
  109. union {
  110. uint8_t raw[4];
  111. uint32_t value;
  112. } pwd;
  113. union {
  114. uint8_t raw[2];
  115. uint16_t value;
  116. } pack;
  117. } MfUltralightAuth;
  118. // Common configuration pages for MFUL EV1, NTAG21x, and NTAG I2C Plus
  119. typedef struct __attribute__((packed)) {
  120. union {
  121. uint8_t value;
  122. struct {
  123. uint8_t rfui1 : 2;
  124. bool strg_mod_en : 1;
  125. bool rfui2 : 1;
  126. uint8_t mirror_byte : 2;
  127. MfUltralightMirrorConf mirror_conf : 2;
  128. };
  129. } mirror;
  130. uint8_t rfui1;
  131. uint8_t mirror_page;
  132. uint8_t auth0;
  133. union {
  134. uint8_t value;
  135. struct {
  136. uint8_t authlim : 3;
  137. bool nfc_cnt_pwd_prot : 1;
  138. bool nfc_cnt_en : 1;
  139. bool nfc_dis_sec1 : 1; // NTAG I2C Plus only
  140. bool cfglck : 1;
  141. bool prot : 1;
  142. };
  143. } access;
  144. uint8_t vctid;
  145. uint8_t rfui2[2];
  146. MfUltralightAuth auth_data;
  147. uint8_t rfui3[2];
  148. } MfUltralightConfigPages;
  149. typedef struct {
  150. uint16_t pages_to_read;
  151. int16_t pages_read;
  152. MfUltralightFeatures supported_features;
  153. } MfUltralightReader;
  154. typedef struct {
  155. MfUltralightData data;
  156. MfUltralightConfigPages* config;
  157. // Most config values don't apply until power cycle, so cache config pages
  158. // for correct behavior
  159. MfUltralightConfigPages config_cache;
  160. MfUltralightFeatures supported_features;
  161. uint16_t page_num;
  162. bool data_changed;
  163. bool comp_write_cmd_started;
  164. uint8_t comp_write_page_addr;
  165. bool auth_success;
  166. uint8_t curr_sector;
  167. bool sector_select_cmd_started;
  168. bool ntag_i2c_plus_sector3_lockout;
  169. bool read_counter_incremented;
  170. } MfUltralightEmulator;
  171. void mf_ul_reset(MfUltralightData* data);
  172. bool mf_ul_check_card_type(uint8_t ATQA0, uint8_t ATQA1, uint8_t SAK);
  173. bool mf_ultralight_read_version(
  174. FuriHalNfcTxRxContext* tx_rx,
  175. MfUltralightReader* reader,
  176. MfUltralightData* data);
  177. bool mf_ultralight_read_pages_direct(
  178. FuriHalNfcTxRxContext* tx_rx,
  179. uint8_t start_index,
  180. uint8_t* data);
  181. bool mf_ultralight_read_pages(
  182. FuriHalNfcTxRxContext* tx_rx,
  183. MfUltralightReader* reader,
  184. MfUltralightData* data);
  185. bool mf_ultralight_fast_read_pages(
  186. FuriHalNfcTxRxContext* tx_rx,
  187. MfUltralightReader* reader,
  188. MfUltralightData* data);
  189. bool mf_ultralight_read_signature(FuriHalNfcTxRxContext* tx_rx, MfUltralightData* data);
  190. bool mf_ultralight_read_counters(FuriHalNfcTxRxContext* tx_rx, MfUltralightData* data);
  191. bool mf_ultralight_read_tearing_flags(FuriHalNfcTxRxContext* tx_rx, MfUltralightData* data);
  192. bool mf_ultralight_authenticate(FuriHalNfcTxRxContext* tx_rx, uint32_t key, uint16_t* pack);
  193. MfUltralightConfigPages* mf_ultralight_get_config_pages(MfUltralightData* data);
  194. bool mf_ul_read_card(
  195. FuriHalNfcTxRxContext* tx_rx,
  196. MfUltralightReader* reader,
  197. MfUltralightData* data);
  198. void mf_ul_reset_emulation(MfUltralightEmulator* emulator, bool is_power_cycle);
  199. void mf_ul_prepare_emulation(MfUltralightEmulator* emulator, MfUltralightData* data);
  200. bool mf_ul_prepare_emulation_response(
  201. uint8_t* buff_rx,
  202. uint16_t buff_rx_len,
  203. uint8_t* buff_tx,
  204. uint16_t* buff_tx_len,
  205. uint32_t* data_type,
  206. void* context);
  207. uint32_t mf_ul_pwdgen_amiibo(FuriHalNfcDevData* data);
  208. uint32_t mf_ul_pwdgen_xiaomi(FuriHalNfcDevData* data);