nfc_worker.c 29 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702
  1. #include "nfc_worker_i.h"
  2. #include <furi_hal.h>
  3. #define TAG "NfcWorker"
  4. /***************************** NFC Worker API *******************************/
  5. NfcWorker* nfc_worker_alloc() {
  6. NfcWorker* nfc_worker = malloc(sizeof(NfcWorker));
  7. // Worker thread attributes
  8. nfc_worker->thread = furi_thread_alloc();
  9. furi_thread_set_name(nfc_worker->thread, "NfcWorker");
  10. furi_thread_set_stack_size(nfc_worker->thread, 8192);
  11. furi_thread_set_callback(nfc_worker->thread, nfc_worker_task);
  12. furi_thread_set_context(nfc_worker->thread, nfc_worker);
  13. nfc_worker->callback = NULL;
  14. nfc_worker->context = NULL;
  15. nfc_worker->storage = furi_record_open("storage");
  16. // Initialize rfal
  17. while(furi_hal_nfc_is_busy()) {
  18. osDelay(10);
  19. }
  20. nfc_worker_change_state(nfc_worker, NfcWorkerStateReady);
  21. if(furi_hal_rtc_is_flag_set(FuriHalRtcFlagDebug)) {
  22. nfc_worker->debug_pcap_worker = nfc_debug_pcap_alloc(nfc_worker->storage);
  23. }
  24. return nfc_worker;
  25. }
  26. void nfc_worker_free(NfcWorker* nfc_worker) {
  27. furi_assert(nfc_worker);
  28. furi_thread_free(nfc_worker->thread);
  29. furi_record_close("storage");
  30. if(nfc_worker->debug_pcap_worker) nfc_debug_pcap_free(nfc_worker->debug_pcap_worker);
  31. free(nfc_worker);
  32. }
  33. NfcWorkerState nfc_worker_get_state(NfcWorker* nfc_worker) {
  34. return nfc_worker->state;
  35. }
  36. void nfc_worker_start(
  37. NfcWorker* nfc_worker,
  38. NfcWorkerState state,
  39. NfcDeviceData* dev_data,
  40. NfcWorkerCallback callback,
  41. void* context) {
  42. furi_assert(nfc_worker);
  43. furi_assert(dev_data);
  44. while(furi_hal_nfc_is_busy()) {
  45. osDelay(10);
  46. }
  47. nfc_worker->callback = callback;
  48. nfc_worker->context = context;
  49. nfc_worker->dev_data = dev_data;
  50. nfc_worker_change_state(nfc_worker, state);
  51. furi_thread_start(nfc_worker->thread);
  52. }
  53. void nfc_worker_stop(NfcWorker* nfc_worker) {
  54. furi_assert(nfc_worker);
  55. if(nfc_worker->state == NfcWorkerStateBroken || nfc_worker->state == NfcWorkerStateReady) {
  56. return;
  57. }
  58. furi_hal_nfc_stop();
  59. nfc_worker_change_state(nfc_worker, NfcWorkerStateStop);
  60. furi_thread_join(nfc_worker->thread);
  61. }
  62. void nfc_worker_change_state(NfcWorker* nfc_worker, NfcWorkerState state) {
  63. nfc_worker->state = state;
  64. }
  65. /***************************** NFC Worker Thread *******************************/
  66. int32_t nfc_worker_task(void* context) {
  67. NfcWorker* nfc_worker = context;
  68. furi_hal_nfc_exit_sleep();
  69. if(nfc_worker->state == NfcWorkerStateDetect) {
  70. nfc_worker_detect(nfc_worker);
  71. } else if(nfc_worker->state == NfcWorkerStateEmulate) {
  72. nfc_worker_emulate(nfc_worker);
  73. } else if(nfc_worker->state == NfcWorkerStateReadEMVApp) {
  74. nfc_worker_read_emv_app(nfc_worker);
  75. } else if(nfc_worker->state == NfcWorkerStateReadEMVData) {
  76. nfc_worker_read_emv(nfc_worker);
  77. } else if(nfc_worker->state == NfcWorkerStateEmulateApdu) {
  78. nfc_worker_emulate_apdu(nfc_worker);
  79. } else if(nfc_worker->state == NfcWorkerStateReadMifareUltralight) {
  80. nfc_worker_read_mifare_ultralight(nfc_worker);
  81. } else if(nfc_worker->state == NfcWorkerStateEmulateMifareUltralight) {
  82. nfc_worker_emulate_mifare_ul(nfc_worker);
  83. } else if(nfc_worker->state == NfcWorkerStateReadMifareClassic) {
  84. nfc_worker_mifare_classic_dict_attack(nfc_worker);
  85. } else if(nfc_worker->state == NfcWorkerStateEmulateMifareClassic) {
  86. nfc_worker_emulate_mifare_classic(nfc_worker);
  87. } else if(nfc_worker->state == NfcWorkerStateReadMifareDesfire) {
  88. nfc_worker_read_mifare_desfire(nfc_worker);
  89. }
  90. furi_hal_nfc_sleep();
  91. nfc_worker_change_state(nfc_worker, NfcWorkerStateReady);
  92. return 0;
  93. }
  94. void nfc_worker_detect(NfcWorker* nfc_worker) {
  95. nfc_device_data_clear(nfc_worker->dev_data);
  96. NfcDeviceData* dev_data = nfc_worker->dev_data;
  97. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  98. while(nfc_worker->state == NfcWorkerStateDetect) {
  99. if(furi_hal_nfc_detect(nfc_data, 1000)) {
  100. // Process first found device
  101. if(nfc_data->type == FuriHalNfcTypeA) {
  102. if(mf_ul_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  103. dev_data->protocol = NfcDeviceProtocolMifareUl;
  104. } else if(mf_classic_check_card_type(
  105. nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  106. dev_data->protocol = NfcDeviceProtocolMifareClassic;
  107. } else if(mf_df_check_card_type(
  108. nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  109. dev_data->protocol = NfcDeviceProtocolMifareDesfire;
  110. } else if(nfc_data->interface == FuriHalNfcInterfaceIsoDep) {
  111. dev_data->protocol = NfcDeviceProtocolEMV;
  112. } else {
  113. dev_data->protocol = NfcDeviceProtocolUnknown;
  114. }
  115. }
  116. // Notify caller and exit
  117. if(nfc_worker->callback) {
  118. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  119. }
  120. break;
  121. }
  122. furi_hal_nfc_sleep();
  123. osDelay(100);
  124. }
  125. }
  126. void nfc_worker_emulate(NfcWorker* nfc_worker) {
  127. FuriHalNfcTxRxContext tx_rx = {};
  128. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx, true);
  129. FuriHalNfcDevData* data = &nfc_worker->dev_data->nfc_data;
  130. NfcReaderRequestData* reader_data = &nfc_worker->dev_data->reader_data;
  131. while(nfc_worker->state == NfcWorkerStateEmulate) {
  132. if(furi_hal_nfc_listen(data->uid, data->uid_len, data->atqa, data->sak, true, 100)) {
  133. if(furi_hal_nfc_tx_rx(&tx_rx, 100)) {
  134. reader_data->size = tx_rx.rx_bits / 8;
  135. if(reader_data->size > 0) {
  136. memcpy(reader_data->data, tx_rx.rx_data, reader_data->size);
  137. if(nfc_worker->callback) {
  138. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  139. }
  140. }
  141. } else {
  142. FURI_LOG_E(TAG, "Failed to get reader commands");
  143. }
  144. }
  145. }
  146. }
  147. void nfc_worker_read_emv_app(NfcWorker* nfc_worker) {
  148. FuriHalNfcTxRxContext tx_rx = {};
  149. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx, false);
  150. EmvApplication emv_app = {};
  151. NfcDeviceData* result = nfc_worker->dev_data;
  152. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  153. nfc_device_data_clear(result);
  154. while(nfc_worker->state == NfcWorkerStateReadEMVApp) {
  155. if(furi_hal_nfc_detect(nfc_data, 1000)) {
  156. // Card was found. Check that it supports EMV
  157. if(nfc_data->interface == FuriHalNfcInterfaceIsoDep) {
  158. result->protocol = NfcDeviceProtocolEMV;
  159. if(emv_search_application(&tx_rx, &emv_app)) {
  160. // Notify caller and exit
  161. result->emv_data.aid_len = emv_app.aid_len;
  162. memcpy(result->emv_data.aid, emv_app.aid, emv_app.aid_len);
  163. if(nfc_worker->callback) {
  164. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  165. }
  166. }
  167. } else {
  168. FURI_LOG_W(TAG, "Card doesn't support EMV");
  169. }
  170. } else {
  171. FURI_LOG_D(TAG, "Can't find any cards");
  172. }
  173. furi_hal_nfc_sleep();
  174. osDelay(20);
  175. }
  176. }
  177. void nfc_worker_read_emv(NfcWorker* nfc_worker) {
  178. FuriHalNfcTxRxContext tx_rx = {};
  179. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx, false);
  180. EmvApplication emv_app = {};
  181. NfcDeviceData* result = nfc_worker->dev_data;
  182. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  183. nfc_device_data_clear(result);
  184. while(nfc_worker->state == NfcWorkerStateReadEMVData) {
  185. if(furi_hal_nfc_detect(nfc_data, 1000)) {
  186. // Card was found. Check that it supports EMV
  187. if(nfc_data->interface == FuriHalNfcInterfaceIsoDep) {
  188. result->protocol = NfcDeviceProtocolEMV;
  189. if(emv_read_bank_card(&tx_rx, &emv_app)) {
  190. result->emv_data.number_len = emv_app.card_number_len;
  191. memcpy(
  192. result->emv_data.number, emv_app.card_number, result->emv_data.number_len);
  193. result->emv_data.aid_len = emv_app.aid_len;
  194. memcpy(result->emv_data.aid, emv_app.aid, emv_app.aid_len);
  195. if(emv_app.name_found) {
  196. memcpy(result->emv_data.name, emv_app.name, sizeof(emv_app.name));
  197. }
  198. if(emv_app.exp_month) {
  199. result->emv_data.exp_mon = emv_app.exp_month;
  200. result->emv_data.exp_year = emv_app.exp_year;
  201. }
  202. if(emv_app.country_code) {
  203. result->emv_data.country_code = emv_app.country_code;
  204. }
  205. if(emv_app.currency_code) {
  206. result->emv_data.currency_code = emv_app.currency_code;
  207. }
  208. // Notify caller and exit
  209. if(nfc_worker->callback) {
  210. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  211. }
  212. break;
  213. }
  214. } else {
  215. FURI_LOG_W(TAG, "Card doesn't support EMV");
  216. }
  217. } else {
  218. FURI_LOG_D(TAG, "Can't find any cards");
  219. }
  220. furi_hal_nfc_sleep();
  221. osDelay(20);
  222. }
  223. }
  224. void nfc_worker_emulate_apdu(NfcWorker* nfc_worker) {
  225. FuriHalNfcTxRxContext tx_rx = {};
  226. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx, true);
  227. FuriHalNfcDevData params = {
  228. .uid = {0xCF, 0x72, 0xd4, 0x40},
  229. .uid_len = 4,
  230. .atqa = {0x00, 0x04},
  231. .sak = 0x20,
  232. .type = FuriHalNfcTypeA,
  233. };
  234. while(nfc_worker->state == NfcWorkerStateEmulateApdu) {
  235. if(furi_hal_nfc_listen(params.uid, params.uid_len, params.atqa, params.sak, false, 300)) {
  236. FURI_LOG_D(TAG, "POS terminal detected");
  237. if(emv_card_emulation(&tx_rx)) {
  238. FURI_LOG_D(TAG, "EMV card emulated");
  239. }
  240. } else {
  241. FURI_LOG_D(TAG, "Can't find reader");
  242. }
  243. furi_hal_nfc_sleep();
  244. osDelay(20);
  245. }
  246. }
  247. void nfc_worker_read_mifare_ultralight(NfcWorker* nfc_worker) {
  248. FuriHalNfcTxRxContext tx_rx = {};
  249. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx, false);
  250. MfUltralightReader reader = {};
  251. MfUltralightData data = {};
  252. NfcDeviceData* result = nfc_worker->dev_data;
  253. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  254. while(nfc_worker->state == NfcWorkerStateReadMifareUltralight) {
  255. if(furi_hal_nfc_detect(nfc_data, 300)) {
  256. if(nfc_data->type == FuriHalNfcTypeA &&
  257. mf_ul_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  258. FURI_LOG_D(TAG, "Found Mifare Ultralight tag. Start reading");
  259. if(mf_ul_read_card(&tx_rx, &reader, &data)) {
  260. result->protocol = NfcDeviceProtocolMifareUl;
  261. result->mf_ul_data = data;
  262. // Notify caller and exit
  263. if(nfc_worker->callback) {
  264. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  265. }
  266. break;
  267. } else {
  268. FURI_LOG_D(TAG, "Failed reading Mifare Ultralight");
  269. }
  270. } else {
  271. FURI_LOG_W(TAG, "Tag is not Mifare Ultralight");
  272. }
  273. } else {
  274. FURI_LOG_D(TAG, "Can't find any tags");
  275. }
  276. furi_hal_nfc_sleep();
  277. osDelay(100);
  278. }
  279. }
  280. void nfc_worker_emulate_mifare_ul(NfcWorker* nfc_worker) {
  281. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  282. MfUltralightEmulator emulator = {};
  283. mf_ul_prepare_emulation(&emulator, &nfc_worker->dev_data->mf_ul_data);
  284. while(nfc_worker->state == NfcWorkerStateEmulateMifareUltralight) {
  285. mf_ul_reset_emulation(&emulator, true);
  286. furi_hal_nfc_emulate_nfca(
  287. nfc_data->uid,
  288. nfc_data->uid_len,
  289. nfc_data->atqa,
  290. nfc_data->sak,
  291. mf_ul_prepare_emulation_response,
  292. &emulator,
  293. 5000);
  294. // Check if data was modified
  295. if(emulator.data_changed) {
  296. nfc_worker->dev_data->mf_ul_data = emulator.data;
  297. if(nfc_worker->callback) {
  298. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  299. }
  300. emulator.data_changed = false;
  301. }
  302. }
  303. }
  304. void nfc_worker_mifare_classic_dict_attack(NfcWorker* nfc_worker) {
  305. furi_assert(nfc_worker->callback);
  306. FuriHalNfcTxRxContext tx_rx_ctx = {};
  307. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx_ctx, false);
  308. MfClassicAuthContext auth_ctx = {};
  309. MfClassicReader reader = {};
  310. uint64_t curr_key = 0;
  311. uint16_t curr_sector = 0;
  312. uint8_t total_sectors = 0;
  313. NfcWorkerEvent event;
  314. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  315. // Open dictionary
  316. nfc_worker->dict_stream = file_stream_alloc(nfc_worker->storage);
  317. if(!nfc_mf_classic_dict_open_file(nfc_worker->dict_stream)) {
  318. event = NfcWorkerEventNoDictFound;
  319. nfc_worker->callback(event, nfc_worker->context);
  320. nfc_mf_classic_dict_close_file(nfc_worker->dict_stream);
  321. stream_free(nfc_worker->dict_stream);
  322. return;
  323. }
  324. // Detect Mifare Classic card
  325. while(nfc_worker->state == NfcWorkerStateReadMifareClassic) {
  326. if(furi_hal_nfc_detect(nfc_data, 300)) {
  327. if(mf_classic_get_type(
  328. nfc_data->uid,
  329. nfc_data->uid_len,
  330. nfc_data->atqa[0],
  331. nfc_data->atqa[1],
  332. nfc_data->sak,
  333. &reader)) {
  334. total_sectors = mf_classic_get_total_sectors_num(&reader);
  335. if(reader.type == MfClassicType1k) {
  336. event = NfcWorkerEventDetectedClassic1k;
  337. } else {
  338. event = NfcWorkerEventDetectedClassic4k;
  339. }
  340. nfc_worker->callback(event, nfc_worker->context);
  341. break;
  342. }
  343. } else {
  344. event = NfcWorkerEventNoCardDetected;
  345. nfc_worker->callback(event, nfc_worker->context);
  346. }
  347. }
  348. if(nfc_worker->state == NfcWorkerStateReadMifareClassic) {
  349. bool card_removed_notified = false;
  350. bool card_found_notified = false;
  351. // Seek for mifare classic keys
  352. for(curr_sector = 0; curr_sector < total_sectors; curr_sector++) {
  353. FURI_LOG_I(TAG, "Sector: %d ...", curr_sector);
  354. event = NfcWorkerEventNewSector;
  355. nfc_worker->callback(event, nfc_worker->context);
  356. mf_classic_auth_init_context(&auth_ctx, reader.cuid, curr_sector);
  357. bool sector_key_found = false;
  358. while(nfc_mf_classic_dict_get_next_key(nfc_worker->dict_stream, &curr_key)) {
  359. furi_hal_nfc_sleep();
  360. if(furi_hal_nfc_activate_nfca(300, &reader.cuid)) {
  361. if(!card_found_notified) {
  362. if(reader.type == MfClassicType1k) {
  363. event = NfcWorkerEventDetectedClassic1k;
  364. } else {
  365. event = NfcWorkerEventDetectedClassic4k;
  366. }
  367. nfc_worker->callback(event, nfc_worker->context);
  368. card_found_notified = true;
  369. card_removed_notified = false;
  370. }
  371. FURI_LOG_D(
  372. TAG,
  373. "Try to auth to sector %d with key %04lx%08lx",
  374. curr_sector,
  375. (uint32_t)(curr_key >> 32),
  376. (uint32_t)curr_key);
  377. if(mf_classic_auth_attempt(&tx_rx_ctx, &auth_ctx, curr_key)) {
  378. sector_key_found = true;
  379. if((auth_ctx.key_a != MF_CLASSIC_NO_KEY) &&
  380. (auth_ctx.key_b != MF_CLASSIC_NO_KEY))
  381. break;
  382. }
  383. } else {
  384. // Notify that no tag is availalble
  385. FURI_LOG_D(TAG, "Can't find tags");
  386. if(!card_removed_notified) {
  387. event = NfcWorkerEventNoCardDetected;
  388. nfc_worker->callback(event, nfc_worker->context);
  389. card_removed_notified = true;
  390. card_found_notified = false;
  391. }
  392. }
  393. if(nfc_worker->state != NfcWorkerStateReadMifareClassic) break;
  394. osDelay(1);
  395. }
  396. if(nfc_worker->state != NfcWorkerStateReadMifareClassic) break;
  397. if(sector_key_found) {
  398. // Notify that keys were found
  399. if(auth_ctx.key_a != MF_CLASSIC_NO_KEY) {
  400. FURI_LOG_I(
  401. TAG,
  402. "Sector %d key A: %04lx%08lx",
  403. curr_sector,
  404. (uint32_t)(auth_ctx.key_a >> 32),
  405. (uint32_t)auth_ctx.key_a);
  406. event = NfcWorkerEventFoundKeyA;
  407. nfc_worker->callback(event, nfc_worker->context);
  408. }
  409. if(auth_ctx.key_b != MF_CLASSIC_NO_KEY) {
  410. FURI_LOG_I(
  411. TAG,
  412. "Sector %d key B: %04lx%08lx",
  413. curr_sector,
  414. (uint32_t)(auth_ctx.key_b >> 32),
  415. (uint32_t)auth_ctx.key_b);
  416. event = NfcWorkerEventFoundKeyB;
  417. nfc_worker->callback(event, nfc_worker->context);
  418. }
  419. // Add sectors to read sequence
  420. mf_classic_reader_add_sector(&reader, curr_sector, auth_ctx.key_a, auth_ctx.key_b);
  421. }
  422. nfc_mf_classic_dict_reset(nfc_worker->dict_stream);
  423. }
  424. }
  425. if(nfc_worker->state == NfcWorkerStateReadMifareClassic) {
  426. FURI_LOG_I(TAG, "Found keys to %d sectors. Start reading sectors", reader.sectors_to_read);
  427. uint8_t sectors_read =
  428. mf_classic_read_card(&tx_rx_ctx, &reader, &nfc_worker->dev_data->mf_classic_data);
  429. if(sectors_read) {
  430. event = NfcWorkerEventSuccess;
  431. nfc_worker->dev_data->protocol = NfcDeviceProtocolMifareClassic;
  432. FURI_LOG_I(TAG, "Successfully read %d sectors", sectors_read);
  433. } else {
  434. event = NfcWorkerEventFail;
  435. FURI_LOG_W(TAG, "Failed to read any sector");
  436. }
  437. nfc_worker->callback(event, nfc_worker->context);
  438. }
  439. nfc_mf_classic_dict_close_file(nfc_worker->dict_stream);
  440. stream_free(nfc_worker->dict_stream);
  441. }
  442. void nfc_worker_emulate_mifare_classic(NfcWorker* nfc_worker) {
  443. FuriHalNfcTxRxContext tx_rx = {};
  444. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx, true);
  445. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  446. MfClassicEmulator emulator = {
  447. .cuid = nfc_util_bytes2num(&nfc_data->uid[nfc_data->uid_len - 4], 4),
  448. .data = nfc_worker->dev_data->mf_classic_data,
  449. .data_changed = false,
  450. };
  451. NfcaSignal* nfca_signal = nfca_signal_alloc();
  452. tx_rx.nfca_signal = nfca_signal;
  453. while(nfc_worker->state == NfcWorkerStateEmulateMifareClassic) {
  454. if(furi_hal_nfc_listen(
  455. nfc_data->uid, nfc_data->uid_len, nfc_data->atqa, nfc_data->sak, true, 300)) {
  456. mf_classic_emulator(&emulator, &tx_rx);
  457. }
  458. }
  459. if(emulator.data_changed) {
  460. nfc_worker->dev_data->mf_classic_data = emulator.data;
  461. if(nfc_worker->callback) {
  462. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  463. }
  464. emulator.data_changed = false;
  465. }
  466. nfca_signal_free(nfca_signal);
  467. }
  468. void nfc_worker_read_mifare_desfire(NfcWorker* nfc_worker) {
  469. FuriHalNfcTxRxContext tx_rx = {};
  470. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx, false);
  471. NfcDeviceData* result = nfc_worker->dev_data;
  472. nfc_device_data_clear(result);
  473. MifareDesfireData* data = &result->mf_df_data;
  474. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  475. while(nfc_worker->state == NfcWorkerStateReadMifareDesfire) {
  476. furi_hal_nfc_sleep();
  477. if(!furi_hal_nfc_detect(nfc_data, 300)) {
  478. osDelay(100);
  479. continue;
  480. }
  481. memset(data, 0, sizeof(MifareDesfireData));
  482. if(nfc_data->type != FuriHalNfcTypeA ||
  483. !mf_df_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  484. FURI_LOG_D(TAG, "Tag is not DESFire");
  485. osDelay(100);
  486. continue;
  487. }
  488. FURI_LOG_D(TAG, "Found DESFire tag");
  489. result->protocol = NfcDeviceProtocolMifareDesfire;
  490. // Get DESFire version
  491. tx_rx.tx_bits = 8 * mf_df_prepare_get_version(tx_rx.tx_data);
  492. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  493. FURI_LOG_W(TAG, "Bad exchange getting version");
  494. continue;
  495. }
  496. if(!mf_df_parse_get_version_response(tx_rx.rx_data, tx_rx.rx_bits / 8, &data->version)) {
  497. FURI_LOG_W(TAG, "Bad DESFire GET_VERSION response");
  498. continue;
  499. }
  500. tx_rx.tx_bits = 8 * mf_df_prepare_get_free_memory(tx_rx.tx_data);
  501. if(furi_hal_nfc_tx_rx_full(&tx_rx)) {
  502. data->free_memory = malloc(sizeof(MifareDesfireFreeMemory));
  503. memset(data->free_memory, 0, sizeof(MifareDesfireFreeMemory));
  504. if(!mf_df_parse_get_free_memory_response(
  505. tx_rx.rx_data, tx_rx.rx_bits / 8, data->free_memory)) {
  506. FURI_LOG_D(TAG, "Bad DESFire GET_FREE_MEMORY response (normal for pre-EV1 cards)");
  507. free(data->free_memory);
  508. data->free_memory = NULL;
  509. }
  510. }
  511. tx_rx.tx_bits = 8 * mf_df_prepare_get_key_settings(tx_rx.tx_data);
  512. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  513. FURI_LOG_D(TAG, "Bad exchange getting key settings");
  514. } else {
  515. data->master_key_settings = malloc(sizeof(MifareDesfireKeySettings));
  516. memset(data->master_key_settings, 0, sizeof(MifareDesfireKeySettings));
  517. if(!mf_df_parse_get_key_settings_response(
  518. tx_rx.rx_data, tx_rx.rx_bits / 8, data->master_key_settings)) {
  519. FURI_LOG_W(TAG, "Bad DESFire GET_KEY_SETTINGS response");
  520. free(data->master_key_settings);
  521. data->master_key_settings = NULL;
  522. } else {
  523. MifareDesfireKeyVersion** key_version_head =
  524. &data->master_key_settings->key_version_head;
  525. for(uint8_t key_id = 0; key_id < data->master_key_settings->max_keys; key_id++) {
  526. tx_rx.tx_bits = 8 * mf_df_prepare_get_key_version(tx_rx.tx_data, key_id);
  527. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  528. FURI_LOG_W(TAG, "Bad exchange getting key version");
  529. continue;
  530. }
  531. MifareDesfireKeyVersion* key_version = malloc(sizeof(MifareDesfireKeyVersion));
  532. memset(key_version, 0, sizeof(MifareDesfireKeyVersion));
  533. key_version->id = key_id;
  534. if(!mf_df_parse_get_key_version_response(
  535. tx_rx.rx_data, tx_rx.rx_bits / 8, key_version)) {
  536. FURI_LOG_W(TAG, "Bad DESFire GET_KEY_VERSION response");
  537. free(key_version);
  538. continue;
  539. }
  540. *key_version_head = key_version;
  541. key_version_head = &key_version->next;
  542. }
  543. }
  544. }
  545. tx_rx.tx_bits = 8 * mf_df_prepare_get_application_ids(tx_rx.tx_data);
  546. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  547. FURI_LOG_W(TAG, "Bad exchange getting application IDs");
  548. } else {
  549. if(!mf_df_parse_get_application_ids_response(
  550. tx_rx.rx_data, tx_rx.rx_bits / 8, &data->app_head)) {
  551. FURI_LOG_W(TAG, "Bad DESFire GET_APPLICATION_IDS response");
  552. }
  553. }
  554. for(MifareDesfireApplication* app = data->app_head; app; app = app->next) {
  555. tx_rx.tx_bits = 8 * mf_df_prepare_select_application(tx_rx.tx_data, app->id);
  556. if(!furi_hal_nfc_tx_rx_full(&tx_rx) ||
  557. !mf_df_parse_select_application_response(tx_rx.rx_data, tx_rx.rx_bits / 8)) {
  558. FURI_LOG_W(TAG, "Bad exchange selecting application");
  559. continue;
  560. }
  561. tx_rx.tx_bits = 8 * mf_df_prepare_get_key_settings(tx_rx.tx_data);
  562. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  563. FURI_LOG_W(TAG, "Bad exchange getting key settings");
  564. } else {
  565. app->key_settings = malloc(sizeof(MifareDesfireKeySettings));
  566. memset(app->key_settings, 0, sizeof(MifareDesfireKeySettings));
  567. if(!mf_df_parse_get_key_settings_response(
  568. tx_rx.rx_data, tx_rx.rx_bits / 8, app->key_settings)) {
  569. FURI_LOG_W(TAG, "Bad DESFire GET_KEY_SETTINGS response");
  570. free(app->key_settings);
  571. app->key_settings = NULL;
  572. continue;
  573. }
  574. MifareDesfireKeyVersion** key_version_head = &app->key_settings->key_version_head;
  575. for(uint8_t key_id = 0; key_id < app->key_settings->max_keys; key_id++) {
  576. tx_rx.tx_bits = 8 * mf_df_prepare_get_key_version(tx_rx.tx_data, key_id);
  577. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  578. FURI_LOG_W(TAG, "Bad exchange getting key version");
  579. continue;
  580. }
  581. MifareDesfireKeyVersion* key_version = malloc(sizeof(MifareDesfireKeyVersion));
  582. memset(key_version, 0, sizeof(MifareDesfireKeyVersion));
  583. key_version->id = key_id;
  584. if(!mf_df_parse_get_key_version_response(
  585. tx_rx.rx_data, tx_rx.rx_bits / 8, key_version)) {
  586. FURI_LOG_W(TAG, "Bad DESFire GET_KEY_VERSION response");
  587. free(key_version);
  588. continue;
  589. }
  590. *key_version_head = key_version;
  591. key_version_head = &key_version->next;
  592. }
  593. }
  594. tx_rx.tx_bits = 8 * mf_df_prepare_get_file_ids(tx_rx.tx_data);
  595. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  596. FURI_LOG_W(TAG, "Bad exchange getting file IDs");
  597. } else {
  598. if(!mf_df_parse_get_file_ids_response(
  599. tx_rx.rx_data, tx_rx.rx_bits / 8, &app->file_head)) {
  600. FURI_LOG_W(TAG, "Bad DESFire GET_FILE_IDS response");
  601. }
  602. }
  603. for(MifareDesfireFile* file = app->file_head; file; file = file->next) {
  604. tx_rx.tx_bits = 8 * mf_df_prepare_get_file_settings(tx_rx.tx_data, file->id);
  605. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  606. FURI_LOG_W(TAG, "Bad exchange getting file settings");
  607. continue;
  608. }
  609. if(!mf_df_parse_get_file_settings_response(
  610. tx_rx.rx_data, tx_rx.rx_bits / 8, file)) {
  611. FURI_LOG_W(TAG, "Bad DESFire GET_FILE_SETTINGS response");
  612. continue;
  613. }
  614. switch(file->type) {
  615. case MifareDesfireFileTypeStandard:
  616. case MifareDesfireFileTypeBackup:
  617. tx_rx.tx_bits = 8 * mf_df_prepare_read_data(tx_rx.tx_data, file->id, 0, 0);
  618. break;
  619. case MifareDesfireFileTypeValue:
  620. tx_rx.tx_bits = 8 * mf_df_prepare_get_value(tx_rx.tx_data, file->id);
  621. break;
  622. case MifareDesfireFileTypeLinearRecord:
  623. case MifareDesfireFileTypeCyclicRecord:
  624. tx_rx.tx_bits = 8 * mf_df_prepare_read_records(tx_rx.tx_data, file->id, 0, 0);
  625. break;
  626. }
  627. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  628. FURI_LOG_W(TAG, "Bad exchange reading file %d", file->id);
  629. continue;
  630. }
  631. if(!mf_df_parse_read_data_response(tx_rx.rx_data, tx_rx.rx_bits / 8, file)) {
  632. FURI_LOG_W(TAG, "Bad response reading file %d", file->id);
  633. continue;
  634. }
  635. }
  636. }
  637. // Notify caller and exit
  638. if(nfc_worker->callback) {
  639. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  640. }
  641. break;
  642. }
  643. }