nfc_worker.c 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448
  1. #include "nfc_worker_i.h"
  2. #include <api-hal.h>
  3. #include "nfc_protocols/emv_decoder.h"
  4. #include "nfc_protocols/mifare_ultralight.h"
  5. #define NFC_WORKER_TAG "nfc worker"
  6. NfcWorker* nfc_worker_alloc(osMessageQueueId_t message_queue) {
  7. NfcWorker* nfc_worker = furi_alloc(sizeof(NfcWorker));
  8. nfc_worker->message_queue = message_queue;
  9. // Worker thread attributes
  10. nfc_worker->thread_attr.name = "nfc_worker";
  11. nfc_worker->thread_attr.stack_size = 8192;
  12. // Initialize rfal
  13. nfc_worker->error = api_hal_nfc_init();
  14. if(nfc_worker->error == ERR_NONE) {
  15. api_hal_nfc_start_sleep();
  16. nfc_worker_change_state(nfc_worker, NfcWorkerStateReady);
  17. } else {
  18. nfc_worker_change_state(nfc_worker, NfcWorkerStateBroken);
  19. }
  20. return nfc_worker;
  21. }
  22. void nfc_worker_free(NfcWorker* nfc_worker) {
  23. furi_assert(nfc_worker);
  24. free(nfc_worker);
  25. }
  26. NfcWorkerState nfc_worker_get_state(NfcWorker* nfc_worker) {
  27. return nfc_worker->state;
  28. }
  29. ReturnCode nfc_worker_get_error(NfcWorker* nfc_worker) {
  30. return nfc_worker->error;
  31. }
  32. void nfc_worker_start(NfcWorker* nfc_worker, NfcWorkerState state) {
  33. furi_assert(nfc_worker);
  34. furi_assert(nfc_worker->state == NfcWorkerStateReady);
  35. nfc_worker_change_state(nfc_worker, state);
  36. nfc_worker->thread = osThreadNew(nfc_worker_task, nfc_worker, &nfc_worker->thread_attr);
  37. }
  38. void nfc_worker_stop(NfcWorker* nfc_worker) {
  39. furi_assert(nfc_worker);
  40. if(nfc_worker->state == NfcWorkerStateBroken) {
  41. return;
  42. }
  43. nfc_worker_change_state(nfc_worker, NfcWorkerStateStop);
  44. }
  45. void nfc_worker_change_state(NfcWorker* nfc_worker, NfcWorkerState state) {
  46. nfc_worker->state = state;
  47. }
  48. void nfc_worker_task(void* context) {
  49. NfcWorker* nfc_worker = context;
  50. api_hal_power_insomnia_enter();
  51. api_hal_nfc_exit_sleep();
  52. if(nfc_worker->state == NfcWorkerStatePoll) {
  53. nfc_worker_poll(nfc_worker);
  54. } else if(nfc_worker->state == NfcWorkerStateReadEMV) {
  55. nfc_worker_read_emv(nfc_worker);
  56. } else if(nfc_worker->state == NfcWorkerStateEmulateEMV) {
  57. nfc_worker_emulate_emv(nfc_worker);
  58. } else if(nfc_worker->state == NfcWorkerStateEmulate) {
  59. nfc_worker_emulate(nfc_worker);
  60. } else if(nfc_worker->state == NfcWorkerStateField) {
  61. nfc_worker_field(nfc_worker);
  62. } else if(nfc_worker->state == NfcWorkerStateReadMfUltralight) {
  63. nfc_worker_read_mf_ultralight(nfc_worker);
  64. }
  65. api_hal_nfc_deactivate();
  66. nfc_worker_change_state(nfc_worker, NfcWorkerStateReady);
  67. api_hal_power_insomnia_exit();
  68. osThreadExit();
  69. }
  70. void nfc_worker_read_emv(NfcWorker* nfc_worker) {
  71. ReturnCode err;
  72. rfalNfcDevice* dev_list;
  73. EmvApplication emv_app = {};
  74. uint8_t dev_cnt = 0;
  75. uint8_t tx_buff[255] = {};
  76. uint16_t tx_len = 0;
  77. uint8_t* rx_buff;
  78. uint16_t* rx_len;
  79. // Update screen before start searching
  80. NfcMessage message = {.type = NfcMessageTypeEMVNotFound};
  81. while(nfc_worker->state == NfcWorkerStateReadEMV) {
  82. furi_check(
  83. osMessageQueuePut(nfc_worker->message_queue, &message, 0, osWaitForever) == osOK);
  84. memset(&emv_app, 0, sizeof(emv_app));
  85. if(api_hal_nfc_detect(&dev_list, &dev_cnt, 100, false)) {
  86. // Card was found. Check that it supports EMV
  87. if(dev_list[0].rfInterface == RFAL_NFC_INTERFACE_ISODEP) {
  88. FURI_LOG_I(NFC_WORKER_TAG, "Send select PPSE command");
  89. tx_len = emv_prepare_select_ppse(tx_buff);
  90. err = api_hal_nfc_data_exchange(tx_buff, tx_len, &rx_buff, &rx_len, false);
  91. if(err != ERR_NONE) {
  92. FURI_LOG_E(NFC_WORKER_TAG, "Error during selection PPSE request: %d", err);
  93. message.type = NfcMessageTypeEMVNotFound;
  94. api_hal_nfc_deactivate();
  95. continue;
  96. }
  97. FURI_LOG_I(
  98. NFC_WORKER_TAG, "Select PPSE response received. Start parsing response");
  99. if(emv_decode_ppse_response(rx_buff, *rx_len, &emv_app)) {
  100. FURI_LOG_I(NFC_WORKER_TAG, "Select PPSE responce parced");
  101. } else {
  102. FURI_LOG_E(NFC_WORKER_TAG, "Can't find pay application");
  103. message.type = NfcMessageTypeEMVNotFound;
  104. api_hal_nfc_deactivate();
  105. continue;
  106. }
  107. FURI_LOG_I(NFC_WORKER_TAG, "Starting application ...");
  108. tx_len = emv_prepare_select_app(tx_buff, &emv_app);
  109. err = api_hal_nfc_data_exchange(tx_buff, tx_len, &rx_buff, &rx_len, false);
  110. if(err != ERR_NONE) {
  111. FURI_LOG_E(
  112. NFC_WORKER_TAG, "Error during application selection request: %d", err);
  113. message.type = NfcMessageTypeEMVNotFound;
  114. api_hal_nfc_deactivate();
  115. continue;
  116. }
  117. FURI_LOG_I(
  118. NFC_WORKER_TAG,
  119. "Select application response received. Start parsing response");
  120. if(emv_decode_select_app_response(rx_buff, *rx_len, &emv_app)) {
  121. FURI_LOG_I(NFC_WORKER_TAG, "Card name: %s", emv_app.name);
  122. memcpy(message.device.emv_card.name, emv_app.name, sizeof(emv_app.name));
  123. } else {
  124. FURI_LOG_E(NFC_WORKER_TAG, "Can't read card name");
  125. message.type = NfcMessageTypeEMVNotFound;
  126. api_hal_nfc_deactivate();
  127. continue;
  128. }
  129. FURI_LOG_I(NFC_WORKER_TAG, "Starting Get Processing Options command ...");
  130. tx_len = emv_prepare_get_proc_opt(tx_buff, &emv_app);
  131. err = api_hal_nfc_data_exchange(tx_buff, tx_len, &rx_buff, &rx_len, false);
  132. if(err != ERR_NONE) {
  133. FURI_LOG_E(
  134. NFC_WORKER_TAG, "Error during Get Processing Options command: %d", err);
  135. message.type = NfcMessageTypeEMVNotFound;
  136. api_hal_nfc_deactivate();
  137. continue;
  138. }
  139. if(emv_decode_get_proc_opt(rx_buff, *rx_len, &emv_app)) {
  140. FURI_LOG_I(NFC_WORKER_TAG, "Card number parsed");
  141. message.type = NfcMessageTypeEMVFound;
  142. memcpy(
  143. message.device.emv_card.number,
  144. emv_app.card_number,
  145. sizeof(emv_app.card_number));
  146. api_hal_nfc_deactivate();
  147. continue;
  148. } else {
  149. // Mastercard doesn't give PAN / card number as GPO response
  150. // Iterate over all files found in application
  151. bool pan_found = false;
  152. for(uint8_t i = 0; (i < emv_app.afl.size) && !pan_found; i += 4) {
  153. uint8_t sfi = emv_app.afl.data[i] >> 3;
  154. uint8_t record_start = emv_app.afl.data[i + 1];
  155. uint8_t record_end = emv_app.afl.data[i + 2];
  156. // Iterate over all records in file
  157. for(uint8_t record = record_start; record <= record_end; ++record) {
  158. tx_len = emv_prepare_read_sfi_record(tx_buff, sfi, record);
  159. err = api_hal_nfc_data_exchange(
  160. tx_buff, tx_len, &rx_buff, &rx_len, false);
  161. if(err != ERR_NONE) {
  162. FURI_LOG_E(
  163. NFC_WORKER_TAG,
  164. "Error reading application sfi %d, record %d",
  165. sfi,
  166. record);
  167. }
  168. if(emv_decode_read_sfi_record(rx_buff, *rx_len, &emv_app)) {
  169. pan_found = true;
  170. break;
  171. }
  172. }
  173. }
  174. if(pan_found) {
  175. FURI_LOG_I(NFC_WORKER_TAG, "Card PAN found");
  176. message.type = NfcMessageTypeEMVFound;
  177. memcpy(
  178. message.device.emv_card.number,
  179. emv_app.card_number,
  180. sizeof(emv_app.card_number));
  181. } else {
  182. FURI_LOG_E(NFC_WORKER_TAG, "Can't read card number");
  183. message.type = NfcMessageTypeEMVNotFound;
  184. }
  185. api_hal_nfc_deactivate();
  186. }
  187. } else {
  188. // Can't find EMV card
  189. FURI_LOG_W(NFC_WORKER_TAG, "Card doesn't support EMV");
  190. message.type = NfcMessageTypeEMVNotFound;
  191. api_hal_nfc_deactivate();
  192. }
  193. } else {
  194. // Can't find EMV card
  195. FURI_LOG_W(NFC_WORKER_TAG, "Can't find any cards");
  196. message.type = NfcMessageTypeEMVNotFound;
  197. api_hal_nfc_deactivate();
  198. }
  199. osDelay(20);
  200. }
  201. }
  202. void nfc_worker_emulate_emv(NfcWorker* nfc_worker) {
  203. ReturnCode err;
  204. uint8_t tx_buff[255] = {};
  205. uint16_t tx_len = 0;
  206. uint8_t* rx_buff;
  207. uint16_t* rx_len;
  208. while(nfc_worker->state == NfcWorkerStateEmulateEMV) {
  209. if(api_hal_nfc_listen(1000)) {
  210. FURI_LOG_I(NFC_WORKER_TAG, "POS terminal detected");
  211. // Read data from POS terminal
  212. err = api_hal_nfc_data_exchange(NULL, 0, &rx_buff, &rx_len, false);
  213. if(err == ERR_NONE) {
  214. FURI_LOG_I(NFC_WORKER_TAG, "Received Select PPSE");
  215. } else {
  216. FURI_LOG_E(NFC_WORKER_TAG, "Error in 1st data exchange: select PPSE");
  217. api_hal_nfc_deactivate();
  218. continue;
  219. }
  220. FURI_LOG_I(NFC_WORKER_TAG, "Transive SELECT PPSE ANS");
  221. tx_len = emv_select_ppse_ans(tx_buff);
  222. err = api_hal_nfc_data_exchange(tx_buff, tx_len, &rx_buff, &rx_len, false);
  223. if(err == ERR_NONE) {
  224. FURI_LOG_I(NFC_WORKER_TAG, "Received Select APP");
  225. } else {
  226. FURI_LOG_E(NFC_WORKER_TAG, "Error in 2nd data exchange: select APP");
  227. api_hal_nfc_deactivate();
  228. continue;
  229. }
  230. FURI_LOG_I(NFC_WORKER_TAG, "Transive SELECT APP ANS");
  231. tx_len = emv_select_app_ans(tx_buff);
  232. err = api_hal_nfc_data_exchange(tx_buff, tx_len, &rx_buff, &rx_len, false);
  233. if(err == ERR_NONE) {
  234. FURI_LOG_I(NFC_WORKER_TAG, "Received PDOL");
  235. } else {
  236. FURI_LOG_E(NFC_WORKER_TAG, "Error in 3rd data exchange: receive PDOL");
  237. api_hal_nfc_deactivate();
  238. continue;
  239. }
  240. FURI_LOG_I(NFC_WORKER_TAG, "Transive PDOL ANS");
  241. tx_len = emv_get_proc_opt_ans(tx_buff);
  242. err = api_hal_nfc_data_exchange(tx_buff, tx_len, &rx_buff, &rx_len, false);
  243. if(err == ERR_NONE) {
  244. FURI_LOG_I(NFC_WORKER_TAG, "Received PDOL");
  245. }
  246. api_hal_nfc_deactivate();
  247. } else {
  248. FURI_LOG_W(NFC_WORKER_TAG, "Can't find reader");
  249. }
  250. osDelay(20);
  251. }
  252. }
  253. void nfc_worker_poll(NfcWorker* nfc_worker) {
  254. rfalNfcDevice* dev_list;
  255. uint8_t dev_cnt;
  256. // Update screen before start searching
  257. NfcMessage message = {.type = NfcMessageTypeDeviceNotFound};
  258. furi_check(osMessageQueuePut(nfc_worker->message_queue, &message, 0, osWaitForever) == osOK);
  259. while(nfc_worker->state == NfcWorkerStatePoll) {
  260. if(api_hal_nfc_detect(&dev_list, &dev_cnt, 100, true)) {
  261. // Send message with first device found
  262. message.type = NfcMessageTypeDeviceFound;
  263. if(dev_list[0].type == RFAL_NFC_LISTEN_TYPE_NFCA) {
  264. message.device.type = NfcDeviceTypeNfca;
  265. message.device.nfca = dev_list[0].dev.nfca;
  266. } else if(dev_list[0].type == RFAL_NFC_LISTEN_TYPE_NFCB) {
  267. message.device.type = NfcDeviceTypeNfcb;
  268. message.device.nfcb = dev_list[0].dev.nfcb;
  269. } else if(dev_list[0].type == RFAL_NFC_LISTEN_TYPE_NFCF) {
  270. message.device.type = NfcDeviceTypeNfcf;
  271. message.device.nfcf = dev_list[0].dev.nfcf;
  272. } else if(dev_list[0].type == RFAL_NFC_LISTEN_TYPE_NFCV) {
  273. message.device.type = NfcDeviceTypeNfcv;
  274. message.device.nfcv = dev_list[0].dev.nfcv;
  275. } else {
  276. // TODO show information about all found devices
  277. message.type = NfcMessageTypeDeviceNotFound;
  278. }
  279. furi_check(
  280. osMessageQueuePut(nfc_worker->message_queue, &message, 0, osWaitForever) == osOK);
  281. } else {
  282. message.type = NfcMessageTypeDeviceNotFound;
  283. furi_check(
  284. osMessageQueuePut(nfc_worker->message_queue, &message, 0, osWaitForever) == osOK);
  285. }
  286. osDelay(5);
  287. }
  288. }
  289. void nfc_worker_read_mf_ultralight(NfcWorker* nfc_worker) {
  290. ReturnCode err;
  291. rfalNfcDevice* dev_list;
  292. uint8_t dev_cnt = 0;
  293. uint8_t tx_buff[255] = {};
  294. uint16_t tx_len = 0;
  295. uint8_t* rx_buff;
  296. uint16_t* rx_len;
  297. MfUltralightRead mf_ul_read;
  298. // Update screen before start searching
  299. NfcMessage message = {.type = NfcMessageTypeMfUlNotFound};
  300. while(nfc_worker->state == NfcWorkerStateReadMfUltralight) {
  301. furi_check(
  302. osMessageQueuePut(nfc_worker->message_queue, &message, 0, osWaitForever) == osOK);
  303. api_hal_nfc_deactivate();
  304. memset(&mf_ul_read, 0, sizeof(mf_ul_read));
  305. if(api_hal_nfc_detect(&dev_list, &dev_cnt, 100, false)) {
  306. if(dev_list[0].type == RFAL_NFC_LISTEN_TYPE_NFCA &&
  307. mf_ul_check_card_type(
  308. dev_list[0].dev.nfca.sensRes.anticollisionInfo,
  309. dev_list[0].dev.nfca.sensRes.platformInfo,
  310. dev_list[0].dev.nfca.selRes.sak)) {
  311. // Get Mifare Ultralight version
  312. FURI_LOG_I(
  313. NFC_WORKER_TAG, "Found Mifare Ultralight tag. Trying to get tag version");
  314. tx_len = mf_ul_prepare_get_version(tx_buff);
  315. err = api_hal_nfc_data_exchange(tx_buff, tx_len, &rx_buff, &rx_len, false);
  316. if(err == ERR_NONE) {
  317. mf_ul_parse_get_version_response(rx_buff, &mf_ul_read);
  318. FURI_LOG_I(
  319. NFC_WORKER_TAG,
  320. "Mifare Ultralight Type: %d, Pages: %d",
  321. mf_ul_read.type,
  322. mf_ul_read.pages_to_read);
  323. } else if(err == ERR_TIMEOUT) {
  324. FURI_LOG_W(
  325. NFC_WORKER_TAG,
  326. "Card doesn't respond to GET VERSION command. Reinit card and set default read parameters");
  327. err = ERR_NONE;
  328. mf_ul_set_default_version(&mf_ul_read);
  329. // Reinit device
  330. api_hal_nfc_deactivate();
  331. if(!api_hal_nfc_detect(&dev_list, &dev_cnt, 100, false)) {
  332. FURI_LOG_E(NFC_WORKER_TAG, "Lost connection. Restarting search");
  333. message.type = NfcMessageTypeMfUlNotFound;
  334. continue;
  335. }
  336. } else {
  337. FURI_LOG_E(
  338. NFC_WORKER_TAG,
  339. "Error getting Mifare Ultralight version. Error code: %d",
  340. err);
  341. message.type = NfcMessageTypeMfUlNotFound;
  342. continue;
  343. }
  344. // Dump Mifare Ultralight card
  345. FURI_LOG_I(NFC_WORKER_TAG, "Trying to read pages");
  346. if(mf_ul_read.support_fast_read) {
  347. // Read card with FAST_READ command
  348. tx_len = mf_ul_prepare_fast_read(tx_buff, 0x00, mf_ul_read.pages_to_read - 1);
  349. err = api_hal_nfc_data_exchange(tx_buff, tx_len, &rx_buff, &rx_len, false);
  350. if(err == ERR_NONE) {
  351. FURI_LOG_I(
  352. NFC_WORKER_TAG,
  353. "Fast read pages %d - %d succeed",
  354. 0,
  355. mf_ul_read.pages_to_read - 1);
  356. memcpy(mf_ul_read.dump, rx_buff, mf_ul_read.pages_to_read * 4);
  357. mf_ul_read.pages_readed = mf_ul_read.pages_to_read;
  358. } else {
  359. FURI_LOG_E(NFC_WORKER_TAG, "Fast read failed");
  360. message.type = NfcMessageTypeMfUlNotFound;
  361. continue;
  362. }
  363. } else {
  364. // READ card with READ command (4 pages at a time)
  365. for(uint8_t page = 0; page < mf_ul_read.pages_to_read; page += 4) {
  366. tx_len = mf_ul_prepare_read(tx_buff, page);
  367. err = api_hal_nfc_data_exchange(tx_buff, tx_len, &rx_buff, &rx_len, false);
  368. if(err == ERR_NONE) {
  369. FURI_LOG_I(
  370. NFC_WORKER_TAG, "Read pages %d - %d succeed", page, page + 3);
  371. memcpy(&mf_ul_read.dump[page * 4], rx_buff, 4 * 4);
  372. mf_ul_read.pages_readed += 4;
  373. } else {
  374. FURI_LOG_W(
  375. NFC_WORKER_TAG, "Read pages %d - %d failed", page, page + 3);
  376. }
  377. }
  378. }
  379. // Fill message for nfc application
  380. message.type = NfcMessageTypeMfUlFound;
  381. memcpy(
  382. message.device.mf_ul_card.uid,
  383. dev_list[0].dev.nfca.nfcId1,
  384. sizeof(message.device.mf_ul_card.uid));
  385. memcpy(message.device.mf_ul_card.man_block, mf_ul_read.dump, 4 * 3);
  386. memcpy(message.device.mf_ul_card.otp, &mf_ul_read.dump[4 * 3], 4);
  387. for(uint8_t i = 0; i < mf_ul_read.pages_readed * 4; i += 4) {
  388. printf("Page %2d: ", i / 4);
  389. for(uint8_t j = 0; j < 4; j++) {
  390. printf("%02X ", mf_ul_read.dump[i + j]);
  391. }
  392. printf("\r\n");
  393. }
  394. } else {
  395. message.type = NfcMessageTypeMfUlNotFound;
  396. FURI_LOG_W(NFC_WORKER_TAG, "Tag does not support Mifare Ultralight");
  397. }
  398. } else {
  399. message.type = NfcMessageTypeMfUlNotFound;
  400. FURI_LOG_W(NFC_WORKER_TAG, "Can't find any tags");
  401. }
  402. osDelay(100);
  403. }
  404. }
  405. void nfc_worker_emulate(NfcWorker* nfc_worker) {
  406. while(nfc_worker->state == NfcWorkerStateEmulate) {
  407. if(api_hal_nfc_listen(100)) {
  408. FURI_LOG_I(NFC_WORKER_TAG, "Reader detected");
  409. api_hal_nfc_deactivate();
  410. }
  411. osDelay(5);
  412. }
  413. }
  414. void nfc_worker_field(NfcWorker* nfc_worker) {
  415. api_hal_nfc_field_on();
  416. while(nfc_worker->state == NfcWorkerStateField) {
  417. osDelay(50);
  418. }
  419. api_hal_nfc_field_off();
  420. }