keeloq.c 28 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718
  1. #include "keeloq.h"
  2. #include "keeloq_common.h"
  3. #include "../subghz_keystore.h"
  4. #include <m-string.h>
  5. #include <m-array.h>
  6. #include "../blocks/const.h"
  7. #include "../blocks/decoder.h"
  8. #include "../blocks/encoder.h"
  9. #include "../blocks/generic.h"
  10. #include "../blocks/math.h"
  11. #define TAG "SubGhzProtocolKeeloq"
  12. static const SubGhzBlockConst subghz_protocol_keeloq_const = {
  13. .te_short = 400,
  14. .te_long = 800,
  15. .te_delta = 140,
  16. .min_count_bit_for_found = 64,
  17. };
  18. struct SubGhzProtocolDecoderKeeloq {
  19. SubGhzProtocolDecoderBase base;
  20. SubGhzBlockDecoder decoder;
  21. SubGhzBlockGeneric generic;
  22. uint16_t header_count;
  23. SubGhzKeystore* keystore;
  24. const char* manufacture_name;
  25. };
  26. struct SubGhzProtocolEncoderKeeloq {
  27. SubGhzProtocolEncoderBase base;
  28. SubGhzProtocolBlockEncoder encoder;
  29. SubGhzBlockGeneric generic;
  30. SubGhzKeystore* keystore;
  31. const char* manufacture_name;
  32. };
  33. typedef enum {
  34. KeeloqDecoderStepReset = 0,
  35. KeeloqDecoderStepCheckPreambula,
  36. KeeloqDecoderStepSaveDuration,
  37. KeeloqDecoderStepCheckDuration,
  38. } KeeloqDecoderStep;
  39. const SubGhzProtocolDecoder subghz_protocol_keeloq_decoder = {
  40. .alloc = subghz_protocol_decoder_keeloq_alloc,
  41. .free = subghz_protocol_decoder_keeloq_free,
  42. .feed = subghz_protocol_decoder_keeloq_feed,
  43. .reset = subghz_protocol_decoder_keeloq_reset,
  44. .get_hash_data = subghz_protocol_decoder_keeloq_get_hash_data,
  45. .serialize = subghz_protocol_decoder_keeloq_serialize,
  46. .deserialize = subghz_protocol_decoder_keeloq_deserialize,
  47. .get_string = subghz_protocol_decoder_keeloq_get_string,
  48. };
  49. const SubGhzProtocolEncoder subghz_protocol_keeloq_encoder = {
  50. .alloc = subghz_protocol_encoder_keeloq_alloc,
  51. .free = subghz_protocol_encoder_keeloq_free,
  52. .deserialize = subghz_protocol_encoder_keeloq_deserialize,
  53. .stop = subghz_protocol_encoder_keeloq_stop,
  54. .yield = subghz_protocol_encoder_keeloq_yield,
  55. };
  56. const SubGhzProtocol subghz_protocol_keeloq = {
  57. .name = SUBGHZ_PROTOCOL_KEELOQ_NAME,
  58. .type = SubGhzProtocolTypeDynamic,
  59. .flag = SubGhzProtocolFlag_433 | SubGhzProtocolFlag_868 | SubGhzProtocolFlag_315 |
  60. SubGhzProtocolFlag_AM | SubGhzProtocolFlag_Decodable | SubGhzProtocolFlag_Load |
  61. SubGhzProtocolFlag_Send,
  62. .decoder = &subghz_protocol_keeloq_decoder,
  63. .encoder = &subghz_protocol_keeloq_encoder,
  64. };
  65. /**
  66. * Analysis of received data
  67. * @param instance Pointer to a SubGhzBlockGeneric* instance
  68. * @param keystore Pointer to a SubGhzKeystore* instance
  69. * @param manufacture_name
  70. */
  71. static void subghz_protocol_keeloq_check_remote_controller(
  72. SubGhzBlockGeneric* instance,
  73. SubGhzKeystore* keystore,
  74. const char** manufacture_name);
  75. void* subghz_protocol_encoder_keeloq_alloc(SubGhzEnvironment* environment) {
  76. SubGhzProtocolEncoderKeeloq* instance = malloc(sizeof(SubGhzProtocolEncoderKeeloq));
  77. instance->base.protocol = &subghz_protocol_keeloq;
  78. instance->generic.protocol_name = instance->base.protocol->name;
  79. instance->keystore = subghz_environment_get_keystore(environment);
  80. instance->encoder.repeat = 10;
  81. instance->encoder.size_upload = 256;
  82. instance->encoder.upload = malloc(instance->encoder.size_upload * sizeof(LevelDuration));
  83. instance->encoder.is_running = false;
  84. return instance;
  85. }
  86. void subghz_protocol_encoder_keeloq_free(void* context) {
  87. furi_assert(context);
  88. SubGhzProtocolEncoderKeeloq* instance = context;
  89. free(instance->encoder.upload);
  90. free(instance);
  91. }
  92. /**
  93. * Key generation from simple data
  94. * @param instance Pointer to a SubGhzProtocolEncoderKeeloq* instance
  95. * @param btn Button number, 4 bit
  96. */
  97. static bool subghz_protocol_keeloq_gen_data(SubGhzProtocolEncoderKeeloq* instance, uint8_t btn) {
  98. instance->generic.cnt++;
  99. uint32_t fix = btn << 28 | instance->generic.serial;
  100. uint32_t decrypt = btn << 28 |
  101. (instance->generic.serial & 0x3FF)
  102. << 16 | //ToDo in some protocols the discriminator is 0
  103. instance->generic.cnt;
  104. uint32_t hop = 0;
  105. uint64_t man = 0;
  106. int res = 0;
  107. for
  108. M_EACH(manufacture_code, *subghz_keystore_get_data(instance->keystore), SubGhzKeyArray_t) {
  109. res = strcmp(string_get_cstr(manufacture_code->name), instance->manufacture_name);
  110. if(res == 0) {
  111. switch(manufacture_code->type) {
  112. case KEELOQ_LEARNING_SIMPLE:
  113. //Simple Learning
  114. hop = subghz_protocol_keeloq_common_encrypt(decrypt, manufacture_code->key);
  115. break;
  116. case KEELOQ_LEARNING_NORMAL:
  117. //Simple Learning
  118. man =
  119. subghz_protocol_keeloq_common_normal_learning(fix, manufacture_code->key);
  120. hop = subghz_protocol_keeloq_common_encrypt(decrypt, man);
  121. break;
  122. case KEELOQ_LEARNING_MAGIC_XOR_TYPE_1:
  123. man = subghz_protocol_keeloq_common_magic_xor_type1_learning(
  124. instance->generic.serial, manufacture_code->key);
  125. hop = subghz_protocol_keeloq_common_encrypt(decrypt, man);
  126. break;
  127. case KEELOQ_LEARNING_UNKNOWN:
  128. hop = 0; //todo
  129. break;
  130. }
  131. break;
  132. }
  133. }
  134. if(hop) {
  135. uint64_t yek = (uint64_t)fix << 32 | hop;
  136. instance->generic.data =
  137. subghz_protocol_blocks_reverse_key(yek, instance->generic.data_count_bit);
  138. return true;
  139. } else {
  140. instance->manufacture_name = "Unknown";
  141. return false;
  142. }
  143. }
  144. bool subghz_protocol_keeloq_create_data(
  145. void* context,
  146. FlipperFormat* flipper_format,
  147. uint32_t serial,
  148. uint8_t btn,
  149. uint16_t cnt,
  150. const char* manufacture_name,
  151. SubGhzPresetDefinition* preset) {
  152. furi_assert(context);
  153. SubGhzProtocolEncoderKeeloq* instance = context;
  154. instance->generic.serial = serial;
  155. instance->generic.cnt = cnt;
  156. instance->manufacture_name = manufacture_name;
  157. instance->generic.data_count_bit = 64;
  158. bool res = subghz_protocol_keeloq_gen_data(instance, btn);
  159. if(res) {
  160. res = subghz_block_generic_serialize(&instance->generic, flipper_format, preset);
  161. }
  162. return res;
  163. }
  164. /**
  165. * Generating an upload from data.
  166. * @param instance Pointer to a SubGhzProtocolEncoderKeeloq instance
  167. * @return true On success
  168. */
  169. static bool
  170. subghz_protocol_encoder_keeloq_get_upload(SubGhzProtocolEncoderKeeloq* instance, uint8_t btn) {
  171. furi_assert(instance);
  172. //gen new key
  173. if(subghz_protocol_keeloq_gen_data(instance, btn)) {
  174. //ToDo if you need to add a callback to automatically update the data on the display
  175. } else {
  176. return false;
  177. }
  178. size_t index = 0;
  179. size_t size_upload = 11 * 2 + 2 + (instance->generic.data_count_bit * 2) + 4;
  180. if(size_upload > instance->encoder.size_upload) {
  181. FURI_LOG_E(TAG, "Size upload exceeds allocated encoder buffer.");
  182. return false;
  183. } else {
  184. instance->encoder.size_upload = size_upload;
  185. }
  186. //Send header
  187. for(uint8_t i = 11; i > 0; i--) {
  188. instance->encoder.upload[index++] =
  189. level_duration_make(true, (uint32_t)subghz_protocol_keeloq_const.te_short);
  190. instance->encoder.upload[index++] =
  191. level_duration_make(false, (uint32_t)subghz_protocol_keeloq_const.te_short);
  192. }
  193. instance->encoder.upload[index++] =
  194. level_duration_make(true, (uint32_t)subghz_protocol_keeloq_const.te_short);
  195. instance->encoder.upload[index++] =
  196. level_duration_make(false, (uint32_t)subghz_protocol_keeloq_const.te_short * 10);
  197. //Send key data
  198. for(uint8_t i = instance->generic.data_count_bit; i > 0; i--) {
  199. if(bit_read(instance->generic.data, i - 1)) {
  200. //send bit 1
  201. instance->encoder.upload[index++] =
  202. level_duration_make(true, (uint32_t)subghz_protocol_keeloq_const.te_short);
  203. instance->encoder.upload[index++] =
  204. level_duration_make(false, (uint32_t)subghz_protocol_keeloq_const.te_long);
  205. } else {
  206. //send bit 0
  207. instance->encoder.upload[index++] =
  208. level_duration_make(true, (uint32_t)subghz_protocol_keeloq_const.te_long);
  209. instance->encoder.upload[index++] =
  210. level_duration_make(false, (uint32_t)subghz_protocol_keeloq_const.te_short);
  211. }
  212. }
  213. // +send 2 status bit
  214. instance->encoder.upload[index++] =
  215. level_duration_make(true, (uint32_t)subghz_protocol_keeloq_const.te_short);
  216. instance->encoder.upload[index++] =
  217. level_duration_make(false, (uint32_t)subghz_protocol_keeloq_const.te_long);
  218. // send end
  219. instance->encoder.upload[index++] =
  220. level_duration_make(true, (uint32_t)subghz_protocol_keeloq_const.te_short);
  221. instance->encoder.upload[index++] =
  222. level_duration_make(false, (uint32_t)subghz_protocol_keeloq_const.te_short * 40);
  223. return true;
  224. }
  225. bool subghz_protocol_encoder_keeloq_deserialize(void* context, FlipperFormat* flipper_format) {
  226. furi_assert(context);
  227. SubGhzProtocolEncoderKeeloq* instance = context;
  228. bool res = false;
  229. do {
  230. if(!subghz_block_generic_deserialize(&instance->generic, flipper_format)) {
  231. FURI_LOG_E(TAG, "Deserialize error");
  232. break;
  233. }
  234. if(instance->generic.data_count_bit !=
  235. subghz_protocol_keeloq_const.min_count_bit_for_found) {
  236. FURI_LOG_E(TAG, "Wrong number of bits in key");
  237. break;
  238. }
  239. subghz_protocol_keeloq_check_remote_controller(
  240. &instance->generic, instance->keystore, &instance->manufacture_name);
  241. if(strcmp(instance->manufacture_name, "DoorHan")) {
  242. break;
  243. }
  244. //optional parameter parameter
  245. flipper_format_read_uint32(
  246. flipper_format, "Repeat", (uint32_t*)&instance->encoder.repeat, 1);
  247. if(!subghz_protocol_encoder_keeloq_get_upload(instance, instance->generic.btn)) break;
  248. if(!flipper_format_rewind(flipper_format)) {
  249. FURI_LOG_E(TAG, "Rewind error");
  250. break;
  251. }
  252. uint8_t key_data[sizeof(uint64_t)] = {0};
  253. for(size_t i = 0; i < sizeof(uint64_t); i++) {
  254. key_data[sizeof(uint64_t) - i - 1] = (instance->generic.data >> i * 8) & 0xFF;
  255. }
  256. if(!flipper_format_update_hex(flipper_format, "Key", key_data, sizeof(uint64_t))) {
  257. FURI_LOG_E(TAG, "Unable to add Key");
  258. break;
  259. }
  260. instance->encoder.is_running = true;
  261. res = true;
  262. } while(false);
  263. return res;
  264. }
  265. void subghz_protocol_encoder_keeloq_stop(void* context) {
  266. SubGhzProtocolEncoderKeeloq* instance = context;
  267. instance->encoder.is_running = false;
  268. }
  269. LevelDuration subghz_protocol_encoder_keeloq_yield(void* context) {
  270. SubGhzProtocolEncoderKeeloq* instance = context;
  271. if(instance->encoder.repeat == 0 || !instance->encoder.is_running) {
  272. instance->encoder.is_running = false;
  273. return level_duration_reset();
  274. }
  275. LevelDuration ret = instance->encoder.upload[instance->encoder.front];
  276. if(++instance->encoder.front == instance->encoder.size_upload) {
  277. instance->encoder.repeat--;
  278. instance->encoder.front = 0;
  279. }
  280. return ret;
  281. }
  282. void* subghz_protocol_decoder_keeloq_alloc(SubGhzEnvironment* environment) {
  283. SubGhzProtocolDecoderKeeloq* instance = malloc(sizeof(SubGhzProtocolDecoderKeeloq));
  284. instance->base.protocol = &subghz_protocol_keeloq;
  285. instance->generic.protocol_name = instance->base.protocol->name;
  286. instance->keystore = subghz_environment_get_keystore(environment);
  287. return instance;
  288. }
  289. void subghz_protocol_decoder_keeloq_free(void* context) {
  290. furi_assert(context);
  291. SubGhzProtocolDecoderKeeloq* instance = context;
  292. free(instance);
  293. }
  294. void subghz_protocol_decoder_keeloq_reset(void* context) {
  295. furi_assert(context);
  296. SubGhzProtocolDecoderKeeloq* instance = context;
  297. instance->decoder.parser_step = KeeloqDecoderStepReset;
  298. }
  299. void subghz_protocol_decoder_keeloq_feed(void* context, bool level, uint32_t duration) {
  300. furi_assert(context);
  301. SubGhzProtocolDecoderKeeloq* instance = context;
  302. switch(instance->decoder.parser_step) {
  303. case KeeloqDecoderStepReset:
  304. if((level) && DURATION_DIFF(duration, subghz_protocol_keeloq_const.te_short) <
  305. subghz_protocol_keeloq_const.te_delta) {
  306. instance->decoder.parser_step = KeeloqDecoderStepCheckPreambula;
  307. instance->header_count++;
  308. }
  309. break;
  310. case KeeloqDecoderStepCheckPreambula:
  311. if((!level) && (DURATION_DIFF(duration, subghz_protocol_keeloq_const.te_short) <
  312. subghz_protocol_keeloq_const.te_delta)) {
  313. instance->decoder.parser_step = KeeloqDecoderStepReset;
  314. break;
  315. }
  316. if((instance->header_count > 2) &&
  317. (DURATION_DIFF(duration, subghz_protocol_keeloq_const.te_short * 10) <
  318. subghz_protocol_keeloq_const.te_delta * 10)) {
  319. // Found header
  320. instance->decoder.parser_step = KeeloqDecoderStepSaveDuration;
  321. instance->decoder.decode_data = 0;
  322. instance->decoder.decode_count_bit = 0;
  323. } else {
  324. instance->decoder.parser_step = KeeloqDecoderStepReset;
  325. instance->header_count = 0;
  326. }
  327. break;
  328. case KeeloqDecoderStepSaveDuration:
  329. if(level) {
  330. instance->decoder.te_last = duration;
  331. instance->decoder.parser_step = KeeloqDecoderStepCheckDuration;
  332. }
  333. break;
  334. case KeeloqDecoderStepCheckDuration:
  335. if(!level) {
  336. if(duration >= ((uint32_t)subghz_protocol_keeloq_const.te_short * 2 +
  337. subghz_protocol_keeloq_const.te_delta)) {
  338. // Found end TX
  339. instance->decoder.parser_step = KeeloqDecoderStepReset;
  340. if(instance->decoder.decode_count_bit >=
  341. subghz_protocol_keeloq_const.min_count_bit_for_found) {
  342. if(instance->generic.data != instance->decoder.decode_data) {
  343. instance->generic.data = instance->decoder.decode_data;
  344. instance->generic.data_count_bit = instance->decoder.decode_count_bit;
  345. if(instance->base.callback)
  346. instance->base.callback(&instance->base, instance->base.context);
  347. }
  348. instance->decoder.decode_data = 0;
  349. instance->decoder.decode_count_bit = 0;
  350. instance->header_count = 0;
  351. }
  352. break;
  353. } else if(
  354. (DURATION_DIFF(instance->decoder.te_last, subghz_protocol_keeloq_const.te_short) <
  355. subghz_protocol_keeloq_const.te_delta) &&
  356. (DURATION_DIFF(duration, subghz_protocol_keeloq_const.te_long) <
  357. subghz_protocol_keeloq_const.te_delta * 2)) {
  358. if(instance->decoder.decode_count_bit <
  359. subghz_protocol_keeloq_const.min_count_bit_for_found) {
  360. subghz_protocol_blocks_add_bit(&instance->decoder, 1);
  361. }
  362. instance->decoder.parser_step = KeeloqDecoderStepSaveDuration;
  363. } else if(
  364. (DURATION_DIFF(instance->decoder.te_last, subghz_protocol_keeloq_const.te_long) <
  365. subghz_protocol_keeloq_const.te_delta * 2) &&
  366. (DURATION_DIFF(duration, subghz_protocol_keeloq_const.te_short) <
  367. subghz_protocol_keeloq_const.te_delta)) {
  368. if(instance->decoder.decode_count_bit <
  369. subghz_protocol_keeloq_const.min_count_bit_for_found) {
  370. subghz_protocol_blocks_add_bit(&instance->decoder, 0);
  371. }
  372. instance->decoder.parser_step = KeeloqDecoderStepSaveDuration;
  373. } else {
  374. instance->decoder.parser_step = KeeloqDecoderStepReset;
  375. instance->header_count = 0;
  376. }
  377. } else {
  378. instance->decoder.parser_step = KeeloqDecoderStepReset;
  379. instance->header_count = 0;
  380. }
  381. break;
  382. }
  383. }
  384. /**
  385. * Validation of decrypt data.
  386. * @param instance Pointer to a SubGhzBlockGeneric instance
  387. * @param decrypt Decrypd data
  388. * @param btn Button number, 4 bit
  389. * @param end_serial decrement the last 10 bits of the serial number
  390. * @return true On success
  391. */
  392. static inline bool subghz_protocol_keeloq_check_decrypt(
  393. SubGhzBlockGeneric* instance,
  394. uint32_t decrypt,
  395. uint8_t btn,
  396. uint32_t end_serial) {
  397. furi_assert(instance);
  398. if((decrypt >> 28 == btn) && (((((uint16_t)(decrypt >> 16)) & 0xFF) == end_serial) ||
  399. ((((uint16_t)(decrypt >> 16)) & 0xFF) == 0))) {
  400. instance->cnt = decrypt & 0x0000FFFF;
  401. return true;
  402. }
  403. return false;
  404. }
  405. /**
  406. * Checking the accepted code against the database manafacture key
  407. * @param instance Pointer to a SubGhzBlockGeneric* instance
  408. * @param fix Fix part of the parcel
  409. * @param hop Hop encrypted part of the parcel
  410. * @param keystore Pointer to a SubGhzKeystore* instance
  411. * @param manufacture_name
  412. * @return true on successful search
  413. */
  414. static uint8_t subghz_protocol_keeloq_check_remote_controller_selector(
  415. SubGhzBlockGeneric* instance,
  416. uint32_t fix,
  417. uint32_t hop,
  418. SubGhzKeystore* keystore,
  419. const char** manufacture_name) {
  420. // protocol HCS300 uses 10 bits in discriminator, HCS200 uses 8 bits, for backward compatibility, we are looking for the 8-bit pattern
  421. // HCS300 -> uint16_t end_serial = (uint16_t)(fix & 0x3FF);
  422. // HCS200 -> uint16_t end_serial = (uint16_t)(fix & 0xFF);
  423. uint16_t end_serial = (uint16_t)(fix & 0xFF);
  424. uint8_t btn = (uint8_t)(fix >> 28);
  425. uint32_t decrypt = 0;
  426. uint64_t man;
  427. uint32_t seed = 0;
  428. for
  429. M_EACH(manufacture_code, *subghz_keystore_get_data(keystore), SubGhzKeyArray_t) {
  430. switch(manufacture_code->type) {
  431. case KEELOQ_LEARNING_SIMPLE:
  432. // Simple Learning
  433. decrypt = subghz_protocol_keeloq_common_decrypt(hop, manufacture_code->key);
  434. if(subghz_protocol_keeloq_check_decrypt(instance, decrypt, btn, end_serial)) {
  435. *manufacture_name = string_get_cstr(manufacture_code->name);
  436. return 1;
  437. }
  438. break;
  439. case KEELOQ_LEARNING_NORMAL:
  440. // Normal Learning
  441. // https://phreakerclub.com/forum/showpost.php?p=43557&postcount=37
  442. man = subghz_protocol_keeloq_common_normal_learning(fix, manufacture_code->key);
  443. decrypt = subghz_protocol_keeloq_common_decrypt(hop, man);
  444. if(subghz_protocol_keeloq_check_decrypt(instance, decrypt, btn, end_serial)) {
  445. *manufacture_name = string_get_cstr(manufacture_code->name);
  446. return 1;
  447. }
  448. break;
  449. case KEELOQ_LEARNING_SECURE:
  450. man = subghz_protocol_keeloq_common_secure_learning(
  451. fix, seed, manufacture_code->key);
  452. decrypt = subghz_protocol_keeloq_common_decrypt(hop, man);
  453. if(subghz_protocol_keeloq_check_decrypt(instance, decrypt, btn, end_serial)) {
  454. *manufacture_name = string_get_cstr(manufacture_code->name);
  455. return 1;
  456. }
  457. break;
  458. case KEELOQ_LEARNING_MAGIC_XOR_TYPE_1:
  459. man = subghz_protocol_keeloq_common_magic_xor_type1_learning(
  460. fix, manufacture_code->key);
  461. decrypt = subghz_protocol_keeloq_common_decrypt(hop, man);
  462. if(subghz_protocol_keeloq_check_decrypt(instance, decrypt, btn, end_serial)) {
  463. *manufacture_name = string_get_cstr(manufacture_code->name);
  464. return 1;
  465. }
  466. break;
  467. case KEELOQ_LEARNING_MAGIC_SERIAL_TYPE_1:
  468. man = subghz_protocol_keeloq_common_magic_serial_type1_learning(
  469. fix, manufacture_code->key);
  470. decrypt = subghz_protocol_keeloq_common_decrypt(hop, man);
  471. if(subghz_protocol_keeloq_check_decrypt(instance, decrypt, btn, end_serial)) {
  472. *manufacture_name = string_get_cstr(manufacture_code->name);
  473. return 1;
  474. }
  475. break;
  476. case KEELOQ_LEARNING_UNKNOWN:
  477. // Simple Learning
  478. decrypt = subghz_protocol_keeloq_common_decrypt(hop, manufacture_code->key);
  479. if(subghz_protocol_keeloq_check_decrypt(instance, decrypt, btn, end_serial)) {
  480. *manufacture_name = string_get_cstr(manufacture_code->name);
  481. return 1;
  482. }
  483. // Check for mirrored man
  484. uint64_t man_rev = 0;
  485. uint64_t man_rev_byte = 0;
  486. for(uint8_t i = 0; i < 64; i += 8) {
  487. man_rev_byte = (uint8_t)(manufacture_code->key >> i);
  488. man_rev = man_rev | man_rev_byte << (56 - i);
  489. }
  490. decrypt = subghz_protocol_keeloq_common_decrypt(hop, man_rev);
  491. if(subghz_protocol_keeloq_check_decrypt(instance, decrypt, btn, end_serial)) {
  492. *manufacture_name = string_get_cstr(manufacture_code->name);
  493. return 1;
  494. }
  495. //###########################
  496. // Normal Learning
  497. // https://phreakerclub.com/forum/showpost.php?p=43557&postcount=37
  498. man = subghz_protocol_keeloq_common_normal_learning(fix, manufacture_code->key);
  499. decrypt = subghz_protocol_keeloq_common_decrypt(hop, man);
  500. if(subghz_protocol_keeloq_check_decrypt(instance, decrypt, btn, end_serial)) {
  501. *manufacture_name = string_get_cstr(manufacture_code->name);
  502. return 1;
  503. }
  504. // Check for mirrored man
  505. man = subghz_protocol_keeloq_common_normal_learning(fix, man_rev);
  506. decrypt = subghz_protocol_keeloq_common_decrypt(hop, man);
  507. if(subghz_protocol_keeloq_check_decrypt(instance, decrypt, btn, end_serial)) {
  508. *manufacture_name = string_get_cstr(manufacture_code->name);
  509. return 1;
  510. }
  511. // Secure Learning
  512. man = subghz_protocol_keeloq_common_secure_learning(
  513. fix, seed, manufacture_code->key);
  514. decrypt = subghz_protocol_keeloq_common_decrypt(hop, man);
  515. if(subghz_protocol_keeloq_check_decrypt(instance, decrypt, btn, end_serial)) {
  516. *manufacture_name = string_get_cstr(manufacture_code->name);
  517. return 1;
  518. }
  519. // Check for mirrored man
  520. man = subghz_protocol_keeloq_common_secure_learning(fix, seed, man_rev);
  521. decrypt = subghz_protocol_keeloq_common_decrypt(hop, man);
  522. if(subghz_protocol_keeloq_check_decrypt(instance, decrypt, btn, end_serial)) {
  523. *manufacture_name = string_get_cstr(manufacture_code->name);
  524. return 1;
  525. }
  526. // Magic xor type1 learning
  527. man = subghz_protocol_keeloq_common_magic_xor_type1_learning(
  528. fix, manufacture_code->key);
  529. decrypt = subghz_protocol_keeloq_common_decrypt(hop, man);
  530. if(subghz_protocol_keeloq_check_decrypt(instance, decrypt, btn, end_serial)) {
  531. *manufacture_name = string_get_cstr(manufacture_code->name);
  532. return 1;
  533. }
  534. // Check for mirrored man
  535. man = subghz_protocol_keeloq_common_magic_xor_type1_learning(fix, man_rev);
  536. decrypt = subghz_protocol_keeloq_common_decrypt(hop, man);
  537. if(subghz_protocol_keeloq_check_decrypt(instance, decrypt, btn, end_serial)) {
  538. *manufacture_name = string_get_cstr(manufacture_code->name);
  539. return 1;
  540. }
  541. break;
  542. }
  543. }
  544. *manufacture_name = "Unknown";
  545. instance->cnt = 0;
  546. return 0;
  547. }
  548. static void subghz_protocol_keeloq_check_remote_controller(
  549. SubGhzBlockGeneric* instance,
  550. SubGhzKeystore* keystore,
  551. const char** manufacture_name) {
  552. uint64_t key = subghz_protocol_blocks_reverse_key(instance->data, instance->data_count_bit);
  553. uint32_t key_fix = key >> 32;
  554. uint32_t key_hop = key & 0x00000000ffffffff;
  555. // Check key AN-Motors
  556. if((key_hop >> 24) == ((key_hop >> 16) & 0x00ff) &&
  557. (key_fix >> 28) == ((key_hop >> 12) & 0x0f) && (key_hop & 0xFFF) == 0x404) {
  558. *manufacture_name = "AN-Motors";
  559. instance->cnt = key_hop >> 16;
  560. } else if((key_hop & 0xFFF) == (0x000) && (key_fix >> 28) == ((key_hop >> 12) & 0x0f)) {
  561. *manufacture_name = "HCS101";
  562. instance->cnt = key_hop >> 16;
  563. } else {
  564. subghz_protocol_keeloq_check_remote_controller_selector(
  565. instance, key_fix, key_hop, keystore, manufacture_name);
  566. }
  567. instance->serial = key_fix & 0x0FFFFFFF;
  568. instance->btn = key_fix >> 28;
  569. }
  570. uint8_t subghz_protocol_decoder_keeloq_get_hash_data(void* context) {
  571. furi_assert(context);
  572. SubGhzProtocolDecoderKeeloq* instance = context;
  573. return subghz_protocol_blocks_get_hash_data(
  574. &instance->decoder, (instance->decoder.decode_count_bit / 8) + 1);
  575. }
  576. bool subghz_protocol_decoder_keeloq_serialize(
  577. void* context,
  578. FlipperFormat* flipper_format,
  579. SubGhzPresetDefinition* preset) {
  580. furi_assert(context);
  581. SubGhzProtocolDecoderKeeloq* instance = context;
  582. subghz_protocol_keeloq_check_remote_controller(
  583. &instance->generic, instance->keystore, &instance->manufacture_name);
  584. bool res = subghz_block_generic_serialize(&instance->generic, flipper_format, preset);
  585. if(res && !flipper_format_write_string_cstr(
  586. flipper_format, "Manufacture", instance->manufacture_name)) {
  587. FURI_LOG_E(TAG, "Unable to add manufacture name");
  588. res = false;
  589. }
  590. return res;
  591. }
  592. bool subghz_protocol_decoder_keeloq_deserialize(void* context, FlipperFormat* flipper_format) {
  593. furi_assert(context);
  594. SubGhzProtocolDecoderKeeloq* instance = context;
  595. bool res = false;
  596. do {
  597. if(!subghz_block_generic_deserialize(&instance->generic, flipper_format)) {
  598. FURI_LOG_E(TAG, "Deserialize error");
  599. break;
  600. }
  601. if(instance->generic.data_count_bit !=
  602. subghz_protocol_keeloq_const.min_count_bit_for_found) {
  603. FURI_LOG_E(TAG, "Wrong number of bits in key");
  604. break;
  605. }
  606. res = true;
  607. } while(false);
  608. return res;
  609. }
  610. void subghz_protocol_decoder_keeloq_get_string(void* context, string_t output) {
  611. furi_assert(context);
  612. SubGhzProtocolDecoderKeeloq* instance = context;
  613. subghz_protocol_keeloq_check_remote_controller(
  614. &instance->generic, instance->keystore, &instance->manufacture_name);
  615. uint32_t code_found_hi = instance->generic.data >> 32;
  616. uint32_t code_found_lo = instance->generic.data & 0x00000000ffffffff;
  617. uint64_t code_found_reverse = subghz_protocol_blocks_reverse_key(
  618. instance->generic.data, instance->generic.data_count_bit);
  619. uint32_t code_found_reverse_hi = code_found_reverse >> 32;
  620. uint32_t code_found_reverse_lo = code_found_reverse & 0x00000000ffffffff;
  621. string_cat_printf(
  622. output,
  623. "%s %dbit\r\n"
  624. "Key:%08lX%08lX\r\n"
  625. "Fix:0x%08lX Cnt:%04X\r\n"
  626. "Hop:0x%08lX Btn:%01lX\r\n"
  627. "MF:%s\r\n"
  628. "Sn:0x%07lX \r\n",
  629. instance->generic.protocol_name,
  630. instance->generic.data_count_bit,
  631. code_found_hi,
  632. code_found_lo,
  633. code_found_reverse_hi,
  634. instance->generic.cnt,
  635. code_found_reverse_lo,
  636. instance->generic.btn,
  637. instance->manufacture_name,
  638. instance->generic.serial);
  639. }