nfc_worker.c 29 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707
  1. #include "nfc_worker_i.h"
  2. #include <furi_hal.h>
  3. #define TAG "NfcWorker"
  4. /***************************** NFC Worker API *******************************/
  5. NfcWorker* nfc_worker_alloc() {
  6. NfcWorker* nfc_worker = malloc(sizeof(NfcWorker));
  7. // Worker thread attributes
  8. nfc_worker->thread = furi_thread_alloc();
  9. furi_thread_set_name(nfc_worker->thread, "NfcWorker");
  10. furi_thread_set_stack_size(nfc_worker->thread, 8192);
  11. furi_thread_set_callback(nfc_worker->thread, nfc_worker_task);
  12. furi_thread_set_context(nfc_worker->thread, nfc_worker);
  13. nfc_worker->callback = NULL;
  14. nfc_worker->context = NULL;
  15. nfc_worker->storage = furi_record_open("storage");
  16. // Initialize rfal
  17. while(furi_hal_nfc_is_busy()) {
  18. osDelay(10);
  19. }
  20. nfc_worker_change_state(nfc_worker, NfcWorkerStateReady);
  21. if(furi_hal_rtc_is_flag_set(FuriHalRtcFlagDebug)) {
  22. nfc_worker->debug_pcap_worker = nfc_debug_pcap_alloc(nfc_worker->storage);
  23. }
  24. return nfc_worker;
  25. }
  26. void nfc_worker_free(NfcWorker* nfc_worker) {
  27. furi_assert(nfc_worker);
  28. furi_thread_free(nfc_worker->thread);
  29. furi_record_close("storage");
  30. if(nfc_worker->debug_pcap_worker) nfc_debug_pcap_free(nfc_worker->debug_pcap_worker);
  31. free(nfc_worker);
  32. }
  33. NfcWorkerState nfc_worker_get_state(NfcWorker* nfc_worker) {
  34. return nfc_worker->state;
  35. }
  36. void nfc_worker_start(
  37. NfcWorker* nfc_worker,
  38. NfcWorkerState state,
  39. NfcDeviceData* dev_data,
  40. NfcWorkerCallback callback,
  41. void* context) {
  42. furi_assert(nfc_worker);
  43. furi_assert(dev_data);
  44. while(furi_hal_nfc_is_busy()) {
  45. osDelay(10);
  46. }
  47. nfc_worker->callback = callback;
  48. nfc_worker->context = context;
  49. nfc_worker->dev_data = dev_data;
  50. nfc_worker_change_state(nfc_worker, state);
  51. furi_thread_start(nfc_worker->thread);
  52. }
  53. void nfc_worker_stop(NfcWorker* nfc_worker) {
  54. furi_assert(nfc_worker);
  55. if(nfc_worker->state == NfcWorkerStateBroken || nfc_worker->state == NfcWorkerStateReady) {
  56. return;
  57. }
  58. furi_hal_nfc_stop();
  59. nfc_worker_change_state(nfc_worker, NfcWorkerStateStop);
  60. furi_thread_join(nfc_worker->thread);
  61. }
  62. void nfc_worker_change_state(NfcWorker* nfc_worker, NfcWorkerState state) {
  63. nfc_worker->state = state;
  64. }
  65. /***************************** NFC Worker Thread *******************************/
  66. int32_t nfc_worker_task(void* context) {
  67. NfcWorker* nfc_worker = context;
  68. furi_hal_nfc_exit_sleep();
  69. if(nfc_worker->state == NfcWorkerStateDetect) {
  70. nfc_worker_detect(nfc_worker);
  71. } else if(nfc_worker->state == NfcWorkerStateEmulate) {
  72. nfc_worker_emulate(nfc_worker);
  73. } else if(nfc_worker->state == NfcWorkerStateReadEMVApp) {
  74. nfc_worker_read_emv_app(nfc_worker);
  75. } else if(nfc_worker->state == NfcWorkerStateReadEMVData) {
  76. nfc_worker_read_emv(nfc_worker);
  77. } else if(nfc_worker->state == NfcWorkerStateEmulateApdu) {
  78. nfc_worker_emulate_apdu(nfc_worker);
  79. } else if(nfc_worker->state == NfcWorkerStateReadMifareUltralight) {
  80. nfc_worker_read_mifare_ultralight(nfc_worker);
  81. } else if(nfc_worker->state == NfcWorkerStateEmulateMifareUltralight) {
  82. nfc_worker_emulate_mifare_ul(nfc_worker);
  83. } else if(nfc_worker->state == NfcWorkerStateReadMifareClassic) {
  84. nfc_worker_mifare_classic_dict_attack(nfc_worker);
  85. } else if(nfc_worker->state == NfcWorkerStateEmulateMifareClassic) {
  86. nfc_worker_emulate_mifare_classic(nfc_worker);
  87. } else if(nfc_worker->state == NfcWorkerStateReadMifareDesfire) {
  88. nfc_worker_read_mifare_desfire(nfc_worker);
  89. }
  90. furi_hal_nfc_sleep();
  91. nfc_worker_change_state(nfc_worker, NfcWorkerStateReady);
  92. return 0;
  93. }
  94. void nfc_worker_detect(NfcWorker* nfc_worker) {
  95. nfc_device_data_clear(nfc_worker->dev_data);
  96. NfcDeviceData* dev_data = nfc_worker->dev_data;
  97. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  98. while(nfc_worker->state == NfcWorkerStateDetect) {
  99. if(furi_hal_nfc_detect(nfc_data, 1000)) {
  100. // Process first found device
  101. if(nfc_data->type == FuriHalNfcTypeA) {
  102. if(mf_ul_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  103. dev_data->protocol = NfcDeviceProtocolMifareUl;
  104. } else if(mf_classic_check_card_type(
  105. nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  106. dev_data->protocol = NfcDeviceProtocolMifareClassic;
  107. } else if(mf_df_check_card_type(
  108. nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  109. dev_data->protocol = NfcDeviceProtocolMifareDesfire;
  110. } else if(nfc_data->interface == FuriHalNfcInterfaceIsoDep) {
  111. dev_data->protocol = NfcDeviceProtocolEMV;
  112. } else {
  113. dev_data->protocol = NfcDeviceProtocolUnknown;
  114. }
  115. }
  116. // Notify caller and exit
  117. if(nfc_worker->callback) {
  118. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  119. }
  120. break;
  121. }
  122. furi_hal_nfc_sleep();
  123. osDelay(100);
  124. }
  125. }
  126. void nfc_worker_emulate(NfcWorker* nfc_worker) {
  127. FuriHalNfcTxRxContext tx_rx = {};
  128. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx, true);
  129. FuriHalNfcDevData* data = &nfc_worker->dev_data->nfc_data;
  130. NfcReaderRequestData* reader_data = &nfc_worker->dev_data->reader_data;
  131. while(nfc_worker->state == NfcWorkerStateEmulate) {
  132. if(furi_hal_nfc_listen(data->uid, data->uid_len, data->atqa, data->sak, true, 100)) {
  133. if(furi_hal_nfc_tx_rx(&tx_rx, 100)) {
  134. reader_data->size = tx_rx.rx_bits / 8;
  135. if(reader_data->size > 0) {
  136. memcpy(reader_data->data, tx_rx.rx_data, reader_data->size);
  137. if(nfc_worker->callback) {
  138. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  139. }
  140. }
  141. } else {
  142. FURI_LOG_E(TAG, "Failed to get reader commands");
  143. }
  144. }
  145. }
  146. }
  147. void nfc_worker_read_emv_app(NfcWorker* nfc_worker) {
  148. FuriHalNfcTxRxContext tx_rx = {};
  149. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx, false);
  150. EmvApplication emv_app = {};
  151. NfcDeviceData* result = nfc_worker->dev_data;
  152. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  153. nfc_device_data_clear(result);
  154. while(nfc_worker->state == NfcWorkerStateReadEMVApp) {
  155. if(furi_hal_nfc_detect(nfc_data, 1000)) {
  156. // Card was found. Check that it supports EMV
  157. if(nfc_data->interface == FuriHalNfcInterfaceIsoDep) {
  158. result->protocol = NfcDeviceProtocolEMV;
  159. if(emv_search_application(&tx_rx, &emv_app)) {
  160. // Notify caller and exit
  161. result->emv_data.aid_len = emv_app.aid_len;
  162. memcpy(result->emv_data.aid, emv_app.aid, emv_app.aid_len);
  163. if(nfc_worker->callback) {
  164. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  165. }
  166. }
  167. } else {
  168. FURI_LOG_W(TAG, "Card doesn't support EMV");
  169. }
  170. } else {
  171. FURI_LOG_D(TAG, "Can't find any cards");
  172. }
  173. furi_hal_nfc_sleep();
  174. osDelay(20);
  175. }
  176. }
  177. void nfc_worker_read_emv(NfcWorker* nfc_worker) {
  178. FuriHalNfcTxRxContext tx_rx = {};
  179. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx, false);
  180. EmvApplication emv_app = {};
  181. NfcDeviceData* result = nfc_worker->dev_data;
  182. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  183. nfc_device_data_clear(result);
  184. while(nfc_worker->state == NfcWorkerStateReadEMVData) {
  185. if(furi_hal_nfc_detect(nfc_data, 1000)) {
  186. // Card was found. Check that it supports EMV
  187. if(nfc_data->interface == FuriHalNfcInterfaceIsoDep) {
  188. result->protocol = NfcDeviceProtocolEMV;
  189. if(emv_read_bank_card(&tx_rx, &emv_app)) {
  190. result->emv_data.number_len = emv_app.card_number_len;
  191. memcpy(
  192. result->emv_data.number, emv_app.card_number, result->emv_data.number_len);
  193. result->emv_data.aid_len = emv_app.aid_len;
  194. memcpy(result->emv_data.aid, emv_app.aid, emv_app.aid_len);
  195. if(emv_app.name_found) {
  196. memcpy(result->emv_data.name, emv_app.name, sizeof(emv_app.name));
  197. }
  198. if(emv_app.exp_month) {
  199. result->emv_data.exp_mon = emv_app.exp_month;
  200. result->emv_data.exp_year = emv_app.exp_year;
  201. }
  202. if(emv_app.country_code) {
  203. result->emv_data.country_code = emv_app.country_code;
  204. }
  205. if(emv_app.currency_code) {
  206. result->emv_data.currency_code = emv_app.currency_code;
  207. }
  208. // Notify caller and exit
  209. if(nfc_worker->callback) {
  210. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  211. }
  212. break;
  213. }
  214. } else {
  215. FURI_LOG_W(TAG, "Card doesn't support EMV");
  216. }
  217. } else {
  218. FURI_LOG_D(TAG, "Can't find any cards");
  219. }
  220. furi_hal_nfc_sleep();
  221. osDelay(20);
  222. }
  223. }
  224. void nfc_worker_emulate_apdu(NfcWorker* nfc_worker) {
  225. FuriHalNfcTxRxContext tx_rx = {};
  226. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx, true);
  227. FuriHalNfcDevData params = {
  228. .uid = {0xCF, 0x72, 0xd4, 0x40},
  229. .uid_len = 4,
  230. .atqa = {0x00, 0x04},
  231. .sak = 0x20,
  232. .type = FuriHalNfcTypeA,
  233. };
  234. while(nfc_worker->state == NfcWorkerStateEmulateApdu) {
  235. if(furi_hal_nfc_listen(params.uid, params.uid_len, params.atqa, params.sak, false, 300)) {
  236. FURI_LOG_D(TAG, "POS terminal detected");
  237. if(emv_card_emulation(&tx_rx)) {
  238. FURI_LOG_D(TAG, "EMV card emulated");
  239. }
  240. } else {
  241. FURI_LOG_D(TAG, "Can't find reader");
  242. }
  243. furi_hal_nfc_sleep();
  244. osDelay(20);
  245. }
  246. }
  247. void nfc_worker_read_mifare_ultralight(NfcWorker* nfc_worker) {
  248. FuriHalNfcTxRxContext tx_rx = {};
  249. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx, false);
  250. MfUltralightReader reader = {};
  251. MfUltralightData data = {};
  252. NfcDeviceData* result = nfc_worker->dev_data;
  253. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  254. while(nfc_worker->state == NfcWorkerStateReadMifareUltralight) {
  255. if(furi_hal_nfc_detect(nfc_data, 300)) {
  256. if(nfc_data->type == FuriHalNfcTypeA &&
  257. mf_ul_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  258. FURI_LOG_D(TAG, "Found Mifare Ultralight tag. Start reading");
  259. if(mf_ul_read_card(&tx_rx, &reader, &data)) {
  260. result->protocol = NfcDeviceProtocolMifareUl;
  261. result->mf_ul_data = data;
  262. // Notify caller and exit
  263. if(nfc_worker->callback) {
  264. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  265. }
  266. break;
  267. } else {
  268. FURI_LOG_D(TAG, "Failed reading Mifare Ultralight");
  269. }
  270. } else {
  271. FURI_LOG_W(TAG, "Tag is not Mifare Ultralight");
  272. }
  273. } else {
  274. FURI_LOG_D(TAG, "Can't find any tags");
  275. }
  276. furi_hal_nfc_sleep();
  277. osDelay(100);
  278. }
  279. }
  280. void nfc_worker_emulate_mifare_ul(NfcWorker* nfc_worker) {
  281. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  282. MfUltralightEmulator emulator = {};
  283. mf_ul_prepare_emulation(&emulator, &nfc_worker->dev_data->mf_ul_data);
  284. while(nfc_worker->state == NfcWorkerStateEmulateMifareUltralight) {
  285. emulator.auth_success = false;
  286. if(emulator.data.type >= MfUltralightTypeNTAGI2C1K) {
  287. // Sector index needs to be reset
  288. emulator.curr_sector = 0;
  289. }
  290. furi_hal_nfc_emulate_nfca(
  291. nfc_data->uid,
  292. nfc_data->uid_len,
  293. nfc_data->atqa,
  294. nfc_data->sak,
  295. mf_ul_prepare_emulation_response,
  296. &emulator,
  297. 5000);
  298. // Check if data was modified
  299. if(emulator.data_changed) {
  300. nfc_worker->dev_data->mf_ul_data = emulator.data;
  301. if(nfc_worker->callback) {
  302. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  303. }
  304. emulator.data_changed = false;
  305. }
  306. }
  307. }
  308. void nfc_worker_mifare_classic_dict_attack(NfcWorker* nfc_worker) {
  309. furi_assert(nfc_worker->callback);
  310. FuriHalNfcTxRxContext tx_rx_ctx = {};
  311. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx_ctx, false);
  312. MfClassicAuthContext auth_ctx = {};
  313. MfClassicReader reader = {};
  314. uint64_t curr_key = 0;
  315. uint16_t curr_sector = 0;
  316. uint8_t total_sectors = 0;
  317. NfcWorkerEvent event;
  318. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  319. // Open dictionary
  320. nfc_worker->dict_stream = file_stream_alloc(nfc_worker->storage);
  321. if(!nfc_mf_classic_dict_open_file(nfc_worker->dict_stream)) {
  322. event = NfcWorkerEventNoDictFound;
  323. nfc_worker->callback(event, nfc_worker->context);
  324. nfc_mf_classic_dict_close_file(nfc_worker->dict_stream);
  325. stream_free(nfc_worker->dict_stream);
  326. return;
  327. }
  328. // Detect Mifare Classic card
  329. while(nfc_worker->state == NfcWorkerStateReadMifareClassic) {
  330. if(furi_hal_nfc_detect(nfc_data, 300)) {
  331. if(mf_classic_get_type(
  332. nfc_data->uid,
  333. nfc_data->uid_len,
  334. nfc_data->atqa[0],
  335. nfc_data->atqa[1],
  336. nfc_data->sak,
  337. &reader)) {
  338. total_sectors = mf_classic_get_total_sectors_num(&reader);
  339. if(reader.type == MfClassicType1k) {
  340. event = NfcWorkerEventDetectedClassic1k;
  341. } else {
  342. event = NfcWorkerEventDetectedClassic4k;
  343. }
  344. nfc_worker->callback(event, nfc_worker->context);
  345. break;
  346. }
  347. } else {
  348. event = NfcWorkerEventNoCardDetected;
  349. nfc_worker->callback(event, nfc_worker->context);
  350. }
  351. }
  352. if(nfc_worker->state == NfcWorkerStateReadMifareClassic) {
  353. bool card_removed_notified = false;
  354. bool card_found_notified = false;
  355. // Seek for mifare classic keys
  356. for(curr_sector = 0; curr_sector < total_sectors; curr_sector++) {
  357. FURI_LOG_I(TAG, "Sector: %d ...", curr_sector);
  358. event = NfcWorkerEventNewSector;
  359. nfc_worker->callback(event, nfc_worker->context);
  360. mf_classic_auth_init_context(&auth_ctx, reader.cuid, curr_sector);
  361. bool sector_key_found = false;
  362. while(nfc_mf_classic_dict_get_next_key(nfc_worker->dict_stream, &curr_key)) {
  363. furi_hal_nfc_sleep();
  364. if(furi_hal_nfc_activate_nfca(300, &reader.cuid)) {
  365. if(!card_found_notified) {
  366. if(reader.type == MfClassicType1k) {
  367. event = NfcWorkerEventDetectedClassic1k;
  368. } else {
  369. event = NfcWorkerEventDetectedClassic4k;
  370. }
  371. nfc_worker->callback(event, nfc_worker->context);
  372. card_found_notified = true;
  373. card_removed_notified = false;
  374. }
  375. FURI_LOG_D(
  376. TAG,
  377. "Try to auth to sector %d with key %04lx%08lx",
  378. curr_sector,
  379. (uint32_t)(curr_key >> 32),
  380. (uint32_t)curr_key);
  381. if(mf_classic_auth_attempt(&tx_rx_ctx, &auth_ctx, curr_key)) {
  382. sector_key_found = true;
  383. if((auth_ctx.key_a != MF_CLASSIC_NO_KEY) &&
  384. (auth_ctx.key_b != MF_CLASSIC_NO_KEY))
  385. break;
  386. }
  387. } else {
  388. // Notify that no tag is availalble
  389. FURI_LOG_D(TAG, "Can't find tags");
  390. if(!card_removed_notified) {
  391. event = NfcWorkerEventNoCardDetected;
  392. nfc_worker->callback(event, nfc_worker->context);
  393. card_removed_notified = true;
  394. card_found_notified = false;
  395. }
  396. }
  397. if(nfc_worker->state != NfcWorkerStateReadMifareClassic) break;
  398. osDelay(1);
  399. }
  400. if(nfc_worker->state != NfcWorkerStateReadMifareClassic) break;
  401. if(sector_key_found) {
  402. // Notify that keys were found
  403. if(auth_ctx.key_a != MF_CLASSIC_NO_KEY) {
  404. FURI_LOG_I(
  405. TAG,
  406. "Sector %d key A: %04lx%08lx",
  407. curr_sector,
  408. (uint32_t)(auth_ctx.key_a >> 32),
  409. (uint32_t)auth_ctx.key_a);
  410. event = NfcWorkerEventFoundKeyA;
  411. nfc_worker->callback(event, nfc_worker->context);
  412. }
  413. if(auth_ctx.key_b != MF_CLASSIC_NO_KEY) {
  414. FURI_LOG_I(
  415. TAG,
  416. "Sector %d key B: %04lx%08lx",
  417. curr_sector,
  418. (uint32_t)(auth_ctx.key_b >> 32),
  419. (uint32_t)auth_ctx.key_b);
  420. event = NfcWorkerEventFoundKeyB;
  421. nfc_worker->callback(event, nfc_worker->context);
  422. }
  423. // Add sectors to read sequence
  424. mf_classic_reader_add_sector(&reader, curr_sector, auth_ctx.key_a, auth_ctx.key_b);
  425. }
  426. nfc_mf_classic_dict_reset(nfc_worker->dict_stream);
  427. }
  428. }
  429. if(nfc_worker->state == NfcWorkerStateReadMifareClassic) {
  430. FURI_LOG_I(TAG, "Found keys to %d sectors. Start reading sectors", reader.sectors_to_read);
  431. uint8_t sectors_read =
  432. mf_classic_read_card(&tx_rx_ctx, &reader, &nfc_worker->dev_data->mf_classic_data);
  433. if(sectors_read) {
  434. event = NfcWorkerEventSuccess;
  435. nfc_worker->dev_data->protocol = NfcDeviceProtocolMifareClassic;
  436. FURI_LOG_I(TAG, "Successfully read %d sectors", sectors_read);
  437. } else {
  438. event = NfcWorkerEventFail;
  439. FURI_LOG_W(TAG, "Failed to read any sector");
  440. }
  441. nfc_worker->callback(event, nfc_worker->context);
  442. }
  443. nfc_mf_classic_dict_close_file(nfc_worker->dict_stream);
  444. stream_free(nfc_worker->dict_stream);
  445. }
  446. void nfc_worker_emulate_mifare_classic(NfcWorker* nfc_worker) {
  447. FuriHalNfcTxRxContext tx_rx = {};
  448. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx, true);
  449. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  450. MfClassicEmulator emulator = {
  451. .cuid = nfc_util_bytes2num(&nfc_data->uid[nfc_data->uid_len - 4], 4),
  452. .data = nfc_worker->dev_data->mf_classic_data,
  453. .data_changed = false,
  454. };
  455. NfcaSignal* nfca_signal = nfca_signal_alloc();
  456. tx_rx.nfca_signal = nfca_signal;
  457. while(nfc_worker->state == NfcWorkerStateEmulateMifareClassic) {
  458. if(furi_hal_nfc_listen(
  459. nfc_data->uid, nfc_data->uid_len, nfc_data->atqa, nfc_data->sak, true, 300)) {
  460. mf_classic_emulator(&emulator, &tx_rx);
  461. }
  462. }
  463. if(emulator.data_changed) {
  464. nfc_worker->dev_data->mf_classic_data = emulator.data;
  465. if(nfc_worker->callback) {
  466. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  467. }
  468. emulator.data_changed = false;
  469. }
  470. nfca_signal_free(nfca_signal);
  471. }
  472. void nfc_worker_read_mifare_desfire(NfcWorker* nfc_worker) {
  473. FuriHalNfcTxRxContext tx_rx = {};
  474. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx, false);
  475. NfcDeviceData* result = nfc_worker->dev_data;
  476. nfc_device_data_clear(result);
  477. MifareDesfireData* data = &result->mf_df_data;
  478. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  479. while(nfc_worker->state == NfcWorkerStateReadMifareDesfire) {
  480. furi_hal_nfc_sleep();
  481. if(!furi_hal_nfc_detect(nfc_data, 300)) {
  482. osDelay(100);
  483. continue;
  484. }
  485. memset(data, 0, sizeof(MifareDesfireData));
  486. if(nfc_data->type != FuriHalNfcTypeA ||
  487. !mf_df_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  488. FURI_LOG_D(TAG, "Tag is not DESFire");
  489. osDelay(100);
  490. continue;
  491. }
  492. FURI_LOG_D(TAG, "Found DESFire tag");
  493. result->protocol = NfcDeviceProtocolMifareDesfire;
  494. // Get DESFire version
  495. tx_rx.tx_bits = 8 * mf_df_prepare_get_version(tx_rx.tx_data);
  496. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  497. FURI_LOG_W(TAG, "Bad exchange getting version");
  498. continue;
  499. }
  500. if(!mf_df_parse_get_version_response(tx_rx.rx_data, tx_rx.rx_bits / 8, &data->version)) {
  501. FURI_LOG_W(TAG, "Bad DESFire GET_VERSION response");
  502. continue;
  503. }
  504. tx_rx.tx_bits = 8 * mf_df_prepare_get_free_memory(tx_rx.tx_data);
  505. if(furi_hal_nfc_tx_rx_full(&tx_rx)) {
  506. data->free_memory = malloc(sizeof(MifareDesfireFreeMemory));
  507. memset(data->free_memory, 0, sizeof(MifareDesfireFreeMemory));
  508. if(!mf_df_parse_get_free_memory_response(
  509. tx_rx.rx_data, tx_rx.rx_bits / 8, data->free_memory)) {
  510. FURI_LOG_D(TAG, "Bad DESFire GET_FREE_MEMORY response (normal for pre-EV1 cards)");
  511. free(data->free_memory);
  512. data->free_memory = NULL;
  513. }
  514. }
  515. tx_rx.tx_bits = 8 * mf_df_prepare_get_key_settings(tx_rx.tx_data);
  516. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  517. FURI_LOG_D(TAG, "Bad exchange getting key settings");
  518. } else {
  519. data->master_key_settings = malloc(sizeof(MifareDesfireKeySettings));
  520. memset(data->master_key_settings, 0, sizeof(MifareDesfireKeySettings));
  521. if(!mf_df_parse_get_key_settings_response(
  522. tx_rx.rx_data, tx_rx.rx_bits / 8, data->master_key_settings)) {
  523. FURI_LOG_W(TAG, "Bad DESFire GET_KEY_SETTINGS response");
  524. free(data->master_key_settings);
  525. data->master_key_settings = NULL;
  526. continue;
  527. }
  528. MifareDesfireKeyVersion** key_version_head =
  529. &data->master_key_settings->key_version_head;
  530. for(uint8_t key_id = 0; key_id < data->master_key_settings->max_keys; key_id++) {
  531. tx_rx.tx_bits = 8 * mf_df_prepare_get_key_version(tx_rx.tx_data, key_id);
  532. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  533. FURI_LOG_W(TAG, "Bad exchange getting key version");
  534. continue;
  535. }
  536. MifareDesfireKeyVersion* key_version = malloc(sizeof(MifareDesfireKeyVersion));
  537. memset(key_version, 0, sizeof(MifareDesfireKeyVersion));
  538. key_version->id = key_id;
  539. if(!mf_df_parse_get_key_version_response(
  540. tx_rx.rx_data, tx_rx.rx_bits / 8, key_version)) {
  541. FURI_LOG_W(TAG, "Bad DESFire GET_KEY_VERSION response");
  542. free(key_version);
  543. continue;
  544. }
  545. *key_version_head = key_version;
  546. key_version_head = &key_version->next;
  547. }
  548. }
  549. tx_rx.tx_bits = 8 * mf_df_prepare_get_application_ids(tx_rx.tx_data);
  550. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  551. FURI_LOG_W(TAG, "Bad exchange getting application IDs");
  552. } else {
  553. if(!mf_df_parse_get_application_ids_response(
  554. tx_rx.rx_data, tx_rx.rx_bits / 8, &data->app_head)) {
  555. FURI_LOG_W(TAG, "Bad DESFire GET_APPLICATION_IDS response");
  556. }
  557. }
  558. for(MifareDesfireApplication* app = data->app_head; app; app = app->next) {
  559. tx_rx.tx_bits = 8 * mf_df_prepare_select_application(tx_rx.tx_data, app->id);
  560. if(!furi_hal_nfc_tx_rx_full(&tx_rx) ||
  561. !mf_df_parse_select_application_response(tx_rx.rx_data, tx_rx.rx_bits / 8)) {
  562. FURI_LOG_W(TAG, "Bad exchange selecting application");
  563. continue;
  564. }
  565. tx_rx.tx_bits = 8 * mf_df_prepare_get_key_settings(tx_rx.tx_data);
  566. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  567. FURI_LOG_W(TAG, "Bad exchange getting key settings");
  568. } else {
  569. app->key_settings = malloc(sizeof(MifareDesfireKeySettings));
  570. memset(app->key_settings, 0, sizeof(MifareDesfireKeySettings));
  571. if(!mf_df_parse_get_key_settings_response(
  572. tx_rx.rx_data, tx_rx.rx_bits / 8, app->key_settings)) {
  573. FURI_LOG_W(TAG, "Bad DESFire GET_KEY_SETTINGS response");
  574. free(app->key_settings);
  575. app->key_settings = NULL;
  576. continue;
  577. }
  578. MifareDesfireKeyVersion** key_version_head = &app->key_settings->key_version_head;
  579. for(uint8_t key_id = 0; key_id < app->key_settings->max_keys; key_id++) {
  580. tx_rx.tx_bits = 8 * mf_df_prepare_get_key_version(tx_rx.tx_data, key_id);
  581. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  582. FURI_LOG_W(TAG, "Bad exchange getting key version");
  583. continue;
  584. }
  585. MifareDesfireKeyVersion* key_version = malloc(sizeof(MifareDesfireKeyVersion));
  586. memset(key_version, 0, sizeof(MifareDesfireKeyVersion));
  587. key_version->id = key_id;
  588. if(!mf_df_parse_get_key_version_response(
  589. tx_rx.rx_data, tx_rx.rx_bits / 8, key_version)) {
  590. FURI_LOG_W(TAG, "Bad DESFire GET_KEY_VERSION response");
  591. free(key_version);
  592. continue;
  593. }
  594. *key_version_head = key_version;
  595. key_version_head = &key_version->next;
  596. }
  597. }
  598. tx_rx.tx_bits = 8 * mf_df_prepare_get_file_ids(tx_rx.tx_data);
  599. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  600. FURI_LOG_W(TAG, "Bad exchange getting file IDs");
  601. } else {
  602. if(!mf_df_parse_get_file_ids_response(
  603. tx_rx.rx_data, tx_rx.rx_bits / 8, &app->file_head)) {
  604. FURI_LOG_W(TAG, "Bad DESFire GET_FILE_IDS response");
  605. }
  606. }
  607. for(MifareDesfireFile* file = app->file_head; file; file = file->next) {
  608. tx_rx.tx_bits = 8 * mf_df_prepare_get_file_settings(tx_rx.tx_data, file->id);
  609. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  610. FURI_LOG_W(TAG, "Bad exchange getting file settings");
  611. continue;
  612. }
  613. if(!mf_df_parse_get_file_settings_response(
  614. tx_rx.rx_data, tx_rx.rx_bits / 8, file)) {
  615. FURI_LOG_W(TAG, "Bad DESFire GET_FILE_SETTINGS response");
  616. continue;
  617. }
  618. switch(file->type) {
  619. case MifareDesfireFileTypeStandard:
  620. case MifareDesfireFileTypeBackup:
  621. tx_rx.tx_bits = 8 * mf_df_prepare_read_data(tx_rx.tx_data, file->id, 0, 0);
  622. break;
  623. case MifareDesfireFileTypeValue:
  624. tx_rx.tx_bits = 8 * mf_df_prepare_get_value(tx_rx.tx_data, file->id);
  625. break;
  626. case MifareDesfireFileTypeLinearRecord:
  627. case MifareDesfireFileTypeCyclicRecord:
  628. tx_rx.tx_bits = 8 * mf_df_prepare_read_records(tx_rx.tx_data, file->id, 0, 0);
  629. break;
  630. }
  631. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  632. FURI_LOG_W(TAG, "Bad exchange reading file %d", file->id);
  633. continue;
  634. }
  635. if(!mf_df_parse_read_data_response(tx_rx.rx_data, tx_rx.rx_bits / 8, file)) {
  636. FURI_LOG_W(TAG, "Bad response reading file %d", file->id);
  637. continue;
  638. }
  639. }
  640. }
  641. // Notify caller and exit
  642. if(nfc_worker->callback) {
  643. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  644. }
  645. break;
  646. }
  647. }