nfc_worker.c 29 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710
  1. #include "nfc_worker_i.h"
  2. #include <furi_hal.h>
  3. #include <lib/nfc_protocols/nfc_util.h>
  4. #include <lib/nfc_protocols/emv.h>
  5. #include <lib/nfc_protocols/mifare_common.h>
  6. #include <lib/nfc_protocols/mifare_ultralight.h>
  7. #include <lib/nfc_protocols/mifare_classic.h>
  8. #include <lib/nfc_protocols/mifare_desfire.h>
  9. #include <lib/nfc_protocols/nfca.h>
  10. #include "helpers/nfc_mf_classic_dict.h"
  11. #define TAG "NfcWorker"
  12. /***************************** NFC Worker API *******************************/
  13. NfcWorker* nfc_worker_alloc() {
  14. NfcWorker* nfc_worker = malloc(sizeof(NfcWorker));
  15. // Worker thread attributes
  16. nfc_worker->thread = furi_thread_alloc();
  17. furi_thread_set_name(nfc_worker->thread, "NfcWorker");
  18. furi_thread_set_stack_size(nfc_worker->thread, 8192);
  19. furi_thread_set_callback(nfc_worker->thread, nfc_worker_task);
  20. furi_thread_set_context(nfc_worker->thread, nfc_worker);
  21. nfc_worker->callback = NULL;
  22. nfc_worker->context = NULL;
  23. nfc_worker->storage = furi_record_open("storage");
  24. // Initialize rfal
  25. while(furi_hal_nfc_is_busy()) {
  26. osDelay(10);
  27. }
  28. nfc_worker_change_state(nfc_worker, NfcWorkerStateReady);
  29. return nfc_worker;
  30. }
  31. void nfc_worker_free(NfcWorker* nfc_worker) {
  32. furi_assert(nfc_worker);
  33. furi_thread_free(nfc_worker->thread);
  34. furi_record_close("storage");
  35. free(nfc_worker);
  36. }
  37. NfcWorkerState nfc_worker_get_state(NfcWorker* nfc_worker) {
  38. return nfc_worker->state;
  39. }
  40. void nfc_worker_start(
  41. NfcWorker* nfc_worker,
  42. NfcWorkerState state,
  43. NfcDeviceData* dev_data,
  44. NfcWorkerCallback callback,
  45. void* context) {
  46. furi_assert(nfc_worker);
  47. furi_assert(dev_data);
  48. while(furi_hal_nfc_is_busy()) {
  49. osDelay(10);
  50. }
  51. nfc_worker->callback = callback;
  52. nfc_worker->context = context;
  53. nfc_worker->dev_data = dev_data;
  54. nfc_worker_change_state(nfc_worker, state);
  55. furi_thread_start(nfc_worker->thread);
  56. }
  57. void nfc_worker_stop(NfcWorker* nfc_worker) {
  58. furi_assert(nfc_worker);
  59. if(nfc_worker->state == NfcWorkerStateBroken || nfc_worker->state == NfcWorkerStateReady) {
  60. return;
  61. }
  62. furi_hal_nfc_stop();
  63. nfc_worker_change_state(nfc_worker, NfcWorkerStateStop);
  64. furi_thread_join(nfc_worker->thread);
  65. }
  66. void nfc_worker_change_state(NfcWorker* nfc_worker, NfcWorkerState state) {
  67. nfc_worker->state = state;
  68. }
  69. /***************************** NFC Worker Thread *******************************/
  70. int32_t nfc_worker_task(void* context) {
  71. NfcWorker* nfc_worker = context;
  72. furi_hal_nfc_exit_sleep();
  73. if(nfc_worker->state == NfcWorkerStateDetect) {
  74. nfc_worker_detect(nfc_worker);
  75. } else if(nfc_worker->state == NfcWorkerStateEmulate) {
  76. nfc_worker_emulate(nfc_worker);
  77. } else if(nfc_worker->state == NfcWorkerStateReadEMVApp) {
  78. nfc_worker_read_emv_app(nfc_worker);
  79. } else if(nfc_worker->state == NfcWorkerStateReadEMVData) {
  80. nfc_worker_read_emv(nfc_worker);
  81. } else if(nfc_worker->state == NfcWorkerStateEmulateApdu) {
  82. nfc_worker_emulate_apdu(nfc_worker);
  83. } else if(nfc_worker->state == NfcWorkerStateReadMifareUltralight) {
  84. nfc_worker_read_mifare_ultralight(nfc_worker);
  85. } else if(nfc_worker->state == NfcWorkerStateEmulateMifareUltralight) {
  86. nfc_worker_emulate_mifare_ul(nfc_worker);
  87. } else if(nfc_worker->state == NfcWorkerStateReadMifareClassic) {
  88. nfc_worker_mifare_classic_dict_attack(nfc_worker);
  89. } else if(nfc_worker->state == NfcWorkerStateEmulateMifareClassic) {
  90. nfc_worker_emulate_mifare_classic(nfc_worker);
  91. } else if(nfc_worker->state == NfcWorkerStateReadMifareDesfire) {
  92. nfc_worker_read_mifare_desfire(nfc_worker);
  93. }
  94. furi_hal_nfc_sleep();
  95. nfc_worker_change_state(nfc_worker, NfcWorkerStateReady);
  96. return 0;
  97. }
  98. void nfc_worker_detect(NfcWorker* nfc_worker) {
  99. nfc_device_data_clear(nfc_worker->dev_data);
  100. NfcDeviceData* dev_data = nfc_worker->dev_data;
  101. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  102. while(nfc_worker->state == NfcWorkerStateDetect) {
  103. if(furi_hal_nfc_detect(nfc_data, 1000)) {
  104. // Process first found device
  105. if(nfc_data->type == FuriHalNfcTypeA) {
  106. if(mf_ul_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  107. dev_data->protocol = NfcDeviceProtocolMifareUl;
  108. } else if(mf_classic_check_card_type(
  109. nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  110. dev_data->protocol = NfcDeviceProtocolMifareClassic;
  111. } else if(mf_df_check_card_type(
  112. nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  113. dev_data->protocol = NfcDeviceProtocolMifareDesfire;
  114. } else if(nfc_data->interface == FuriHalNfcInterfaceIsoDep) {
  115. dev_data->protocol = NfcDeviceProtocolEMV;
  116. } else {
  117. dev_data->protocol = NfcDeviceProtocolUnknown;
  118. }
  119. }
  120. // Notify caller and exit
  121. if(nfc_worker->callback) {
  122. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  123. }
  124. break;
  125. }
  126. furi_hal_nfc_sleep();
  127. osDelay(100);
  128. }
  129. }
  130. void nfc_worker_emulate(NfcWorker* nfc_worker) {
  131. FuriHalNfcTxRxContext tx_rx = {};
  132. FuriHalNfcDevData* data = &nfc_worker->dev_data->nfc_data;
  133. NfcReaderRequestData* reader_data = &nfc_worker->dev_data->reader_data;
  134. while(nfc_worker->state == NfcWorkerStateEmulate) {
  135. if(furi_hal_nfc_listen(data->uid, data->uid_len, data->atqa, data->sak, true, 100)) {
  136. if(furi_hal_nfc_tx_rx(&tx_rx, 100)) {
  137. reader_data->size = tx_rx.rx_bits / 8;
  138. if(reader_data->size > 0) {
  139. memcpy(reader_data->data, tx_rx.rx_data, reader_data->size);
  140. if(nfc_worker->callback) {
  141. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  142. }
  143. }
  144. } else {
  145. FURI_LOG_E(TAG, "Failed to get reader commands");
  146. }
  147. }
  148. }
  149. }
  150. void nfc_worker_read_emv_app(NfcWorker* nfc_worker) {
  151. FuriHalNfcTxRxContext tx_rx = {};
  152. EmvApplication emv_app = {};
  153. NfcDeviceData* result = nfc_worker->dev_data;
  154. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  155. nfc_device_data_clear(result);
  156. while(nfc_worker->state == NfcWorkerStateReadEMVApp) {
  157. if(furi_hal_nfc_detect(nfc_data, 1000)) {
  158. // Card was found. Check that it supports EMV
  159. if(nfc_data->interface == FuriHalNfcInterfaceIsoDep) {
  160. result->protocol = NfcDeviceProtocolEMV;
  161. if(emv_search_application(&tx_rx, &emv_app)) {
  162. // Notify caller and exit
  163. result->emv_data.aid_len = emv_app.aid_len;
  164. memcpy(result->emv_data.aid, emv_app.aid, emv_app.aid_len);
  165. if(nfc_worker->callback) {
  166. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  167. }
  168. }
  169. } else {
  170. FURI_LOG_W(TAG, "Card doesn't support EMV");
  171. }
  172. } else {
  173. FURI_LOG_D(TAG, "Can't find any cards");
  174. }
  175. furi_hal_nfc_sleep();
  176. osDelay(20);
  177. }
  178. }
  179. void nfc_worker_read_emv(NfcWorker* nfc_worker) {
  180. FuriHalNfcTxRxContext tx_rx = {};
  181. EmvApplication emv_app = {};
  182. NfcDeviceData* result = nfc_worker->dev_data;
  183. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  184. nfc_device_data_clear(result);
  185. while(nfc_worker->state == NfcWorkerStateReadEMVData) {
  186. if(furi_hal_nfc_detect(nfc_data, 1000)) {
  187. // Card was found. Check that it supports EMV
  188. if(nfc_data->interface == FuriHalNfcInterfaceIsoDep) {
  189. result->protocol = NfcDeviceProtocolEMV;
  190. if(emv_read_bank_card(&tx_rx, &emv_app)) {
  191. result->emv_data.number_len = emv_app.card_number_len;
  192. memcpy(
  193. result->emv_data.number, emv_app.card_number, result->emv_data.number_len);
  194. result->emv_data.aid_len = emv_app.aid_len;
  195. memcpy(result->emv_data.aid, emv_app.aid, emv_app.aid_len);
  196. if(emv_app.name_found) {
  197. memcpy(result->emv_data.name, emv_app.name, sizeof(emv_app.name));
  198. }
  199. if(emv_app.exp_month) {
  200. result->emv_data.exp_mon = emv_app.exp_month;
  201. result->emv_data.exp_year = emv_app.exp_year;
  202. }
  203. if(emv_app.country_code) {
  204. result->emv_data.country_code = emv_app.country_code;
  205. }
  206. if(emv_app.currency_code) {
  207. result->emv_data.currency_code = emv_app.currency_code;
  208. }
  209. // Notify caller and exit
  210. if(nfc_worker->callback) {
  211. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  212. }
  213. break;
  214. }
  215. } else {
  216. FURI_LOG_W(TAG, "Card doesn't support EMV");
  217. }
  218. } else {
  219. FURI_LOG_D(TAG, "Can't find any cards");
  220. }
  221. furi_hal_nfc_sleep();
  222. osDelay(20);
  223. }
  224. }
  225. void nfc_worker_emulate_apdu(NfcWorker* nfc_worker) {
  226. FuriHalNfcTxRxContext tx_rx = {};
  227. FuriHalNfcDevData params = {
  228. .uid = {0xCF, 0x72, 0xd4, 0x40},
  229. .uid_len = 4,
  230. .atqa = {0x00, 0x04},
  231. .sak = 0x20,
  232. .type = FuriHalNfcTypeA,
  233. };
  234. while(nfc_worker->state == NfcWorkerStateEmulateApdu) {
  235. if(furi_hal_nfc_listen(params.uid, params.uid_len, params.atqa, params.sak, false, 300)) {
  236. FURI_LOG_D(TAG, "POS terminal detected");
  237. if(emv_card_emulation(&tx_rx)) {
  238. FURI_LOG_D(TAG, "EMV card emulated");
  239. }
  240. } else {
  241. FURI_LOG_D(TAG, "Can't find reader");
  242. }
  243. furi_hal_nfc_sleep();
  244. osDelay(20);
  245. }
  246. }
  247. void nfc_worker_read_mifare_ultralight(NfcWorker* nfc_worker) {
  248. FuriHalNfcTxRxContext tx_rx = {};
  249. MfUltralightReader reader = {};
  250. MfUltralightData data = {};
  251. NfcDeviceData* result = nfc_worker->dev_data;
  252. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  253. while(nfc_worker->state == NfcWorkerStateReadMifareUltralight) {
  254. if(furi_hal_nfc_detect(nfc_data, 300)) {
  255. if(nfc_data->type == FuriHalNfcTypeA &&
  256. mf_ul_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  257. FURI_LOG_D(TAG, "Found Mifare Ultralight tag. Start reading");
  258. if(mf_ul_read_card(&tx_rx, &reader, &data)) {
  259. result->protocol = NfcDeviceProtocolMifareUl;
  260. result->mf_ul_data = data;
  261. // Notify caller and exit
  262. if(nfc_worker->callback) {
  263. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  264. }
  265. break;
  266. } else {
  267. FURI_LOG_D(TAG, "Failed reading Mifare Ultralight");
  268. }
  269. } else {
  270. FURI_LOG_W(TAG, "Tag is not Mifare Ultralight");
  271. }
  272. } else {
  273. FURI_LOG_D(TAG, "Can't find any tags");
  274. }
  275. furi_hal_nfc_sleep();
  276. osDelay(100);
  277. }
  278. }
  279. void nfc_worker_emulate_mifare_ul(NfcWorker* nfc_worker) {
  280. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  281. MfUltralightEmulator emulator = {};
  282. mf_ul_prepare_emulation(&emulator, &nfc_worker->dev_data->mf_ul_data);
  283. while(nfc_worker->state == NfcWorkerStateEmulateMifareUltralight) {
  284. emulator.auth_success = false;
  285. if(emulator.data.type >= MfUltralightTypeNTAGI2C1K) {
  286. // Sector index needs to be reset
  287. emulator.curr_sector = 0;
  288. }
  289. furi_hal_nfc_emulate_nfca(
  290. nfc_data->uid,
  291. nfc_data->uid_len,
  292. nfc_data->atqa,
  293. nfc_data->sak,
  294. mf_ul_prepare_emulation_response,
  295. &emulator,
  296. 5000);
  297. // Check if data was modified
  298. if(emulator.data_changed) {
  299. nfc_worker->dev_data->mf_ul_data = emulator.data;
  300. if(nfc_worker->callback) {
  301. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  302. }
  303. emulator.data_changed = false;
  304. }
  305. }
  306. }
  307. void nfc_worker_mifare_classic_dict_attack(NfcWorker* nfc_worker) {
  308. furi_assert(nfc_worker->callback);
  309. FuriHalNfcTxRxContext tx_rx_ctx = {};
  310. MfClassicAuthContext auth_ctx = {};
  311. MfClassicReader reader = {};
  312. uint64_t curr_key = 0;
  313. uint16_t curr_sector = 0;
  314. uint8_t total_sectors = 0;
  315. NfcWorkerEvent event;
  316. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  317. // Open dictionary
  318. nfc_worker->dict_stream = file_stream_alloc(nfc_worker->storage);
  319. if(!nfc_mf_classic_dict_open_file(nfc_worker->dict_stream)) {
  320. event = NfcWorkerEventNoDictFound;
  321. nfc_worker->callback(event, nfc_worker->context);
  322. nfc_mf_classic_dict_close_file(nfc_worker->dict_stream);
  323. stream_free(nfc_worker->dict_stream);
  324. return;
  325. }
  326. // Detect Mifare Classic card
  327. while(nfc_worker->state == NfcWorkerStateReadMifareClassic) {
  328. if(furi_hal_nfc_detect(nfc_data, 300)) {
  329. if(mf_classic_get_type(
  330. nfc_data->uid,
  331. nfc_data->uid_len,
  332. nfc_data->atqa[0],
  333. nfc_data->atqa[1],
  334. nfc_data->sak,
  335. &reader)) {
  336. total_sectors = mf_classic_get_total_sectors_num(&reader);
  337. if(reader.type == MfClassicType1k) {
  338. event = NfcWorkerEventDetectedClassic1k;
  339. } else {
  340. event = NfcWorkerEventDetectedClassic4k;
  341. }
  342. nfc_worker->callback(event, nfc_worker->context);
  343. break;
  344. }
  345. } else {
  346. event = NfcWorkerEventNoCardDetected;
  347. nfc_worker->callback(event, nfc_worker->context);
  348. }
  349. }
  350. if(nfc_worker->state == NfcWorkerStateReadMifareClassic) {
  351. bool card_removed_notified = false;
  352. bool card_found_notified = false;
  353. // Seek for mifare classic keys
  354. for(curr_sector = 0; curr_sector < total_sectors; curr_sector++) {
  355. FURI_LOG_I(TAG, "Sector: %d ...", curr_sector);
  356. event = NfcWorkerEventNewSector;
  357. nfc_worker->callback(event, nfc_worker->context);
  358. mf_classic_auth_init_context(&auth_ctx, reader.cuid, curr_sector);
  359. bool sector_key_found = false;
  360. while(nfc_mf_classic_dict_get_next_key(nfc_worker->dict_stream, &curr_key)) {
  361. furi_hal_nfc_sleep();
  362. if(furi_hal_nfc_activate_nfca(300, &reader.cuid)) {
  363. if(!card_found_notified) {
  364. if(reader.type == MfClassicType1k) {
  365. event = NfcWorkerEventDetectedClassic1k;
  366. } else {
  367. event = NfcWorkerEventDetectedClassic4k;
  368. }
  369. nfc_worker->callback(event, nfc_worker->context);
  370. card_found_notified = true;
  371. card_removed_notified = false;
  372. }
  373. FURI_LOG_D(
  374. TAG,
  375. "Try to auth to sector %d with key %04lx%08lx",
  376. curr_sector,
  377. (uint32_t)(curr_key >> 32),
  378. (uint32_t)curr_key);
  379. if(mf_classic_auth_attempt(&tx_rx_ctx, &auth_ctx, curr_key)) {
  380. sector_key_found = true;
  381. if((auth_ctx.key_a != MF_CLASSIC_NO_KEY) &&
  382. (auth_ctx.key_b != MF_CLASSIC_NO_KEY))
  383. break;
  384. }
  385. } else {
  386. // Notify that no tag is availalble
  387. FURI_LOG_D(TAG, "Can't find tags");
  388. if(!card_removed_notified) {
  389. event = NfcWorkerEventNoCardDetected;
  390. nfc_worker->callback(event, nfc_worker->context);
  391. card_removed_notified = true;
  392. card_found_notified = false;
  393. }
  394. }
  395. if(nfc_worker->state != NfcWorkerStateReadMifareClassic) break;
  396. osDelay(1);
  397. }
  398. if(nfc_worker->state != NfcWorkerStateReadMifareClassic) break;
  399. if(sector_key_found) {
  400. // Notify that keys were found
  401. if(auth_ctx.key_a != MF_CLASSIC_NO_KEY) {
  402. FURI_LOG_I(
  403. TAG,
  404. "Sector %d key A: %04lx%08lx",
  405. curr_sector,
  406. (uint32_t)(auth_ctx.key_a >> 32),
  407. (uint32_t)auth_ctx.key_a);
  408. event = NfcWorkerEventFoundKeyA;
  409. nfc_worker->callback(event, nfc_worker->context);
  410. }
  411. if(auth_ctx.key_b != MF_CLASSIC_NO_KEY) {
  412. FURI_LOG_I(
  413. TAG,
  414. "Sector %d key B: %04lx%08lx",
  415. curr_sector,
  416. (uint32_t)(auth_ctx.key_b >> 32),
  417. (uint32_t)auth_ctx.key_b);
  418. event = NfcWorkerEventFoundKeyB;
  419. nfc_worker->callback(event, nfc_worker->context);
  420. }
  421. // Add sectors to read sequence
  422. mf_classic_reader_add_sector(&reader, curr_sector, auth_ctx.key_a, auth_ctx.key_b);
  423. }
  424. nfc_mf_classic_dict_reset(nfc_worker->dict_stream);
  425. }
  426. }
  427. if(nfc_worker->state == NfcWorkerStateReadMifareClassic) {
  428. FURI_LOG_I(TAG, "Found keys to %d sectors. Start reading sectors", reader.sectors_to_read);
  429. uint8_t sectors_read =
  430. mf_classic_read_card(&tx_rx_ctx, &reader, &nfc_worker->dev_data->mf_classic_data);
  431. if(sectors_read) {
  432. event = NfcWorkerEventSuccess;
  433. nfc_worker->dev_data->protocol = NfcDeviceProtocolMifareClassic;
  434. FURI_LOG_I(TAG, "Successfully read %d sectors", sectors_read);
  435. } else {
  436. event = NfcWorkerEventFail;
  437. FURI_LOG_W(TAG, "Failed to read any sector");
  438. }
  439. nfc_worker->callback(event, nfc_worker->context);
  440. }
  441. nfc_mf_classic_dict_close_file(nfc_worker->dict_stream);
  442. stream_free(nfc_worker->dict_stream);
  443. }
  444. void nfc_worker_emulate_mifare_classic(NfcWorker* nfc_worker) {
  445. FuriHalNfcTxRxContext tx_rx;
  446. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  447. MfClassicEmulator emulator = {
  448. .cuid = nfc_util_bytes2num(&nfc_data->uid[nfc_data->uid_len - 4], 4),
  449. .data = nfc_worker->dev_data->mf_classic_data,
  450. .data_changed = false,
  451. };
  452. NfcaSignal* nfca_signal = nfca_signal_alloc();
  453. tx_rx.nfca_signal = nfca_signal;
  454. while(nfc_worker->state == NfcWorkerStateEmulateMifareClassic) {
  455. if(furi_hal_nfc_listen(
  456. nfc_data->uid, nfc_data->uid_len, nfc_data->atqa, nfc_data->sak, true, 300)) {
  457. mf_classic_emulator(&emulator, &tx_rx);
  458. }
  459. }
  460. if(emulator.data_changed) {
  461. nfc_worker->dev_data->mf_classic_data = emulator.data;
  462. if(nfc_worker->callback) {
  463. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  464. }
  465. emulator.data_changed = false;
  466. }
  467. nfca_signal_free(nfca_signal);
  468. }
  469. void nfc_worker_read_mifare_desfire(NfcWorker* nfc_worker) {
  470. ReturnCode err;
  471. uint8_t tx_buff[64] = {};
  472. uint16_t tx_len = 0;
  473. uint8_t rx_buff[512] = {};
  474. uint16_t rx_len;
  475. NfcDeviceData* result = nfc_worker->dev_data;
  476. nfc_device_data_clear(result);
  477. MifareDesfireData* data = &result->mf_df_data;
  478. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  479. while(nfc_worker->state == NfcWorkerStateReadMifareDesfire) {
  480. furi_hal_nfc_sleep();
  481. if(!furi_hal_nfc_detect(nfc_data, 300)) {
  482. osDelay(100);
  483. continue;
  484. }
  485. memset(data, 0, sizeof(MifareDesfireData));
  486. if(nfc_data->type != FuriHalNfcTypeA ||
  487. !mf_df_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  488. FURI_LOG_D(TAG, "Tag is not DESFire");
  489. osDelay(100);
  490. continue;
  491. }
  492. FURI_LOG_D(TAG, "Found DESFire tag");
  493. result->protocol = NfcDeviceProtocolMifareDesfire;
  494. // Get DESFire version
  495. tx_len = mf_df_prepare_get_version(tx_buff);
  496. err = furi_hal_nfc_exchange_full(tx_buff, tx_len, rx_buff, sizeof(rx_buff), &rx_len);
  497. if(err != ERR_NONE) {
  498. FURI_LOG_W(TAG, "Bad exchange getting version, err: %d", err);
  499. continue;
  500. }
  501. if(!mf_df_parse_get_version_response(rx_buff, rx_len, &data->version)) {
  502. FURI_LOG_W(TAG, "Bad DESFire GET_VERSION response");
  503. continue;
  504. }
  505. tx_len = mf_df_prepare_get_free_memory(tx_buff);
  506. err = furi_hal_nfc_exchange_full(tx_buff, tx_len, rx_buff, sizeof(rx_buff), &rx_len);
  507. if(err == ERR_NONE) {
  508. data->free_memory = malloc(sizeof(MifareDesfireFreeMemory));
  509. memset(data->free_memory, 0, sizeof(MifareDesfireFreeMemory));
  510. if(!mf_df_parse_get_free_memory_response(rx_buff, rx_len, data->free_memory)) {
  511. FURI_LOG_D(TAG, "Bad DESFire GET_FREE_MEMORY response (normal for pre-EV1 cards)");
  512. free(data->free_memory);
  513. data->free_memory = NULL;
  514. }
  515. }
  516. tx_len = mf_df_prepare_get_key_settings(tx_buff);
  517. err = furi_hal_nfc_exchange_full(tx_buff, tx_len, rx_buff, sizeof(rx_buff), &rx_len);
  518. if(err != ERR_NONE) {
  519. FURI_LOG_D(TAG, "Bad exchange getting key settings, err: %d", err);
  520. } else {
  521. data->master_key_settings = malloc(sizeof(MifareDesfireKeySettings));
  522. memset(data->master_key_settings, 0, sizeof(MifareDesfireKeySettings));
  523. if(!mf_df_parse_get_key_settings_response(rx_buff, rx_len, data->master_key_settings)) {
  524. FURI_LOG_W(TAG, "Bad DESFire GET_KEY_SETTINGS response");
  525. free(data->master_key_settings);
  526. data->master_key_settings = NULL;
  527. continue;
  528. }
  529. MifareDesfireKeyVersion** key_version_head =
  530. &data->master_key_settings->key_version_head;
  531. for(uint8_t key_id = 0; key_id < data->master_key_settings->max_keys; key_id++) {
  532. tx_len = mf_df_prepare_get_key_version(tx_buff, key_id);
  533. err =
  534. furi_hal_nfc_exchange_full(tx_buff, tx_len, rx_buff, sizeof(rx_buff), &rx_len);
  535. if(err != ERR_NONE) {
  536. FURI_LOG_W(TAG, "Bad exchange getting key version, err: %d", err);
  537. continue;
  538. }
  539. MifareDesfireKeyVersion* key_version = malloc(sizeof(MifareDesfireKeyVersion));
  540. memset(key_version, 0, sizeof(MifareDesfireKeyVersion));
  541. key_version->id = key_id;
  542. if(!mf_df_parse_get_key_version_response(rx_buff, rx_len, key_version)) {
  543. FURI_LOG_W(TAG, "Bad DESFire GET_KEY_VERSION response");
  544. free(key_version);
  545. continue;
  546. }
  547. *key_version_head = key_version;
  548. key_version_head = &key_version->next;
  549. }
  550. }
  551. tx_len = mf_df_prepare_get_application_ids(tx_buff);
  552. err = furi_hal_nfc_exchange_full(tx_buff, tx_len, rx_buff, sizeof(rx_buff), &rx_len);
  553. if(err != ERR_NONE) {
  554. FURI_LOG_W(TAG, "Bad exchange getting application IDs, err: %d", err);
  555. } else {
  556. if(!mf_df_parse_get_application_ids_response(rx_buff, rx_len, &data->app_head)) {
  557. FURI_LOG_W(TAG, "Bad DESFire GET_APPLICATION_IDS response");
  558. }
  559. }
  560. for(MifareDesfireApplication* app = data->app_head; app; app = app->next) {
  561. tx_len = mf_df_prepare_select_application(tx_buff, app->id);
  562. err = furi_hal_nfc_exchange_full(tx_buff, tx_len, rx_buff, sizeof(rx_buff), &rx_len);
  563. if(!mf_df_parse_select_application_response(rx_buff, rx_len)) {
  564. FURI_LOG_W(TAG, "Bad exchange selecting application, err: %d", err);
  565. continue;
  566. }
  567. tx_len = mf_df_prepare_get_key_settings(tx_buff);
  568. err = furi_hal_nfc_exchange_full(tx_buff, tx_len, rx_buff, sizeof(rx_buff), &rx_len);
  569. if(err != ERR_NONE) {
  570. FURI_LOG_W(TAG, "Bad exchange getting key settings, err: %d", err);
  571. } else {
  572. app->key_settings = malloc(sizeof(MifareDesfireKeySettings));
  573. memset(app->key_settings, 0, sizeof(MifareDesfireKeySettings));
  574. if(!mf_df_parse_get_key_settings_response(rx_buff, rx_len, app->key_settings)) {
  575. FURI_LOG_W(TAG, "Bad DESFire GET_KEY_SETTINGS response");
  576. free(app->key_settings);
  577. app->key_settings = NULL;
  578. continue;
  579. }
  580. MifareDesfireKeyVersion** key_version_head = &app->key_settings->key_version_head;
  581. for(uint8_t key_id = 0; key_id < app->key_settings->max_keys; key_id++) {
  582. tx_len = mf_df_prepare_get_key_version(tx_buff, key_id);
  583. err = furi_hal_nfc_exchange_full(
  584. tx_buff, tx_len, rx_buff, sizeof(rx_buff), &rx_len);
  585. if(err != ERR_NONE) {
  586. FURI_LOG_W(TAG, "Bad exchange getting key version, err: %d", err);
  587. continue;
  588. }
  589. MifareDesfireKeyVersion* key_version = malloc(sizeof(MifareDesfireKeyVersion));
  590. memset(key_version, 0, sizeof(MifareDesfireKeyVersion));
  591. key_version->id = key_id;
  592. if(!mf_df_parse_get_key_version_response(rx_buff, rx_len, key_version)) {
  593. FURI_LOG_W(TAG, "Bad DESFire GET_KEY_VERSION response");
  594. free(key_version);
  595. continue;
  596. }
  597. *key_version_head = key_version;
  598. key_version_head = &key_version->next;
  599. }
  600. }
  601. tx_len = mf_df_prepare_get_file_ids(tx_buff);
  602. err = furi_hal_nfc_exchange_full(tx_buff, tx_len, rx_buff, sizeof(rx_buff), &rx_len);
  603. if(err != ERR_NONE) {
  604. FURI_LOG_W(TAG, "Bad exchange getting file IDs, err: %d", err);
  605. } else {
  606. if(!mf_df_parse_get_file_ids_response(rx_buff, rx_len, &app->file_head)) {
  607. FURI_LOG_W(TAG, "Bad DESFire GET_FILE_IDS response");
  608. }
  609. }
  610. for(MifareDesfireFile* file = app->file_head; file; file = file->next) {
  611. tx_len = mf_df_prepare_get_file_settings(tx_buff, file->id);
  612. err =
  613. furi_hal_nfc_exchange_full(tx_buff, tx_len, rx_buff, sizeof(rx_buff), &rx_len);
  614. if(err != ERR_NONE) {
  615. FURI_LOG_W(TAG, "Bad exchange getting file settings, err: %d", err);
  616. continue;
  617. }
  618. if(!mf_df_parse_get_file_settings_response(rx_buff, rx_len, file)) {
  619. FURI_LOG_W(TAG, "Bad DESFire GET_FILE_SETTINGS response");
  620. continue;
  621. }
  622. switch(file->type) {
  623. case MifareDesfireFileTypeStandard:
  624. case MifareDesfireFileTypeBackup:
  625. tx_len = mf_df_prepare_read_data(tx_buff, file->id, 0, 0);
  626. break;
  627. case MifareDesfireFileTypeValue:
  628. tx_len = mf_df_prepare_get_value(tx_buff, file->id);
  629. break;
  630. case MifareDesfireFileTypeLinearRecord:
  631. case MifareDesfireFileTypeCyclicRecord:
  632. tx_len = mf_df_prepare_read_records(tx_buff, file->id, 0, 0);
  633. break;
  634. }
  635. err =
  636. furi_hal_nfc_exchange_full(tx_buff, tx_len, rx_buff, sizeof(rx_buff), &rx_len);
  637. if(err != ERR_NONE) {
  638. FURI_LOG_W(TAG, "Bad exchange reading file %d, err: %d", file->id, err);
  639. continue;
  640. }
  641. if(!mf_df_parse_read_data_response(rx_buff, rx_len, file)) {
  642. FURI_LOG_W(TAG, "Bad response reading file %d", file->id);
  643. continue;
  644. }
  645. }
  646. }
  647. // Notify caller and exit
  648. if(nfc_worker->callback) {
  649. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  650. }
  651. break;
  652. }
  653. }