passy_reader.c 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473
  1. #include "passy_reader.h"
  2. #define TAG "PassyReader"
  3. #define PASSY_READER_DG1_CHUNK_SIZE 0x20
  4. #define PASSY_READER_DG2_CHUNK_SIZE 0x20
  5. static uint8_t passport_aid[] = {0xA0, 0x00, 0x00, 0x02, 0x47, 0x10, 0x01};
  6. static uint8_t select_header[] = {0x00, 0xA4, 0x04, 0x0C};
  7. static uint8_t get_challenge[] = {0x00, 0x84, 0x00, 0x00, 0x08};
  8. static uint8_t SW_success[] = {0x90, 0x00};
  9. static const uint8_t jpeg_header[4] = {0xFF, 0xD8, 0xFF, 0xE0};
  10. static const uint8_t jpeg2k_header[6] = {0x00, 0x00, 0x00, 0x0C, 0x6A, 0x50};
  11. static const uint8_t jpeg2k_cs_header[4] = {0xFF, 0x4F, 0xFF, 0x51};
  12. size_t asn1_length(uint8_t data[3]) {
  13. if(data[0] <= 0x7F) {
  14. return data[0];
  15. } else if(data[0] == 0x81) {
  16. return data[1];
  17. } else if(data[0] == 0x82) {
  18. return (data[1] << 8) | data[2];
  19. }
  20. return 0;
  21. }
  22. size_t asn1_length_length(uint8_t data[3]) {
  23. if(data[0] <= 0x7F) {
  24. return 1;
  25. } else if(data[0] == 0x81) {
  26. return 2;
  27. } else if(data[0] == 0x82) {
  28. return 3;
  29. }
  30. return 0;
  31. }
  32. PassyReader* passy_reader_alloc(Passy* passy) {
  33. PassyReader* passy_reader = malloc(sizeof(PassyReader));
  34. memset(passy_reader, 0, sizeof(PassyReader));
  35. furi_assert(passy);
  36. passy_reader->passy = passy;
  37. passy_reader->DG1 = passy->DG1;
  38. passy_reader->tx_buffer = bit_buffer_alloc(PASSY_READER_MAX_BUFFER_SIZE);
  39. passy_reader->rx_buffer = bit_buffer_alloc(PASSY_READER_MAX_BUFFER_SIZE);
  40. char passport_number[11];
  41. memset(passport_number, 0, sizeof(passport_number));
  42. memcpy(passport_number, passy->passport_number, strlen(passy->passport_number));
  43. passport_number[strlen(passy->passport_number)] = passy_checksum(passy->passport_number);
  44. FURI_LOG_I(TAG, "Passport number: %s", passport_number);
  45. char date_of_birth[8];
  46. memset(date_of_birth, 0, sizeof(date_of_birth));
  47. memcpy(date_of_birth, passy->date_of_birth, strlen(passy->date_of_birth));
  48. date_of_birth[strlen(passy->date_of_birth)] = passy_checksum(passy->date_of_birth);
  49. FURI_LOG_I(TAG, "Date of birth: %s", date_of_birth);
  50. char date_of_expiry[8];
  51. memset(date_of_expiry, 0, sizeof(date_of_expiry));
  52. memcpy(date_of_expiry, passy->date_of_expiry, strlen(passy->date_of_expiry));
  53. date_of_expiry[strlen(passy->date_of_expiry)] = passy_checksum(passy->date_of_expiry);
  54. FURI_LOG_I(TAG, "Date of expiry: %s", date_of_expiry);
  55. passy_reader->secure_messaging = secure_messaging_alloc(
  56. (uint8_t*)passport_number, (uint8_t*)date_of_birth, (uint8_t*)date_of_expiry);
  57. return passy_reader;
  58. }
  59. void passy_reader_free(PassyReader* passy_reader) {
  60. furi_assert(passy_reader);
  61. bit_buffer_free(passy_reader->tx_buffer);
  62. bit_buffer_free(passy_reader->rx_buffer);
  63. if(passy_reader->secure_messaging) {
  64. secure_messaging_free(passy_reader->secure_messaging);
  65. }
  66. free(passy_reader);
  67. }
  68. NfcCommand passy_reader_send(PassyReader* passy_reader) {
  69. NfcCommand ret = NfcCommandContinue;
  70. BitBuffer* tx_buffer = passy_reader->tx_buffer;
  71. BitBuffer* rx_buffer = passy_reader->rx_buffer;
  72. Iso14443_4bPoller* iso14443_4b_poller = passy_reader->iso14443_4b_poller;
  73. Iso14443_4bError error;
  74. passy_log_bitbuffer(TAG, "NFC transmit", tx_buffer);
  75. error = iso14443_4b_poller_send_block(iso14443_4b_poller, tx_buffer, rx_buffer);
  76. if(error != Iso14443_4bErrorNone) {
  77. FURI_LOG_W(TAG, "iso14443_4b_poller_send_block error %d", error);
  78. return NfcCommandStop;
  79. }
  80. bit_buffer_reset(tx_buffer);
  81. passy_log_bitbuffer(TAG, "NFC response", rx_buffer);
  82. // Check SW
  83. size_t length = bit_buffer_get_size_bytes(rx_buffer);
  84. const uint8_t* data = bit_buffer_get_data(rx_buffer);
  85. if(length < 2) {
  86. FURI_LOG_W(TAG, "Invalid response length %d", length);
  87. return NfcCommandStop;
  88. }
  89. if(memcmp(data + length - 2, SW_success, sizeof(SW_success)) != 0) {
  90. FURI_LOG_W(TAG, "Invalid SW %02x %02x", data[length - 2], data[length - 1]);
  91. return NfcCommandStop;
  92. }
  93. return ret;
  94. }
  95. NfcCommand passy_reader_select_application(PassyReader* passy_reader) {
  96. NfcCommand ret = NfcCommandContinue;
  97. BitBuffer* tx_buffer = passy_reader->tx_buffer;
  98. bit_buffer_append_bytes(tx_buffer, select_header, sizeof(select_header));
  99. bit_buffer_append_byte(tx_buffer, sizeof(passport_aid));
  100. bit_buffer_append_bytes(tx_buffer, passport_aid, sizeof(passport_aid));
  101. bit_buffer_append_byte(tx_buffer, 0x00); // Le
  102. ret = passy_reader_send(passy_reader);
  103. if(ret != NfcCommandContinue) {
  104. return ret;
  105. }
  106. return ret;
  107. }
  108. NfcCommand passy_reader_get_challenge(PassyReader* passy_reader) {
  109. NfcCommand ret = NfcCommandContinue;
  110. bit_buffer_append_bytes(passy_reader->tx_buffer, get_challenge, sizeof(get_challenge));
  111. ret = passy_reader_send(passy_reader);
  112. if(ret != NfcCommandContinue) {
  113. return ret;
  114. }
  115. const uint8_t* data = bit_buffer_get_data(passy_reader->rx_buffer);
  116. SecureMessaging* secure_messaging = passy_reader->secure_messaging;
  117. const uint8_t* rnd_icc = data;
  118. memcpy(secure_messaging->rndICC, rnd_icc, 8);
  119. return ret;
  120. }
  121. NfcCommand passy_reader_authenticate(PassyReader* passy_reader) {
  122. NfcCommand ret = NfcCommandContinue;
  123. BitBuffer* tx_buffer = passy_reader->tx_buffer;
  124. // TODO: move into secure_messaging
  125. SecureMessaging* secure_messaging = passy_reader->secure_messaging;
  126. uint8_t S[32];
  127. memset(S, 0, sizeof(S));
  128. uint8_t eifd[32];
  129. memcpy(S, secure_messaging->rndIFD, sizeof(secure_messaging->rndIFD));
  130. memcpy(
  131. S + sizeof(secure_messaging->rndIFD),
  132. secure_messaging->rndICC,
  133. sizeof(secure_messaging->rndICC));
  134. memcpy(
  135. S + sizeof(secure_messaging->rndIFD) + sizeof(secure_messaging->rndICC),
  136. secure_messaging->Kifd,
  137. sizeof(secure_messaging->Kifd));
  138. uint8_t iv[8];
  139. memset(iv, 0, sizeof(iv));
  140. mbedtls_des3_context ctx;
  141. mbedtls_des3_init(&ctx);
  142. mbedtls_des3_set2key_enc(&ctx, secure_messaging->KENC);
  143. mbedtls_des3_crypt_cbc(&ctx, MBEDTLS_DES_ENCRYPT, sizeof(S), iv, S, eifd);
  144. mbedtls_des3_free(&ctx);
  145. passy_log_buffer(TAG, "S", S, sizeof(S));
  146. passy_log_buffer(TAG, "eifd", eifd, sizeof(eifd));
  147. uint8_t mifd[8];
  148. passy_mac(secure_messaging->KMAC, eifd, sizeof(eifd), mifd, false);
  149. passy_log_buffer(TAG, "mifd", mifd, sizeof(mifd));
  150. uint8_t authenticate_header[] = {0x00, 0x82, 0x00, 0x00};
  151. bit_buffer_append_bytes(tx_buffer, authenticate_header, sizeof(authenticate_header));
  152. bit_buffer_append_byte(tx_buffer, sizeof(eifd) + sizeof(mifd));
  153. bit_buffer_append_bytes(tx_buffer, eifd, sizeof(eifd));
  154. bit_buffer_append_bytes(tx_buffer, mifd, sizeof(mifd));
  155. bit_buffer_append_byte(tx_buffer, 0x28); // Le
  156. ret = passy_reader_send(passy_reader);
  157. if(ret != NfcCommandContinue) {
  158. return ret;
  159. }
  160. const uint8_t* data = bit_buffer_get_data(passy_reader->rx_buffer);
  161. size_t length = bit_buffer_get_size_bytes(passy_reader->rx_buffer);
  162. const uint8_t* mac = data + length - 2 - 8;
  163. uint8_t calculated_mac[8];
  164. passy_mac(secure_messaging->KMAC, (uint8_t*)data, length - 8 - 2, calculated_mac, false);
  165. if(memcmp(mac, calculated_mac, sizeof(calculated_mac)) != 0) {
  166. FURI_LOG_W(TAG, "Invalid MAC");
  167. return NfcCommandStop;
  168. }
  169. uint8_t decrypted[32];
  170. do {
  171. uint8_t iv[8];
  172. memset(iv, 0, sizeof(iv));
  173. mbedtls_des3_context ctx;
  174. mbedtls_des3_init(&ctx);
  175. mbedtls_des3_set2key_dec(&ctx, secure_messaging->KENC);
  176. mbedtls_des3_crypt_cbc(&ctx, MBEDTLS_DES_DECRYPT, length - 2 - 8, iv, data, decrypted);
  177. mbedtls_des3_free(&ctx);
  178. } while(false);
  179. passy_log_buffer(TAG, "decrypted", decrypted, sizeof(decrypted));
  180. uint8_t* rnd_icc = decrypted;
  181. uint8_t* rnd_ifd = decrypted + 8;
  182. uint8_t* Kicc = decrypted + 16;
  183. if(memcmp(rnd_icc, secure_messaging->rndICC, sizeof(secure_messaging->rndICC)) != 0) {
  184. FURI_LOG_W(TAG, "Invalid rndICC");
  185. return NfcCommandStop;
  186. }
  187. memcpy(secure_messaging->Kicc, Kicc, sizeof(secure_messaging->Kicc));
  188. memcpy(secure_messaging->SSC + 0, rnd_icc + 4, 4);
  189. memcpy(secure_messaging->SSC + 4, rnd_ifd + 4, 4);
  190. return ret;
  191. }
  192. NfcCommand passy_reader_select_file(PassyReader* passy_reader, uint16_t file_id) {
  193. NfcCommand ret = NfcCommandContinue;
  194. uint8_t select_0101[] = {0x00, 0xa4, 0x02, 0x0c, 0x02, 0x00, 0x00};
  195. select_0101[5] = (file_id >> 8) & 0xFF;
  196. select_0101[6] = file_id & 0xFF;
  197. secure_messaging_wrap_apdu(
  198. passy_reader->secure_messaging, select_0101, sizeof(select_0101), passy_reader->tx_buffer);
  199. ret = passy_reader_send(passy_reader);
  200. if(ret != NfcCommandContinue) {
  201. return ret;
  202. }
  203. secure_messaging_unwrap_rapdu(passy_reader->secure_messaging, passy_reader->rx_buffer);
  204. passy_log_bitbuffer(TAG, "NFC response (decrypted)", passy_reader->rx_buffer);
  205. return ret;
  206. }
  207. NfcCommand passy_reader_read_binary(
  208. PassyReader* passy_reader,
  209. uint16_t offset,
  210. uint8_t Le,
  211. uint8_t* output_buffer) {
  212. NfcCommand ret = NfcCommandContinue;
  213. if(offset & 0x8000) {
  214. FURI_LOG_W(TAG, "Invalid offset %04x", offset);
  215. }
  216. uint8_t read_binary[] = {0x00, 0xB0, (offset >> 8) & 0xff, (offset >> 0) & 0xff, Le};
  217. secure_messaging_wrap_apdu(
  218. passy_reader->secure_messaging, read_binary, sizeof(read_binary), passy_reader->tx_buffer);
  219. ret = passy_reader_send(passy_reader);
  220. if(ret != NfcCommandContinue) {
  221. return ret;
  222. }
  223. secure_messaging_unwrap_rapdu(passy_reader->secure_messaging, passy_reader->rx_buffer);
  224. const uint8_t* decrypted_data = bit_buffer_get_data(passy_reader->rx_buffer);
  225. memcpy(output_buffer, decrypted_data, Le);
  226. return ret;
  227. }
  228. NfcCommand passy_reader_state_machine(PassyReader* passy_reader) {
  229. furi_assert(passy_reader);
  230. Passy* passy = passy_reader->passy;
  231. NfcCommand ret = NfcCommandContinue;
  232. do {
  233. ret = passy_reader_select_application(passy_reader);
  234. if(ret != NfcCommandContinue) {
  235. view_dispatcher_send_custom_event(passy->view_dispatcher, PassyCustomEventReaderError);
  236. break;
  237. }
  238. ret = passy_reader_get_challenge(passy_reader);
  239. if(ret != NfcCommandContinue) {
  240. view_dispatcher_send_custom_event(passy->view_dispatcher, PassyCustomEventReaderError);
  241. break;
  242. }
  243. ret = passy_reader_authenticate(passy_reader);
  244. if(ret != NfcCommandContinue) {
  245. view_dispatcher_send_custom_event(passy->view_dispatcher, PassyCustomEventReaderError);
  246. break;
  247. }
  248. FURI_LOG_I(TAG, "Mututal authentication success");
  249. secure_messaging_calculate_session_keys(passy_reader->secure_messaging);
  250. view_dispatcher_send_custom_event(
  251. passy->view_dispatcher, PassyCustomEventReaderAuthenticated);
  252. ret = passy_reader_select_file(passy_reader, passy->read_type);
  253. if(ret != NfcCommandContinue) {
  254. view_dispatcher_send_custom_event(passy->view_dispatcher, PassyCustomEventReaderError);
  255. break;
  256. }
  257. if(passy->read_type == PassyReadDG1) {
  258. bit_buffer_reset(passy->DG1);
  259. uint8_t header[4];
  260. ret = passy_reader_read_binary(passy_reader, 0x00, sizeof(header), header);
  261. if(ret != NfcCommandContinue) {
  262. view_dispatcher_send_custom_event(
  263. passy->view_dispatcher, PassyCustomEventReaderError);
  264. break;
  265. }
  266. size_t body_size = 1 + asn1_length_length(header + 1) + asn1_length(header + 1);
  267. uint8_t body_offset = sizeof(header);
  268. bit_buffer_append_bytes(passy_reader->DG1, header, sizeof(header));
  269. do {
  270. view_dispatcher_send_custom_event(
  271. passy->view_dispatcher, PassyCustomEventReaderReading);
  272. uint8_t chunk[PASSY_READER_DG1_CHUNK_SIZE];
  273. uint8_t Le = MIN(sizeof(chunk), (size_t)(body_size - body_offset));
  274. ret = passy_reader_read_binary(passy_reader, body_offset, Le, chunk);
  275. if(ret != NfcCommandContinue) {
  276. view_dispatcher_send_custom_event(
  277. passy->view_dispatcher, PassyCustomEventReaderError);
  278. break;
  279. }
  280. bit_buffer_append_bytes(passy_reader->DG1, chunk, Le);
  281. body_offset += Le;
  282. } while(body_offset < body_size);
  283. passy_log_bitbuffer(TAG, "DG1", passy_reader->DG1);
  284. } else if(passy->read_type == PassyReadDG2 || passy->read_type == PassyReadDG7) {
  285. uint8_t header[100];
  286. ret = passy_reader_read_binary(passy_reader, 0x00, sizeof(header), header);
  287. if(ret != NfcCommandContinue) {
  288. view_dispatcher_send_custom_event(
  289. passy->view_dispatcher, PassyCustomEventReaderError);
  290. break;
  291. }
  292. view_dispatcher_send_custom_event(
  293. passy->view_dispatcher, PassyCustomEventReaderReading);
  294. size_t body_size = 1 + asn1_length_length(header + 1) + asn1_length(header + 1);
  295. FURI_LOG_I(
  296. TAG, "%s length: %d", passy->read_type == PassyReadDG2 ? "DG2" : "DG7", body_size);
  297. if(body_size == 0) {
  298. FURI_LOG_W(
  299. TAG,
  300. "This document does not contain data in %s.",
  301. passy->read_type == PassyReadDG2 ? "DG2" : "DG7");
  302. view_dispatcher_send_custom_event(
  303. passy->view_dispatcher, PassyCustomEventReaderNoDGXData);
  304. break;
  305. }
  306. void* jpeg = memmem(header, sizeof(header), jpeg_header, sizeof(jpeg_header));
  307. void* jpeg2k = memmem(header, sizeof(header), jpeg2k_header, sizeof(jpeg2k_header));
  308. void* jpeg2k_cs =
  309. memmem(header, sizeof(header), jpeg2k_cs_header, sizeof(jpeg2k_cs_header));
  310. FuriString* path = furi_string_alloc();
  311. uint8_t start = 0;
  312. const char* dg_type = passy->read_type == PassyReadDG2 ? "DG2" : "DG7";
  313. if(jpeg) {
  314. furi_string_printf(
  315. path, "%s/%s%s", STORAGE_APP_DATA_PATH_PREFIX, dg_type, ".jpeg");
  316. start = (uint8_t*)jpeg - header;
  317. } else if(jpeg2k) {
  318. furi_string_printf(path, "%s/%s%s", STORAGE_APP_DATA_PATH_PREFIX, dg_type, ".jp2");
  319. start = (uint8_t*)jpeg2k - header;
  320. } else if(jpeg2k_cs) {
  321. furi_string_printf(path, "%s/%s%s", STORAGE_APP_DATA_PATH_PREFIX, dg_type, ".jpc");
  322. start = (uint8_t*)jpeg2k_cs - header;
  323. } else {
  324. furi_string_printf(path, "%s/%s%s", STORAGE_APP_DATA_PATH_PREFIX, dg_type, ".bin");
  325. start = 0;
  326. passy_log_buffer(TAG, "header", header, sizeof(header));
  327. }
  328. FURI_LOG_I(TAG, "Writing offset %d to %s", start, furi_string_get_cstr(path));
  329. Storage* storage = furi_record_open(RECORD_STORAGE);
  330. Stream* stream = file_stream_alloc(storage);
  331. file_stream_open(stream, furi_string_get_cstr(path), FSAM_WRITE, FSOM_OPEN_ALWAYS);
  332. uint8_t chunk[PASSY_READER_DG2_CHUNK_SIZE];
  333. passy->offset = start;
  334. passy->bytes_total = body_size;
  335. do {
  336. memset(chunk, 0, sizeof(chunk));
  337. uint8_t Le = MIN(sizeof(chunk), (size_t)(body_size - passy->offset));
  338. ret = passy_reader_read_binary(passy_reader, passy->offset, Le, chunk);
  339. if(ret != NfcCommandContinue) {
  340. view_dispatcher_send_custom_event(
  341. passy->view_dispatcher, PassyCustomEventReaderError);
  342. break;
  343. }
  344. passy->offset += Le;
  345. // passy_log_buffer(TAG, "chunk", chunk, sizeof(chunk));
  346. stream_write(stream, chunk, Le);
  347. view_dispatcher_send_custom_event(
  348. passy->view_dispatcher, PassyCustomEventReaderReading);
  349. } while(passy->offset < body_size);
  350. file_stream_close(stream);
  351. furi_record_close(RECORD_STORAGE);
  352. furi_string_free(path);
  353. }
  354. // Everything done
  355. ret = NfcCommandStop;
  356. view_dispatcher_send_custom_event(passy->view_dispatcher, PassyCustomEventReaderSuccess);
  357. } while(false);
  358. return ret;
  359. }
  360. NfcCommand passy_reader_poller_callback(NfcGenericEvent event, void* context) {
  361. furi_assert(event.protocol == NfcProtocolIso14443_4b);
  362. PassyReader* passy_reader = context;
  363. NfcCommand ret = NfcCommandContinue;
  364. const Iso14443_4bPollerEvent* iso14443_4b_event = event.event_data;
  365. Iso14443_4bPoller* iso14443_4b_poller = event.instance;
  366. FURI_LOG_D(TAG, "iso14443_4b_event->type %i", iso14443_4b_event->type);
  367. passy_reader->iso14443_4b_poller = iso14443_4b_poller;
  368. if(iso14443_4b_event->type == Iso14443_4bPollerEventTypeReady) {
  369. view_dispatcher_send_custom_event(
  370. passy_reader->passy->view_dispatcher, PassyCustomEventReaderDetected);
  371. nfc_device_set_data(
  372. passy_reader->passy->nfc_device,
  373. NfcProtocolIso14443_4b,
  374. nfc_poller_get_data(passy_reader->passy->poller));
  375. ret = passy_reader_state_machine(passy_reader);
  376. furi_thread_set_current_priority(FuriThreadPriorityLowest);
  377. } else if(iso14443_4b_event->type == Iso14443_4bPollerEventTypeError) {
  378. Iso14443_4bPollerEventData* data = iso14443_4b_event->data;
  379. Iso14443_4bError error = data->error;
  380. FURI_LOG_W(TAG, "Iso14443_4bError %i", error);
  381. switch(error) {
  382. case Iso14443_4bErrorNone:
  383. break;
  384. case Iso14443_4bErrorNotPresent:
  385. break;
  386. case Iso14443_4bErrorProtocol:
  387. ret = NfcCommandStop;
  388. break;
  389. case Iso14443_4bErrorTimeout:
  390. break;
  391. }
  392. }
  393. return ret;
  394. }