gen4_poller_i.c 9.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287
  1. #include "gen4_poller_i.h"
  2. #include "bit_buffer.h"
  3. #include "protocols/gen4/gen4_poller.h"
  4. #include <nfc/protocols/iso14443_3a/iso14443_3a_poller.h>
  5. #define GEN4_CMD_PREFIX (0xCF)
  6. #define GEN4_CMD_SET_SHD_MODE (0x32)
  7. #define GEN4_CMD_GET_CFG (0xC6)
  8. #define GEN4_CMD_GET_REVISION (0xCC)
  9. #define GEN4_CMD_WRITE (0xCD)
  10. #define GEN4_CMD_READ (0xCE)
  11. #define GEN4_CMD_SET_DW_BLOCK_0 (0xCF)
  12. #define GEN4_CMD_SET_CFG (0xF0)
  13. #define GEN4_CMD_FUSE_CFG (0xF1)
  14. #define GEN4_CMD_SET_PWD (0xFE)
  15. #define GEM4_RESPONSE_SUCCESS (0x02)
  16. #define CONFIG_SIZE_MAX (32)
  17. #define CONFIG_SIZE_MIN (30)
  18. #define REVISION_SIZE (5)
  19. static Gen4PollerError gen4_poller_process_error(Iso14443_3aError error) {
  20. Gen4PollerError ret = Gen4PollerErrorNone;
  21. if(error == Iso14443_3aErrorNone) {
  22. ret = Gen4PollerErrorNone;
  23. } else {
  24. ret = Gen4PollerErrorTimeout;
  25. }
  26. return ret;
  27. }
  28. Gen4PollerError gen4_poller_set_shadow_mode(
  29. Gen4Poller* instance,
  30. uint32_t password,
  31. Gen4PollerShadowMode mode) {
  32. Gen4PollerError ret = Gen4PollerErrorNone;
  33. bit_buffer_reset(instance->tx_buffer);
  34. do {
  35. uint8_t password_arr[4] = {};
  36. bit_lib_num_to_bytes_be(password, COUNT_OF(password_arr), password_arr);
  37. bit_buffer_append_byte(instance->tx_buffer, GEN4_CMD_PREFIX);
  38. bit_buffer_append_bytes(instance->tx_buffer, password_arr, COUNT_OF(password_arr));
  39. bit_buffer_append_byte(instance->tx_buffer, GEN4_CMD_SET_SHD_MODE);
  40. bit_buffer_append_byte(instance->tx_buffer, mode);
  41. Iso14443_3aError error = iso14443_3a_poller_send_standard_frame(
  42. instance->iso3_poller, instance->tx_buffer, instance->rx_buffer, GEN4_POLLER_MAX_FWT);
  43. if(error != Iso14443_3aErrorNone) {
  44. ret = gen4_poller_process_error(error);
  45. break;
  46. }
  47. size_t response = bit_buffer_get_size_bytes(instance->rx_buffer);
  48. FURI_LOG_D(TAG, "Card response: 0x%02X, Shadow mode set: 0x%02X", response, mode);
  49. if(response != GEM4_RESPONSE_SUCCESS) {
  50. ret = Gen4PollerErrorProtocol;
  51. break;
  52. }
  53. } while(false);
  54. return ret;
  55. }
  56. Gen4PollerError gen4_poller_set_direct_write_block_0_mode(
  57. Gen4Poller* instance,
  58. uint32_t password,
  59. Gen4PollerDirectWriteBlock0Mode mode) {
  60. Gen4PollerError ret = Gen4PollerErrorNone;
  61. bit_buffer_reset(instance->tx_buffer);
  62. do {
  63. uint8_t password_arr[4] = {};
  64. bit_lib_num_to_bytes_be(password, COUNT_OF(password_arr), password_arr);
  65. bit_buffer_append_byte(instance->tx_buffer, GEN4_CMD_PREFIX);
  66. bit_buffer_append_bytes(instance->tx_buffer, password_arr, COUNT_OF(password_arr));
  67. bit_buffer_append_byte(instance->tx_buffer, GEN4_CMD_SET_DW_BLOCK_0);
  68. bit_buffer_append_byte(instance->tx_buffer, mode);
  69. Iso14443_3aError error = iso14443_3a_poller_send_standard_frame(
  70. instance->iso3_poller, instance->tx_buffer, instance->rx_buffer, GEN4_POLLER_MAX_FWT);
  71. if(error != Iso14443_3aErrorNone) {
  72. ret = gen4_poller_process_error(error);
  73. break;
  74. }
  75. size_t response = bit_buffer_get_size_bytes(instance->rx_buffer);
  76. FURI_LOG_D(
  77. TAG, "Card response: 0x%02X, Direct write to block 0 mode set: 0x%02X", response, mode);
  78. if(response != GEM4_RESPONSE_SUCCESS) {
  79. ret = Gen4PollerErrorProtocol;
  80. break;
  81. }
  82. } while(false);
  83. return ret;
  84. }
  85. Gen4PollerError
  86. gen4_poller_get_config(Gen4Poller* instance, uint32_t password, uint8_t* config_result) {
  87. Gen4PollerError ret = Gen4PollerErrorNone;
  88. bit_buffer_reset(instance->tx_buffer);
  89. do {
  90. uint8_t password_arr[4] = {};
  91. bit_lib_num_to_bytes_be(password, COUNT_OF(password_arr), password_arr);
  92. bit_buffer_append_byte(instance->tx_buffer, GEN4_CMD_PREFIX);
  93. bit_buffer_append_bytes(instance->tx_buffer, password_arr, COUNT_OF(password_arr));
  94. bit_buffer_append_byte(instance->tx_buffer, GEN4_CMD_GET_CFG);
  95. Iso14443_3aError error = iso14443_3a_poller_send_standard_frame(
  96. instance->iso3_poller, instance->tx_buffer, instance->rx_buffer, GEN4_POLLER_MAX_FWT);
  97. if(error != Iso14443_3aErrorNone) {
  98. ret = gen4_poller_process_error(error);
  99. break;
  100. }
  101. size_t rx_bytes = bit_buffer_get_size_bytes(instance->rx_buffer);
  102. if((rx_bytes != CONFIG_SIZE_MAX) && (rx_bytes != CONFIG_SIZE_MIN)) {
  103. ret = Gen4PollerErrorProtocol;
  104. break;
  105. }
  106. bit_buffer_write_bytes(instance->rx_buffer, config_result, CONFIG_SIZE_MAX);
  107. } while(false);
  108. return ret;
  109. }
  110. Gen4PollerError
  111. gen4_poller_get_revision(Gen4Poller* instance, uint32_t password, uint8_t* revision_result) {
  112. Gen4PollerError ret = Gen4PollerErrorNone;
  113. bit_buffer_reset(instance->tx_buffer);
  114. do {
  115. uint8_t password_arr[4] = {};
  116. bit_lib_num_to_bytes_be(password, COUNT_OF(password_arr), password_arr);
  117. bit_buffer_append_byte(instance->tx_buffer, GEN4_CMD_PREFIX);
  118. bit_buffer_append_bytes(instance->tx_buffer, password_arr, COUNT_OF(password_arr));
  119. bit_buffer_append_byte(instance->tx_buffer, GEN4_CMD_GET_REVISION);
  120. Iso14443_3aError error = iso14443_3a_poller_send_standard_frame(
  121. instance->iso3_poller, instance->tx_buffer, instance->rx_buffer, GEN4_POLLER_MAX_FWT);
  122. if(error != Iso14443_3aErrorNone) {
  123. ret = gen4_poller_process_error(error);
  124. break;
  125. }
  126. size_t rx_bytes = bit_buffer_get_size_bytes(instance->rx_buffer);
  127. if(rx_bytes != REVISION_SIZE) {
  128. ret = Gen4PollerErrorProtocol;
  129. break;
  130. }
  131. bit_buffer_write_bytes(instance->rx_buffer, revision_result, REVISION_SIZE);
  132. } while(false);
  133. return ret;
  134. }
  135. Gen4PollerError gen4_poller_set_config(
  136. Gen4Poller* instance,
  137. uint32_t password,
  138. const uint8_t* config,
  139. size_t config_size,
  140. bool fuse) {
  141. Gen4PollerError ret = Gen4PollerErrorNone;
  142. bit_buffer_reset(instance->tx_buffer);
  143. do {
  144. uint8_t password_arr[4] = {};
  145. bit_lib_num_to_bytes_be(password, COUNT_OF(password_arr), password_arr);
  146. bit_buffer_append_byte(instance->tx_buffer, GEN4_CMD_PREFIX);
  147. bit_buffer_append_bytes(instance->tx_buffer, password_arr, COUNT_OF(password_arr));
  148. uint8_t fuse_config = fuse ? GEN4_CMD_FUSE_CFG : GEN4_CMD_SET_CFG;
  149. bit_buffer_append_byte(instance->tx_buffer, fuse_config);
  150. bit_buffer_append_bytes(instance->tx_buffer, config, config_size);
  151. Iso14443_3aError error = iso14443_3a_poller_send_standard_frame(
  152. instance->iso3_poller, instance->tx_buffer, instance->rx_buffer, GEN4_POLLER_MAX_FWT);
  153. if(error != Iso14443_3aErrorNone) {
  154. ret = gen4_poller_process_error(error);
  155. break;
  156. }
  157. size_t response = bit_buffer_get_size_bytes(instance->rx_buffer);
  158. FURI_LOG_D(TAG, "Card response to set default config command: 0x%02X", response);
  159. if(response != GEM4_RESPONSE_SUCCESS) {
  160. ret = Gen4PollerErrorProtocol;
  161. break;
  162. }
  163. } while(false);
  164. return ret;
  165. }
  166. Gen4PollerError gen4_poller_write_block(
  167. Gen4Poller* instance,
  168. uint32_t password,
  169. uint8_t block_num,
  170. const uint8_t* data) {
  171. Gen4PollerError ret = Gen4PollerErrorNone;
  172. bit_buffer_reset(instance->tx_buffer);
  173. do {
  174. uint8_t password_arr[4] = {};
  175. bit_lib_num_to_bytes_be(password, COUNT_OF(password_arr), password_arr);
  176. bit_buffer_append_byte(instance->tx_buffer, GEN4_CMD_PREFIX);
  177. bit_buffer_append_bytes(instance->tx_buffer, password_arr, COUNT_OF(password_arr));
  178. bit_buffer_append_byte(instance->tx_buffer, GEN4_CMD_WRITE);
  179. bit_buffer_append_byte(instance->tx_buffer, block_num);
  180. bit_buffer_append_bytes(instance->tx_buffer, data, GEN4_POLLER_BLOCK_SIZE);
  181. Iso14443_3aError error = iso14443_3a_poller_send_standard_frame(
  182. instance->iso3_poller, instance->tx_buffer, instance->rx_buffer, GEN4_POLLER_MAX_FWT);
  183. if(error != Iso14443_3aErrorNone) {
  184. ret = gen4_poller_process_error(error);
  185. break;
  186. }
  187. size_t rx_bytes = bit_buffer_get_size_bytes(instance->rx_buffer);
  188. if(rx_bytes != 2) {
  189. ret = Gen4PollerErrorProtocol;
  190. break;
  191. }
  192. } while(false);
  193. return ret;
  194. }
  195. Gen4PollerError
  196. gen4_poller_change_password(Gen4Poller* instance, uint32_t pwd_current, uint32_t pwd_new) {
  197. Gen4PollerError ret = Gen4PollerErrorNone;
  198. bit_buffer_reset(instance->tx_buffer);
  199. do {
  200. uint8_t password_arr[4] = {};
  201. bit_lib_num_to_bytes_be(pwd_current, COUNT_OF(password_arr), password_arr);
  202. bit_buffer_append_byte(instance->tx_buffer, GEN4_CMD_PREFIX);
  203. bit_buffer_append_bytes(instance->tx_buffer, password_arr, COUNT_OF(password_arr));
  204. bit_buffer_append_byte(instance->tx_buffer, GEN4_CMD_SET_PWD);
  205. bit_lib_num_to_bytes_be(pwd_new, COUNT_OF(password_arr), password_arr);
  206. bit_buffer_append_bytes(instance->tx_buffer, password_arr, COUNT_OF(password_arr));
  207. Iso14443_3aError error = iso14443_3a_poller_send_standard_frame(
  208. instance->iso3_poller, instance->tx_buffer, instance->rx_buffer, GEN4_POLLER_MAX_FWT);
  209. if(error != Iso14443_3aErrorNone) {
  210. ret = gen4_poller_process_error(error);
  211. break;
  212. }
  213. size_t response = bit_buffer_get_size_bytes(instance->rx_buffer);
  214. FURI_LOG_D(
  215. TAG,
  216. "Trying to change password from 0x%08lX to 0x%08lX. Card response: 0x%02X",
  217. pwd_current,
  218. pwd_new,
  219. response);
  220. if(response != GEM4_RESPONSE_SUCCESS) {
  221. ret = Gen4PollerErrorProtocol;
  222. break;
  223. }
  224. } while(false);
  225. return ret;
  226. }