mifare_ultralight.h 7.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256
  1. #pragma once
  2. #include <furi_hal_nfc.h>
  3. // Largest tag is NTAG I2C Plus 2K, both data sectors plus SRAM
  4. #define MF_UL_MAX_DUMP_SIZE ((238 + 256 + 16) * 4)
  5. #define MF_UL_TEARING_FLAG_DEFAULT (0xBD)
  6. #define MF_UL_HALT_START (0x50)
  7. #define MF_UL_GET_VERSION_CMD (0x60)
  8. #define MF_UL_READ_CMD (0x30)
  9. #define MF_UL_FAST_READ_CMD (0x3A)
  10. #define MF_UL_WRITE (0xA2)
  11. #define MF_UL_FAST_WRITE (0xA6)
  12. #define MF_UL_COMP_WRITE (0xA0)
  13. #define MF_UL_READ_CNT (0x39)
  14. #define MF_UL_INC_CNT (0xA5)
  15. #define MF_UL_AUTH (0x1B)
  16. #define MF_UL_READ_SIG (0x3C)
  17. #define MF_UL_CHECK_TEARING (0x3E)
  18. #define MF_UL_READ_VCSL (0x4B)
  19. #define MF_UL_SECTOR_SELECT (0xC2)
  20. #define MF_UL_ACK (0xa)
  21. #define MF_UL_NAK_INVALID_ARGUMENT (0x0)
  22. #define MF_UL_NAK_AUTHLIM_REACHED (0x4)
  23. #define MF_UL_NTAG203_COUNTER_PAGE (41)
  24. #define MF_UL_DEFAULT_PWD (0xFFFFFFFF)
  25. typedef enum {
  26. MfUltralightAuthMethodManual,
  27. MfUltralightAuthMethodAmeebo,
  28. MfUltralightAuthMethodXiaomi,
  29. MfUltralightAuthMethodAuto,
  30. } MfUltralightAuthMethod;
  31. // Important: order matters; some features are based on positioning in this enum
  32. typedef enum {
  33. MfUltralightTypeUnknown,
  34. MfUltralightTypeNTAG203,
  35. // Below have config pages and GET_VERSION support
  36. MfUltralightTypeUL11,
  37. MfUltralightTypeUL21,
  38. MfUltralightTypeNTAG213,
  39. MfUltralightTypeNTAG215,
  40. MfUltralightTypeNTAG216,
  41. // Below also have sector select
  42. // NTAG I2C's *does not* have regular config pages, so it's a bit of an odd duck
  43. MfUltralightTypeNTAGI2C1K,
  44. MfUltralightTypeNTAGI2C2K,
  45. // NTAG I2C Plus has stucture expected from NTAG21x
  46. MfUltralightTypeNTAGI2CPlus1K,
  47. MfUltralightTypeNTAGI2CPlus2K,
  48. // Keep last for number of types calculation
  49. MfUltralightTypeNum,
  50. } MfUltralightType;
  51. typedef enum {
  52. MfUltralightSupportNone = 0,
  53. MfUltralightSupportFastRead = 1 << 0,
  54. MfUltralightSupportTearingFlags = 1 << 1,
  55. MfUltralightSupportReadCounter = 1 << 2,
  56. MfUltralightSupportIncrCounter = 1 << 3,
  57. MfUltralightSupportSignature = 1 << 4,
  58. MfUltralightSupportFastWrite = 1 << 5,
  59. MfUltralightSupportCompatWrite = 1 << 6,
  60. MfUltralightSupportAuth = 1 << 7,
  61. MfUltralightSupportVcsl = 1 << 8,
  62. MfUltralightSupportSectorSelect = 1 << 9,
  63. // NTAG21x only has counter 2
  64. MfUltralightSupportSingleCounter = 1 << 10,
  65. // ASCII mirror is not a command, but handy to have as a flag
  66. MfUltralightSupportAsciiMirror = 1 << 11,
  67. // NTAG203 counter that's in memory rather than through a command
  68. MfUltralightSupportCounterInMemory = 1 << 12,
  69. } MfUltralightFeatures;
  70. typedef enum {
  71. MfUltralightMirrorNone,
  72. MfUltralightMirrorUid,
  73. MfUltralightMirrorCounter,
  74. MfUltralightMirrorUidCounter,
  75. } MfUltralightMirrorConf;
  76. typedef struct {
  77. uint8_t header;
  78. uint8_t vendor_id;
  79. uint8_t prod_type;
  80. uint8_t prod_subtype;
  81. uint8_t prod_ver_major;
  82. uint8_t prod_ver_minor;
  83. uint8_t storage_size;
  84. uint8_t protocol_type;
  85. } MfUltralightVersion;
  86. typedef struct {
  87. uint8_t sn0[3];
  88. uint8_t btBCC0;
  89. uint8_t sn1[4];
  90. uint8_t btBCC1;
  91. uint8_t internal;
  92. uint8_t lock[2];
  93. uint8_t otp[4];
  94. } MfUltralightManufacturerBlock;
  95. typedef struct {
  96. MfUltralightType type;
  97. MfUltralightVersion version;
  98. uint8_t signature[32];
  99. uint32_t counter[3];
  100. uint8_t tearing[3];
  101. MfUltralightAuthMethod auth_method;
  102. uint8_t auth_key[4];
  103. bool auth_success;
  104. uint16_t curr_authlim;
  105. uint16_t data_size;
  106. uint8_t data[MF_UL_MAX_DUMP_SIZE];
  107. uint16_t data_read;
  108. } MfUltralightData;
  109. typedef struct __attribute__((packed)) {
  110. union {
  111. uint8_t raw[4];
  112. uint32_t value;
  113. } pwd;
  114. union {
  115. uint8_t raw[2];
  116. uint16_t value;
  117. } pack;
  118. } MfUltralightAuth;
  119. // Common configuration pages for MFUL EV1, NTAG21x, and NTAG I2C Plus
  120. typedef struct __attribute__((packed)) {
  121. union {
  122. uint8_t value;
  123. struct {
  124. uint8_t rfui1 : 2;
  125. bool strg_mod_en : 1;
  126. bool rfui2 : 1;
  127. uint8_t mirror_byte : 2;
  128. MfUltralightMirrorConf mirror_conf : 2;
  129. };
  130. } mirror;
  131. uint8_t rfui1;
  132. uint8_t mirror_page;
  133. uint8_t auth0;
  134. union {
  135. uint8_t value;
  136. struct {
  137. uint8_t authlim : 3;
  138. bool nfc_cnt_pwd_prot : 1;
  139. bool nfc_cnt_en : 1;
  140. bool nfc_dis_sec1 : 1; // NTAG I2C Plus only
  141. bool cfglck : 1;
  142. bool prot : 1;
  143. };
  144. } access;
  145. uint8_t vctid;
  146. uint8_t rfui2[2];
  147. MfUltralightAuth auth_data;
  148. uint8_t rfui3[2];
  149. } MfUltralightConfigPages;
  150. typedef struct {
  151. uint16_t pages_to_read;
  152. int16_t pages_read;
  153. MfUltralightFeatures supported_features;
  154. } MfUltralightReader;
  155. // TODO rework with reader analyzer
  156. typedef void (*MfUltralightAuthReceivedCallback)(MfUltralightAuth auth, void* context);
  157. typedef struct {
  158. MfUltralightData data;
  159. MfUltralightConfigPages* config;
  160. // Most config values don't apply until power cycle, so cache config pages
  161. // for correct behavior
  162. MfUltralightConfigPages config_cache;
  163. MfUltralightFeatures supported_features;
  164. uint16_t page_num;
  165. bool data_changed;
  166. bool comp_write_cmd_started;
  167. uint8_t comp_write_page_addr;
  168. bool auth_success;
  169. uint8_t curr_sector;
  170. bool sector_select_cmd_started;
  171. bool ntag_i2c_plus_sector3_lockout;
  172. bool read_counter_incremented;
  173. bool auth_attempted;
  174. MfUltralightAuth auth_attempt;
  175. // TODO rework with reader analyzer
  176. MfUltralightAuthReceivedCallback auth_received_callback;
  177. void* context;
  178. } MfUltralightEmulator;
  179. void mf_ul_reset(MfUltralightData* data);
  180. bool mf_ul_check_card_type(uint8_t ATQA0, uint8_t ATQA1, uint8_t SAK);
  181. bool mf_ultralight_read_version(
  182. FuriHalNfcTxRxContext* tx_rx,
  183. MfUltralightReader* reader,
  184. MfUltralightData* data);
  185. bool mf_ultralight_read_pages_direct(
  186. FuriHalNfcTxRxContext* tx_rx,
  187. uint8_t start_index,
  188. uint8_t* data);
  189. bool mf_ultralight_read_pages(
  190. FuriHalNfcTxRxContext* tx_rx,
  191. MfUltralightReader* reader,
  192. MfUltralightData* data);
  193. bool mf_ultralight_fast_read_pages(
  194. FuriHalNfcTxRxContext* tx_rx,
  195. MfUltralightReader* reader,
  196. MfUltralightData* data);
  197. bool mf_ultralight_read_signature(FuriHalNfcTxRxContext* tx_rx, MfUltralightData* data);
  198. bool mf_ultralight_read_counters(FuriHalNfcTxRxContext* tx_rx, MfUltralightData* data);
  199. bool mf_ultralight_read_tearing_flags(FuriHalNfcTxRxContext* tx_rx, MfUltralightData* data);
  200. bool mf_ultralight_authenticate(FuriHalNfcTxRxContext* tx_rx, uint32_t key, uint16_t* pack);
  201. MfUltralightConfigPages* mf_ultralight_get_config_pages(MfUltralightData* data);
  202. bool mf_ul_read_card(
  203. FuriHalNfcTxRxContext* tx_rx,
  204. MfUltralightReader* reader,
  205. MfUltralightData* data);
  206. void mf_ul_reset_emulation(MfUltralightEmulator* emulator, bool is_power_cycle);
  207. void mf_ul_prepare_emulation(MfUltralightEmulator* emulator, MfUltralightData* data);
  208. bool mf_ul_prepare_emulation_response(
  209. uint8_t* buff_rx,
  210. uint16_t buff_rx_len,
  211. uint8_t* buff_tx,
  212. uint16_t* buff_tx_len,
  213. uint32_t* data_type,
  214. void* context);
  215. uint32_t mf_ul_pwdgen_amiibo(FuriHalNfcDevData* data);
  216. uint32_t mf_ul_pwdgen_xiaomi(FuriHalNfcDevData* data);
  217. bool mf_ul_is_full_capture(MfUltralightData* data);