mifare_ultralight.c 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364
  1. #include "mifare_ultralight.h"
  2. #include <furi.h>
  3. #include <furi_hal_nfc.h>
  4. bool mf_ul_check_card_type(uint8_t ATQA0, uint8_t ATQA1, uint8_t SAK) {
  5. if((ATQA0 == 0x44) && (ATQA1 == 0x00) && (SAK == 0x00)) {
  6. return true;
  7. }
  8. return false;
  9. }
  10. uint16_t mf_ul_prepare_get_version(uint8_t* dest) {
  11. dest[0] = MF_UL_GET_VERSION_CMD;
  12. return 1;
  13. }
  14. void mf_ul_parse_get_version_response(uint8_t* buff, MifareUlDevice* mf_ul_read) {
  15. MfUltralightVersion* version = (MfUltralightVersion*)buff;
  16. memcpy(&mf_ul_read->data.version, version, sizeof(MfUltralightVersion));
  17. if(version->storage_size == 0x0B || version->storage_size == 0x00) {
  18. mf_ul_read->data.type = MfUltralightTypeUL11;
  19. mf_ul_read->pages_to_read = 20;
  20. mf_ul_read->support_fast_read = true;
  21. } else if(version->storage_size == 0x0E) {
  22. mf_ul_read->data.type = MfUltralightTypeUL21;
  23. mf_ul_read->pages_to_read = 41;
  24. mf_ul_read->support_fast_read = true;
  25. } else if(version->storage_size == 0x0F) {
  26. mf_ul_read->data.type = MfUltralightTypeNTAG213;
  27. mf_ul_read->pages_to_read = 45;
  28. mf_ul_read->support_fast_read = false;
  29. } else if(version->storage_size == 0x11) {
  30. mf_ul_read->data.type = MfUltralightTypeNTAG215;
  31. mf_ul_read->pages_to_read = 135;
  32. mf_ul_read->support_fast_read = false;
  33. } else if(version->storage_size == 0x13) {
  34. mf_ul_read->data.type = MfUltralightTypeNTAG216;
  35. mf_ul_read->pages_to_read = 231;
  36. mf_ul_read->support_fast_read = false;
  37. } else {
  38. mf_ul_set_default_version(mf_ul_read);
  39. }
  40. }
  41. void mf_ul_set_default_version(MifareUlDevice* mf_ul_read) {
  42. mf_ul_read->data.type = MfUltralightTypeUnknown;
  43. mf_ul_read->pages_to_read = 16;
  44. mf_ul_read->support_fast_read = false;
  45. }
  46. uint16_t mf_ul_prepare_read(uint8_t* dest, uint8_t start_page) {
  47. dest[0] = MF_UL_READ_CMD;
  48. dest[1] = start_page;
  49. return 2;
  50. }
  51. void mf_ul_parse_read_response(uint8_t* buff, uint16_t page_addr, MifareUlDevice* mf_ul_read) {
  52. uint8_t pages_read = 4;
  53. uint8_t page_read_count = mf_ul_read->pages_read + pages_read;
  54. if(page_read_count > mf_ul_read->pages_to_read) {
  55. pages_read -= page_read_count - mf_ul_read->pages_to_read;
  56. }
  57. mf_ul_read->pages_read += pages_read;
  58. mf_ul_read->data.data_size = mf_ul_read->pages_read * 4;
  59. memcpy(&mf_ul_read->data.data[page_addr * 4], buff, pages_read * 4);
  60. }
  61. uint16_t mf_ul_prepare_fast_read(uint8_t* dest, uint8_t start_page, uint8_t end_page) {
  62. dest[0] = MF_UL_FAST_READ_CMD;
  63. dest[1] = start_page;
  64. dest[2] = end_page;
  65. return 3;
  66. }
  67. void mf_ul_parse_fast_read_response(
  68. uint8_t* buff,
  69. uint8_t start_page,
  70. uint8_t end_page,
  71. MifareUlDevice* mf_ul_read) {
  72. mf_ul_read->pages_read = end_page - start_page + 1;
  73. mf_ul_read->data.data_size = mf_ul_read->pages_read * 4;
  74. memcpy(mf_ul_read->data.data, buff, mf_ul_read->data.data_size);
  75. }
  76. uint16_t mf_ul_prepare_read_signature(uint8_t* dest) {
  77. dest[0] = MF_UL_READ_SIG;
  78. dest[1] = 0;
  79. return 2;
  80. }
  81. void mf_ul_parse_read_signature_response(uint8_t* buff, MifareUlDevice* mf_ul_read) {
  82. memcpy(mf_ul_read->data.signature, buff, sizeof(mf_ul_read->data.signature));
  83. }
  84. uint16_t mf_ul_prepare_read_cnt(uint8_t* dest, uint8_t cnt_index) {
  85. if(cnt_index > 2) {
  86. return 0;
  87. }
  88. dest[0] = MF_UL_READ_CNT;
  89. dest[1] = cnt_index;
  90. return 2;
  91. }
  92. void mf_ul_parse_read_cnt_response(uint8_t* buff, uint8_t cnt_index, MifareUlDevice* mf_ul_read) {
  93. // Reverse LSB sequence
  94. if(cnt_index < 3) {
  95. mf_ul_read->data.counter[cnt_index] = (buff[2] << 16) | (buff[1] << 8) | (buff[0]);
  96. }
  97. }
  98. uint16_t mf_ul_prepare_inc_cnt(uint8_t* dest, uint8_t cnt_index, uint32_t value) {
  99. if(cnt_index > 2) {
  100. return 0;
  101. }
  102. dest[0] = MF_UL_INC_CNT;
  103. dest[1] = cnt_index;
  104. dest[2] = (uint8_t)value;
  105. dest[3] = (uint8_t)(value >> 8);
  106. dest[4] = (uint8_t)(value >> 16);
  107. dest[5] = 0;
  108. return 6;
  109. }
  110. uint16_t mf_ul_prepare_check_tearing(uint8_t* dest, uint8_t cnt_index) {
  111. if(cnt_index > 2) {
  112. return 0;
  113. }
  114. dest[0] = MF_UL_CHECK_TEARING;
  115. dest[1] = cnt_index;
  116. return 2;
  117. }
  118. void mf_ul_parse_check_tearing_response(
  119. uint8_t* buff,
  120. uint8_t cnt_index,
  121. MifareUlDevice* mf_ul_read) {
  122. if(cnt_index < 2) {
  123. mf_ul_read->data.tearing[cnt_index] = buff[0];
  124. }
  125. }
  126. uint16_t mf_ul_prepare_write(uint8_t* dest, uint16_t page_addr, uint32_t data) {
  127. if(page_addr < 2) {
  128. return 0;
  129. }
  130. dest[0] = MF_UL_WRITE;
  131. dest[1] = page_addr;
  132. dest[2] = (uint8_t)(data >> 24);
  133. dest[3] = (uint8_t)(data >> 16);
  134. dest[4] = (uint8_t)(data >> 8);
  135. dest[5] = (uint8_t)data;
  136. return 6;
  137. }
  138. void mf_ul_prepare_emulation(MifareUlDevice* mf_ul_emulate, MifareUlData* data) {
  139. mf_ul_emulate->data = *data;
  140. mf_ul_emulate->auth_data = NULL;
  141. mf_ul_emulate->data_changed = false;
  142. mf_ul_emulate->comp_write_cmd_started = false;
  143. if(data->version.storage_size == 0) {
  144. mf_ul_emulate->data.type = MfUltralightTypeUnknown;
  145. mf_ul_emulate->support_fast_read = false;
  146. } else if(data->version.storage_size == 0x0B) {
  147. mf_ul_emulate->data.type = MfUltralightTypeUL11;
  148. mf_ul_emulate->support_fast_read = true;
  149. } else if(data->version.storage_size == 0x0E) {
  150. mf_ul_emulate->data.type = MfUltralightTypeUL21;
  151. mf_ul_emulate->support_fast_read = true;
  152. } else if(data->version.storage_size == 0x0F) {
  153. mf_ul_emulate->data.type = MfUltralightTypeNTAG213;
  154. mf_ul_emulate->support_fast_read = true;
  155. } else if(data->version.storage_size == 0x11) {
  156. mf_ul_emulate->data.type = MfUltralightTypeNTAG215;
  157. mf_ul_emulate->support_fast_read = true;
  158. } else if(data->version.storage_size == 0x13) {
  159. mf_ul_emulate->data.type = MfUltralightTypeNTAG216;
  160. mf_ul_emulate->support_fast_read = true;
  161. }
  162. if(mf_ul_emulate->data.type >= MfUltralightTypeNTAG213) {
  163. uint16_t pwd_page = (data->data_size / 4) - 2;
  164. mf_ul_emulate->auth_data = (MifareUlAuthData*)&data->data[pwd_page * 4];
  165. }
  166. }
  167. void mf_ul_protect_auth_data_on_read_command(
  168. uint8_t* tx_buff,
  169. uint8_t start_page,
  170. uint8_t end_page,
  171. MifareUlDevice* mf_ul_emulate) {
  172. if(mf_ul_emulate->data.type >= MfUltralightTypeNTAG213) {
  173. uint8_t pwd_page = (mf_ul_emulate->data.data_size / 4) - 2;
  174. uint8_t pack_page = pwd_page + 1;
  175. if((start_page <= pwd_page) && (end_page >= pwd_page)) {
  176. memset(&tx_buff[(pwd_page - start_page) * 4], 0, 4);
  177. }
  178. if((start_page <= pack_page) && (end_page >= pack_page)) {
  179. memset(&tx_buff[(pack_page - start_page) * 4], 0, 2);
  180. }
  181. }
  182. }
  183. bool mf_ul_prepare_emulation_response(
  184. uint8_t* buff_rx,
  185. uint16_t buff_rx_len,
  186. uint8_t* buff_tx,
  187. uint16_t* buff_tx_len,
  188. uint32_t* data_type,
  189. void* context) {
  190. furi_assert(context);
  191. MifareUlDevice* mf_ul_emulate = context;
  192. uint8_t cmd = buff_rx[0];
  193. uint16_t page_num = mf_ul_emulate->data.data_size / 4;
  194. uint16_t tx_bytes = 0;
  195. uint16_t tx_bits = 0;
  196. bool command_parsed = false;
  197. // Check composite commands
  198. if(mf_ul_emulate->comp_write_cmd_started) {
  199. // Compatibility write is the only one composit command
  200. if(buff_rx_len == 16) {
  201. memcpy(&mf_ul_emulate->data.data[mf_ul_emulate->comp_write_page_addr * 4], buff_rx, 4);
  202. mf_ul_emulate->data_changed = true;
  203. // Send ACK message
  204. buff_tx[0] = 0x0A;
  205. tx_bits = 4;
  206. *data_type = FURI_HAL_NFC_TXRX_RAW;
  207. command_parsed = true;
  208. }
  209. mf_ul_emulate->comp_write_cmd_started = false;
  210. } else if(cmd == MF_UL_GET_VERSION_CMD) {
  211. if(mf_ul_emulate->data.type != MfUltralightTypeUnknown) {
  212. tx_bytes = sizeof(mf_ul_emulate->data.version);
  213. memcpy(buff_tx, &mf_ul_emulate->data.version, tx_bytes);
  214. *data_type = FURI_HAL_NFC_TXRX_DEFAULT;
  215. command_parsed = true;
  216. }
  217. } else if(cmd == MF_UL_READ_CMD) {
  218. uint8_t start_page = buff_rx[1];
  219. if(start_page < page_num) {
  220. tx_bytes = 16;
  221. if(start_page + 4 > page_num) {
  222. // Handle roll-over mechanism
  223. uint8_t end_pages_num = page_num - start_page;
  224. memcpy(buff_tx, &mf_ul_emulate->data.data[start_page * 4], end_pages_num * 4);
  225. memcpy(
  226. &buff_tx[end_pages_num * 4],
  227. mf_ul_emulate->data.data,
  228. (4 - end_pages_num) * 4);
  229. } else {
  230. memcpy(buff_tx, &mf_ul_emulate->data.data[start_page * 4], tx_bytes);
  231. }
  232. mf_ul_protect_auth_data_on_read_command(
  233. buff_tx, start_page, (start_page + 4), mf_ul_emulate);
  234. *data_type = FURI_HAL_NFC_TXRX_DEFAULT;
  235. command_parsed = true;
  236. }
  237. } else if(cmd == MF_UL_FAST_READ_CMD) {
  238. if(mf_ul_emulate->support_fast_read) {
  239. uint8_t start_page = buff_rx[1];
  240. uint8_t end_page = buff_rx[2];
  241. if((start_page < page_num) && (end_page < page_num) && (start_page < (end_page + 1))) {
  242. tx_bytes = ((end_page + 1) - start_page) * 4;
  243. memcpy(buff_tx, &mf_ul_emulate->data.data[start_page * 4], tx_bytes);
  244. mf_ul_protect_auth_data_on_read_command(
  245. buff_tx, start_page, end_page, mf_ul_emulate);
  246. *data_type = FURI_HAL_NFC_TXRX_DEFAULT;
  247. command_parsed = true;
  248. }
  249. }
  250. } else if(cmd == MF_UL_WRITE) {
  251. uint8_t write_page = buff_rx[1];
  252. if((write_page > 1) && (write_page < page_num - 2)) {
  253. memcpy(&mf_ul_emulate->data.data[write_page * 4], &buff_rx[2], 4);
  254. mf_ul_emulate->data_changed = true;
  255. // ACK
  256. buff_tx[0] = 0x0A;
  257. tx_bits = 4;
  258. *data_type = FURI_HAL_NFC_TXRX_RAW;
  259. command_parsed = true;
  260. }
  261. } else if(cmd == MF_UL_COMP_WRITE) {
  262. uint8_t write_page = buff_rx[1];
  263. if((write_page > 1) && (write_page < page_num - 2)) {
  264. mf_ul_emulate->comp_write_cmd_started = true;
  265. mf_ul_emulate->comp_write_page_addr = write_page;
  266. // ACK
  267. buff_tx[0] = 0x0A;
  268. tx_bits = 4;
  269. *data_type = FURI_HAL_NFC_TXRX_RAW;
  270. command_parsed = true;
  271. }
  272. } else if(cmd == MF_UL_READ_CNT) {
  273. uint8_t cnt_num = buff_rx[1];
  274. if(cnt_num < 3) {
  275. buff_tx[0] = mf_ul_emulate->data.counter[cnt_num] >> 16;
  276. buff_tx[1] = mf_ul_emulate->data.counter[cnt_num] >> 8;
  277. buff_tx[2] = mf_ul_emulate->data.counter[cnt_num];
  278. tx_bytes = 3;
  279. *data_type = FURI_HAL_NFC_TXRX_DEFAULT;
  280. command_parsed = true;
  281. }
  282. } else if(cmd == MF_UL_INC_CNT) {
  283. uint8_t cnt_num = buff_rx[1];
  284. uint32_t inc = (buff_rx[2] | (buff_rx[3] << 8) | (buff_rx[4] << 16));
  285. if((cnt_num < 3) && (mf_ul_emulate->data.counter[cnt_num] + inc < 0x00FFFFFF)) {
  286. mf_ul_emulate->data.counter[cnt_num] += inc;
  287. mf_ul_emulate->data_changed = true;
  288. // ACK
  289. buff_tx[0] = 0x0A;
  290. tx_bits = 4;
  291. *data_type = FURI_HAL_NFC_TXRX_RAW;
  292. command_parsed = true;
  293. }
  294. } else if(cmd == MF_UL_AUTH) {
  295. if(mf_ul_emulate->data.type >= MfUltralightTypeNTAG213) {
  296. if(memcmp(&buff_rx[1], mf_ul_emulate->auth_data->pwd, 4) == 0) {
  297. buff_tx[0] = mf_ul_emulate->auth_data->pack.raw[0];
  298. buff_tx[1] = mf_ul_emulate->auth_data->pack.raw[1];
  299. tx_bytes = 2;
  300. *data_type = FURI_HAL_NFC_TXRX_DEFAULT;
  301. command_parsed = true;
  302. } else if(!mf_ul_emulate->auth_data->pack.value) {
  303. buff_tx[0] = 0x80;
  304. buff_tx[1] = 0x80;
  305. tx_bytes = 2;
  306. *data_type = FURI_HAL_NFC_TXRX_DEFAULT;
  307. command_parsed = true;
  308. }
  309. }
  310. } else if(cmd == MF_UL_READ_SIG) {
  311. // Check 2nd byte = 0x00 - RFU
  312. if(buff_rx[1] == 0x00) {
  313. tx_bytes = sizeof(mf_ul_emulate->data.signature);
  314. memcpy(buff_tx, mf_ul_emulate->data.signature, tx_bytes);
  315. *data_type = FURI_HAL_NFC_TXRX_DEFAULT;
  316. command_parsed = true;
  317. }
  318. } else if(cmd == MF_UL_CHECK_TEARING) {
  319. uint8_t cnt_num = buff_rx[1];
  320. if(cnt_num < 3) {
  321. buff_tx[0] = mf_ul_emulate->data.tearing[cnt_num];
  322. tx_bytes = 1;
  323. *data_type = FURI_HAL_NFC_TXRX_DEFAULT;
  324. command_parsed = true;
  325. }
  326. } else if(cmd == MF_UL_HALT_START) {
  327. tx_bits = 0;
  328. command_parsed = true;
  329. }
  330. if(!command_parsed) {
  331. // Send NACK
  332. buff_tx[0] = 0x00;
  333. tx_bits = 4;
  334. *data_type = FURI_HAL_NFC_TXRX_RAW;
  335. }
  336. // Return tx buffer size in bits
  337. if(tx_bytes) {
  338. tx_bits = tx_bytes * 8;
  339. }
  340. *buff_tx_len = tx_bits;
  341. return tx_bits > 0;
  342. }