nfc_worker.c 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362
  1. #include "nfc_worker_i.h"
  2. #include <api-hal.h>
  3. #include "nfc_protocols/emv_decoder.h"
  4. #define NFC_WORKER_TAG "nfc worker"
  5. NfcWorker* nfc_worker_alloc(osMessageQueueId_t message_queue) {
  6. NfcWorker* nfc_worker = furi_alloc(sizeof(NfcWorker));
  7. nfc_worker->message_queue = message_queue;
  8. // Worker thread attributes
  9. nfc_worker->thread_attr.name = "nfc_worker";
  10. nfc_worker->thread_attr.stack_size = 8192;
  11. // Initialize rfal
  12. nfc_worker->error = api_hal_nfc_init();
  13. if(nfc_worker->error == ERR_NONE) {
  14. api_hal_nfc_start_sleep();
  15. nfc_worker_change_state(nfc_worker, NfcWorkerStateReady);
  16. } else {
  17. nfc_worker_change_state(nfc_worker, NfcWorkerStateBroken);
  18. }
  19. return nfc_worker;
  20. }
  21. void nfc_worker_free(NfcWorker* nfc_worker) {
  22. furi_assert(nfc_worker);
  23. free(nfc_worker);
  24. }
  25. NfcWorkerState nfc_worker_get_state(NfcWorker* nfc_worker) {
  26. return nfc_worker->state;
  27. }
  28. ReturnCode nfc_worker_get_error(NfcWorker* nfc_worker) {
  29. return nfc_worker->error;
  30. }
  31. void nfc_worker_start(NfcWorker* nfc_worker, NfcWorkerState state) {
  32. furi_assert(nfc_worker);
  33. furi_assert(nfc_worker->state == NfcWorkerStateReady);
  34. nfc_worker_change_state(nfc_worker, state);
  35. nfc_worker->thread = osThreadNew(nfc_worker_task, nfc_worker, &nfc_worker->thread_attr);
  36. }
  37. void nfc_worker_stop(NfcWorker* nfc_worker) {
  38. furi_assert(nfc_worker);
  39. if(nfc_worker->state == NfcWorkerStateBroken) {
  40. return;
  41. }
  42. nfc_worker_change_state(nfc_worker, NfcWorkerStateStop);
  43. }
  44. void nfc_worker_change_state(NfcWorker* nfc_worker, NfcWorkerState state) {
  45. nfc_worker->state = state;
  46. }
  47. void nfc_worker_task(void* context) {
  48. NfcWorker* nfc_worker = context;
  49. api_hal_power_insomnia_enter();
  50. if(nfc_worker->state == NfcWorkerStatePoll) {
  51. nfc_worker_poll(nfc_worker);
  52. } else if(nfc_worker->state == NfcWorkerStateReadEMV) {
  53. nfc_worker_read_emv(nfc_worker);
  54. } else if(nfc_worker->state == NfcWorkerStateEmulate) {
  55. nfc_worker_emulate(nfc_worker);
  56. } else if(nfc_worker->state == NfcWorkerStateField) {
  57. nfc_worker_field(nfc_worker);
  58. }
  59. nfc_worker_change_state(nfc_worker, NfcWorkerStateReady);
  60. api_hal_power_insomnia_exit();
  61. osThreadExit();
  62. }
  63. void nfc_worker_read_emv(NfcWorker* nfc_worker) {
  64. ReturnCode err;
  65. rfalNfcDevice* dev_list;
  66. rfalNfcDevice* dev_active;
  67. EmvApplication emv_app = {};
  68. uint8_t dev_cnt = 0;
  69. uint8_t tx_buff[255] = {};
  70. uint16_t tx_len = 0;
  71. uint8_t* rx_buff;
  72. uint16_t* rx_len;
  73. // Update screen before start searching
  74. NfcMessage message = {.type = NfcMessageTypeEMVNotFound};
  75. while(nfc_worker->state == NfcWorkerStateReadEMV) {
  76. furi_check(
  77. osMessageQueuePut(nfc_worker->message_queue, &message, 0, osWaitForever) == osOK);
  78. memset(&emv_app, 0, sizeof(emv_app));
  79. if(api_hal_nfc_detect(&dev_list, &dev_cnt, 100, false)) {
  80. // Card was found. Check that it supports EMV
  81. if(dev_list[0].rfInterface == RFAL_NFC_INTERFACE_ISODEP) {
  82. dev_active = &dev_list[0];
  83. FURI_LOG_I(NFC_WORKER_TAG, "Send select PPSE command");
  84. tx_len = emv_prepare_select_ppse(tx_buff);
  85. err = api_hal_nfc_data_exchange(
  86. dev_active, tx_buff, tx_len, &rx_buff, &rx_len, false);
  87. if(err != ERR_NONE) {
  88. FURI_LOG_E(NFC_WORKER_TAG, "Error during selection PPSE request: %d", err);
  89. message.type = NfcMessageTypeEMVNotFound;
  90. api_hal_nfc_deactivate();
  91. continue;
  92. }
  93. FURI_LOG_I(
  94. NFC_WORKER_TAG, "Select PPSE response received. Start parsing response");
  95. if(emv_decode_ppse_response(rx_buff, *rx_len, &emv_app)) {
  96. FURI_LOG_I(NFC_WORKER_TAG, "Select PPSE responce parced");
  97. } else {
  98. FURI_LOG_E(NFC_WORKER_TAG, "Can't find pay application");
  99. message.type = NfcMessageTypeEMVNotFound;
  100. api_hal_nfc_deactivate();
  101. continue;
  102. }
  103. FURI_LOG_I(NFC_WORKER_TAG, "Starting application ...");
  104. tx_len = emv_prepare_select_app(tx_buff, &emv_app);
  105. err = api_hal_nfc_data_exchange(
  106. dev_active, tx_buff, tx_len, &rx_buff, &rx_len, false);
  107. if(err != ERR_NONE) {
  108. FURI_LOG_E(
  109. NFC_WORKER_TAG, "Error during application selection request: %d", err);
  110. message.type = NfcMessageTypeEMVNotFound;
  111. api_hal_nfc_deactivate();
  112. continue;
  113. }
  114. FURI_LOG_I(
  115. NFC_WORKER_TAG,
  116. "Select application response received. Start parsing response");
  117. if(emv_decode_select_app_response(rx_buff, *rx_len, &emv_app)) {
  118. FURI_LOG_I(NFC_WORKER_TAG, "Card name: %s", emv_app.name);
  119. memcpy(message.device.emv_card.name, emv_app.name, sizeof(emv_app.name));
  120. } else {
  121. FURI_LOG_E(NFC_WORKER_TAG, "Can't read card name");
  122. message.type = NfcMessageTypeEMVNotFound;
  123. api_hal_nfc_deactivate();
  124. continue;
  125. }
  126. FURI_LOG_I(NFC_WORKER_TAG, "Starting Get Processing Options command ...");
  127. tx_len = emv_prepare_get_proc_opt(tx_buff, &emv_app);
  128. err = api_hal_nfc_data_exchange(
  129. dev_active, tx_buff, tx_len, &rx_buff, &rx_len, false);
  130. if(err != ERR_NONE) {
  131. FURI_LOG_E(
  132. NFC_WORKER_TAG, "Error during Get Processing Options command: %d", err);
  133. message.type = NfcMessageTypeEMVNotFound;
  134. api_hal_nfc_deactivate();
  135. continue;
  136. }
  137. if(emv_decode_get_proc_opt(rx_buff, *rx_len, &emv_app)) {
  138. FURI_LOG_I(NFC_WORKER_TAG, "Card number parsed");
  139. message.type = NfcMessageTypeEMVFound;
  140. memcpy(
  141. message.device.emv_card.number,
  142. emv_app.card_number,
  143. sizeof(emv_app.card_number));
  144. api_hal_nfc_deactivate();
  145. continue;
  146. } else {
  147. // Mastercard doesn't give PAN / card number as GPO response
  148. // Iterate over all files found in application
  149. bool pan_found = false;
  150. for(uint8_t i = 0; (i < emv_app.afl.size) && !pan_found; i += 4) {
  151. uint8_t sfi = emv_app.afl.data[i] >> 3;
  152. uint8_t record_start = emv_app.afl.data[i + 1];
  153. uint8_t record_end = emv_app.afl.data[i + 2];
  154. // Iterate over all records in file
  155. for(uint8_t record = record_start; record <= record_end; ++record) {
  156. tx_len = emv_prepare_read_sfi_record(tx_buff, sfi, record);
  157. err = api_hal_nfc_data_exchange(
  158. dev_active, tx_buff, tx_len, &rx_buff, &rx_len, false);
  159. if(err != ERR_NONE) {
  160. FURI_LOG_E(
  161. NFC_WORKER_TAG,
  162. "Error reading application sfi %d, record %d",
  163. sfi,
  164. record);
  165. }
  166. if(emv_decode_read_sfi_record(rx_buff, *rx_len, &emv_app)) {
  167. pan_found = true;
  168. break;
  169. }
  170. }
  171. }
  172. if(pan_found) {
  173. FURI_LOG_I(NFC_WORKER_TAG, "Card PAN found");
  174. message.type = NfcMessageTypeEMVFound;
  175. memcpy(
  176. message.device.emv_card.number,
  177. emv_app.card_number,
  178. sizeof(emv_app.card_number));
  179. } else {
  180. FURI_LOG_E(NFC_WORKER_TAG, "Can't read card number");
  181. message.type = NfcMessageTypeEMVNotFound;
  182. }
  183. api_hal_nfc_deactivate();
  184. }
  185. } else {
  186. // Can't find EMV card
  187. FURI_LOG_W(NFC_WORKER_TAG, "Card doesn't support EMV");
  188. message.type = NfcMessageTypeEMVNotFound;
  189. api_hal_nfc_deactivate();
  190. }
  191. } else {
  192. // Can't find EMV card
  193. FURI_LOG_W(NFC_WORKER_TAG, "Can't find any cards");
  194. message.type = NfcMessageTypeEMVNotFound;
  195. api_hal_nfc_deactivate();
  196. }
  197. osDelay(20);
  198. }
  199. api_hal_nfc_deactivate();
  200. }
  201. void nfc_worker_poll(NfcWorker* nfc_worker) {
  202. rfalNfcDevice* dev_list;
  203. uint8_t dev_cnt;
  204. // Update screen before start searching
  205. NfcMessage message = {.type = NfcMessageTypeDeviceNotFound};
  206. furi_check(osMessageQueuePut(nfc_worker->message_queue, &message, 0, osWaitForever) == osOK);
  207. while(nfc_worker->state == NfcWorkerStatePoll) {
  208. if(api_hal_nfc_detect(&dev_list, &dev_cnt, 100, true)) {
  209. // Send message with first device found
  210. message.type = NfcMessageTypeDeviceFound;
  211. if(dev_list[0].type == RFAL_NFC_LISTEN_TYPE_NFCA) {
  212. message.device.type = NfcDeviceTypeNfca;
  213. message.device.nfca = dev_list[0].dev.nfca;
  214. } else if(dev_list[0].type == RFAL_NFC_LISTEN_TYPE_NFCB) {
  215. message.device.type = NfcDeviceTypeNfcb;
  216. message.device.nfcb = dev_list[0].dev.nfcb;
  217. } else if(dev_list[0].type == RFAL_NFC_LISTEN_TYPE_NFCF) {
  218. message.device.type = NfcDeviceTypeNfcf;
  219. message.device.nfcf = dev_list[0].dev.nfcf;
  220. } else if(dev_list[0].type == RFAL_NFC_LISTEN_TYPE_NFCV) {
  221. message.device.type = NfcDeviceTypeNfcv;
  222. message.device.nfcv = dev_list[0].dev.nfcv;
  223. } else {
  224. // TODO show information about all found devices
  225. message.type = NfcMessageTypeDeviceNotFound;
  226. }
  227. furi_check(
  228. osMessageQueuePut(nfc_worker->message_queue, &message, 0, osWaitForever) == osOK);
  229. } else {
  230. message.type = NfcMessageTypeDeviceNotFound;
  231. furi_check(
  232. osMessageQueuePut(nfc_worker->message_queue, &message, 0, osWaitForever) == osOK);
  233. }
  234. osDelay(20);
  235. }
  236. }
  237. void nfc_worker_state_callback(rfalNfcState st) {
  238. (void)st;
  239. }
  240. ReturnCode nfc_worker_trx(
  241. uint8_t* txBuf,
  242. uint16_t txBufSize,
  243. uint8_t** rxData,
  244. uint16_t** rcvLen,
  245. uint32_t fwt) {
  246. ReturnCode err;
  247. err = rfalNfcDataExchangeStart(txBuf, txBufSize, rxData, rcvLen, fwt);
  248. if(err == ERR_NONE) {
  249. do {
  250. rfalNfcWorker();
  251. err = rfalNfcDataExchangeGetStatus();
  252. } while(err == ERR_BUSY);
  253. }
  254. return err;
  255. }
  256. void nfc_worker_exchange(NfcWorker* nfc_worker, rfalNfcDevice* nfc_device) {
  257. ReturnCode err = ERR_NONE;
  258. uint8_t* rxData;
  259. uint16_t* rcvLen;
  260. uint8_t txBuf[100];
  261. uint16_t txLen;
  262. do {
  263. rfalNfcWorker();
  264. switch(rfalNfcGetState()) {
  265. case RFAL_NFC_STATE_ACTIVATED:
  266. err = nfc_worker_trx(NULL, 0, &rxData, &rcvLen, 0);
  267. break;
  268. case RFAL_NFC_STATE_DATAEXCHANGE:
  269. case RFAL_NFC_STATE_DATAEXCHANGE_DONE:
  270. // Not supported
  271. txBuf[0] = ((char)0x68);
  272. txBuf[1] = ((char)0x00);
  273. txLen = 2;
  274. err = nfc_worker_trx(txBuf, txLen, &rxData, &rcvLen, RFAL_FWT_NONE);
  275. break;
  276. case RFAL_NFC_STATE_START_DISCOVERY:
  277. return;
  278. case RFAL_NFC_STATE_LISTEN_SLEEP:
  279. default:
  280. break;
  281. }
  282. } while((err == ERR_NONE) || (err == ERR_SLEEP_REQ));
  283. }
  284. void nfc_worker_emulate(NfcWorker* nfc_worker) {
  285. rfalNfcDiscoverParam params;
  286. params.compMode = RFAL_COMPLIANCE_MODE_NFC;
  287. params.techs2Find = RFAL_NFC_LISTEN_TECH_A;
  288. params.totalDuration = 1000U;
  289. params.devLimit = 1;
  290. params.wakeupEnabled = false;
  291. params.wakeupConfigDefault = true;
  292. params.nfcfBR = RFAL_BR_212;
  293. params.ap2pBR = RFAL_BR_424;
  294. params.maxBR = RFAL_BR_KEEP;
  295. params.GBLen = RFAL_NFCDEP_GB_MAX_LEN;
  296. params.notifyCb = nfc_worker_state_callback;
  297. params.lmConfigPA.nfcidLen = RFAL_LM_NFCID_LEN_07;
  298. params.lmConfigPA.nfcid[0] = 0x00;
  299. params.lmConfigPA.nfcid[1] = 0x01;
  300. params.lmConfigPA.nfcid[2] = 0x02;
  301. params.lmConfigPA.nfcid[3] = 0x03;
  302. params.lmConfigPA.nfcid[4] = 0x04;
  303. params.lmConfigPA.nfcid[5] = 0x05;
  304. params.lmConfigPA.nfcid[6] = 0x06;
  305. params.lmConfigPA.SENS_RES[0] = 0x44;
  306. params.lmConfigPA.SENS_RES[1] = 0x00;
  307. params.lmConfigPA.SEL_RES = 0x00;
  308. api_hal_nfc_exit_sleep();
  309. ReturnCode ret;
  310. ret = rfalNfcDiscover(&params);
  311. if(ret != ERR_NONE) {
  312. asm("bkpt 1");
  313. return;
  314. }
  315. rfalNfcDevice* nfc_device;
  316. while(nfc_worker->state == NfcWorkerStateEmulate) {
  317. rfalNfcWorker();
  318. if(rfalNfcIsDevActivated(rfalNfcGetState())) {
  319. rfalNfcGetActiveDevice(&nfc_device);
  320. nfc_worker_exchange(nfc_worker, nfc_device);
  321. }
  322. osDelay(10);
  323. }
  324. rfalNfcDeactivate(false);
  325. api_hal_nfc_start_sleep();
  326. }
  327. void nfc_worker_field(NfcWorker* nfc_worker) {
  328. api_hal_nfc_field_on();
  329. while(nfc_worker->state == NfcWorkerStateField) {
  330. osDelay(50);
  331. }
  332. api_hal_nfc_field_off();
  333. }