mifare_ultralight.c 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330
  1. #include "mifare_ultralight.h"
  2. bool mf_ul_check_card_type(uint8_t ATQA0, uint8_t ATQA1, uint8_t SAK) {
  3. if((ATQA0 == 0x44) && (ATQA1 == 0x00) && (SAK == 0x00)) {
  4. return true;
  5. }
  6. return false;
  7. }
  8. uint16_t mf_ul_prepare_get_version(uint8_t* dest) {
  9. dest[0] = MF_UL_GET_VERSION_CMD;
  10. return 1;
  11. }
  12. void mf_ul_parse_get_version_response(uint8_t* buff, MifareUlDevice* mf_ul_read) {
  13. MfUltralightVersion* version = (MfUltralightVersion*) buff;
  14. memcpy(&mf_ul_read->data.version, version, sizeof(MfUltralightVersion));
  15. if(version->storage_size == 0x0B || version->storage_size == 0x00) {
  16. mf_ul_read->data.type = MfUltralightTypeUL11;
  17. mf_ul_read->pages_to_read = 20;
  18. mf_ul_read->support_fast_read = true;
  19. } else if(version->storage_size == 0x0E) {
  20. mf_ul_read->data.type = MfUltralightTypeUL21;
  21. mf_ul_read->pages_to_read = 41;
  22. mf_ul_read->support_fast_read = true;
  23. } else if(version->storage_size == 0x0F) {
  24. mf_ul_read->data.type = MfUltralightTypeNTAG213;
  25. mf_ul_read->pages_to_read = 45;
  26. mf_ul_read->support_fast_read = false;
  27. } else if(version->storage_size == 0x11) {
  28. mf_ul_read->data.type = MfUltralightTypeNTAG215;
  29. mf_ul_read->pages_to_read = 135;
  30. mf_ul_read->support_fast_read = false;
  31. } else if(version->storage_size == 0x13) {
  32. mf_ul_read->data.type = MfUltralightTypeNTAG216;
  33. mf_ul_read->pages_to_read = 231;
  34. mf_ul_read->support_fast_read = false;
  35. } else {
  36. mf_ul_set_default_version(mf_ul_read);
  37. }
  38. }
  39. void mf_ul_set_default_version(MifareUlDevice* mf_ul_read) {
  40. mf_ul_read->data.type = MfUltralightTypeUnknown;
  41. mf_ul_read->pages_to_read = 16;
  42. mf_ul_read->support_fast_read = false;
  43. }
  44. uint16_t mf_ul_prepare_read(uint8_t* dest, uint8_t start_page) {
  45. dest[0] = MF_UL_READ_CMD;
  46. dest[1] = start_page;
  47. return 2;
  48. }
  49. void mf_ul_parse_read_response(uint8_t* buff, uint16_t page_addr, MifareUlDevice* mf_ul_read) {
  50. uint8_t pages_read = 4;
  51. uint8_t page_read_count = mf_ul_read->pages_readed + pages_read;
  52. if(page_read_count > mf_ul_read->pages_to_read) {
  53. pages_read -= page_read_count - mf_ul_read->pages_to_read;
  54. }
  55. mf_ul_read->pages_readed += pages_read;
  56. mf_ul_read->data.data_size = mf_ul_read->pages_readed * 4;
  57. memcpy(&mf_ul_read->data.data[page_addr * 4], buff, pages_read * 4);
  58. }
  59. uint16_t mf_ul_prepare_fast_read(uint8_t* dest, uint8_t start_page, uint8_t end_page) {
  60. dest[0] = MF_UL_FAST_READ_CMD;
  61. dest[1] = start_page;
  62. dest[2] = end_page;
  63. return 3;
  64. }
  65. void mf_ul_parse_fast_read_response(uint8_t* buff, uint8_t start_page, uint8_t end_page, MifareUlDevice* mf_ul_read) {
  66. mf_ul_read->pages_readed = end_page - start_page + 1;
  67. mf_ul_read->data.data_size = mf_ul_read->pages_readed * 4;
  68. memcpy(mf_ul_read->data.data, buff, mf_ul_read->data.data_size);
  69. }
  70. uint16_t mf_ul_prepare_read_signature(uint8_t* dest) {
  71. dest[0] = MF_UL_READ_SIG;
  72. dest[1] = 0;
  73. return 2;
  74. }
  75. void mf_ul_parse_read_signature_response(uint8_t* buff, MifareUlDevice* mf_ul_read) {
  76. memcpy(mf_ul_read->data.signature, buff, sizeof(mf_ul_read->data.signature));
  77. }
  78. uint16_t mf_ul_prepare_read_cnt(uint8_t* dest, uint8_t cnt_index) {
  79. if(cnt_index > 2) {
  80. return 0;
  81. }
  82. dest[0] = MF_UL_READ_CNT;
  83. dest[1] = cnt_index;
  84. return 2;
  85. }
  86. void mf_ul_parse_read_cnt_response(uint8_t* buff, uint8_t cnt_index, MifareUlDevice* mf_ul_read) {
  87. // Reverse LSB sequence
  88. if(cnt_index < 3) {
  89. mf_ul_read->data.counter[cnt_index] = (buff[2] << 16) | (buff[1] << 8) | (buff[0]);
  90. }
  91. }
  92. uint16_t mf_ul_prepare_inc_cnt(uint8_t* dest, uint8_t cnt_index, uint32_t value) {
  93. if(cnt_index > 2) {
  94. return 0;
  95. }
  96. dest[0] = MF_UL_INC_CNT;
  97. dest[1] = cnt_index;
  98. dest[2] = (uint8_t) value;
  99. dest[3] = (uint8_t) (value >> 8);
  100. dest[4] = (uint8_t) (value >> 16);
  101. dest[5] = 0;
  102. return 6;
  103. }
  104. uint16_t mf_ul_prepare_check_tearing(uint8_t* dest, uint8_t cnt_index) {
  105. if(cnt_index > 2) {
  106. return 0;
  107. }
  108. dest[0] = MF_UL_CHECK_TEARING;
  109. dest[1] = cnt_index;
  110. return 2;
  111. }
  112. void mf_ul_parse_check_tearing_response(uint8_t* buff, uint8_t cnt_index, MifareUlDevice* mf_ul_read) {
  113. if(cnt_index < 2) {
  114. mf_ul_read->data.tearing[cnt_index] = buff[0];
  115. }
  116. }
  117. uint16_t mf_ul_prepare_write(uint8_t* dest, uint16_t page_addr, uint32_t data) {
  118. if(page_addr < 2) {
  119. return 0;
  120. }
  121. dest[0] = MF_UL_WRITE;
  122. dest[1] = page_addr;
  123. dest[2] = (uint8_t) (data >> 24);
  124. dest[3] = (uint8_t) (data >> 16);
  125. dest[4] = (uint8_t) (data >> 8);
  126. dest[5] = (uint8_t) data;
  127. return 6;
  128. }
  129. void mf_ul_prepare_emulation(MifareUlDevice* mf_ul_emulate, MifareUlData* data) {
  130. mf_ul_emulate->data = *data;
  131. mf_ul_emulate->auth_data = NULL;
  132. mf_ul_emulate->data_changed = false;
  133. if(data->version.storage_size == 0) {
  134. mf_ul_emulate->data.type = MfUltralightTypeUnknown;
  135. mf_ul_emulate->support_fast_read = false;
  136. } else if(data->version.storage_size == 0x0B) {
  137. mf_ul_emulate->data.type = MfUltralightTypeUL11;
  138. mf_ul_emulate->support_fast_read = true;
  139. } else if(data->version.storage_size == 0x0E) {
  140. mf_ul_emulate->data.type = MfUltralightTypeUL21;
  141. mf_ul_emulate->support_fast_read = true;
  142. } else if(data->version.storage_size == 0x0F) {
  143. mf_ul_emulate->data.type = MfUltralightTypeNTAG213;
  144. mf_ul_emulate->support_fast_read = true;
  145. } else if(data->version.storage_size == 0x11) {
  146. mf_ul_emulate->data.type = MfUltralightTypeNTAG215;
  147. mf_ul_emulate->support_fast_read = true;
  148. } else if(data->version.storage_size == 0x13) {
  149. mf_ul_emulate->data.type = MfUltralightTypeNTAG216;
  150. mf_ul_emulate->support_fast_read = true;
  151. }
  152. if(mf_ul_emulate->data.type >= MfUltralightTypeNTAG213) {
  153. uint16_t pwd_page = (data->data_size / 4) - 2;
  154. mf_ul_emulate->auth_data = (MifareUlAuthData*)&data->data[pwd_page * 4];
  155. }
  156. }
  157. void mf_ul_protect_auth_data_on_read_command(
  158. uint8_t* tx_buff,
  159. uint8_t start_page,
  160. uint8_t end_page,
  161. MifareUlDevice* mf_ul_emulate) {
  162. if(mf_ul_emulate->data.type >= MfUltralightTypeNTAG213) {
  163. uint8_t pwd_page = (mf_ul_emulate->data.data_size / 4) - 2;
  164. uint8_t pack_page = pwd_page + 1;
  165. if((start_page <= pwd_page) && (end_page >= pwd_page)) {
  166. memset(&tx_buff[(pwd_page - start_page) * 4], 0, 4);
  167. }
  168. if((start_page <= pack_page) && (end_page >= pack_page)) {
  169. memset(&tx_buff[(pack_page - start_page) * 4], 0, 2);
  170. }
  171. }
  172. }
  173. uint16_t mf_ul_prepare_emulation_response(uint8_t* buff_rx, uint16_t len_rx, uint8_t* buff_tx, MifareUlDevice* mf_ul_emulate) {
  174. uint8_t cmd = buff_rx[0];
  175. uint16_t page_num = mf_ul_emulate->data.data_size / 4;
  176. uint16_t tx_bytes = 0;
  177. uint16_t tx_bits = 0;
  178. bool command_parsed = false;
  179. // Check composite commands
  180. if(mf_ul_emulate->comp_write_cmd_started) {
  181. // Compatibility write is the only one composit command
  182. if(len_rx == 16) {
  183. memcpy(&mf_ul_emulate->data.data[mf_ul_emulate->comp_write_page_addr * 4], buff_rx, 4);
  184. mf_ul_emulate->data_changed = true;
  185. // Send ACK message
  186. buff_tx[0] = 0x0A;
  187. tx_bits = 4;
  188. command_parsed = true;
  189. }
  190. mf_ul_emulate->comp_write_cmd_started = false;
  191. } else if(cmd == MF_UL_GET_VERSION_CMD) {
  192. if(mf_ul_emulate->data.type != MfUltralightTypeUnknown) {
  193. tx_bytes = sizeof(mf_ul_emulate->data.version);
  194. memcpy(buff_tx, &mf_ul_emulate->data.version, tx_bytes);
  195. command_parsed = true;
  196. }
  197. } else if(cmd == MF_UL_READ_CMD) {
  198. uint8_t start_page = buff_rx[1];
  199. if(start_page < page_num) {
  200. tx_bytes = 16;
  201. if(start_page + 4 > page_num) {
  202. // Handle roll-over mechanism
  203. uint8_t end_pages_num = page_num - start_page;
  204. memcpy(buff_tx, &mf_ul_emulate->data.data[start_page * 4], end_pages_num * 4);
  205. memcpy(&buff_tx[end_pages_num * 4], mf_ul_emulate->data.data, (4 - end_pages_num) * 4);
  206. } else {
  207. memcpy(buff_tx, &mf_ul_emulate->data.data[start_page * 4], tx_bytes);
  208. }
  209. mf_ul_protect_auth_data_on_read_command(
  210. buff_tx, start_page, (start_page + 4), mf_ul_emulate);
  211. command_parsed = true;
  212. }
  213. } else if(cmd == MF_UL_FAST_READ_CMD) {
  214. if(mf_ul_emulate->support_fast_read) {
  215. uint8_t start_page = buff_rx[1];
  216. uint8_t end_page = buff_rx[2];
  217. if((start_page < page_num) &&
  218. (end_page < page_num) && (start_page < (end_page + 1))) {
  219. tx_bytes = ((end_page + 1) - start_page) * 4;
  220. memcpy(buff_tx, &mf_ul_emulate->data.data[start_page * 4], tx_bytes);
  221. mf_ul_protect_auth_data_on_read_command(
  222. buff_tx, start_page, end_page, mf_ul_emulate);
  223. command_parsed = true;
  224. }
  225. }
  226. } else if(cmd == MF_UL_WRITE) {
  227. uint8_t write_page = buff_rx[1];
  228. if((write_page > 1) && (write_page < page_num - 2)) {
  229. memcpy(&mf_ul_emulate->data.data[write_page * 4], &buff_rx[2], 4);
  230. mf_ul_emulate->data_changed = true;
  231. // ACK
  232. buff_tx[0] = 0x0A;
  233. tx_bits = 4;
  234. command_parsed = true;
  235. }
  236. } else if(cmd == MF_UL_COMP_WRITE) {
  237. uint8_t write_page = buff_rx[1];
  238. if((write_page > 1) && (write_page < page_num - 2)) {
  239. mf_ul_emulate->comp_write_cmd_started = true;
  240. mf_ul_emulate->comp_write_page_addr = write_page;
  241. // ACK
  242. buff_tx[0] = 0x0A;
  243. tx_bits = 4;
  244. command_parsed = true;
  245. }
  246. } else if(cmd == MF_UL_READ_CNT) {
  247. uint8_t cnt_num = buff_rx[1];
  248. if(cnt_num < 3) {
  249. buff_tx[0] = mf_ul_emulate->data.counter[cnt_num] >> 16;
  250. buff_tx[1] = mf_ul_emulate->data.counter[cnt_num] >> 8;
  251. buff_tx[2] = mf_ul_emulate->data.counter[cnt_num];
  252. tx_bytes = 3;
  253. command_parsed = true;
  254. }
  255. } else if(cmd == MF_UL_INC_CNT) {
  256. uint8_t cnt_num = buff_rx[1];
  257. uint32_t inc = (buff_rx[2] | (buff_rx[3] << 8) | (buff_rx[4] << 16));
  258. if((cnt_num < 3) && (mf_ul_emulate->data.counter[cnt_num] + inc < 0x00FFFFFF)) {
  259. mf_ul_emulate->data.counter[cnt_num] += inc;
  260. mf_ul_emulate->data_changed = true;
  261. // ACK
  262. buff_tx[0] = 0x0A;
  263. tx_bits = 4;
  264. command_parsed = true;
  265. }
  266. } else if(cmd == MF_UL_AUTH) {
  267. if(mf_ul_emulate->data.type >= MfUltralightTypeNTAG213) {
  268. if(memcmp(&buff_rx[1], mf_ul_emulate->auth_data->pwd, 4) == 0) {
  269. buff_tx[0] = mf_ul_emulate->auth_data->pack.raw[0];
  270. buff_tx[1] = mf_ul_emulate->auth_data->pack.raw[1];
  271. tx_bytes = 2;
  272. command_parsed = true;
  273. } else if(!mf_ul_emulate->auth_data->pack.value) {
  274. buff_tx[0] = 0x80;
  275. buff_tx[1] = 0x80;
  276. tx_bytes = 2;
  277. command_parsed = true;
  278. }
  279. }
  280. } else if(cmd == MF_UL_READ_SIG) {
  281. // Check 2nd byte = 0x00 - RFU
  282. if(buff_rx[1] == 0x00) {
  283. tx_bytes = sizeof(mf_ul_emulate->data.signature);
  284. memcpy(buff_tx, mf_ul_emulate->data.signature, tx_bytes);
  285. command_parsed = true;
  286. }
  287. } else if(cmd == MF_UL_CHECK_TEARING) {
  288. uint8_t cnt_num = buff_rx[1];
  289. if(cnt_num < 3) {
  290. buff_tx[0] = mf_ul_emulate->data.tearing[cnt_num];
  291. tx_bytes = 1;
  292. command_parsed = true;
  293. }
  294. } else if(cmd == MF_UL_HALT_START) {
  295. tx_bits = 0;
  296. command_parsed = true;
  297. }
  298. if(!command_parsed) {
  299. // Send NACK
  300. buff_tx[0] = 0x00;
  301. tx_bits = 4;
  302. }
  303. // Return tx buffer size in bits
  304. if(tx_bytes) {
  305. tx_bits = tx_bytes * 8;
  306. }
  307. return tx_bits;
  308. }