nfc_worker.c 29 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708
  1. #include "nfc_worker_i.h"
  2. #include <furi_hal.h>
  3. #include <platform.h>
  4. #define TAG "NfcWorker"
  5. /***************************** NFC Worker API *******************************/
  6. NfcWorker* nfc_worker_alloc() {
  7. NfcWorker* nfc_worker = malloc(sizeof(NfcWorker));
  8. // Worker thread attributes
  9. nfc_worker->thread = furi_thread_alloc();
  10. furi_thread_set_name(nfc_worker->thread, "NfcWorker");
  11. furi_thread_set_stack_size(nfc_worker->thread, 8192);
  12. furi_thread_set_callback(nfc_worker->thread, nfc_worker_task);
  13. furi_thread_set_context(nfc_worker->thread, nfc_worker);
  14. nfc_worker->callback = NULL;
  15. nfc_worker->context = NULL;
  16. nfc_worker->storage = furi_record_open("storage");
  17. // Initialize rfal
  18. while(furi_hal_nfc_is_busy()) {
  19. osDelay(10);
  20. }
  21. nfc_worker_change_state(nfc_worker, NfcWorkerStateReady);
  22. if(furi_hal_rtc_is_flag_set(FuriHalRtcFlagDebug)) {
  23. nfc_worker->debug_pcap_worker = nfc_debug_pcap_alloc(nfc_worker->storage);
  24. }
  25. return nfc_worker;
  26. }
  27. void nfc_worker_free(NfcWorker* nfc_worker) {
  28. furi_assert(nfc_worker);
  29. furi_thread_free(nfc_worker->thread);
  30. furi_record_close("storage");
  31. if(nfc_worker->debug_pcap_worker) nfc_debug_pcap_free(nfc_worker->debug_pcap_worker);
  32. free(nfc_worker);
  33. }
  34. NfcWorkerState nfc_worker_get_state(NfcWorker* nfc_worker) {
  35. return nfc_worker->state;
  36. }
  37. void nfc_worker_start(
  38. NfcWorker* nfc_worker,
  39. NfcWorkerState state,
  40. NfcDeviceData* dev_data,
  41. NfcWorkerCallback callback,
  42. void* context) {
  43. furi_assert(nfc_worker);
  44. furi_assert(dev_data);
  45. while(furi_hal_nfc_is_busy()) {
  46. osDelay(10);
  47. }
  48. nfc_worker->callback = callback;
  49. nfc_worker->context = context;
  50. nfc_worker->dev_data = dev_data;
  51. nfc_worker_change_state(nfc_worker, state);
  52. furi_thread_start(nfc_worker->thread);
  53. }
  54. void nfc_worker_stop(NfcWorker* nfc_worker) {
  55. furi_assert(nfc_worker);
  56. if(nfc_worker->state == NfcWorkerStateBroken || nfc_worker->state == NfcWorkerStateReady) {
  57. return;
  58. }
  59. furi_hal_nfc_stop();
  60. nfc_worker_change_state(nfc_worker, NfcWorkerStateStop);
  61. furi_thread_join(nfc_worker->thread);
  62. }
  63. void nfc_worker_change_state(NfcWorker* nfc_worker, NfcWorkerState state) {
  64. nfc_worker->state = state;
  65. }
  66. /***************************** NFC Worker Thread *******************************/
  67. int32_t nfc_worker_task(void* context) {
  68. NfcWorker* nfc_worker = context;
  69. furi_hal_nfc_exit_sleep();
  70. if(nfc_worker->state == NfcWorkerStateDetect) {
  71. nfc_worker_detect(nfc_worker);
  72. } else if(nfc_worker->state == NfcWorkerStateEmulate) {
  73. nfc_worker_emulate(nfc_worker);
  74. } else if(nfc_worker->state == NfcWorkerStateReadEMVApp) {
  75. nfc_worker_read_emv_app(nfc_worker);
  76. } else if(nfc_worker->state == NfcWorkerStateReadEMVData) {
  77. nfc_worker_read_emv(nfc_worker);
  78. } else if(nfc_worker->state == NfcWorkerStateEmulateApdu) {
  79. nfc_worker_emulate_apdu(nfc_worker);
  80. } else if(nfc_worker->state == NfcWorkerStateReadMifareUltralight) {
  81. nfc_worker_read_mifare_ultralight(nfc_worker);
  82. } else if(nfc_worker->state == NfcWorkerStateEmulateMifareUltralight) {
  83. nfc_worker_emulate_mifare_ul(nfc_worker);
  84. } else if(nfc_worker->state == NfcWorkerStateReadMifareClassic) {
  85. nfc_worker_mifare_classic_dict_attack(nfc_worker);
  86. } else if(nfc_worker->state == NfcWorkerStateEmulateMifareClassic) {
  87. nfc_worker_emulate_mifare_classic(nfc_worker);
  88. } else if(nfc_worker->state == NfcWorkerStateReadMifareDesfire) {
  89. nfc_worker_read_mifare_desfire(nfc_worker);
  90. }
  91. furi_hal_nfc_sleep();
  92. nfc_worker_change_state(nfc_worker, NfcWorkerStateReady);
  93. return 0;
  94. }
  95. void nfc_worker_detect(NfcWorker* nfc_worker) {
  96. nfc_device_data_clear(nfc_worker->dev_data);
  97. NfcDeviceData* dev_data = nfc_worker->dev_data;
  98. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  99. while(nfc_worker->state == NfcWorkerStateDetect) {
  100. if(furi_hal_nfc_detect(nfc_data, 1000)) {
  101. // Process first found device
  102. if(nfc_data->type == FuriHalNfcTypeA) {
  103. if(mf_ul_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  104. dev_data->protocol = NfcDeviceProtocolMifareUl;
  105. } else if(mf_classic_check_card_type(
  106. nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  107. dev_data->protocol = NfcDeviceProtocolMifareClassic;
  108. } else if(mf_df_check_card_type(
  109. nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  110. dev_data->protocol = NfcDeviceProtocolMifareDesfire;
  111. } else if(nfc_data->interface == FuriHalNfcInterfaceIsoDep) {
  112. dev_data->protocol = NfcDeviceProtocolEMV;
  113. } else {
  114. dev_data->protocol = NfcDeviceProtocolUnknown;
  115. }
  116. }
  117. // Notify caller and exit
  118. if(nfc_worker->callback) {
  119. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  120. }
  121. break;
  122. }
  123. furi_hal_nfc_sleep();
  124. osDelay(100);
  125. }
  126. }
  127. void nfc_worker_emulate(NfcWorker* nfc_worker) {
  128. FuriHalNfcTxRxContext tx_rx = {};
  129. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx, true);
  130. FuriHalNfcDevData* data = &nfc_worker->dev_data->nfc_data;
  131. NfcReaderRequestData* reader_data = &nfc_worker->dev_data->reader_data;
  132. while(nfc_worker->state == NfcWorkerStateEmulate) {
  133. if(furi_hal_nfc_listen(data->uid, data->uid_len, data->atqa, data->sak, true, 100)) {
  134. if(furi_hal_nfc_tx_rx(&tx_rx, 100)) {
  135. reader_data->size = tx_rx.rx_bits / 8;
  136. if(reader_data->size > 0) {
  137. memcpy(reader_data->data, tx_rx.rx_data, reader_data->size);
  138. if(nfc_worker->callback) {
  139. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  140. }
  141. }
  142. } else {
  143. FURI_LOG_E(TAG, "Failed to get reader commands");
  144. }
  145. }
  146. }
  147. }
  148. void nfc_worker_read_emv_app(NfcWorker* nfc_worker) {
  149. FuriHalNfcTxRxContext tx_rx = {};
  150. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx, false);
  151. EmvApplication emv_app = {};
  152. NfcDeviceData* result = nfc_worker->dev_data;
  153. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  154. nfc_device_data_clear(result);
  155. while(nfc_worker->state == NfcWorkerStateReadEMVApp) {
  156. if(furi_hal_nfc_detect(nfc_data, 1000)) {
  157. // Card was found. Check that it supports EMV
  158. if(nfc_data->interface == FuriHalNfcInterfaceIsoDep) {
  159. result->protocol = NfcDeviceProtocolEMV;
  160. if(emv_search_application(&tx_rx, &emv_app)) {
  161. // Notify caller and exit
  162. result->emv_data.aid_len = emv_app.aid_len;
  163. memcpy(result->emv_data.aid, emv_app.aid, emv_app.aid_len);
  164. if(nfc_worker->callback) {
  165. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  166. }
  167. }
  168. } else {
  169. FURI_LOG_W(TAG, "Card doesn't support EMV");
  170. }
  171. } else {
  172. FURI_LOG_D(TAG, "Can't find any cards");
  173. }
  174. furi_hal_nfc_sleep();
  175. osDelay(20);
  176. }
  177. }
  178. void nfc_worker_read_emv(NfcWorker* nfc_worker) {
  179. FuriHalNfcTxRxContext tx_rx = {};
  180. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx, false);
  181. EmvApplication emv_app = {};
  182. NfcDeviceData* result = nfc_worker->dev_data;
  183. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  184. nfc_device_data_clear(result);
  185. while(nfc_worker->state == NfcWorkerStateReadEMVData) {
  186. if(furi_hal_nfc_detect(nfc_data, 1000)) {
  187. // Card was found. Check that it supports EMV
  188. if(nfc_data->interface == FuriHalNfcInterfaceIsoDep) {
  189. result->protocol = NfcDeviceProtocolEMV;
  190. if(emv_read_bank_card(&tx_rx, &emv_app)) {
  191. result->emv_data.number_len = emv_app.card_number_len;
  192. memcpy(
  193. result->emv_data.number, emv_app.card_number, result->emv_data.number_len);
  194. result->emv_data.aid_len = emv_app.aid_len;
  195. memcpy(result->emv_data.aid, emv_app.aid, emv_app.aid_len);
  196. if(emv_app.name_found) {
  197. memcpy(result->emv_data.name, emv_app.name, sizeof(emv_app.name));
  198. }
  199. if(emv_app.exp_month) {
  200. result->emv_data.exp_mon = emv_app.exp_month;
  201. result->emv_data.exp_year = emv_app.exp_year;
  202. }
  203. if(emv_app.country_code) {
  204. result->emv_data.country_code = emv_app.country_code;
  205. }
  206. if(emv_app.currency_code) {
  207. result->emv_data.currency_code = emv_app.currency_code;
  208. }
  209. // Notify caller and exit
  210. if(nfc_worker->callback) {
  211. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  212. }
  213. break;
  214. }
  215. } else {
  216. FURI_LOG_W(TAG, "Card doesn't support EMV");
  217. }
  218. } else {
  219. FURI_LOG_D(TAG, "Can't find any cards");
  220. }
  221. furi_hal_nfc_sleep();
  222. osDelay(20);
  223. }
  224. }
  225. void nfc_worker_emulate_apdu(NfcWorker* nfc_worker) {
  226. FuriHalNfcTxRxContext tx_rx = {};
  227. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx, true);
  228. FuriHalNfcDevData params = {
  229. .uid = {0xCF, 0x72, 0xd4, 0x40},
  230. .uid_len = 4,
  231. .atqa = {0x00, 0x04},
  232. .sak = 0x20,
  233. .type = FuriHalNfcTypeA,
  234. };
  235. while(nfc_worker->state == NfcWorkerStateEmulateApdu) {
  236. if(furi_hal_nfc_listen(params.uid, params.uid_len, params.atqa, params.sak, false, 300)) {
  237. FURI_LOG_D(TAG, "POS terminal detected");
  238. if(emv_card_emulation(&tx_rx)) {
  239. FURI_LOG_D(TAG, "EMV card emulated");
  240. }
  241. } else {
  242. FURI_LOG_D(TAG, "Can't find reader");
  243. }
  244. furi_hal_nfc_sleep();
  245. osDelay(20);
  246. }
  247. }
  248. void nfc_worker_read_mifare_ultralight(NfcWorker* nfc_worker) {
  249. FuriHalNfcTxRxContext tx_rx = {};
  250. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx, false);
  251. MfUltralightReader reader = {};
  252. MfUltralightData data = {};
  253. NfcDeviceData* result = nfc_worker->dev_data;
  254. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  255. while(nfc_worker->state == NfcWorkerStateReadMifareUltralight) {
  256. if(furi_hal_nfc_detect(nfc_data, 300)) {
  257. if(nfc_data->type == FuriHalNfcTypeA &&
  258. mf_ul_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  259. FURI_LOG_D(TAG, "Found Mifare Ultralight tag. Start reading");
  260. if(mf_ul_read_card(&tx_rx, &reader, &data)) {
  261. result->protocol = NfcDeviceProtocolMifareUl;
  262. result->mf_ul_data = data;
  263. // Notify caller and exit
  264. if(nfc_worker->callback) {
  265. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  266. }
  267. break;
  268. } else {
  269. FURI_LOG_D(TAG, "Failed reading Mifare Ultralight");
  270. }
  271. } else {
  272. FURI_LOG_W(TAG, "Tag is not Mifare Ultralight");
  273. }
  274. } else {
  275. FURI_LOG_D(TAG, "Can't find any tags");
  276. }
  277. furi_hal_nfc_sleep();
  278. osDelay(100);
  279. }
  280. }
  281. void nfc_worker_emulate_mifare_ul(NfcWorker* nfc_worker) {
  282. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  283. MfUltralightEmulator emulator = {};
  284. mf_ul_prepare_emulation(&emulator, &nfc_worker->dev_data->mf_ul_data);
  285. while(nfc_worker->state == NfcWorkerStateEmulateMifareUltralight) {
  286. mf_ul_reset_emulation(&emulator, true);
  287. furi_hal_nfc_emulate_nfca(
  288. nfc_data->uid,
  289. nfc_data->uid_len,
  290. nfc_data->atqa,
  291. nfc_data->sak,
  292. mf_ul_prepare_emulation_response,
  293. &emulator,
  294. 5000);
  295. // Check if data was modified
  296. if(emulator.data_changed) {
  297. nfc_worker->dev_data->mf_ul_data = emulator.data;
  298. if(nfc_worker->callback) {
  299. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  300. }
  301. emulator.data_changed = false;
  302. }
  303. }
  304. }
  305. void nfc_worker_mifare_classic_dict_attack(NfcWorker* nfc_worker) {
  306. furi_assert(nfc_worker->callback);
  307. FuriHalNfcTxRxContext tx_rx_ctx = {};
  308. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx_ctx, false);
  309. MfClassicAuthContext auth_ctx = {};
  310. MfClassicReader reader = {};
  311. uint64_t curr_key = 0;
  312. uint16_t curr_sector = 0;
  313. uint8_t total_sectors = 0;
  314. NfcWorkerEvent event;
  315. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  316. // Open dictionary
  317. nfc_worker->dict_stream = file_stream_alloc(nfc_worker->storage);
  318. if(!nfc_mf_classic_dict_open_file(nfc_worker->dict_stream)) {
  319. event = NfcWorkerEventNoDictFound;
  320. nfc_worker->callback(event, nfc_worker->context);
  321. nfc_mf_classic_dict_close_file(nfc_worker->dict_stream);
  322. stream_free(nfc_worker->dict_stream);
  323. return;
  324. }
  325. // Detect Mifare Classic card
  326. while(nfc_worker->state == NfcWorkerStateReadMifareClassic) {
  327. if(furi_hal_nfc_detect(nfc_data, 300)) {
  328. if(mf_classic_get_type(
  329. nfc_data->uid,
  330. nfc_data->uid_len,
  331. nfc_data->atqa[0],
  332. nfc_data->atqa[1],
  333. nfc_data->sak,
  334. &reader)) {
  335. total_sectors = mf_classic_get_total_sectors_num(&reader);
  336. if(reader.type == MfClassicType1k) {
  337. event = NfcWorkerEventDetectedClassic1k;
  338. } else {
  339. event = NfcWorkerEventDetectedClassic4k;
  340. }
  341. nfc_worker->callback(event, nfc_worker->context);
  342. break;
  343. }
  344. } else {
  345. event = NfcWorkerEventNoCardDetected;
  346. nfc_worker->callback(event, nfc_worker->context);
  347. }
  348. }
  349. if(nfc_worker->state == NfcWorkerStateReadMifareClassic) {
  350. bool card_removed_notified = false;
  351. bool card_found_notified = false;
  352. // Seek for mifare classic keys
  353. for(curr_sector = 0; curr_sector < total_sectors; curr_sector++) {
  354. FURI_LOG_I(TAG, "Sector: %d ...", curr_sector);
  355. event = NfcWorkerEventNewSector;
  356. nfc_worker->callback(event, nfc_worker->context);
  357. mf_classic_auth_init_context(&auth_ctx, reader.cuid, curr_sector);
  358. bool sector_key_found = false;
  359. while(nfc_mf_classic_dict_get_next_key(nfc_worker->dict_stream, &curr_key)) {
  360. furi_hal_nfc_sleep();
  361. if(furi_hal_nfc_activate_nfca(300, &reader.cuid)) {
  362. if(!card_found_notified) {
  363. if(reader.type == MfClassicType1k) {
  364. event = NfcWorkerEventDetectedClassic1k;
  365. } else {
  366. event = NfcWorkerEventDetectedClassic4k;
  367. }
  368. nfc_worker->callback(event, nfc_worker->context);
  369. card_found_notified = true;
  370. card_removed_notified = false;
  371. }
  372. FURI_LOG_D(
  373. TAG,
  374. "Try to auth to sector %d with key %04lx%08lx",
  375. curr_sector,
  376. (uint32_t)(curr_key >> 32),
  377. (uint32_t)curr_key);
  378. if(mf_classic_auth_attempt(&tx_rx_ctx, &auth_ctx, curr_key)) {
  379. sector_key_found = true;
  380. if((auth_ctx.key_a != MF_CLASSIC_NO_KEY) &&
  381. (auth_ctx.key_b != MF_CLASSIC_NO_KEY))
  382. break;
  383. }
  384. } else {
  385. // Notify that no tag is availalble
  386. FURI_LOG_D(TAG, "Can't find tags");
  387. if(!card_removed_notified) {
  388. event = NfcWorkerEventNoCardDetected;
  389. nfc_worker->callback(event, nfc_worker->context);
  390. card_removed_notified = true;
  391. card_found_notified = false;
  392. }
  393. }
  394. if(nfc_worker->state != NfcWorkerStateReadMifareClassic) break;
  395. osDelay(1);
  396. }
  397. if(nfc_worker->state != NfcWorkerStateReadMifareClassic) break;
  398. if(sector_key_found) {
  399. // Notify that keys were found
  400. if(auth_ctx.key_a != MF_CLASSIC_NO_KEY) {
  401. FURI_LOG_I(
  402. TAG,
  403. "Sector %d key A: %04lx%08lx",
  404. curr_sector,
  405. (uint32_t)(auth_ctx.key_a >> 32),
  406. (uint32_t)auth_ctx.key_a);
  407. event = NfcWorkerEventFoundKeyA;
  408. nfc_worker->callback(event, nfc_worker->context);
  409. }
  410. if(auth_ctx.key_b != MF_CLASSIC_NO_KEY) {
  411. FURI_LOG_I(
  412. TAG,
  413. "Sector %d key B: %04lx%08lx",
  414. curr_sector,
  415. (uint32_t)(auth_ctx.key_b >> 32),
  416. (uint32_t)auth_ctx.key_b);
  417. event = NfcWorkerEventFoundKeyB;
  418. nfc_worker->callback(event, nfc_worker->context);
  419. }
  420. // Add sectors to read sequence
  421. mf_classic_reader_add_sector(&reader, curr_sector, auth_ctx.key_a, auth_ctx.key_b);
  422. }
  423. nfc_mf_classic_dict_reset(nfc_worker->dict_stream);
  424. }
  425. }
  426. if(nfc_worker->state == NfcWorkerStateReadMifareClassic) {
  427. FURI_LOG_I(TAG, "Found keys to %d sectors. Start reading sectors", reader.sectors_to_read);
  428. uint8_t sectors_read =
  429. mf_classic_read_card(&tx_rx_ctx, &reader, &nfc_worker->dev_data->mf_classic_data);
  430. if(sectors_read) {
  431. event = NfcWorkerEventSuccess;
  432. nfc_worker->dev_data->protocol = NfcDeviceProtocolMifareClassic;
  433. FURI_LOG_I(TAG, "Successfully read %d sectors", sectors_read);
  434. } else {
  435. event = NfcWorkerEventFail;
  436. FURI_LOG_W(TAG, "Failed to read any sector");
  437. }
  438. nfc_worker->callback(event, nfc_worker->context);
  439. }
  440. nfc_mf_classic_dict_close_file(nfc_worker->dict_stream);
  441. stream_free(nfc_worker->dict_stream);
  442. }
  443. void nfc_worker_emulate_mifare_classic(NfcWorker* nfc_worker) {
  444. FuriHalNfcTxRxContext tx_rx = {};
  445. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx, true);
  446. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  447. MfClassicEmulator emulator = {
  448. .cuid = nfc_util_bytes2num(&nfc_data->uid[nfc_data->uid_len - 4], 4),
  449. .data = nfc_worker->dev_data->mf_classic_data,
  450. .data_changed = false,
  451. };
  452. NfcaSignal* nfca_signal = nfca_signal_alloc();
  453. tx_rx.nfca_signal = nfca_signal;
  454. rfal_platform_spi_acquire();
  455. furi_hal_nfc_listen_start(nfc_data);
  456. while(nfc_worker->state == NfcWorkerStateEmulateMifareClassic) {
  457. if(furi_hal_nfc_listen_rx(&tx_rx, 300)) {
  458. mf_classic_emulator(&emulator, &tx_rx);
  459. }
  460. }
  461. if(emulator.data_changed) {
  462. nfc_worker->dev_data->mf_classic_data = emulator.data;
  463. if(nfc_worker->callback) {
  464. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  465. }
  466. emulator.data_changed = false;
  467. }
  468. nfca_signal_free(nfca_signal);
  469. rfal_platform_spi_release();
  470. }
  471. void nfc_worker_read_mifare_desfire(NfcWorker* nfc_worker) {
  472. FuriHalNfcTxRxContext tx_rx = {};
  473. nfc_debug_pcap_prepare_tx_rx(nfc_worker->debug_pcap_worker, &tx_rx, false);
  474. NfcDeviceData* result = nfc_worker->dev_data;
  475. nfc_device_data_clear(result);
  476. MifareDesfireData* data = &result->mf_df_data;
  477. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  478. while(nfc_worker->state == NfcWorkerStateReadMifareDesfire) {
  479. furi_hal_nfc_sleep();
  480. if(!furi_hal_nfc_detect(nfc_data, 300)) {
  481. osDelay(100);
  482. continue;
  483. }
  484. memset(data, 0, sizeof(MifareDesfireData));
  485. if(nfc_data->type != FuriHalNfcTypeA ||
  486. !mf_df_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  487. FURI_LOG_D(TAG, "Tag is not DESFire");
  488. osDelay(100);
  489. continue;
  490. }
  491. FURI_LOG_D(TAG, "Found DESFire tag");
  492. result->protocol = NfcDeviceProtocolMifareDesfire;
  493. // Get DESFire version
  494. tx_rx.tx_bits = 8 * mf_df_prepare_get_version(tx_rx.tx_data);
  495. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  496. FURI_LOG_W(TAG, "Bad exchange getting version");
  497. continue;
  498. }
  499. if(!mf_df_parse_get_version_response(tx_rx.rx_data, tx_rx.rx_bits / 8, &data->version)) {
  500. FURI_LOG_W(TAG, "Bad DESFire GET_VERSION response");
  501. continue;
  502. }
  503. tx_rx.tx_bits = 8 * mf_df_prepare_get_free_memory(tx_rx.tx_data);
  504. if(furi_hal_nfc_tx_rx_full(&tx_rx)) {
  505. data->free_memory = malloc(sizeof(MifareDesfireFreeMemory));
  506. memset(data->free_memory, 0, sizeof(MifareDesfireFreeMemory));
  507. if(!mf_df_parse_get_free_memory_response(
  508. tx_rx.rx_data, tx_rx.rx_bits / 8, data->free_memory)) {
  509. FURI_LOG_D(TAG, "Bad DESFire GET_FREE_MEMORY response (normal for pre-EV1 cards)");
  510. free(data->free_memory);
  511. data->free_memory = NULL;
  512. }
  513. }
  514. tx_rx.tx_bits = 8 * mf_df_prepare_get_key_settings(tx_rx.tx_data);
  515. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  516. FURI_LOG_D(TAG, "Bad exchange getting key settings");
  517. } else {
  518. data->master_key_settings = malloc(sizeof(MifareDesfireKeySettings));
  519. memset(data->master_key_settings, 0, sizeof(MifareDesfireKeySettings));
  520. if(!mf_df_parse_get_key_settings_response(
  521. tx_rx.rx_data, tx_rx.rx_bits / 8, data->master_key_settings)) {
  522. FURI_LOG_W(TAG, "Bad DESFire GET_KEY_SETTINGS response");
  523. free(data->master_key_settings);
  524. data->master_key_settings = NULL;
  525. } else {
  526. MifareDesfireKeyVersion** key_version_head =
  527. &data->master_key_settings->key_version_head;
  528. for(uint8_t key_id = 0; key_id < data->master_key_settings->max_keys; key_id++) {
  529. tx_rx.tx_bits = 8 * mf_df_prepare_get_key_version(tx_rx.tx_data, key_id);
  530. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  531. FURI_LOG_W(TAG, "Bad exchange getting key version");
  532. continue;
  533. }
  534. MifareDesfireKeyVersion* key_version = malloc(sizeof(MifareDesfireKeyVersion));
  535. memset(key_version, 0, sizeof(MifareDesfireKeyVersion));
  536. key_version->id = key_id;
  537. if(!mf_df_parse_get_key_version_response(
  538. tx_rx.rx_data, tx_rx.rx_bits / 8, key_version)) {
  539. FURI_LOG_W(TAG, "Bad DESFire GET_KEY_VERSION response");
  540. free(key_version);
  541. continue;
  542. }
  543. *key_version_head = key_version;
  544. key_version_head = &key_version->next;
  545. }
  546. }
  547. }
  548. tx_rx.tx_bits = 8 * mf_df_prepare_get_application_ids(tx_rx.tx_data);
  549. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  550. FURI_LOG_W(TAG, "Bad exchange getting application IDs");
  551. } else {
  552. if(!mf_df_parse_get_application_ids_response(
  553. tx_rx.rx_data, tx_rx.rx_bits / 8, &data->app_head)) {
  554. FURI_LOG_W(TAG, "Bad DESFire GET_APPLICATION_IDS response");
  555. }
  556. }
  557. for(MifareDesfireApplication* app = data->app_head; app; app = app->next) {
  558. tx_rx.tx_bits = 8 * mf_df_prepare_select_application(tx_rx.tx_data, app->id);
  559. if(!furi_hal_nfc_tx_rx_full(&tx_rx) ||
  560. !mf_df_parse_select_application_response(tx_rx.rx_data, tx_rx.rx_bits / 8)) {
  561. FURI_LOG_W(TAG, "Bad exchange selecting application");
  562. continue;
  563. }
  564. tx_rx.tx_bits = 8 * mf_df_prepare_get_key_settings(tx_rx.tx_data);
  565. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  566. FURI_LOG_W(TAG, "Bad exchange getting key settings");
  567. } else {
  568. app->key_settings = malloc(sizeof(MifareDesfireKeySettings));
  569. memset(app->key_settings, 0, sizeof(MifareDesfireKeySettings));
  570. if(!mf_df_parse_get_key_settings_response(
  571. tx_rx.rx_data, tx_rx.rx_bits / 8, app->key_settings)) {
  572. FURI_LOG_W(TAG, "Bad DESFire GET_KEY_SETTINGS response");
  573. free(app->key_settings);
  574. app->key_settings = NULL;
  575. continue;
  576. }
  577. MifareDesfireKeyVersion** key_version_head = &app->key_settings->key_version_head;
  578. for(uint8_t key_id = 0; key_id < app->key_settings->max_keys; key_id++) {
  579. tx_rx.tx_bits = 8 * mf_df_prepare_get_key_version(tx_rx.tx_data, key_id);
  580. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  581. FURI_LOG_W(TAG, "Bad exchange getting key version");
  582. continue;
  583. }
  584. MifareDesfireKeyVersion* key_version = malloc(sizeof(MifareDesfireKeyVersion));
  585. memset(key_version, 0, sizeof(MifareDesfireKeyVersion));
  586. key_version->id = key_id;
  587. if(!mf_df_parse_get_key_version_response(
  588. tx_rx.rx_data, tx_rx.rx_bits / 8, key_version)) {
  589. FURI_LOG_W(TAG, "Bad DESFire GET_KEY_VERSION response");
  590. free(key_version);
  591. continue;
  592. }
  593. *key_version_head = key_version;
  594. key_version_head = &key_version->next;
  595. }
  596. }
  597. tx_rx.tx_bits = 8 * mf_df_prepare_get_file_ids(tx_rx.tx_data);
  598. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  599. FURI_LOG_W(TAG, "Bad exchange getting file IDs");
  600. } else {
  601. if(!mf_df_parse_get_file_ids_response(
  602. tx_rx.rx_data, tx_rx.rx_bits / 8, &app->file_head)) {
  603. FURI_LOG_W(TAG, "Bad DESFire GET_FILE_IDS response");
  604. }
  605. }
  606. for(MifareDesfireFile* file = app->file_head; file; file = file->next) {
  607. tx_rx.tx_bits = 8 * mf_df_prepare_get_file_settings(tx_rx.tx_data, file->id);
  608. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  609. FURI_LOG_W(TAG, "Bad exchange getting file settings");
  610. continue;
  611. }
  612. if(!mf_df_parse_get_file_settings_response(
  613. tx_rx.rx_data, tx_rx.rx_bits / 8, file)) {
  614. FURI_LOG_W(TAG, "Bad DESFire GET_FILE_SETTINGS response");
  615. continue;
  616. }
  617. switch(file->type) {
  618. case MifareDesfireFileTypeStandard:
  619. case MifareDesfireFileTypeBackup:
  620. tx_rx.tx_bits = 8 * mf_df_prepare_read_data(tx_rx.tx_data, file->id, 0, 0);
  621. break;
  622. case MifareDesfireFileTypeValue:
  623. tx_rx.tx_bits = 8 * mf_df_prepare_get_value(tx_rx.tx_data, file->id);
  624. break;
  625. case MifareDesfireFileTypeLinearRecord:
  626. case MifareDesfireFileTypeCyclicRecord:
  627. tx_rx.tx_bits = 8 * mf_df_prepare_read_records(tx_rx.tx_data, file->id, 0, 0);
  628. break;
  629. }
  630. if(!furi_hal_nfc_tx_rx_full(&tx_rx)) {
  631. FURI_LOG_W(TAG, "Bad exchange reading file %d", file->id);
  632. continue;
  633. }
  634. if(!mf_df_parse_read_data_response(tx_rx.rx_data, tx_rx.rx_bits / 8, file)) {
  635. FURI_LOG_W(TAG, "Bad response reading file %d", file->id);
  636. continue;
  637. }
  638. }
  639. }
  640. // Notify caller and exit
  641. if(nfc_worker->callback) {
  642. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  643. }
  644. break;
  645. }
  646. }