]> git.zerfleddert.de Git - proxmark3-svn/blame - common/lfdemod.c
add checksum to viking demod
[proxmark3-svn] / common / lfdemod.c
CommitLineData
eb191de6 1//-----------------------------------------------------------------------------
ba1a299c 2// Copyright (C) 2014
eb191de6 3//
4// This code is licensed to you under the terms of the GNU GPL, version 2 or,
5// at your option, any later version. See the LICENSE.txt file for the text of
6// the license.
7//-----------------------------------------------------------------------------
1e090a61 8// Low frequency demod/decode commands
eb191de6 9//-----------------------------------------------------------------------------
10
eb191de6 11#include <stdlib.h>
12#include <string.h>
eb191de6 13#include "lfdemod.h"
a1d17964 14uint8_t justNoise(uint8_t *BitStream, size_t size)
15{
16 static const uint8_t THRESHOLD = 123;
17 //test samples are not just noise
18 uint8_t justNoise1 = 1;
19 for(size_t idx=0; idx < size && justNoise1 ;idx++){
20 justNoise1 = BitStream[idx] < THRESHOLD;
21 }
22 return justNoise1;
23}
24
1e090a61 25//by marshmellow
872e3d4d 26//get high and low values of a wave with passed in fuzz factor. also return noise test = 1 for passed or 0 for only noise
1e090a61 27int getHiLo(uint8_t *BitStream, size_t size, int *high, int *low, uint8_t fuzzHi, uint8_t fuzzLo)
28{
29 *high=0;
30 *low=255;
31 // get high and low thresholds
2eec55c8 32 for (size_t i=0; i < size; i++){
1e090a61 33 if (BitStream[i] > *high) *high = BitStream[i];
34 if (BitStream[i] < *low) *low = BitStream[i];
35 }
36 if (*high < 123) return -1; // just noise
75cbbe9a 37 *high = ((*high-128)*fuzzHi + 12800)/100;
38 *low = ((*low-128)*fuzzLo + 12800)/100;
1e090a61 39 return 1;
40}
41
a1d17964 42// by marshmellow
43// pass bits to be tested in bits, length bits passed in bitLen, and parity type (even=0 | odd=1) in pType
44// returns 1 if passed
45uint8_t parityTest(uint32_t bits, uint8_t bitLen, uint8_t pType)
46{
47 uint8_t ans = 0;
48 for (uint8_t i = 0; i < bitLen; i++){
49 ans ^= ((bits >> i) & 1);
50 }
f3bf15e4 51 //PrintAndLog("DEBUG: ans: %d, ptype: %d",ans,pType);
a1d17964 52 return (ans == pType);
53}
54
55//by marshmellow
2147c307 56//search for given preamble in given BitStream and return success=1 or fail=0 and startIndex and length
a1d17964 57uint8_t preambleSearch(uint8_t *BitStream, uint8_t *preamble, size_t pLen, size_t *size, size_t *startIdx)
58{
e0165dcf 59 uint8_t foundCnt=0;
60 for (int idx=0; idx < *size - pLen; idx++){
61 if (memcmp(BitStream+idx, preamble, pLen) == 0){
62 //first index found
63 foundCnt++;
64 if (foundCnt == 1){
65 *startIdx = idx;
66 }
67 if (foundCnt == 2){
68 *size = idx - *startIdx;
69 return 1;
70 }
71 }
72 }
73 return 0;
a1d17964 74}
75
2147c307 76//by marshmellow
77//takes 1s and 0s and searches for EM410x format - output EM ID
78uint8_t Em410xDecode(uint8_t *BitStream, size_t *size, size_t *startIdx, uint32_t *hi, uint64_t *lo)
79{
e0165dcf 80 //no arguments needed - built this way in case we want this to be a direct call from "data " cmds in the future
81 // otherwise could be a void with no arguments
82 //set defaults
83 uint32_t i = 0;
2767fc02 84 if (BitStream[1]>1) return 0; //allow only 1s and 0s
85
e0165dcf 86 // 111111111 bit pattern represent start of frame
87 // include 0 in front to help get start pos
88 uint8_t preamble[] = {0,1,1,1,1,1,1,1,1,1};
89 uint32_t idx = 0;
90 uint32_t parityBits = 0;
91 uint8_t errChk = 0;
92 uint8_t FmtLen = 10;
93 *startIdx = 0;
94 errChk = preambleSearch(BitStream, preamble, sizeof(preamble), size, startIdx);
95 if (errChk == 0 || *size < 64) return 0;
96 if (*size > 64) FmtLen = 22;
97 *startIdx += 1; //get rid of 0 from preamble
98 idx = *startIdx + 9;
99 for (i=0; i<FmtLen; i++){ //loop through 10 or 22 sets of 5 bits (50-10p = 40 bits or 88 bits)
100 parityBits = bytebits_to_byte(BitStream+(i*5)+idx,5);
2eec55c8 101 //check even parity - quit if failed
102 if (parityTest(parityBits, 5, 0) == 0) return 0;
e0165dcf 103 //set uint64 with ID from BitStream
104 for (uint8_t ii=0; ii<4; ii++){
105 *hi = (*hi << 1) | (*lo >> 63);
106 *lo = (*lo << 1) | (BitStream[(i*5)+ii+idx]);
107 }
108 }
109 if (errChk != 0) return 1;
110 //skip last 5 bit parity test for simplicity.
111 // *size = 64 | 128;
112 return 0;
2147c307 113}
114
fef74fdc 115//by marshmellow
116//demodulates strong heavily clipped samples
23f0a7d8 117int cleanAskRawDemod(uint8_t *BinStream, size_t *size, int clk, int invert, int high, int low)
118{
119 size_t bitCnt=0, smplCnt=0, errCnt=0;
120 uint8_t waveHigh = 0;
23f0a7d8 121 for (size_t i=0; i < *size; i++){
122 if (BinStream[i] >= high && waveHigh){
123 smplCnt++;
124 } else if (BinStream[i] <= low && !waveHigh){
125 smplCnt++;
126 } else { //transition
127 if ((BinStream[i] >= high && !waveHigh) || (BinStream[i] <= low && waveHigh)){
128 if (smplCnt > clk-(clk/4)-1) { //full clock
129 if (smplCnt > clk + (clk/4)+1) { //too many samples
130 errCnt++;
2767fc02 131 BinStream[bitCnt++]=7;
23f0a7d8 132 } else if (waveHigh) {
133 BinStream[bitCnt++] = invert;
134 BinStream[bitCnt++] = invert;
135 } else if (!waveHigh) {
136 BinStream[bitCnt++] = invert ^ 1;
137 BinStream[bitCnt++] = invert ^ 1;
138 }
139 waveHigh ^= 1;
140 smplCnt = 0;
141 } else if (smplCnt > (clk/2) - (clk/4)-1) {
142 if (waveHigh) {
143 BinStream[bitCnt++] = invert;
144 } else if (!waveHigh) {
145 BinStream[bitCnt++] = invert ^ 1;
146 }
147 waveHigh ^= 1;
148 smplCnt = 0;
149 } else if (!bitCnt) {
150 //first bit
151 waveHigh = (BinStream[i] >= high);
152 smplCnt = 1;
153 } else {
154 smplCnt++;
155 //transition bit oops
156 }
157 } else { //haven't hit new high or new low yet
158 smplCnt++;
159 }
160 }
161 }
162 *size = bitCnt;
163 return errCnt;
164}
165
eb191de6 166//by marshmellow
fef74fdc 167void askAmp(uint8_t *BitStream, size_t size)
168{
169 for(size_t i = 1; i<size; i++){
170 if (BitStream[i]-BitStream[i-1]>=30) //large jump up
171 BitStream[i]=127;
172 else if(BitStream[i]-BitStream[i-1]<=-20) //large jump down
173 BitStream[i]=-127;
174 }
175 return;
176}
177
178//by marshmellow
179//attempts to demodulate ask modulations, askType == 0 for ask/raw, askType==1 for ask/manchester
180int askdemod(uint8_t *BinStream, size_t *size, int *clk, int *invert, int maxErr, uint8_t amp, uint8_t askType)
eb191de6 181{
fef74fdc 182 if (*size==0) return -1;
6e984446 183 int start = DetectASKClock(BinStream, *size, clk, maxErr); //clock default
2eec55c8 184 if (*clk==0 || start < 0) return -3;
fef74fdc 185 if (*invert != 1) *invert = 0;
186 if (amp==1) askAmp(BinStream, *size);
187
2eec55c8 188 uint8_t initLoopMax = 255;
189 if (initLoopMax > *size) initLoopMax = *size;
ba1a299c 190 // Detect high and lows
fef74fdc 191 //25% clip in case highs and lows aren't clipped [marshmellow]
2eec55c8 192 int high, low;
fef74fdc 193 if (getHiLo(BinStream, initLoopMax, &high, &low, 75, 75) < 1)
194 return -2; //just noise
ba1a299c 195
fef74fdc 196 size_t errCnt = 0;
23f0a7d8 197 // if clean clipped waves detected run alternate demod
198 if (DetectCleanAskWave(BinStream, *size, high, low)) {
fef74fdc 199 errCnt = cleanAskRawDemod(BinStream, size, *clk, *invert, high, low);
200 if (askType) //askman
201 return manrawdecode(BinStream, size, 0);
202 else //askraw
203 return errCnt;
23f0a7d8 204 }
205
fef74fdc 206 int lastBit; //set first clock check - can go negative
207 size_t i, bitnum = 0; //output counter
208 uint8_t midBit = 0;
2eec55c8 209 uint8_t tol = 0; //clock tolerance adjust - waves will be accepted as within the clock if they fall + or - this value + clock from last valid wave
fef74fdc 210 if (*clk <= 32) tol = 1; //clock tolerance may not be needed anymore currently set to + or - 1 but could be increased for poor waves or removed entirely
211 size_t MaxBits = 1024;
6e984446 212 lastBit = start - *clk;
fef74fdc 213
6e984446 214 for (i = start; i < *size; ++i) {
fef74fdc 215 if (i-lastBit >= *clk-tol){
216 if (BinStream[i] >= high) {
217 BinStream[bitnum++] = *invert;
218 } else if (BinStream[i] <= low) {
219 BinStream[bitnum++] = *invert ^ 1;
220 } else if (i-lastBit >= *clk+tol) {
221 if (bitnum > 0) {
222 BinStream[bitnum++]=7;
223 errCnt++;
224 }
225 } else { //in tolerance - looking for peak
226 continue;
227 }
228 midBit = 0;
2eec55c8 229 lastBit += *clk;
fef74fdc 230 } else if (i-lastBit >= (*clk/2-tol) && !midBit && !askType){
231 if (BinStream[i] >= high) {
232 BinStream[bitnum++] = *invert;
233 } else if (BinStream[i] <= low) {
234 BinStream[bitnum++] = *invert ^ 1;
235 } else if (i-lastBit >= *clk/2+tol) {
236 BinStream[bitnum] = BinStream[bitnum-1];
237 bitnum++;
238 } else { //in tolerance - looking for peak
239 continue;
240 }
241 midBit = 1;
2eec55c8 242 }
243 if (bitnum >= MaxBits) break;
ba1a299c 244 }
2eec55c8 245 *size = bitnum;
6e984446 246 return errCnt;
eb191de6 247}
248
249//by marshmellow
250//take 10 and 01 and manchester decode
251//run through 2 times and take least errCnt
fef74fdc 252int manrawdecode(uint8_t * BitStream, size_t *size, uint8_t invert)
eb191de6 253{
13d77ef9 254 uint16_t bitnum=0, MaxBits = 512, errCnt = 0;
255 size_t i, ii;
256 uint16_t bestErr = 1000, bestRun = 0;
fef74fdc 257 if (*size < 16) return -1;
2767fc02 258 //find correct start position [alignment]
13d77ef9 259 for (ii=0;ii<2;++ii){
fef74fdc 260 for (i=ii; i<*size-3; i+=2)
2eec55c8 261 if (BitStream[i]==BitStream[i+1])
ba1a299c 262 errCnt++;
2eec55c8 263
ba1a299c 264 if (bestErr>errCnt){
265 bestErr=errCnt;
266 bestRun=ii;
267 }
268 errCnt=0;
269 }
2767fc02 270 //decode
fef74fdc 271 for (i=bestRun; i < *size-3; i+=2){
23f0a7d8 272 if(BitStream[i] == 1 && (BitStream[i+1] == 0)){
fef74fdc 273 BitStream[bitnum++]=invert;
23f0a7d8 274 } else if((BitStream[i] == 0) && BitStream[i+1] == 1){
fef74fdc 275 BitStream[bitnum++]=invert^1;
23f0a7d8 276 } else {
2767fc02 277 BitStream[bitnum++]=7;
ba1a299c 278 }
23f0a7d8 279 if(bitnum>MaxBits) break;
ba1a299c 280 }
23f0a7d8 281 *size=bitnum;
2eec55c8 282 return bestErr;
f822a063 283}
284
3606ac0a 285uint32_t manchesterEncode2Bytes(uint16_t datain) {
286 uint32_t output = 0;
287 uint8_t curBit = 0;
288 for (uint8_t i=0; i<16; i++) {
289 curBit = (datain >> (15-i) & 1);
290 output |= (1<<(((15-i)*2)+curBit));
291 }
292 return output;
293}
294
fef74fdc 295//by marshmellow
296//encode binary data into binary manchester
297int ManchesterEncode(uint8_t *BitStream, size_t size)
298{
299 size_t modIdx=20000, i=0;
300 if (size>modIdx) return -1;
301 for (size_t idx=0; idx < size; idx++){
302 BitStream[idx+modIdx++] = BitStream[idx];
303 BitStream[idx+modIdx++] = BitStream[idx]^1;
304 }
305 for (; i<(size*2); i++){
306 BitStream[i] = BitStream[i+20000];
307 }
308 return i;
309}
310
f822a063 311//by marshmellow
2147c307 312//take 01 or 10 = 1 and 11 or 00 = 0
313//check for phase errors - should never have 111 or 000 should be 01001011 or 10110100 for 1010
13d77ef9 314//decodes biphase or if inverted it is AKA conditional dephase encoding AKA differential manchester encoding
1e090a61 315int BiphaseRawDecode(uint8_t *BitStream, size_t *size, int offset, int invert)
f822a063 316{
2eec55c8 317 uint16_t bitnum = 0;
318 uint16_t errCnt = 0;
319 size_t i = offset;
2147c307 320 uint16_t MaxBits=512;
321 //if not enough samples - error
322 if (*size < 51) return -1;
323 //check for phase change faults - skip one sample if faulty
324 uint8_t offsetA = 1, offsetB = 1;
325 for (; i<48; i+=2){
326 if (BitStream[i+1]==BitStream[i+2]) offsetA=0;
327 if (BitStream[i+2]==BitStream[i+3]) offsetB=0;
328 }
329 if (!offsetA && offsetB) offset++;
330 for (i=offset; i<*size-3; i+=2){
331 //check for phase error
13d77ef9 332 if (BitStream[i+1]==BitStream[i+2]) {
2767fc02 333 BitStream[bitnum++]=7;
2147c307 334 errCnt++;
335 }
ba1a299c 336 if((BitStream[i]==1 && BitStream[i+1]==0) || (BitStream[i]==0 && BitStream[i+1]==1)){
1e090a61 337 BitStream[bitnum++]=1^invert;
ba1a299c 338 } else if((BitStream[i]==0 && BitStream[i+1]==0) || (BitStream[i]==1 && BitStream[i+1]==1)){
1e090a61 339 BitStream[bitnum++]=invert;
ba1a299c 340 } else {
2767fc02 341 BitStream[bitnum++]=7;
ba1a299c 342 errCnt++;
343 }
6de43508 344 if(bitnum>MaxBits) break;
ba1a299c 345 }
346 *size=bitnum;
347 return errCnt;
eb191de6 348}
349
fef74fdc 350// by marshmellow
11081e04 351// demod gProxIIDemod
352// error returns as -x
353// success returns start position in BitStream
354// BitStream must contain previously askrawdemod and biphasedemoded data
355int gProxII_Demod(uint8_t BitStream[], size_t *size)
356{
357 size_t startIdx=0;
358 uint8_t preamble[] = {1,1,1,1,1,0};
359
360 uint8_t errChk = preambleSearch(BitStream, preamble, sizeof(preamble), size, &startIdx);
361 if (errChk == 0) return -3; //preamble not found
362 if (*size != 96) return -2; //should have found 96 bits
363 //check first 6 spacer bits to verify format
364 if (!BitStream[startIdx+5] && !BitStream[startIdx+10] && !BitStream[startIdx+15] && !BitStream[startIdx+20] && !BitStream[startIdx+25] && !BitStream[startIdx+30]){
365 //confirmed proper separator bits found
366 //return start position
367 return (int) startIdx;
368 }
369 return -5;
370}
371
ba1a299c 372//translate wave to 11111100000 (1 for each short wave 0 for each long wave)
f822a063 373size_t fsk_wave_demod(uint8_t * dest, size_t size, uint8_t fchigh, uint8_t fclow)
eb191de6 374{
2eec55c8 375 size_t last_transition = 0;
376 size_t idx = 1;
ac3ba7ee 377 //uint32_t maxVal=0;
ba1a299c 378 if (fchigh==0) fchigh=10;
379 if (fclow==0) fclow=8;
84871873 380 //set the threshold close to 0 (graph) or 128 std to avoid static
381 uint8_t threshold_value = 123;
f4eadf8a 382 size_t preLastSample = 0;
383 size_t LastSample = 0;
384 size_t currSample = 0;
ba1a299c 385 // sync to first lo-hi transition, and threshold
386
387 // Need to threshold first sample
388
389 if(dest[0] < threshold_value) dest[0] = 0;
390 else dest[0] = 1;
391
392 size_t numBits = 0;
393 // count cycles between consecutive lo-hi transitions, there should be either 8 (fc/8)
394 // or 10 (fc/10) cycles but in practice due to noise etc we may end up with with anywhere
395 // between 7 to 11 cycles so fuzz it by treat anything <9 as 8 and anything else as 10
396 for(idx = 1; idx < size; idx++) {
397 // threshold current value
398
399 if (dest[idx] < threshold_value) dest[idx] = 0;
400 else dest[idx] = 1;
401
402 // Check for 0->1 transition
403 if (dest[idx-1] < dest[idx]) { // 0 -> 1 transition
f4eadf8a 404 preLastSample = LastSample;
405 LastSample = currSample;
406 currSample = idx-last_transition;
407 if (currSample < (fclow-2)){ //0-5 = garbage noise
ba1a299c 408 //do nothing with extra garbage
f4eadf8a 409 } else if (currSample < (fchigh-1)) { //6-8 = 8 sample waves
410 if (LastSample > (fchigh-2) && preLastSample < (fchigh-1)){
411 dest[numBits-1]=1; //correct last 9 wave surrounded by 8 waves
412 }
2eec55c8 413 dest[numBits++]=1;
f4eadf8a 414
415 } else if (currSample > (fchigh+1) && !numBits) { //12 + and first bit = garbage
13d77ef9 416 //do nothing with beginning garbage
f4eadf8a 417 } else if (currSample == (fclow+1) && LastSample == (fclow-1)) { // had a 7 then a 9 should be two 8's
418 dest[numBits++]=1;
419 } else { //9+ = 10 sample waves
2eec55c8 420 dest[numBits++]=0;
ba1a299c 421 }
422 last_transition = idx;
ba1a299c 423 }
424 }
425 return numBits; //Actually, it returns the number of bytes, but each byte represents a bit: 1 or 0
eb191de6 426}
427
ba1a299c 428//translate 11111100000 to 10
2eec55c8 429size_t aggregate_bits(uint8_t *dest, size_t size, uint8_t rfLen,
e0165dcf 430 uint8_t invert, uint8_t fchigh, uint8_t fclow)
eb191de6 431{
ba1a299c 432 uint8_t lastval=dest[0];
2eec55c8 433 size_t idx=0;
ba1a299c 434 size_t numBits=0;
435 uint32_t n=1;
ba1a299c 436 for( idx=1; idx < size; idx++) {
13d77ef9 437 n++;
2eec55c8 438 if (dest[idx]==lastval) continue;
439
ba1a299c 440 //if lastval was 1, we have a 1->0 crossing
13d77ef9 441 if (dest[idx-1]==1) {
75cbbe9a 442 if (!numBits && n < rfLen/fclow) {
13d77ef9 443 n=0;
444 lastval = dest[idx];
445 continue;
446 }
75cbbe9a 447 n = (n * fclow + rfLen/2) / rfLen;
13d77ef9 448 } else {// 0->1 crossing
449 //test first bitsample too small
75cbbe9a 450 if (!numBits && n < rfLen/fchigh) {
13d77ef9 451 n=0;
452 lastval = dest[idx];
453 continue;
454 }
75cbbe9a 455 n = (n * fchigh + rfLen/2) / rfLen;
ba1a299c 456 }
457 if (n == 0) n = 1;
458
2eec55c8 459 memset(dest+numBits, dest[idx-1]^invert , n);
460 numBits += n;
ba1a299c 461 n=0;
462 lastval=dest[idx];
463 }//end for
13d77ef9 464 // if valid extra bits at the end were all the same frequency - add them in
75cbbe9a 465 if (n > rfLen/fchigh) {
13d77ef9 466 if (dest[idx-2]==1) {
75cbbe9a 467 n = (n * fclow + rfLen/2) / rfLen;
13d77ef9 468 } else {
75cbbe9a 469 n = (n * fchigh + rfLen/2) / rfLen;
13d77ef9 470 }
2eec55c8 471 memset(dest+numBits, dest[idx-1]^invert , n);
13d77ef9 472 numBits += n;
473 }
ba1a299c 474 return numBits;
eb191de6 475}
476//by marshmellow (from holiman's base)
477// full fsk demod from GraphBuffer wave to decoded 1s and 0s (no mandemod)
f822a063 478int fskdemod(uint8_t *dest, size_t size, uint8_t rfLen, uint8_t invert, uint8_t fchigh, uint8_t fclow)
eb191de6 479{
ba1a299c 480 // FSK demodulator
481 size = fsk_wave_demod(dest, size, fchigh, fclow);
2eec55c8 482 size = aggregate_bits(dest, size, rfLen, invert, fchigh, fclow);
ba1a299c 483 return size;
eb191de6 484}
a1d17964 485
eb191de6 486// loop to get raw HID waveform then FSK demodulate the TAG ID from it
ec75f5c1 487int HIDdemodFSK(uint8_t *dest, size_t *size, uint32_t *hi2, uint32_t *hi, uint32_t *lo)
eb191de6 488{
e0165dcf 489 if (justNoise(dest, *size)) return -1;
490
491 size_t numStart=0, size2=*size, startIdx=0;
492 // FSK demodulator
493 *size = fskdemod(dest, size2,50,1,10,8); //fsk2a
2eec55c8 494 if (*size < 96*2) return -2;
e0165dcf 495 // 00011101 bit pattern represent start of frame, 01 pattern represents a 0 and 10 represents a 1
496 uint8_t preamble[] = {0,0,0,1,1,1,0,1};
497 // find bitstring in array
498 uint8_t errChk = preambleSearch(dest, preamble, sizeof(preamble), size, &startIdx);
499 if (errChk == 0) return -3; //preamble not found
500
501 numStart = startIdx + sizeof(preamble);
502 // final loop, go over previously decoded FSK data and manchester decode into usable tag ID
503 for (size_t idx = numStart; (idx-numStart) < *size - sizeof(preamble); idx+=2){
504 if (dest[idx] == dest[idx+1]){
505 return -4; //not manchester data
506 }
507 *hi2 = (*hi2<<1)|(*hi>>31);
508 *hi = (*hi<<1)|(*lo>>31);
509 //Then, shift in a 0 or one into low
510 if (dest[idx] && !dest[idx+1]) // 1 0
511 *lo=(*lo<<1)|1;
512 else // 0 1
513 *lo=(*lo<<1)|0;
514 }
515 return (int)startIdx;
eb191de6 516}
517
ec75f5c1 518// loop to get raw paradox waveform then FSK demodulate the TAG ID from it
a1d17964 519int ParadoxdemodFSK(uint8_t *dest, size_t *size, uint32_t *hi2, uint32_t *hi, uint32_t *lo)
ec75f5c1 520{
a1d17964 521 if (justNoise(dest, *size)) return -1;
522
523 size_t numStart=0, size2=*size, startIdx=0;
ec75f5c1 524 // FSK demodulator
a1d17964 525 *size = fskdemod(dest, size2,50,1,10,8); //fsk2a
526 if (*size < 96) return -2;
ec75f5c1 527
a1d17964 528 // 00001111 bit pattern represent start of frame, 01 pattern represents a 0 and 10 represents a 1
529 uint8_t preamble[] = {0,0,0,0,1,1,1,1};
530
531 uint8_t errChk = preambleSearch(dest, preamble, sizeof(preamble), size, &startIdx);
532 if (errChk == 0) return -3; //preamble not found
533
534 numStart = startIdx + sizeof(preamble);
535 // final loop, go over previously decoded FSK data and manchester decode into usable tag ID
536 for (size_t idx = numStart; (idx-numStart) < *size - sizeof(preamble); idx+=2){
537 if (dest[idx] == dest[idx+1])
538 return -4; //not manchester data
539 *hi2 = (*hi2<<1)|(*hi>>31);
540 *hi = (*hi<<1)|(*lo>>31);
541 //Then, shift in a 0 or one into low
542 if (dest[idx] && !dest[idx+1]) // 1 0
543 *lo=(*lo<<1)|1;
544 else // 0 1
545 *lo=(*lo<<1)|0;
ec75f5c1 546 }
a1d17964 547 return (int)startIdx;
ec75f5c1 548}
549
fd1d30cb 550uint32_t bytebits_to_byte(uint8_t *src, size_t numbits)
eb191de6 551{
ba1a299c 552 uint32_t num = 0;
553 for(int i = 0 ; i < numbits ; i++)
554 {
555 num = (num << 1) | (*src);
556 src++;
557 }
558 return num;
eb191de6 559}
560
04bb0567 561//least significant bit first
fd1d30cb 562uint32_t bytebits_to_byteLSBF(uint8_t *src, size_t numbits)
04bb0567 563{
564 uint32_t num = 0;
565 for(int i = 0 ; i < numbits ; i++)
566 {
fd1d30cb 567 num = (num << 1) | *(src + (numbits-(i+1)));
04bb0567 568 }
569 return num;
570}
571
eb191de6 572int IOdemodFSK(uint8_t *dest, size_t size)
573{
a1d17964 574 if (justNoise(dest, size)) return -1;
ba1a299c 575 //make sure buffer has data
a1d17964 576 if (size < 66*64) return -2;
ba1a299c 577 // FSK demodulator
a1d17964 578 size = fskdemod(dest, size, 64, 1, 10, 8); // FSK2a RF/64
579 if (size < 65) return -3; //did we get a good demod?
ba1a299c 580 //Index map
581 //0 10 20 30 40 50 60
582 //| | | | | | |
583 //01234567 8 90123456 7 89012345 6 78901234 5 67890123 4 56789012 3 45678901 23
584 //-----------------------------------------------------------------------------
585 //00000000 0 11110000 1 facility 1 version* 1 code*one 1 code*two 1 ???????? 11
586 //
587 //XSF(version)facility:codeone+codetwo
588 //Handle the data
a1d17964 589 size_t startIdx = 0;
590 uint8_t preamble[] = {0,0,0,0,0,0,0,0,0,1};
591 uint8_t errChk = preambleSearch(dest, preamble, sizeof(preamble), &size, &startIdx);
592 if (errChk == 0) return -4; //preamble not found
eb191de6 593
a1d17964 594 if (!dest[startIdx+8] && dest[startIdx+17]==1 && dest[startIdx+26]==1 && dest[startIdx+35]==1 && dest[startIdx+44]==1 && dest[startIdx+53]==1){
595 //confirmed proper separator bits found
596 //return start position
597 return (int) startIdx;
1e090a61 598 }
a1d17964 599 return -5;
415274a7 600}
601
602// by marshmellow
603// find viking preamble 0xF200 in already demoded data
604int VikingDemod_AM(uint8_t *dest, size_t *size) {
605 if (justNoise(dest, *size)) return -1;
606 //make sure buffer has data
607 if (*size < 64*2) return -2;
608
609 size_t startIdx = 0;
610 uint8_t preamble[] = {1,1,1,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0};
611 uint8_t errChk = preambleSearch(dest, preamble, sizeof(preamble), size, &startIdx);
612 if (errChk == 0) return -4; //preamble not found
3ea7254a 613 uint32_t checkCalc = bytebits_to_byte(dest+startIdx,8) ^ bytebits_to_byte(dest+startIdx+8,8) ^ bytebits_to_byte(dest+startIdx+16,8)
614 ^ bytebits_to_byte(dest+startIdx+24,8) ^ bytebits_to_byte(dest+startIdx+32,8) ^ bytebits_to_byte(dest+startIdx+40,8)
615 ^ bytebits_to_byte(dest+startIdx+48,8) ^ bytebits_to_byte(dest+startIdx+56,8);
616 if ( checkCalc != 0xA8 ) return -5;
415274a7 617 if (*size != 64) return -5;
618 //return start position
619 return (int) startIdx;
1e090a61 620}
621
622// by marshmellow
623// takes a array of binary values, start position, length of bits per parity (includes parity bit),
29b6cacc 624// Parity Type (1 for odd; 0 for even; 2 Always 1's), and binary Length (length to run)
1e090a61 625size_t removeParity(uint8_t *BitStream, size_t startIdx, uint8_t pLen, uint8_t pType, size_t bLen)
626{
627 uint32_t parityWd = 0;
628 size_t j = 0, bitCnt = 0;
629 for (int word = 0; word < (bLen); word+=pLen){
630 for (int bit=0; bit < pLen; bit++){
631 parityWd = (parityWd << 1) | BitStream[startIdx+word+bit];
f3bf15e4 632 BitStream[j++] = (BitStream[startIdx+word+bit]);
1e090a61 633 }
29b6cacc 634 j--; // overwrite parity with next data
1e090a61 635 // if parity fails then return 0
29b6cacc 636 if (pType == 2) { // then marker bit which should be a 1
637 if (!BitStream[j]) return 0;
638 } else {
639 if (parityTest(parityWd, pLen, pType) == 0) return 0;
fd1d30cb 640 }
1e090a61 641 bitCnt+=(pLen-1);
642 parityWd = 0;
643 }
644 // if we got here then all the parities passed
645 //return ID start index and size
646 return bitCnt;
647}
648
04bb0567 649// Ask/Biphase Demod then try to locate an ISO 11784/85 ID
650// BitStream must contain previously askrawdemod and biphasedemoded data
b2c330b3 651int FDXBdemodBI(uint8_t *dest, size_t *size)
04bb0567 652{
653 //make sure buffer has enough data
654 if (*size < 128) return -1;
655
656 size_t startIdx = 0;
657 uint8_t preamble[] = {0,0,0,0,0,0,0,0,0,0,1};
658
659 uint8_t errChk = preambleSearch(dest, preamble, sizeof(preamble), size, &startIdx);
660 if (errChk == 0) return -2; //preamble not found
661 return (int)startIdx;
662}
663
1e090a61 664// by marshmellow
665// FSK Demod then try to locate an AWID ID
a1d17964 666int AWIDdemodFSK(uint8_t *dest, size_t *size)
1e090a61 667{
a1d17964 668 //make sure buffer has enough data
669 if (*size < 96*50) return -1;
670
671 if (justNoise(dest, *size)) return -2;
1e090a61 672
673 // FSK demodulator
a1d17964 674 *size = fskdemod(dest, *size, 50, 1, 10, 8); // fsk2a RF/50
675 if (*size < 96) return -3; //did we get a good demod?
676
677 uint8_t preamble[] = {0,0,0,0,0,0,0,1};
678 size_t startIdx = 0;
679 uint8_t errChk = preambleSearch(dest, preamble, sizeof(preamble), size, &startIdx);
680 if (errChk == 0) return -4; //preamble not found
681 if (*size != 96) return -5;
682 return (int)startIdx;
1e090a61 683}
684
685// by marshmellow
686// FSK Demod then try to locate an Farpointe Data (pyramid) ID
a1d17964 687int PyramiddemodFSK(uint8_t *dest, size_t *size)
1e090a61 688{
f3bf15e4 689 //make sure buffer has data
690 if (*size < 128*50) return -5;
a1d17964 691
f3bf15e4 692 //test samples are not just noise
693 if (justNoise(dest, *size)) return -1;
1e090a61 694
f3bf15e4 695 // FSK demodulator
696 *size = fskdemod(dest, *size, 50, 1, 10, 8); // fsk2a RF/50
697 if (*size < 128) return -2; //did we get a good demod?
a1d17964 698
f3bf15e4 699 uint8_t preamble[] = {0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1};
a1d17964 700 size_t startIdx = 0;
701 uint8_t errChk = preambleSearch(dest, preamble, sizeof(preamble), size, &startIdx);
702 if (errChk == 0) return -4; //preamble not found
703 if (*size != 128) return -3;
704 return (int)startIdx;
1e090a61 705}
706
fef74fdc 707// by marshmellow
708// to detect a wave that has heavily clipped (clean) samples
cc15a118 709uint8_t DetectCleanAskWave(uint8_t dest[], size_t size, uint8_t high, uint8_t low)
6de43508 710{
1fbf8956 711 uint16_t allPeaks=1;
6de43508 712 uint16_t cntPeaks=0;
cc15a118 713 size_t loopEnd = 512+60;
1fbf8956 714 if (loopEnd > size) loopEnd = size;
715 for (size_t i=60; i<loopEnd; i++){
6de43508 716 if (dest[i]>low && dest[i]<high)
717 allPeaks=0;
718 else
719 cntPeaks++;
720 }
1fbf8956 721 if (allPeaks == 0){
722 if (cntPeaks > 300) return 1;
6de43508 723 }
724 return allPeaks;
725}
726
2eec55c8 727// by marshmellow
728// to help detect clocks on heavily clipped samples
cc15a118 729// based on count of low to low
730int DetectStrongAskClock(uint8_t dest[], size_t size, uint8_t high, uint8_t low)
13d77ef9 731{
cc15a118 732 uint8_t fndClk[] = {8,16,32,40,50,64,128};
733 size_t startwave;
734 size_t i = 0;
735 size_t minClk = 255;
736 // get to first full low to prime loop and skip incomplete first pulse
737 while ((dest[i] < high) && (i < size))
738 ++i;
739 while ((dest[i] > low) && (i < size))
740 ++i;
741
742 // loop through all samples
743 while (i < size) {
744 // measure from low to low
745 while ((dest[i] > low) && (i < size))
746 ++i;
747 startwave= i;
748 while ((dest[i] < high) && (i < size))
749 ++i;
750 while ((dest[i] > low) && (i < size))
751 ++i;
752 //get minimum measured distance
753 if (i-startwave < minClk && i < size)
754 minClk = i - startwave;
13d77ef9 755 }
cc15a118 756 // set clock
757 for (uint8_t clkCnt = 0; clkCnt<7; clkCnt++) {
758 if (minClk >= fndClk[clkCnt]-(fndClk[clkCnt]/8) && minClk <= fndClk[clkCnt]+1)
759 return fndClk[clkCnt];
13d77ef9 760 }
cc15a118 761 return 0;
13d77ef9 762}
763
eb191de6 764// by marshmellow
765// not perfect especially with lower clocks or VERY good antennas (heavy wave clipping)
766// maybe somehow adjust peak trimming value based on samples to fix?
6de43508 767// return start index of best starting position for that clock and return clock (by reference)
768int DetectASKClock(uint8_t dest[], size_t size, int *clock, int maxErr)
eb191de6 769{
6e984446 770 size_t i=1;
cc15a118 771 uint8_t clk[] = {255,8,16,32,40,50,64,100,128,255};
772 uint8_t clkEnd = 9;
2eec55c8 773 uint8_t loopCnt = 255; //don't need to loop through entire array...
cc15a118 774 if (size <= loopCnt) return -1; //not enough samples
6e984446 775
776 //if we already have a valid clock
777 uint8_t clockFnd=0;
cc15a118 778 for (;i<clkEnd;++i)
779 if (clk[i] == *clock) clockFnd = i;
6e984446 780 //clock found but continue to find best startpos
e0165dcf 781
782 //get high and low peak
783 int peak, low;
2eec55c8 784 if (getHiLo(dest, loopCnt, &peak, &low, 75, 75) < 1) return -1;
e0165dcf 785
786 //test for large clean peaks
cc15a118 787 if (!clockFnd){
788 if (DetectCleanAskWave(dest, size, peak, low)==1){
789 int ans = DetectStrongAskClock(dest, size, peak, low);
790 for (i=clkEnd-1; i>0; i--){
791 if (clk[i] == ans) {
792 *clock = ans;
793 //clockFnd = i;
794 return 0; // for strong waves i don't use the 'best start position' yet...
795 //break; //clock found but continue to find best startpos [not yet]
796 }
e0165dcf 797 }
798 }
799 }
cc15a118 800
2eec55c8 801 uint8_t ii;
802 uint8_t clkCnt, tol = 0;
803 uint16_t bestErr[]={1000,1000,1000,1000,1000,1000,1000,1000,1000};
804 uint8_t bestStart[]={0,0,0,0,0,0,0,0,0};
805 size_t errCnt = 0;
806 size_t arrLoc, loopEnd;
6e984446 807
cc15a118 808 if (clockFnd>0) {
809 clkCnt = clockFnd;
810 clkEnd = clockFnd+1;
811 }
812 else clkCnt=1;
813
814 //test each valid clock from smallest to greatest to see which lines up
815 for(; clkCnt < clkEnd; clkCnt++){
fef74fdc 816 if (clk[clkCnt] <= 32){
e0165dcf 817 tol=1;
818 }else{
819 tol=0;
820 }
2767fc02 821 //if no errors allowed - keep start within the first clock
cc15a118 822 if (!maxErr && size > clk[clkCnt]*2 + tol && clk[clkCnt]<128) loopCnt=clk[clkCnt]*2;
e0165dcf 823 bestErr[clkCnt]=1000;
6e984446 824 //try lining up the peaks by moving starting point (try first few clocks)
cc15a118 825 for (ii=0; ii < loopCnt; ii++){
2eec55c8 826 if (dest[ii] < peak && dest[ii] > low) continue;
827
828 errCnt=0;
829 // now that we have the first one lined up test rest of wave array
830 loopEnd = ((size-ii-tol) / clk[clkCnt]) - 1;
831 for (i=0; i < loopEnd; ++i){
832 arrLoc = ii + (i * clk[clkCnt]);
833 if (dest[arrLoc] >= peak || dest[arrLoc] <= low){
834 }else if (dest[arrLoc-tol] >= peak || dest[arrLoc-tol] <= low){
835 }else if (dest[arrLoc+tol] >= peak || dest[arrLoc+tol] <= low){
836 }else{ //error no peak detected
837 errCnt++;
e0165dcf 838 }
839 }
cc15a118 840 //if we found no errors then we can stop here and a low clock (common clocks)
2eec55c8 841 // this is correct one - return this clock
842 //PrintAndLog("DEBUG: clk %d, err %d, ii %d, i %d",clk[clkCnt],errCnt,ii,i);
cc15a118 843 if(errCnt==0 && clkCnt<7) {
844 if (!clockFnd) *clock = clk[clkCnt];
2eec55c8 845 return ii;
846 }
847 //if we found errors see if it is lowest so far and save it as best run
848 if(errCnt<bestErr[clkCnt]){
849 bestErr[clkCnt]=errCnt;
850 bestStart[clkCnt]=ii;
851 }
e0165dcf 852 }
853 }
cc15a118 854 uint8_t iii;
e0165dcf 855 uint8_t best=0;
cc15a118 856 for (iii=1; iii<clkEnd; ++iii){
2eec55c8 857 if (bestErr[iii] < bestErr[best]){
858 if (bestErr[iii] == 0) bestErr[iii]=1;
e0165dcf 859 // current best bit to error ratio vs new bit to error ratio
2eec55c8 860 if ( (size/clk[best])/bestErr[best] < (size/clk[iii])/bestErr[iii] ){
e0165dcf 861 best = iii;
862 }
863 }
864 }
2767fc02 865 //if (bestErr[best] > maxErr) return -1;
cc15a118 866 if (!clockFnd) *clock = clk[best];
e0165dcf 867 return bestStart[best];
eb191de6 868}
ba1a299c 869
870//by marshmellow
6de43508 871//detect psk clock by reading each phase shift
872// a phase shift is determined by measuring the sample length of each wave
873int DetectPSKClock(uint8_t dest[], size_t size, int clock)
ba1a299c 874{
e0165dcf 875 uint8_t clk[]={255,16,32,40,50,64,100,128,255}; //255 is not a valid clock
876 uint16_t loopCnt = 4096; //don't need to loop through entire array...
877 if (size == 0) return 0;
878 if (size<loopCnt) loopCnt = size;
879
880 //if we already have a valid clock quit
881 size_t i=1;
882 for (; i < 8; ++i)
883 if (clk[i] == clock) return clock;
884
885 size_t waveStart=0, waveEnd=0, firstFullWave=0, lastClkBit=0;
886 uint8_t clkCnt, fc=0, fullWaveLen=0, tol=1;
887 uint16_t peakcnt=0, errCnt=0, waveLenCnt=0;
888 uint16_t bestErr[]={1000,1000,1000,1000,1000,1000,1000,1000,1000};
889 uint16_t peaksdet[]={0,0,0,0,0,0,0,0,0};
2eec55c8 890 fc = countFC(dest, size, 0);
891 if (fc!=2 && fc!=4 && fc!=8) return -1;
e0165dcf 892 //PrintAndLog("DEBUG: FC: %d",fc);
893
894 //find first full wave
895 for (i=0; i<loopCnt; i++){
896 if (dest[i] < dest[i+1] && dest[i+1] >= dest[i+2]){
897 if (waveStart == 0) {
898 waveStart = i+1;
899 //PrintAndLog("DEBUG: waveStart: %d",waveStart);
900 } else {
901 waveEnd = i+1;
902 //PrintAndLog("DEBUG: waveEnd: %d",waveEnd);
903 waveLenCnt = waveEnd-waveStart;
904 if (waveLenCnt > fc){
905 firstFullWave = waveStart;
906 fullWaveLen=waveLenCnt;
907 break;
908 }
909 waveStart=0;
910 }
911 }
912 }
913 //PrintAndLog("DEBUG: firstFullWave: %d, waveLen: %d",firstFullWave,fullWaveLen);
914
915 //test each valid clock from greatest to smallest to see which lines up
916 for(clkCnt=7; clkCnt >= 1 ; clkCnt--){
917 lastClkBit = firstFullWave; //set end of wave as clock align
918 waveStart = 0;
919 errCnt=0;
920 peakcnt=0;
921 //PrintAndLog("DEBUG: clk: %d, lastClkBit: %d",clk[clkCnt],lastClkBit);
922
923 for (i = firstFullWave+fullWaveLen-1; i < loopCnt-2; i++){
924 //top edge of wave = start of new wave
925 if (dest[i] < dest[i+1] && dest[i+1] >= dest[i+2]){
926 if (waveStart == 0) {
927 waveStart = i+1;
928 waveLenCnt=0;
929 } else { //waveEnd
930 waveEnd = i+1;
931 waveLenCnt = waveEnd-waveStart;
932 if (waveLenCnt > fc){
933 //if this wave is a phase shift
934 //PrintAndLog("DEBUG: phase shift at: %d, len: %d, nextClk: %d, ii: %d, fc: %d",waveStart,waveLenCnt,lastClkBit+clk[clkCnt]-tol,ii+1,fc);
935 if (i+1 >= lastClkBit + clk[clkCnt] - tol){ //should be a clock bit
936 peakcnt++;
937 lastClkBit+=clk[clkCnt];
938 } else if (i<lastClkBit+8){
939 //noise after a phase shift - ignore
940 } else { //phase shift before supposed to based on clock
941 errCnt++;
942 }
943 } else if (i+1 > lastClkBit + clk[clkCnt] + tol + fc){
944 lastClkBit+=clk[clkCnt]; //no phase shift but clock bit
945 }
946 waveStart=i+1;
947 }
948 }
949 }
950 if (errCnt == 0){
951 return clk[clkCnt];
952 }
953 if (errCnt <= bestErr[clkCnt]) bestErr[clkCnt]=errCnt;
954 if (peakcnt > peaksdet[clkCnt]) peaksdet[clkCnt]=peakcnt;
955 }
956 //all tested with errors
957 //return the highest clk with the most peaks found
958 uint8_t best=7;
959 for (i=7; i>=1; i--){
960 if (peaksdet[i] > peaksdet[best]) {
961 best = i;
962 }
963 //PrintAndLog("DEBUG: Clk: %d, peaks: %d, errs: %d, bestClk: %d",clk[iii],peaksdet[iii],bestErr[iii],clk[best]);
964 }
965 return clk[best];
ba1a299c 966}
967
6de43508 968//by marshmellow
969//detect nrz clock by reading #peaks vs no peaks(or errors)
970int DetectNRZClock(uint8_t dest[], size_t size, int clock)
ba1a299c 971{
2eec55c8 972 size_t i=0;
973 uint8_t clk[]={8,16,32,40,50,64,100,128,255};
974 size_t loopCnt = 4096; //don't need to loop through entire array...
e0165dcf 975 if (size == 0) return 0;
976 if (size<loopCnt) loopCnt = size;
977
978 //if we already have a valid clock quit
979 for (; i < 8; ++i)
980 if (clk[i] == clock) return clock;
981
982 //get high and low peak
983 int peak, low;
2eec55c8 984 if (getHiLo(dest, loopCnt, &peak, &low, 75, 75) < 1) return 0;
e0165dcf 985
986 //PrintAndLog("DEBUG: peak: %d, low: %d",peak,low);
2eec55c8 987 size_t ii;
e0165dcf 988 uint8_t clkCnt;
989 uint8_t tol = 0;
2eec55c8 990 uint16_t peakcnt=0;
991 uint16_t peaksdet[]={0,0,0,0,0,0,0,0};
992 uint16_t maxPeak=0;
e0165dcf 993 //test for large clipped waves
994 for (i=0; i<loopCnt; i++){
995 if (dest[i] >= peak || dest[i] <= low){
996 peakcnt++;
997 } else {
998 if (peakcnt>0 && maxPeak < peakcnt){
999 maxPeak = peakcnt;
1000 }
1001 peakcnt=0;
1002 }
1003 }
1004 peakcnt=0;
1005 //test each valid clock from smallest to greatest to see which lines up
1006 for(clkCnt=0; clkCnt < 8; ++clkCnt){
1007 //ignore clocks smaller than largest peak
1008 if (clk[clkCnt]<maxPeak) continue;
1009
1010 //try lining up the peaks by moving starting point (try first 256)
1011 for (ii=0; ii< loopCnt; ++ii){
1012 if ((dest[ii] >= peak) || (dest[ii] <= low)){
1013 peakcnt=0;
1014 // now that we have the first one lined up test rest of wave array
1015 for (i=0; i < ((int)((size-ii-tol)/clk[clkCnt])-1); ++i){
1016 if (dest[ii+(i*clk[clkCnt])]>=peak || dest[ii+(i*clk[clkCnt])]<=low){
1017 peakcnt++;
1018 }
1019 }
1020 if(peakcnt>peaksdet[clkCnt]) {
1021 peaksdet[clkCnt]=peakcnt;
1022 }
1023 }
1024 }
1025 }
1026 int iii=7;
2eec55c8 1027 uint8_t best=0;
e0165dcf 1028 for (iii=7; iii > 0; iii--){
1029 if (peaksdet[iii] > peaksdet[best]){
1030 best = iii;
1031 }
1032 //PrintAndLog("DEBUG: Clk: %d, peaks: %d, errs: %d, bestClk: %d",clk[iii],peaksdet[iii],bestErr[iii],clk[best]);
1033 }
1034 return clk[best];
ba1a299c 1035}
1036
04d2721b 1037// by marshmellow
1038// convert psk1 demod to psk2 demod
1039// only transition waves are 1s
1040void psk1TOpsk2(uint8_t *BitStream, size_t size)
1041{
1042 size_t i=1;
1043 uint8_t lastBit=BitStream[0];
1044 for (; i<size; i++){
2767fc02 1045 if (BitStream[i]==7){
7a8a982b 1046 //ignore errors
1047 } else if (lastBit!=BitStream[i]){
04d2721b 1048 lastBit=BitStream[i];
1049 BitStream[i]=1;
1050 } else {
1051 BitStream[i]=0;
1052 }
1053 }
1054 return;
1055}
ba1a299c 1056
3bc66a96 1057// by marshmellow
1058// convert psk2 demod to psk1 demod
1059// from only transition waves are 1s to phase shifts change bit
1060void psk2TOpsk1(uint8_t *BitStream, size_t size)
1061{
712ebfa6 1062 uint8_t phase=0;
1063 for (size_t i=0; i<size; i++){
1064 if (BitStream[i]==1){
3bc66a96 1065 phase ^=1;
1066 }
1067 BitStream[i]=phase;
1068 }
1069 return;
1070}
1071
04d2721b 1072// redesigned by marshmellow adjusted from existing decode functions
1073// indala id decoding - only tested on 26 bit tags, but attempted to make it work for more
ba1a299c 1074int indala26decode(uint8_t *bitStream, size_t *size, uint8_t *invert)
1075{
1076 //26 bit 40134 format (don't know other formats)
1077 int i;
84871873 1078 int long_wait=29;//29 leading zeros in format
ba1a299c 1079 int start;
1080 int first = 0;
1081 int first2 = 0;
1082 int bitCnt = 0;
1083 int ii;
1084 // Finding the start of a UID
1085 for (start = 0; start <= *size - 250; start++) {
1086 first = bitStream[start];
1087 for (i = start; i < start + long_wait; i++) {
1088 if (bitStream[i] != first) {
1089 break;
1090 }
1091 }
1092 if (i == (start + long_wait)) {
1093 break;
1094 }
1095 }
1096 if (start == *size - 250 + 1) {
1097 // did not find start sequence
1098 return -1;
1099 }
ba1a299c 1100 // Inverting signal if needed
1101 if (first == 1) {
1102 for (i = start; i < *size; i++) {
1103 bitStream[i] = !bitStream[i];
1104 }
1105 *invert = 1;
1106 }else *invert=0;
1107
1108 int iii;
84871873 1109 //found start once now test length by finding next one
ba1a299c 1110 for (ii=start+29; ii <= *size - 250; ii++) {
1111 first2 = bitStream[ii];
1112 for (iii = ii; iii < ii + long_wait; iii++) {
1113 if (bitStream[iii] != first2) {
1114 break;
1115 }
1116 }
1117 if (iii == (ii + long_wait)) {
1118 break;
1119 }
1120 }
1121 if (ii== *size - 250 + 1){
1122 // did not find second start sequence
1123 return -2;
1124 }
1125 bitCnt=ii-start;
1126
1127 // Dumping UID
1128 i = start;
1129 for (ii = 0; ii < bitCnt; ii++) {
1130 bitStream[ii] = bitStream[i++];
1131 }
1132 *size=bitCnt;
1133 return 1;
1134}
1135
6de43508 1136// by marshmellow - demodulate NRZ wave (both similar enough)
04d2721b 1137// peaks invert bit (high=1 low=0) each clock cycle = 1 bit determined by last peak
6de43508 1138// there probably is a much simpler way to do this....
1139int nrzRawDemod(uint8_t *dest, size_t *size, int *clk, int *invert, int maxErr)
ba1a299c 1140{
e0165dcf 1141 if (justNoise(dest, *size)) return -1;
1142 *clk = DetectNRZClock(dest, *size, *clk);
1143 if (*clk==0) return -2;
2eec55c8 1144 size_t i, gLen = 4096;
e0165dcf 1145 if (gLen>*size) gLen = *size;
1146 int high, low;
1147 if (getHiLo(dest, gLen, &high, &low, 75, 75) < 1) return -3; //25% fuzz on high 25% fuzz on low
1148 int lastBit = 0; //set first clock check
2eec55c8 1149 size_t iii = 0, bitnum = 0; //bitnum counter
1150 uint16_t errCnt = 0, MaxBits = 1000;
1151 size_t bestErrCnt = maxErr+1;
1152 size_t bestPeakCnt = 0, bestPeakStart = 0;
1153 uint8_t bestFirstPeakHigh=0, firstPeakHigh=0, curBit=0, bitHigh=0, errBitHigh=0;
e0165dcf 1154 uint8_t tol = 1; //clock tolerance adjust - waves will be accepted as within the clock if they fall + or - this value + clock from last valid wave
e0165dcf 1155 uint16_t peakCnt=0;
1156 uint8_t ignoreWindow=4;
2eec55c8 1157 uint8_t ignoreCnt=ignoreWindow; //in case of noise near peak
e0165dcf 1158 //loop to find first wave that works - align to clock
1159 for (iii=0; iii < gLen; ++iii){
1160 if ((dest[iii]>=high) || (dest[iii]<=low)){
1161 if (dest[iii]>=high) firstPeakHigh=1;
1162 else firstPeakHigh=0;
1163 lastBit=iii-*clk;
1164 peakCnt=0;
1165 errCnt=0;
e0165dcf 1166 //loop through to see if this start location works
1167 for (i = iii; i < *size; ++i) {
2eec55c8 1168 // if we are at a clock bit
1169 if ((i >= lastBit + *clk - tol) && (i <= lastBit + *clk + tol)) {
1170 //test high/low
1171 if (dest[i] >= high || dest[i] <= low) {
1172 bitHigh = 1;
1173 peakCnt++;
1174 errBitHigh = 0;
1175 ignoreCnt = ignoreWindow;
1176 lastBit += *clk;
1177 } else if (i == lastBit + *clk + tol) {
1178 lastBit += *clk;
1179 }
e0165dcf 1180 //else if no bars found
2eec55c8 1181 } else if (dest[i] < high && dest[i] > low){
e0165dcf 1182 if (ignoreCnt==0){
1183 bitHigh=0;
2eec55c8 1184 if (errBitHigh==1) errCnt++;
e0165dcf 1185 errBitHigh=0;
1186 } else {
1187 ignoreCnt--;
1188 }
2eec55c8 1189 } else if ((dest[i]>=high || dest[i]<=low) && (bitHigh==0)) {
e0165dcf 1190 //error bar found no clock...
1191 errBitHigh=1;
1192 }
2eec55c8 1193 if (((i-iii) / *clk)>=MaxBits) break;
e0165dcf 1194 }
1195 //we got more than 64 good bits and not all errors
2eec55c8 1196 if (((i-iii) / *clk) > 64 && (errCnt <= (maxErr))) {
e0165dcf 1197 //possible good read
2eec55c8 1198 if (!errCnt || peakCnt > bestPeakCnt){
e0165dcf 1199 bestFirstPeakHigh=firstPeakHigh;
1200 bestErrCnt = errCnt;
1201 bestPeakCnt = peakCnt;
1202 bestPeakStart = iii;
2eec55c8 1203 if (!errCnt) break; //great read - finish
e0165dcf 1204 }
e0165dcf 1205 }
1206 }
1207 }
1208 //PrintAndLog("DEBUG: bestErrCnt: %d, maxErr: %d, bestStart: %d, bestPeakCnt: %d, bestPeakStart: %d",bestErrCnt,maxErr,bestStart,bestPeakCnt,bestPeakStart);
2eec55c8 1209 if (bestErrCnt > maxErr) return bestErrCnt;
1210
1211 //best run is good enough set to best run and set overwrite BinStream
1212 lastBit = bestPeakStart - *clk;
1213 memset(dest, bestFirstPeakHigh^1, bestPeakStart / *clk);
1214 bitnum += (bestPeakStart / *clk);
1215 for (i = bestPeakStart; i < *size; ++i) {
1216 // if expecting a clock bit
1217 if ((i >= lastBit + *clk - tol) && (i <= lastBit + *clk + tol)) {
1218 // test high/low
1219 if (dest[i] >= high || dest[i] <= low) {
1220 peakCnt++;
1221 bitHigh = 1;
1222 errBitHigh = 0;
1223 ignoreCnt = ignoreWindow;
1224 curBit = *invert;
1225 if (dest[i] >= high) curBit ^= 1;
1226 dest[bitnum++] = curBit;
1227 lastBit += *clk;
1228 //else no bars found in clock area
1229 } else if (i == lastBit + *clk + tol) {
1230 dest[bitnum++] = curBit;
1231 lastBit += *clk;
1232 }
1233 //else if no bars found
1234 } else if (dest[i] < high && dest[i] > low){
1235 if (ignoreCnt == 0){
1236 bitHigh = 0;
1237 if (errBitHigh == 1){
2767fc02 1238 dest[bitnum++] = 7;
2eec55c8 1239 errCnt++;
e0165dcf 1240 }
2eec55c8 1241 errBitHigh=0;
1242 } else {
1243 ignoreCnt--;
e0165dcf 1244 }
2eec55c8 1245 } else if ((dest[i] >= high || dest[i] <= low) && (bitHigh == 0)) {
1246 //error bar found no clock...
1247 errBitHigh=1;
e0165dcf 1248 }
2eec55c8 1249 if (bitnum >= MaxBits) break;
e0165dcf 1250 }
2eec55c8 1251 *size = bitnum;
1252 return bestErrCnt;
ba1a299c 1253}
1254
1e090a61 1255//by marshmellow
03e6bb4a 1256//detects the bit clock for FSK given the high and low Field Clocks
1257uint8_t detectFSKClk(uint8_t *BitStream, size_t size, uint8_t fcHigh, uint8_t fcLow)
1e090a61 1258{
e0165dcf 1259 uint8_t clk[] = {8,16,32,40,50,64,100,128,0};
1260 uint16_t rfLens[] = {0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0};
1261 uint8_t rfCnts[] = {0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0};
1262 uint8_t rfLensFnd = 0;
2eec55c8 1263 uint8_t lastFCcnt = 0;
1264 uint16_t fcCounter = 0;
e0165dcf 1265 uint16_t rfCounter = 0;
1266 uint8_t firstBitFnd = 0;
1267 size_t i;
1268 if (size == 0) return 0;
1269
1270 uint8_t fcTol = (uint8_t)(0.5+(float)(fcHigh-fcLow)/2);
1271 rfLensFnd=0;
1272 fcCounter=0;
1273 rfCounter=0;
1274 firstBitFnd=0;
1275 //PrintAndLog("DEBUG: fcTol: %d",fcTol);
1276 // prime i to first up transition
1277 for (i = 1; i < size-1; i++)
1278 if (BitStream[i] > BitStream[i-1] && BitStream[i]>=BitStream[i+1])
1279 break;
1280
1281 for (; i < size-1; i++){
2eec55c8 1282 fcCounter++;
1283 rfCounter++;
1284
1285 if (BitStream[i] <= BitStream[i-1] || BitStream[i] < BitStream[i+1])
1286 continue;
1287 // else new peak
1288 // if we got less than the small fc + tolerance then set it to the small fc
1289 if (fcCounter < fcLow+fcTol)
1290 fcCounter = fcLow;
1291 else //set it to the large fc
1292 fcCounter = fcHigh;
1293
1294 //look for bit clock (rf/xx)
1295 if ((fcCounter < lastFCcnt || fcCounter > lastFCcnt)){
1296 //not the same size as the last wave - start of new bit sequence
1297 if (firstBitFnd > 1){ //skip first wave change - probably not a complete bit
1298 for (int ii=0; ii<15; ii++){
1299 if (rfLens[ii] == rfCounter){
1300 rfCnts[ii]++;
1301 rfCounter = 0;
1302 break;
e0165dcf 1303 }
e0165dcf 1304 }
2eec55c8 1305 if (rfCounter > 0 && rfLensFnd < 15){
1306 //PrintAndLog("DEBUG: rfCntr %d, fcCntr %d",rfCounter,fcCounter);
1307 rfCnts[rfLensFnd]++;
1308 rfLens[rfLensFnd++] = rfCounter;
1309 }
1310 } else {
1311 firstBitFnd++;
e0165dcf 1312 }
2eec55c8 1313 rfCounter=0;
1314 lastFCcnt=fcCounter;
e0165dcf 1315 }
2eec55c8 1316 fcCounter=0;
e0165dcf 1317 }
1318 uint8_t rfHighest=15, rfHighest2=15, rfHighest3=15;
1319
1320 for (i=0; i<15; i++){
1321 //PrintAndLog("DEBUG: RF %d, cnts %d",rfLens[i], rfCnts[i]);
1322 //get highest 2 RF values (might need to get more values to compare or compare all?)
1323 if (rfCnts[i]>rfCnts[rfHighest]){
1324 rfHighest3=rfHighest2;
1325 rfHighest2=rfHighest;
1326 rfHighest=i;
1327 } else if(rfCnts[i]>rfCnts[rfHighest2]){
1328 rfHighest3=rfHighest2;
1329 rfHighest2=i;
1330 } else if(rfCnts[i]>rfCnts[rfHighest3]){
1331 rfHighest3=i;
1332 }
1333 }
1334 // set allowed clock remainder tolerance to be 1 large field clock length+1
1335 // we could have mistakenly made a 9 a 10 instead of an 8 or visa versa so rfLens could be 1 FC off
1336 uint8_t tol1 = fcHigh+1;
1337
1338 //PrintAndLog("DEBUG: hightest: 1 %d, 2 %d, 3 %d",rfLens[rfHighest],rfLens[rfHighest2],rfLens[rfHighest3]);
1339
1340 // loop to find the highest clock that has a remainder less than the tolerance
1341 // compare samples counted divided by
1342 int ii=7;
1343 for (; ii>=0; ii--){
1344 if (rfLens[rfHighest] % clk[ii] < tol1 || rfLens[rfHighest] % clk[ii] > clk[ii]-tol1){
1345 if (rfLens[rfHighest2] % clk[ii] < tol1 || rfLens[rfHighest2] % clk[ii] > clk[ii]-tol1){
1346 if (rfLens[rfHighest3] % clk[ii] < tol1 || rfLens[rfHighest3] % clk[ii] > clk[ii]-tol1){
1347 break;
1348 }
1349 }
1350 }
1351 }
1352
1353 if (ii<0) return 0; // oops we went too far
1354
1355 return clk[ii];
03e6bb4a 1356}
1e090a61 1357
03e6bb4a 1358//by marshmellow
1359//countFC is to detect the field clock lengths.
1360//counts and returns the 2 most common wave lengths
6de43508 1361//mainly used for FSK field clock detection
2eec55c8 1362uint16_t countFC(uint8_t *BitStream, size_t size, uint8_t fskAdj)
03e6bb4a 1363{
e0165dcf 1364 uint8_t fcLens[] = {0,0,0,0,0,0,0,0,0,0};
1365 uint16_t fcCnts[] = {0,0,0,0,0,0,0,0,0,0};
1366 uint8_t fcLensFnd = 0;
1367 uint8_t lastFCcnt=0;
2eec55c8 1368 uint8_t fcCounter = 0;
e0165dcf 1369 size_t i;
1370 if (size == 0) return 0;
1371
1372 // prime i to first up transition
1373 for (i = 1; i < size-1; i++)
1374 if (BitStream[i] > BitStream[i-1] && BitStream[i] >= BitStream[i+1])
1375 break;
1376
1377 for (; i < size-1; i++){
1378 if (BitStream[i] > BitStream[i-1] && BitStream[i] >= BitStream[i+1]){
1379 // new up transition
1380 fcCounter++;
2eec55c8 1381 if (fskAdj){
1382 //if we had 5 and now have 9 then go back to 8 (for when we get a fc 9 instead of an 8)
1383 if (lastFCcnt==5 && fcCounter==9) fcCounter--;
1384 //if fc=9 or 4 add one (for when we get a fc 9 instead of 10 or a 4 instead of a 5)
1385 if ((fcCounter==9) || fcCounter==4) fcCounter++;
e0165dcf 1386 // save last field clock count (fc/xx)
2eec55c8 1387 lastFCcnt = fcCounter;
1388 }
e0165dcf 1389 // find which fcLens to save it to:
1390 for (int ii=0; ii<10; ii++){
1391 if (fcLens[ii]==fcCounter){
1392 fcCnts[ii]++;
1393 fcCounter=0;
1394 break;
1395 }
1396 }
1397 if (fcCounter>0 && fcLensFnd<10){
1398 //add new fc length
1399 fcCnts[fcLensFnd]++;
1400 fcLens[fcLensFnd++]=fcCounter;
1401 }
1402 fcCounter=0;
1403 } else {
1404 // count sample
1405 fcCounter++;
1406 }
1407 }
1408
1409 uint8_t best1=9, best2=9, best3=9;
1410 uint16_t maxCnt1=0;
1411 // go through fclens and find which ones are bigest 2
1412 for (i=0; i<10; i++){
1413 // PrintAndLog("DEBUG: FC %d, Cnt %d, Errs %d",fcLens[i],fcCnts[i],errCnt);
1414 // get the 3 best FC values
1415 if (fcCnts[i]>maxCnt1) {
1416 best3=best2;
1417 best2=best1;
1418 maxCnt1=fcCnts[i];
1419 best1=i;
1420 } else if(fcCnts[i]>fcCnts[best2]){
1421 best3=best2;
1422 best2=i;
1423 } else if(fcCnts[i]>fcCnts[best3]){
1424 best3=i;
1425 }
1426 }
1427 uint8_t fcH=0, fcL=0;
1428 if (fcLens[best1]>fcLens[best2]){
1429 fcH=fcLens[best1];
1430 fcL=fcLens[best2];
1431 } else{
1432 fcH=fcLens[best2];
1433 fcL=fcLens[best1];
1434 }
1435
e0165dcf 1436 // TODO: take top 3 answers and compare to known Field clocks to get top 2
1437
1438 uint16_t fcs = (((uint16_t)fcH)<<8) | fcL;
1439 // PrintAndLog("DEBUG: Best %d best2 %d best3 %d",fcLens[best1],fcLens[best2],fcLens[best3]);
2eec55c8 1440 if (fskAdj) return fcs;
1441 return fcLens[best1];
6de43508 1442}
1443
1444//by marshmellow - demodulate PSK1 wave
1445//uses wave lengths (# Samples)
1446int pskRawDemod(uint8_t dest[], size_t *size, int *clock, int *invert)
1447{
e0165dcf 1448 if (size == 0) return -1;
2eec55c8 1449 uint16_t loopCnt = 4096; //don't need to loop through entire array...
e0165dcf 1450 if (*size<loopCnt) loopCnt = *size;
1451
1452 uint8_t curPhase = *invert;
1453 size_t i, waveStart=1, waveEnd=0, firstFullWave=0, lastClkBit=0;
1454 uint8_t fc=0, fullWaveLen=0, tol=1;
1455 uint16_t errCnt=0, waveLenCnt=0;
2eec55c8 1456 fc = countFC(dest, *size, 0);
e0165dcf 1457 if (fc!=2 && fc!=4 && fc!=8) return -1;
1458 //PrintAndLog("DEBUG: FC: %d",fc);
1459 *clock = DetectPSKClock(dest, *size, *clock);
2eec55c8 1460 if (*clock == 0) return -1;
e0165dcf 1461 int avgWaveVal=0, lastAvgWaveVal=0;
1462 //find first phase shift
1463 for (i=0; i<loopCnt; i++){
1464 if (dest[i]+fc < dest[i+1] && dest[i+1] >= dest[i+2]){
1465 waveEnd = i+1;
1466 //PrintAndLog("DEBUG: waveEnd: %d",waveEnd);
1467 waveLenCnt = waveEnd-waveStart;
1468 if (waveLenCnt > fc && waveStart > fc){ //not first peak and is a large wave
1469 lastAvgWaveVal = avgWaveVal/(waveLenCnt);
1470 firstFullWave = waveStart;
1471 fullWaveLen=waveLenCnt;
1472 //if average wave value is > graph 0 then it is an up wave or a 1
2eec55c8 1473 if (lastAvgWaveVal > 123) curPhase ^= 1; //fudge graph 0 a little 123 vs 128
e0165dcf 1474 break;
1475 }
1476 waveStart = i+1;
1477 avgWaveVal = 0;
1478 }
2eec55c8 1479 avgWaveVal += dest[i+2];
e0165dcf 1480 }
1481 //PrintAndLog("DEBUG: firstFullWave: %d, waveLen: %d",firstFullWave,fullWaveLen);
1482 lastClkBit = firstFullWave; //set start of wave as clock align
1483 //PrintAndLog("DEBUG: clk: %d, lastClkBit: %d", *clock, lastClkBit);
1484 waveStart = 0;
e0165dcf 1485 size_t numBits=0;
1486 //set skipped bits
2eec55c8 1487 memset(dest, curPhase^1, firstFullWave / *clock);
e0165dcf 1488 numBits += (firstFullWave / *clock);
1489 dest[numBits++] = curPhase; //set first read bit
2eec55c8 1490 for (i = firstFullWave + fullWaveLen - 1; i < *size-3; i++){
e0165dcf 1491 //top edge of wave = start of new wave
1492 if (dest[i]+fc < dest[i+1] && dest[i+1] >= dest[i+2]){
1493 if (waveStart == 0) {
1494 waveStart = i+1;
2eec55c8 1495 waveLenCnt = 0;
e0165dcf 1496 avgWaveVal = dest[i+1];
1497 } else { //waveEnd
1498 waveEnd = i+1;
1499 waveLenCnt = waveEnd-waveStart;
1500 lastAvgWaveVal = avgWaveVal/waveLenCnt;
1501 if (waveLenCnt > fc){
1502 //PrintAndLog("DEBUG: avgWaveVal: %d, waveSum: %d",lastAvgWaveVal,avgWaveVal);
2eec55c8 1503 //this wave is a phase shift
e0165dcf 1504 //PrintAndLog("DEBUG: phase shift at: %d, len: %d, nextClk: %d, i: %d, fc: %d",waveStart,waveLenCnt,lastClkBit+*clock-tol,i+1,fc);
1505 if (i+1 >= lastClkBit + *clock - tol){ //should be a clock bit
2eec55c8 1506 curPhase ^= 1;
e0165dcf 1507 dest[numBits++] = curPhase;
1508 lastClkBit += *clock;
2eec55c8 1509 } else if (i < lastClkBit+10+fc){
e0165dcf 1510 //noise after a phase shift - ignore
1511 } else { //phase shift before supposed to based on clock
1512 errCnt++;
2767fc02 1513 dest[numBits++] = 7;
e0165dcf 1514 }
1515 } else if (i+1 > lastClkBit + *clock + tol + fc){
1516 lastClkBit += *clock; //no phase shift but clock bit
1517 dest[numBits++] = curPhase;
1518 }
2eec55c8 1519 avgWaveVal = 0;
1520 waveStart = i+1;
e0165dcf 1521 }
1522 }
2eec55c8 1523 avgWaveVal += dest[i+1];
e0165dcf 1524 }
1525 *size = numBits;
1526 return errCnt;
6de43508 1527}
Impressum, Datenschutz