1 //-----------------------------------------------------------------------------
3 // This code is licensed to you under the terms of the GNU GPL, version 2 or,
4 // at your option, any later version. See the LICENSE.txt file for the text of
6 //-----------------------------------------------------------------------------
7 // Low frequency Noralsy tag commands
8 // ASK/Manchester, STT, RF/32, 96 bits long (some bits unknown)
9 //-----------------------------------------------------------------------------
11 #include "cmdlfnoralsy.h"
20 #include "cmdparser.h"
24 #include "protocols.h" // for T55xx config register definitions
25 #include "lfdemod.h" // parityTest
27 static int CmdHelp(const char *Cmd
);
29 int usage_lf_noralsy_clone(void){
30 PrintAndLog("clone a Noralsy tag to a T55x7 tag.");
31 PrintAndLog("Usage: lf noralsy clone [h] <card id> <year> <Q5>");
32 PrintAndLog("Options:");
33 PrintAndLog(" h : This help");
34 PrintAndLog(" <card id> : Noralsy card ID");
35 PrintAndLog(" <year> : Tag allocation year");
36 PrintAndLog(" <Q5> : specify write to Q5 (t5555 instead of t55x7)");
38 PrintAndLog("Sample: lf noralsy clone 112233");
42 int usage_lf_noralsy_sim(void) {
43 PrintAndLog("Enables simulation of Noralsy card with specified card number.");
44 PrintAndLog("Simulation runs until the button is pressed or another USB command is issued.");
46 PrintAndLog("Usage: lf noralsy sim [h] <card id> <year>");
47 PrintAndLog("Options:");
48 PrintAndLog(" h : This help");
49 PrintAndLog(" <card id> : Noralsy card ID");
50 PrintAndLog(" <year> : Tag allocation year");
52 PrintAndLog("Sample: lf noralsy sim 112233");
56 static uint8_t noralsy_chksum( uint8_t* bits
, uint8_t len
) {
58 for (uint8_t i
= 0; i
< len
; i
+= 4)
59 sum
^= bytebits_to_byte(bits
+i
, 4);
62 int getnoralsyBits(uint32_t id
, uint16_t year
, uint8_t *bits
) {
64 num_to_bytebits(0xBB0214FF, 32, bits
); // --> Have seen 0xBB0214FF / 0xBB0314FF UNKNOWN
68 uint16_t sub1
= (id
& 0xFFF0000) >> 16;
69 uint8_t sub2
= (id
& 0x000FF00) >> 8;
70 uint8_t sub3
= (id
& 0x00000FF);
72 num_to_bytebits(sub1
, 12, bits
+32);
73 num_to_bytebits(year
, 8, bits
+44);
74 num_to_bytebits(0, 4, bits
+52); // --> UNKNOWN. Flag?
76 num_to_bytebits(sub2
, 8, bits
+56);
77 num_to_bytebits(sub3
, 8, bits
+64);
80 uint8_t chksum
= noralsy_chksum(bits
+32, 40);
81 num_to_bytebits(chksum
, 4, bits
+72);
82 chksum
= noralsy_chksum(bits
, 76);
83 num_to_bytebits(chksum
, 4, bits
+76);
88 // find Noralsy preamble in already demoded data
89 int NoralsyDemod_AM(uint8_t *dest
, size_t *size
) {
90 if (*size
< 96) return -1; //make sure buffer has data
92 uint8_t preamble
[] = {1,0,1,1,1,0,1,1,0,0,0,0};
93 if (!preambleSearch(dest
, preamble
, sizeof(preamble
), size
, &startIdx
))
94 return -2; //preamble not found
95 if (*size
!= 96) return -3; //wrong demoded size
96 //return start position
102 * 2520116 | BB0214FF2529900116360000 | 10111011 00000011 00010100 11111111 00100101 00101001 10010000 00000001 00010110 00110110 00000000 00000000
103 * aaa*aaaaiiiYY*iiiicc---- **** iiiiiiii iiiiYYYY YYYY**** iiiiiiii iiiiiiii cccccccc
105 * a = fixed value BB0*14FF
106 * i = printed id, BCD-format
113 //see ASKDemod for what args are accepted
114 int CmdNoralsyDemod(const char *Cmd
) {
118 if (!ASKDemod_ext("32 0 0", false, false, 1, &st
)) {
119 if (g_debugMode
) PrintAndLog("DEBUG: Error - Noralsy: ASK/Manchester Demod failed");
124 size_t size
= DemodBufferLen
;
125 int ans
= NoralsyDemod_AM(DemodBuffer
, &size
);
129 PrintAndLog("DEBUG: Error - Noralsy: too few bits found");
131 PrintAndLog("DEBUG: Error - Noralsy: preamble not found");
133 PrintAndLog("DEBUG: Error - Noralsy: Size not correct: %d", size
);
135 PrintAndLog("DEBUG: Error - Noralsy: ans: %d", ans
);
139 setDemodBuf(DemodBuffer
, 96, ans
);
140 setClockGrid(g_DemodClock
, g_DemodStartIdx
+ (ans
*g_DemodClock
));
144 uint32_t raw1
= bytebits_to_byte(DemodBuffer
, 32);
145 uint32_t raw2
= bytebits_to_byte(DemodBuffer
+32, 32);
146 uint32_t raw3
= bytebits_to_byte(DemodBuffer
+64, 32);
148 uint32_t cardid
= (bytebits_to_byte(DemodBuffer
+32, 12)<<16) | bytebits_to_byte(DemodBuffer
+32+24, 16);
150 uint16_t year
= (raw2
& 0x000ff000) >> 12;
151 year
+= ( year
> 0x60 ) ? 0x1900: 0x2000;
154 uint8_t calc1
= noralsy_chksum(DemodBuffer
+32, 40);
155 uint8_t calc2
= noralsy_chksum(DemodBuffer
, 76);
156 uint8_t chk1
= 0, chk2
= 0;
157 chk1
= bytebits_to_byte(DemodBuffer
+72, 4);
158 chk2
= bytebits_to_byte(DemodBuffer
+76, 4);
160 if ( chk1
!= calc1
) {
161 if (g_debugMode
) PrintAndLog("DEBUG: Error - Noralsy: checksum 1 failed %x - %x\n", chk1
, calc1
);
164 if ( chk2
!= calc2
) {
165 if (g_debugMode
) PrintAndLog("DEBUG: Error - Noralsy: checksum 2 failed %x - %x\n", chk2
, calc2
);
169 PrintAndLog("Noralsy Tag Found: Card ID %X, Year: %X Raw: %08X%08X%08X", cardid
, year
, raw1
,raw2
, raw3
);
170 if (raw1
!= 0xBB0214FF) {
171 PrintAndLog("Unknown bits set in first block! Expected 0xBB0214FF, Found: 0x%08X", raw1
);
172 PrintAndLog("Please post this output in forum to further research on this format");
177 int CmdNoralsyRead(const char *Cmd
) {
179 return CmdNoralsyDemod(Cmd
);
182 int CmdNoralsyClone(const char *Cmd
) {
186 uint32_t blocks
[4] = {T55x7_MODULATION_MANCHESTER
| T55x7_BITRATE_RF_32
| T55x7_ST_TERMINATOR
| 3 << T55x7_MAXBLOCK_SHIFT
, 0, 0};
189 memset(bs
, 0, sizeof(bits
));
191 char cmdp
= param_getchar(Cmd
, 0);
192 if (strlen(Cmd
) == 0 || cmdp
== 'h' || cmdp
== 'H') return usage_lf_noralsy_clone();
194 id
= param_get32ex(Cmd
, 0, 0, 16);
195 year
= param_get32ex(Cmd
, 1, 2000, 16);
198 if (param_getchar(Cmd
, 2) == 'Q' || param_getchar(Cmd
, 2) == 'q') {
199 //t5555 (Q5) BITRATE = (RF-2)/2 (iceman)
200 blocks
[0] = T5555_MODULATION_MANCHESTER
| ((32-2)>>1) << T5555_BITRATE_SHIFT
| T5555_ST_TERMINATOR
| 3 << T5555_MAXBLOCK_SHIFT
;
203 if ( !getnoralsyBits(id
, year
, bs
)) {
204 PrintAndLog("Error with tag bitstream generation.");
209 blocks
[1] = bytebits_to_byte(bs
,32);
210 blocks
[2] = bytebits_to_byte(bs
+32,32);
211 blocks
[3] = bytebits_to_byte(bs
+64,32);
213 PrintAndLog("Preparing to clone Noralsy to T55x7 with CardId: %x", id
);
214 PrintAndLog("Blk | Data ");
215 PrintAndLog("----+------------");
216 PrintAndLog(" 00 | 0x%08x", blocks
[0]);
217 PrintAndLog(" 01 | 0x%08x", blocks
[1]);
218 PrintAndLog(" 02 | 0x%08x", blocks
[2]);
219 PrintAndLog(" 03 | 0x%08x", blocks
[3]);
222 UsbCommand c
= {CMD_T55XX_WRITE_BLOCK
, {0,0,0}};
224 for (int i
= 3; i
>= 0; --i
) {
225 c
.arg
[0] = blocks
[i
];
227 clearCommandBuffer();
229 if (!WaitForResponseTimeout(CMD_ACK
, &resp
, T55XX_WRITE_TIMEOUT
)){
230 PrintAndLog("Error occurred, device did not respond during write operation.");
237 int CmdNoralsySim(const char *Cmd
) {
241 memset(bs
, 0, sizeof(bits
));
246 char cmdp
= param_getchar(Cmd
, 0);
247 if (strlen(Cmd
) == 0 || cmdp
== 'h' || cmdp
== 'H') return usage_lf_noralsy_sim();
249 id
= param_get32ex(Cmd
, 0, 0, 16);
250 year
= param_get32ex(Cmd
, 1, 2000, 16);
252 uint8_t clk
= 32, encoding
= 1, separator
= 1, invert
= 0;
255 arg1
= clk
<< 8 | encoding
;
256 arg2
= invert
<< 8 | separator
;
258 if ( !getnoralsyBits(id
, year
, bs
)) {
259 PrintAndLog("Error with tag bitstream generation.");
263 PrintAndLog("Simulating Noralsy - CardId: %x", id
);
265 UsbCommand c
= {CMD_ASK_SIM_TAG
, {arg1
, arg2
, size
}};
266 memcpy(c
.d
.asBytes
, bs
, size
);
267 clearCommandBuffer();
272 static command_t CommandTable
[] = {
273 {"help", CmdHelp
, 1, "This help"},
274 {"demod", CmdNoralsyDemod
,1, "Attempt to read and extract tag data from the GraphBuffer"},
275 {"read", CmdNoralsyRead
, 0, "Attempt to read and extract tag data from the antenna"},
276 {"clone", CmdNoralsyClone
,0, "clone Noralsy tag"},
277 {"sim", CmdNoralsySim
, 0, "simulate Noralsy tag"},
278 {NULL
, NULL
, 0, NULL
}
281 int CmdLFNoralsy(const char *Cmd
) {
282 clearCommandBuffer();
283 CmdsParse(CommandTable
, Cmd
);
287 int CmdHelp(const char *Cmd
) {
288 CmdsHelp(CommandTable
);