1 | #include "globals.h"
|
---|
2 | #include "reader-common.h"
|
---|
3 |
|
---|
4 | #ifdef HAVE_AES
|
---|
5 | typedef unsigned long u32;
|
---|
6 | #endif
|
---|
7 |
|
---|
8 | extern uchar cta_cmd[], cta_res[];
|
---|
9 | extern ushort cta_lr;
|
---|
10 |
|
---|
11 | #define CMD_LEN 5
|
---|
12 |
|
---|
13 | static unsigned char nds_Seed[] = {
|
---|
14 | 0x56, 0x01, 0x40, 0x00, 0x20, 0x00,
|
---|
15 | 0xB9, 0xD5, 0xEF, 0xD5, 0xF5, 0xD5, 0xFB, 0xD5, 0x31, 0xD6, 0x43, 0xD6, 0x55, 0xD6, 0x61, 0xD6, 0x85, 0xD6, 0x9D,
|
---|
16 | 0xD6, 0xAF, 0xD6, 0xC7, 0xD6, 0xD9, 0xD6, 0x09, 0xD7, 0x15, 0xD7, 0x21, 0xD7, 0x27, 0xD7, 0x3F, 0xD7, 0x45, 0xD7,
|
---|
17 | 0xB1, 0xD7, 0xBD, 0xD7, 0xDB, 0xD7, 0x11, 0xD8, 0x23, 0xD8, 0x29, 0xD8, 0x2F, 0xD8, 0x4D, 0xD8, 0x8F, 0xD8, 0xA1,
|
---|
18 | 0xD8, 0xAD, 0xD8, 0xBF, 0xD8, 0xD7, 0xD8,
|
---|
19 | 0x01, 0x00, 0xCF, 0x13, 0xE0, 0x60, 0x54, 0xAC, 0xAB, 0x99, 0xE6, 0x0C, 0x9F, 0x5B, 0x91, 0xB9, 0x72, 0x72, 0x4D,
|
---|
20 | 0x5B, 0x5F, 0xD3, 0xB7, 0x5B, 0x01, 0x4D, 0xEF, 0x9E, 0x6B, 0x8A, 0xB9, 0xD1, 0xC9, 0x9F, 0xA1, 0x2A, 0x8D, 0x86,
|
---|
21 | 0xB6, 0xD6, 0x39, 0xB4, 0x64, 0x65, 0x13, 0x77, 0xA1, 0x0A, 0x0C, 0xCF, 0xB4, 0x2B, 0x3A, 0x2F, 0xD2, 0x09, 0x92,
|
---|
22 | 0x15, 0x40, 0x47, 0x66, 0x5C, 0xDA, 0xC9
|
---|
23 | };
|
---|
24 |
|
---|
25 | static const u32 Te4[256] = {
|
---|
26 | 0x63636363U, 0x7c7c7c7cU, 0x77777777U, 0x7b7b7b7bU,
|
---|
27 | 0xf2f2f2f2U, 0x6b6b6b6bU, 0x6f6f6f6fU, 0xc5c5c5c5U,
|
---|
28 | 0x30303030U, 0x01010101U, 0x67676767U, 0x2b2b2b2bU,
|
---|
29 | 0xfefefefeU, 0xd7d7d7d7U, 0xababababU, 0x76767676U,
|
---|
30 | 0xcacacacaU, 0x82828282U, 0xc9c9c9c9U, 0x7d7d7d7dU,
|
---|
31 | 0xfafafafaU, 0x59595959U, 0x47474747U, 0xf0f0f0f0U,
|
---|
32 | 0xadadadadU, 0xd4d4d4d4U, 0xa2a2a2a2U, 0xafafafafU,
|
---|
33 | 0x9c9c9c9cU, 0xa4a4a4a4U, 0x72727272U, 0xc0c0c0c0U,
|
---|
34 | 0xb7b7b7b7U, 0xfdfdfdfdU, 0x93939393U, 0x26262626U,
|
---|
35 | 0x36363636U, 0x3f3f3f3fU, 0xf7f7f7f7U, 0xccccccccU,
|
---|
36 | 0x34343434U, 0xa5a5a5a5U, 0xe5e5e5e5U, 0xf1f1f1f1U,
|
---|
37 | 0x71717171U, 0xd8d8d8d8U, 0x31313131U, 0x15151515U,
|
---|
38 | 0x04040404U, 0xc7c7c7c7U, 0x23232323U, 0xc3c3c3c3U,
|
---|
39 | 0x18181818U, 0x96969696U, 0x05050505U, 0x9a9a9a9aU,
|
---|
40 | 0x07070707U, 0x12121212U, 0x80808080U, 0xe2e2e2e2U,
|
---|
41 | 0xebebebebU, 0x27272727U, 0xb2b2b2b2U, 0x75757575U,
|
---|
42 | 0x09090909U, 0x83838383U, 0x2c2c2c2cU, 0x1a1a1a1aU,
|
---|
43 | 0x1b1b1b1bU, 0x6e6e6e6eU, 0x5a5a5a5aU, 0xa0a0a0a0U,
|
---|
44 | 0x52525252U, 0x3b3b3b3bU, 0xd6d6d6d6U, 0xb3b3b3b3U,
|
---|
45 | 0x29292929U, 0xe3e3e3e3U, 0x2f2f2f2fU, 0x84848484U,
|
---|
46 | 0x53535353U, 0xd1d1d1d1U, 0x00000000U, 0xededededU,
|
---|
47 | 0x20202020U, 0xfcfcfcfcU, 0xb1b1b1b1U, 0x5b5b5b5bU,
|
---|
48 | 0x6a6a6a6aU, 0xcbcbcbcbU, 0xbebebebeU, 0x39393939U,
|
---|
49 | 0x4a4a4a4aU, 0x4c4c4c4cU, 0x58585858U, 0xcfcfcfcfU,
|
---|
50 | 0xd0d0d0d0U, 0xefefefefU, 0xaaaaaaaaU, 0xfbfbfbfbU,
|
---|
51 | 0x43434343U, 0x4d4d4d4dU, 0x33333333U, 0x85858585U,
|
---|
52 | 0x45454545U, 0xf9f9f9f9U, 0x02020202U, 0x7f7f7f7fU,
|
---|
53 | 0x50505050U, 0x3c3c3c3cU, 0x9f9f9f9fU, 0xa8a8a8a8U,
|
---|
54 | 0x51515151U, 0xa3a3a3a3U, 0x40404040U, 0x8f8f8f8fU,
|
---|
55 | 0x92929292U, 0x9d9d9d9dU, 0x38383838U, 0xf5f5f5f5U,
|
---|
56 | 0xbcbcbcbcU, 0xb6b6b6b6U, 0xdadadadaU, 0x21212121U,
|
---|
57 | 0x10101010U, 0xffffffffU, 0xf3f3f3f3U, 0xd2d2d2d2U,
|
---|
58 | 0xcdcdcdcdU, 0x0c0c0c0cU, 0x13131313U, 0xececececU,
|
---|
59 | 0x5f5f5f5fU, 0x97979797U, 0x44444444U, 0x17171717U,
|
---|
60 | 0xc4c4c4c4U, 0xa7a7a7a7U, 0x7e7e7e7eU, 0x3d3d3d3dU,
|
---|
61 | 0x64646464U, 0x5d5d5d5dU, 0x19191919U, 0x73737373U,
|
---|
62 | 0x60606060U, 0x81818181U, 0x4f4f4f4fU, 0xdcdcdcdcU,
|
---|
63 | 0x22222222U, 0x2a2a2a2aU, 0x90909090U, 0x88888888U,
|
---|
64 | 0x46464646U, 0xeeeeeeeeU, 0xb8b8b8b8U, 0x14141414U,
|
---|
65 | 0xdedededeU, 0x5e5e5e5eU, 0x0b0b0b0bU, 0xdbdbdbdbU,
|
---|
66 | 0xe0e0e0e0U, 0x32323232U, 0x3a3a3a3aU, 0x0a0a0a0aU,
|
---|
67 | 0x49494949U, 0x06060606U, 0x24242424U, 0x5c5c5c5cU,
|
---|
68 | 0xc2c2c2c2U, 0xd3d3d3d3U, 0xacacacacU, 0x62626262U,
|
---|
69 | 0x91919191U, 0x95959595U, 0xe4e4e4e4U, 0x79797979U,
|
---|
70 | 0xe7e7e7e7U, 0xc8c8c8c8U, 0x37373737U, 0x6d6d6d6dU,
|
---|
71 | 0x8d8d8d8dU, 0xd5d5d5d5U, 0x4e4e4e4eU, 0xa9a9a9a9U,
|
---|
72 | 0x6c6c6c6cU, 0x56565656U, 0xf4f4f4f4U, 0xeaeaeaeaU,
|
---|
73 | 0x65656565U, 0x7a7a7a7aU, 0xaeaeaeaeU, 0x08080808U,
|
---|
74 | 0xbabababaU, 0x78787878U, 0x25252525U, 0x2e2e2e2eU,
|
---|
75 | 0x1c1c1c1cU, 0xa6a6a6a6U, 0xb4b4b4b4U, 0xc6c6c6c6U,
|
---|
76 | 0xe8e8e8e8U, 0xddddddddU, 0x74747474U, 0x1f1f1f1fU,
|
---|
77 | 0x4b4b4b4bU, 0xbdbdbdbdU, 0x8b8b8b8bU, 0x8a8a8a8aU,
|
---|
78 | 0x70707070U, 0x3e3e3e3eU, 0xb5b5b5b5U, 0x66666666U,
|
---|
79 | 0x48484848U, 0x03030303U, 0xf6f6f6f6U, 0x0e0e0e0eU,
|
---|
80 | 0x61616161U, 0x35353535U, 0x57575757U, 0xb9b9b9b9U,
|
---|
81 | 0x86868686U, 0xc1c1c1c1U, 0x1d1d1d1dU, 0x9e9e9e9eU,
|
---|
82 | 0xe1e1e1e1U, 0xf8f8f8f8U, 0x98989898U, 0x11111111U,
|
---|
83 | 0x69696969U, 0xd9d9d9d9U, 0x8e8e8e8eU, 0x94949494U,
|
---|
84 | 0x9b9b9b9bU, 0x1e1e1e1eU, 0x87878787U, 0xe9e9e9e9U,
|
---|
85 | 0xcecececeU, 0x55555555U, 0x28282828U, 0xdfdfdfdfU,
|
---|
86 | 0x8c8c8c8cU, 0xa1a1a1a1U, 0x89898989U, 0x0d0d0d0dU,
|
---|
87 | 0xbfbfbfbfU, 0xe6e6e6e6U, 0x42424242U, 0x68686868U,
|
---|
88 | 0x41414141U, 0x99999999U, 0x2d2d2d2dU, 0x0f0f0f0fU,
|
---|
89 | 0xb0b0b0b0U, 0x54545454U, 0xbbbbbbbbU, 0x16161616U,
|
---|
90 | };
|
---|
91 |
|
---|
92 | static unsigned char d0_b4_00_00_40_Value[0x40];
|
---|
93 | static unsigned char oldHBuffer[0x10];
|
---|
94 | static unsigned char d0BCKey[0x10];
|
---|
95 | static unsigned char d3BEKey[0x10];
|
---|
96 |
|
---|
97 |
|
---|
98 | static void nSwap (unsigned char i_key[16], unsigned char o_key[16]);
|
---|
99 | static void nLookup (unsigned char i_key[16], unsigned char o_key[16]);
|
---|
100 |
|
---|
101 | static void xor16 (unsigned char i_val1[16], unsigned char i_val2[16], unsigned char o_val[16]);
|
---|
102 |
|
---|
103 | static void do_d0b4 (unsigned char *msgBody);
|
---|
104 | static void extractModule (unsigned char seedBuffer[0x86], unsigned char *outBuffer);
|
---|
105 | static void processD0BC (unsigned char exp_seedBuffer[0x86], unsigned char *outbuffer);
|
---|
106 | static void handle_d0_Class (unsigned char *msgFrmCard, unsigned char *msgBody, unsigned char *msgStatus);
|
---|
107 | static void handle_d1_Class (unsigned char *msgFrmCard, unsigned char *msgBody, unsigned char *msgStatus);
|
---|
108 | static void handle_d3_Class (unsigned char *msgFrmCard, unsigned char *msgBody, unsigned char *msgStatus);
|
---|
109 |
|
---|
110 | static unsigned char cw1[0x8];
|
---|
111 | static unsigned char cw2[0x8];
|
---|
112 |
|
---|
113 | static int ndsRouteClass (unsigned char *msgFrmCard, int msgFrmCardsize, unsigned char *cw1, unsigned char *cw2);
|
---|
114 | static void get_D0_B4_PublicModule (unsigned char *module);
|
---|
115 |
|
---|
116 | static int CommandSendCardCAM (unsigned char *command, char *answer);
|
---|
117 | static int CommandSendCAMCard (unsigned char *command, char *status, unsigned char *payload);
|
---|
118 |
|
---|
119 | static unsigned char nds_SC_UA[4] = { 0, 0, 0, 0 };
|
---|
120 |
|
---|
121 | static unsigned int nds_SC_CAID = 0x0900;
|
---|
122 | static unsigned char nds_IRD_BoxID[4] = { 0, 0, 0, 0 };
|
---|
123 |
|
---|
124 | static unsigned char nds_supportedIns[0xFF];
|
---|
125 | static unsigned char ndsCommand[0xFF];
|
---|
126 |
|
---|
127 | static unsigned char CardAnswer[0xFF];
|
---|
128 | static unsigned char d3BEKey[0x10];
|
---|
129 |
|
---|
130 | static AES_KEY aeskey;
|
---|
131 |
|
---|
132 | static void nds_aes_set_key (char *key)
|
---|
133 | {
|
---|
134 | AES_set_encrypt_key ((unsigned char *)key, 128, &aeskey);
|
---|
135 | }
|
---|
136 |
|
---|
137 | static int CommandSendCardCAM(unsigned char *command, char *answer_payload)
|
---|
138 | {
|
---|
139 | int insLenData = command[4];
|
---|
140 |
|
---|
141 | if (!reader_cmd2icc (command, CMD_LEN)) {
|
---|
142 | answer_payload[0] = command[1];
|
---|
143 | memcpy (&answer_payload[1], cta_res, insLenData);
|
---|
144 | return 0; //success
|
---|
145 | }
|
---|
146 | else
|
---|
147 | return -1;//error
|
---|
148 |
|
---|
149 | }
|
---|
150 |
|
---|
151 | static int CommandSendCAMCard (unsigned char *command, char *status, unsigned char *answer_payload)
|
---|
152 | {
|
---|
153 | int insLenData = command[4];
|
---|
154 | unsigned char tmpPayLoad[0xFF];
|
---|
155 |
|
---|
156 | memcpy (tmpPayLoad, command, 5);
|
---|
157 | memcpy (tmpPayLoad + 5, answer_payload, insLenData);
|
---|
158 |
|
---|
159 | if (!reader_cmd2icc (tmpPayLoad, CMD_LEN + insLenData)) {
|
---|
160 | memcpy (status, &cta_res[cta_lr - 2], 2);
|
---|
161 | }
|
---|
162 | else
|
---|
163 | return -1;
|
---|
164 |
|
---|
165 | return 0;
|
---|
166 | }
|
---|
167 |
|
---|
168 | static void nSwap (unsigned char i_val[16], unsigned char o_val[16])
|
---|
169 | {
|
---|
170 | int i, y, a = 0;
|
---|
171 | for (i = 0; i < 0x4; i++) {
|
---|
172 | for (y = 0; y < 0x4; y++) {
|
---|
173 | o_val[a] = i_val[(y * 4) + i];
|
---|
174 | a++;
|
---|
175 | }
|
---|
176 | }
|
---|
177 | }
|
---|
178 |
|
---|
179 | static void nLookup (unsigned char i_key[16], unsigned char o_key[16])
|
---|
180 | {
|
---|
181 | int i;
|
---|
182 | unsigned char flg, lastVal;
|
---|
183 |
|
---|
184 | flg = (i_key[0xF] % 2) << 7;
|
---|
185 | for (i = 0; i < 0x10; i++) {
|
---|
186 | lastVal = i_key[i];
|
---|
187 | o_key[i] = Te4[(i_key[i] >> 1) | flg] & 0xFF;
|
---|
188 | flg = (lastVal % 2) << 7;
|
---|
189 | }
|
---|
190 | }
|
---|
191 |
|
---|
192 |
|
---|
193 | static void xor16 (unsigned char i_val1[16], unsigned char i_val2[16], unsigned char o_val[16])
|
---|
194 | {
|
---|
195 | int i;
|
---|
196 | for (i = 0; i < 0x10; i++) {
|
---|
197 | o_val[i] = i_val1[i] ^ i_val2[i];
|
---|
198 | }
|
---|
199 | }
|
---|
200 |
|
---|
201 |
|
---|
202 |
|
---|
203 | static int ndsRouteClass (unsigned char *msgFrmCard, int msgFrmCardsize, unsigned char *cw1, unsigned char *cw2)
|
---|
204 | {
|
---|
205 | unsigned char *msgBody;
|
---|
206 | unsigned char *msgStatus;
|
---|
207 | int i;
|
---|
208 | msgBody = msgFrmCard + 5;
|
---|
209 | msgStatus = msgFrmCard + msgFrmCardsize - 2;
|
---|
210 | switch (msgFrmCard[0]) {
|
---|
211 | case 0xD0:
|
---|
212 | handle_d0_Class (msgFrmCard, msgBody, msgStatus);
|
---|
213 | break;
|
---|
214 | case 0xD1:
|
---|
215 | handle_d1_Class (msgFrmCard, msgBody, msgStatus);
|
---|
216 | break;
|
---|
217 | case 0xD3:
|
---|
218 | handle_d3_Class (msgFrmCard, msgBody, msgStatus);
|
---|
219 | if (msgFrmCard[1] == 0x54) {
|
---|
220 | for (i = 0; i < 8; i++) {
|
---|
221 | cw1[i] = msgBody[i];
|
---|
222 | cw2[i] = msgBody[0x24 + i];
|
---|
223 | }
|
---|
224 | }
|
---|
225 | break;
|
---|
226 | }
|
---|
227 | return 0;
|
---|
228 | }
|
---|
229 |
|
---|
230 |
|
---|
231 | static void get_D0_B4_PublicModule (unsigned char *module)
|
---|
232 | {
|
---|
233 | extractModule (nds_Seed, module);
|
---|
234 | }
|
---|
235 |
|
---|
236 | static void handle_d0_Class (unsigned char *msgFrmCard, unsigned char *msgBody, unsigned char *msgStatus)
|
---|
237 | {
|
---|
238 | switch (msgFrmCard[1]) {
|
---|
239 | case 0xB4:
|
---|
240 | do_d0b4 (msgBody);
|
---|
241 | break;
|
---|
242 | case 0xBC:
|
---|
243 | processD0BC (nds_Seed, msgBody);
|
---|
244 | break;
|
---|
245 | }
|
---|
246 | }
|
---|
247 |
|
---|
248 | static void do_d0b4 (unsigned char *msgBody)
|
---|
249 | {
|
---|
250 | int i;
|
---|
251 | for (i = 0; i < 0x40; i++) {
|
---|
252 | d0_b4_00_00_40_Value[i] = msgBody[i];
|
---|
253 | }
|
---|
254 | }
|
---|
255 |
|
---|
256 |
|
---|
257 |
|
---|
258 | static void recalc_Module (unsigned short *buffer, unsigned short *index, unsigned short value, unsigned int sumValue)
|
---|
259 | {
|
---|
260 | int i = 0, a = 0;
|
---|
261 | unsigned int tmpBuff;
|
---|
262 | if (*index != 0) {
|
---|
263 | do {
|
---|
264 | tmpBuff = buffer[a];
|
---|
265 | tmpBuff = tmpBuff * value;
|
---|
266 | tmpBuff = tmpBuff + sumValue;
|
---|
267 | buffer[a] = tmpBuff;
|
---|
268 | sumValue = tmpBuff >> 16;
|
---|
269 | i++;
|
---|
270 | a++;
|
---|
271 | } while (i < *index);
|
---|
272 | }
|
---|
273 | if (sumValue != 0) {
|
---|
274 | buffer[*index] = sumValue;
|
---|
275 | *index = *index + 1;
|
---|
276 | }
|
---|
277 | }
|
---|
278 |
|
---|
279 | static void extractModule (unsigned char seedBuffer[0x86], unsigned char *outBuffer)
|
---|
280 | {
|
---|
281 | int i, a;
|
---|
282 | unsigned short index[1], tmpVal;
|
---|
283 | unsigned short tmpSeedBuffer[0x20];
|
---|
284 | unsigned short tmpSeedBufferOut[0x20];
|
---|
285 | a = 0;
|
---|
286 | for (i = 0; i < 0x20; i++) {
|
---|
287 | tmpVal = seedBuffer[a + 6];
|
---|
288 | tmpSeedBuffer[i] = seedBuffer[a + 1 + 6] << 8 | tmpVal;
|
---|
289 | a = a + 2;
|
---|
290 | }
|
---|
291 | index[0] = 0x1;
|
---|
292 | tmpSeedBufferOut[0] = 1;
|
---|
293 | for (i = 0; i < 0x20; i++) {
|
---|
294 | recalc_Module (tmpSeedBufferOut, index, tmpSeedBuffer[i], 0);
|
---|
295 | }
|
---|
296 | for (i = 0; i < 0x20; i++) {
|
---|
297 | outBuffer[(i * 2)] = tmpSeedBufferOut[i] & 0xFF;
|
---|
298 | outBuffer[(i * 2) + 1] = (tmpSeedBufferOut[i] >> 8) & 0xFF;
|
---|
299 | }
|
---|
300 |
|
---|
301 | }
|
---|
302 | /*
|
---|
303 | static void extractExponent (unsigned char seedBuffer[0x86], unsigned char *outBuffer)
|
---|
304 | {
|
---|
305 | int i;
|
---|
306 | for (i = 0; i < 0x40;) {
|
---|
307 | outBuffer[i] = seedBuffer[i + 0x46 + 1];
|
---|
308 | outBuffer[i + 1] = seedBuffer[i + 0x46];
|
---|
309 | i = i + 2;
|
---|
310 | }
|
---|
311 | }*/
|
---|
312 |
|
---|
313 | static unsigned short lmul (unsigned short value)
|
---|
314 | {
|
---|
315 | unsigned int var1;
|
---|
316 | var1 = ((value * 4) + value);
|
---|
317 | var1 = (var1 << 4) + var1;
|
---|
318 | var1 = (var1 << 8) + var1;
|
---|
319 | var1 = (((var1 * 2) + value) >> 16) & 0xFFFF;
|
---|
320 | return var1;
|
---|
321 |
|
---|
322 | }
|
---|
323 |
|
---|
324 | static void recalc_BC_Expo (unsigned short value, unsigned int index, unsigned short *expoBuffer,
|
---|
325 | unsigned short *seedBuffer)
|
---|
326 | {
|
---|
327 | unsigned int i, a, val3;
|
---|
328 | unsigned short val1, val2, tmpExp, tmpSed;
|
---|
329 | if (index != 0) {
|
---|
330 | tmpExp = expoBuffer[index - 1];
|
---|
331 | tmpSed = seedBuffer[index];
|
---|
332 | val1 = tmpSed - tmpExp;
|
---|
333 | a = index - 2;
|
---|
334 | for (i = 0; (signed) i < index - 1; i++) {
|
---|
335 | val3 = seedBuffer[a] * val1;
|
---|
336 | val3 = val3 % seedBuffer[index];
|
---|
337 | val1 = val3 - expoBuffer[a];
|
---|
338 | if (val1 > val3) {
|
---|
339 | val1 = val1 + tmpSed;
|
---|
340 | }
|
---|
341 | a--;
|
---|
342 | }
|
---|
343 | val2 = val1 + value;
|
---|
344 | if (value > val2 || val2 > seedBuffer[index]) {
|
---|
345 | val2 = val2 - seedBuffer[index];
|
---|
346 | }
|
---|
347 | val3 = expoBuffer[index] * val2;
|
---|
348 | expoBuffer[index] = val3 % seedBuffer[index];
|
---|
349 |
|
---|
350 | }
|
---|
351 | else {
|
---|
352 | expoBuffer[index] = value;
|
---|
353 | }
|
---|
354 | }
|
---|
355 |
|
---|
356 | static void processD0BC (unsigned char exp_seedBuffer[0x86], unsigned char *outbuffer)
|
---|
357 | {
|
---|
358 | unsigned short seedBuffer[0x20];
|
---|
359 | unsigned short expoBuffer[0x20];
|
---|
360 | unsigned short dataBuffer[0x20];
|
---|
361 | unsigned int i, a, x, value, tmpVal;
|
---|
362 | unsigned short seedVal;
|
---|
363 | unsigned short index[1];
|
---|
364 |
|
---|
365 | a = 0;
|
---|
366 | for (i = 0; i < 0x20; i++) {
|
---|
367 | expoBuffer[i] = exp_seedBuffer[a + 0x46 + 1] << 8 | exp_seedBuffer[a + 0x46];
|
---|
368 | a = a + 2;
|
---|
369 | }
|
---|
370 |
|
---|
371 | a = 0;
|
---|
372 | for (i = 0; i < 0x20; i++) {
|
---|
373 | seedBuffer[i] = exp_seedBuffer[a + 0x6 + 1] << 8 | exp_seedBuffer[a + 0x6];
|
---|
374 | a = a + 2;
|
---|
375 | }
|
---|
376 |
|
---|
377 | a = 0;
|
---|
378 | for (i = 0; i < 0x20; i++) {
|
---|
379 | dataBuffer[i] = outbuffer[a + 1] << 8 | outbuffer[a];
|
---|
380 | a = a + 2;
|
---|
381 | }
|
---|
382 | for (x = 0; x < 0x20; x++) {
|
---|
383 | seedVal = seedBuffer[x] & 0xFFFF;
|
---|
384 | value = 0;
|
---|
385 | for (i = 0x20; i > 0; i--) {
|
---|
386 | tmpVal = value << 16 | dataBuffer[i - 1];
|
---|
387 | tmpVal = tmpVal / seedVal;
|
---|
388 | value = dataBuffer[i - 1] - (tmpVal * seedVal) & 0xFFFF;
|
---|
389 | }
|
---|
390 |
|
---|
391 | tmpVal = lmul (seedVal) | 1;
|
---|
392 | a = 1;
|
---|
393 | while (tmpVal != 0) {
|
---|
394 | if (tmpVal % 2 == 1) {
|
---|
395 | a = a * value % seedVal & 0xFFFF;
|
---|
396 | }
|
---|
397 | value = value * value % seedVal & 0xFFFF;
|
---|
398 | tmpVal = tmpVal / 2;
|
---|
399 | }
|
---|
400 | recalc_BC_Expo ((unsigned short) a, x, expoBuffer, seedBuffer);
|
---|
401 | }
|
---|
402 | a = 0x1F;
|
---|
403 | index[0] = 0;
|
---|
404 | for (i = 0; i < 0x20; i++) {
|
---|
405 | recalc_Module (dataBuffer, index, seedBuffer[a], expoBuffer[a]);
|
---|
406 | a = a - 1;
|
---|
407 | }
|
---|
408 | for (i = 0; i < 0x20; i++) {
|
---|
409 | outbuffer[(i * 2)] = dataBuffer[i] & 0xFF;
|
---|
410 | outbuffer[(i * 2) + 1] = (dataBuffer[i] >> 8) & 0xFF;
|
---|
411 | }
|
---|
412 | nSwap (outbuffer, d0BCKey);
|
---|
413 | nds_aes_set_key ((char *)d0BCKey);
|
---|
414 | }
|
---|
415 |
|
---|
416 |
|
---|
417 |
|
---|
418 | static void handle_d1_Class (unsigned char *msgFrmCard, unsigned char *msgBody, unsigned char *msgStatus)
|
---|
419 | {
|
---|
420 | int msgLen, a, rounds, roundIndex = 0;
|
---|
421 | unsigned char insHeader[0x10];
|
---|
422 | unsigned char insBody[0x10];
|
---|
423 | unsigned char buffer[0x10];
|
---|
424 | unsigned char tmpbuff1[0x10];
|
---|
425 | unsigned char tmpbuff2[0x10];
|
---|
426 |
|
---|
427 | msgLen = msgStatus - msgBody;
|
---|
428 | rounds = msgLen / 0x10;
|
---|
429 |
|
---|
430 | memset (tmpbuff1, 0, 0x10);
|
---|
431 | memset (tmpbuff2, 0, 0x10);
|
---|
432 | memset (buffer, 0, 0x10);
|
---|
433 |
|
---|
434 | memset (insBody, 0, 0x10);
|
---|
435 | memset (insHeader, 0, 0x10);
|
---|
436 |
|
---|
437 | memcpy (insHeader, msgFrmCard, 0x5);
|
---|
438 |
|
---|
439 |
|
---|
440 | xor16 (insHeader, oldHBuffer, tmpbuff1);
|
---|
441 | memcpy (oldHBuffer, tmpbuff1, 0x10);
|
---|
442 |
|
---|
443 | for (a = 0; a < rounds + 2; a++) {
|
---|
444 | if (a == rounds) {
|
---|
445 | memset (insBody, 0, 0x10);
|
---|
446 | memcpy (insBody, msgBody + roundIndex, (msgLen) % 0x10);
|
---|
447 | }
|
---|
448 | else if (a == rounds + 1) {
|
---|
449 | memset (insBody, 0, 0x10);
|
---|
450 | memcpy (insBody + 5, msgStatus, 0x2);
|
---|
451 | }
|
---|
452 | else {
|
---|
453 | memcpy (insBody, msgBody + roundIndex, 0x10);
|
---|
454 | }
|
---|
455 | xor16 (tmpbuff1, insBody, tmpbuff2);
|
---|
456 |
|
---|
457 | nSwap (tmpbuff2, buffer);
|
---|
458 | AES_encrypt (buffer, buffer, &aeskey);
|
---|
459 | nSwap (buffer, tmpbuff2);
|
---|
460 | roundIndex = roundIndex + 0x10;
|
---|
461 | xor16 (tmpbuff2, oldHBuffer, tmpbuff1);
|
---|
462 |
|
---|
463 | }
|
---|
464 | memcpy (oldHBuffer, tmpbuff2, 0x10);
|
---|
465 | }
|
---|
466 |
|
---|
467 |
|
---|
468 |
|
---|
469 |
|
---|
470 |
|
---|
471 | static void handle_d3_Class (unsigned char *msgFrmCard, unsigned char *msgBody, unsigned char *msgStatus)
|
---|
472 | {
|
---|
473 | int i, msgLen, rounds, roundIndex = 0;
|
---|
474 | unsigned char insHeader[0x10];
|
---|
475 | unsigned char insBody[0x10];
|
---|
476 | unsigned char insStatus[0x10];
|
---|
477 | unsigned char tmpbuff1[0x10];
|
---|
478 | unsigned char tmpbuff2[0x10];
|
---|
479 | unsigned char wBuffer[0x10];
|
---|
480 | unsigned char dispBuffer[0x100];
|
---|
481 |
|
---|
482 | //aes_context ctx;
|
---|
483 |
|
---|
484 | if (msgFrmCard[4] > 0x10) {
|
---|
485 | msgFrmCard[4] = msgFrmCard[4] - 0x10;
|
---|
486 | }
|
---|
487 |
|
---|
488 | if (msgFrmCard[1] == 0xBE) {
|
---|
489 | memset (oldHBuffer, 0, 0x10);
|
---|
490 | }
|
---|
491 | memcpy (tmpbuff1, oldHBuffer, 0x10); // Get from oldHbuffer
|
---|
492 |
|
---|
493 |
|
---|
494 | memset (wBuffer, 0, 0x10);
|
---|
495 | memset (insHeader, 0, 0x10);
|
---|
496 | memcpy (insHeader, msgFrmCard, 0x5);
|
---|
497 |
|
---|
498 | memset (insStatus, 0, 0x10);
|
---|
499 | memcpy (insStatus + 5, msgStatus, 0x2);
|
---|
500 |
|
---|
501 | memset (insBody, 0, 0x10);
|
---|
502 | memcpy (insBody, msgBody, 0x10);
|
---|
503 |
|
---|
504 | xor16 (insHeader, oldHBuffer, oldHBuffer);
|
---|
505 |
|
---|
506 | msgLen = msgFrmCard[4];
|
---|
507 | rounds = msgLen / 0x10;
|
---|
508 | /*Rounds */
|
---|
509 | if (msgFrmCard[1] != 0xBE) {
|
---|
510 | rounds++;
|
---|
511 | }
|
---|
512 | for (i = 0; i < rounds; i++) {
|
---|
513 | wBuffer[0] = wBuffer[0] + i;
|
---|
514 | xor16 (wBuffer, oldHBuffer, wBuffer);
|
---|
515 |
|
---|
516 | nSwap (wBuffer, tmpbuff2);
|
---|
517 | AES_encrypt (tmpbuff2, tmpbuff2, &aeskey);
|
---|
518 | nSwap (tmpbuff2, wBuffer);
|
---|
519 | memcpy (tmpbuff1, msgBody + roundIndex, 0x10);
|
---|
520 |
|
---|
521 | xor16 (wBuffer, tmpbuff1, dispBuffer + roundIndex);
|
---|
522 | if (i == msgLen / 0x10) {
|
---|
523 | memset (dispBuffer + roundIndex + (msgLen - roundIndex), 0, 0x10 - (msgLen - roundIndex));
|
---|
524 | }
|
---|
525 | xor16 (dispBuffer + roundIndex, oldHBuffer, oldHBuffer);
|
---|
526 | nLookup (oldHBuffer, oldHBuffer);
|
---|
527 |
|
---|
528 | roundIndex = roundIndex + 0x10;
|
---|
529 | }
|
---|
530 | xor16 (oldHBuffer, insStatus, oldHBuffer);
|
---|
531 | nSwap (oldHBuffer, tmpbuff2);
|
---|
532 | AES_encrypt (tmpbuff2, tmpbuff2, &aeskey);
|
---|
533 | nSwap (tmpbuff2, oldHBuffer);
|
---|
534 |
|
---|
535 | /*Get Phase from Last 16 Bytes */
|
---|
536 | memcpy (oldHBuffer, msgStatus - 0x10, 0x10);
|
---|
537 |
|
---|
538 | nSwap (oldHBuffer, tmpbuff2);
|
---|
539 | AES_encrypt (tmpbuff2, tmpbuff2, &aeskey);
|
---|
540 | nSwap (tmpbuff2, oldHBuffer);
|
---|
541 |
|
---|
542 | memcpy (msgBody, dispBuffer, msgLen);
|
---|
543 |
|
---|
544 | if (msgFrmCard[1] == 0xBE) {
|
---|
545 | nSwap (dispBuffer, d3BEKey);
|
---|
546 | nds_aes_set_key ((char *)d3BEKey);
|
---|
547 | }
|
---|
548 |
|
---|
549 | }
|
---|
550 |
|
---|
551 |
|
---|
552 | static int nds_getInsParams (unsigned char *insHeader, unsigned char *dir, unsigned char *len)
|
---|
553 | {
|
---|
554 | int i, a, retval;
|
---|
555 | retval = 1;
|
---|
556 | a = 4;
|
---|
557 | for (i = 0; i < nds_supportedIns[2]; i++) {
|
---|
558 | if (insHeader[1] == nds_supportedIns[a + 1]) {
|
---|
559 | *len = nds_supportedIns[a + 2];
|
---|
560 | *dir = nds_supportedIns[a + 3];
|
---|
561 | retval = 0;
|
---|
562 | }
|
---|
563 | a = a + 4;
|
---|
564 | }
|
---|
565 | return retval;
|
---|
566 | }
|
---|
567 |
|
---|
568 | static void nds_createEcmInsFromRawEcm (unsigned char *rawEcm, unsigned char *ecmIns)
|
---|
569 | {
|
---|
570 | unsigned char ecmINSHeader[5] = { 0xD1, 0x40, 0x40, 0x80, 0xFF };
|
---|
571 | int insLen;
|
---|
572 | insLen = rawEcm[2] - 0xF;
|
---|
573 | ecmINSHeader[4] = insLen;
|
---|
574 | memset (ecmIns, 0, 0xFF);
|
---|
575 | memcpy (ecmIns, ecmINSHeader, 5);
|
---|
576 | memcpy (ecmIns + 6, rawEcm + 19, insLen + 0x12);
|
---|
577 | //cs_log("ECM: %s",cs_hexdump(0,ecmIns,ecmINSHeader[4]+5));
|
---|
578 | }
|
---|
579 |
|
---|
580 | static int nds_AskInsLen (unsigned char ins[5])
|
---|
581 | {
|
---|
582 | unsigned char oldP2;
|
---|
583 | int error = 0;
|
---|
584 | oldP2 = ins[3];
|
---|
585 | ins[3] = 0x80; // getLengh
|
---|
586 | ins[4] = 0x01; // getLengh
|
---|
587 | error = CommandSendCardCAM (ins, (char *) CardAnswer);
|
---|
588 | ins[3] = oldP2; // getLengh
|
---|
589 | if (error) {
|
---|
590 | return -1;
|
---|
591 | }
|
---|
592 | else {
|
---|
593 | ins[4] = CardAnswer[1]; // update lenght
|
---|
594 | }
|
---|
595 | return 0;
|
---|
596 | }
|
---|
597 |
|
---|
598 | static int nds_buildIncomingCommandWSB (unsigned char *isoHeader, unsigned char *commandPayload,
|
---|
599 | unsigned char *statusBytes, unsigned char *outCommand)
|
---|
600 | {
|
---|
601 | unsigned int len;
|
---|
602 | memcpy(outCommand, isoHeader, 5);
|
---|
603 | len = 5;
|
---|
604 | memcpy(outCommand + len, commandPayload, isoHeader[4]);
|
---|
605 | len += isoHeader[4];
|
---|
606 | memcpy(outCommand + len, statusBytes,2);
|
---|
607 | len += 2;
|
---|
608 | return len;
|
---|
609 | }
|
---|
610 |
|
---|
611 | static int nds_buildIncomingCommand (unsigned char *isoHeader, unsigned char *cardResponse, unsigned char *outCommand)
|
---|
612 | {
|
---|
613 | unsigned int len;
|
---|
614 | memcpy(outCommand, isoHeader, 5);
|
---|
615 | len = 5;
|
---|
616 | memcpy(outCommand + len, cardResponse + 1, isoHeader[4] + 2);
|
---|
617 | len += isoHeader[4] + 2;
|
---|
618 | return len;
|
---|
619 | }
|
---|
620 |
|
---|
621 | static void nds_parseUAInfo (unsigned char *uaInsData)
|
---|
622 | {
|
---|
623 | nds_SC_UA[0] = uaInsData[8];
|
---|
624 | nds_SC_UA[1] = uaInsData[9];
|
---|
625 | nds_SC_UA[2] = uaInsData[10];
|
---|
626 | nds_SC_UA[3] = uaInsData[11];
|
---|
627 |
|
---|
628 | nds_SC_CAID = (uaInsData[0x1D] << 8) | (uaInsData[0x1E]);
|
---|
629 | }
|
---|
630 |
|
---|
631 | static void nds_parseBoxIDInfo (unsigned char *boxIDData)
|
---|
632 | {
|
---|
633 | if (reader[ridx].boxid)
|
---|
634 | return;
|
---|
635 |
|
---|
636 | int i;
|
---|
637 | for (i = 0; i < 0x8F; i++) {
|
---|
638 | if ((boxIDData[i] == 0x00) && (boxIDData[i + 1] == 0xF3)) {
|
---|
639 | memcpy (&nds_IRD_BoxID, &boxIDData[i + 2], sizeof (nds_IRD_BoxID));
|
---|
640 | }
|
---|
641 | }
|
---|
642 | }
|
---|
643 |
|
---|
644 | static unsigned int nds_getSupportedIns (void)
|
---|
645 | {
|
---|
646 | unsigned int retval = 0;
|
---|
647 | static unsigned char ndsBoot_GetSupportedIns[] = { 0xd0, 0x74, 0x01, 0x00, 0xFF };
|
---|
648 | nds_AskInsLen (ndsBoot_GetSupportedIns);
|
---|
649 | CommandSendCardCAM (ndsBoot_GetSupportedIns, (char *) CardAnswer);
|
---|
650 | memcpy (nds_supportedIns, CardAnswer + 1, ndsBoot_GetSupportedIns[4]);
|
---|
651 | return retval;
|
---|
652 | }
|
---|
653 |
|
---|
654 | static unsigned int nds_sendCommandToCard (unsigned char *insHeader, unsigned char *cmdPayload, unsigned char *cmdOut)
|
---|
655 | {
|
---|
656 | unsigned char dir, len, cmdLen;
|
---|
657 | nds_getInsParams (insHeader, &dir, &len);
|
---|
658 | if ((len == 0xFF) & (dir == 2)) {
|
---|
659 | nds_AskInsLen (insHeader);
|
---|
660 | }
|
---|
661 | if (len != 0xFF) {
|
---|
662 | insHeader[4] = len;
|
---|
663 | }
|
---|
664 | if (insHeader[0] == 0xD3) {
|
---|
665 | insHeader[4] = len + 0x10;
|
---|
666 | }
|
---|
667 | if (dir >= 2) { //Card -> Cam
|
---|
668 | CommandSendCardCAM (insHeader, (char *) CardAnswer);
|
---|
669 | cmdLen = nds_buildIncomingCommand (insHeader, CardAnswer, cmdOut);
|
---|
670 | }
|
---|
671 | if (dir <= 1) { //Cam -> Card
|
---|
672 | CommandSendCAMCard (insHeader, (char *) CardAnswer, cmdPayload);
|
---|
673 | cmdLen = nds_buildIncomingCommandWSB (insHeader, cmdPayload, CardAnswer, cmdOut);
|
---|
674 | }
|
---|
675 |
|
---|
676 | ndsRouteClass (cmdOut, cmdLen, cw1, cw2);
|
---|
677 | return 0;
|
---|
678 | }
|
---|
679 |
|
---|
680 | static unsigned int nds_getUAandBoxId ()
|
---|
681 | {
|
---|
682 | static unsigned char ndsBoot_GetPhoneInfo[] = { 0xd0, 0x36, 0x00, 0x00, 0x00 };
|
---|
683 | static unsigned char ndsBoot_SendBoxid[] = { 0xd0, 0x4C, 0x00, 0x00, 0x00 };
|
---|
684 | static unsigned char ndsBoxID_Payload[] = { 0x00, 0x00, 0x00, 0x00, 0x03, 0x00, 0x00, 0x02, 0x04 };
|
---|
685 | static unsigned char ndsBoot_GetUAInfo[] = { 0xd0, 0x58, 0x00, 0x00, 0x00 };
|
---|
686 | nds_sendCommandToCard (ndsBoot_GetPhoneInfo, NULL, ndsCommand);
|
---|
687 | nds_parseBoxIDInfo (ndsCommand);
|
---|
688 | memcpy (ndsBoxID_Payload, nds_IRD_BoxID, 4);
|
---|
689 | nds_sendCommandToCard (ndsBoot_SendBoxid, ndsBoxID_Payload, ndsCommand);
|
---|
690 | cs_log ("BoxID: %02X%02X%02X%02X (%02X %02X)", ndsBoxID_Payload[0], ndsBoxID_Payload[1], ndsBoxID_Payload[2],
|
---|
691 | ndsBoxID_Payload[3], cta_res[cta_lr - 2], cta_res[cta_lr - 1]);
|
---|
692 | nds_sendCommandToCard (ndsBoot_GetUAInfo, NULL, ndsCommand);
|
---|
693 | nds_parseUAInfo (ndsCommand);
|
---|
694 | return 0;
|
---|
695 | }
|
---|
696 |
|
---|
697 | static unsigned int nds_getUAandBoxId_D1 ()
|
---|
698 | {
|
---|
699 | static unsigned char ndsBoot_SendBoxid[] = { 0xd1, 0x4C, 0x00, 0x00, 0x00 };
|
---|
700 | static unsigned char ndsBoxID_Payload[] = { 0x00, 0x00, 0x00, 0x00, 0x03, 0x00, 0x00, 0x02, 0x04 };
|
---|
701 | static unsigned char ndsBoot_GetUAInfo[] = { 0xd1, 0x58, 0x00, 0x00, 0x00 };
|
---|
702 | memcpy (ndsBoxID_Payload, nds_IRD_BoxID, 4);
|
---|
703 | nds_sendCommandToCard (ndsBoot_GetUAInfo, NULL, ndsCommand);
|
---|
704 | nds_sendCommandToCard (ndsBoot_SendBoxid, ndsBoxID_Payload, ndsCommand);
|
---|
705 | cs_log ("BoxID: %02X%02X%02X%02X (%02X %02X)", ndsBoxID_Payload[0], ndsBoxID_Payload[1], ndsBoxID_Payload[2],
|
---|
706 | ndsBoxID_Payload[3], cta_res[cta_lr - 2], cta_res[cta_lr - 1]);
|
---|
707 | return 0;
|
---|
708 | }
|
---|
709 |
|
---|
710 |
|
---|
711 | static unsigned int nds_getCamCryptKeys ()
|
---|
712 | {
|
---|
713 | static unsigned char ndsBoot_SendModul[] = { 0xd0, 0xb4, 0x00, 0x00, 0x00 };
|
---|
714 | static unsigned char ndsBoot_AskD0Key[] = { 0xd0, 0xbc, 0x00, 0x00, 0x00 };
|
---|
715 | static unsigned char ndsBoot_AskD3Key[] = { 0xd3, 0xbe, 0x00, 0x00, 0x00 };
|
---|
716 |
|
---|
717 | static unsigned char ndsModul_Payload[0x40];
|
---|
718 | get_D0_B4_PublicModule (ndsModul_Payload);
|
---|
719 | nds_sendCommandToCard (ndsBoot_SendModul, ndsModul_Payload, ndsCommand);
|
---|
720 | nds_sendCommandToCard (ndsBoot_AskD0Key, NULL, ndsCommand);
|
---|
721 |
|
---|
722 | nds_sendCommandToCard (ndsBoot_AskD3Key, NULL, ndsCommand);
|
---|
723 |
|
---|
724 | return 0;
|
---|
725 | }
|
---|
726 |
|
---|
727 |
|
---|
728 | static int ndsBoot (void)
|
---|
729 | {
|
---|
730 | static unsigned char ndsBoot_Get7416[] = { 0xd0, 0x74, 0x16, 0x00, 0x00 };
|
---|
731 |
|
---|
732 | nds_getSupportedIns ();
|
---|
733 | nds_sendCommandToCard (ndsBoot_Get7416, NULL, ndsCommand);
|
---|
734 | nds_getUAandBoxId ();
|
---|
735 | nds_getCamCryptKeys ();
|
---|
736 | nds_getUAandBoxId_D1 ();
|
---|
737 |
|
---|
738 | return 1;
|
---|
739 | }
|
---|
740 |
|
---|
741 |
|
---|
742 | ///====================================================================================================
|
---|
743 |
|
---|
744 | int nds_card_init (uchar * atr, int atrsize)
|
---|
745 | {
|
---|
746 | if (atrsize < 14 || (atr[10] != 0x69 && atr[11] != 0xFF && atr[12] != 0x4A && atr[13] != 0x50))
|
---|
747 | return (0);
|
---|
748 |
|
---|
749 | unsigned char atr_premiere[] = { 0x3F, 0xFF, 0x11, 0x25, 0x03, 0x10, 0x80, 0x41, 0xB0, 0x07, 0x69, 0xFF, 0x4A, 0x50, 0x70, 0x00, 0x00, 0x50, 0x31, 0x01, 0x00, 0x11 };
|
---|
750 | if (!(atrsize == sizeof (atr_premiere)) || (!memcmp (atr, atr_premiere, atrsize) == 0))
|
---|
751 | {
|
---|
752 | return 0; //for all other nds videoguard2 should be used
|
---|
753 | }
|
---|
754 | /*
|
---|
755 | if (reader[ridx].pincode[0]) {
|
---|
756 | nds_IRD_BoxID[0] = (gethexval (reader[ridx].pincode[0]) << 4) | gethexval (reader[ridx].pincode[1]);
|
---|
757 | nds_IRD_BoxID[1] = (gethexval (reader[ridx].pincode[2]) << 4) | gethexval (reader[ridx].pincode[3]);
|
---|
758 | nds_IRD_BoxID[2] = (gethexval (reader[ridx].pincode[4]) << 4) | gethexval (reader[ridx].pincode[5]);
|
---|
759 | nds_IRD_BoxID[3] = (gethexval (reader[ridx].pincode[6]) << 4) | gethexval (reader[ridx].pincode[7]);
|
---|
760 | }
|
---|
761 | */
|
---|
762 | if (reader[ridx].boxid > 0) {
|
---|
763 | /* the boxid is specified in the config */
|
---|
764 | int i;
|
---|
765 | for (i=0; i < 4; i++) {
|
---|
766 | nds_IRD_BoxID[i] = (reader[ridx].boxid >> (8 * (3 - i))) % 0x100;
|
---|
767 | }
|
---|
768 | }
|
---|
769 |
|
---|
770 | ndsBoot ();
|
---|
771 | reader[ridx].caid[0] = nds_SC_CAID;
|
---|
772 | reader[ridx].hexserial[0] = nds_SC_UA[0];
|
---|
773 | reader[ridx].hexserial[1] = nds_SC_UA[1];
|
---|
774 | reader[ridx].hexserial[2] = nds_SC_UA[2];
|
---|
775 | reader[ridx].hexserial[3] = nds_SC_UA[3];
|
---|
776 |
|
---|
777 | cs_ri_log ("type: nds, card: %c%c.%d, boxID: %02X%02X%02X%02X, caid: %04X, ascii serial: %ld, hex serial: %s",
|
---|
778 | atr[17], atr[18], atr[19],
|
---|
779 | nds_IRD_BoxID[0], nds_IRD_BoxID[1], nds_IRD_BoxID[2], nds_IRD_BoxID[3], reader[ridx].caid[0],
|
---|
780 | (reader[ridx].hexserial[0] << 24 | reader[ridx].hexserial[1] << 16 | reader[ridx].
|
---|
781 | hexserial[2] << 8 | reader[ridx].hexserial[3]), cs_hexdump (0, reader[ridx].hexserial, 4));
|
---|
782 |
|
---|
783 | reader[ridx].nprov = 1;
|
---|
784 | memset (reader[ridx].prid, 0, sizeof (reader[ridx].prid));
|
---|
785 | memset (reader[ridx].sa, 0xFF, sizeof (reader[ridx].sa));
|
---|
786 | memcpy (reader[ridx].sa, reader[ridx].hexserial, 3);
|
---|
787 | reader[ridx].sa[0][3] = 0;
|
---|
788 |
|
---|
789 | cs_ri_log ("NDS-Provider:%d", reader[ridx].nprov);
|
---|
790 |
|
---|
791 | int j;
|
---|
792 | for (j = 0; j < reader[ridx].nprov; j++) {
|
---|
793 | cs_ri_log ("Provider:%d Provider-Id:%06X", j + 1, b2ll (4, reader[ridx].prid[j]));
|
---|
794 | cs_ri_log ("Provider:%d SharedAddress:%08X", j + 1, b2ll (4, reader[ridx].sa[j]));
|
---|
795 | }
|
---|
796 |
|
---|
797 | cs_log ("ready for requests");
|
---|
798 | return (1);
|
---|
799 | }
|
---|
800 |
|
---|
801 | int nds_do_ecm (ECM_REQUEST * er)
|
---|
802 | {
|
---|
803 | static unsigned char ndsEcm_GetDW[] = { 0xd3, 0x54, 0x00, 0x00, 0x00 };
|
---|
804 |
|
---|
805 | unsigned char insHeader[5];
|
---|
806 | nds_createEcmInsFromRawEcm (er->ecm, CardAnswer);
|
---|
807 | memcpy (insHeader, CardAnswer, 5);
|
---|
808 | memcpy (ndsCommand, CardAnswer + 5, insHeader[4]);
|
---|
809 |
|
---|
810 | nds_sendCommandToCard (insHeader, ndsCommand, CardAnswer);
|
---|
811 | nds_sendCommandToCard (ndsEcm_GetDW, NULL, CardAnswer);
|
---|
812 |
|
---|
813 | if (er->ecm[0] == 0x80)
|
---|
814 | memcpy (er->cw, cw1, 8);
|
---|
815 |
|
---|
816 | if (er->ecm[0] == 0x81)
|
---|
817 | memcpy (er->cw + 8, cw1, 8);
|
---|
818 |
|
---|
819 | if (er->cw[0] == 0 && er->cw[8] == 0)
|
---|
820 | return 0;
|
---|
821 | return 1;
|
---|
822 | }
|
---|
823 |
|
---|
824 | static int nds_AddrMode (unsigned char *data)
|
---|
825 | {
|
---|
826 | switch (data[3] & 0xC0) {
|
---|
827 | case 0x40:
|
---|
828 | return 3;
|
---|
829 | case 0x80:
|
---|
830 | return 2;
|
---|
831 | default:
|
---|
832 | return 0;
|
---|
833 | }
|
---|
834 | }
|
---|
835 |
|
---|
836 | static unsigned int nds_NumAddr (unsigned char *data)
|
---|
837 | {
|
---|
838 | return ((data[3] & 0x30) >> 4) + 1;
|
---|
839 | }
|
---|
840 |
|
---|
841 | static unsigned char *nds_PayloadStart (unsigned char *data)
|
---|
842 | {
|
---|
843 | //return &data[4 + NumAddr(data)*4 + 2];
|
---|
844 | if (nds_AddrMode (data) == 0)
|
---|
845 | return &data[4];
|
---|
846 | else
|
---|
847 | return &data[4 + nds_NumAddr (data) * 4];
|
---|
848 | }
|
---|
849 |
|
---|
850 | int nds_do_emm (EMM_PACKET * ep)
|
---|
851 | {
|
---|
852 | unsigned char insEMM[] = { 0xD1, 0x42, 0x00, 0x00, 0x00 };
|
---|
853 |
|
---|
854 | int lenEMM, rc = 0;
|
---|
855 |
|
---|
856 | unsigned char *payloaddata = nds_PayloadStart (ep->emm);
|
---|
857 | switch (payloaddata[0]) {
|
---|
858 | case 2:
|
---|
859 | lenEMM = payloaddata[payloaddata[1] + 2];
|
---|
860 | payloaddata += 3 + payloaddata[1]; // skip len specifier
|
---|
861 | break;
|
---|
862 | default:
|
---|
863 | //EMM: bad payload type byte
|
---|
864 | return 0;
|
---|
865 | }
|
---|
866 |
|
---|
867 | if (lenEMM <= 8 || lenEMM > 188) {
|
---|
868 | return 0;
|
---|
869 | }
|
---|
870 |
|
---|
871 | insEMM[4] = lenEMM;
|
---|
872 | nds_sendCommandToCard (insEMM, payloaddata, ndsCommand);
|
---|
873 | //cs_log("EMM A: %s",cs_hexdump(1,cta_res,cta_lr));
|
---|
874 | rc = ((cta_res[cta_lr - 2] == 0x90) && (cta_res[cta_lr - 1] == 0x00));
|
---|
875 |
|
---|
876 | return (rc);
|
---|
877 | }
|
---|
878 |
|
---|
879 | static void nds_RevDateCalc (const unsigned char *Date, int *year, int *mon, int *day, int *hh, int *mm, int *ss)
|
---|
880 | {
|
---|
881 | *year = (Date[0] / 12) + 2000;
|
---|
882 | *mon = (Date[0] % 12) + 1;
|
---|
883 | *day = Date[1];
|
---|
884 | *hh = Date[2] / 8;
|
---|
885 | *mm = (0x100 * (Date[2] - *hh * 8) + Date[3]) / 32;
|
---|
886 | *ss = (Date[3] - *mm * 32) * 2;
|
---|
887 | }
|
---|
888 |
|
---|
889 | int nds_card_info (void)
|
---|
890 | {
|
---|
891 | int i = 0;
|
---|
892 |
|
---|
893 | unsigned char ins2a[] = { 0xd0, 0x2a, 0x00, 0x00, 0x00 };
|
---|
894 | nds_sendCommandToCard (ins2a, NULL, ndsCommand);
|
---|
895 |
|
---|
896 | unsigned char ins76[] = { 0xd0, 0x76, 0x00, 0x00, 0x00 };
|
---|
897 | ins76[3] = 0x7f;
|
---|
898 | ins76[4] = 2;
|
---|
899 |
|
---|
900 | nds_sendCommandToCard (ins76, NULL, ndsCommand);
|
---|
901 | //cs_log("A: %s...",cs_hexdump(1,cta_res,cta_lr));
|
---|
902 | //cs_log("A: %s...",cs_hexdump(1,ndsCommand,cta_lr));
|
---|
903 | ins76[3] = 0;
|
---|
904 | ins76[4] = 0;
|
---|
905 | int num = cta_res[1];
|
---|
906 |
|
---|
907 | for (i = 0; i < num; i++) {
|
---|
908 | ins76[2] = i;
|
---|
909 | nds_sendCommandToCard (ins76, NULL, ndsCommand);
|
---|
910 | //cs_log("A: %s...",cs_hexdump(1,cta_res,cta_lr));
|
---|
911 | if (cta_res[5 + 2] == 0 && cta_res[5 + 3] == 0)
|
---|
912 | break;
|
---|
913 | int y, m, d, H, M, S;
|
---|
914 | nds_RevDateCalc (&cta_res[5 + 4], &y, &m, &d, &H, &M, &S);
|
---|
915 | cs_ri_log ("chid: %02x%02x, date: %04d-%02d-%02d %02d:%02d:%02d", cta_res[5 + 2], cta_res[5 + 3], y, m, d, H, M, S);
|
---|
916 | }
|
---|
917 | return (1);
|
---|
918 | }
|
---|