mirror of
https://github.com/RfidResearchGroup/proxmark3.git
synced 2026-10-05 23:07:39 +00:00
Simulation now completes the full exchange with a genuine Paxton reader in password mode, and crypto mode read/write passes Proxmark-to-Proxmark. Firmware: - SOF was one bit period short. The lead-in that compensated for the lost head half bit was removed and nothing replaced it, so readers rejected every answer with a second START_AUTH. Default is now 6. - The edge-detect threshold was latched before being measured, so the value chosen depended on whether the Proxmark was in a field when sim started. It is now measured on field entry and re-armed when the reader leaves. - The percentile walk latched on run-scoped variables, so one attempt made outside a field poisoned every later one. - Field loss was detected from TIMESTAMP, which is free-running MCU time and never stalls. Detect it from receive silence instead. - Frames of a length the protocol does not have no longer reach the state machine; our own modulation tail was resetting the session and breaking every write. - A dropped edge merges two or three reader bit periods into one gap. Those bits were discarded; they are now recovered by decomposition, which is what made crypto mode work (AUTH decode 15% -> 100%). - Threshold selection is limited to 20 and 32 and settles in under 25 ms. Client: - lf hitag info printed a hardcoded 0x06 and reported 'Password mode' for every tag. It now reads page 3, takes -k (4 bytes password, 6 bytes crypto), and says so when the config cannot be read. - lf hitag restore: writes a dump back in dependency order - user pages, then key material, then config last - validates the config byte, and prints the credential the tag will require afterwards. - lf hitag crack2 now reports why it failed instead of a bare 'fail'. - trace list: bit count moved to its own column, relative mode shows a Frame Delay Time row rather than renaming Start/End, --frame and -r rejected together.
108 lines
3.2 KiB
Verilog
108 lines
3.2 KiB
Verilog
//-----------------------------------------------------------------------------
|
|
// Copyright (C) Proxmark3 contributors. See AUTHORS.md for details.
|
|
//
|
|
// This program is free software: you can redistribute it and/or modify
|
|
// it under the terms of the GNU General Public License as published by
|
|
// the Free Software Foundation, either version 3 of the License, or
|
|
// (at your option) any later version.
|
|
//
|
|
// This program is distributed in the hope that it will be useful,
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
// GNU General Public License for more details.
|
|
//
|
|
// See LICENSE.txt for the text of the license.
|
|
//-----------------------------------------------------------------------------
|
|
//
|
|
// The way that we connect things in low-frequency simulation mode. In this
|
|
// case just pass everything through to the ARM, which can bit-bang this
|
|
// (because it is so slow).
|
|
//
|
|
// Jonathan Westhues, April 2006
|
|
//-----------------------------------------------------------------------------
|
|
|
|
module lo_adc(
|
|
input pck0,
|
|
input [7:0] adc_d,
|
|
input [7:0] divisor,
|
|
input lf_field,
|
|
input lf_weak_load,
|
|
input ssp_dout,
|
|
|
|
output ssp_din,
|
|
output ssp_frame,
|
|
output ssp_clk,
|
|
output adc_clk,
|
|
output pwr_lo,
|
|
output pwr_hi,
|
|
output pwr_oe1,
|
|
output pwr_oe2,
|
|
output pwr_oe3,
|
|
output pwr_oe4,
|
|
output debug
|
|
);
|
|
|
|
reg [7:0] to_arm_shiftreg;
|
|
reg [7:0] pck_divider;
|
|
reg clk_state;
|
|
|
|
// Antenna logic, depending on "lf_field" (in arm defined as FPGA_LF_READER_FIELD)
|
|
wire tag_modulation = ssp_dout & !lf_field;
|
|
wire reader_modulation = !ssp_dout & lf_field & clk_state;
|
|
|
|
// always on (High Frequency outputs, unused)
|
|
assign pwr_oe1 = 1'b0;
|
|
assign pwr_hi = 1'b0;
|
|
|
|
// low frequency outputs
|
|
assign pwr_lo = reader_modulation;
|
|
assign pwr_oe2 = 1'b0; // 33 Ohms
|
|
// lf_weak_load moves the modulation from the 33 Ohm leg to the 10k one, so the
|
|
// depth measured here matches what lo_edge_detect does in the same mode.
|
|
assign pwr_oe3 = tag_modulation & ~lf_weak_load; // base antenna load = 33 Ohms
|
|
assign pwr_oe4 = tag_modulation & lf_weak_load; // 10k Ohms
|
|
|
|
// Debug Output ADC clock
|
|
assign debug = adc_clk;
|
|
|
|
// ADC clock out of phase with antenna driver
|
|
assign adc_clk = ~clk_state;
|
|
|
|
// serialized SSP data is gated by clk_state to suppress unwanted signal
|
|
assign ssp_din = to_arm_shiftreg[7] && !clk_state;
|
|
|
|
// SSP clock always runs at 24MHz
|
|
assign ssp_clk = pck0;
|
|
|
|
// SSP frame is gated by clk_state and goes high when pck_divider=8..15
|
|
assign ssp_frame = (pck_divider[7:3] == 5'd1) && !clk_state;
|
|
|
|
// divide 24mhz down to 3mhz
|
|
always @(posedge pck0)
|
|
begin
|
|
if (pck_divider == divisor[7:0])
|
|
begin
|
|
pck_divider <= 8'd0;
|
|
clk_state = !clk_state;
|
|
end
|
|
else
|
|
begin
|
|
pck_divider <= pck_divider + 1;
|
|
end
|
|
end
|
|
|
|
// this task also runs at pck0 frequency (24Mhz) and is used to serialize
|
|
// the ADC output which is then clocked into the ARM SSP.
|
|
always @(posedge pck0)
|
|
begin
|
|
if ((pck_divider == 8'd7) && !clk_state)
|
|
to_arm_shiftreg <= adc_d;
|
|
else
|
|
begin
|
|
to_arm_shiftreg[7:1] <= to_arm_shiftreg[6:0];
|
|
to_arm_shiftreg[0] <= 1'b0;
|
|
end
|
|
end
|
|
|
|
endmodule
|