blob: bc1ebf7214e7e19940ad5bae5e5d73c021658e56 [file] [log] [blame]
Sylvain Munaut76504e02010-12-07 00:24:32 +01001#!/usr/bin/env python
2# -*- coding: utf-8 -*-
3
4""" pySim: Card programmation logic
5"""
6
7#
8# Copyright (C) 2009-2010 Sylvain Munaut <tnt@246tNt.com>
Harald Welte3156d902011-03-22 21:48:19 +01009# Copyright (C) 2011 Harald Welte <laforge@gnumonks.org>
Alexander Chemeriseb6807d2017-07-18 17:04:38 +030010# Copyright (C) 2017 Alexander.Chemeris <Alexander.Chemeris@gmail.com>
Sylvain Munaut76504e02010-12-07 00:24:32 +010011#
12# This program is free software: you can redistribute it and/or modify
13# it under the terms of the GNU General Public License as published by
14# the Free Software Foundation, either version 2 of the License, or
15# (at your option) any later version.
16#
17# This program is distributed in the hope that it will be useful,
18# but WITHOUT ANY WARRANTY; without even the implied warranty of
19# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
20# GNU General Public License for more details.
21#
22# You should have received a copy of the GNU General Public License
23# along with this program. If not, see <http://www.gnu.org/licenses/>.
24#
25
Alexander Chemeriseb6807d2017-07-18 17:04:38 +030026from pySim.ts_51_011 import EF, DF
27from pySim.utils import *
Alexander Chemeris8ad124a2018-01-10 14:17:55 +090028from smartcard.util import toBytes
Sylvain Munaut76504e02010-12-07 00:24:32 +010029
30class Card(object):
31
32 def __init__(self, scc):
33 self._scc = scc
Alexander Chemeriseb6807d2017-07-18 17:04:38 +030034 self._adm_chv_num = 4
Sylvain Munaut76504e02010-12-07 00:24:32 +010035
Sylvain Munaut76504e02010-12-07 00:24:32 +010036 def reset(self):
37 self._scc.reset_card()
38
Alexander Chemeriseb6807d2017-07-18 17:04:38 +030039 def verify_adm(self, key):
40 '''
41 Authenticate with ADM key
42 '''
43 (res, sw) = self._scc.verify_chv(self._adm_chv_num, key)
44 return sw
45
46 def read_iccid(self):
47 (res, sw) = self._scc.read_binary(EF['ICCID'])
48 if sw == '9000':
49 return (dec_iccid(res), sw)
50 else:
51 return (None, sw)
52
53 def read_imsi(self):
54 (res, sw) = self._scc.read_binary(EF['IMSI'])
55 if sw == '9000':
56 return (dec_imsi(res), sw)
57 else:
58 return (None, sw)
59
60 def update_imsi(self, imsi):
61 data, sw = self._scc.update_binary(EF['IMSI'], enc_imsi(imsi))
62 return sw
63
64 def update_acc(self, acc):
65 data, sw = self._scc.update_binary(EF['ACC'], lpad(acc, 4))
66 return sw
67
68 def update_hplmn_act(self, mcc, mnc, access_tech='FFFF'):
69 """
70 Update Home PLMN with access technology bit-field
71
72 See Section "10.3.37 EFHPLMNwAcT (HPLMN Selector with Access Technology)"
73 in ETSI TS 151 011 for the details of the access_tech field coding.
74 Some common values:
75 access_tech = '0080' # Only GSM is selected
76 access_tech = 'FFFF' # All technologues selected, even Reserved for Future Use ones
77 """
78 # get size and write EF.HPLMNwAcT
Supreeth Herle2d785972019-11-30 11:00:10 +010079 data = self._scc.read_binary(EF['HPLMNwAcT'], length=None, offset=0)
80 size = len(data[0])/2
Alexander Chemeriseb6807d2017-07-18 17:04:38 +030081 hplmn = enc_plmn(mcc, mnc)
82 content = hplmn + access_tech
83 data, sw = self._scc.update_binary(EF['HPLMNwAcT'], content + 'ffffff0000' * (size/5-1))
84 return sw
85
Philipp Maierc8ce82a2018-07-04 17:57:20 +020086 def update_oplmn_act(self, mcc, mnc, access_tech='FFFF'):
87 """
Denis 'GNUtoo' Carikli84d2cb32019-09-12 01:46:25 +020088 See note in update_hplmn_act()
Philipp Maierc8ce82a2018-07-04 17:57:20 +020089 """
90 # get size and write EF.OPLMNwAcT
Denis 'GNUtoo' Carikli84d2cb32019-09-12 01:46:25 +020091 data = self._scc.read_binary(EF['OPLMNwAcT'], length=None, offset=0)
92 size = len(data[0])/2
Philipp Maierc8ce82a2018-07-04 17:57:20 +020093 hplmn = enc_plmn(mcc, mnc)
94 content = hplmn + access_tech
95 data, sw = self._scc.update_binary(EF['OPLMNwAcT'], content + 'ffffff0000' * (size/5-1))
96 return sw
97
98 def update_plmn_act(self, mcc, mnc, access_tech='FFFF'):
99 """
Denis 'GNUtoo' Carikli84d2cb32019-09-12 01:46:25 +0200100 See note in update_hplmn_act()
Philipp Maierc8ce82a2018-07-04 17:57:20 +0200101 """
102 # get size and write EF.PLMNwAcT
Denis 'GNUtoo' Carikli84d2cb32019-09-12 01:46:25 +0200103 data = self._scc.read_binary(EF['PLMNwAcT'], length=None, offset=0)
104 size = len(data[0])/2
Philipp Maierc8ce82a2018-07-04 17:57:20 +0200105 hplmn = enc_plmn(mcc, mnc)
106 content = hplmn + access_tech
107 data, sw = self._scc.update_binary(EF['PLMNwAcT'], content + 'ffffff0000' * (size/5-1))
108 return sw
109
Denis 'GNUtoo' Carikli84d2cb32019-09-12 01:46:25 +0200110 def update_plmnsel(self, mcc, mnc):
111 data = self._scc.read_binary(EF['PLMNsel'], length=None, offset=0)
112 size = len(data[0])/2
Philipp Maier5bf42602018-07-11 23:23:40 +0200113 hplmn = enc_plmn(mcc, mnc)
Philipp Maieraf9ae8b2018-07-13 11:15:49 +0200114 data, sw = self._scc.update_binary(EF['PLMNsel'], hplmn + 'ff' * (size-3))
115 return sw
Philipp Maier5bf42602018-07-11 23:23:40 +0200116
Alexander Chemeriseb6807d2017-07-18 17:04:38 +0300117 def update_smsp(self, smsp):
118 data, sw = self._scc.update_record(EF['SMSP'], 1, rpad(smsp, 84))
119 return sw
120
Philipp Maieree908ae2019-03-21 16:21:12 +0100121 def update_ad(self, mnc):
Denis 'GNUtoo' Carikli84d2cb32019-09-12 01:46:25 +0200122 #See also: 3GPP TS 31.102, chapter 4.2.18
123 mnclen = len(str(mnc))
124 if mnclen == 1:
125 mnclen = 2
126 if mnclen > 3:
Philipp Maieree908ae2019-03-21 16:21:12 +0100127 raise RuntimeError('unable to calculate proper mnclen')
128
Denis 'GNUtoo' Carikli84d2cb32019-09-12 01:46:25 +0200129 data = self._scc.read_binary(EF['AD'], length=None, offset=0)
130 size = len(data[0])/2
131 content = data[0][0:6] + "%02X" % mnclen
Philipp Maieree908ae2019-03-21 16:21:12 +0100132 data, sw = self._scc.update_binary(EF['AD'], content)
133 return sw
134
Alexander Chemeriseb6807d2017-07-18 17:04:38 +0300135 def read_spn(self):
136 (spn, sw) = self._scc.read_binary(EF['SPN'])
137 if sw == '9000':
138 return (dec_spn(spn), sw)
139 else:
140 return (None, sw)
141
142 def update_spn(self, name, hplmn_disp=False, oplmn_disp=False):
143 content = enc_spn(name, hplmn_disp, oplmn_disp)
144 data, sw = self._scc.update_binary(EF['SPN'], rpad(content, 32))
145 return sw
146
Philipp Maier0ad5bcf2019-12-31 17:55:47 +0100147 # Read the (full) AID for either ISIM or USIM application
148 def read_aid(self, isim = False):
149
150 # First (known) halves of the AID
151 aid_usim = "a0000000871002"
152 aid_isim = "a0000000871004"
153
154 # Select which one to look for
155 if isim:
156 aid = aid_isim
157 else:
158 aid = aid_usim
159
160 # Find out how many records the EF.DIR has, then go through
161 # all records and try to find the AID we are looking for
162 aid_record_count = self._scc.record_count(['2F00'])
163 for i in range(0, aid_record_count):
164 record = self._scc.read_record(['2F00'], i + 1)
165 if aid in record[0]:
166 aid_len = int(record[0][6:8], 16)
167 return record[0][8:8 + aid_len * 2]
168
169 return None
170
Sylvain Munaut76504e02010-12-07 00:24:32 +0100171
172class _MagicSimBase(Card):
173 """
174 Theses cards uses several record based EFs to store the provider infos,
175 each possible provider uses a specific record number in each EF. The
176 indexes used are ( where N is the number of providers supported ) :
177 - [2 .. N+1] for the operator name
Supreeth Herle9ca41c12020-01-21 12:50:30 +0100178 - [1 .. N] for the programable EFs
Sylvain Munaut76504e02010-12-07 00:24:32 +0100179
180 * 3f00/7f4d/8f0c : Operator Name
181
182 bytes 0-15 : provider name, padded with 0xff
183 byte 16 : length of the provider name
184 byte 17 : 01 for valid records, 00 otherwise
185
186 * 3f00/7f4d/8f0d : Programmable Binary EFs
187
188 * 3f00/7f4d/8f0e : Programmable Record EFs
189
190 """
191
192 @classmethod
193 def autodetect(kls, scc):
194 try:
195 for p, l, t in kls._files.values():
196 if not t:
197 continue
198 if scc.record_size(['3f00', '7f4d', p]) != l:
199 return None
200 except:
201 return None
202
203 return kls(scc)
204
205 def _get_count(self):
206 """
207 Selects the file and returns the total number of entries
208 and entry size
209 """
210 f = self._files['name']
211
212 r = self._scc.select_file(['3f00', '7f4d', f[0]])
213 rec_len = int(r[-1][28:30], 16)
214 tlen = int(r[-1][4:8],16)
215 rec_cnt = (tlen / rec_len) - 1;
216
217 if (rec_cnt < 1) or (rec_len != f[1]):
218 raise RuntimeError('Bad card type')
219
220 return rec_cnt
221
222 def program(self, p):
223 # Go to dir
224 self._scc.select_file(['3f00', '7f4d'])
225
226 # Home PLMN in PLMN_Sel format
Alexander Chemeris7be92ff2013-07-10 11:18:06 +0400227 hplmn = enc_plmn(p['mcc'], p['mnc'])
Sylvain Munaut76504e02010-12-07 00:24:32 +0100228
229 # Operator name ( 3f00/7f4d/8f0c )
230 self._scc.update_record(self._files['name'][0], 2,
231 rpad(b2h(p['name']), 32) + ('%02x' % len(p['name'])) + '01'
232 )
233
234 # ICCID/IMSI/Ki/HPLMN ( 3f00/7f4d/8f0d )
235 v = ''
236
237 # inline Ki
238 if self._ki_file is None:
239 v += p['ki']
240
241 # ICCID
Alexander Chemeris7be92ff2013-07-10 11:18:06 +0400242 v += '3f00' + '2fe2' + '0a' + enc_iccid(p['iccid'])
Sylvain Munaut76504e02010-12-07 00:24:32 +0100243
244 # IMSI
Alexander Chemeris7be92ff2013-07-10 11:18:06 +0400245 v += '7f20' + '6f07' + '09' + enc_imsi(p['imsi'])
Sylvain Munaut76504e02010-12-07 00:24:32 +0100246
247 # Ki
248 if self._ki_file:
249 v += self._ki_file + '10' + p['ki']
250
251 # PLMN_Sel
252 v+= '6f30' + '18' + rpad(hplmn, 36)
253
Alexander Chemeris21885242013-07-02 16:56:55 +0400254 # ACC
255 # This doesn't work with "fake" SuperSIM cards,
256 # but will hopefully work with real SuperSIMs.
257 if p.get('acc') is not None:
258 v+= '6f78' + '02' + lpad(p['acc'], 4)
259
Sylvain Munaut76504e02010-12-07 00:24:32 +0100260 self._scc.update_record(self._files['b_ef'][0], 1,
261 rpad(v, self._files['b_ef'][1]*2)
262 )
263
264 # SMSP ( 3f00/7f4d/8f0e )
265 # FIXME
266
267 # Write PLMN_Sel forcefully as well
268 r = self._scc.select_file(['3f00', '7f20', '6f30'])
269 tl = int(r[-1][4:8], 16)
270
Alexander Chemeris7be92ff2013-07-10 11:18:06 +0400271 hplmn = enc_plmn(p['mcc'], p['mnc'])
Sylvain Munaut76504e02010-12-07 00:24:32 +0100272 self._scc.update_binary('6f30', hplmn + 'ff' * (tl-3))
273
274 def erase(self):
275 # Dummy
276 df = {}
277 for k, v in self._files.iteritems():
278 ofs = 1
279 fv = v[1] * 'ff'
280 if k == 'name':
281 ofs = 2
282 fv = fv[0:-4] + '0000'
283 df[v[0]] = (fv, ofs)
284
285 # Write
286 for n in range(0,self._get_count()):
287 for k, (msg, ofs) in df.iteritems():
288 self._scc.update_record(['3f00', '7f4d', k], n + ofs, msg)
289
290
291class SuperSim(_MagicSimBase):
292
293 name = 'supersim'
294
295 _files = {
296 'name' : ('8f0c', 18, True),
297 'b_ef' : ('8f0d', 74, True),
298 'r_ef' : ('8f0e', 50, True),
299 }
300
301 _ki_file = None
302
303
304class MagicSim(_MagicSimBase):
305
306 name = 'magicsim'
307
308 _files = {
309 'name' : ('8f0c', 18, True),
310 'b_ef' : ('8f0d', 130, True),
311 'r_ef' : ('8f0e', 102, False),
312 }
313
314 _ki_file = '6f1b'
315
316
317class FakeMagicSim(Card):
318 """
319 Theses cards have a record based EF 3f00/000c that contains the provider
320 informations. See the program method for its format. The records go from
321 1 to N.
322 """
323
324 name = 'fakemagicsim'
325
326 @classmethod
327 def autodetect(kls, scc):
328 try:
329 if scc.record_size(['3f00', '000c']) != 0x5a:
330 return None
331 except:
332 return None
333
334 return kls(scc)
335
336 def _get_infos(self):
337 """
338 Selects the file and returns the total number of entries
339 and entry size
340 """
341
342 r = self._scc.select_file(['3f00', '000c'])
343 rec_len = int(r[-1][28:30], 16)
344 tlen = int(r[-1][4:8],16)
345 rec_cnt = (tlen / rec_len) - 1;
346
347 if (rec_cnt < 1) or (rec_len != 0x5a):
348 raise RuntimeError('Bad card type')
349
350 return rec_cnt, rec_len
351
352 def program(self, p):
353 # Home PLMN
354 r = self._scc.select_file(['3f00', '7f20', '6f30'])
355 tl = int(r[-1][4:8], 16)
356
Alexander Chemeris7be92ff2013-07-10 11:18:06 +0400357 hplmn = enc_plmn(p['mcc'], p['mnc'])
Sylvain Munaut76504e02010-12-07 00:24:32 +0100358 self._scc.update_binary('6f30', hplmn + 'ff' * (tl-3))
359
360 # Get total number of entries and entry size
361 rec_cnt, rec_len = self._get_infos()
362
363 # Set first entry
364 entry = (
Philipp Maier45daa922019-04-01 15:49:45 +0200365 '81' + # 1b Status: Valid & Active
Sylvain Munaut76504e02010-12-07 00:24:32 +0100366 rpad(b2h(p['name'][0:14]), 28) + # 14b Entry Name
Philipp Maier45daa922019-04-01 15:49:45 +0200367 enc_iccid(p['iccid']) + # 10b ICCID
368 enc_imsi(p['imsi']) + # 9b IMSI_len + id_type(9) + IMSI
369 p['ki'] + # 16b Ki
370 lpad(p['smsp'], 80) # 40b SMSP (padded with ff if needed)
Sylvain Munaut76504e02010-12-07 00:24:32 +0100371 )
372 self._scc.update_record('000c', 1, entry)
373
374 def erase(self):
375 # Get total number of entries and entry size
376 rec_cnt, rec_len = self._get_infos()
377
378 # Erase all entries
379 entry = 'ff' * rec_len
380 for i in range(0, rec_cnt):
381 self._scc.update_record('000c', 1+i, entry)
382
Sylvain Munaut5da8d4e2013-07-02 15:13:24 +0200383
Harald Welte3156d902011-03-22 21:48:19 +0100384class GrcardSim(Card):
385 """
386 Greencard (grcard.cn) HZCOS GSM SIM
387 These cards have a much more regular ISO 7816-4 / TS 11.11 structure,
388 and use standard UPDATE RECORD / UPDATE BINARY commands except for Ki.
389 """
390
391 name = 'grcardsim'
392
393 @classmethod
394 def autodetect(kls, scc):
395 return None
396
397 def program(self, p):
398 # We don't really know yet what ADM PIN 4 is about
399 #self._scc.verify_chv(4, h2b("4444444444444444"))
400
401 # Authenticate using ADM PIN 5
Jan Balkec3ebd332015-01-26 12:22:55 +0100402 if p['pin_adm']:
Philipp Maiera3de5a32018-08-23 10:27:04 +0200403 pin = h2b(p['pin_adm'])
Jan Balkec3ebd332015-01-26 12:22:55 +0100404 else:
405 pin = h2b("4444444444444444")
406 self._scc.verify_chv(5, pin)
Harald Welte3156d902011-03-22 21:48:19 +0100407
408 # EF.ICCID
409 r = self._scc.select_file(['3f00', '2fe2'])
Alexander Chemeris7be92ff2013-07-10 11:18:06 +0400410 data, sw = self._scc.update_binary('2fe2', enc_iccid(p['iccid']))
Harald Welte3156d902011-03-22 21:48:19 +0100411
412 # EF.IMSI
413 r = self._scc.select_file(['3f00', '7f20', '6f07'])
Alexander Chemeris7be92ff2013-07-10 11:18:06 +0400414 data, sw = self._scc.update_binary('6f07', enc_imsi(p['imsi']))
Harald Welte3156d902011-03-22 21:48:19 +0100415
416 # EF.ACC
Alexander Chemeris21885242013-07-02 16:56:55 +0400417 if p.get('acc') is not None:
418 data, sw = self._scc.update_binary('6f78', lpad(p['acc'], 4))
Harald Welte3156d902011-03-22 21:48:19 +0100419
420 # EF.SMSP
Denis 'GNUtoo' Carikli84d2cb32019-09-12 01:46:25 +0200421 if p.get('smsp'):
Harald Welte23888da2019-08-28 23:19:11 +0200422 r = self._scc.select_file(['3f00', '7f10', '6f42'])
423 data, sw = self._scc.update_record('6f42', 1, lpad(p['smsp'], 80))
Harald Welte3156d902011-03-22 21:48:19 +0100424
425 # Set the Ki using proprietary command
426 pdu = '80d4020010' + p['ki']
427 data, sw = self._scc._tp.send_apdu(pdu)
428
429 # EF.HPLMN
430 r = self._scc.select_file(['3f00', '7f20', '6f30'])
431 size = int(r[-1][4:8], 16)
Alexander Chemeris7be92ff2013-07-10 11:18:06 +0400432 hplmn = enc_plmn(p['mcc'], p['mnc'])
Harald Welte3156d902011-03-22 21:48:19 +0100433 self._scc.update_binary('6f30', hplmn + 'ff' * (size-3))
434
435 # EF.SPN (Service Provider Name)
436 r = self._scc.select_file(['3f00', '7f20', '6f30'])
437 size = int(r[-1][4:8], 16)
438 # FIXME
439
440 # FIXME: EF.MSISDN
441
442 def erase(self):
443 return
Sylvain Munaut76504e02010-12-07 00:24:32 +0100444
Harald Weltee10394b2011-12-07 12:34:14 +0100445class SysmoSIMgr1(GrcardSim):
446 """
447 sysmocom sysmoSIM-GR1
448 These cards have a much more regular ISO 7816-4 / TS 11.11 structure,
449 and use standard UPDATE RECORD / UPDATE BINARY commands except for Ki.
450 """
451 name = 'sysmosim-gr1'
452
Denis 'GNUtoo' Carikli84d2cb32019-09-12 01:46:25 +0200453 @classmethod
Philipp Maier087feff2018-08-23 09:41:36 +0200454 def autodetect(kls, scc):
455 try:
456 # Look for ATR
457 if scc.get_atr() == toBytes("3B 99 18 00 11 88 22 33 44 55 66 77 60"):
458 return kls(scc)
459 except:
460 return None
461 return None
Sylvain Munaut5da8d4e2013-07-02 15:13:24 +0200462
Holger Hans Peter Freyther4d91bf42012-03-22 14:28:38 +0100463class SysmoUSIMgr1(Card):
464 """
465 sysmocom sysmoUSIM-GR1
466 """
467 name = 'sysmoUSIM-GR1'
468
469 @classmethod
470 def autodetect(kls, scc):
471 # TODO: Access the ATR
472 return None
473
474 def program(self, p):
475 # TODO: check if verify_chv could be used or what it needs
476 # self._scc.verify_chv(0x0A, [0x33,0x32,0x32,0x31,0x33,0x32,0x33,0x32])
477 # Unlock the card..
478 data, sw = self._scc._tp.send_apdu_checksw("0020000A083332323133323332")
479
480 # TODO: move into SimCardCommands
Holger Hans Peter Freyther4d91bf42012-03-22 14:28:38 +0100481 par = ( p['ki'] + # 16b K
Alexander Chemeris7be92ff2013-07-10 11:18:06 +0400482 p['opc'] + # 32b OPC
483 enc_iccid(p['iccid']) + # 10b ICCID
484 enc_imsi(p['imsi']) # 9b IMSI_len + id_type(9) + IMSI
Holger Hans Peter Freyther4d91bf42012-03-22 14:28:38 +0100485 )
486 data, sw = self._scc._tp.send_apdu_checksw("0099000033" + par)
487
488 def erase(self):
489 return
490
Sylvain Munaut053c8952013-07-02 15:12:32 +0200491
Sylvain Munaut2fc205c2013-12-23 17:22:56 +0100492class SysmoSIMgr2(Card):
493 """
494 sysmocom sysmoSIM-GR2
495 """
496
497 name = 'sysmoSIM-GR2'
498
499 @classmethod
500 def autodetect(kls, scc):
Alexander Chemeris8ad124a2018-01-10 14:17:55 +0900501 try:
502 # Look for ATR
503 if scc.get_atr() == toBytes("3B 7D 94 00 00 55 55 53 0A 74 86 93 0B 24 7C 4D 54 68"):
504 return kls(scc)
505 except:
506 return None
Sylvain Munaut2fc205c2013-12-23 17:22:56 +0100507 return None
508
509 def program(self, p):
510
511 # select MF
512 r = self._scc.select_file(['3f00'])
513
514 # authenticate as SUPER ADM using default key
515 self._scc.verify_chv(0x0b, h2b("3838383838383838"))
516
517 # set ADM pin using proprietary command
518 # INS: D4
519 # P1: 3A for PIN, 3B for PUK
520 # P2: CHV number, as in VERIFY CHV for PIN, and as in UNBLOCK CHV for PUK
521 # P3: 08, CHV length (curiously the PUK is also 08 length, instead of 10)
Jan Balkec3ebd332015-01-26 12:22:55 +0100522 if p['pin_adm']:
Daniel Willmann7d38d742018-06-15 07:31:50 +0200523 pin = h2b(p['pin_adm'])
Jan Balkec3ebd332015-01-26 12:22:55 +0100524 else:
525 pin = h2b("4444444444444444")
526
527 pdu = 'A0D43A0508' + b2h(pin)
Sylvain Munaut2fc205c2013-12-23 17:22:56 +0100528 data, sw = self._scc._tp.send_apdu(pdu)
529
530 # authenticate as ADM (enough to write file, and can set PINs)
Jan Balkec3ebd332015-01-26 12:22:55 +0100531
532 self._scc.verify_chv(0x05, pin)
Sylvain Munaut2fc205c2013-12-23 17:22:56 +0100533
534 # write EF.ICCID
535 data, sw = self._scc.update_binary('2fe2', enc_iccid(p['iccid']))
536
537 # select DF_GSM
538 r = self._scc.select_file(['7f20'])
539
540 # write EF.IMSI
541 data, sw = self._scc.update_binary('6f07', enc_imsi(p['imsi']))
542
543 # write EF.ACC
544 if p.get('acc') is not None:
545 data, sw = self._scc.update_binary('6f78', lpad(p['acc'], 4))
546
547 # get size and write EF.HPLMN
548 r = self._scc.select_file(['6f30'])
549 size = int(r[-1][4:8], 16)
550 hplmn = enc_plmn(p['mcc'], p['mnc'])
551 self._scc.update_binary('6f30', hplmn + 'ff' * (size-3))
552
553 # set COMP128 version 0 in proprietary file
554 data, sw = self._scc.update_binary('0001', '001000')
555
556 # set Ki in proprietary file
557 data, sw = self._scc.update_binary('0001', p['ki'], 3)
558
559 # select DF_TELECOM
560 r = self._scc.select_file(['3f00', '7f10'])
561
562 # write EF.SMSP
Denis 'GNUtoo' Carikli84d2cb32019-09-12 01:46:25 +0200563 if p.get('smsp'):
Harald Welte23888da2019-08-28 23:19:11 +0200564 data, sw = self._scc.update_record('6f42', 1, lpad(p['smsp'], 80))
Sylvain Munaut2fc205c2013-12-23 17:22:56 +0100565
566 def erase(self):
567 return
568
Jan Balke3e840672015-01-26 15:36:27 +0100569class SysmoUSIMSJS1(Card):
570 """
571 sysmocom sysmoUSIM-SJS1
572 """
573
574 name = 'sysmoUSIM-SJS1'
575
576 def __init__(self, ssc):
577 super(SysmoUSIMSJS1, self).__init__(ssc)
578 self._scc.cla_byte = "00"
Philipp Maier2d15ea02019-03-20 12:40:36 +0100579 self._scc.sel_ctrl = "0004" #request an FCP
Jan Balke3e840672015-01-26 15:36:27 +0100580
581 @classmethod
582 def autodetect(kls, scc):
Alexander Chemeris8ad124a2018-01-10 14:17:55 +0900583 try:
584 # Look for ATR
585 if scc.get_atr() == toBytes("3B 9F 96 80 1F C7 80 31 A0 73 BE 21 13 67 43 20 07 18 00 00 01 A5"):
586 return kls(scc)
587 except:
588 return None
Jan Balke3e840672015-01-26 15:36:27 +0100589 return None
590
591 def program(self, p):
592
Philipp Maiere9604882017-03-21 17:24:31 +0100593 # authenticate as ADM using default key (written on the card..)
594 if not p['pin_adm']:
595 raise ValueError("Please provide a PIN-ADM as there is no default one")
596 self._scc.verify_chv(0x0A, h2b(p['pin_adm']))
Jan Balke3e840672015-01-26 15:36:27 +0100597
598 # select MF
599 r = self._scc.select_file(['3f00'])
600
Philipp Maiere9604882017-03-21 17:24:31 +0100601 # write EF.ICCID
602 data, sw = self._scc.update_binary('2fe2', enc_iccid(p['iccid']))
603
Jan Balke3e840672015-01-26 15:36:27 +0100604 # select DF_GSM
605 r = self._scc.select_file(['7f20'])
606
Jan Balke3e840672015-01-26 15:36:27 +0100607 # set Ki in proprietary file
608 data, sw = self._scc.update_binary('00FF', p['ki'])
609
Philipp Maier1be35bf2018-07-13 11:29:03 +0200610 # set OPc in proprietary file
Daniel Willmann67acdbc2018-06-15 07:42:48 +0200611 if 'opc' in p:
612 content = "01" + p['opc']
613 data, sw = self._scc.update_binary('00F7', content)
Jan Balke3e840672015-01-26 15:36:27 +0100614
Supreeth Herle7947d922019-06-08 07:50:53 +0200615 # set Service Provider Name
Supreeth Herle840a9e22020-01-21 13:32:46 +0100616 if p.get('name') is not None:
617 content = enc_spn(p['name'], True, True)
618 data, sw = self._scc.update_binary('6F46', rpad(content, 32))
Supreeth Herle7947d922019-06-08 07:50:53 +0200619
Supreeth Herlec8796a32019-12-23 12:23:42 +0100620 if p.get('acc') is not None:
621 self.update_acc(p['acc'])
622
Jan Balke3e840672015-01-26 15:36:27 +0100623 # write EF.IMSI
624 data, sw = self._scc.update_binary('6f07', enc_imsi(p['imsi']))
625
Philipp Maier2d15ea02019-03-20 12:40:36 +0100626 # EF.PLMNsel
Denis 'GNUtoo' Carikli84d2cb32019-09-12 01:46:25 +0200627 if p.get('mcc') and p.get('mnc'):
628 sw = self.update_plmnsel(p['mcc'], p['mnc'])
629 if sw != '9000':
Philipp Maier2d15ea02019-03-20 12:40:36 +0100630 print("Programming PLMNsel failed with code %s"%sw)
631
Denis 'GNUtoo' Carikli84d2cb32019-09-12 01:46:25 +0200632 # EF.PLMNwAcT
633 if p.get('mcc') and p.get('mnc'):
Philipp Maier2d15ea02019-03-20 12:40:36 +0100634 sw = self.update_plmn_act(p['mcc'], p['mnc'])
635 if sw != '9000':
636 print("Programming PLMNwAcT failed with code %s"%sw)
637
Denis 'GNUtoo' Carikli84d2cb32019-09-12 01:46:25 +0200638 # EF.OPLMNwAcT
639 if p.get('mcc') and p.get('mnc'):
Philipp Maier2d15ea02019-03-20 12:40:36 +0100640 sw = self.update_oplmn_act(p['mcc'], p['mnc'])
641 if sw != '9000':
642 print("Programming OPLMNwAcT failed with code %s"%sw)
643
Denis 'GNUtoo' Carikli84d2cb32019-09-12 01:46:25 +0200644 # EF.AD
645 if p.get('mcc') and p.get('mnc'):
Philipp Maieree908ae2019-03-21 16:21:12 +0100646 sw = self.update_ad(p['mnc'])
647 if sw != '9000':
648 print("Programming AD failed with code %s"%sw)
Philipp Maier2d15ea02019-03-20 12:40:36 +0100649
Daniel Willmann1d087ef2017-08-31 10:08:45 +0200650 # EF.SMSP
Harald Welte23888da2019-08-28 23:19:11 +0200651 if p.get('smsp'):
652 r = self._scc.select_file(['3f00', '7f10'])
653 data, sw = self._scc.update_record('6f42', 1, lpad(p['smsp'], 104), force_len=True)
Jan Balke3e840672015-01-26 15:36:27 +0100654
Alexander Chemerise0d9d882018-01-10 14:18:32 +0900655 def erase(self):
656 return
657
658
659class FairwavesSIM(Card):
660 """
661 FairwavesSIM
662
663 The SIM card is operating according to the standard.
664 For Ki/OP/OPC programming the following files are additionally open for writing:
665 3F00/7F20/FF01 – OP/OPC:
666 byte 1 = 0x01, bytes 2-17: OPC;
667 byte 1 = 0x00, bytes 2-17: OP;
668 3F00/7F20/FF02: Ki
669 """
670
Philipp Maier5a876312019-11-11 11:01:46 +0100671 name = 'Fairwaves-SIM'
Alexander Chemerise0d9d882018-01-10 14:18:32 +0900672 # Propriatary files
673 _EF_num = {
674 'Ki': 'FF02',
675 'OP/OPC': 'FF01',
676 }
677 _EF = {
678 'Ki': DF['GSM']+[_EF_num['Ki']],
679 'OP/OPC': DF['GSM']+[_EF_num['OP/OPC']],
680 }
681
682 def __init__(self, ssc):
683 super(FairwavesSIM, self).__init__(ssc)
684 self._adm_chv_num = 0x11
685 self._adm2_chv_num = 0x12
686
687
688 @classmethod
689 def autodetect(kls, scc):
690 try:
691 # Look for ATR
692 if scc.get_atr() == toBytes("3B 9F 96 80 1F C7 80 31 A0 73 BE 21 13 67 44 22 06 10 00 00 01 A9"):
693 return kls(scc)
694 except:
695 return None
696 return None
697
698
699 def verify_adm2(self, key):
700 '''
701 Authenticate with ADM2 key.
702
703 Fairwaves SIM cards support hierarchical key structure and ADM2 key
704 is a key which has access to proprietary files (Ki and OP/OPC).
705 That said, ADM key inherits permissions of ADM2 key and thus we rarely
706 need ADM2 key per se.
707 '''
708 (res, sw) = self._scc.verify_chv(self._adm2_chv_num, key)
709 return sw
710
711
712 def read_ki(self):
713 """
714 Read Ki in proprietary file.
715
716 Requires ADM1 access level
717 """
718 return self._scc.read_binary(self._EF['Ki'])
719
720
721 def update_ki(self, ki):
722 """
723 Set Ki in proprietary file.
724
725 Requires ADM1 access level
726 """
727 data, sw = self._scc.update_binary(self._EF['Ki'], ki)
728 return sw
729
730
731 def read_op_opc(self):
732 """
733 Read Ki in proprietary file.
734
735 Requires ADM1 access level
736 """
737 (ef, sw) = self._scc.read_binary(self._EF['OP/OPC'])
738 type = 'OP' if ef[0:2] == '00' else 'OPC'
739 return ((type, ef[2:]), sw)
740
741
742 def update_op(self, op):
743 """
744 Set OP in proprietary file.
745
746 Requires ADM1 access level
747 """
748 content = '00' + op
749 data, sw = self._scc.update_binary(self._EF['OP/OPC'], content)
750 return sw
751
752
753 def update_opc(self, opc):
754 """
755 Set OPC in proprietary file.
756
757 Requires ADM1 access level
758 """
759 content = '01' + opc
760 data, sw = self._scc.update_binary(self._EF['OP/OPC'], content)
761 return sw
762
763
764 def program(self, p):
765 # authenticate as ADM1
766 if not p['pin_adm']:
767 raise ValueError("Please provide a PIN-ADM as there is no default one")
768 sw = self.verify_adm(h2b(p['pin_adm']))
769 if sw != '9000':
770 raise RuntimeError('Failed to authenticate with ADM key %s'%(p['pin_adm'],))
771
772 # TODO: Set operator name
773 if p.get('smsp') is not None:
774 sw = self.update_smsp(p['smsp'])
775 if sw != '9000':
776 print("Programming SMSP failed with code %s"%sw)
777 # This SIM doesn't support changing ICCID
778 if p.get('mcc') is not None and p.get('mnc') is not None:
779 sw = self.update_hplmn_act(p['mcc'], p['mnc'])
780 if sw != '9000':
781 print("Programming MCC/MNC failed with code %s"%sw)
782 if p.get('imsi') is not None:
783 sw = self.update_imsi(p['imsi'])
784 if sw != '9000':
785 print("Programming IMSI failed with code %s"%sw)
786 if p.get('ki') is not None:
787 sw = self.update_ki(p['ki'])
788 if sw != '9000':
789 print("Programming Ki failed with code %s"%sw)
790 if p.get('opc') is not None:
791 sw = self.update_opc(p['opc'])
792 if sw != '9000':
793 print("Programming OPC failed with code %s"%sw)
794 if p.get('acc') is not None:
795 sw = self.update_acc(p['acc'])
796 if sw != '9000':
797 print("Programming ACC failed with code %s"%sw)
Jan Balke3e840672015-01-26 15:36:27 +0100798
799 def erase(self):
800 return
801
802
Todd Neal9eeadfc2018-04-25 15:36:29 -0500803class OpenCellsSim(Card):
804 """
805 OpenCellsSim
806
807 """
808
Philipp Maier5a876312019-11-11 11:01:46 +0100809 name = 'OpenCells-SIM'
Todd Neal9eeadfc2018-04-25 15:36:29 -0500810
811 def __init__(self, ssc):
812 super(OpenCellsSim, self).__init__(ssc)
813 self._adm_chv_num = 0x0A
814
815
816 @classmethod
817 def autodetect(kls, scc):
818 try:
819 # Look for ATR
820 if scc.get_atr() == toBytes("3B 9F 95 80 1F C3 80 31 E0 73 FE 21 13 57 86 81 02 86 98 44 18 A8"):
821 return kls(scc)
822 except:
823 return None
824 return None
825
826
827 def program(self, p):
828 if not p['pin_adm']:
829 raise ValueError("Please provide a PIN-ADM as there is no default one")
830 self._scc.verify_chv(0x0A, h2b(p['pin_adm']))
831
832 # select MF
833 r = self._scc.select_file(['3f00'])
834
835 # write EF.ICCID
836 data, sw = self._scc.update_binary('2fe2', enc_iccid(p['iccid']))
837
838 r = self._scc.select_file(['7ff0'])
839
840 # set Ki in proprietary file
841 data, sw = self._scc.update_binary('FF02', p['ki'])
842
843 # set OPC in proprietary file
844 data, sw = self._scc.update_binary('FF01', p['opc'])
845
846 # select DF_GSM
847 r = self._scc.select_file(['7f20'])
848
849 # write EF.IMSI
850 data, sw = self._scc.update_binary('6f07', enc_imsi(p['imsi']))
851
Philipp Maierc8ce82a2018-07-04 17:57:20 +0200852class WavemobileSim(Card):
853 """
854 WavemobileSim
855
856 """
857
858 name = 'Wavemobile-SIM'
859
860 def __init__(self, ssc):
861 super(WavemobileSim, self).__init__(ssc)
862 self._adm_chv_num = 0x0A
863 self._scc.cla_byte = "00"
864 self._scc.sel_ctrl = "0004" #request an FCP
865
866 @classmethod
867 def autodetect(kls, scc):
868 try:
869 # Look for ATR
870 if scc.get_atr() == toBytes("3B 9F 95 80 1F C7 80 31 E0 73 F6 21 13 67 4D 45 16 00 43 01 00 8F"):
871 return kls(scc)
872 except:
873 return None
874 return None
875
876 def program(self, p):
877 if not p['pin_adm']:
878 raise ValueError("Please provide a PIN-ADM as there is no default one")
879 sw = self.verify_adm(h2b(p['pin_adm']))
880 if sw != '9000':
881 raise RuntimeError('Failed to authenticate with ADM key %s'%(p['pin_adm'],))
882
Denis 'GNUtoo' Carikli84d2cb32019-09-12 01:46:25 +0200883 # EF.ICCID
884 # TODO: Add programming of the ICCID
885 if p.get('iccid'):
Philipp Maierc8ce82a2018-07-04 17:57:20 +0200886 print("Warning: Programming of the ICCID is not implemented for this type of card.")
887
Denis 'GNUtoo' Carikli84d2cb32019-09-12 01:46:25 +0200888 # KI (Presumably a propritary file)
889 # TODO: Add programming of KI
890 if p.get('ki'):
Philipp Maierc8ce82a2018-07-04 17:57:20 +0200891 print("Warning: Programming of the KI is not implemented for this type of card.")
892
Denis 'GNUtoo' Carikli84d2cb32019-09-12 01:46:25 +0200893 # OPc (Presumably a propritary file)
894 # TODO: Add programming of OPc
895 if p.get('opc'):
Philipp Maierc8ce82a2018-07-04 17:57:20 +0200896 print("Warning: Programming of the OPc is not implemented for this type of card.")
897
Denis 'GNUtoo' Carikli84d2cb32019-09-12 01:46:25 +0200898 # EF.SMSP
Philipp Maierc8ce82a2018-07-04 17:57:20 +0200899 if p.get('smsp'):
900 sw = self.update_smsp(p['smsp'])
901 if sw != '9000':
902 print("Programming SMSP failed with code %s"%sw)
903
Denis 'GNUtoo' Carikli84d2cb32019-09-12 01:46:25 +0200904 # EF.IMSI
Philipp Maierc8ce82a2018-07-04 17:57:20 +0200905 if p.get('imsi'):
906 sw = self.update_imsi(p['imsi'])
907 if sw != '9000':
908 print("Programming IMSI failed with code %s"%sw)
909
910 # EF.ACC
911 if p.get('acc'):
912 sw = self.update_acc(p['acc'])
913 if sw != '9000':
914 print("Programming ACC failed with code %s"%sw)
915
916 # EF.PLMNsel
Denis 'GNUtoo' Carikli84d2cb32019-09-12 01:46:25 +0200917 if p.get('mcc') and p.get('mnc'):
918 sw = self.update_plmnsel(p['mcc'], p['mnc'])
919 if sw != '9000':
Philipp Maierc8ce82a2018-07-04 17:57:20 +0200920 print("Programming PLMNsel failed with code %s"%sw)
921
Denis 'GNUtoo' Carikli84d2cb32019-09-12 01:46:25 +0200922 # EF.PLMNwAcT
923 if p.get('mcc') and p.get('mnc'):
Philipp Maierc8ce82a2018-07-04 17:57:20 +0200924 sw = self.update_plmn_act(p['mcc'], p['mnc'])
925 if sw != '9000':
926 print("Programming PLMNwAcT failed with code %s"%sw)
927
Denis 'GNUtoo' Carikli84d2cb32019-09-12 01:46:25 +0200928 # EF.OPLMNwAcT
929 if p.get('mcc') and p.get('mnc'):
Philipp Maierc8ce82a2018-07-04 17:57:20 +0200930 sw = self.update_oplmn_act(p['mcc'], p['mnc'])
931 if sw != '9000':
932 print("Programming OPLMNwAcT failed with code %s"%sw)
933
Denis 'GNUtoo' Carikli84d2cb32019-09-12 01:46:25 +0200934 # EF.AD
935 if p.get('mcc') and p.get('mnc'):
Philipp Maier6e507a72019-04-01 16:33:48 +0200936 sw = self.update_ad(p['mnc'])
937 if sw != '9000':
938 print("Programming AD failed with code %s"%sw)
939
Denis 'GNUtoo' Carikli84d2cb32019-09-12 01:46:25 +0200940 return None
Philipp Maierc8ce82a2018-07-04 17:57:20 +0200941
942 def erase(self):
943 return
944
Todd Neal9eeadfc2018-04-25 15:36:29 -0500945
Philipp Maier0ad5bcf2019-12-31 17:55:47 +0100946class SysmoISIMSJA2(Card):
947 """
948 sysmocom sysmoISIM-SJA2
949 """
950
951 name = 'sysmoISIM-SJA2'
952
953 def __init__(self, ssc):
954 super(SysmoISIMSJA2, self).__init__(ssc)
955 self._scc.cla_byte = "00"
956 self._scc.sel_ctrl = "0004" #request an FCP
957
958 @classmethod
959 def autodetect(kls, scc):
960 try:
961 # Try card model #1
962 atr = "3B 9F 96 80 1F 87 80 31 E0 73 FE 21 1B 67 4A 4C 75 30 34 05 4B A9"
963 if scc.get_atr() == toBytes(atr):
964 return kls(scc)
965
966 # Try card model #2
967 atr = "3B 9F 96 80 1F 87 80 31 E0 73 FE 21 1B 67 4A 4C 75 31 33 02 51 B2"
968 if scc.get_atr() == toBytes(atr):
969 return kls(scc)
970 except:
971 return None
972 return None
973
974 def program(self, p):
975 # authenticate as ADM using default key (written on the card..)
976 if not p['pin_adm']:
977 raise ValueError("Please provide a PIN-ADM as there is no default one")
978 self._scc.verify_chv(0x0A, h2b(p['pin_adm']))
979
980 # This type of card does not allow to reprogram the ICCID.
981 # Reprogramming the ICCID would mess up the card os software
982 # license management, so the ICCID must be kept at its factory
983 # setting!
984 if p.get('iccid'):
985 print("Warning: Programming of the ICCID is not implemented for this type of card.")
986
987 # select DF_GSM
988 self._scc.select_file(['7f20'])
989
990 # write EF.IMSI
991 if p.get('imsi'):
992 self._scc.update_binary('6f07', enc_imsi(p['imsi']))
993
994 # EF.PLMNsel
995 if p.get('mcc') and p.get('mnc'):
996 sw = self.update_plmnsel(p['mcc'], p['mnc'])
997 if sw != '9000':
998 print("Programming PLMNsel failed with code %s"%sw)
999
1000 # EF.PLMNwAcT
1001 if p.get('mcc') and p.get('mnc'):
1002 sw = self.update_plmn_act(p['mcc'], p['mnc'])
1003 if sw != '9000':
1004 print("Programming PLMNwAcT failed with code %s"%sw)
1005
1006 # EF.OPLMNwAcT
1007 if p.get('mcc') and p.get('mnc'):
1008 sw = self.update_oplmn_act(p['mcc'], p['mnc'])
1009 if sw != '9000':
1010 print("Programming OPLMNwAcT failed with code %s"%sw)
1011
1012 # EF.AD
1013 if p.get('mcc') and p.get('mnc'):
1014 sw = self.update_ad(p['mnc'])
1015 if sw != '9000':
1016 print("Programming AD failed with code %s"%sw)
1017
1018 # EF.SMSP
1019 if p.get('smsp'):
1020 r = self._scc.select_file(['3f00', '7f10'])
1021 data, sw = self._scc.update_record('6f42', 1, lpad(p['smsp'], 104), force_len=True)
1022
1023 # update EF-SIM_AUTH_KEY (and EF-USIM_AUTH_KEY_2G, which is
1024 # hard linked to EF-USIM_AUTH_KEY)
1025 self._scc.select_file(['3f00'])
1026 self._scc.select_file(['a515'])
1027 if p.get('ki'):
1028 self._scc.update_binary('6f20', p['ki'], 1)
1029 if p.get('opc'):
1030 self._scc.update_binary('6f20', p['opc'], 17)
1031
1032 # update EF-USIM_AUTH_KEY in ADF.ISIM
1033 self._scc.select_file(['3f00'])
1034 aid = self.read_aid(isim = True)
1035 self._scc.select_adf(aid)
1036 if p.get('ki'):
1037 self._scc.update_binary('af20', p['ki'], 1)
1038 if p.get('opc'):
1039 self._scc.update_binary('af20', p['opc'], 17)
1040
1041 # update EF-USIM_AUTH_KEY in ADF.USIM
1042 self._scc.select_file(['3f00'])
1043 aid = self.read_aid()
1044 self._scc.select_adf(aid)
1045 if p.get('ki'):
1046 self._scc.update_binary('af20', p['ki'], 1)
1047 if p.get('opc'):
1048 self._scc.update_binary('af20', p['opc'], 17)
1049
1050 return
1051
1052 def erase(self):
1053 return
1054
1055
Todd Neal9eeadfc2018-04-25 15:36:29 -05001056# In order for autodetection ...
Harald Weltee10394b2011-12-07 12:34:14 +01001057_cards_classes = [ FakeMagicSim, SuperSim, MagicSim, GrcardSim,
Alexander Chemerise0d9d882018-01-10 14:18:32 +09001058 SysmoSIMgr1, SysmoSIMgr2, SysmoUSIMgr1, SysmoUSIMSJS1,
Philipp Maier0ad5bcf2019-12-31 17:55:47 +01001059 FairwavesSIM, OpenCellsSim, WavemobileSim, SysmoISIMSJA2 ]
Alexander Chemeris8ad124a2018-01-10 14:17:55 +09001060
1061def card_autodetect(scc):
1062 for kls in _cards_classes:
1063 card = kls.autodetect(scc)
1064 if card is not None:
1065 card.reset()
1066 return card
1067 return None