Small refactor for rp2 and rp3 + add new sign keys

This commit is contained in:
QCDLZCLW3K
2022-05-12 05:18:07 +09:00
parent ce75e149f7
commit 926bbf2e10
16 changed files with 179 additions and 175 deletions
+9
View File
@@ -53,6 +53,15 @@
#define SECURITY_MCODE_GAME_JB_1 "H44"
#define SECURITY_MCODE_GAME_JB_3 "J44"
/* DDR */
#define SECURITY_MCODE_GAME_DDR_X "HDX"
/* pop'n music */
#define SECURITY_MCODE_GAME_POPN_15 "G15"
#define SECURITY_MCODE_GAME_POPN_16 "H16"
#define SECURITY_MCODE_GAME_POPN_17 "I17"
#define SECURITY_MCODE_GAME_POPN_18 "J39"
/* Region */
#define SECURITY_MCODE_REGION_ASIA 'A'
#define SECURITY_MCODE_REGION_JAPAN 'J'
+14 -2
View File
@@ -3,8 +3,20 @@
const struct security_rp_sign_key security_rp_sign_key_white_eamuse = {
.data = "E-AMUSE3"};
const struct security_rp_sign_key security_rp_sign_key_black_ps2 = {
const struct security_rp_sign_key security_rp_sign_key_black_python2 = {
.data = "GENTAKAH"};
const struct security_rp_sign_key security_rp_sign_key_black_gfdmv4 = {
.data = "UDONHRKI"};
.data = "UDONHRKI"};
const struct security_rp_sign_key security_rp_sign_key_black_gfdmv8 = {
.data = "SHAMOSAN"};
const struct security_rp_sign_key security_rp_sign_key_black_ddrx = {
.data = "573PROJE"};
const struct security_rp_sign_key security_rp_sign_key_black_iidx = {
.data = "2DXGLDAC"};
const struct security_rp_sign_key security_rp_sign_key_black_popn = {
.data = "POPNG15A"};
+38 -6
View File
@@ -11,23 +11,55 @@ struct security_rp_sign_key {
};
/**
* Signing key used to create eeprom signitures for all white eamuse dongles.
* Signing key used to create eeprom signatures for all white eamuse dongles
*/
extern const struct security_rp_sign_key security_rp_sign_key_white_eamuse;
/**
* Signing key used to create eeprom signitures for all black dongles used
* on PS2 games (as far as we are aware of).
* Signing key used to create eeprom signatures for all black dongles used
* on Python 2 games.
*/
extern const struct security_rp_sign_key security_rp_sign_key_black_ps2;
extern const struct security_rp_sign_key security_rp_sign_key_black_python2;
/**
* Signing key used to create eeprom signitures for all black dongles used
* Signing key used to create eeprom signatures for all black dongles used
* on the following games:
*
* - GF & DM V4 to V8 (TODO needs verification)
* - GF & DM V4 to V7
* - jubeat (1)
*/
extern const struct security_rp_sign_key security_rp_sign_key_black_gfdmv4;
/**
* Signing key used to create eeprom signatures for all black dongles used
* on the following games:
*
* - GF & DM V8, XG to XG3, Gitadora series
*/
extern const struct security_rp_sign_key security_rp_sign_key_black_gfdmv8;
/**
* Signing key used to create eeprom signatures for all black dongles used
* on the following games:
*
* - DDR X
*/
extern const struct security_rp_sign_key security_rp_sign_key_black_ddrx;
/**
* Signing key used to create eeprom signatures for all black dongles used
* on the following games:
*
* - IIDX 14 to 17
*/
extern const struct security_rp_sign_key security_rp_sign_key_black_iidx;
/**
* Signing key used to create eeprom signatures for all black dongles used
* on the following games:
*
* - pop'n music 15 to 17
*/
extern const struct security_rp_sign_key security_rp_sign_key_black_popn;
#endif
+1 -1
View File
@@ -10,7 +10,7 @@
/**
* Structure for data which is usually stored in the eeprom section of the
* dongle. This contains a signiture to verify the ROM's contents as well as
* dongle. This contains a signature to verify the ROM's contents as well as
* the game this dongle is signed for.
*/
struct security_rp_eeprom {
+14 -43
View File
@@ -1,15 +1,10 @@
#include "security/rp2.h"
#include "security/rp-util.h"
#include "security/util.h"
#include "util/crypto.h"
#include "util/log.h"
static const uint8_t security_rp2_sign_key_base_black[] = {
0x32, 0x44, 0x58, 0x47, 0x4C, 0x44, 0x41, 0x43};
static const uint8_t security_rp2_sign_key_base_white[] = {
0x45, 0x2D, 0x41, 0x4D, 0x55, 0x53, 0x45, 0x33};
static uint8_t security_rp2_signature_scramble_table[16] = {0x0C,
0x02,
0x0F,
@@ -27,7 +22,7 @@ static uint8_t security_rp2_signature_scramble_table[16] = {0x0C,
0x08,
0x06};
static void security_rp2_create_signiture(
void security_rp2_create_signature(
const uint8_t *plug_id_enc, const uint8_t *sign_key_packed, uint8_t *out)
{
uint8_t data[14];
@@ -55,56 +50,32 @@ static void security_rp2_create_signiture(
void security_rp2_generate_signed_eeprom_data(
enum security_rp_util_rp_type type,
const struct security_mcode *boot_version,
const struct security_rp_sign_key *sign_key,
const struct security_mcode *plug_mcode,
const struct security_id *plug_id,
struct security_rp2_eeprom *out)
{
uint8_t sign_key[8];
uint8_t sign_key_tmp[8];
uint8_t plug_id_enc[8];
char *boot_version_str;
log_assert(boot_version);
log_assert(sign_key);
log_assert(plug_mcode);
log_assert(plug_id);
log_assert(out);
boot_version_str = (char *) boot_version;
memcpy(sign_key_tmp, sign_key, sizeof(sign_key_tmp));
/* -------------------------------- */
switch (type) {
case SECURITY_RP_UTIL_RP_TYPE_BLACK:
memcpy(
sign_key, security_rp2_sign_key_base_black, sizeof(sign_key));
sign_key[0] = boot_version_str[0] ^ sign_key[0];
sign_key[1] ^= boot_version_str[1];
sign_key[2] = boot_version_str[2] ^ sign_key[2];
sign_key[3] = boot_version_str[3] ^ sign_key[3];
sign_key[4] = boot_version_str[4] ^ sign_key[4];
sign_key[5] ^= boot_version_str[5];
sign_key[6] = boot_version_str[6] ^ sign_key[6];
sign_key[7] = boot_version_str[7] ^ sign_key[7];
break;
case SECURITY_RP_UTIL_RP_TYPE_WHITE:
memcpy(
sign_key, security_rp2_sign_key_base_white, sizeof(sign_key));
break;
default:
log_assert(false);
break;
if (type == SECURITY_RP_UTIL_RP_TYPE_BLACK) {
for (int i = 0; i < sizeof(sign_key_tmp); i++) {
sign_key_tmp[i] ^= ((const uint8_t *) plug_mcode)[i];
}
}
for (uint8_t i = 0; i < sizeof(sign_key); i++) {
sign_key[i] ^= 0x40;
for (uint8_t i = 0; i < sizeof(sign_key_tmp); i++) {
sign_key_tmp[i] ^= 0x40;
}
security_util_8_to_6_encode(sign_key, sign_key);
security_util_8_to_6_encode(sign_key_tmp, sign_key_tmp);
plug_id_enc[0] = plug_id->checksum;
plug_id_enc[1] = plug_id->id[2];
@@ -115,7 +86,7 @@ void security_rp2_generate_signed_eeprom_data(
plug_id_enc[6] = plug_id->id[7];
plug_id_enc[7] = plug_id->id[1];
security_rp2_create_signiture(plug_id_enc, sign_key, (uint8_t *) out);
security_rp2_create_signature(plug_id_enc, sign_key_tmp, (uint8_t *) out);
security_util_8_to_6_encode(
(const uint8_t *) plug_mcode, out->packed_payload);
+19 -2
View File
@@ -6,11 +6,12 @@
#include "security/id.h"
#include "security/mcode.h"
#include "security/rp-sign-key.h"
#include "security/rp-util.h"
/**
* Structure for data which is usually stored in the eeprom section of the
* dongle. This contains a signiture to verify the ROM's contents as well as
* dongle. This contains a signature to verify the ROM's contents as well as
* the game this dongle is signed for.
*/
struct security_rp2_eeprom {
@@ -18,6 +19,18 @@ struct security_rp2_eeprom {
uint8_t packed_payload[6];
};
/**
* Generates the signature for the given plug id. Used by both rp2 and rp3.
*
* @param plug_id The scrambled form of the plug id stored on the plug.
* @param sign_key_packed The packed key to use for generating the signature.
* @param out Pointer to the buffer for the resulting data.
*/
void security_rp2_create_signature(
const uint8_t *plug_id_enc,
const uint8_t *sign_key_packed,
uint8_t *out);
/**
* Generate signed eeprom data from non encrypted and unobfuscated data required
* to pass security checks on games using black (game specific) and white
@@ -25,8 +38,12 @@ struct security_rp2_eeprom {
*
* This implementation (rp 2) is used by the following games
* - iidx 14 to 17
* - pop'n music 15 to 18
*
* @param type Type of plug to sign eeprom data for (black or white).
* @param sign_key The key to use for generating the signature.
* This key can be extracted from the executables of the games and might
* be re-used for multiple games of the same series or generation.
* @param boot_version The boot version mcode that is used for bootstrapping
* the security backend (of the ezusb.dll).
* @param plug_mcode The mcode of the game to boot. Typically, this code is
@@ -39,7 +56,7 @@ struct security_rp2_eeprom {
*/
void security_rp2_generate_signed_eeprom_data(
enum security_rp_util_rp_type type,
const struct security_mcode *boot_version,
const struct security_rp_sign_key *sign_key,
const struct security_mcode *plug_mcode,
const struct security_id *plug_id,
struct security_rp2_eeprom *out);
+4 -47
View File
@@ -1,3 +1,4 @@
#include "security/rp2.h"
#include "security/rp3.h"
#include "security/rp-util.h"
#include "security/util.h"
@@ -6,49 +7,6 @@
#include "util/crypto.h"
#include "util/log.h"
static uint8_t security_rp3_signature_scramble_table[] = {0x0C,
0x02,
0x0F,
0x01,
0x07,
0x09,
0x04,
0x0A,
0x00,
0x0E,
0x03,
0x0D,
0x0B,
0x05,
0x08,
0x06};
static void security_rp3_create_signature(
const uint8_t *plug_id, const uint8_t *sign_key_packed, uint8_t *out)
{
uint8_t data[14];
uint8_t md5[16];
uint8_t buffer[18];
memcpy(data, plug_id, 8);
memcpy(data + 8, sign_key_packed, 6);
crypto_init();
md5_compute(data, 14, md5, sizeof(md5));
crypto_fini();
for (int i = 0; i < 16; i++) {
buffer[i] = md5[security_rp3_signature_scramble_table[i]];
}
buffer[16] = 0xDE;
buffer[17] = 0xAD;
for (int i = 0; i < 6; i++) {
out[i] = buffer[i + 12] ^ buffer[i + 6] ^ buffer[i];
}
}
void security_rp3_generate_signed_eeprom_data(
enum security_rp_util_rp_type type,
const struct security_rp_sign_key *sign_key,
@@ -57,7 +15,6 @@ void security_rp3_generate_signed_eeprom_data(
struct security_rp3_eeprom *out)
{
uint8_t sign_key_tmp[8];
uint8_t sign_key_packed[6];
uint8_t plug_id_reversed[8];
log_assert(sign_key);
@@ -73,7 +30,7 @@ void security_rp3_generate_signed_eeprom_data(
}
}
security_util_8_to_6_encode(sign_key_tmp, sign_key_packed);
security_util_8_to_6_encode(sign_key_tmp, sign_key_tmp);
for (int i = 0; i < sizeof(plug_id_reversed); i++) {
plug_id_reversed[i] = plug_id->id[7 - i];
@@ -83,7 +40,7 @@ void security_rp3_generate_signed_eeprom_data(
(const uint8_t *) plug_mcode, out->packed_payload);
memset(out->zeros, 0, sizeof(out->zeros));
security_rp3_create_signature(
plug_id_reversed, sign_key_packed, out->signature);
security_rp2_create_signature(
plug_id_reversed, sign_key_tmp, out->signature);
out->crc = crc8((uint8_t *) out, sizeof(*out) - 1, 0);
}
+8 -3
View File
@@ -11,7 +11,7 @@
/**
* Structure for data which is usually stored in the eeprom section of the
* dongle. This contains a signiture to verify the ROM's contents as well as
* dongle. This contains a signature to verify the ROM's contents as well as
* the game this dongle is signed for.
*/
struct security_rp3_eeprom {
@@ -26,11 +26,16 @@ struct security_rp3_eeprom {
* to pass security checks on games using black (game specific) and white
* (eamuse) roundplugs.
*
* Algorithm is the same as RP2 but plug ID is handled in reverse order
* and response has additional padding + checksum at the end of the message.
*
* Used on the following games:
* - jubeat
* - jubeat series
* - DDR series
* - GFDM V series, XG series, Gitadora series
*
* @param type Type of plug to sign eeprom data for (black or white).
* @param sign_key The key to use for generating the signiture.
* @param sign_key The key to use for generating the signature.
* This key can be extracted from the executables of the games and might
* be re-used for multiple games of the same series or generation.
* @param plug_mcode The mcode of the game to boot. Typically, this code is