<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.element14.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Forum - Recent Threads</title><link>https://community.element14.com/challenges-projects/project14/nfc-rfid/f/forum</link><description /><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><lastBuildDate>Thu, 03 Dec 2020 15:09:14 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://community.element14.com/challenges-projects/project14/nfc-rfid/f/forum" /><item><title>RFID tag in car/motorcycle key</title><link>https://community.element14.com/thread/11142?ContentTypeID=0</link><pubDate>Mon, 24 Aug 2020 12:35:39 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:fa494499-0176-41c2-9d20-e872f374fcc0</guid><dc:creator>Kilohercas</dc:creator><slash:comments>9</slash:comments><comments>https://community.element14.com/thread/11142?ContentTypeID=0</comments><wfw:commentRss>https://community.element14.com/challenges-projects/project14/nfc-rfid/f/forum/11142/rfid-tag-in-car-motorcycle-key/rss?ContentTypeId=0</wfw:commentRss><description>&lt;p style="margin:0;"&gt;Hello,&lt;br /&gt;Does any one has more information what kind NFC tag is used in car/motorcycle key ? &lt;br /&gt;&lt;br /&gt;Any key-less car key can turn on car without need of battery, and i would like to know what kind of standard dues it use.&lt;br /&gt;&lt;br /&gt;I tested my car keys with phones NFC reader, but it did not provide any lock on RFID chip inside it, so how can i read it ?&lt;br /&gt;&lt;br /&gt;And also, is it static code, or is it some-kind dynamic, so i can&amp;#39;t clone int that easy ?&lt;br /&gt;&lt;br /&gt;Thank you !&lt;/p&gt;</description></item><item><title>RE: RFID tag in car/motorcycle key</title><link>https://community.element14.com/thread/185297?ContentTypeID=1</link><pubDate>Thu, 03 Dec 2020 15:09:14 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:2a71df00-cbc8-4e03-b6b1-adc31b90d6cc</guid><dc:creator>Jan Cumps</dc:creator><slash:comments>0</slash:comments><comments>https://community.element14.com/thread/185297?ContentTypeID=1</comments><wfw:commentRss>https://community.element14.com/challenges-projects/project14/nfc-rfid/f/forum/11142/rfid-tag-in-car-motorcycle-key/rss?ContentTypeId=0</wfw:commentRss><description>&lt;p style="margin:0;"&gt;The key does not generate a clearly visible change. It modulates the original signal but that may be subtle. It would not be a amplitude modulation I&amp;#39;d expect.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: RFID tag in car/motorcycle key</title><link>https://community.element14.com/thread/149628?ContentTypeID=1</link><pubDate>Thu, 03 Dec 2020 05:33:10 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:bba94685-a463-4f05-a277-5f9aed6afb7b</guid><dc:creator>Kilohercas</dc:creator><slash:comments>1</slash:comments><comments>https://community.element14.com/thread/149628?ContentTypeID=1</comments><wfw:commentRss>https://community.element14.com/challenges-projects/project14/nfc-rfid/f/forum/11142/rfid-tag-in-car-motorcycle-key/rss?ContentTypeId=0</wfw:commentRss><description>&lt;p style="margin:0;"&gt;I would expect is is doing something to magnetic field with shorting or doing something similar. In this case I would expect signal like this :&lt;/p&gt;&lt;p style="margin:0;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span&gt;&lt;a href="https://community.element14.com/resized-image/__size/620x368/__key/communityserver-discussions-components-files/239/5556.contentimage_5F00_192205.png"&gt;&lt;img alt="image" src="https://community-storage.element14.com/communityserver-components-secureimagefileviewer/communityserver/discussions/components/files/239/5556.contentimage_192205.png-620x368.png?sv=2016-05-31&amp;amp;sr=b&amp;amp;sig=gjsLTImx7Me8b0SiTHciu%2F786x4FsllmHyrSL0GzVUU%3D&amp;amp;se=2026-04-21T23%3A59%3A59Z&amp;amp;sp=r&amp;amp;_=IHIBx/hzHZ3sj1DYnBeJoQ==" style="max-height: 368px;max-width: 620px;" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;"&gt;In this case, you can clearly see that master is generating waveform, and tag is modifying quality of coil (and in this case resonating voltage will be lower that can be picked up) , and you can clearly see data transmitted.&lt;br /&gt;&lt;br /&gt;But in my case, I see nothing like that. I see perfect 125kHz data burst and no response. If my key is modulating quality of exciter coil, signal &lt;strong&gt;WOULD NOT GO TO ZERO&lt;/strong&gt;.&lt;br /&gt;&lt;br /&gt;So how does key is communicating with motorcycle... Only thing that left is transmitting 315MHz RF that my scope can&amp;#39;t capture in that timescale... I just don&amp;#39;t see any other way&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: RFID tag in car/motorcycle key</title><link>https://community.element14.com/thread/149488?ContentTypeID=1</link><pubDate>Sun, 22 Nov 2020 12:33:56 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:7ee70551-0b6c-4bad-803f-c888500da043</guid><dc:creator>Jan Cumps</dc:creator><slash:comments>1</slash:comments><comments>https://community.element14.com/thread/149488?ContentTypeID=1</comments><wfw:commentRss>https://community.element14.com/challenges-projects/project14/nfc-rfid/f/forum/11142/rfid-tag-in-car-motorcycle-key/rss?ContentTypeId=0</wfw:commentRss><description>&lt;p style="margin:0;"&gt;It has to use RF. If there&amp;#39;s no contact, and no infrared sender / receiver, it has to be a radio signal.&lt;/p&gt;&lt;p style="margin:0;padding:0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin:0;"&gt;In essence the RF tag is more of a disturber than a radio. It will cause modulations on the signal emitted by the sender, by modifying the impedance of its own RF circuit.&lt;/p&gt;&lt;p style="margin:0;"&gt;The sender coil and token coil are closely coupled when near each other, so that impedance change in the tag antenna RF circuit impacts (agitates) the sender RF circuit.&lt;/p&gt;&lt;p style="margin:0;"&gt;The sender has to detect those modulations and interpret them.&lt;/p&gt;&lt;p style="margin:0;padding:0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin:0;"&gt;If you are looking for a reply of the token, after the motorcycle sent its signal, you will not find it because it&amp;#39;s not there.&lt;/p&gt;&lt;p style="margin:0;"&gt;The reply is imposed upon the original signal.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: RFID tag in car/motorcycle key</title><link>https://community.element14.com/thread/149477?ContentTypeID=1</link><pubDate>Sun, 22 Nov 2020 11:46:24 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:038ac046-bb1a-4760-b55a-dbaf309361dd</guid><dc:creator>Kilohercas</dc:creator><slash:comments>1</slash:comments><comments>https://community.element14.com/thread/149477?ContentTypeID=1</comments><wfw:commentRss>https://community.element14.com/challenges-projects/project14/nfc-rfid/f/forum/11142/rfid-tag-in-car-motorcycle-key/rss?ContentTypeId=0</wfw:commentRss><description>&lt;p style="margin:0;"&gt;I know that it uses RF for normal operation, so i would not see this on scope, but i am probing coil and i can&amp;#39;t see anything, only data from ECU at very high voltage.&lt;br /&gt;&lt;br /&gt;So I don&amp;#39;t know whats doing on here. IS it really uses RF somehow ?&lt;br /&gt;&lt;br /&gt;Data is static, does not change, does not have any roiling code, every single time is the same, so I can replay it and it should work. &lt;strong&gt;Problem I don&amp;#39;t see any response from key, while motorcycle does see message from key&lt;/strong&gt;. Maybe I have to use spectrum analyzer or something to get this working...&lt;br /&gt;&lt;br /&gt;Very strange&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: RFID tag in car/motorcycle key</title><link>https://community.element14.com/thread/149446?ContentTypeID=1</link><pubDate>Sun, 22 Nov 2020 10:39:59 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:e55534cc-e049-4faf-b6c7-0448be288cfc</guid><dc:creator>Jan Cumps</dc:creator><slash:comments>1</slash:comments><comments>https://community.element14.com/thread/149446?ContentTypeID=1</comments><wfw:commentRss>https://community.element14.com/challenges-projects/project14/nfc-rfid/f/forum/11142/rfid-tag-in-car-motorcycle-key/rss?ContentTypeId=0</wfw:commentRss><description>&lt;p style="margin:0;"&gt;Usually, these keys are powered from the radio signal emitted from the car.&lt;/p&gt;&lt;p style="margin:0;"&gt;They have RF circuitry on board and a little bit of intelligence - a low power tiny microcontroller. Or the two combined on a small flack of silicon.&lt;/p&gt;&lt;blockquote class="jive-quote"&gt;&lt;p style="margin:0;"&gt; I need to make hardware that captures this response and replays back, but if I don&amp;#39;t know what going on, it is impossible....&lt;/p&gt;&lt;/blockquote&gt;&lt;p style="margin:0;"&gt;Yes. 2 reasons. The main reason is that re-sending a previously recorded reply will not work. It&amp;#39;s not a remote control.&lt;/p&gt;&lt;p style="margin:0;"&gt;2nd reason - not relevant because of the 1st one above - I believe your setup doesn&amp;#39;t succeed in showing the signals from key to car. &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: RFID tag in car/motorcycle key</title><link>https://community.element14.com/thread/149445?ContentTypeID=1</link><pubDate>Sun, 22 Nov 2020 07:43:51 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:60c9440a-0dd2-4ddb-9d6a-b571aa70e87f</guid><dc:creator>Kilohercas</dc:creator><slash:comments>0</slash:comments><comments>https://community.element14.com/thread/149445?ContentTypeID=1</comments><wfw:commentRss>https://community.element14.com/challenges-projects/project14/nfc-rfid/f/forum/11142/rfid-tag-in-car-motorcycle-key/rss?ContentTypeId=0</wfw:commentRss><description>&lt;p style="margin:0;"&gt;Ok, I am at total lost now. As far as I understand, this is nothing more than HITAG2 chip because is most commonly used by automakers. Now ok, it says 125Khz, perfect with what I see.&lt;br /&gt;&lt;br /&gt;Part I don&amp;#39;t understand is how they are communicating. I attached scope to coil antenna so I can see signals that ECU is seeing. problem is, I don&amp;#39;t see any response from key-fob, while Motorcycle do acknowledges key and allows you to start the engine. Also, where is no battery in remote, or even worse, I use special key they is designed only emergency and from BMW it cost only 50$, so no way any RF circuitry is inside.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;strong&gt;Look at this waveform. This is successful unlock of motorcycle using RFID key. If key is transmitting data, it should produce lower amplitude signal, not a perfect one as for exatation. If key is shorting magnetic field, it would not go to zero.&lt;/strong&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;So what a hell ? How they are communicating ?&lt;br /&gt;&lt;br /&gt;Is is bit by bit exploded view of signal:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;So, can any one tell me how it&amp;#39;s doing communication ? I need to make hardware that captures this response and replays back, but if I don&amp;#39;t know what going on, it is impossible....&lt;span&gt;&lt;a href="https://community.element14.com/resized-image/__size/620x372/__key/communityserver-discussions-components-files/239/4130.contentimage_5F00_192203.png"&gt;&lt;img alt="image" src="https://community-storage.element14.com/communityserver-components-secureimagefileviewer/communityserver/discussions/components/files/239/4130.contentimage_192203.png-620x372.png?sv=2016-05-31&amp;amp;sr=b&amp;amp;sig=K3Wwrfckcu4mCYk9mNjZ0JwF6PFaX6vGKlShuWr6%2BCo%3D&amp;amp;se=2026-04-21T23%3A59%3A59Z&amp;amp;sp=r&amp;amp;_=ZdXzQRPg+pC6IqclMwizKw==" style="max-height: 372px;max-width: 620px;" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span&gt;&lt;a href="https://community.element14.com/resized-image/__size/620x372/__key/communityserver-discussions-components-files/239/8372.contentimage_5F00_192204.png"&gt;&lt;img loading="lazy" alt="image" src="https://community-storage.element14.com/communityserver-components-secureimagefileviewer/communityserver/discussions/components/files/239/8372.contentimage_192204.png-620x372.png?sv=2016-05-31&amp;amp;sr=b&amp;amp;sig=Jse3ikJ15dzS8TBn%2BsfCKlkP8KJuq1%2BWRoTHE4voAmg%3D&amp;amp;se=2026-04-21T23%3A59%3A59Z&amp;amp;sp=r&amp;amp;_=68HBPvbmGp5ivycaCSC/nQ==" style="max-height: 372px;max-width: 620px;" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: RFID tag in car/motorcycle key</title><link>https://community.element14.com/thread/148442?ContentTypeID=1</link><pubDate>Wed, 02 Sep 2020 03:09:20 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:705af95f-e82a-4e40-a18d-aa303e4c078e</guid><dc:creator>Kilohercas</dc:creator><slash:comments>0</slash:comments><comments>https://community.element14.com/thread/148442?ContentTypeID=1</comments><wfw:commentRss>https://community.element14.com/challenges-projects/project14/nfc-rfid/f/forum/11142/rfid-tag-in-car-motorcycle-key/rss?ContentTypeId=0</wfw:commentRss><description>&lt;p style="margin:0;"&gt;Probing showed static data.&lt;br /&gt;&lt;br /&gt;So it does not look to be anything fancy. One fancy thing is that in excitation stage, it does generate some data. That can be that if only this data is present, key RFID chip will send back any data to motorcycle.&lt;br /&gt;&lt;br /&gt;In this scenario, it is perfectly safe, since you can&amp;#39;t read key and replay it off the motorcycle, but if you are at the coil when you normally unlock motorcycle with RFID, you will know what data was send, and what data was replayed. And you just need to replay data you capture after excitation ping.&lt;br /&gt;&lt;br /&gt;So as safety logic goes, if you already have good key in correct location, where is no point of doing any scrambling/rolling code generation, since that means you have original key. But if you try to copy it outside motorcycle, you will need to generate correct key to do it. Where is 20bit code, and it is send around 100ms, that means in order to copy code, you have to probe it 100 000s or 30minutes.&lt;br /&gt;&lt;br /&gt;I would say it is perfectly safe. It would be more safe is key would generate ther data on different ping message, in that case, you will have to replay all messages, it would take days of work to unlock it..&lt;/p&gt;&lt;p style="margin:0;padding:0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin:0;"&gt;Ping message:&lt;/p&gt;&lt;p style="margin:0;"&gt;&lt;span&gt;&lt;a href="https://community.element14.com/resized-image/__size/620x372/__key/communityserver-discussions-components-files/239/8637.contentimage_5F00_192202.png"&gt;&lt;img alt="image" src="https://community-storage.element14.com/communityserver-components-secureimagefileviewer/communityserver/discussions/components/files/239/8637.contentimage_192202.png-620x372.png?sv=2016-05-31&amp;amp;sr=b&amp;amp;sig=fnS9yNdVTmZjwwFOTgsBC5dy5iRp3v1maHTkWImZXPQ%3D&amp;amp;se=2026-04-21T23%3A59%3A59Z&amp;amp;sp=r&amp;amp;_=VgltUT/m6SJYOkOGhuYKTw==" style="max-height: 372px;max-width: 620px;" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: RFID tag in car/motorcycle key</title><link>https://community.element14.com/thread/148404?ContentTypeID=1</link><pubDate>Mon, 31 Aug 2020 08:37:29 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:aa4d1af1-9fcf-40eb-be70-fc31018a19e0</guid><dc:creator>Jan Cumps</dc:creator><slash:comments>1</slash:comments><comments>https://community.element14.com/thread/148404?ContentTypeID=1</comments><wfw:commentRss>https://community.element14.com/challenges-projects/project14/nfc-rfid/f/forum/11142/rfid-tag-in-car-motorcycle-key/rss?ContentTypeId=0</wfw:commentRss><description>&lt;p style="margin:0;"&gt;In recent cars, the communication is via certificates and keys (sic). Record and playback will (hopefully for car owners) not work.&lt;/p&gt;&lt;p style="margin:0;"&gt;If you succeed, record and document it and you&amp;#39;ll have a speaking spot on the next Black Hat conference.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: RFID tag in car/motorcycle key</title><link>https://community.element14.com/thread/148393?ContentTypeID=1</link><pubDate>Mon, 31 Aug 2020 02:43:10 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:e8f69d85-2330-4689-9038-ae4d9117e8ea</guid><dc:creator>Kilohercas</dc:creator><slash:comments>1</slash:comments><comments>https://community.element14.com/thread/148393?ContentTypeID=1</comments><wfw:commentRss>https://community.element14.com/challenges-projects/project14/nfc-rfid/f/forum/11142/rfid-tag-in-car-motorcycle-key/rss?ContentTypeId=0</wfw:commentRss><description>&lt;p style="margin:0;"&gt;Did some probing, it turns out to be 133kHz signal. SO it looks like i will be making my own pick up and transmitter circuit based on MCU &lt;span&gt;&lt;a href="https://community.element14.com/resized-image/__size/16x16/__key/communityserver-discussions-components-files/239/contentimage_5F00_1.png"&gt;&lt;img alt="image" src="https://community-storage.element14.com/communityserver-components-secureimagefileviewer/communityserver/discussions/components/files/239/contentimage_1.png-16x16.png?sv=2016-05-31&amp;amp;sr=b&amp;amp;sig=aDJJ%2FxHQPMOvO6S2Fe5Di%2BUQo1%2F%2Fx1pcOMMvMK480%2BA%3D&amp;amp;se=2026-04-21T23%3A59%3A59Z&amp;amp;sp=r&amp;amp;_=zGEM7pHL10Vt71gae75OdA==" style="max-height: 16px;max-width: 16px;" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>