I just have a secured one, tried to get some datasheets to get all commands for these tags, but unfortunately they are available with NDA - and the public ones you get do not reveal much about the secure mode...
In secure mode it looks like there is some negotiation, reader always starts this challenge/response with a0 0520030005
The token sends everytime different bytes back, and the next command from reader is also everytime different , but constant command start: a0 05f9fafafa <then random bytes>.
I sniffed with chameleon mini.
Cheers
]]>===================================
This is from hf 15 dumpmemory (SRF55V02S) secure mode
===================================
proxmark3> hf 15 dumpmemory
Reading memory from tag UID=E00550000AC2AA32
Tag Info: Infineon; SRF55V02S [IC id = 80] secure mode 2kBit
Tag returned Error 16: The specified block is not available (doesn’t exist).
proxmark3>
Thanks
]]>I am not sure this topic may relate to pm3. At lease pm3 can read this kind of tag in ISO15693 or hf 15
I am testing tag Infineon My-d vicinity SRF55V02S and SRF55V10P. Regarding the datasheet, Tag has 2 operation mode 1) Plain Mode 2) Secure mode
I have both kind of tags.
1) Plain mode can read data from any block while
2) Secure mode I can get only UID, when I tried to read block data it read failed.
I am wondering I can't/no permission to read block data so how the specific reader gets data from tag in secure mode? Is there a secret keys sending between specific reader and tag? Is it possible to sniff data using pm3?
Thank you.
]]>