1 |
05b1332d
|
Oliver Smith
|
/* Copyright 2020 sysmocom s.f.m.c. GmbH
|
2 |
|
|
* SPDX-License-Identifier: Apache-2.0 */
|
3 |
4e5e516a
|
Oliver Smith
|
package org.osmocom.IMSIPseudo;
|
4 |
d20f93a2
|
Neels Hofmeyr
|
import org.osmocom.IMSIPseudo.MobileIdentity;
|
5 |
4e5e516a
|
Oliver Smith
|
|
6 |
4eee13d7
|
Oliver Smith
|
import sim.access.*;
|
7 |
|
|
import sim.toolkit.*;
|
8 |
|
|
import javacard.framework.*;
|
9 |
4e5e516a
|
Oliver Smith
|
|
10 |
|
|
public class IMSIPseudo extends Applet implements ToolkitInterface, ToolkitConstants {
|
11 |
|
|
// DON'T DECLARE USELESS INSTANCE VARIABLES! They get saved to the EEPROM,
|
12 |
|
|
// which has a limited number of write cycles.
|
13 |
|
|
|
14 |
ca866fe7
|
Oliver Smith
|
private byte STKServicesMenuId;
|
15 |
2259cb9f
|
Oliver Smith
|
private SIMView gsmFile;
|
16 |
cf04db03
|
Neels Hofmeyr
|
static byte[] LUCounter = { '0', 'x', ' ', 'L', 'U' };
|
17 |
ca866fe7
|
Oliver Smith
|
|
18 |
|
|
/* Main menu */
|
19 |
cf04db03
|
Neels Hofmeyr
|
private static final byte[] title = { 'I', 'M', 'S', 'I', ' ', 'P', 's', 'e', 'u', 'd', 'o', 'n', 'y', 'm',
|
20 |
2dcbfabb
|
Oliver Smith
|
'i', 'z', 'a', 't', 'i', 'o', 'n'};
|
21 |
cf04db03
|
Neels Hofmeyr
|
private static final byte[] showLU = {'S', 'h', 'o', 'w', ' ', 'L', 'U', ' ', 'c', 'o', 'u', 'n', 't', 'e', 'r'};
|
22 |
483f5a4f
|
Neels Hofmeyr
|
private static final byte[] changeIMSI = {'C', 'h', 'a', 'n', 'g', 'e', ' ', 'I', 'M', 'S', 'I'};
|
23 |
|
|
private static final byte[] invalidIMSI = {'I', 'n', 'v', 'a', 'l', 'i', 'd', ' ', 'I', 'M', 'S', 'I'};
|
24 |
|
|
private static final byte[] noChange = {'N', 'o', ' ', 'c', 'h', 'a', 'n', 'g', 'e'};
|
25 |
|
|
private static final byte[] changed = {'I', 'M', 'S', 'I', ' ', 'c', 'h', 'a', 'n', 'g', 'e', 'd', '!'};
|
26 |
|
|
private static final byte error[] = {'E', 'R', 'R', 'O', 'R' };
|
27 |
|
|
private final Object[] itemListMain = {title, showLU, changeIMSI};
|
28 |
4e5e516a
|
Oliver Smith
|
|
29 |
|
|
private IMSIPseudo() {
|
30 |
2259cb9f
|
Oliver Smith
|
gsmFile = SIMSystem.getTheSIMView();
|
31 |
|
|
|
32 |
ca866fe7
|
Oliver Smith
|
/* Register menu and trigger on location updates */
|
33 |
4e5e516a
|
Oliver Smith
|
ToolkitRegistry reg = ToolkitRegistry.getEntry();
|
34 |
ca866fe7
|
Oliver Smith
|
STKServicesMenuId = reg.initMenuEntry(title, (short)0, (short)title.length, PRO_CMD_SELECT_ITEM, false,
|
35 |
|
|
(byte)0, (short)0);
|
36 |
e28705af
|
Oliver Smith
|
reg.setEvent(EVENT_EVENT_DOWNLOAD_LOCATION_STATUS);
|
37 |
4e5e516a
|
Oliver Smith
|
}
|
38 |
|
|
|
39 |
|
|
public static void install(byte[] bArray, short bOffset, byte bLength) {
|
40 |
|
|
IMSIPseudo applet = new IMSIPseudo();
|
41 |
|
|
applet.register();
|
42 |
|
|
}
|
43 |
|
|
|
44 |
|
|
public void process(APDU arg0) throws ISOException {
|
45 |
|
|
if (selectingApplet())
|
46 |
|
|
return;
|
47 |
|
|
}
|
48 |
|
|
|
49 |
|
|
public void processToolkit(byte event) throws ToolkitException {
|
50 |
|
|
EnvelopeHandler envHdlr = EnvelopeHandler.getTheHandler();
|
51 |
|
|
|
52 |
|
|
if (event == EVENT_MENU_SELECTION) {
|
53 |
|
|
byte selectedItemId = envHdlr.getItemIdentifier();
|
54 |
|
|
|
55 |
ca866fe7
|
Oliver Smith
|
if (selectedItemId == STKServicesMenuId) {
|
56 |
583bfecc
|
Neels Hofmeyr
|
showMenu(itemListMain);
|
57 |
ca866fe7
|
Oliver Smith
|
handleMenuResponseMain();
|
58 |
4e5e516a
|
Oliver Smith
|
}
|
59 |
|
|
}
|
60 |
e28705af
|
Oliver Smith
|
|
61 |
|
|
if (event == EVENT_EVENT_DOWNLOAD_LOCATION_STATUS) {
|
62 |
1e5cc46d
|
Oliver Smith
|
LUCounter[0]++;
|
63 |
234ab54b
|
Oliver Smith
|
showMsg(LUCounter);
|
64 |
e28705af
|
Oliver Smith
|
}
|
65 |
4e5e516a
|
Oliver Smith
|
}
|
66 |
|
|
|
67 |
583bfecc
|
Neels Hofmeyr
|
private void showMenu(Object[] itemList) {
|
68 |
ca866fe7
|
Oliver Smith
|
ProactiveHandler proHdlr = ProactiveHandler.getTheHandler();
|
69 |
|
|
proHdlr.init((byte) PRO_CMD_SELECT_ITEM,(byte)0,DEV_ID_ME);
|
70 |
|
|
|
71 |
583bfecc
|
Neels Hofmeyr
|
for (byte i=(byte)0; i < itemList.length; i++) {
|
72 |
ca866fe7
|
Oliver Smith
|
if (i == 0) {
|
73 |
|
|
/* Title */
|
74 |
|
|
proHdlr.appendTLV((byte)(TAG_ALPHA_IDENTIFIER | TAG_SET_CR), (byte[])itemList[i],
|
75 |
|
|
(short)0, (short)((byte[])itemList[i]).length);
|
76 |
|
|
|
77 |
|
|
} else {
|
78 |
|
|
/* Menu entry */
|
79 |
|
|
proHdlr.appendTLV((byte)(TAG_ITEM | TAG_SET_CR), (byte)i, (byte[])itemList[i], (short)0,
|
80 |
|
|
(short)((byte[])itemList[i]).length);
|
81 |
|
|
}
|
82 |
|
|
}
|
83 |
|
|
proHdlr.send();
|
84 |
|
|
}
|
85 |
|
|
|
86 |
cef081c1
|
Oliver Smith
|
private void showMsg(byte[] msg) {
|
87 |
|
|
ProactiveHandler proHdlr = ProactiveHandler.getTheHandler();
|
88 |
|
|
proHdlr.initDisplayText((byte)0, DCS_8_BIT_DATA, msg, (short)0, (short)(msg.length));
|
89 |
|
|
proHdlr.send();
|
90 |
|
|
}
|
91 |
|
|
|
92 |
ba7a6f22
|
Neels Hofmeyr
|
private byte[] getResponse()
|
93 |
|
|
{
|
94 |
|
|
ProactiveResponseHandler rspHdlr = ProactiveResponseHandler.getTheHandler();
|
95 |
|
|
byte[] resp = new byte[rspHdlr.getTextStringLength()];
|
96 |
|
|
rspHdlr.copyTextString(resp, (short)0);
|
97 |
|
|
return resp;
|
98 |
|
|
}
|
99 |
|
|
|
100 |
9a3428e4
|
Neels Hofmeyr
|
/*
|
101 |
|
|
This was used to find out that the first byte of a text field seems to be 4.
|
102 |
|
|
private byte[] getResponseDBG()
|
103 |
|
|
{
|
104 |
|
|
ProactiveResponseHandler rspHdlr;
|
105 |
|
|
byte resp[];
|
106 |
|
|
byte strlen = -1;
|
107 |
|
|
rspHdlr = ProactiveResponseHandler.getTheHandler();
|
108 |
|
|
|
109 |
|
|
for (byte occurence = 1; occurence <= 3; occurence++) {
|
110 |
|
|
short len;
|
111 |
|
|
try {
|
112 |
|
|
if (rspHdlr.findTLV(TAG_TEXT_STRING, (byte)occurence) != TLV_NOT_FOUND) {
|
113 |
|
|
if ((len = rspHdlr.getValueLength()) > 1) {
|
114 |
|
|
len = 3;
|
115 |
|
|
resp = new byte[len];
|
116 |
|
|
rspHdlr.copyValue((short)0, resp, (short)0, (short)(len));
|
117 |
|
|
showMsg(resp);
|
118 |
|
|
showMsgAndWaitKey(Bytes.hexdump(resp));
|
119 |
|
|
return resp;
|
120 |
|
|
}
|
121 |
|
|
}
|
122 |
|
|
} catch (Exception e) {
|
123 |
|
|
showError((short)(30 + occurence));
|
124 |
|
|
return null;
|
125 |
|
|
}
|
126 |
|
|
}
|
127 |
|
|
showError((short)(39));
|
128 |
|
|
return null;
|
129 |
|
|
}
|
130 |
|
|
*/
|
131 |
|
|
|
132 |
ba7a6f22
|
Neels Hofmeyr
|
private byte[] showMsgAndWaitKey(byte[] msg) {
|
133 |
cfb476d2
|
Neels Hofmeyr
|
ProactiveHandler proHdlr = ProactiveHandler.getTheHandler();
|
134 |
|
|
proHdlr.initGetInkey((byte)0, DCS_8_BIT_DATA, msg, (short)0, (short)(msg.length));
|
135 |
|
|
proHdlr.send();
|
136 |
ba7a6f22
|
Neels Hofmeyr
|
|
137 |
|
|
return getResponse();
|
138 |
|
|
}
|
139 |
|
|
|
140 |
9a3428e4
|
Neels Hofmeyr
|
private byte[] prompt(byte[] msg, byte[] prefillVal, short minLen, short maxLen) {
|
141 |
ba7a6f22
|
Neels Hofmeyr
|
/* if maxLen < 1, the applet crashes */
|
142 |
|
|
if (maxLen < 1)
|
143 |
|
|
maxLen = 1;
|
144 |
|
|
|
145 |
|
|
ProactiveHandler proHdlr = ProactiveHandler.getTheHandler();
|
146 |
|
|
proHdlr.initGetInput((byte)0, DCS_8_BIT_DATA, msg, (short)0, (short)(msg.length), minLen, maxLen);
|
147 |
9a3428e4
|
Neels Hofmeyr
|
if (prefillVal != null && prefillVal.length > 0) {
|
148 |
|
|
/* appendTLV() expects the first byte to be some header before the actual text.
|
149 |
|
|
* At first I thought it was the value's length, but turned out to only work for lengths under 8...
|
150 |
|
|
* In the end I reversed the value 4 from the first byte read by rspHdlr.copyValue() for
|
151 |
|
|
* TAG_TEXT_STRING fields. As long as we write 4 into the first byte, things just work out,
|
152 |
|
|
* apparently.
|
153 |
|
|
* Fucking well could have said so in the API docs, too; oh the brain damage, oh the hours wasted.
|
154 |
|
|
* This is the appendTLV() variant that writes one byte ahead of writing an array: */
|
155 |
|
|
proHdlr.appendTLV((byte)(TAG_DEFAULT_TEXT), (byte)4, prefillVal, (short)0,
|
156 |
|
|
(short)(prefillVal.length));
|
157 |
|
|
}
|
158 |
ba7a6f22
|
Neels Hofmeyr
|
proHdlr.send();
|
159 |
|
|
|
160 |
|
|
return getResponse();
|
161 |
cfb476d2
|
Neels Hofmeyr
|
}
|
162 |
|
|
|
163 |
d7f18920
|
Oliver Smith
|
private void showError(short code) {
|
164 |
cf04db03
|
Neels Hofmeyr
|
byte[] msg = {'E', '?', '?'};
|
165 |
d7f18920
|
Oliver Smith
|
msg[1] = (byte)('0' + code / 10);
|
166 |
|
|
msg[2] = (byte)('0' + code % 10);
|
167 |
|
|
showMsg(msg);
|
168 |
|
|
}
|
169 |
|
|
|
170 |
ca866fe7
|
Oliver Smith
|
private void handleMenuResponseMain() {
|
171 |
|
|
ProactiveResponseHandler rspHdlr = ProactiveResponseHandler.getTheHandler();
|
172 |
|
|
|
173 |
|
|
switch (rspHdlr.getItemIdentifier()) {
|
174 |
c8e96413
|
Neels Hofmeyr
|
case 1: /* Show LU counter */
|
175 |
|
|
showMsg(LUCounter);
|
176 |
|
|
break;
|
177 |
483f5a4f
|
Neels Hofmeyr
|
case 2: /* Change IMSI */
|
178 |
|
|
byte prevIMSI_mi[] = readIMSI();
|
179 |
|
|
byte prevIMSI_str[] = MobileIdentity.mi2str(prevIMSI_mi);
|
180 |
|
|
promptIMSI(prevIMSI_str);
|
181 |
c8e96413
|
Neels Hofmeyr
|
break;
|
182 |
ca866fe7
|
Oliver Smith
|
}
|
183 |
|
|
}
|
184 |
|
|
|
185 |
483f5a4f
|
Neels Hofmeyr
|
private void promptIMSI(byte prevIMSI_str[])
|
186 |
|
|
{
|
187 |
|
|
byte newIMSI_str[] = prevIMSI_str;
|
188 |
|
|
|
189 |
|
|
try {
|
190 |
|
|
newIMSI_str = prompt(changeIMSI, newIMSI_str, (short)0, (short)15);
|
191 |
|
|
} catch (Exception e) {
|
192 |
|
|
showError((short)40);
|
193 |
|
|
return;
|
194 |
|
|
}
|
195 |
|
|
|
196 |
|
|
if (newIMSI_str.length < 6 || newIMSI_str.length > 15
|
197 |
|
|
|| !Bytes.isDigit(newIMSI_str)) {
|
198 |
|
|
showMsg(invalidIMSI);
|
199 |
|
|
return;
|
200 |
|
|
}
|
201 |
|
|
|
202 |
|
|
if (Bytes.equals(newIMSI_str, prevIMSI_str)) {
|
203 |
|
|
showMsg(noChange);
|
204 |
|
|
return;
|
205 |
0866f3a0
|
Neels Hofmeyr
|
}
|
206 |
|
|
|
207 |
d20f93a2
|
Neels Hofmeyr
|
byte mi[];
|
208 |
|
|
try {
|
209 |
483f5a4f
|
Neels Hofmeyr
|
/* The IMSI file should be 9 bytes long, even if the IMSI is shorter */
|
210 |
|
|
mi = MobileIdentity.str2mi(newIMSI_str, MobileIdentity.MI_IMSI, (byte)9);
|
211 |
41b6f543
|
Neels Hofmeyr
|
writeIMSI(mi);
|
212 |
483f5a4f
|
Neels Hofmeyr
|
showMsg(changed);
|
213 |
134f41f5
|
Oliver Smith
|
invalidateTMSI((short)SIMView.FID_EF_LOCI);
|
214 |
|
|
invalidateTMSI((short)SIMView.FID_EF_LOCIGPRS);
|
215 |
15c3bfb4
|
Oliver Smith
|
invalidateKc((short)SIMView.FID_EF_KC);
|
216 |
|
|
invalidateKc((short)SIMView.FID_EF_KCGPRS);
|
217 |
b80a9f87
|
Oliver Smith
|
/* FIXME: also invalidate EF_KEYS, EF_KEYS_PS */
|
218 |
4ac43a2f
|
Neels Hofmeyr
|
refreshIMSI();
|
219 |
d20f93a2
|
Neels Hofmeyr
|
} catch (Exception e) {
|
220 |
483f5a4f
|
Neels Hofmeyr
|
showError((short)42);
|
221 |
d20f93a2
|
Neels Hofmeyr
|
}
|
222 |
ca866fe7
|
Oliver Smith
|
}
|
223 |
c24fdd1a
|
Neels Hofmeyr
|
|
224 |
|
|
private byte[] readIMSI()
|
225 |
|
|
{
|
226 |
|
|
gsmFile.select((short) SIMView.FID_DF_GSM);
|
227 |
|
|
gsmFile.select((short) SIMView.FID_EF_IMSI);
|
228 |
|
|
byte[] IMSI = new byte[9];
|
229 |
|
|
gsmFile.readBinary((short)0, IMSI, (short)0, (short)9);
|
230 |
|
|
return IMSI;
|
231 |
|
|
}
|
232 |
|
|
|
233 |
26256941
|
Neels Hofmeyr
|
private void writeIMSI(byte mi[]) throws Exception
|
234 |
c24fdd1a
|
Neels Hofmeyr
|
{
|
235 |
26256941
|
Neels Hofmeyr
|
if (mi.length != 9)
|
236 |
|
|
throw new Exception();
|
237 |
c24fdd1a
|
Neels Hofmeyr
|
gsmFile.select((short) SIMView.FID_DF_GSM);
|
238 |
|
|
gsmFile.select((short) SIMView.FID_EF_IMSI);
|
239 |
|
|
gsmFile.updateBinary((short)0, mi, (short)0, (short)mi.length);
|
240 |
|
|
}
|
241 |
4ac43a2f
|
Neels Hofmeyr
|
|
242 |
134f41f5
|
Oliver Smith
|
private void invalidateTMSI(short fid)
|
243 |
|
|
{
|
244 |
|
|
byte[] TMSI = {(byte)0xff, (byte)0xff, (byte)0xff, (byte)0xff};
|
245 |
|
|
gsmFile.select((short) SIMView.FID_DF_GSM);
|
246 |
|
|
gsmFile.select(fid);
|
247 |
|
|
gsmFile.updateBinary((short)0, TMSI, (short)0, (short)TMSI.length);
|
248 |
|
|
}
|
249 |
|
|
|
250 |
15c3bfb4
|
Oliver Smith
|
private void invalidateKc(short fid)
|
251 |
|
|
{
|
252 |
|
|
byte[] Kc = {(byte)0x07}; /* proper N/A value, see 3GPP TS 31.102, chapter 4.4.3.1 */
|
253 |
|
|
gsmFile.select((short) SIMView.FID_DF_GSM);
|
254 |
|
|
gsmFile.select(fid);
|
255 |
|
|
gsmFile.updateBinary((short)0, Kc, (short)0, (short)Kc.length);
|
256 |
|
|
}
|
257 |
|
|
|
258 |
4ac43a2f
|
Neels Hofmeyr
|
/*
|
259 |
|
|
* - command qualifiers for REFRESH,
|
260 |
|
|
* ETSI TS 101 267 / 3GPP TS 11.14 chapter 12.6 "Command details":
|
261 |
9748cdc6
|
Oliver Smith
|
* '00' = SIM Initialization and Full File Change Notification;
|
262 |
4ac43a2f
|
Neels Hofmeyr
|
* '01' = File Change Notification;
|
263 |
|
|
* '02' = SIM Initialization and File Change Notification;
|
264 |
|
|
* '03' = SIM Initialization;
|
265 |
|
|
* '04' = SIM Reset;
|
266 |
|
|
* '05' to 'FF' = reserved values.
|
267 |
|
|
*/
|
268 |
|
|
public static final byte SIM_REFRESH_SIM_INIT_FULL_FILE_CHANGE = 0x00;
|
269 |
|
|
public static final byte SIM_REFRESH_FILE_CHANGE = 0x01;
|
270 |
|
|
public static final byte SIM_REFRESH_SIM_INIT_FILE_CHANGE = 0x02;
|
271 |
|
|
public static final byte SIM_REFRESH_SIM_INIT = 0x03;
|
272 |
|
|
public static final byte SIM_REFRESH_SIM_RESET = 0x04;
|
273 |
|
|
|
274 |
|
|
/* Run the Proactive SIM REFRESH command for the FID_EF_IMSI. */
|
275 |
|
|
private void refreshIMSI()
|
276 |
|
|
{
|
277 |
|
|
/* See ETSI TS 101 267 / 3GPP TS 11.14 section 6.4.7.1 "EF IMSI changing procedure":
|
278 |
|
|
* Valid qualifiers are SIM_REFRESH_SIM_INIT_FILE_CHANGE and SIM_REFRESH_SIM_INIT_FULL_FILE_CHANGE.
|
279 |
|
|
*/
|
280 |
|
|
ProactiveHandler proHdlr = ProactiveHandler.getTheHandler();
|
281 |
|
|
proHdlr.init((byte)PRO_CMD_REFRESH, SIM_REFRESH_SIM_INIT_FULL_FILE_CHANGE, DEV_ID_ME);
|
282 |
|
|
proHdlr.send();
|
283 |
|
|
}
|
284 |
4e5e516a
|
Oliver Smith
|
}
|