Deutsch · English

SSR-Labs · Technical Capability Brief

NFC / RFID Pentest & Transponder Suite

A Windows workbench with in-house, GPL-free crypto engines, GPU-accelerated key recovery and a verified transponder knowledge base — built entirely from public and clean-room sources.

Version 3.98 “Empire Edition” As of 2026-09-14 Author Robert Schilke SSR-Labs.de · Duderstadt
68 / 68crypto self-tests green
4in-house GPU kernels
20+calculators
95+modules
~14ksamples, 0 errors
17smartcard-MCU profiles

§1Summary

The suite covers the full analysis cycle of authorised NFC/RFID work: identify, read, key recovery, cloning and reporting — for HF cards (13.56 MHz), LF transponders (125–134 kHz) and automotive immobilisers. The core is deliberately self-contained: Crypto-1 recovery runs on a self-written, GPL-free engine, and four in-house OpenCL kernels move the heavy brute-force runs onto the GPU. Every shipped cipher is verified against published known-answer vectors or against hardware; every GPU result is cross-checked against its cipher oracle.

Nothing is marked “done” unless it is backed by test vectors or real hardware. Open items are flagged as such.

Section 2 lists the unique selling points, Section 3 shows per chip what the suite can actually do. The technical Sections 4–11 go into detail, Section 12 describes operation; Section 13 states scope and source discipline.

§2Unique selling points

These capabilities are developed in-house and, in this combination, are what sets the tool apart from stock tooling — no third-party or copyleft code in the shipping build.

What the software actually does (not “info about…”, but computes / cracks / reads)

Own engines · own GPU kernels · own recovery

GPL-free Crypto-1 recovery engine exclusive

Full clean-room reimplementation in ssrcrypto.dll: mfkey32, nested, nested_multi, nested_blind and FM11RF08S fingerprint. No more GPL/crapto1 in the build — hence sellable without a copyleft leash. -O3-optimised, faster than the former upstream; self-test 200/200, live blind crack on S50 in ≈ 42 s.

Four in-house OpenCL kernels, RTX-verified exclusive

Self-written and zero-dependency — they load the NVIDIA ICD at runtime themselves, needing neither a CUDA toolkit nor CL headers. All verified against KAT on an RTX 5050: DST40 (~135 M keys/s), Hitag2 (~1.1 billion keys/s), DST80-keyR (80-bit, end-to-end) and Ultralight-C 2K3DES (DES kernel bit-identical to the CPU engine; PKO page 2²⁸ in 3.9 s).

DST80 downgrade recovery, full 80 bit exclusive

Verified DST80 cipher (4/4 vectors) plus the rarely-finished recovery: keyL via DST40 downgrade (page30/page4 unlock) and keyR brute on CPU or GPU. Covers Toyota 8A and Kia/Hyundai 4E (TMS37126).

AUT64 / TK5561 with real constants exclusive

Not just the cipher, but the full TK5561 structure per Hicks (TCHES 2018): kG-from-IDCode (Def. 8 + TD table), 24-round TU/TL and pbox recovery over 5040 cyclic candidates.

Ultralight-C PKO & counterfeit detector exclusive

IACR 2026/100 implemented as detector + keyspace reduction (112 → 4×28 bit), offline 3DES segment brute (CPU & GPU) and counterfeit PRNG detection (ULCG UID-1589, 16-bit LFSR). Carried by an own raw DES/3DES engine (SsrDes) that also computes the weak keys .NET refuses.

Clone Magic & BMW-EWS key maker exclusive

Clone Magic: per-chip transponder catalog (EU + USA/Asia) with an honest status per chip (Ready / Recover-then-Write / NeedSecret / in progress). BMW-EWS key maker: clean-room EEPROM→precode plan as a replacement for the dead AK90 software — no cipher break, but the documented vendor path.

Clean-room calculators instead of a black box exclusive

What Xhorse/OBDSTAR sell as opaque tables, here traceable from public sources: GM PCM seed/key (256-algo interpreter, stgterm format), VAG · Fiat · Ford/Volvo seed-key (from “Beneath the Bonnet”), plus a data-driven seed-key engine (families + an open profile format to load more). Also Wiegand 26/34, VIN check digit and an EEPROM checksum suite. No secret OEM tables in the build — sellable where the black boxes are not.

§3Capabilities per chip

What the suite can actually do per transponder — read, key recovery, offline processing (no live reader, from sniff/transcription), cloning and detection/audit.

Fig. 1 — capability matrix. Gold = exclusive in-house path (engine/GPU/recovery).
Chip / fobReadRecoveryOfflineCloneDetectEngine
MIFARE Classic✓✓ CPU engine✓ mfkey32/nested/static✓ magic/PM3✓ access mapown, GPL-free
MIFARE Ultralight-C✓✓ PKO 2²⁸✓ CPU+GPU○ own tags✓ PKO+fake-PRNGSsrDes (raw)
DESFire EV1/2/3✓ auth audit— (AES)——✓ app mapAN10922 div
NTAG / Ultralight✓——✓ magic✓ NDEF/ID—
iCLASS legacy✓✓ key div✓ hash0/DES○ PM3✓DES + hash0
ICODE / ISO 15693✓——✓✓CRC-16/X-25
Hitag2 (ID46)✓✓ 2 auths, GPU✓ masks/PDEP✓ T5577✓ TMCFown, ssrhitag2
DST40 (4C/4D)✓✓ 2⁴⁰ GPU✓ oracle✓✓own kernel
DST80 (4E/8A)✓✓ downgrade+GPU✓ keyL/keyR○ unlock needed✓own, 80-bit
Megamos ID48✓○ em4x70 / 2⁴⁹✓ solver○ pair to car✓ID48LIB (MIT)
AUT64 / TK5561 (8C)✓✓ pbox 5040✓ kG-from-ID○ constants✓Hicks-faithful
KeeLoq (RKE)✓ hop decode— (scope)—○ with device key✓ RollJam/-BackNLFSR 528
PCF7935 (Philips)✓ lock model— no break—○ copy-w/-orig.✓ config 8/8vendor path
EM4100 / LF access✓— fixed code—✓ auto-clone✓T5577 encode
T5577 / EM4305 / Q5✓✓ PW dict—✓ universal target✓ block019 presets
FDX-B / iButton✓——✓ RW1990✓ CRCKERMIT / CRC8
Hitag S (S32/256/2048)✓✓ 2 auths✓ config/crypto○ magic✓= Hitag2 cipher
LEGIC Prime✓✓ no cipher✓ decoder○ magic/PM3✓CRC/PRNG (own)
ICODE SLIX (audio figure)✓— UID✓ .nfc parse○ magic/15693✓ClonyBox*
✓ gold exclusive in-house path ✓ covered by the suite ○ partial / hardware-pending — no (scope or no public break)

§4Crypto engines

Every engine runs through a central self-test against its test vectors — currently 68 of 68 green. The one deliberate exception is the Atmel cipher: spec-faithful and structurally verified, but without a public KAT and therefore honestly marked 🟡.

Crypto-1 / MIFARE Classicssrcrypto.dll · SsrCrypto
Own clean-room recovery core: mfkey32, nested, nested_multi, nested_blind, FM11RF08S. Live blind crack on S50 ≈ 42 s. GPL-free.
DST40 / DST80Dst40 · Dst80 · *Recovery
DST40 bit-exact (5CA1BA/CD6504); DST80 4/4 (Apache-2.0 vectors) plus 80-bit downgrade recovery. CPU + GPU.
Hitag2 (ID46)ssrhitag2.dll · Hitag2Recovery
Cipher end-to-end against the RFIDler reference (06AC851BABC3); recovery from 2 auths, self-test 5/5, GPU bridge.
Megamos ID48ssrid48.dll · Em4x70
Solver live-verified. Instant with the em4x70 partial; without it a 2⁴⁹ TMTO (GPU/FPGA) 🟡.
AUT64 / TK5561Aut64 · Aut64Tk5561
64-bit Feistel, 120-bit key (reference AB21B6C5224F6D9D) + full Hicks TK5561 constants.
DES / 3DES (raw) · Ultralight-CSsrDes · UlcCrypto · UlcPko
Own raw DES/2K3DES engine (KAT 85E813540F0AB405) that also computes the weak keys .NET refuses. Carries ULC 0x1A auth, PKO keyspace reduction and offline brute.
More ciphersKeeLoq · KeyDiversification · IClassCrypto · Pcf7935 · AtmelCipher
KeeLoq NLFSR (0xE44F4CDF), AN10922 AES-CMAC diversification, iCLASS hash0+DES, PCF7935 lock model (8/8), Atmel SM/CM spec-faithful 🟡.

§5GPU-accelerated recovery

Four in-house OpenCL kernels, all verified against known-answer vectors on an RTX 5050 (OpenCL 3.0). The zero-dependency host loads the NVIDIA ICD itself; no CUDA toolkit is installed. Every GPU result is then cross-checked against its own cipher oracle — the GPU accelerates, but does not decide on its own.

KeeLoq and Megamos deliberately remain without a master-key brute (scope).

§6HF / NFC · 13.56 MHz

Live Card LabLiveCardLabWindow
All-in-one window live on the card: scan → recon → colour structure map (open/restricted/locked) with a decoded log. The reader is passed through, no reconnect.
MIFARE Classic auto-pwnMifareClassic · MifareAccess
Dictionary → nested/darkside → dump, access-bits map, UID→key derivation check.
DESFire / Ultralight-C / NTAGDesfireAudit · UlcCrypto
Auth audit, Type-4 audit, variant identify (EV1/2/3), app→file recon map.
ICODE / ISO 15693 (SLIX)Iso15693 · Icode · Proxmark
Inventory / dump / write / clone + CRC-16/X-25. Live path via PN5180/Proxmark 🟡.
ISO-7816 “brain” + VDV transitIso7816 · Vdv · FuzzMatrix
Status-word decoder, AID detection, VDV-KA reader + EF.DIR recon, systematic CLA/INS/P1P2 fuzz matrix (reselect before each command).
NDEF parser · iCLASS/PicopassNdefParser · IClassCrypto
URI/Text/MIME/SmartPoster with 36 URI prefixes; iCLASS legacy diversification div_key = hash0(DES(AA1,CSN)).
Consumer repair: Sonicare BrushSyncSonicareBrush · 1-click reset
Right-to-repair on your OWN brush head (NTAG213/213C): decoder (model/manufacturing code/target life/ usage counter) + UID-bound password derivation (CRC16-CCITT/0x49A3, public Hackaday/atc1441). 1-click counter reset on the Proxmark — PWD_AUTH + authenticated write, verified live on real hardware (PWD 81F680C5, PACK B1DC, counter set→reset). ⚠ Only with the verified PWD (NTAG213 locks after 3 failed attempts).

§7LF / transponders · 125–134 kHz

Keyfob StudioKeyfobStudio · Keyfob
Guided flow identify → dump → sniff → recover → write → adapt, with fob→chip selection and domain-separated PM3 commands per type.
LF accessLfTransponder
EM4100, HID, Indala, AWID, Paradox, Keri, Pyramid, ioProx, Nexwatch, Securakey, Gallagher, Nedap, PAC, Jablotron — incl. EU/USA/China/Russia families.
T5577 / EM4305 / Q5T5577Clone · T5577Config
19 config presets + template system + intelligent auto-clone (fob X → T5577). Universal LF clone target; EM4100→T5577 hardware-verified.
Hitag2 config · FDX-B · iButtonHitag2Config · FdxB · IButton
Page-3 TMCF decode (crypto/plain/locked), FDX-B pet chip (ISO 11784/85, KERMIT-CRC), 1-Wire DS1990A/Cyfral/Metakom with clone→RW1990.

§8Signal & protocol analysis

PulsPirat (internally “Radio Paul”) is the built-in signal and protocol analysis: it takes pulse/bitstream captures from various sources and decodes them into frames, codes and runnable firmware templates. Hardened on ~14,000 real samples — zero crashes.

PulsPirat / “Radio Paul”SignalAnalyzer
Inputs Flipper .sub, SDR, Proxmark and ESP32; PWM + PPM decode, frame extraction, code→log→firmware. The core of SubGHz/RKE analysis.
Protocol templatesSignalAnalyzer.Templates
EV1527, PT2262/2264, HT12E, KeeLoq, X10, Somfy, Nice, Came and GM-RKE — automatic mapping of the detected protocol to the bitstream.
RKE rolling awarenessRkeEncoder · KeeLoq
Encoder catalog (fixed/learning/rolling) plus attack knowledge: RollJam, RollBack, RollingPWN (CVE-2021-46145), relay/PKES — as awareness, not a turnkey opener.
ISM sensor decodersRfSensors
433/868/315-MHz payload → physical values: Nexus/Digitech (temp/humidity), Acurite 606TX (CRC8-checked — bad frames dropped), EV1527/PT2262 fixed-code (garage door/socket/doorbell: address + button), TPMS sensor ID. Every decoder with a round-trip KAT, clean-room from public facts. PulsPirat feeds detected bitstreams straight in here.

§9Automotive & immobiliser

Calculator hubImmoCalc · GmSeedKey · SeedKeyEngine · EcuDiagSeedKey
Seed-key: GM PCM (256-algo interpreter, stgterm format), VAG · Fiat · Ford/Volvo (from “Beneath the Bonnet”), KW1281 SKC over OBD — plus a data-driven engine with an open profile format to load more. Access/automotive: Wiegand 26/34-bit, VIN check digit + model year, EEPROM checksums (CRC8/16/32, Fletcher). All public/clean-room; proprietary PIN/incode honestly marked “vendor/online”.
EEPROM file workbenchImmobilizer window
Load a dump (.bin from TL866/XGecu/Orange5/CH341A …) → hex view + chip candidate + BMW parse → byte patch (offset/hex) → recompute checksum → save → write back with the programmer. Universal, no driver.
BMW EWS → CAS → FEM/BDCBmwEws.Systems
11 systems with transponder/EEPROM/ISN + honest status: EWS2/3/3.3/4 (PCF7935 precode, like AK90) · CAS1–3 (Hitag2 recover + precode) · CAS3+ (EEPROM encrypted 🟡) · CAS4/FEM-BDC (AES/ISN bench 🟡).
Immobiliser knowledge base (≈24 makers)ImmobilizerData.ModuleHints
Public module/EEPROM/transponder facts per brand — EU, USA (Ford PATS, GM PK3, Chrysler SKIM, Tesla), Asia (Toyota, Nissan NATS, Honda, Hyundai SMARTRA …), India (Maruti/Tata/Mahindra), Russia (Lada/AvtoVAZ, GAZ/UAZ). Tells where dump/PIN/ISN live; exact offsets from the dump 🟡.
Clone Magic · vehicle→chipCloneMagicWindow · VehicleTransponder · Keyfob
Per-chip clone status (42 transponder types), ~1200 vehicle applications (make/model/year → chip + path). Vehicle mapping explicitly labelled as unreliable.
OBD / ELM327 diagnostics 🟡 work in progressElm327 · ObdProfiles · VpicClient · UdsCodes
Clean-room ELM327 driver (BT-SPP/USB = COM): OBD mode 01/03/09, UDS 0x22/0x27, ISO-TP. Read VIN → NHTSA vPIC decode (public domain, +offline WMI). 7 OEM profiles. UDS answers in plain text (ISO 14229: 7F 27 35 → “Invalid key”). Read-only by default, injection only standing + authorised. 🟡 Not yet verified end-to-end against a real ELM327/vehicle — driver/parser built, live test pending.
VAG SA2 SecurityAccess (end-to-end)Sa2Interpreter · Sa2Extract
Own SA2 bytecode VM (10 opcodes, clean-room, verified against published KATs) — one interpreter covers hundreds of VAG UDS ECUs. Script extraction from SGO (@0x1BC) / ODX. In the OBD window: load file → seed (27 01) → key → 27 02 → plain-text result.
Seed→key auto-solverSeedKeySolver · SeedKeyEngine
Feed public (seed,key) pairs → searches not/rotate/swap + xor/add/sub constant (32/24/16-bit) → reports only a formula that holds against all pairs (no overfit). A hit is usable directly as a SecurityAccess profile. Example: Hyundai/Kia cluster derived in-house (KEY=~SEED+0x0D, 6/6). Real LFSR/block ciphers are honestly not faked.
Bosch flash checksumsBoschChecksum
ME7 (16-bit) + MED9.1 (32-bit) sum/complement pairs over range tables — verify detects tampering, repair heals before the flash (otherwise ECU limp mode). Public Bosch scheme, pure arithmetic. Range/offsets input-/mappack-dependent 🟡 (not guessed).

§10Secure smartcard MCU

Recon and awareness layer for secure MCUs (pay-TV / banking / SIM) — deterministic analysis, no CAS or attack tool in the product.

MCU registry (17 chips)SmartcardMcu
AT90SC, P8WE5033, P5 SmartMX/CC036, ST19XL34V2/WL18, TT80, AT88SC, SLE4442, Infineon SLE66/70/78, SmartMX2/3, ST23/33.
ATR decoder (ISO 7816-3)SmartcardMcu
TS/T0/interface bytes/historical/TCK, Fi/Di, chip hint — fully deterministic.

§11Hardware & interoperability

PN532 / PCR532 (USB)Pn532Reader · Win32Serial
Read/write HF cards, hardware-verified (PN532 v1.6). The CH340 USB reader only talks over Win32 CreateFile — an own Win32Serial layer, not the stock serial API.
Proxmark3 Easy (Iceman v4.21611)Proxmark · Pm3Route
Fully hardware-verified (2026-09-14): HF — scan/identify, Mifare Classic read (hf mf rdbl) + auto-pwn + dump, NTAG recon (hf mfu dump) + write (hf mfu wrbl, NDEF, auth-PWD), magic-UID clone gen1a (backdoor) + gen2/CUID (block-0 --force), DESFire info (hf mfdes), ISO-7816 session (chained hf 14a apdu -k). LF — T55xx detect + EM4100 clone (lf em 410x). Editor actions in Live Card Lab: UID→magic, EM4100→T5577, Sonicare reset. Auto client detection + Qt/libs environment. Flash: proxmarkbuilds.org (RRG/Generic 512k), bootrom→fullimage.
FR-RATEL / iCopyFrRatel
125 kHz – 13.56 MHz access cloner over reversed USB-HID (RC4). LF EM4100/HID/T5577 + HF Mifare.
ESP32-S3 LF/HF add-onEspApiClient · EspLfBackend
S3 N16R8 + EM4095 + RC522-I²C + microSD + OLED, pin plan locked, web interface + PC sync API. PCF7931 RMT firmware 🟡.
ACR122U (ACS · PC/SC) 🟡Acr122uReader · Acr122CardReader
Full 4th reader profile via the Windows-native PC/SC stack (winscard.dll, no third-party DLL): scan (SAK/ATQA via PN532 passthrough), MIFARE Classic (FF 82/86/B0/D6), NTAG/Ultralight read/write, ISO7816 APDU for smartcards. Usable in Live Card Lab / NDEF-Studio / all audits. PN532 behind PC/SC → no ISO15693/LF. Spec/SDK-based, not yet confirmed on a real reader.
Flipper Zero import · ChameleonFlipperImport
.nfc/.rfid/.sub/.ibutton/.picopass + dict merge (6/6); Chameleon auto-detect.
Integrated CVEs & exportSaflok · StoredValue · DumpExport
Public NFC CVEs (Telenot, KioSoft, FM11RF08S, Be-Tech, Saflok — identify + report) plus dump export/diff and known-key annotation.

§12Operation & workflow

Reader selection + one connectReaderManager
“Detect devices” (COM friendly name + USB VID + PC/SC; Proxmark via VID_2D2D even with a generic name) → pick a reader → one connect opens it and passes it through to the Live Card Lab.
Reader profiles (one interface, honest capabilities)ICardReader
PN532 / Proxmark / FR-RATEL implement the same profile and each report only what they really can do — Proxmark = everything (scan/Mifare/APDU/ISO15693/LF); PN532 = HF (scan/Mifare/APDU); FR-RATEL = scan + Mifare dump (no APDU). Analysis windows use the profile; anything unsupported is reported honestly instead of faked.
Keyfob Studio (guided)KeyfobStudio
Identify → dump → sniff → recovery, with fob→chip selection and domain-separated PM3 commands per type. Crypto keyfobs are read/dumped and fed to key recovery — no writing/cloning of these fobs (not testable without a real fob).
Local cracking (tab)LocalCrackingWindow
Pick a fob → engine auto-selected (Hitag2 / DST40 / DST80 / Megamos) → sniff data → crack (CPU dict/masks or GPU) with ETA. Every result is cross-checked against the verified cipher (oracle-gated).
Clone Magic (tab)CloneMagicWindow
Per-chip catalog with honest status; always opens, even with just a PN532. With a loaded dump, direct HF magic write.
Crypto self-test (one button)CryptoSelfTest
Runs all engines against their test vectors → PASS/FAIL, currently 68/68 green. Also logged at startup.

§13Scope, sources & ethics

Every capability comes from public, open-source or clean-room sources — no leaked specifications, no stolen CA or manufacturer keys. No turnkey vehicle-theft tool, no pay-TV CAS in the product, and for the Ultralight-C attack no relay/session hijack of third-party operator readers and no credential forger. Use is for authorised repair and pentests with proof of ownership; PoCs run exclusively on owned or released hardware.

§14Sponsoring & Test-Hardware · Sponsorship & Test Hardware

Der Krypto- und Protokoll-Kern ist gegen publizierte Testvektoren verifiziert (68/68) und der komplette Reader-Kern (Proxmark3, HF + LF) an echter Hardware bestätigt. Einige Engines sind spec-treu und strukturell verifiziert, aber noch nicht gegen ein echtes Exemplar gegengeprüft (🟡) — weil das jeweilige physische Testobjekt fehlt. Wer Test-Hardware (oder deren Finanzierung) beisteuert, wird hier namentlich gewürdigt.

🇩🇪 Deutsch

Gesucht (nur legale, autorisierte Tests am eigenen Material): Auto-Keyfobs/Transponder, HF-Zutrittskarten, ISO-15693-Spielzeug, OBD/ECU-Diagnose-Hardware, ISM-Funksender. Jedes Teil hebt eine 🟡-Engine auf hardware-verifiziert.

🇬🇧 English

Wanted (legal, authorised testing on owned material only): a sponsor who contributes test hardware — or its funding — is credited here by name. Every part moves a 🟡 engine to hardware-verified and makes the tool provably stronger.

🇨🇳 中文

征集(仅限对自有物料的合法授权测试):赞助测试硬件或其资金者,将在此署名致谢。每一件都能把一个 🟡 引擎提升为硬件验证通过,让工具更强。

🇷🇺 Русский

Требуется (только легальное авторизованное тестирование на собственном материале): спонсор, предоставивший тестовое оборудование или его финансирование, будет упомянут здесь поимённо. Каждая деталь переводит движок из 🟡 в проверено на оборудовании.

Wunschliste · Wishlist · 需求清单 · Список

Kontakt · Contact · 联系 · Контакт: info@ssr-labs.de · SSR-Labs.de