SSR-Labs · Technical Capability Brief
A Windows workbench with in-house, GPL-free crypto engines, GPU-accelerated key recovery and a verified transponder knowledge base — built entirely from public and clean-room sources.
The suite covers the full analysis cycle of authorised NFC/RFID work: identify, read, key recovery, cloning and reporting — for HF cards (13.56 MHz), LF transponders (125–134 kHz) and automotive immobilisers. The core is deliberately self-contained: Crypto-1 recovery runs on a self-written, GPL-free engine, and four in-house OpenCL kernels move the heavy brute-force runs onto the GPU. Every shipped cipher is verified against published known-answer vectors or against hardware; every GPU result is cross-checked against its cipher oracle.
Nothing is marked “done” unless it is backed by test vectors or real hardware. Open items are flagged as such.
Section 2 lists the unique selling points, Section 3 shows per chip what the suite can actually do. The technical Sections 4–11 go into detail, Section 12 describes operation; Section 13 states scope and source discipline.
These capabilities are developed in-house and, in this combination, are what sets the tool apart from stock tooling — no third-party or copyleft code in the shipping build.
What the software actually does (not “info about…”, but computes / cracks / reads)
Full clean-room reimplementation in ssrcrypto.dll: mfkey32, nested, nested_multi, nested_blind and FM11RF08S fingerprint. No more GPL/crapto1 in the build — hence sellable without a copyleft leash. -O3-optimised, faster than the former upstream; self-test 200/200, live blind crack on S50 in ≈ 42 s.
Self-written and zero-dependency — they load the NVIDIA ICD at runtime themselves, needing neither a CUDA toolkit nor CL headers. All verified against KAT on an RTX 5050: DST40 (~135 M keys/s), Hitag2 (~1.1 billion keys/s), DST80-keyR (80-bit, end-to-end) and Ultralight-C 2K3DES (DES kernel bit-identical to the CPU engine; PKO page 2²⁸ in 3.9 s).
Verified DST80 cipher (4/4 vectors) plus the rarely-finished recovery: keyL via DST40 downgrade (page30/page4 unlock) and keyR brute on CPU or GPU. Covers Toyota 8A and Kia/Hyundai 4E (TMS37126).
Not just the cipher, but the full TK5561 structure per Hicks (TCHES 2018): kG-from-IDCode (Def. 8 + TD table), 24-round TU/TL and pbox recovery over 5040 cyclic candidates.
IACR 2026/100 implemented as detector + keyspace reduction (112 → 4×28 bit), offline 3DES segment brute (CPU & GPU) and counterfeit PRNG detection (ULCG UID-1589, 16-bit LFSR). Carried by an own raw DES/3DES engine (SsrDes) that also computes the weak keys .NET refuses.
Clone Magic: per-chip transponder catalog (EU + USA/Asia) with an honest status per chip (Ready / Recover-then-Write / NeedSecret / in progress). BMW-EWS key maker: clean-room EEPROM→precode plan as a replacement for the dead AK90 software — no cipher break, but the documented vendor path.
What Xhorse/OBDSTAR sell as opaque tables, here traceable from public sources: GM PCM seed/key (256-algo interpreter, stgterm format), VAG · Fiat · Ford/Volvo seed-key (from “Beneath the Bonnet”), plus a data-driven seed-key engine (families + an open profile format to load more). Also Wiegand 26/34, VIN check digit and an EEPROM checksum suite. No secret OEM tables in the build — sellable where the black boxes are not.
What the suite can actually do per transponder — read, key recovery, offline processing (no live reader, from sniff/transcription), cloning and detection/audit.
| Chip / fob | Read | Recovery | Offline | Clone | Detect | Engine |
|---|---|---|---|---|---|---|
| MIFARE Classic | ✓ | ✓ CPU engine | ✓ mfkey32/nested/static | ✓ magic/PM3 | ✓ access map | own, GPL-free |
| MIFARE Ultralight-C | ✓ | ✓ PKO 2²⁸ | ✓ CPU+GPU | ○ own tags | ✓ PKO+fake-PRNG | SsrDes (raw) |
| DESFire EV1/2/3 | ✓ auth audit | — (AES) | — | — | ✓ app map | AN10922 div |
| NTAG / Ultralight | ✓ | — | — | ✓ magic | ✓ NDEF/ID | — |
| iCLASS legacy | ✓ | ✓ key div | ✓ hash0/DES | ○ PM3 | ✓ | DES + hash0 |
| ICODE / ISO 15693 | ✓ | — | — | ✓ | ✓ | CRC-16/X-25 |
| Hitag2 (ID46) | ✓ | ✓ 2 auths, GPU | ✓ masks/PDEP | ✓ T5577 | ✓ TMCF | own, ssrhitag2 |
| DST40 (4C/4D) | ✓ | ✓ 2⁴⁰ GPU | ✓ oracle | ✓ | ✓ | own kernel |
| DST80 (4E/8A) | ✓ | ✓ downgrade+GPU | ✓ keyL/keyR | ○ unlock needed | ✓ | own, 80-bit |
| Megamos ID48 | ✓ | ○ em4x70 / 2⁴⁹ | ✓ solver | ○ pair to car | ✓ | ID48LIB (MIT) |
| AUT64 / TK5561 (8C) | ✓ | ✓ pbox 5040 | ✓ kG-from-ID | ○ constants | ✓ | Hicks-faithful |
| KeeLoq (RKE) | ✓ hop decode | — (scope) | — | ○ with device key | ✓ RollJam/-Back | NLFSR 528 |
| PCF7935 (Philips) | ✓ lock model | — no break | — | ○ copy-w/-orig. | ✓ config 8/8 | vendor path |
| EM4100 / LF access | ✓ | — fixed code | — | ✓ auto-clone | ✓ | T5577 encode |
| T5577 / EM4305 / Q5 | ✓ | ✓ PW dict | — | ✓ universal target | ✓ block0 | 19 presets |
| FDX-B / iButton | ✓ | — | — | ✓ RW1990 | ✓ CRC | KERMIT / CRC8 |
| Hitag S (S32/256/2048) | ✓ | ✓ 2 auths | ✓ config/crypto | ○ magic | ✓ | = Hitag2 cipher |
| LEGIC Prime | ✓ | ✓ no cipher | ✓ decoder | ○ magic/PM3 | ✓ | CRC/PRNG (own) |
| ICODE SLIX (audio figure) | ✓ | — UID | ✓ .nfc parse | ○ magic/15693 | ✓ | ClonyBox* |
Every engine runs through a central self-test against its test vectors — currently 68 of 68 green. The one deliberate exception is the Atmel cipher: spec-faithful and structurally verified, but without a public KAT and therefore honestly marked 🟡.
Four in-house OpenCL kernels, all verified against known-answer vectors on an RTX 5050 (OpenCL 3.0). The zero-dependency host loads the NVIDIA ICD itself; no CUDA toolkit is installed. Every GPU result is then cross-checked against its own cipher oracle — the GPU accelerates, but does not decide on its own.
KeeLoq and Megamos deliberately remain without a master-key brute (scope).
PulsPirat (internally “Radio Paul”) is the built-in signal and protocol analysis: it takes pulse/bitstream captures from various sources and decodes them into frames, codes and runnable firmware templates. Hardened on ~14,000 real samples — zero crashes.
Recon and awareness layer for secure MCUs (pay-TV / banking / SIM) — deterministic analysis, no CAS or attack tool in the product.
Every capability comes from public, open-source or clean-room sources — no leaked specifications, no stolen CA or manufacturer keys. No turnkey vehicle-theft tool, no pay-TV CAS in the product, and for the Ultralight-C attack no relay/session hijack of third-party operator readers and no credential forger. Use is for authorised repair and pentests with proof of ownership; PoCs run exclusively on owned or released hardware.
Der Krypto- und Protokoll-Kern ist gegen publizierte Testvektoren verifiziert (68/68) und der komplette Reader-Kern (Proxmark3, HF + LF) an echter Hardware bestätigt. Einige Engines sind spec-treu und strukturell verifiziert, aber noch nicht gegen ein echtes Exemplar gegengeprüft (🟡) — weil das jeweilige physische Testobjekt fehlt. Wer Test-Hardware (oder deren Finanzierung) beisteuert, wird hier namentlich gewürdigt.
Gesucht (nur legale, autorisierte Tests am eigenen Material): Auto-Keyfobs/Transponder, HF-Zutrittskarten, ISO-15693-Spielzeug, OBD/ECU-Diagnose-Hardware, ISM-Funksender. Jedes Teil hebt eine 🟡-Engine auf hardware-verifiziert.
Wanted (legal, authorised testing on owned material only): a sponsor who contributes test hardware — or its funding — is credited here by name. Every part moves a 🟡 engine to hardware-verified and makes the tool provably stronger.
征集(仅限对自有物料的合法授权测试):赞助测试硬件或其资金者,将在此署名致谢。每一件都能把一个 🟡 引擎提升为硬件验证通过,让工具更强。
Требуется (только легальное авторизованное тестирование на собственном материале): спонсор, предоставивший тестовое оборудование или его финансирование, будет упомянут здесь поимённо. Каждая деталь переводит движок из 🟡 в проверено на оборудовании.
Kontakt · Contact · 联系 · Контакт: info@ssr-labs.de · SSR-Labs.de