How do I open the garage door (please do not imitate illegally)

This article aims to open the garage electric rolling shutter door by radio remote control without using the original key. It conducts an in-depth study of ASK/OOK encoding/decoding, and uses a Raspberry Pi + a five-yuan transmitter module to realize various postures for opening the garage door. This article applies to mainstream 315/433MHz radio frequency remote control.

Background

The garage is equipped with an electric rolling shutter door. In order to understand its safety and to control it independently, we studied its remote control principle. In fact, during this process, I tested almost all cordless remote controls in my home, including electric curtains, projection screens, electric clothes hangers, and car keys. Except for the car key, everything else is similar, that is, ASK/OOK encoding.

ASK, simply understood, is amplitude modulation, using different amplitudes to represent different information. OOK is a special case of ASK, because there are only 0 and 1 to represent. You can use carrier to represent 1 and no carrier to represent 0. But in fact it is not so direct. Pulse width modulation (PWM) is usually added to improve the anti-interference ability.

Use HackRF to determine feasibility

It is said that some garage doors have rolling codes (the codes change). We can first use HackRF to do a simple replay attack test.

Record 2 seconds of signal and play back:

hackrf_transfer -f 433920000 -s 2000000 -a 1 -r capture.raw -n 4000000 -g 40 -l 16
hackrf_transfer -f 433920000 -s 2000000 -a 1 -t capture.raw -x 40

Some operating tips:

call hackrf_set_sample_rate(2000000 Hz/2.000 MHz)
call hackrf_set_hw_sync_mode(0)
call hackrf_set_freq(433920000 Hz/433.920 MHz)
call hackrf_set_amp_enable(1)
samples_to_xfer 4000000/4Mio
Stop with Ctrl-C
 3.9 MiB / 1.000 sec = 3.9 MiB/second
 3.9 MiB / 1.000 sec = 3.9 MiB/second
 0.3 MiB / 1.000 sec = 0.3 MiB/second
Exiting... hackrf_is_streaming() result: streaming terminated (-1004)

The recorded signal used for actual measurement can be controlled (if not, pay attention to adjusting the gain of the HackRF amplifier). But this does not have much technical content, and the cost is high and the amount of data is large. Our goal is to decode and then re-encode/play back.

Use GNU Radio to record signals

Use GNU Radio to build a simple receiving block diagram. On the one hand, the received signal is saved to a file, and on the other hand, the signal is displayed in a waterfall chart as a real-time feedback. Because the remote control signal is 433.92MHz, the center frequency can be set near this; the sampling rate of 2M is enough.

How do I open the garage door (please do not imitate illegally)

The following picture is a waterfall chart during operation, in which the remote control is pressed 5 times.

How do I open the garage door (please do not imitate illegally)

Use Inspectrum to decode manually

Use apt-get to install inspectrum, or download the latest Inspectrum code and compile it yourself according to the documentation. I\’ve tried it on Debian and Mac and it works fine (using MacPorts on Mac requires a bunch of dependencies to be installed). Not much to say about compilation, the following are the main steps of decoding:

  1. Open the previously recorded file with Inspectrum, and set the sampling rate to the sampling rate during recording (2M);
  2. Drag horizontally to find the area with signal;
  3. Right-click on the original signal, Add derived plot => Add sample plot;
  4. At this time, two horizontal lines will appear on the original signal. Drag with the mouse to adjust the position and width of the center frequency;
  5. On the original signal Right-click, Add derived plot => Add amplitude plot;
  6. Right-click on the Amplitude plot, Add derived plot => Add threshold plot;
  7. Check \”Enable cursors\”, two vertical lines will appear;
  8. Zoom enlarges the signal diagram and moves the two vertical lines so that their width contains one symbol. Note that the leading high and low levels (start1, start0) are skipped. Data is usually pulse width encoded, and a pair of high and low levels represents a bit: a wider high level represents a 1, and a wider low level represents a 0. You should be able to see this pattern from the picture.
  9. Change the number of symbols to include the entire signal area (65 symbols in the picture, which is equivalent to a complete key), and adjust the head-to-tail alignment (there is usually a longer low level at the end), At this time, the symbol rate can be obtained, that is, the baud rate (for OOK, it is actually equivalent to the bit rate).

How do I open the garage door (please do not imitate illegally)

Finally, right-click on the Amplitude plot or Threshold plot respectively and Extract symbols (to stdout) to get the decoded data. The former is equivalent to an analog signal, a simple understanding: positive numbers represent 1, negative numbers represent 0; the latter is the bit stream we want.

How do I open the garage door (please do not imitate illegally)

To confirm that the decoding is correct, you can select another signal area and do the same operation to see if the results are consistent. After all, ASK is not strong in anti-interference and may sometimes be poor. One or two bits. Usually, press the remote, same. The data will be sent several times.

Remote control signal encoding analysis

Based on the previous decoding and the analysis of more remote controls, a model can be summarized. The following parts (parameters):

  • start1: The starting high-level time length;
  • start0: The starting low-level time length;
  • stop0: The ending low-level time length;
  • period: The period of each bit. In PWM coding, each bit corresponds to a pair of high/low levels, and they are always high first and then low;
  • duty: Duty cycle, for example, the duty cycle is 75%, which means that if about 75% of a cycle is high level, it represents 1; and about 75% of it is low level, it represents 0;
  • bits: The actual bit stream.

The duty cycle here must be greater than 50%, usually around 75%, which can separate the two voltages (in each cycle) The ratio difference between levels can reduce misjudgments at the receiving end; it can also ensure that two levels can be sampled during reception, which is also for In order to reduce bit errors. Imagine that for a duty cycle of 99%, the level of 1% period may not be sampled by the receiving end, resulting in the same level of 199% (or even longer) period being sampled, so that when decoding

Launch module

Initially, I wanted to use GNU. Radio performs ASK/OOK encoding and transmission. The versatile HackRF and SDR are supposed to handle this small case.

After researching, I found that this is not an easy task and requires the use of many modules. This might be a good GNU Radio practice questions. But I decided to see if there was an easier way first.

Then I drooled over TI’s EZ430-Chronos watch and looked for a “cheap” RFcat, but found that it was not easy to buy. Arrived. Finally, I found the real cheap one on the all-purpose fake store. Dongdong: It’s only 5 yuan! (You can’t suffer a loss or be cheated.)

This module is very simple. It modulates/transmits the input signal with a 433/315M carrier. level, just press the high level amplitude modulation output (please note that what is modulated here is the level, not theIt\’s data. In other words, this module doesn\’t care how long the data \”1\” corresponds to high level or low level – these are things that the encoding module has to deal with).

How do I open the garage door (please do not imitate illegally)

Coding in Python

In order to modularize the code and reduce the amount of calculation during launch, we encode first and then send plan. According to the model of the ASK signal established earlier, this signal is encoded into a waveform of alternating high and low levels and represented by an array. Each element in the array stores the corresponding timestamp when the high and low levels are switched. The waveform always starts with a high level.

Theoretically, parameters such as the start/end level duration and duty cycle do not need to be strictly accurate, but this depends on the tolerance of the receiving end, so we try to be faithful to the original signal.

The following is the core Python code snippet, where ts is the timestamp array.

 def encodePWM(self, ts):
 t=0
 ts.append(t)
 t += self.start1
 ts.append(t)
 t += self.start0
 ts.append(t)
 for i in range(0, self.bits.len):
 w = self.duty if self.bits[i] else 1 - self.duty
 ts.append(t + self.period * w)
 t += self.period
 ts.append(t)
 ts[-1] += self.stop0

Send with Raspberry Pi

The sending work is very simple: connect the DATA pin of the transmitting module to a GPIO of Raspberry Pi, and use the power supply directly from Raspberry Pi. ;

How do I open the garage door (please do not imitate illegally)

Then flip the corresponding GPIO alternately according to the timestamp. The following is the core code of Python.

 def send(self, ts). :
 b = 1
 t1 = time.time()
 GPIO.output(self.pin_tx, b)
 t1 -= ts[0]
 for t in ts[1:-1]:
 b = 1 - b
 wait = t1 + t - time.time()
 if wait > 0:
 time.sleep(wait)
 GPIO.output(self.pin_tx, b)
 wait = t1 + ts[-1] - time.time()
 if wait > 0:
 time.sleep(wait)

Although there is a certain error in using sleep to control the time, and the script language does not run that fast, it is sufficient in actual testing. The picture below is the waveform diagram of the DATA pin seen on the oscilloscope (both channels are connected to the DATA pin).

How do I open the garage door (please do not imitate illegally)

To facilitate observation, I set the encoding period to 1ms, which corresponds to the 1ms/div of the oscilloscope interface. The measured spacing in the picture is 2.78ms (expected is 2.75ms), the deviation is acceptable.

Open the garage door with multiple postures

Put the transmitting device in the garage and connect it to the network. We can control the opening/closing of the garage door independently without a key.

Mobile phone opens and closes the door

h1>

You don’t need to write the app yourself. You can log in with the ssh terminal key and execute the command. You can open/close the door with one click on your mobile phone and control it remotely.

How do I open the garage door (please do not imitate illegally)

Automatically open and close the door

Use the designated mobile phone as the key. When you hold the mobile phone near the garage (actually after connecting to the garage WiFi), Automatic door opening. The general process is:

  1. Remotely execute the router\’s iwinfo command (as shown below) to detect the device connected to it;
  2. If the MAC of the mobile phone used as the key is in the list, and the signal If the strength (SNR) exceeds the set value, it is counted as a valid connection. When the number of connections changes from 0 to non-0, the door will be opened automatically.
  3. If the number of valid connections on the key phone drops to 0, the door will be closed automatically.
ssh [email protected] \'iwinfo ra0 assoclist && iwinfo rai0 assoclist\'

The advantage of automatically closing the door is that it can prevent people from forgetting to close the door after leaving (it really happened in my house).

Open Sesame

Theoretically it can be done, but it requires reliable voiceprint recognition. Forget it. .

Lock the garage door

Set the GPIO corresponding to the transmitting module to high level. Since the transmitting module signal is strong and the distance is close, the receiving end always receives 1, resulting in No real key can open the door.

Conclusion

Garage doors that do not use rolling codes are actually not safe at all. Whether it is simple replay of the original signal or replay after decoding and then encoding, it is relatively easy to implement. But we can use this insecurity to our advantage, allowing us to open and close our doors more flexibly. In addition, using the transmitting module to emit high-level signals can interfere with the key\’s signal and achieve the effect of locking the garage door.

But if it is not by monitoring the signal of the key, it is not that easy to crack the Key with brute force. Because in addition to data matching and the same carrier frequency, ASK encoding also requires the data encoding rate and even the duration of the start and end levels to be consistent.

Using a cheap hardware transmitter module with a Raspberry Pi (or microcontroller) can encode/transmit ASK/OOK signals at low cost, which is simple and easy. However, HackRF plus Inspectrum decoding is only suitable for experimentation and debugging, and has low practical value. In the future, we will try automatic decoding of ASK/OOK (you know what decoding can be used for).

本站内容及图片来自网络,版权归原作者所有,内容仅供读者参考,不承担相关法律责任,如有侵犯请联系我们:609448834

(0)
华夏门网的头像华夏门网
上一篇 2024年12月16日 11:05:00
下一篇 2024年12月16日 11:09:31

相关推荐

  • 翻板車庫門扭簧加力需要註意的細節

    翻板車庫門扭簧加力需要註意的細節 經常有網友向昆明海頓車庫門新媒體小編咨詢翻板車庫門的扭簧如何調節,還有一些業主想要用傢裡的梅花起子給雙車位的翻板門扭簧加力,這些不規范的操作會帶來哪些安全隱患,沒有大力鉗的緊固下為什麼按照加力計算公式調整之後仍然不可正常使用? 今天,小編就帶大傢一起瞭解一下翻板車庫門的扭簧加力需要註意的細節。 一、安全準備方面 關門操作:在…

    车库门 2024年11月14日
    1010
  • 理想的别墅车库门怎么选?这篇文章告诉你答案

    欢迎关注金星宇遮阳账号,获取更多建筑外遮阳产品信息~ 理想的车库门设计,一定是既要考虑建筑物的安装限制条件,尽可能减少占用空间,保证产品的便捷性、稳定性、耐久性,同时又能满足车主对外观、色彩的个性化需求。 金星宇拥有自主发明专利的侧移车库门,自2022年开始加大线上推广以来,凭借其产品优势,目前已进驻全国各大省市,为北京、上海、深圳、南京、杭州、南昌、苏州、…

    车库门 2023年9月18日
    1440
  • 电动遥控车库门误操作开关打开了门该如何应对?

    电动遥控车库门误操作开关打开了门该如何应对? 国庆节当晚,昆明海顿车库门一用户凌晨一点左右发信息咨询,自家的电动车库门当晚10点46分突然自动打开了,是否是工厂的人打开的? 一般来说,海顿工人在帮助用户安装调试好车库门以后,都会清除测试用的配置记录,之后就不可能再动着用户家的车库门。因此,用户家的车库门有一天突然莫名其妙的打开了,基本可以排除是工厂的工人操作…

    车库门 2023年10月22日
    1850
  • 不交物业费,不能进车库门?法院判决:物业公司侵权

    记者12月9日从南通崇川法院获悉,日前,由该院宣判的一起物业纠纷案引起了不小的关注。 通讯员 任磊 扬子晚报/紫牛新闻记者 朱亚运 小王是南通市某高档小区业主,购买了该小区地下车位。小王认为物业公司服务欠佳,故一直拒付物业费,双方存在矛盾。后物业公司启用了车牌识别系统,却未将小王的车牌号录入系统,小王因车牌无法被识别而无法正常驶入地下车库,每次均需向物业公司…

    车库门 2023年10月31日
    280
  • 小车堵住车库门,警察让车主挪车,车主:挪不了,该拘拘,该判判

    原创文章,全网首发,严禁搬运,搬运必维权。本文为微小说,情节虚构,请理性阅读。 夜幕低垂,城市的灯火渐渐亮起,李明拖着疲惫的身躯从公司走出,心中只有一个念头——回家。他的家就在公司附近的一个小区里,每天他都会把车停在小区的车库里,然后步行去上班。今天,他像往常一样,带着满身的疲惫,走向车库。 然而,当他走到车库门前时,却发现一辆陌生的小车横亘在车库门口,将他…

    车库门 2024年6月11日
    440

联系我们

400-800-8888

在线咨询: QQ交谈

邮件:[email protected]

工作时间:周一至周五,9:30-18:30,节假日休息

关注微信