Pages: [1]
Author Topic: Decrypting VAG M/EDC17 Immobiliser Data  (Read 4937 times)
navatar_
Newbie
*

Karma: +1/-1
Offline Offline

Posts: 18


« on: November 21, 2019, 01:08:52 PM »

Hi everyone. I've recently been studying with how the immobiliser data (PIN, CS & MAC) is stored and encrypted on VAG EDC17 ECUs.

So far my understanding is as follows:
Every 17-series ECU has a unique OTP burned from factory in to its tricore flash at 0x17F00 and is a few lines long. The EEPROM is structured in blocks 0x80 bytes long and the first byte of the block signifies its category.

The blocks of interest for immo data are blocks 08, 09 and 0A and the immo data is repeated in these blocks. Each block also has 2 checksums: a 2 byte CRC near the beginning and 4 byte CRC at the tail of the block, these algos have very kindly been RE'd and documented with source by H2Deetoo and ozzy_rp elsewhere on this forum.

I understand that the immo data is ciphered with the OTP data and therefore the EEPROM immo data cannot be deciphered or altered without being accompanied with its respective flash read (obviously read must include the OTP section).

I am however at a total loss as to how to decrypt this small section of data. I thought it might be some sort of simple XOR/substitution and/or shuffling method but despite my many attempts, I have been unable to get this algo worked out. Have found 2 functions pointing to 0x17F10 using Ghidra but the one returns a bool and the other returns a single byte and I don't think either function/label is important.

If anyone could provide insight on the cipher or guidance in the right direction it would be hugely appreciated.
Logged
carservice
Newbie
*

Karma: +0/-1
Offline Offline

Posts: 7


« Reply #1 on: February 01, 2020, 06:30:41 AM »

hi
Have you succeeded in your research?
 I'm also looking for this calculation.
In fact, it's only related to CPU HW ID。
Logged
sandor1987
Jr. Member
**

Karma: +5/-4
Offline Offline

Posts: 46


« Reply #2 on: February 03, 2020, 03:10:28 PM »

also here finding a solution!
Logged
rwgodoy
Newbie
*

Karma: +0/-0
Offline Offline

Posts: 1


« Reply #3 on: July 25, 2020, 09:16:18 AM »

I'm looking for a solution too. if someone got, pls e-mail me ricardowermond@gmail.com
Logged
Pages: [1]
  Print  
 
Jump to:  

Powered by SMF 1.1.21 | SMF © 2015, Simple Machines Page created in 0.114 seconds with 16 queries. (Pretty URLs adds 0s, 0q)