兴趣内容
精选
最新
小米空气净化器RFID芯片滤芯破解重置
小米带芯片的空气净化器滤芯寿命是按照通电使用时间计算的,可能没怎么使用但时间到了就频繁提示购买新滤芯,一是浪费,二是穷,所以就折腾一下,后续内容仅为技术学习与讨论,不涉及侵犯知识产权等,如有问题,私信联系我删除内容。米家小米空气净化器滤芯滤网除菌版升级款除甲醛除菌除烟味适用于1代/2/2S/3/pro169元京东去购买 思路来自CSDN文章小米空气净化器滤芯RFID解密_robur的博客-CSDN博客_rfid解密我采用的方案是手头的arduino mega 2560 + RC522小板子 MEGA2560R3开发板扩展版ATMEGA16U2CH340G适用于Arduino官方版88元天猫精选去购买 MFRC-522RC522RFID射频IC卡感应模块读卡器送S50复旦卡钥匙扣6.9元天猫精选去购买 然后小撸一段代码就ok了:1:读取到滤芯底部RFID的UID2:通过算法计算出密码 3:擦掉BLOCK 8的数据【PM3】重置小米空气净化器滤芯 | Ray of Hope raycn.pub如果你不会或者麻烦,淘宝上有写好的标签,你也可以只换个标签也行。 其实淘宝上有替换的滤芯rfid贴纸,几块钱一张,链接无法添加你们可以搜一下后边是我贴的代码,看不懂就别看了哈哈/*【Arduino】MEGA 2560 MFRC-522 RC522 RFID射频 读写NTAG213射频标签 米空气净化器2S的正版滤芯,底下贴了一张NXP NTAG213射频标签。 空气净化器靠这个射频标签中的数据,判断滤芯的剩余寿命,以及是不是正版滤芯。 射频标签的密码采用了“一卡一密”。 密码采用射频卡UID计算得来 得到密码后只要把BLOCK 8清空掉就可以重置滤芯仅用于技术学习与交流RFID与Arduino的连线SDA------------------------Digital 53SCK------------------------Digital 52MOSI----------------------Digital 51MISO----------------------Digital 50IRQ------------------------不用连接GND-----------------------GNDRST------------------------Digital 2 3.3V------------------------3.3V 千万不要连接到5V接口!!!*/#include #include #include #include #include #include #include #include #define SS_PIN 53#define RST_PIN 2MFRC522 mfrc522SS_PIN, RST_PIN;MFRC522::MIFARE_Key key;int serial_putc char c, struct __file * { Serial.write c ; return c;}void printf_beginvoid{ fdevopen &serial_putc, 0 ;}void setup { // put your setup code here, to run once: Serial.begin115200; printf_begin; SPI.begin; mfrc522.PCD_Init; printf"初始化结束rn";}void loop { // put your main code here, to run repeatedly: // 寻卡 if ! mfrc522.PICC_IsNewCardPresent return; printf"寻卡成功rn"; // 选择一张卡 if ! mfrc522.PICC_ReadCardSerial return; printf"选择卡片成功,卡片UID:rn"; dump_byte_arraymfrc522.uid.uidByte, mfrc522.uid.size; Serial.println; //获取卡片类型 MFRC522::PICC_Type piccType = mfrc522.PICC_GetTypemfrc522.uid.sak; Serial.printlnmfrc522.PICC_GetTypeNamepiccType; if piccType != MFRC522::PICC_TYPE_MIFARE_UL { printf"卡片类型错误rn"; return; } printf"卡片类型正确rn"; //计算1卡1密 byte PSWBuff[] = {0x00, 0x00, 0x00, 0x00}; byte pACK[] = {0, 0};//NFCtag 返回的 16 位密码 ACK。 xiaomi_air_purifier_passwordmfrc522.uid.uidByte,PSWBuff; printf"卡片密码:"; dump_byte_arrayPSWBuff, 4; printf"rn"; MFRC522::StatusCode status; status = MFRC522::StatusCode mfrc522.PCD_NTAG216_AUTH&PSWBuff[0], pACK; if status != MFRC522::STATUS_OK { printf"认证失败rn"; } printf"认证成功rn"; byte blockAddr = 8; byte buffer[18]; byte size = sizeofbuffer; status = MFRC522::StatusCode mfrc522.MIFARE_ReadblockAddr, buffer, &size; if status != MFRC522::STATUS_OK { printf"读取失败rn"; } printf"读取 block 8 成功,block 8数据:"; dump_byte_arraybuffer, 16; printf"rn"; byte dataBlock[] = { 0x00, 0x00, 0x00, 0x00, // 1, 2, 3, 4, 0x00, 0x00, 0x00, 0x00, // 5, 6, 7, 8, 0x00, 0x00, 0x00, 0x00, // 9, 10, 255, 11, 0x00, 0x00, 0x00, 0x00 // 12, 13, 14, 15 }; //清除数据 status = MFRC522::StatusCode mfrc522.MIFARE_WriteblockAddr, dataBlock, sizeofdataBlock; if status != MFRC522::STATUS_OK { printf"写入失败rn"; } printf"写入成功rn"; delay5000; }void xiaomi_air_purifier_passwordbyte *uid, byte *PSWBuff { unsigned char output[40]; unsigned char i; utils_sha1_hexuid,7,output; PSWBuff[0] = output[output[0] % 20]; PSWBuff[1] = output[output[0]+5 % 20]; PSWBuff[2] = output[output[0]+13 % 20]; PSWBuff[3] = output[output[0]+17 % 20];}void dump_byte_arraybyte *buffer, byte bufferSize { for byte i = 0; i < bufferSize; i++ { Serial.printbuffer[i] < 0x10 ? " 0" : " "; Serial.printbuffer[i], HEX; }}
23-01-16

公众号


