Eric Wild 88a6a782a2 firmware: use the full 11 bit US_FIDI.FI_DI_RATIO
US_FIDI_FI_DI_RATIO_Msk is 0x7ff,
cemu rejected >= 0x400 in emu_update_fidi() and masked with 0x3ff
in card_emu_uart_update_fidi(), but update_fidi() used by
the sniffer already used 0x7ff.

-> ratios 1024..2047 are unusable in cemu, which is the entire upper
half of ISO 7816-3 Table 7 at Di=1.

A reader trying one of those in a PPS gets the proposal echoed and
accepted, after which the card keeps transmitting at the old rate.

FI_DI_RATIO is clock periods per bit -> larger ratio is a SLOWER link.
The old check rejected slow values but accepted Fi=372/Di=64, ratio 5 !?

Unify and use the register mask (= shifed by 0 so usable as value) and
reject ratios that do not fit rather than truncating to garbage dividers.

Change-Id: I6211dd5be7c5c5d2150af2aa37a403b33e6d340d
2026-08-10 16:13:59 +00:00
2024-03-23 11:32:23 +01:00
2026-08-07 16:01:43 +02:00
2023-04-25 17:53:11 +02:00
2025-06-23 16:00:59 +02:00
2021-07-30 10:32:35 +02:00
2021-11-01 12:03:38 +00:00
2026-07-14 18:24:10 +02:00
2025-02-12 16:09:26 +01:00

SIMtrace v2.0

This is the repository for the next-generation SIMtrace devices, providing abilities to trace the communication between (U)SIM card and phone, remote (U)SIM card forward, (U)SIM man-in-the-middle, and more.

NOTE: Nothing in this repository applies to the SIMtrace v1.x hardware or its associated firmware. SIMtrace v1.x is based on a different CPU / microcontroller architecture and uses a completely different software stack and host software.

Supported Hardware

  • Osmocom SIMtrace2 with SAM3 controller
    • this is open hardware and schematics / PCB design is published
    • pre-built hardware available from sysmocom webshop
  • Osmocom ngff-cardem M.2/NGFF modem carrier with SAM3 controller
    • this is open hardware and schematics / PCB design is published
    • pre-built hardware available from sysmocom webshoo
  • sysmocom sysmoQMOD (with 4 Modems, 4 SIM slots and 2 SAM3)
    • this is a proprietary device, publicly available from sysmocom
    • hardware evaluation kit available from sysmocom webshop
  • sysmocom OWHW (with 2 Modems and 1 SAM3 onboard)
    • this is not publicly available hardware, but still supported

This Repository

This repository contains several directory

  • firmware - the firmware to run on the actual devices
  • hardware - some information related to the hardware
  • host - Programs to use on the USB host to interface with the hardware

The host software includes

  • libosmo-simtrace2 - a shared library to talk to devices running the simtrace2 firmware
  • simtrace2-list - list any USB-attached devices running simtrace2 firmware
  • simtrace2-sniff - interface the 'trace' firmware to obtain card protocol traces
  • simtrace2-cardem-pcsc - interface the 'cardem' firmware to use a SIM in a PC/SC reader

Do not expect SIMtrace2 to work in VMs

We only support running SIMtrace2 together with a Linux system running "bare iron" on actual hardware (x86, x86_64, arm, ...). using VMs with USB pass-through for things with critical timing like SIMtrace2 is calling for trouble and we will not accept related bug reports or support you if you do. If you still want to use VMs: Feel free to do so, but understand that it's unsupported and you are on your own.

Debug UART

The debug UART configuration is 921600 8N1, TTL 3.3V.

On the simtrace 2 use either a 2.5 mm stereo headphone connector (tip = TX, ring = RX, sleeve = GND) or the nearby DEBUG port (pin 1 = GND, pin 4 = TX, pin 5 = RX).

S
Description
No description provided
Readme 7.1 MiB
Languages
C 90.7%
Linker Script 3.7%
HTML 2.8%
Makefile 0.9%
Lua 0.6%
Other 1.3%