ISO 7816-3 section 10.2 defines WT = WI x 960 x Fi/f seconds, store as etu, etu = Fi / (D x f) seconds, so the Fi cancels, but the D does not: WT [etu] = WI x 960 x D cemu dropped both (?!) -> WI x 960. The old comment explains why Fi can be dropped, which is right, but what about Di ?! sniffer gets it right (wt_wi * 960UL * wt_d), so the two state machines disagreed here again, by up to a factor of 64???!!?!!? This was fixed in osmo-ccid-firmware in 066489d in 2020 but not ported to st2. Additionally the waiting time was only recalculated at the end of the ATR, where D is still 1 by definition, so a PPS increasing D reprogrammed the baud rate but left the waiting time untouched??! etu duration shrinks with D by the same factor, wall clock WT is independent of D, which is the whole point. The old code decreased the waiting time by a factor of D: after a PPS to D=8 the card emitted its NULL procedure byte at ~0.09s instead of ~0.71s with a reader deadline of ~1.43s, and the inactivity timeout fires 8x too early, which probably led to unexplained wtime_exp errors. Update wt when WI becomes known (end of ATR) and where D changes (after the PPS response) + tests. Change-Id: I4263176d6073029d01f9ff5b11a6311617956af6
SIMtrace v2.0
This is the repository for the next-generation SIMtrace devices, providing abilities to trace the communication between (U)SIM card and phone, remote (U)SIM card forward, (U)SIM man-in-the-middle, and more.
NOTE: Nothing in this repository applies to the SIMtrace v1.x hardware or its associated firmware. SIMtrace v1.x is based on a different CPU / microcontroller architecture and uses a completely different software stack and host software.
Supported Hardware
- Osmocom SIMtrace2 with SAM3 controller
- this is open hardware and schematics / PCB design is published
- pre-built hardware available from sysmocom webshop
- Osmocom ngff-cardem M.2/NGFF modem carrier with SAM3 controller
- this is open hardware and schematics / PCB design is published
- pre-built hardware available from sysmocom webshoo
- sysmocom sysmoQMOD (with 4 Modems, 4 SIM slots and 2 SAM3)
- this is a proprietary device, publicly available from sysmocom
- hardware evaluation kit available from sysmocom webshop
- sysmocom OWHW (with 2 Modems and 1 SAM3 onboard)
- this is not publicly available hardware, but still supported
This Repository
This repository contains several directory
- firmware - the firmware to run on the actual devices
- hardware - some information related to the hardware
- host - Programs to use on the USB host to interface with the hardware
The host software includes
- libosmo-simtrace2 - a shared library to talk to devices running the simtrace2 firmware
- simtrace2-list - list any USB-attached devices running simtrace2 firmware
- simtrace2-sniff - interface the 'trace' firmware to obtain card protocol traces
- simtrace2-cardem-pcsc - interface the 'cardem' firmware to use a SIM in a PC/SC reader
Do not expect SIMtrace2 to work in VMs
We only support running SIMtrace2 together with a Linux system running "bare iron" on actual hardware (x86, x86_64, arm, ...). using VMs with USB pass-through for things with critical timing like SIMtrace2 is calling for trouble and we will not accept related bug reports or support you if you do. If you still want to use VMs: Feel free to do so, but understand that it's unsupported and you are on your own.
Debug UART
The debug UART configuration is 921600 8N1, TTL 3.3V.
On the simtrace 2 use either a 2.5 mm stereo headphone connector (tip = TX, ring = RX, sleeve = GND) or the nearby DEBUG port (pin 1 = GND, pin 4 = TX, pin 5 = RX).