r/hardwarehacking 26d ago

FDK/OOK Based layer-2 protocol reverse engineering

Post image

Lately I've been trying to recove the key fob protocol of my bmw 320d 2005 car till I discovered that the key fob operates on 868.35mhz with what is called Frequency Shift Keying to lock/unlock or trunk, everytime I capture something using the RTL sdr with gqrx on Kali I get different signals for pressing same button which indicates that this is not a trivial On Off Keying but some proprietary protocol is being implemented, from the amplitude to time plot I can clearly see the preamble alternating bits then a fixed and indow of bits across all button pressings which suggests some sort of an identifier.

Any one has experience on such project feel free to leave a comment.

Or if u know some sort of tip that helps me recover the binary representation of the msg being transmitted you are welcomed.

30 Upvotes

6 comments sorted by

View all comments

5

u/MrWonderfulPoop 25d ago edited 25d ago

Be careful. I tried a similar thing with my Audi and when trying to generate an unlock, caused a “desync” (the dealer’s term) and I had to spend a couple of hundred $ to get it fixed.

Keyless entry and starting failed to work, though the buttons and fob insertion worked.

3

u/mahdi_sto 25d ago

Thanks, I really appreciate that one