Files
KAT/docs/ford_v3.md
T
KaraZajac 754af4134a
Deploy to Pages / build (push) Waiting to run
Deploy to Pages / deploy (push) Blocked by required conditions
v1.3.0: Add 14 keyfob protocols (8 ProtoPirate + 6 Flipper-ARF), fix KeeLoq overflow
Brings KAT to 32 protocol decoders. Ported from the ProtoPirate reference and the
D4C1-Labs/Flipper-ARF firmware:

  ProtoPirate (8): Kia V7, Ford V1, Ford V2, Ford V3, Chrysler V0, Honda Static,
  Honda V1, Land Rover V0.
  Flipper-ARF (6): Toyota, Land Rover RKE, Mazda Siemens, BMW CAS4,
  Porsche Cayenne, PSA2.

Each decoder is gated (CRC / checksum / fixed markers / frame structure) so it
cannot false-match existing protocols; every previously-decoding IMPORTS capture
decodes unchanged. Real-capture decodes added for Ford V3 (LDV T80), Honda Static
(Honda), Toyota (Camry NRZ variant), and PSA2 (Groupe PSA, serial 0x99EB25); the
rest are validated by encode/decode round-trip and synthetic-frame tests.

Also fixes a debug-only underflow panic in keeloq_common::keeloq_decrypt
(15 - r underflowed; now wrapping_sub to match the reference's unsigned wrap;
release behavior unchanged).

Adds per-protocol docs, updates the README protocol table, capture metadata
(encoding / RF / encryption), make-suggestion mapping, and CHANGELOG.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JEfaKqzB3T4qsrybwfEi73
2026-06-23 20:08:54 -04:00

56 lines
1.9 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
layout: default
---
# Ford V3 Protocol
**Rust module:** `src/protocols/ford_v3.rs`
**Reference:** `REFERENCES/ProtoPirate/protocols/ford_v3.c`
## Overview
Ford V3 uses Manchester encoding at 240/480 µs. 104 bits total (13 bytes), transmitted as plaintext —
there is no CRC or encryption. Decode-only: the ProtoPirate reference ships a NULL encoder, so KAT
does not transmit Ford V3 (Replay still works on the raw capture).
The Manchester decoder uses Flipper's `manchester_decoder.h` transition table (same table as Ford V0),
but Ford V3 maps the level the opposite way from Ford V0: `level ? High : Low`.
## Timing
| Parameter | Value | Notes |
|-----------|--------|--------------------|
| Short | 240 µs | ±60 µs (te_delta) |
| Long | 480 µs | ±60 µs |
| Min bits | 104 | 13 bytes |
| Preamble | ≥30 short pulses | before first long |
## Frame Layout (104 bits / 13 bytes)
- **byte 0:** header
- **bytes 14:** serial (32-bit, big-endian)
- **byte 5:** hop/reserved
- **byte 6:** button — bit 0 set → Unlock, else Lock
- **bytes 78:** counter, stored bitwise-inverted (`~b[7]`, `~b[8]`)
- **bytes 912:** rolling/hop tail (not parsed)
## Decoder Steps
1. **Reset** — a short pulse (~240 µs) starts the preamble (count = 1).
2. **Preamble** — count short pulses; once ≥30 shorts are seen, a long pulse begins the data
(Manchester state seeded to Mid1, first bit decoded from the long pulse).
3. **Data** — Manchester events (short/long × level) feed the state machine; bits pack MSB-first into
13 bytes. At 104 bits the fields are parsed and the signal is emitted. A non-short/non-long pulse
(gap) ends the frame.
## RF
- **Encoding:** Manchester
- **RF modulation:** FM (per ProtoPirate `SubGhzProtocolFlag_FM`)
- **Encryption:** none (plaintext)
- **Frequencies:** 315 MHz, 433.92 MHz
## Encoder
Not supported (reference encoder is NULL). Decode-only.