Files
KAT/docs/honda_static.md
T
KaraZajac 754af4134a
Deploy to Pages / build (push) Waiting to run
Deploy to Pages / deploy (push) Blocked by required conditions
v1.3.0: Add 14 keyfob protocols (8 ProtoPirate + 6 Flipper-ARF), fix KeeLoq overflow
Brings KAT to 32 protocol decoders. Ported from the ProtoPirate reference and the
D4C1-Labs/Flipper-ARF firmware:

  ProtoPirate (8): Kia V7, Ford V1, Ford V2, Ford V3, Chrysler V0, Honda Static,
  Honda V1, Land Rover V0.
  Flipper-ARF (6): Toyota, Land Rover RKE, Mazda Siemens, BMW CAS4,
  Porsche Cayenne, PSA2.

Each decoder is gated (CRC / checksum / fixed markers / frame structure) so it
cannot false-match existing protocols; every previously-decoding IMPORTS capture
decodes unchanged. Real-capture decodes added for Ford V3 (LDV T80), Honda Static
(Honda), Toyota (Camry NRZ variant), and PSA2 (Groupe PSA, serial 0x99EB25); the
rest are validated by encode/decode round-trip and synthetic-frame tests.

Also fixes a debug-only underflow panic in keeloq_common::keeloq_decrypt
(15 - r underflowed; now wrapping_sub to match the reference's unsigned wrap;
release behavior unchanged).

Adds per-protocol docs, updates the README protocol table, capture metadata
(encoding / RF / encryption), make-suggestion mapping, and CHANGELOG.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JEfaKqzB3T4qsrybwfEi73
2026-06-23 20:08:54 -04:00

3.0 KiB
Raw Blame History

layout
layout
default

Honda Static Protocol

Rust module: src/protocols/honda_static.rs Reference: REFERENCES/ProtoPirate/protocols/honda_static.c

Overview

Honda/Acura fixed-code keyfobs. 64-bit frame. Unlike most KAT decoders, Honda Static does NOT use the Flipper manchester_decoder.h transition table: it buffers a per-element symbol stream (one bit per ~63 µs element) and then performs a custom Manchester unpack over symbol pairs. A short pulse contributes one symbol equal to the pulse level; a long pulse contributes two symbols of the same level. Anything outside both ranges (e.g. the 700 µs sync or a trailing gap) terminates the buffer and triggers a parse.

The checksum is an XOR of the first 7 packet bytes. Emission is gated on the checksum, so Honda Static will not false-match. The parser tries the inverted-Manchester interpretation first (what the encoder emits), then non-inverted forward, then a bit-reversed-bytes pass.

Timing

Parameter Value Notes
Element 63 µs one symbol per element
Short pulse 2898 µs base 28 µs, span 70 µs
Long pulse 61191 µs base 61 µs, span 130 µs (two symbols)
Sync 700 µs terminates the symbol buffer
Min symbols 36 before a parse is attempted
Min bits 64

(Reported timing profile: te_short 63 µs, te_long 700 µs, te_delta 120 µs.)

Frame Layout (64 bits, MSB-first into 8 bytes)

  • bits 03: button (4-bit) — Lock=1, Unlock=2, Trunk=4, Remote Start=5, Panic=8, Lock×2=9
  • bits 431: serial (28-bit)
  • bits 3255: counter (24-bit)
  • bits 5663: checksum (XOR of bytes 06)

The exported data (Key) word is the C generic.data: a compact nibble-packed layout, NOT the raw decoded packet bytes. The KAT counter field is the low 16 bits of the 24-bit counter.

RF

  • Encoding: custom symbol-stream Manchester over ~63 µs elements
  • RF modulation: FM
  • Encryption: none — gated on the XOR checksum + valid button + valid serial (serial ≠ 0 and ≠ 0x0FFFFFFF)
  • Frequencies: 315 MHz, 433.92 MHz

Decoder Steps

  1. feed — classify each pulse: short → 1 symbol, long → 2 symbols; buffer them.
  2. On an out-of-range pulse (700 µs sync or gap), if ≥36 symbols are buffered, walk past the alternating preamble + sync run, Manchester-unpack 64 bits over symbol pairs (inverted first, then non-inverted), validate, and emit. Then clear the buffer.

Encoder

Supported (matches honda_static_build_upload). Emits a 700 µs HIGH sync, a 160-element alternating preamble at 63 µs, 64 data bits (each as !value/value at 63 µs), and a trailing 700 µs sync.

Validation

Decodes REAL IMPORTS captures (IMPORTS/honda Lock and Unlock). Also covered by encode→decode round-trip and packet-validate unit tests.