Files
KAT/docs/kia_v7.md
T
KaraZajac 754af4134a
Deploy to Pages / build (push) Waiting to run
Deploy to Pages / deploy (push) Blocked by required conditions
v1.3.0: Add 14 keyfob protocols (8 ProtoPirate + 6 Flipper-ARF), fix KeeLoq overflow
Brings KAT to 32 protocol decoders. Ported from the ProtoPirate reference and the
D4C1-Labs/Flipper-ARF firmware:

  ProtoPirate (8): Kia V7, Ford V1, Ford V2, Ford V3, Chrysler V0, Honda Static,
  Honda V1, Land Rover V0.
  Flipper-ARF (6): Toyota, Land Rover RKE, Mazda Siemens, BMW CAS4,
  Porsche Cayenne, PSA2.

Each decoder is gated (CRC / checksum / fixed markers / frame structure) so it
cannot false-match existing protocols; every previously-decoding IMPORTS capture
decodes unchanged. Real-capture decodes added for Ford V3 (LDV T80), Honda Static
(Honda), Toyota (Camry NRZ variant), and PSA2 (Groupe PSA, serial 0x99EB25); the
rest are validated by encode/decode round-trip and synthetic-frame tests.

Also fixes a debug-only underflow panic in keeloq_common::keeloq_decrypt
(15 - r underflowed; now wrapping_sub to match the reference's unsigned wrap;
release behavior unchanged).

Adds per-protocol docs, updates the README protocol table, capture metadata
(encoding / RF / encryption), make-suggestion mapping, and CHANGELOG.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JEfaKqzB3T4qsrybwfEi73
2026-06-23 20:08:54 -04:00

2.1 KiB
Raw Blame History

layout
layout
default

Kia V7 Protocol

Rust module: src/protocols/kia_v7.rs Reference: REFERENCES/ProtoPirate/protocols/kia_v7.c

Overview

Kia V7 uses Manchester encoding at 250/500 µs. 64 bits. The decoded 64-bit word is bit-inverted (~data); a valid frame has a fixed header byte 0x4C and a CRC8 (poly 0x7F, init 0x4C) over bytes 06. Emission is gated on header + CRC, so Kia V7 is strongly validated and will not false-match.

Timing

Parameter Value Notes
Short 250 µs ±100 µs (te_delta)
Long 500 µs ±100 µs
Min bits 64
Preamble ≥16 short pairs before sync

Frame Layout (64 bits / 8 bytes, after inversion)

  • byte 0: header 0x4C
  • bytes 12: counter (16-bit, big-endian)
  • bytes 36: serial (28-bit) — (b3<<20)|(b4<<12)|(b5<<4)|(b6>>4), masked to 0x0FFFFFFF
  • byte 6 low nibble: button (4-bit) — Lock=1, Unlock=2, Trunk=3, aux=8
  • byte 7: CRC8 over bytes 06 (poly 0x7F, init 0x4C)

RF

  • Encoding: Manchester (level ? (H,L) : (L,H); decoded word is bit-inverted)
  • RF modulation: FM (per ProtoPirate SubGhzProtocolFlag_FM)
  • Encryption: none — gated on fixed header 0x4C + CRC8
  • Frequencies: 315 MHz, 433.92 MHz

Decoder Steps

  1. Reset — a short HIGH pulse begins the preamble.
  2. Preamble — count short pairs; once >15 pairs are seen, a long HIGH pulse transitions to SyncLow and preloads four seed bits (1,0,1,1 = the inverted header's top nibble 0xB).
  3. SyncLow — a short LOW after the long sync enters Data.
  4. Data — Manchester-decode the remaining 60 bits. At 64 bits, invert the word, check the header equals 0x4C and the CRC8 validates, then emit.

Encoder

Supported (matches kia_v7_encode_key). Rebuilds the 64-bit key from serial/button/counter with the CRC8, then emits a 32-pair short preamble, a merged long sync pulse, 64 Manchester bits, and a trailing gap.

Validation

Verified by an encode→decode round-trip / synthetic-frame check (no local capture available).