follow ft86club on our blog, twitter or facebook.
FT86CLUB
Ft86Club
Delicious Tuning
Register Garage Community Calendar Today's Posts Search

Go Back   Toyota GR86, 86, FR-S and Subaru BRZ Forum & Owners Community - FT86CLUB > Technical Topics > Software Tuning

Software Tuning Discuss all software tuning topics.


User Tag List

Reply
 
Thread Tools Search this Thread
Old 02-08-2013, 09:26 PM   #281
jedibow
post whore extraordinaire
 
Join Date: Jun 2012
Drives: 2013 Asphalt Grey FR-S 2003 Evo 8
Location: Land of drama looking for a way out
Posts: 456
Thanks: 177
Thanked 114 Times in 73 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Garage
Quote:
Originally Posted by pozer View Post
Check the BRZedit thread
we are discussing openecu, or romraider here, not ecuedit. Not to get into the differences too much, but one is a purchased ROM editor that cannot be altered (ecuedit), and the other is completely user defined.

We need all the tuning options we can get however, this is two different platforms. To clarify ecuedit would be closer to ecutek, than openecu.
__________________
Originally Posted by ImAwesome
Great info in here. arghx7 what do you do?

He's obviously a very knowledgable landscaper.
jedibow is offline   Reply With Quote
Old 02-08-2013, 09:38 PM   #282
Dimman
Kuruma Otaku
 
Dimman's Avatar
 
Join Date: Dec 2009
Drives: Mk3 Supra with Semi-built 7MGTE
Location: Greater Vancouver (New West)
Posts: 6,854
Thanks: 2,398
Thanked 2,265 Times in 1,234 Posts
Mentioned: 78 Post(s)
Tagged: 2 Thread(s)
Garage
Quote:
Originally Posted by jedibow View Post
we are discussing openecu, or romraider here, not ecuedit. Not to get into the differences too much, but one is a purchased ROM editor that cannot be altered (ecuedit), and the other is completely user defined.

We need all the tuning options we can get however, this is two different platforms. To clarify ecuedit would be closer to ecutek, than openecu.
You're back at this? Nice.

How are things?
__________________


Because titanium.
Dimman is offline   Reply With Quote
The Following User Says Thank You to Dimman For This Useful Post:
jedibow (02-08-2013)
Old 02-08-2013, 09:43 PM   #283
jedibow
post whore extraordinaire
 
Join Date: Jun 2012
Drives: 2013 Asphalt Grey FR-S 2003 Evo 8
Location: Land of drama looking for a way out
Posts: 456
Thanks: 177
Thanked 114 Times in 73 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Garage
Quote:
Originally Posted by Dimman View Post
You're back at this? Nice.

How are things?
I will be now...LOL

Good, made it to Canada, loved it! Herniated my bicep so had to pull out of ninja warrior, and converted the Evo to a dedicated time attack car. LOL

Now time for some 86 love...

George
__________________
Originally Posted by ImAwesome
Great info in here. arghx7 what do you do?

He's obviously a very knowledgable landscaper.
jedibow is offline   Reply With Quote
The Following 2 Users Say Thank You to jedibow For This Useful Post:
Deepseadiver (02-10-2013), Dimman (02-08-2013)
Old 02-26-2013, 02:46 AM   #284
D-VO
Senior Member
 
Join Date: Sep 2012
Drives: Whiteout FR-S, Evo 8 RS
Location: Kissimmee FL.
Posts: 242
Thanks: 131
Thanked 42 Times in 32 Posts
Mentioned: 16 Post(s)
Tagged: 0 Thread(s)
http://www.ft86club.com/forums/showthread.php?t=3603

=D
__________________
D-VO is offline   Reply With Quote
Old 05-09-2013, 10:36 AM   #285
ItsRealFast
Junior Member
 
Join Date: May 2013
Drives: s2000 Turbo
Location: FL
Posts: 3
Thanks: 0
Thanked 12 Times in 3 Posts
Mentioned: 1 Post(s)
Tagged: 0 Thread(s)
Development Started

Hey I would like to Thank everyone for this development info into the FRS ecu. I am new here

Well I would like to provide some insight here on exactly what I have planned. My FRS ecu just arrived and my buddy is a Master Tech at Toyota. He has access to all sort of tools. This weekend I will sniff the CAN lines along with K and L lines to see whats really going on the bus. I will gather logs with the car off, logs with the ignition on, logs with the car running, and logs with the dealer tool connected. This way i can filter out idle data vs dealer tool data.

I will then write a program to communicate to my custom hardware which will emulate dealer equipment. I would then connect the Stock ecu and try to reproduce messages and hope to get the same responses.

I know a lot about can bus, hacking ecus, dumping, and protocol stuff. I am still educating myself about about dissembling ecu code to find table data.

I am looking to team up with a couple of people to make this a group effort.

Thanks

Marc
ItsRealFast is offline   Reply With Quote
The Following 3 Users Say Thank You to ItsRealFast For This Useful Post:
D-VO (05-10-2013), Deepseadiver (05-09-2013), xjohnx (05-09-2013)
Old 05-09-2013, 10:43 AM   #286
xjohnx
Grip>Slip
 
xjohnx's Avatar
 
Join Date: Jun 2012
Drives: 13 SWP BRZ Ltd - Innovate Powered!
Location: RVA
Posts: 3,563
Thanks: 656
Thanked 1,716 Times in 1,031 Posts
Mentioned: 45 Post(s)
Tagged: 3 Thread(s)
Quote:
Originally Posted by ItsRealFast View Post
Hey I would like to Thank everyone for this development info into the FRS ecu. I am new here

Well I would like to provide some insight here on exactly what I have planned. My FRS ecu just arrived and my buddy is a Master Tech at Toyota. He has access to all sort of tools. This weekend I will sniff the CAN lines along with K and L lines to see whats really going on the bus. I will gather logs with the car off, logs with the ignition on, logs with the car running, and logs with the dealer tool connected. This way i can filter out idle data vs dealer tool data.

I will then write a program to communicate to my custom hardware which will emulate dealer equipment. I would then connect the Stock ecu and try to reproduce messages and hope to get the same responses.

I know a lot about can bus, hacking ecus, dumping, and protocol stuff. I am still educating myself about about dissembling ecu code to find table data.

I am looking to team up with a couple of people to make this a group effort.

Thanks

Marc
YES! I wish I could help, but I'm more of an infrastructure guy than a developer, but I'm sure you'll find a couple people here that will be able to assist.
xjohnx is offline   Reply With Quote
Old 05-09-2013, 10:45 AM   #287
ft_sjo
Banned
 
Join Date: Oct 2012
Drives: GT86
Location: The Motherland
Posts: 1,398
Thanks: 140
Thanked 473 Times in 271 Posts
Mentioned: 22 Post(s)
Tagged: 0 Thread(s)
I hope you're a crypto expert as well.
ft_sjo is offline   Reply With Quote
Old 05-09-2013, 11:32 AM   #288
ItsRealFast
Junior Member
 
Join Date: May 2013
Drives: s2000 Turbo
Location: FL
Posts: 3
Thanks: 0
Thanked 12 Times in 3 Posts
Mentioned: 1 Post(s)
Tagged: 0 Thread(s)
Quote:
Originally Posted by ft_sjo View Post
I hope you're a crypto expert as well.
Actually I noticed the CPU is a 32bit instruction and with the newer cars the seed and key level of security has also increased with sub levels. So i have been doing some reading about 32bit encryption and I noticed there could be a possibility that the Seed and Key access is 16 or 32 bit public encryption. Which is not an easy task to unlock. There are different levels of Encryption access.

This is due because they may want certain features available to one group of people such as locksmiths who may need to add a new key to the vehicle while still keeping the other levels secure.

So a typically Security Access transaction will have sub-functions that will essentially be the level that you wish to access.

Really tricky stuff. There could be over 4 billion different combinations. And if this process is Dynamic even worst.

But with a team we can reverse which sub security seed and key algorithm to grant us access to the reprogramming section.

I have a Plan for this, But I will not discuss it openly until I've confirmed my speculations this weekend.

Anybody care to shed some light?

Thanks
Marc
ItsRealFast is offline   Reply With Quote
The Following 4 Users Say Thank You to ItsRealFast For This Useful Post:
D-VO (05-10-2013), Deepseadiver (05-09-2013), jamesm (05-09-2013), xjohnx (05-09-2013)
Old 05-26-2013, 06:17 PM   #289
Deepseadiver
Senior Member
 
Join Date: Aug 2012
Drives: 2013 BRZ DMG manual Limited
Location: Hawaii
Posts: 238
Thanks: 229
Thanked 35 Times in 33 Posts
Mentioned: 4 Post(s)
Tagged: 0 Thread(s)
Quote:
Originally Posted by ItsRealFast View Post
Actually I noticed the CPU is a 32bit instruction and with the newer cars the seed and key level of security has also increased with sub levels. So i have been doing some reading about 32bit encryption and I noticed there could be a possibility that the Seed and Key access is 16 or 32 bit public encryption. Which is not an easy task to unlock. There are different levels of Encryption access.

This is due because they may want certain features available to one group of people such as locksmiths who may need to add a new key to the vehicle while still keeping the other levels secure.

So a typically Security Access transaction will have sub-functions that will essentially be the level that you wish to access.

Really tricky stuff. There could be over 4 billion different combinations. And if this process is Dynamic even worst.

But with a team we can reverse which sub security seed and key algorithm to grant us access to the reprogramming section.

I have a Plan for this, But I will not discuss it openly until I've confirmed my speculations this weekend.

Anybody care to shed some light?

Thanks
Marc
Can you shed any new information?
Deepseadiver is offline   Reply With Quote
Old 05-28-2013, 10:17 PM   #290
ItsRealFast
Junior Member
 
Join Date: May 2013
Drives: s2000 Turbo
Location: FL
Posts: 3
Thanks: 0
Thanked 12 Times in 3 Posts
Mentioned: 1 Post(s)
Tagged: 0 Thread(s)
Hey all

Well here's my update. I know its been a longer than I said but I was kinnda waiting for others to chime in on the discussion. I did monitor the thread but I saw only silence. I am really looking for some developers along with some mathematician cryptographic knowledge. Seems no one is serious.

Further findings, there are different levels of security for sure. I was able to send different seed and key request and I did notice the many secure levels.

I went to the dealer and connected to the TIS Techstream tool to gather some logs in a FRS and on my bench ecu. I was able to gather a couple of seed and keys. But the weekends are very busy there and my time during the week is very slim.

Here is a small list I was able to gather while I was there.

SEEDs - KEYs
00000000 - A4 71 2F 96
00000001 - A2 31 4E EE
00000002 - B0 BC 54 F7
00000003 - 38 FF 61 28
00000004 - 76 41 5F E0
00000005 - 0F 47 F4 83
00000006 - FE 96 D8 29
00000007 - 0A EE C5 A8
00000008 - 8C 05 F8 95
00000009 - 26 1D FA 8F
0000000A - 20 75 C5 D7

Its a 32bit encryption so here are the possible number of combinations 4294967295. Yea that's a lot. Algorithm cracking time. I did get the algorithm recreation quoted by a couple of creditable US companies and the average price is 8500 bukcs. Yea that's also a lot of money. Last on my list.

The Seed request always changes when called. Which makes it so tough to actually get a crack at memory address inside the ECU. The list above shows a sequence list which I was able to acquire.

Attach is a picture of my bench setup Took me about 4 hours to get it working on the bench without frying the ecu. I am a very caution with electronics especially since these ecu's are hard to find...

Well lets keep this going. Also Lets Go Heat!!
Attached Images
 
ItsRealFast is offline   Reply With Quote
The Following 5 Users Say Thank You to ItsRealFast For This Useful Post:
Deepseadiver (05-30-2013), Lonewolf (05-28-2013), Sensisnow (05-28-2013), Sportsguy83 (10-09-2013), xjohnx (05-28-2013)
Old 05-28-2013, 10:32 PM   #291
xjohnx
Grip>Slip
 
xjohnx's Avatar
 
Join Date: Jun 2012
Drives: 13 SWP BRZ Ltd - Innovate Powered!
Location: RVA
Posts: 3,563
Thanks: 656
Thanked 1,716 Times in 1,031 Posts
Mentioned: 45 Post(s)
Tagged: 3 Thread(s)
Quote:
Originally Posted by ItsRealFast View Post
Well lets keep this going. Also Lets Go Heat!!

great work, and i can't stand the heat, but if them winning is what it takes to get this thing moving, then by all means, go heat!

i wonder if we could raise the funds needed to crack the algorithm from forum members, maybe via a site like kickstarter (although, i'm pretty sure something like this would violate Kickstarter's TOS.), i'm assuming there's another similar site.
xjohnx is offline   Reply With Quote
Old 05-28-2013, 10:52 PM   #292
xwd
Senior Member
 
Join Date: Feb 2012
Drives: 2013 DGM Subaru BRZ (Subie #9)
Location: ATL, US
Posts: 2,667
Thanks: 123
Thanked 860 Times in 552 Posts
Mentioned: 32 Post(s)
Tagged: 0 Thread(s)
I would maybe head over to the Romraider or openecu forums since they have been down this road before. The short is people have reversed engineered the 16 and 32 bit Subaru ECUs in the past including the comm protocols. The roms are not encrypted , people have figured out how to dump the roms without using the SSM protocol and then disassembled from there. Ecutek and BRZEdit (epifan) have obviously done this already but I don't think they are going to share.
xwd is offline   Reply With Quote
Old 05-28-2013, 10:54 PM   #293
Lonewolf
Senior Member
 
Lonewolf's Avatar
 
Join Date: Dec 2011
Drives: Moped
Location: CA
Posts: 4,298
Thanks: 4,897
Thanked 2,128 Times in 1,193 Posts
Mentioned: 21 Post(s)
Tagged: 0 Thread(s)
Quote:
Originally Posted by xjohnx View Post
great work, and i can't stand the heat, but if them winning is what it takes to get this thing moving, then by all means, go heat!

i wonder if we could raise the funds needed to crack the algorithm from forum members, maybe via a site like kickstarter (although, i'm pretty sure something like this would violate Kickstarter's TOS.), i'm assuming there's another similar site.
Hell, I'd chip in 5-10 bucks to help out the community, and I'm sure many others would as well. I would just want to know estimated lead times for cracking...if it's going to take over a year...
Lonewolf is offline   Reply With Quote
Old 05-28-2013, 10:56 PM   #294
Sensisnow
Senior Member
 
Join Date: Mar 2013
Drives: 05 TSX & 13 BRZ
Location: Fairfield, OH
Posts: 189
Thanks: 266
Thanked 89 Times in 72 Posts
Mentioned: 6 Post(s)
Tagged: 0 Thread(s)
Garage
Quote:
Originally Posted by xjohnx View Post
great work, and i can't stand the heat, but if them winning is what it takes to get this thing moving, then by all means, go heat!

i wonder if we could raise the funds needed to crack the algorithm from forum members, maybe via a site like kickstarter (although, i'm pretty sure something like this would violate Kickstarter's TOS.), i'm assuming there's another similar site.
I'd happily throw in $100 to get this thing cracked! I have a background in IT, but this cryptography is WAY above my head, so I can't offer anything else.
Sensisnow is offline   Reply With Quote
 
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Great dealership in NE Ohio.. (still has multiple pre-order slots open) eikond BRZ First-Gen (2012+) -- General Topics 15 03-02-2012 01:03 PM
Open Air FR-S Concept Rampant FR-S & 86 Photos, Videos, Wallpapers, Gallery Forum 22 02-01-2012 11:01 PM
Open Deck Block nrclptcnsmniak Engine, Exhaust, Transmission 36 01-27-2012 01:00 PM
Keep your eyes/cameras open in SoCal? Buggy51 Scion FR-S / Toyota 86 GT86 General Forum 14 10-10-2011 10:21 PM


All times are GMT -4. The time now is 10:24 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.
User Alert System provided by Advanced User Tagging v3.3.0 (Lite) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.

Garage vBulletin Plugins by Drive Thru Online, Inc.