12#include <esp_random.h>
66constexpr uint32_t KEY_EXTRACTION_AUTO_OFF_MS = 10 * 60 * 1000;
70constexpr uint8_t KEY_EXTRACTION_MANUFACTURER_ID = MANUFACTURER_SOMFY;
72constexpr uint8_t KEY_EXTRACTION_ADVERTISED_SUBTYPE = 0;
73constexpr uint8_t KEY_EXTRACTION_ID_GEN_MAX_ATTEMPTS = 16;
74constexpr const char *KEY_EXTRACTION_TIMEOUT_NAME =
"key_extraction_auto_off";
75constexpr uint32_t RANDOM_LOW_BYTE_MASK = 0xFF;
77constexpr uint32_t KEY_EXTRACTION_MID_ATTEMPT_TIMEOUT_MS = 5000;
100constexpr uint32_t KEY_EXTRACTION_POST_EXTRACT_GRACE_MS = 60000;
111constexpr const char *KEY_EXTRACTION_GRACE_TIMER_NAME =
"key_extraction_post_extract_grace";
118 return "SYSTEM KEY EXTRACTED -- DO NOT SHARE YOUR SYSTEM KEY\n"
119 "Anyone with this key and node_id can control every device on this installation.\n"
120 "This exchange has not been independently confirmed against your specific hub -- test\n"
121 "this key (e.g. by controlling a device with it) before relying on it.\n"
122 "Copy the block below into a new hub's YAML.\n"
137 transmit_(std::move(transmit)),
138 schedule_auto_off_(std::move(schedule_auto_off)) {}
141 for (uint8_t attempt = 0; attempt < KEY_EXTRACTION_ID_GEN_MAX_ATTEMPTS; attempt++) {
142 for (uint8_t i = 0; i < NODE_ID_SIZE; i++)
143 out[i] =
static_cast<uint8_t
>(esp_random() & RANDOM_LOW_BYTE_MASK);
146 if (memcmp(out, this->node_id_, NODE_ID_SIZE) == 0)
148 if (memcmp(out, BROADCAST_DISCOVER, NODE_ID_SIZE) == 0 || memcmp(out, BROADCAST_DISCOVER_ALT, NODE_ID_SIZE) == 0)
166 if (this->armed_callback_)
167 this->armed_callback_(
false);
178 "Key extraction: ARMED for 10 minutes, throwaway ID %s. Put your existing hub into pairing/add-device "
187 this->schedule_auto_off_(KEY_EXTRACTION_TIMEOUT_NAME, KEY_EXTRACTION_AUTO_OFF_MS, [
this]() {
194 ESP_LOGW(
detail::TAG,
"Key extraction: window expired, no pairing attempt seen. Disarming.");
196 ESP_LOGW(
detail::TAG,
"Key extraction: window expired while in progress (reached stage=%s). Disarming.",
202 if (this->armed_callback_)
203 this->armed_callback_(
true);
210 if (frame.
cmd == CMD_DISCOVER_REQ) {
211 this->handle_discover_(frame);
214 if (memcmp(frame.
dst, this->key_extraction_ctx_.throwaway_id, NODE_ID_SIZE) != 0)
216 if (frame.
cmd == CMD_DISCOVER_CONFIRM) {
217 this->handle_discover_confirm_(frame);
220 if (frame.
cmd == CMD_KEY_INIT) {
221 this->handle_key_init_(frame);
224 if (frame.
cmd == CMD_KEY_TRANSFER) {
225 this->handle_key_transfer_(frame);
228 if (frame.
cmd == CMD_NODE_VERIFY_REQ) {
229 this->handle_node_verify_req_(frame);
232 if (frame.
cmd == CMD_CHALLENGE_REQ) {
233 this->handle_node_verify_challenge_(frame);
239void KeyExtractionResponder::broadcast_reply_(
const IoFrame &frame) {
270 const uint16_t preamble =
272 this->transmit_(frame, FREQ_CH1, preamble);
273 this->transmit_(frame, FREQ_CH3, preamble);
274 this->transmit_(frame, FREQ_CH2, preamble);
277void KeyExtractionResponder::handle_discover_(
const IoFrame &frame) {
283 this->key_extraction_ctx_.advertised_type, this->key_extraction_ctx_.advertised_subtype,
284 KEY_EXTRACTION_MANUFACTURER_ID)) {
285 ESP_LOGW(
detail::TAG,
"Key extraction: failed to build discovery response");
294 this->broadcast_reply_(resp);
296 ESP_LOGI(
detail::TAG,
"Key extraction: replied to discovery from hub %s with throwaway ID %s",
300void KeyExtractionResponder::handle_discover_confirm_(
const IoFrame &frame) {
306 ESP_LOGW(
detail::TAG,
"Key extraction: failed to build discovery-confirm ack");
311 this->broadcast_reply_(resp);
313 ESP_LOGI(
detail::TAG,
"Key extraction: acknowledged discovery confirm from hub %s",
317void KeyExtractionResponder::handle_key_init_(
const IoFrame &frame) {
318 uint8_t candidate_challenge[HMAC_SIZE];
325 this->key_extraction_ctx_.challenge)) {
326 ESP_LOGW(
detail::TAG,
"Key extraction: failed to build challenge request");
331 this->broadcast_reply_(resp);
336void KeyExtractionResponder::handle_key_transfer_(
const IoFrame &frame) {
337 if (frame.data_len < AES_KEY_SIZE) {
338 ESP_LOGW(
detail::TAG,
"Key extraction: key-transfer payload too short (%u bytes)", frame.data_len);
346 this->broadcast_reply_(resp);
348 ESP_LOGW(
detail::TAG,
"Key extraction: failed to build key confirm");
355 "Key extraction: still listening for up to %" PRIu32
356 " more seconds in case the hub verifies this device (CMD_NODE_VERIFY_REQ/0x36) — leave the "
357 "switch on until it turns off on its own.",
358 KEY_EXTRACTION_POST_EXTRACT_GRACE_MS / 1000);
371void KeyExtractionResponder::handle_node_verify_req_(
const IoFrame &frame) {
378 if (memcmp(frame.src, this->key_extraction_ctx_.hub_node_id, NODE_ID_SIZE) != 0)
384 ESP_LOGW(
detail::TAG,
"Key extraction: failed to build address response");
387 this->broadcast_reply_(resp);
389 ESP_LOGI(
detail::TAG,
"Key extraction: answered node verification request from hub %s",
393void KeyExtractionResponder::handle_node_verify_challenge_(
const IoFrame &frame) {
396 if (memcmp(frame.src, this->key_extraction_ctx_.hub_node_id, NODE_ID_SIZE) != 0)
401 if (frame.data_len < HMAC_SIZE) {
402 ESP_LOGW(
detail::TAG,
"Key extraction: address challenge payload too short (%u bytes)", frame.data_len);
411 IoFrame our_node_verify_resp;
417 frame.data, our_node_verify_resp, this->key_extraction_ctx_.recovered_key)) {
418 ESP_LOGW(
detail::TAG,
"Key extraction: failed to build address challenge response");
421 this->broadcast_reply_(resp);
445 this->schedule_auto_off_(KEY_EXTRACTION_GRACE_TIMER_NAME, KEY_EXTRACTION_POST_EXTRACT_GRACE_MS, [
this]() {
461 ESP_LOGI(
detail::TAG,
"Key extraction: post-extraction grace window elapsed (stage=%s). Disarming.",
477void KeyExtractionResponder::log_result_() {
487 ESP_LOGW(
detail::TAG,
"========================================");
490 this->key_extraction_ctx_.recovered_key));
491 ESP_LOGW(
detail::TAG,
"========================================");
Owns the per-hub device table, update callbacks, and linked-remote associations.
Abstract radio driver for IO-Homecontrol.
Per-hub device table, update-callback fan-out, and linked-remote map.
Hub-layer log tag and log/format helpers shared by the hub and its collaborators.
void generate_challenge(uint8_t out[HMAC_SIZE])
Generate 6 random bytes for a challenge using the ESP32 hardware RNG.
constexpr const char * TAG
Shared log tag for hub-level messages.
void log_multiline_result(const char *tag, bool is_warning, const std::string &prefix, const std::string &message)
Log prefix followed by message, one line per log call rather than one call for the whole (possibly mu...
std::string build_key_extraction_report(const uint8_t node_id[NODE_ID_SIZE], const uint8_t key[AES_KEY_SIZE])
Build the ready-to-paste 2W system-key-extraction report: node_id:/system_key: as a home_io_control: ...
std::string format_key_hex(const uint8_t key[AES_KEY_SIZE])
Format a 16-byte key as an uppercase, unseparated hex string for display.
bool on_key_transfer(ResponderContext &ctx, const uint8_t transfer_payload[AES_KEY_SIZE])
Decide how to react to an inbound CMD_KEY_TRANSFER (0x32) while armed.
const char * responder_stage_name(ResponderState state)
Get a short, log/telemetry-friendly name for a responder state.
bool on_discover_confirm(ResponderContext &ctx)
Decide how to react to an inbound CMD_DISCOVER_CONFIRM (0x2C) addressed to our throwaway ID.
bool on_node_verify_req(ResponderContext &ctx)
Decide how to react to an inbound CMD_NODE_VERIFY_REQ (0x36) addressed to our throwaway ID.
bool on_key_init(ResponderContext &ctx, const uint8_t challenge[HMAC_SIZE], const uint8_t hub_node_id[NODE_ID_SIZE])
Decide how to react to an inbound CMD_KEY_INIT (0x31) addressed to our throwaway ID.
bool on_node_verify_challenge(const ResponderContext &ctx)
Decide how to react to an inbound CMD_CHALLENGE_REQ (0x3C) — issued by the hub this time,...
@ ARMED_IDLE
Armed, listening for a discovery request (0x28).
@ DISARMED
Not armed; 0x28/0x2C/0x31/0x32 traffic is ignored.
@ SENT_NODE_VERIFY_RESP
Answered a hub's CMD_NODE_VERIFY_REQ (0x36) with our CMD_NODE_VERIFY_RESP (0x37); waiting for the hub...
@ EXTRACTED
System key recovered from a valid 0x32.
bool on_discover_request(ResponderContext &ctx, const uint8_t hub_node_id[NODE_ID_SIZE])
Decide how to react to an inbound CMD_DISCOVER_REQ (0x28) while armed.
DeviceType
Device type identifiers reported by IO‑Homecontrol products.
@ ROLLER_SHUTTER
Roller shutter.
bool create_node_verify_resp_device_role(IoFrame &f, const uint8_t *own, const uint8_t *dst)
Build an address response (0x37) — device side, used only by the key-extraction responder.
bool create_discover_resp(IoFrame &f, const uint8_t *own, const uint8_t *dst, DeviceType type, uint8_t subtype, uint8_t manufacturer_id)
Build a discovery response (0x29) — device side, used only by the key-extraction responder.
bool is_start(const IoFrame &f)
Check START flag.
bool create_key_confirm(IoFrame &f, const uint8_t *own, const uint8_t *dst)
Build a key-confirm frame (0x33) — device side, used only by the key-extraction responder.
std::function< bool(const IoFrame &frame, uint32_t freq_hz, uint16_t preamble)> TransmitFrameFn
Puts a frame on air on a given channel via the hub's protected transmit_frame_().
bool stored_node_id_is_valid(const uint8_t id[NODE_ID_SIZE])
Check whether a node ID is usable as an address: not all-zero and not all-0xFF, the two patterns blan...
bool create_discover_confirm_ack(IoFrame &f, const uint8_t *own, const uint8_t *dst)
Build a discovery-confirm acknowledgement (0x2D) — device side, used only by the key-extraction respo...
std::string node_id_to_string(const uint8_t id[NODE_ID_SIZE])
Format a 3‑byte node ID as a 6‑character uppercase hex string.
bool create_challenge_req_device_role(IoFrame &f, const uint8_t *dst, const uint8_t *src, const uint8_t challenge[HMAC_SIZE])
Build a device-role challenge request (0x3C) — device side, used only by the key-extraction responder...
std::function< void(const char *name, uint32_t delay_ms, std::function< void()> callback)> NamedTimeoutFn
Schedules a named, replace-on-same-name timeout on the hub's ESPHome scheduler.
bool create_challenge_resp_device_role(IoFrame &f, const uint8_t *dst, const uint8_t *src, const uint8_t challenge[HMAC_SIZE], const IoFrame &origin, const uint8_t *key)
Build a device-role challenge response (0x3D) — device side, used only by the key-extraction responde...
Pure decision logic for the device-role "Accept Foreign Pairing" (system-key extraction) responder.
Command builders for the IO‑Homecontrol protocol.
Cryptographic helpers for the IO‑Homecontrol protocol.
Radio abstraction layer for IO-Homecontrol.
Parsed IO‑Homecontrol frame (CTRL0/1 + addresses + command + data).
uint8_t dst[NODE_ID_SIZE]
Destination node ID (3 bytes).
All runtime tunable parameters for pairing and radio diagnostics.
uint16_t cold_broadcast_reply_preamble
Preamble for a start-flagged key-extraction broadcast reply (0x29).
Context for one key-extraction arm cycle.
ResponderState state
Current state.
DeviceType advertised_type
Device type advertised in our 0x29.
uint8_t throwaway_id[NODE_ID_SIZE]
Random per-arm-cycle node ID we advertise as ourselves.
uint8_t advertised_subtype
Device subtype advertised in our 0x29.
uint8_t hub_node_id[NODE_ID_SIZE]
Foreign hub's real node ID, captured from the 0x31's src.
Runtime tuning configuration for pairing and radio diagnostics.