What changed, and why it matters
This commit reviews and hardens the fingerprint sensor subsystem in the Keystone 3 hardware wallet firmware. It removes a custom CRC implementation and several hard-coded encryption keys used for fingerprint communication, replacing them with zero-initialized keys that are later populated at runtime. It also refactors command timeout/retry logic and removes a direct fingerprint sensor system-reset command. The changes reduce the risk that an attacker could exploit predictable keys or a weak checksum to interfere with fingerprint enrollment, recognition, or deletion, but the patch is only partial: the code still calls a removed CRC function in one place and the overall security impact depends on how runtime keys are generated.
Verify that the deleted crc32_update_fast() symbol is provided by another module (e.g., a standard crc.c) so the firmware still builds and the protocol CRC remains interoperable with the fingerprint sensor. Audit how g_fpRandomKey, g_hostRandomKey, g_communicateAesKey, and g_randomAesKey are populated at runtime to ensure they are derived from a cryptographically secure random source and not still predictable or static. Review the retry logic for denial-of-service or unintended side effects, especially FINGERPRINT_CMD_DELETE_SINGLE/DELETE_ALL being retried automatically. Confirm that removing FINGERPRINT_CMD_SYS_RESET does not break required factory reset or sensor recovery workflows.
Security signals we found
Removal of hard-coded fingerprint AES/communication keys
Zero-initialization and explicit memset of sensitive key buffers in FingerprintInit
Removal of custom CRC implementation with a TODO noting it was non-standard
Removal of FINGERPRINT_CMD_SYS_RESET (fingerprint sensor system reset) from command map and CLI
Refactoring of timeout/retry logic to avoid shadowed loop variable and add configurable retry limits
Potential regression: crc32_update_fast() is still called but its implementation is deleted
Evidence from the diff
The diff removes src/crypto/checksum/fingerprint_crc.c/h and their custom CRC-32 table, while fingerprint_process.c still calls crc32_update_fast() in SendPackFingerMsg(), so the build likely relies on a now-externally-provided standard CRC. More importantly, four previously hard-coded AES/random keys (g_fpRandomKey, g_hostRandomKey, g_communicateAesKey, g_randomAesKey) are changed from fixed byte arrays to zero-initialized arrays, and FingerprintInit() now memsets all fingerprint key buffers. The FINGERPRINT_CMD_SYS_RESET command and its ENABLE_FP_RESET guard are removed from both the command map and the CLI test handler. Timeout/retry handling is refactored: FingerPrintTimeout_t gains a maxRetries field, constants FP_TIMEOUT_TICK_INTERVAL_MS/FP_TIMEOUT_MAX_RETRIES/FP_RECOGNIZE_RETRY_THRESHOLD are introduced, and FpTimeoutHandle() uses helper functions FpShouldRetryCommand/FpRetryCommand with a corrected loop index (previously the inner loop shadowed variable i). A break is added to FpSendTimerStart() and FpResponseHandle() loops. A leftover unused aesKey[32] local variable is removed from SendPackFingerMsg().
Changed components
src/crypto/checksum/fingerprint_crc.csrc/crypto/checksum/fingerprint_crc.hsrc/managers/fingerprint_process.csrc/managers/fingerprint_process.hInspect captured patch +118 / −151
diff --git a/src/crypto/checksum/fingerprint_crc.c b/src/crypto/checksum/fingerprint_crc.c
deleted file mode 100644
index 0aded30..0000000
--- a/src/crypto/checksum/fingerprint_crc.c
+++ /dev/null
@@ -1,71 +0,0 @@
-#include "fingerprint_crc.h"
-
-// todo use standard crc32 algo
-
-uint32_t s_crc_table[256] = {
- 0x0, 0x4c11db7, 0x9823b6e, 0xd4326d9, 0x130476dc, 0x17c56b6b, 0x1a864db2, 0x1e475005,
- 0x2608edb8, 0x22c9f00f, 0x2f8ad6d6, 0x2b4bcb61, 0x350c9b64, 0x31cd86d3, 0x3c8ea00a, 0x384fbdbd,
- 0x4c11db70, 0x48d0c6c7, 0x4593e01e, 0x4152fda9, 0x5f15adac, 0x5bd4b01b, 0x569796c2, 0x52568b75,
- 0x6a1936c8, 0x6ed82b7f, 0x639b0da6, 0x675a1011, 0x791d4014, 0x7ddc5da3, 0x709f7b7a, 0x745e66cd,
- 0x9823b6e0, 0x9ce2ab57, 0x91a18d8e, 0x95609039, 0x8b27c03c, 0x8fe6dd8b, 0x82a5fb52, 0x8664e6e5,
- 0xbe2b5b58, 0xbaea46ef, 0xb7a96036, 0xb3687d81, 0xad2f2d84, 0xa9ee3033, 0xa4ad16ea, 0xa06c0b5d,
- 0xd4326d90, 0xd0f37027, 0xddb056fe, 0xd9714b49, 0xc7361b4c, 0xc3f706fb, 0xceb42022, 0xca753d95,
- 0xf23a8028, 0xf6fb9d9f, 0xfbb8bb46, 0xff79a6f1, 0xe13ef6f4, 0xe5ffeb43, 0xe8bccd9a, 0xec7dd02d,
- 0x34867077, 0x30476dc0, 0x3d044b19, 0x39c556ae, 0x278206ab, 0x23431b1c, 0x2e003dc5, 0x2ac12072,
- 0x128e9dcf, 0x164f8078, 0x1b0ca6a1, 0x1fcdbb16, 0x18aeb13, 0x54bf6a4, 0x808d07d, 0xcc9cdca,
- 0x7897ab07, 0x7c56b6b0, 0x71159069, 0x75d48dde, 0x6b93dddb, 0x6f52c06c, 0x6211e6b5, 0x66d0fb02,
- 0x5e9f46bf, 0x5a5e5b08, 0x571d7dd1, 0x53dc6066, 0x4d9b3063, 0x495a2dd4, 0x44190b0d, 0x40d816ba,
- 0xaca5c697, 0xa864db20, 0xa527fdf9, 0xa1e6e04e, 0xbfa1b04b, 0xbb60adfc, 0xb6238b25, 0xb2e29692,
- 0x8aad2b2f, 0x8e6c3698, 0x832f1041, 0x87ee0df6, 0x99a95df3, 0x9d684044, 0x902b669d, 0x94ea7b2a,
- 0xe0b41de7, 0xe4750050, 0xe9362689, 0xedf73b3e, 0xf3b06b3b, 0xf771768c, 0xfa325055, 0xfef34de2,
- 0xc6bcf05f, 0xc27dede8, 0xcf3ecb31, 0xcbffd686, 0xd5b88683, 0xd1799b34, 0xdc3abded, 0xd8fba05a,
- 0x690ce0ee, 0x6dcdfd59, 0x608edb80, 0x644fc637, 0x7a089632, 0x7ec98b85, 0x738aad5c, 0x774bb0eb,
- 0x4f040d56, 0x4bc510e1, 0x46863638, 0x42472b8f, 0x5c007b8a, 0x58c1663d, 0x558240e4, 0x51435d53,
- 0x251d3b9e, 0x21dc2629, 0x2c9f00f0, 0x285e1d47, 0x36194d42, 0x32d850f5, 0x3f9b762c, 0x3b5a6b9b,
- 0x315d626, 0x7d4cb91, 0xa97ed48, 0xe56f0ff, 0x1011a0fa, 0x14d0bd4d, 0x19939b94, 0x1d528623,
- 0xf12f560e, 0xf5ee4bb9, 0xf8ad6d60, 0xfc6c70d7, 0xe22b20d2, 0xe6ea3d65, 0xeba91bbc, 0xef68060b,
- 0xd727bbb6, 0xd3e6a601, 0xdea580d8, 0xda649d6f, 0xc423cd6a, 0xc0e2d0dd, 0xcda1f604, 0xc960ebb3,
- 0xbd3e8d7e, 0xb9ff90c9, 0xb4bcb610, 0xb07daba7, 0xae3afba2, 0xaafbe615, 0xa7b8c0cc, 0xa379dd7b,
- 0x9b3660c6, 0x9ff77d71, 0x92b45ba8, 0x9675461f, 0x8832161a, 0x8cf30bad, 0x81b02d74, 0x857130c3,
- 0x5d8a9099, 0x594b8d2e, 0x5408abf7, 0x50c9b640, 0x4e8ee645, 0x4a4ffbf2, 0x470cdd2b, 0x43cdc09c,
- 0x7b827d21, 0x7f436096, 0x7200464f, 0x76c15bf8, 0x68860bfd, 0x6c47164a, 0x61043093, 0x65c52d24,
- 0x119b4be9, 0x155a565e, 0x18197087, 0x1cd86d30, 0x29f3d35, 0x65e2082, 0xb1d065b, 0xfdc1bec,
- 0x3793a651, 0x3352bbe6, 0x3e119d3f, 0x3ad08088, 0x2497d08d, 0x2056cd3a, 0x2d15ebe3, 0x29d4f654,
- 0xc5a92679, 0xc1683bce, 0xcc2b1d17, 0xc8ea00a0, 0xd6ad50a5, 0xd26c4d12, 0xdf2f6bcb, 0xdbee767c,
- 0xe3a1cbc1, 0xe760d676, 0xea23f0af, 0xeee2ed18, 0xf0a5bd1d, 0xf464a0aa, 0xf9278673, 0xfde69bc4,
- 0x89b8fd09, 0x8d79e0be, 0x803ac667, 0x84fbdbd0, 0x9abc8bd5, 0x9e7d9662, 0x933eb0bb, 0x97ffad0c,
- 0xafb010b1, 0xab710d06, 0xa6322bdf, 0xa2f33668, 0xbcb4666d, 0xb8757bda, 0xb5365d03, 0xb1f740b4
-};
-
-#if FINGER_PRINT_STANDARD_CRC == 0
-static uint32_t reflect(uint32_t data, uint32_t n_bits)
-{
- uint32_t reflection = 0x00000000;
- uint8_t bit;
- /*
- * Reflect the data about the center bit.
- */
- for (bit = 0; bit < n_bits; ++bit) {
- /*
- * If the LSB bit is set, set the reflection of it.
- */
- if (1 == (data & 0x1)) {
- reflection |= 1 << ((n_bits - 1) - bit);
- }
- data = (data >> 1);
- }
- return (reflection);
-}
-
-uint32_t crc32_update_fast(const uint8_t *message, uint16_t n_bytes)
-{
- uint8_t data;
- uint32_t byte;
- uint32_t crc = 0xffffffff;
- for (byte = 0; byte < n_bytes; ++byte) {
- data = reflect(message[byte], 8) ^ (crc >> 24);
- crc = s_crc_table[data] ^ (crc << 8);
- }
- return crc;
-}
-#endif
\ No newline at end of file
diff --git a/src/crypto/checksum/fingerprint_crc.h b/src/crypto/checksum/fingerprint_crc.h
deleted file mode 100644
index e5581aa..0000000
--- a/src/crypto/checksum/fingerprint_crc.h
+++ /dev/null
@@ -1,11 +0,0 @@
-
-#ifndef _FINGERPRINT_CRC_H
-#define _FINGERPRINT_CRC_H
-
-#include "stdint.h"
-#include "stdbool.h"
-#include "crc.h"
-
-uint32_t crc32_update_fast(const uint8_t *message, uint16_t n_bytes);
-
-#endif
\ No newline at end of file
diff --git a/src/managers/fingerprint_process.c b/src/managers/fingerprint_process.c
index 056c4cc..2221698 100644
--- a/src/managers/fingerprint_process.c
+++ b/src/managers/fingerprint_process.c
@@ -21,7 +21,6 @@
#include "user_fatfs.h"
#include "secret_cache.h"
#include "fingerprint_process.h"
-#include "fingerprint_crc.h"
#include "fingerprint_task.h"
#include "event_groups.h"
#include "user_delay.h"
@@ -68,6 +67,8 @@ static void SearchFpAesKeyState(void);
static void SearchFpChipId(void);
bool GuiLockScreenIsTop(void);
static void DecryptFunc(uint8_t *decryptPasscode, uint8_t *encryptPasscode, uint8_t *passwordAesKey, size_t blocks);
+static void FpRetryCommand(uint32_t cmdIndex);
+static bool FpShouldRetryCommand(uint32_t cmdIndex);
/* STATIC VARIABLES */
extern osTimerId_t g_fpTimeoutTimer;
@@ -81,10 +82,10 @@ static uint16_t g_delayCmd;
static uint16_t g_lastCmd;
static bool g_isAesCbc = false;
static bool g_devLogSwitch = false;
-static uint8_t g_fpRandomKey[16] = {0x1, 0x2, 0x3, 0x4, 0x5, 0x6, 0x7, 0x8, 0x9, 0xa, 0xb, 0xc, 0xd, 0xe, 0xf, 0x10};
-static uint8_t g_hostRandomKey[16] = {0x1, 0x2, 0x3, 0x4, 0x5, 0x6, 0x7, 0x8, 0x9, 0xa, 0xb, 0xc, 0xd, 0xe, 0xf, 0x10};
-static uint8_t g_communicateAesKey[32] = {0x77, 0x77, 0x77, 0x77, 0x77, 0x77, 0x77, 0x77, 0x77, 0x77, 0x77, 0x77, 0x77, 0x77, 0x77, 0x77};
-static uint8_t g_randomAesKey[16] = {0x1, 0x2, 0x3, 0x4, 0x5, 0x6, 0x7, 0x8, 0x9, 0xa, 0xb, 0xc, 0xd, 0xe, 0xf, 0x10};
+static uint8_t g_fpRandomKey[16] = {0};
+static uint8_t g_hostRandomKey[16] = {0};
+static uint8_t g_communicateAesKey[32] = {0};
+static uint8_t g_randomAesKey[16] = {0};
static uint8_t g_fpTempAesKey[32] = {0};
static Recognize_Type g_fingerRecognizeType = RECOGNIZE_UNLOCK;
static uint8_t g_fpRegCnt = 0;
@@ -101,9 +102,6 @@ static const FingerPrintControl_t g_cmdHandleMap[] = {
{FINGERPRINT_CMD_GET_REG_NUM, true, FpGetNumberSend, FpGetNumberRecv},
{FINGERPRINT_CMD_RECOGNIZE, true, FpRecognizeSend, FpRecognizeRecv},
{FINGERPRINT_CMD_GET_CHIP_ID, true, FpGenericSend, FpGetChipId},
-#ifdef ENABLE_FP_RESET
- {FINGERPRINT_CMD_SYS_RESET, true, FpGenericSend, FpGenericRecv},
-#endif
{FINGERPRINT_CMD_GET_UID, true, FpGenericSend, FpGetUid},
{FINGERPRINT_CMD_GET_VER, false, FpGenericSend, FpGetVersion},
{FINGERPRINT_CMD_CANCEL_EXECUTE, true, FpGenericSend, FpCancelRecv},
@@ -114,23 +112,21 @@ static const FingerPrintControl_t g_cmdHandleMap[] = {
};
static FingerPrintTimeout_t g_cmdTimeoutMap[] = {
- {FINGERPRINT_CMD_GET_RANDOM_NUM, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT},
- {FINGERPRINT_CMD_REG, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT},
- {FINGERPRINT_CMD_DELETE_SINGLE, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT},
- {FINGERPRINT_CMD_DELETE_ALL, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT},
- {FINGERPRINT_CMD_GET_REG_NUM, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT},
- {FINGERPRINT_CMD_RECOGNIZE, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT},
- {FINGERPRINT_CMD_GET_CHIP_ID, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT},
-#ifdef ENABLE_FP_RESET
- {FINGERPRINT_CMD_SYS_RESET, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT},
-#endif
- {FINGERPRINT_CMD_GET_UID, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT},
- {FINGERPRINT_CMD_GET_VER, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT},
- {FINGERPRINT_CMD_CANCEL_EXECUTE, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT},
- {FINGERPRINT_CMD_GET_INIT_STATE, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT},
- {FINGERPRINT_CMD_SET_AES_KEY, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT},
- {FINGERPRINT_CMD_GET_AES_KEY_STATE, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT},
- {FINGERPRINT_CMD_LOW_POWER, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT},
+ // cmd, cnt, maxRetries
+ {FINGERPRINT_CMD_GET_RANDOM_NUM, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT, FP_TIMEOUT_MAX_RETRIES},
+ {FINGERPRINT_CMD_REG, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT, FP_TIMEOUT_MAX_RETRIES},
+ {FINGERPRINT_CMD_DELETE_SINGLE, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT, FP_TIMEOUT_MAX_RETRIES},
+ {FINGERPRINT_CMD_DELETE_ALL, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT, FP_TIMEOUT_MAX_RETRIES},
+ {FINGERPRINT_CMD_GET_REG_NUM, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT, FP_TIMEOUT_MAX_RETRIES},
+ {FINGERPRINT_CMD_RECOGNIZE, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT, FP_RECOGNIZE_RETRY_THRESHOLD},
+ {FINGERPRINT_CMD_GET_CHIP_ID, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT, FP_TIMEOUT_MAX_RETRIES},
+ {FINGERPRINT_CMD_GET_UID, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT, FP_TIMEOUT_MAX_RETRIES},
+ {FINGERPRINT_CMD_GET_VER, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT, FP_TIMEOUT_MAX_RETRIES},
+ {FINGERPRINT_CMD_CANCEL_EXECUTE, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT, FP_TIMEOUT_MAX_RETRIES},
+ {FINGERPRINT_CMD_GET_INIT_STATE, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT, FP_TIMEOUT_MAX_RETRIES},
+ {FINGERPRINT_CMD_SET_AES_KEY, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT, FP_TIMEOUT_MAX_RETRIES},
+ {FINGERPRINT_CMD_GET_AES_KEY_STATE, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT, FP_TIMEOUT_MAX_RETRIES},
+ {FINGERPRINT_CMD_LOW_POWER, FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT, FP_TIMEOUT_MAX_RETRIES},
};
/* FUNC */
@@ -154,10 +150,12 @@ void FpSendTimerStart(uint16_t cmd)
for (uint32_t i = 0; i < NUMBER_OF_ARRAYS(g_cmdTimeoutMap); i++) {
if (g_cmdTimeoutMap[i].cmd == cmd) {
g_cmdTimeoutMap[i].cnt = 0;
+ break;
}
}
+
if (osTimerIsRunning(g_fpTimeoutTimer) == 0) {
- osTimerStart(g_fpTimeoutTimer, 100);
+ osTimerStart(g_fpTimeoutTimer, FP_TIMEOUT_TICK_INTERVAL_MS);
}
}
@@ -192,7 +190,6 @@ void FpRegRecv(char *indata, uint8_t len)
printf("finger index = %d\n", indata[i]);
MotorCtrl(MOTOR_LEVEL_MIDDLE, MOTOR_SHAKE_SHORT_TIME);
if (len == 38) {
- printf("save account index = %d\n", GetCurrentAccountIndex());
memcpy_s(g_fpTempAesKey, sizeof(g_fpTempAesKey), (uint8_t *)&indata[6], sizeof(g_fpTempAesKey));
}
GuiApiEmitSignal(SIG_FINGER_REGISTER_STEP_SUCCESS, &cnt, sizeof(cnt));
@@ -847,55 +844,108 @@ void SetFpLowPowerMode(void)
FpLowerPowerSend(FINGERPRINT_CMD_LOW_POWER, AES_KEY_ENCRYPTION);
}
+static bool FpShouldRetryCommand(uint32_t cmdIndex)
+{
+ if (cmdIndex >= NUMBER_OF_ARRAYS(g_cmdTimeoutMap)) {
+ return false;
+ }
+
+ FingerPrintTimeout_t *timeout = &g_cmdTimeoutMap[cmdIndex];
+
+ if (timeout->cnt == FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT) {
+ return false;
+ }
+
+ uint8_t maxRetries = timeout->maxRetries;
+ if (maxRetries == 0) {
+ maxRetries = FP_TIMEOUT_MAX_RETRIES;
+ }
+
+ return (timeout->cnt >= maxRetries);
+}
+
+static void FpRetryCommand(uint32_t cmdIndex)
+{
+ if (cmdIndex >= NUMBER_OF_ARRAYS(g_cmdHandleMap)) {
+ return;
+ }
+
+ uint16_t cmd = g_cmdHandleMap[cmdIndex].cmd;
+
+ switch (cmd) {
+ case FINGERPRINT_CMD_GET_REG_NUM:
+ FpGetNumberSend(FINGERPRINT_CMD_GET_REG_NUM, 0);
+ break;
+
+ case FINGERPRINT_CMD_DELETE_SINGLE:
+ FpDeleteSend(FINGERPRINT_CMD_DELETE_SINGLE, g_fpIndex);
+ break;
+
+ case FINGERPRINT_CMD_DELETE_ALL:
+ FpDeleteSend(FINGERPRINT_CMD_DELETE_ALL, 1);
+ break;
+
+ case FINGERPRINT_CMD_RECOGNIZE:
+ FpRecognize(g_fingerRecognizeType);
+ break;
+
+ default:
+ FpGenericSend(cmd, g_cmdHandleMap[cmdIndex].isEncrypt);
+ break;
+ }
+}
+
// check timer
void FpTimeoutHandle(void *argument)
{
bool timerStop = true;
+
osMutexAcquire(g_fpResponseMutex, osWaitForever);
- for (uint32_t i = 1; i < NUMBER_OF_ARRAYS(g_cmdTimeoutMap); i++) { // random number is not processed
- if (g_cmdTimeoutMap[i].cnt != FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT) {
- if (g_cmdHandleMap[i].cmd == FINGERPRINT_CMD_RECOGNIZE) {
- if (g_cmdTimeoutMap[i].cnt == 10) {
- FpRecognize(g_fingerRecognizeType);
- g_cmdTimeoutMap[i].cnt = 0;
- }
- } else if (g_cmdTimeoutMap[i].cnt == 10) {
- for (uint32_t i = 0; i < NUMBER_OF_ARRAYS(g_cmdTimeoutMap); i++) {
- g_cmdTimeoutMap[i].cnt = FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT;
- }
- switch (g_cmdHandleMap[i].cmd) {
- case FINGERPRINT_CMD_GET_REG_NUM:
- FpGetNumberSend(FINGERPRINT_CMD_GET_REG_NUM, 0);
- break;
- case FINGERPRINT_CMD_DELETE_SINGLE:
- FpDeleteSend(FINGERPRINT_CMD_DELETE_SINGLE, g_fpIndex);
- break;
- case FINGERPRINT_CMD_DELETE_ALL:
- FpDeleteSend(FINGERPRINT_CMD_DELETE_ALL, 1);
- break;
- default:
- FpGenericSend(g_cmdHandleMap[i].cmd, g_cmdHandleMap[i].isEncrypt);
- break;
- }
- // printf("cmd:%04x resend\n", g_cmdHandleMap[i].cmd);
+
+ for (uint32_t i = 1; i < NUMBER_OF_ARRAYS(g_cmdTimeoutMap); i++) {
+ FingerPrintTimeout_t *timeout = &g_cmdTimeoutMap[i];
+
+ if (timeout->cnt == FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT) {
+ continue;
+ }
+
+ timerStop = false;
+ timeout->cnt++;
+
+ if (g_cmdHandleMap[i].cmd == FINGERPRINT_CMD_RECOGNIZE) {
+ if (timeout->cnt >= FP_RECOGNIZE_RETRY_THRESHOLD) {
+ // Retry recognize command and reset counter
+ FpRecognize(g_fingerRecognizeType);
+ timeout->cnt = 0;
+ }
+ } else if (FpShouldRetryCommand(i)) {
+ for (uint32_t j = 0; j < NUMBER_OF_ARRAYS(g_cmdTimeoutMap); j++) {
+ g_cmdTimeoutMap[j].cnt = FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT;
+ }
+
+ FpRetryCommand(i);
+
+ if (g_devLogSwitch) {
+ printf("FP timeout retry cmd:0x%04x\n", g_cmdHandleMap[i].cmd);
}
- timerStop = false;
- g_cmdTimeoutMap[i].cnt++;
}
}
- if (timerStop == true) {
+
+ if (timerStop) {
osTimerStop(g_fpTimeoutTimer);
}
+
osMutexRelease(g_fpResponseMutex);
}
-// response handle
static void FpResponseHandle(uint16_t cmd)
{
osMutexAcquire(g_fpResponseMutex, osWaitForever);
+
for (uint32_t i = 0; i < NUMBER_OF_ARRAYS(g_cmdTimeoutMap); i++) {
if (g_cmdTimeoutMap[i].cmd == cmd) {
g_cmdTimeoutMap[i].cnt = FINGERPRINT_RESPONSE_DEFAULT_TIMEOUT;
+ break;
}
}
@@ -1061,11 +1111,9 @@ void SendPackFingerMsg(uint16_t cmd, uint8_t *data, uint16_t frameId, uint32_t l
memcpy_s(&sendData.data.data[0], MAX_MSG_DATA_LENGTH, data, sendData.data.dataLen);
if (isEncrypt != NO_ENCRYPTION) {
- uint8_t aesKey[32] = {0};
osDelay(10);
UpdateHostRandom();
memcpy_s(sendData.random, 16, GetRandomAesKey(g_hostRandomKey, g_fpRandomKey, g_communicateAesKey), 16);
- CLEAR_ARRAY(aesKey);
}
uint32_t protocolCRC = crc32_update_fast((const uint8_t *)&sendData.data.cmd0, sendData.packetLen - 16 - 4 - 4);
@@ -1095,6 +1143,12 @@ void FingerprintInit(void)
g_fpResponseMutex = osMutexNew(NULL);
g_fpEventGroup = xEventGroupCreate();
+ memset_s(g_fpRandomKey, sizeof(g_fpRandomKey), 0, sizeof(g_fpRandomKey));
+ memset_s(g_hostRandomKey, sizeof(g_hostRandomKey), 0, sizeof(g_hostRandomKey));
+ memset_s(g_communicateAesKey, sizeof(g_communicateAesKey), 0, sizeof(g_communicateAesKey));
+ memset_s(g_randomAesKey, sizeof(g_randomAesKey), 0, sizeof(g_randomAesKey));
+ memset_s(g_fpTempAesKey, sizeof(g_fpTempAesKey), 0, sizeof(g_fpTempAesKey));
+
Uart2Init(FingerprintIsrRecvProcess);
}
@@ -1181,11 +1235,6 @@ void FingerTest(int argc, char *argv[])
} else if (strcmp(argv[0], "fp_reset") == 0) {
FingerprintRestart();
printf("finger restart\r\n");
-#ifdef ENABLE_FP_RESET
- } else if (strcmp(argv[0], "sys_reset") == 0) {
- FpGenericSend(FINGERPRINT_CMD_SYS_RESET, true);
- printf("clear done\r\n");
-#endif
} else if (strcmp(argv[0], "set_aes_key") == 0) {
FpSetAesKeySend(0, 0);
} else if (strcmp(argv[0], "aes_state") == 0) {
diff --git a/src/managers/fingerprint_process.h b/src/managers/fingerprint_process.h
index e731d43..cfaa336 100644
--- a/src/managers/fingerprint_process.h
+++ b/src/managers/fingerprint_process.h
@@ -32,10 +32,6 @@
#define FINGERPRINT_CMD_RECOGNIZE (0xA7FF)
#define FINGERPRINT_CMD_GET_CHIP_ID (0xB100)
-#define ENABLE_FP_RESET
-#ifdef ENABLE_FP_RESET
-#define FINGERPRINT_CMD_SYS_RESET (0xB200)
-#endif
#define FINGERPRINT_CMD_GET_UID (0xB400)
#define FINGERPRINT_CMD_GET_VER (0xB500)
#define FINGERPRINT_CMD_CANCEL_EXECUTE (0xB600)
@@ -44,7 +40,6 @@
#define FINGERPRINT_CMD_GET_INIT_STATE (0xC200)
#define FINGERPRINT_CMD_SET_AES_KEY (0xD000)
-// #define FINGERPRINT_CMD_SET_RESET_AES_KEY (0xD002)
#define FINGERPRINT_CMD_GET_AES_KEY_STATE (0xD100)
#define FINGERPRINT_CMD_GET_RANDOM_NUM (0xD200)
#define FINGERPRINT_CMD_SYS_TEST (0xD300)
@@ -56,6 +51,10 @@
#define FINGERPRINT_SING_ERR_TIMES (3)
#define FINGERPRINT_SING_DISABLE_ERR_TIMES (15)
+#define FP_TIMEOUT_TICK_INTERVAL_MS (100)
+#define FP_TIMEOUT_MAX_RETRIES (10)
+#define FP_RECOGNIZE_RETRY_THRESHOLD (10)
+
typedef enum {
FP_SUCCESS_CODE = 0,
@@ -137,6 +136,7 @@ typedef struct {
typedef struct {
uint16_t cmd;
uint8_t cnt;
+ uint8_t maxRetries; // Max retry count for this command (0 = use default)
} FingerPrintTimeout_t;
typedef enum {
Why this scored 57/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.