Skip to content

Collaboration document for PSK Identity 02

Chris Weiss edited this page Nov 23, 2020 · 279 revisions

Here we will share and organize our findings and data from #483

Please help edit this document!

Much of this was bulk copy-pasted and needs to be transformed into a useful form

The Goal

  • Derive the PSK from the PSK identity or other known information, if that is even possible with the information we can obtain before a TLS connection is established.

The challenge of this issue is mapping known information (ie gwId) to the PSK (pskKey), which as mentioned before is indeed unique to every device. This is not possible to extract from the firmware, because to obtain the firmware would require we already know the PSK (or open the device at which point OTA becomes moot).

The previous implementation leaked information through the PSK ID (the MD5 of the auzKey), but this latest implementation uses already public information (the SHA256 of the gwId) as the PSK ID.

It may be that the pskKey is totally random and only stored on Tuya servers and the smart device. If this turns out to be the case, there is no solution to our challenge and this strategy of flashing firmware OTA is no longer viable.

The prod_idx is used to compute the PSK identity. This is handed to the server by the client during the handshake, so it is not secret information.

prod_idx is not secret information, it is the first part of the gwId. The gwId is what is being hashed here, which is prod_idx + mac.

The point is that the previous implementation did leak secret information through the PSK identity, which we could use to compute the PSK. Now that it does not, our job is harder.

Findings (and comments that need to be edited into findings)

  • firmware OS SDK version did not change, but the hash and build time did
    • OS SDK ver: 2.0.0(e8c5810) compiled @ Jan 25 2019 14:26:04
    • OS SDK ver: 2.0.0(29f7e05) compiled @ Sep 30 2019 11:19:12
      • interesting that this build date corresponds with the release of tuya-convert 2.0, coincidence?
  • psk begins with 02 rather than 01
    • guessing this will tell us the psk algorithm version
    • On OHLUX bulbs, psk begins with 03
  • disabled most of the serial debugging output
    • unfortunate as this was a useful reverse engineering resource
    • system_uart_swap() is called, switching uart over to GPIO2 (at least for LSC devices). There, the debug output is still shown.
  • did not respond to our smartconfig procedure
    • it may use a new mechanism or additional restrictions have been imposed
  • MAC address in flash appears to be compared with actual device MAC
    • likely to foil reverse engineering attempts by running firmware on a dev board
    • this means that a given firmware backup will only run on the original device
  • new factory written key found in flash, "pskKey"
    • the app never has access to the PSK, it is only used between the IoT device and the cloud
    • once written to flash it is never transmitted, period.
    • stored in JSON blob at 0xFB000
    • this is indeed the PSK key, unencrypted
      • this means if you have a firmware backup you can use this to decrypt captures from the same device
      • since obtaining the firmware requires a working hack or physically opening the device, this doesn't help us for OTA purposes
    • the PSK key does not change with each new session
      • previously the PSK key changed each session, computed using the PSK ID (fixed) and PSK hint from the server (variable)
      • the previous implementation leaked information via the PSK ID while 02 does not
    • this may mean the encryption key will no longer be derived deterministically, big bummer
    • only found in @rsbob's backup, looks like @Farfar's was updated to this firmware and thus lacks this factory written key
      • this may mean there is still hope for devices that came with a lower firmware, since updating to this firmware would require fetching the key
      • this is a very interesting new endpoint: tuya.device.uuid.pskkey.get
        • if we can figure out the format of this call, we could try faking it and seeing what it returns after multiple calls
        • to do this, we'll need to capture network traffic from a device upgrading to this firmware from an older one without PSK 02
  • PSK ID derivation:
    • '\x02' + 'BAohbmd6aG91IFR1' + sha256(gwId)
    • where gwId = prod_idx + mac_addr
    • where prod_idx is an 8 digit ASCII identifier for that device model
    • where mac_addr is the lowercase hex representation of the device MAC address
  • The device can request the server downgrade to the old authentication, but the server cannot ask the device to downgrade
    • Since we emulate the server, the downgrade path doesn't help us.
  • outside of updating a vulnerable device to the new firmware, the PSK never leaves Tuya's servers
    • Since this communication is encrypted by the highest version of the encryption scheme that the device supports, this isn't too helpful. Currently we can only decrypt that communication if the device is on the old firmware or we have a firmware dumps from that particular device.
  • the PSK is unique to each device, not shared among an entire model
  • there is currently unused code for what I think is certificate pinning in the Tuya SDK (the one on the device)
  • the server cannot tell Tuya devices to turn off encryption
    • The devices will reject any connection not secured with the TLS_PSK_WITH_AES_128_CBC_SHA256 cipher suite.
  • why do they use PSK, why not do the certificate pinning to the cloud?
    • likely answer is that the public key cryptography necessary to validate a certificate or chain is too slow on the ESP8266
  • The alphabet for both auz_key and pskKey seem to be (a-z, A-Z, 0-9)
    • We know that is it likely not base64, as we have plenty of samples and no instances of the +/ characters
    • It is possible that it is base62, but it seems more likely that this is a random string generated at the factory and stored only on the device and the cloud.
      • That would lead me to the guess, that they are not the result of any computation (like hashing the mac_addr or the like), because converting the binary result of such a computation into the above format is not straight forward.
    • Does anybody have an idea, why the length of the pskKey is 37? That sounds rather random.

Procedures

Creating network captures and firmware backups primer

  1. Install create_ap
git clone https://github.com/oblique/create_ap
cd create_ap
sudo make install
cd ..
  1. Setup a pass through AP (assuming your interface is wlan0)
sudo create_ap wlan0 wlan0 MyAccessPoint MyPassPhrase
  1. Start recording
tcpdump -i wlan0 -w capture.pcap
  1. Connect your phone to MyAccessPoint (or whatever you decide to call it)
  2. Use the app (SmartLife or vendor branded app) to pair the device
  3. Wait for registration to complete
  4. Disconnect the device
  5. Go back to tcpdump and press Ctrl + C
  6. Disassemble the device and connect to the serial port of the ESP
  7. Download the firmware using esptool
esptool.py read_flash 0 0x100000 firmware.bin
  1. Upload both capture.pcap and firmware.bin

Experiment:

The question here is how are devices with old firmware being integrated into Tuya's newer security scheme, which can help us understand how these new PSKs are created.

  • It may be when a device is first updated through the app, that the new randomly generated PSK is linked to the device MAC (or other device identifier), and that same PSK is issued again after downgrading and updating
    • we could potentially obtain the PSK by faking the API call to the cloud, however this strategy would likely be patched against quickly
  • Or a random PSK is generated each time
    • this would be bad

Requirements:

  • Tuya device with
    • old firmware that works with TuyaConvert, or
    • a converted device with the original backup for that device (MAC address must match)
  • firmware upgrade available for that device model in the Tuya app
    • Confirmed that it is possible to get the new PSK firmware through the app, but not guaranteed to be there for all devices
    • Teckin SB50 firmware was upgraded through Tuya app to new PSK firmware
    • Powertech SL225X sold with new PSK firmware, but no firmware update available in Tuya app for SL225x devices with old firmware
  • ability to open the device and serial flash it

Steps:

  1. take a device with pre-patched Tuya firmware and back it up
  2. step up network capture via WireShark or tcpdump
  3. register the device to the app and get the updated patched firmware
  4. backup the new firmware to determine the new PSK
  5. flash the device back to the pre-patched firmware
  6. register the device again to the Tuya app to get the patched firmware
  7. backup the new firmware, extract the PSK and determine if it matches the PSK from step 3)
  8. share your findings here!

Data

Known Affected Devices

  • Aoycocr U3S (4 pack, Amazon - October 13, 2020)
  • Aoycocr X10S Ordered from Amazon April 21, 2020 (FCC ID 2AKBP-X10S)
  • Amzdest C168 Outdoor Plug (Amazon 1 OCT 2020)
  • AL Above Lights 810lm
  • AOFO Smart Power Strip (ZLD-44EU-W)
  • Arlec GLD060HA lamp
  • Arlec GLD120HA (Bunnings September 2020)
  • Arlec GLD081HA (Bunnings October 2020)
  • Arlec PC399HA
  • Arlec PC190HA
  • AHRise AHR-083 Power Strip
  • AHRise AHR-085 Power Strip (Amazon, Oct 24 2020)
  • Avatar Mini Smart Socket AWP14H (4 pack, Amazon - October 16, 2020) - note: board is marked HYS-U1S-SOCKET-V1.3 2018-09-21.
  • AWOW EU3S smart socket
  • Bearware WDP 303899 / 20200422WZ001 (/20190809WZ001 is working!) (Amazon, Nov. 17 2020)
  • BAC-002ALW (unbranded) fan coil thermostat (H33711B-2) (Aliexpress, Oct 06 2020)
  • Bakibo TB95
  • Bakibo TP22Y
  • BENEXMART Wifi Tuya WiFi Roller Shade Driver
  • BHT-002-GALW (Decdeal, Moes, MoesGo, etc.) room thermostat (ordered Oct 15, 2020 over Amazon - Moes Go)
  • BHT-002GBLW room thermostat (ordered Sept 16, 2020)
  • BHT-3000GBLW room thermostat (ordered Sept 28, 2020)
  • Blitzwolf BW-LT11
  • Blitzwolf BW-LT29
  • Blitzwolf BW-SHP8
  • Blitzwolf BW-SHP11 (ordered via banggood 5th nov, 2020)
  • BN-Link BNC-60 (ordered Amazon Sept 6, 2020)
  • BSD29
  • BSD34 smart socket
  • Connect SmartHome CCT Downlight
  • Deltaco SH-OP01
  • Deltaco SH-P01
  • Deltaco SH-P01E
  • DETA Quad Smart Switch (6904HA)
  • DETA Smart Downlight (DET902HA)
  • DETA Triple Smart Switch
  • Dogain E12 (packaging says GDT-smart bulb Q5-4) (Amazon Nov 20, 2020)
  • Eachen WiFi-IR Universal Remote (SANT-IR-01)
  • Etersky WF-CS01 Curtain Switch
  • FEIT Smart Wifi Bulb
  • FEIT OM100/RGBW/CA/AG (fccid: SYW-A21RGBWAGT2R - non R versions seem to be unaffected)
  • FEIT Smart Dimmer
  • Fitop Smart Bulb E27
  • Girier 16A Power Monitoring Plug (JR-PM01)
  • Gosund 800l bulb
  • Gosund EP2 (2500W, sucessor of SP111 Plug - now glued and soldered, ESP8285. Amazon, Oct 2020)
  • Gosund SP 112
  • Gosund WB4 bulb
  • Gosund WP3 socket (newer, Amazon, October 20, 2020)
  • Gosund WP5 socket (Amazon, October 8, 2020)
  • Halonix Prime Prizm 12W RGB Bulb(Amazon.in, October 28, 2020)
  • Hama 10W 1050lm RGBW E27 Bulb (Amazon, October 2020)
  • Jinvoo SM-PW713
  • KHSUIN A19 E26 RGBCW 7w 800lm bulb (Amazon, June 2020)
  • Kogan KASMCDSKTLA 1.7L Smart Kettle
  • Kogan KASPEMHUSBA Smart Plug with Energy Meter
  • Kogan KAB22RGBC1A Smart Bulb (B22) 10W 806LM
  • LOHAS E14 bulb
  • LOHAS Candelabra LED Bulb E12 Base
  • LOHAS RGBCW GU10 Bulb
  • Loratap sc500w curtain switch
  • Loratap SC511WSC Curtain switch module with remote
  • Maxcio YX-L01C-E14
  • Maxcio YX-L01C-E27
  • Merkury MI-BW320-999W Light bulb
  • Merkury MI-BW944-999W 11W 1050LM Light Bulb
  • Merkury MI-EW003-999W LED Light strip
  • Mirabella Genio 9W LED Wi-Fi Dimmable Downlight - I002741
  • MoesHouse Smart Downlight
  • NEO Coolcam NAS-WR01W
  • Nedis Wi-Fi Smart Plug WIFIP130FWT
  • Novostella 20w Smart LED Floodlight
  • Novostella 13W Smart LED Light Bulbs RGBCW
  • NX-SM112
  • NX-SM400
  • OHLUX Smart WiFi LED (ASIN B08CL2CKW3, OS SDK ver: 2.0.0(29f7e05) compiled @ Sep 30 2019 11:19:12)
  • OHLUX 40W 4000LM Smart Outdoor Flood Lights (ASIN B083TZFB29)
  • Powertech SL225X (firmware V3.3.16 TC compatible, V3.3.30 new PSK)
  • QS-WIFI-S03 Module Switch
  • SANA SW02-02 Smart Switch
  • SMRTLite (Costco) LED Panel Light DS18901
  • Stitch Wireless Smart Power Strip (Monoprice.com, Oct 26 2020, P/N 34082)
  • Sunco G25 RGBW Smart Bulb
  • Sunco PAR38 WIFI LED SMART (PAR38_S-13W-27K_5K-2PK)
  • SRL Glass Wallplate Touch Switches (all gang combos) https://srltech.com.au/portfolio_page/one-gang-series/
  • Teckin SB50 (firmware V1.61 new PSK, was previously TC compatible until firmware update through Tuya app).
  • Teckin SB53 (some of them, even BNIB never updated)
  • Teckin SS31 Outdoor smart outlet
  • Teckin SS42 Outdoor smart outlet
  • Treatlife A19 8W 650lm RGBCCT Bulb
  • Treatlife Ceiling Fan & Light Dimmer Switch DS03
  • TreatLife Smart Dimmer Switch DS01C
  • Treatlife Smart Dimmer Switch DS02S
  • TreatLife Smart Plug-in Dimmer DP10
  • Treatlife SS01 3-Way Switch
  • Treatlife SS02S Single Pole Switch
  • UCOMEN Outdoor Sockets PA-GEBA-01SWP2
  • UFO-R1 Smarty Wifi Infrared Controller (tested version is labeled by MOES)
  • Zemismart 4 inch 10W Wifi RGBW
  • Zemismart 6 inch 14W WiFi RGBCW
  • Zemismart Curtain Motor ZM79E-DT WiFi here
  • WiFi Smart Power Strip 4 AC - SA-P402A (Zeoota)
  • Zeoota ZLD-44EU-W - WiFi Smart Power Strip

Firmware

5 firmware backups that tuya convert made. One from a smart plug and another four from smart switches.

firmware-9c52d8.bin.gz firmware-52a6fb.bin.gz firmware-a068f4.bin.gz firmware-a0709d.bin.gz

Network Captures

Strings

OS SDK ver: 2.0.0(29f7e05) compiled @ Sep 30 2019 11:19:12
[N]%s:%d metedata is without encryption, cover this partition with encrypted data
[N]%s:%d var block [%d] last version is without encryption,now need to encrypt data and cover this partition
[ERR]%s:%d flash_aes128_ecb_encrypt err
[ERR]%s:%d !!!!!!CHIP_MAC:%s FLASH_MAC:%s!!!!!!
aes-internal-dec.c
aes-internal-enc.c
lhttps://a3.tuyacn.com/gw.json
https://a3.tuyaeu.com/gw.json
https://a3-ueaz.tuyaus.com/gw.json
https://a3.tuyaus.com/gw.json
{"mac_addr":"500291e8f141","prod_idx":"26636676","auz_key":"wg7xdxUcsi7W0EmnPUlEtuwoyZwcF2W2","pskKey":"GUKgTWzsxGCn8UR5tIFFluuKD2qA8FYmaZwY2","prod_test":false}
{"ap_ssid":"SmartLife","ap_pwd":null}
{"CC":"CN"}
vtrust-flash
ESP_E8F141
vtrust-flash

{"ip":"10.42.42.16","gwId":"22885450c44f33b5ed3e","active":2,"ability":0,"mode":0,"encrypt":true,"productKey":"key75ugrk53wuycc","version":"3.3"}
{"mac_addr":"c82b964e3b29","prod_idx":"64785071","auz_key":"eDOnWtAUy5gJOiKtcXkNplBMqOMjJmM3","pskKey":"ggD99i71cC7R7MTVnHadCtjaK28H2f6fOJLrG","prod_test":false}{"mac_addr":"c82b964e3b22","prod_idx":"64785071","auz_key":"in18hm8DJch2NzlkjkSVHVuFJ3kpUo6k","pskKey":"hcXNpRfvnob0zqZWQ4zL4oxa0BHHRzC6jns3X","prod_test":false}

https://github.com/ct-Open-Source/tuya-convert/issues/483#issuecomment-599560871 : {"mac_addr":"2462ab3989fe","prod_idx":"08488420","auz_key":"diI5mLzLQx5GBNCQQZsZ8J0dQLYMaAeT","pskKey":"Z9ir6z2hsTlRVJKwEZyqpfyIzfLyzkMBkwyGd","prod_test":false}

https://github.com/ct-Open-Source/tuya-convert/issues/483#issuecomment-570766710 : {"mac_addr":"c44f33bc1794","prod_idx":"65046664","auz_key":"tKzPU69mMe3ns8PmA5M2cAuUUDOtrTeA","pskKey":"yhULg57DUA3Uo1xTP5xhoI0C1kRpWQOwqjMO8","prod_test":false}

https://github.com/ct-Open-Source/tuya-convert/issues/483#issuecomment-594468592 : {"mac_addr":"98f4abc96ac3","prod_idx":"06402221","auz_key":"Yw0VAIvFe3aWlvdKEZfmBPg8xfQ3Jg4Q","pskKey":"kPJ6yZaAbTUqlk5fHrCN6DyWY2Flz9LLI49un","prod_test":false}

AOFO Smart Power Strip ZLD-44EU-W : {"mac_addr":"d8f15bdf7e98","prod_idx":"20432477","auz_key":"5RpboSdogNamQInfsrpMeVbr01fvAd9V","pskKey":"eH3eYWXmNxaAxTJXPLhJSCucK0N8VkPwCxp24","prod_test":false}

Zemismart 6 inch 14W WiFi RGBCW : {"mac_addr":"fcf5c4800682","prod_idx":"40426764","auz_key":"UOLjYJbk07gHZO0VBHaZshkxW65HsW0d","pskKey":"WgWAqXlPnX8qAdaD8GU2Ljoa8TYaTcD65r6Ur","prod_test":false}

Full firmwares..

Below are the following firmwares: Original + 3 different upgrades (from the same device) via reflashing original and then upgrading.

Useful Info/Links

more investigations in Tuya IOT plattform:

Clone this wiki locally