Home Blog EM4100 sniffer/cloner

Well... as I told you, I have decided to publish how to add the bidirectional communications capability to the actual Open RFID Tag hardware (version 0.3).

I spent some time figuring how to do it with the least number of components and avoiding damage the PCB (without cutting any trace). Finally I manage to do it with one diode, one resistor and 3 capacitors.

I don't have time right now to publish the instructions for modifying the hardware, but I will do it the next week.

 

And this is the result:

 


 

100% passive cloner. Actually it can clone only the EM4100 family, but I will add support for others.

 

 

How the EM4100 cloner works.

Pressing button S1 when approaching the Open RFID tag to a RFID reader will boot the capture mode.

In this mode, the Open RFID Tag sniffs and decodes the communication between the RFID tag and the RFID reader. If an EM4100 memory map is correctly captured (the CRC and parity is checked), the memory map is stored and LED1 is switched on.

If  S1 is not pressed, the Open RFID Tag emulates the latest RFID tag captured.

Leave a Comment • • Edit

Comments  

 
0 #3 2012-10-02 03:49
Thats wats up!wher do I find dis EM4100
and how Do I get it to duplicate almost all the families?
Quote
 
 
0 #2 2011-10-01 08:59
Man this is great!!!
Quote
 
 
0 #1 2011-10-01 08:07
Great Job! I hope you post more about this project
Quote
 

Add comment


Security code
Refresh

 

Old posts

«»
Mayo 13
DLMMJVS
 1234
567891011
12131415161718
19202122232425
262728293031