逆向解析汽车方向盘CAN总线0x3D4报文的8位校验字节生成规则
I'm currently reverse-engineering CAN bus messages from a car's steering wheel, focusing specifically on the message with ID 0x3D4 which carries steering wheel button press data. Here's what I know so far:
- The message has a DLC (Data Length Code) of 8 bytes.
- The second byte contains a 4-bit counter that cycles from 0 to F.
- The first byte is a custom checksum—not a standard CRC algorithm—and its value depends on the other bytes in the message, with a dependency on their positions.
- When a button is pressed, both the relevant data bits and this checksum byte change; if I forge a message without updating the checksum correctly, the car doesn't respond.
My goal is to derive the checksum generation rule so I can create valid, functional messages. Below are the captured message samples I've collected:
Initial Captured Messages
CA 0E 80 00 00 04 00 00 1F 0F 80 00 00 04 00 00 ED 00 80 00 00 04 00 00 4A 01 81 00 00 04 00 00 01 02 81 00 00 04 00 00 4C 03 81 00 00 04 00 00 DC 04 81 00 00 04 00 00 37 05 81 00 00 04 00 00 1E 06 81 00 00 04 00 00 8B 07 80 00 00 04 00 00 25 08 80 00 00 04 00 00 70 09 80 00 00 04 00 00 6B 0A 80 00 00 04 00 00 9B 0B 81 00 00 04 00 00 BE 0C 81 00 00 04 00 00 41 0D 81 00 00 04 00 00 3E 0E 81 00 00 04 00 00 1F 0F 80 00 00 04 00 00 ED 00 80 00 00 04 00 00 BE 01 80 00 00 04 00 00 F5 02 80 00 00 04 00 00 B8 03 80 00 00 04 00 00
Messages with Identical First Byte
7F 2D 84 00 00 04 00 00 7F 07 81 00 00 04 00 00 7F 03 82 00 00 04 00 00 4C 03 81 00 00 04 00 00 4C 00 84 00 00 04 00 00 4C 07 82 00 00 04 00 00 BE 0C 81 00 00 04 00 00 BE 01 80 00 00 04 00 00 BE 0F 84 00 00 04 00 00 BE 23 88 00 00 04 00 00
Supplemental Captured Messages
70 09 80 00 00 04 00 00 6B 0A 80 00 00 04 00 00 9B 0B 81 00 00 04 00 00 BE 0C 81 00 00 04 00 00 41 0D 81 00 00 04 00 00 3E 0E 81 00 00 04 00 00 EB 0F 81 00 00 04 00 00 ED 00 80 00 00 04 00 00 BE 01 80 00 00 04 00 00 F5 02 80 00 00 04 00 00 B8 03 80 00 00 04 00 00 28 04 80 00 00 04 00 00 04 05 82 00 00 04 00 00 4B 06 84 00 00 04 00 00 2A 07 84 00 00 04 00 00 26 18 84 00 00 04 00 00 73 19 84 00 00 04 00 00 68 1A 84 00 00 04 00 00 6C 1B 84 00 00 04 00 00 49 1C 84 00 00 04 00 00 B6 1D 84 00 00 04 00 00 C9 1E 84 00 00 04 00 00 BE 0F 84 00 00 04 00 00 4C 00 84 00 00 04 00 00 1F 01 84 00 00 04 00 00 54 02 84 00 00 04 00 00 19 03 84 00 00 04 00 00 89 04 84 00 00 04 00 00 09 25 84 00 00 04 00 00 20 26 84 00 00 04 00 00 41 27 84 00 00 04 00 00 EF 28 84 00 00 04 00 00 BA 29 84 00 00 04 00 00 A1 2A 84 00 00 04 00 00 A5 2B 84 00 00 04 00 00 80 2C 84 00 00 04 00 00 7F 2D 84 00 00 04 00 00 00 2E 84 00 00 04 00 00 D5 2F 84 00 00 04 00 00 27 20 84 00 00 04 00 00 74 21 84 00 00 04 00 00 3F 22 84 00 00 04 00 00 19 03 84 00 00 04 00 00 2B 14 84 00 00 04 00 00 C0 15 84 00 00 04 00 00 E9 16 84 00 00 04 00 00 88 17 84 00 00 04 00 00 26 18 84 00 00 04 00 00 73 19 84 00 00 04 00 00 68 1A 84 00 00 04 00 00 6C 1B 84 00 00 04 00 00 49 1C 84 00 00 04 00 00 B6 1D 84 00 00 04 00 00 C9 1E 84 00 00 04 00 00 1C 1F 84 00 00 04 00 00 EE 10 84 00 00 04 00 00 BD 11 84 00 00 04 00 00 F6 12 84 00 00 04 00 00 BB 13 84 00 00 04 00 00 2B 14 84 00 00 04 00 00 0C 15 88 00 00 04 00 00 25 16 88 00 00 04 00 00 44 17 88 00 00 04 00 00 EA 18 88 00 00 04 00 00 BF 19 88 00 00 04 00 00 A4 1A 88 00 00 04 00 00 02 0B 88 00 00 04 00 00 27 0C 88 00 00 04 00 00 D8 0D 88 00 00 04 00 00 CC 2E 88 00 00 04 00 00 19 2F 88 00 00 04 00 00 EB 20 88 00 00 04 00 00 B8 21 88 00 00 04 00 00 F3 22 88 00 00 04 00 00 BE 23 88 00 00 04 00 00 2E 24 88 00 00 04 00 00 C5 25 88 00 00 04 00 00 EC 26 88 00 00 04 00 00 8D 27 88 00 00 04 00 00 23 28 88 00 00 04 00 00 76 29 88 00 00 04 00 00 6D 2A 88 00 00 04 00 00 69 2B 88 00 00 04 00 00 4C 2C 88 00 00 04 00 00 B3 2D 88 00 00 04 00 00 CC 2E 88 00 00 04 00 00 72 0F 88 00 00 04 00 00 80 00 88 00 00 04 00 00 D3 01 88 00 00 04 00 00 98 02 88 00 00 04 00 00 D5 03 88 00 00 04 00 00 45 04 88 00 00 04 00 00 AE 05 88 00 00 04 00 00 4B 06 84 00 00 04 00 00 2A 07 84 00 00 04 00 00 E2 08 82 00 00 04 00 00 B7 09 82 00 00 04 00 00 AC 0A 82 00 00 04 00 00 A8 0B 82 00 00 04 00 00 8D 0C 82 00 00 04 00 00 72 0D 82 00 00 04 00 00 0D 0E 82 00 00 04 00 00 D8 0F 82 00 00 04 00 00 2A 00 82 00 00 04 00 00 79 01 82 00 00 04 00 00 32 02 82 00 00 04 00 00 7F 03 82 00 00 04 00 00 EF 04 82 00 00 04 00 00 04 05 82 00 00 04 00 00 2D 06 82 00 00 04 00 00 4C 07 82 00 00
Initial Observations & Next Steps
Looking at the data, there are several pairs of messages that differ only in the counter byte (second byte) and checksum. For example:
ED 00 80 00 00 04 00 00andBE 01 80 00 00 04 00 00(counter goes from 00 to 01, checksum from ED to BE)1F 0F 80 00 00 04 00 00andED 00 80 00 00 04 00 00(counter from 0F to 00, checksum from 1F to ED)
These pairs are ideal for isolating the checksum's dependency on the counter. Additionally, messages with the same checksum but different data (like the 7F and 4C groups) can help identify how other bytes contribute.
A common approach for custom checksums is to compute a weighted sum of the other bytes, possibly with XOR operations or bitwise rotations, then take the result modulo 256. I'll start by calculating the difference between checksums and corresponding byte changes to look for patterns.
内容的提问来源于stack exchange,提问作者Alex

