11 ms·
Unveiling secrets of the ESP32: creating an open-source MAC layer
- dgreensp 3y agoHeadline should read "MAC" layer like it does in the article, not "Mac" layer. Two very different things :)
- redfast00 3y agoOops, my bad, copy-pasted it incorrectly; fixed now
- Max-q 3y agoThe article claims that the ESP32 costs $5. The reality is around half of that for the MCU, and around $3 for pre certified modules including crystal, PCB antenna or UF-L connector. So it's really affordable. Espressif has also launched a new ESP32C3 based on RISC-V, with modules priced at around $2.
- rwaksmunski 3y agoESP32C3 has great Rust support too.
- KRAKRISMOTT 3y agoThat's the development unit price. ESP's MCUs have amazing value when you buy in bulk.
- jareklupinski 3y agothat second core is worth its weight in gold cant wait until they can make a dual-core risc-v but p.happy on the -s3
- adolph 3y agoDual core RISC-V? Presenting ESP32-C6: It consists of a high-performance (HP) 32-bit RISC-V processor, which can be clocked up to 160 MHz, and a low-power (LP) 32-bit RISC-V processor, which can be clocked up to 20 MHz. It has a 320KB ROM, a 512KB SRAM, and works with external flash. It comes with 30 (QFN40) or 22 (QFN32) programmable GPIOs, with support for SPI, UART, I2C, I2S, RMT, TWAI, PWM, SDIO, Motor Control PWM. It also packs a 12-bit ADC and a temperature sensor. https://www.espressif.com/en/products/socs/esp32-c6 https://www.espressif.com/en/products/socs/esp32-c6 [The High Performance] CPU . . . has 4-stage, in-order, scalar pipeline optimized for area, power and performance. CPU core complex has a debug module (DM), interrupt-controller (INTC), core local interrupts (CLINT) and system bus (SYS BUS) interfaces for memory and peripheral access. The ESP32-C6 Low-Power CPU (LP CPU) . . . features ultra-low power consumption and has a 2 stage, in-order, and scalar pipeline. [It has same features but lacks core local interrupts (CLINT)]. https://www.espressif.com/sites/default/files/documentation/esp32-c6_technical_reference_manual_en.pdf https://www.espressif.com/sites/default/files/documentation/...
- jareklupinski 3y agooh sweet i didnt realize there was a module out https://www.mouser.com/ProductDetail/Espressif-Systems/ESP32-C6-WROOM-1-N4 https://www.mouser.com/ProductDetail/Espressif-Systems/ESP32... i prefer using dual-core designs over one uC for WiFi + one uC for realtime UI + TFT screens, so much cleaner and less hardware to worry about literally porting the design i'm working on rn to that one :) ty!
- baybal2 3y ago[dead]
- icpmacdo 3y agoI can attest to the challenges of the section on Dynamic analysis on real hardware and the struggles of attenuating signal interference on the ESP. Anyone have a recommendation on conducting fabric for RF isolation as briefly mentioned in the article or resources on the subject of rf isolation/Faraday cages for microcontrollers?
- redfast00 3y agoAs part of the NLNet grant, I will build an affordable Faraday cage; I'll post the BOM, assembly process and a test report in a separate blog post.
- reachableceo 3y agoI am researching that at this time as well. I have VNA etc and am keen to collaborate ! Charles@turnsys.com I have quite a collection of research material on RF cages / testing .
- pietervdvn 3y agoThere is an email address at the bottom of the blog post, you can send directly there.
- jcalvinowens 3y agoBased only on my own anecdotal experience... I think the hole the cables go through is the biggest problem in OPs setup. I'd solder the shields to the cage circumferentially around the hole. Shielded USB cables aren't too hard to find, it wouldn't be as good as something optical but it's a lot easier.
- 127361 3y agoFeed through capacitors for power and use fiber for the rest?
- 3y ago
- calamari4065 3y agoWouldn't this invalidate the FCC certification on the prebuilt modules? You'd have to get certified with this firmware to ensure you aren't violating transmission power requirements. Admittedly, this is a non-issue for hobby scale projects, but is potentially a blocker for commercial applications. I wouldn't say it's necessarily a bad thing, but worth discussion.
- throw0101b 3y ago> Wouldn't this invalidate the FCC certification on the prebuilt modules? MAC is at OSI Layer 2. FCC concerns about radio power occur at the PHY layer, OSI Layer 1: > On the ESP32, the PHY layer is implemented in hardware; most of the MAC layer is implemented in the proprietary blob. One notable exception to this separation is sending acknowlegement frame: if a device receives a frame, it should send a packet back to acknowledge that this packet was received correctly. This ACK packet needs to be sent within ~10 microseconds; it would be hard to get this timing correct in software. * https://pics.zeus.gent/vYXyQm2t9pJCzpDdWFvq9oWR2DACoUJoTsYf8qiz.jpg https://pics.zeus.gent/vYXyQm2t9pJCzpDdWFvq9oWR2DACoUJoTsYf8...
- calamari4065 3y agoHuh, neat!
- crote 3y agoIt's not that simple. Besides implementing a SoftMAC, the blob is also responsible for setting up the PHY, so it would definitely be able to adjust things like transmitting power. See the part describing `esp_phy_enable()`.
- rkfjrjrkfnrkd 3y agoIf you know where to look, I'm quite sure you can already do this with vanilla ESP-IDF. I don't have a VNA or whatever is used to measure power at the antenna, but I do have a precision ammeter that confirmed my changes were effective at the supply. I only changed PHY power parameters and a lot more power was going somewhere. Also, in my limited understanding, even changing the physical antenna can alter transmission power characteristics in such a way that it likely violates some limit, at least for some very specific wavelength or direction.
- WatchDog 3y agoThe section on trying to attenuate outside wifi signals interested me. There is a bunch of hand wavy information on building faraday cages online, some people suggesting to utilize a microwave oven, since they operate at the same frequency. There are even wifi faraday cages for sale on amazon. However I can't really find much actual benchmark data online about how well these various approaches actually attenuate signals.
- cchance 3y agoNot sure on specific numbers but based on the picture he posted of it in a can he would have probably done better with metal netting from a window screen or metal chicken wire it destroys wifi signal pretty damn effectively
- zamadatix 3y agoIf the product doesn't list some form of dB loss (at at least 1 frequency) I assume it's more or less just a standard box. Sometimes that'll be right, sometimes it won't. Some of it comes down to how you use the box as well. If you're feeding un-isolated power in via a big hole in the back then it doesn't really matter how perfect the front is at blocking signals. I'm surprised their paint can only gave them a 10 dB difference. I've found simply wrapping things in aluminum foil is good for about 40 dB when it comes to Wi-Fi.
- mschuster91 3y agoAt least for microwave ovens, with domestic models reaching 1 kW and commercial (e.g. in food) 2 kW, the shielding on these needs to be pretty darn good to make sure that someone standing right next to it doesn't get their body fried. The maximum allowed leakage power density is 5-10 mW/cm² [1], according to a 2004 study even then most ovens barely get up to 1% of the legally allowed emissions limits [2, page 7]. Out of random interest I tested the "put a phone in it and call it" and it didn't work (as did wifi) that's mentioned in [2]. [1] https://www.hea.de/fachwissen/mikrowellen/sicherheit https://www.hea.de/fachwissen/mikrowellen/sicherheit [2] https://www.sfu.ca/phys/346/121/resources/physics_of_microwave_ovens.pdf https://www.sfu.ca/phys/346/121/resources/physics_of_microwa...
- rkfjrjrkfnrkd 3y agoThis is very interesting. I'm keen to get involved but, while I'm very experienced with ESP32, I don't have experience with this type of reverse engineering. How long did it take you to get the environment and tools set up, so you could start digging in? Is time or money a more valuable investment at this stage? If it's not too forward, how much would be useful to your organisation? (I can email if preferred.)
- redfast00 3y agoPlease contact me via email (at the bottom of the blog post)
- finnjohnsen2 3y agoI wasnt aware of this wifi blob. This feeds a tiny paranoia I have at the back of my head when dealing with esp32/espressif. I have dozens of esp32s around and I love them, but Espressif is 100% Chinese. Im uncomfortable with what I read that every company of significant size in China automatically requires CCP party members to be involved in the company at a high level. So Im very happy to hear people such as these guys are looking deep at this. Ofcourse since Espressif controls the hardware, so they can do anything eventually. My itch will always be there and Im going to switch once I find something made in preferably the EU when I find something comparable to esp32. Maybe Nordic Semiconductors will make some nice risk-v chips and dev-boards soon.
- ajsnigrutin 3y agoWifi is easy... there's no way to send anything undetected, since you control the routers, etc. GSM->5G modems are a lot harder to debug... maybe now in recent years with cheaper SDRs, but a lot harder then wifi. And not sure why you'd be afraid of CCP, we saw the wikileaks, USA does a lot of similiarly bad stuff too and even got caught doing it... and if you live in a "western" country, USA has much easier access to you than China.
- jacquesm 3y agoYou are assuming you have full insight into what the board is capable of.
- ajsnigrutin 3y agoWhat part don't I have insight into? At least the parts that could be exploited by china in some way that would affect me, and couldn't be detected?
- jacquesm 3y agoGoogle 'the thing' and tell me that you could have predicted what it was and how it worked. Hardware is finicky in that way: you look at one thing it can be quite another.
- madushan1000 3y agoI think bl602 shares the wifi rf/mac layer with esp32. There is a monitor mode implementation here https://github.com/stschake/bl60x-wifimon/ https://github.com/stschake/bl60x-wifimon/
- Sprite_tm 3y agoNo, it doesn't. I know with 100% certainty ESP WiFi hardware is developed in-house and not shared. I think BL602 uses CEVA IP, not sure about that, but it certainly is not shared with ESP chips.
- maduran 3y agoSprite, how will Espressif react to this effort to open-source wifi? Will it help by releasing wifi phy documentation? Will it add DRM to block future efforts? (sprite_tm works at Espressif)
- droptablemain 3y agoI picked up an ESP32 devboard recently. I've always been intrigued by embedded but don't have a background in it at all. I have no idea what my first project should be. Any ideas?
- jof 3y agoMake an LED blink. Then, connect an RGB LED and experiment with PWM signal generation. Then, experiment with network programming, accepting a UDP packet to the ESP32 that sets the color of the RGB LED.
- PeterisP 3y agoAlternatively, you can go high-level immediately - instead of accepting a UDP packet to set the color, run a webserver on it with functionality to change the RGB LED color that you can access from any browser. Modern microcontrollers have enough resources to just spend them like that.
- zlg_codes 3y agoAre we talking lightweight servers like minihttp and shizaru, mid-level lighttpd , or big-ass Apache and nginx?
- raajg 3y agoPretty barebones but working web servers are possible. Example: https://randomnerdtutorials.com/esp32-web-server-arduino-ide/ https://randomnerdtutorials.com/esp32-web-server-arduino-ide...
- leptons 3y agough.. arduino. Better to start with ESP-IDF, there's a pretty full featured well documented web server, and a lot more. https://github.com/espressif/esp-idf/tree/master/examples/protocols/http_server https://github.com/espressif/esp-idf/tree/master/examples/pr...
- raajg 3y agoFor someone unexperienced with ESP32 but wanting to dip your toes, I'd highly recommend M5Stack - https://m5stack.com/ https://m5stack.com/ . No affiliation whatsoever, but I started playing with some basic boards last year for the first time and the the tiny devices they build have so many different sensors, transmitters, etc that you can start with a lot of early experiments just using a single device and a USB-C cable.
- vbezhenar 3y agoWhat kind of programmer does one need to work with ESP32? I bought jlink for stm32 thinking that's the ultimate programmer for all my needs, however it does not claim compatibility with esp32.
- sifttio 3y agoA usb cord to your computer. Flash the firmware with whatever you want. Check out WLED if you have wifi.
- ultrarunner 3y agoThey do have a boot loader that speaks uart, but are also compatible with jtag and openocd. However, I haven’t needed to burn the pins on jtag because they’ve implemented a gdb stub over uart, including the ability to trap interrupts and dump into a paused gdb session. It’s not ideal, but it’s pretty impressive from a preexisting tools perspective. This doesn’t really answer your question, but it feels like it’s worth mentioning.
- vGPU 3y agoI’ve actually found that ESPHome is sufficient for most basic use cases
- fragmede 3y agoThe question then is where have you found ESPHome to fall short?
- vGPU 3y agoHonestly? Nowhere where an ESP32 was a suitable device. Anything that esphome can’t do generally requires more powerful or specialized hardware anyways. I did have some issues with updates killing WiFi on the boards and needing a reflash but I think they fixed that bug. I could also never get the chrome based flasher to work properly when I tried that out.
- sunshine-o 3y ago
- seba_dos1 3y agoJust a few months ago I was thinking "surely someone must have tried to RE the ESP32 Wi-Fi stack" and tried to find some research on it, but couldn't find anything. Great work!
- jjtech 3y ago…I wonder if this could be used to implement AWDL (Apple Wireless Direct Link) for use with AirDrop… if I recall correctly, the blocker on normal WiFi chipsets is being unable to send the ACK frames, which this should enable?
- no_time 3y agothe esp32 also has a mask ROM (which includes BASIC for some weird reason). Hence fully deblobbing it is a hopeless battle. https://docs.espressif.com/projects/esp-idf/en/v4.3/esp32/api-guides/romconsole.html https://docs.espressif.com/projects/esp-idf/en/v4.3/esp32/ap...
- dezgeg 3y agoI would guess most 32-bit microcontrollers and any SoCs capable of running Linux have some sort of boot ROM, at least for the flash programming mode (especially if it's over USB).
- calamari4065 3y agoPretty much, yeah. You'll usually see a boot ROM, but it will also have the ability to boot into flash so you can run your own bootloader. But the ROM is always there as a fallback and can't be destroyed.
- wkat4242 3y agoNothing an electron microscope can't handle. It's not a hardened security chip. It'll cost a bit but it's probably possible for a company to do it for free to show off their services. This is how die shots usually happen.
- calamari4065 3y agoNothing about a mask ROM makes the data unrecoverable. It's still Memory that can be Read. I'd be very surprised if there's not an exploit that will get the CPU to barf up the full ROM contents. That's if there isn't a more direct way to read it. Even in the extremely unlikely case that it can't be read programmatically, you can always physically decode it with a microscope and a working eyeball. From there, it's "just" a matter of decompiling the machine code into something readable. It's not trivial, but it can be done by a single person in a reasonable timeframe.
- BertoldVdb 3y agoYou can just read the ROM on ESP32 (or download it, it is somewhere on the website in the SDK)
- londons_explore 3y ago> 50000 peripheral memory accesses are needed [to initialize the hardware] Wow, that's a lot. If OP could upload somewhere the list of accesses together with a stack trace for each, I think we could crowd source a rewrite of each function - I'd be willing to bet the vast majority of those are repetitive patterns - ie. 'run this transmission test 1000 times while increasing the power levels each time until the received power = some set value'.
- londons_explore 3y ago> 50000 peripheral memory accesses are needed Have you tried just replaying those 50,000 accesses and seeing if things work? Obviously some things might not be correctly calibrated, but merely knowing that a simple replay works tells you that there are no complex hardware/software handshakes (ie. Take random token from here and write it to there). It also tells you that the process is probably fairly timing independent.
- 127361 3y agoI think Espressif have or at least used to have their own in-house developed MAC and PHY, which is not publicly documented. For the Bouffalo Lab and Beken WiFi SoCs we already have SVD files[1] for the WiFi MAC (and likely the PHY too). Thus we have nearly complete documentation for all chip registers and their bitfields. Both SoCs are based on CEVA RivieraWaves WiFi IP. Also you might be able to use it as a SDR for the 2.4GHz band, there appears to be registers to send ADC data to on-chip SRAM. And USB 2.0 High Speed device functionality on some of the Bouffalo chips. I was thinking of hacking it to use as a cheap uplink to the QO-100 amateur radio satellite, which uplinks in the 2.4GHz band. I think 100mW of power might be just enough for CW or some very narrowband PSK mode. By the way, on the Bouffalo devices, watch out for the eFuse registers, they're not fully lockable and write protectable, one wrong register write and the whole chip itself can be bricked and stuck permanently in secure boot mode. It happened to me, and I'm going to try and work around it by glitching the clock input on boot, just at the right time, to disrupt the eFuse reading, just for the fun of it. 1. https://github.com/bouffalolab/bl_iot_sdk/blob/master/components/platform/soc/bl602/bl602_std/bl602_std/Device/Bouffalo/BL602/Peripherals/soc602_reg.svd https://github.com/bouffalolab/bl_iot_sdk/blob/master/compon...
- natalewalter 3y ago[dead]
- deleted 3y ago[deleted]
- BGotti4 3y ago[dead]
- rurban 3y agoHe should just go with stm and its open source LwMesh library instead. But the closed radio parts are indeed horrible. Qualcomm (US Intelligence) and Broadcom (Chinese intelligence) controlling the physical layer underneath is as disturbing as the various Intel, AMD, ARM backdoors in their pre-OS layers.