Login Register

Vida CEM swapping

A mid-size luxury crossover SUV, the Volvo XC90 made its debut in 2002 at the Detroit Motor Show. Recognized for its safety, practicality, and comfort, the XC90 is a popular vehicle around the world. The XC90 proved to be very popular, and very good for Volvo's sales numbers, since its introduction in model year 2003 (North America). P2 platform.
Post Reply
T5Luke
Posts: 142
Joined: 11 November 2020
Year and Model: S60 T5 2001
Location: DE
Has thanked: 11 times
Been thanked: 130 times

Re: Vida CEM swapping

Post by T5Luke »

The CEM reads the transponder and if transponder is valid it comunicates with ECM. An idea would be to turn the transponder check routine into a false positive or always positive check routine to allow always starting.

MaxDenisov
Posts: 36
Joined: 6 March 2021
Year and Model: XC90 2010
Location: Moscow
Has thanked: 2 times

Post by MaxDenisov »

blasaab wrote: 31 Mar 2021, 15:03 I have cloned my key. Only remote dosent work but can unlock with the blade.
I already have cut the blade of new key and ready for sw config. Just mentioned above that I am a bit lazy to remove CEM from the car to use Xprog or other solutions for eeprom editing.
Better to find OBDii soluton

User avatar
RickHaleParker
Posts: 7129
Joined: 25 May 2015
Year and Model: See Signature below.
Location: Kansas
Has thanked: 8 times
Been thanked: 958 times

Post by RickHaleParker »

vtl wrote: 31 Mar 2021, 14:35 My only key (well, ID48 pill) is glued to the immobilizer antenna
Have you checked with your local locksmith? ID48 transponders can be cloned. The CEM would not be able to tell one clone from the other.
⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙
1998 C70, B5234T3, 16T, AW50-42, Bosch Motronic 4.4, Special Edition package.
2003 S40, B4204T3, 14T twin scroll AW55-50/51SN, Siemens EMS 2000.
2004 S60R, B8444S TF80 AWD. Yamaha V8 conversion
2005 XC90 T6 Executive, B6294T, 4T65 AWD, Bosch Motronic 7.0.

vtl
Posts: 4724
Joined: 16 August 2012
Year and Model: 2005 XC70
Location: Boston
Has thanked: 114 times
Been thanked: 603 times

Post by vtl »

RickHaleParker wrote: 31 Mar 2021, 16:20 Have you checked with your local locksmith? ID48 transponders can be cloned. The CEM would not be able to tell one clone from the other.
If I remember correctly, our ID48 has an actual (semi)random key that is locked. There was a research paper a few years ago that most of Megamos Cryptos can be hijacked because of dumb and lazy automotive vendors, but Volvo was not affected. IIRC.

Also I want to be able to start my car with just a screwdriver. I take it to places where any help is days away, so need a car in the most reliable shape as it can be. Security-schmecurity...

blasaab
Posts: 34
Joined: 24 March 2021
Year and Model: Volvo xc90/V50/144
Location: Perstorp
Has thanked: 4 times
Been thanked: 3 times

Post by blasaab »

Hoppfully i get the box and teensy today. The rest off the build is waiting.
Attachments
DSC_0156.JPG

T5Luke
Posts: 142
Joined: 11 November 2020
Year and Model: S60 T5 2001
Location: DE
Has thanked: 11 times
Been thanked: 130 times

Post by T5Luke »

I make progress in flashing by own sbl, a flasher could be an easter egg in this forum, so wait a few days and keep your pincodes and dice units ready :D

vtl
Posts: 4724
Joined: 16 August 2012
Year and Model: 2005 XC70
Location: Boston
Has thanked: 114 times
Been thanked: 603 times

Post by vtl »

That's awesome! :)

User avatar
RickHaleParker
Posts: 7129
Joined: 25 May 2015
Year and Model: See Signature below.
Location: Kansas
Has thanked: 8 times
Been thanked: 958 times

Post by RickHaleParker »

vtl wrote: 31 Mar 2021, 16:34 If I remember correctly, our ID48 has an actual (semi)random key that is locked.
Cannot be:

Our first attack, which comprises all vehicles using
Megamos Crypto, exploits the following weaknesses.
The transponder lacks a pseudo-random number
generator,
which makes the authentication protocol
vulnerable to replay attacks.




vtl wrote: 31 Mar 2021, 16:34 There was a research paper a few years ago that most of Megamos Cryptos can be hijacked because of dumb and lazy automotive vendors, but Volvo was not affected. IIRC.
A collaboration between Radboud University Nijmegen, The Netherlands and University of Birmingham, UK. Research paper is Here.

"Our third attack is based on the following observation.
Many of the keys that we recovered using the previous
attack had very low entropy and exhibit a well defined
pattern, i.e., the first 32 bits of the key are all zeros. This
attack consists of a time-memory trade-off that exploits
this weakness to recover the secret key, within a fewminutes,
from two authentication traces. This attack requires
storage of a 1.5 terabyte rainbowtable."


I take that Volvo is one that did not reduce the 96bit key to 64bits and issue the keys in a well defined pattern. This might be your "(semi) random key" .
⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙⸙
1998 C70, B5234T3, 16T, AW50-42, Bosch Motronic 4.4, Special Edition package.
2003 S40, B4204T3, 14T twin scroll AW55-50/51SN, Siemens EMS 2000.
2004 S60R, B8444S TF80 AWD. Yamaha V8 conversion
2005 XC90 T6 Executive, B6294T, 4T65 AWD, Bosch Motronic 7.0.

MaxDenisov
Posts: 36
Joined: 6 March 2021
Year and Model: XC90 2010
Location: Moscow
Has thanked: 2 times

Post by MaxDenisov »

any success on sbl?
Just found Volha Bordyk study : https://publications.lib.chalmers.se/re ... 156295.pdf

MaxDenisov
Posts: 36
Joined: 6 March 2021
Year and Model: XC90 2010
Location: Moscow
Has thanked: 2 times

Post by MaxDenisov »


Post Reply
  • Similar Topics
    Replies
    Views
    Last post