RFIDler – An Open Source Software Defined RFID Reader/Writer/Emulator

RFIDler – An Open Source Software Defined RFID Reader/Writer/Emulator

A message going from the READER to the TAG is signalled by the CARRIER being ON or OFF and the message coming back is either DAMPED or UN-DAMPED. Things get a lot easier to understand if we visualise them, so here is a plain 125KHz CARRIER viewed from an oscilloscope:

And here is the READER sending a message to the TAG:

In this case it’s using a long pulse to represent a ‘1’ and a short a ‘0’, so the message here is ‘11000’, or ‘START_AUTH’ if you’re a HITAG2. Let’s use the PM3 to take a look at the raw data we get from each type of tag… The PM3 will act as a basic reader circuit and filter out the CARRIER, leaving only the effect of the DAMPING.

Source: adamsblog.aperturelabs.com