View Full Version : Unlock BMW smart display fob.
rband
12th January, 2022, 07:22 PM
Is it possible to unlock or erase that type of fob(please see picture).
vas100
12th January, 2022, 08:54 PM
Check on board if is pcf795xx
rband
13th January, 2022, 12:52 AM
I`ll check.
rband
13th January, 2022, 01:47 AM
Not sure which one would be if any.
rband
13th January, 2022, 02:18 AM
Not sure which one would be if any.
Another pic.
alex_r_2001
13th January, 2022, 09:42 AM
IC part number (mcimx285avm4b)
MX285: Multimedia Applications Processors - Integrated Power Management, Ethernet, Resistive Touch Screen, Arm9™ Core
Has a 128 kbyte rom
Maybe somebody with more experience can take a deeper dive ... It seems there is software available to communicate with (IC) this (IC] also has built in USB and ethernet protocol...
(https://www.nxp.com/design/development-boards/i-mx-evaluation-and-development-boards/i-mx28-software-and-development-tool-resources:IMX28_SW?tab=Design_Tools_Tab)
alex_r_2001
13th January, 2022, 09:47 AM
Here is a teardown with detailed clear pics if anybody would like to further research..
(https://fccid.io/2ADB4DK1S/Internal-Photos/Internal-Photos-3520982)
rband
13th January, 2022, 02:58 PM
Would be nice if it could be done through the USB port, initialy I though the port was only for charging.
Thank you for the info.
IC part number (mcimx285avm4b)
MX285: Multimedia Applications Processors - Integrated Power Management, Ethernet, Resistive Touch Screen, Arm9™ Core
Has a 128 kbyte rom
Maybe somebody with more experience can take a deeper dive ... It seems there is software available to communicate with (IC) this (IC] also has built in USB and ethernet protocol...
(https://www.nxp.com/design/development-boards/i-mx-evaluation-and-development-boards/i-mx28-software-and-development-tool-resources:IMX28_SW?tab=Design_Tools_Tab)
jodge
13th January, 2022, 10:48 PM
the 128k in the mcu is just the bootloader the key opsystem is in the spansion flash (https://www.infineon.com/dgdl/Infineon-S25FL512S_512_Mb_(64_MB)_3.0_V_SPI_Flash_Memory-DataSheet-v19_00-EN.pdf?fileId=8ac78c8c7d0d8da4017d0ed046ae4b53&utm_source=cypress&utm_medium=referral&utm_campaign=202110_globe_en_all_integration-datasheet). However the immo related stuff it seems not part the MCU/flash there is at least one NXP F2971 (https://www.eetimes.com/nxp-adds-latest-automotive-uwb-chip-as-bmw-drives-digital-key-3-0/) and maybe the unmarked too.
If it's using asymmetric encryption ther is no way to renew. Even when you replace to a brand new chip you will need RSA private key(s) to start using them. And the NXP guys are learning too from the cracked/renewed older NXP trasponders too (7961/7952..etc).
And ther is no way to get the BMW private keys
Just an example since 2003 to the selling to the Microsoft the Nokia's security servers in Salo, Finnland are under attac for the flash, simlock area and imei signature keys. Every day :) And they are remained unknow.
rband
14th January, 2022, 12:54 AM
Thanks for the input.
Powered by vBulletin® Version 4.2.5 Copyright © 2025 vBulletin Solutions Inc. All rights reserved.