NPDRM: Difference between revisions
mNo edit summary |
|||
Line 28: | Line 28: | ||
From there, the lv1 hypervisor by loading [[Hypervisor_Reverse_Engineering#appldr|Appldr]], will transform (again) this key by using the [[Keys#klic_dec_key|klic_dec_key]] and finally remove the NPDRM layer for start the [[SELF File Format and Decryption|SELF]] decryption. | From there, the lv1 hypervisor by loading [[Hypervisor_Reverse_Engineering#appldr|Appldr]], will transform (again) this key by using the [[Keys#klic_dec_key|klic_dec_key]] and finally remove the NPDRM layer for start the [[SELF File Format and Decryption|SELF]] decryption. | ||
See also: | |||
*wololo.net/talk/viewtopic.php?f=67&t=40656 Tutorial: How to find dev klicensee by '''Mysis''' | |||
==act.dat header(encrypted) structure== | ==act.dat header(encrypted) structure== |
Revision as of 02:18, 5 December 2014
This article is marked for rewrite/restructuring in proper wiki format. You can help PS3 Developer wiki by editing it. |
The info on this page is an extract (and simplify) of talk page, conversations and forum posts, please digest the info and move it this page
Once the user is trying to start a SELF, the vsh looks for the appinfo header type; if the type is 8, then the control digest element type 3 (NPD element) is located. From this NPD header the vsh gets the License Types (network license, local or free).
- Type 1 (Network License): if a remote paid content is to be loaded, the vsh loads the act.dat and the rif associated to the content (will download to vsh process memory).
- Type 2 (Local): For this paid content too, the vsh locate a file with the same title id on NPD element (CONTENT_ID), then the signature is checked (last 0x28 bytes of both RIF and act.dat).
- Type 3 (Free): if a free content (no license check: no need for rif/act.dat) is detected then a generic klicense will be use for further steps (go to LV2).
Using the RIF_KEY with the act.dat index decryption key, it will obtain the actdatIndex, and finally having the actDat key index, the execution pass to LV2 Syscalls 471.
This function has different parameters depending if the content is debug, paid (type 1 & 2) or free (type 3):
PAID: syscall471(npd.type, &npd.titleID, NULL, &actdat.keyTable[rif.actDatIndex], &rif.key, npd.license, &npd); FREE: syscall471(npd.type, &npd.titleID, freeklicensee, NULL, NULL, npd.license, &npd);
- *PAID can also include free games/apps too but require this licensing check
The lv2 keeps a memory table with contentID and the associated key:
- Paid content: the rif.key is converted to the klicensee (by using a constant value on lv2, IDPS and the act.dat) and once transformed it is stored on memory table.
- free content: copies the titleID and the generic klicensee to the table.
From there, the lv1 hypervisor by loading Appldr, will transform (again) this key by using the klic_dec_key and finally remove the NPDRM layer for start the SELF decryption.
See also:
- wololo.net/talk/viewtopic.php?f=67&t=40656 Tutorial: How to find dev klicensee by Mysis
act.dat header(encrypted) structure
Name | Offset | Size | Example | Remark |
Version Number | 0x0 | 0x4 | 00000001 | |
License Type | 0x4 | 0x4 | 00000001 | |
Account ID | 0x8 | 0x8 | B4 1F 2C 0B DC 1B 43 31 | |
Data Hash Table Retail | 0x10 | 0x800 | N.A | |
Data Hash Table Debug | 0x810 | 0x800 | N.A | |
Signature | 0x1010 | 0x28 | N.A |
rif file(encrypted) structure
The rif holds the klicensee for both SELF and paid EDAT.
Name | Offset | Size | Example | Remark |
Version Number | 0x0 | 0x4 | 00 00 00 01 | |
License Type | 0x4 | 0x4 | 00 00 00 02 | |
Account ID | 0x8 | 0x8 | B4 1F 2C 0B DC 1B 43 31 | Used on Rap2Rif header |
CONTENT ID | 0x10 | 0x30 | UP900-UCUS98721_00-PATAPONPSNDEMO08 | Content ID |
Index hash | 0x40 | 0x10 | N.A | |
Header hash | 0x50 | 0x10 | N.A | |
License start time | 0x60 | 0x4 | 00 00 01 1F | For human readable, convert to decimal and use one Epoch-Unix converter time format online. Should be 0x08 lenght |
License expiration time | 0x4 | C5 16 7B D8 | If zeroed,-, there is no time limit. Used on PS+ for example. should be 0x08 | |
NULL | 0x68 | 0x8 | ||
Signature | 0x70 | 0x28 | 11 | Patched in some CFW to allow unsigned. See Rif_Junk on Rap2Rif by Flatz |
|