Keys: Difference between revisions
m (→SMI (Slot 0x213): Add first derivation seed) |
|||
(37 intermediate revisions by 5 users not shown) | |||
Line 1: | Line 1: | ||
[[Category:Software]]<noinclude>[[Category:Main]]</noinclude> | [[Category:Software]] | ||
<noinclude> | |||
[[Category:Main]] | |||
</noinclude> | |||
= Useful Information = | = Useful Information = | ||
Line 18: | Line 21: | ||
* priv file (private): %s-priv-%s | * priv file (private): %s-priv-%s | ||
= | = Per-console keys = | ||
See [https://www.psdevwiki.com/psp/Kirk#Individual_Seed Kirk documentation] for usage of PSP-related individual seeds. | |||
== | == Cmep Keyring 0x600 - Visible ID (Test Subject 9 PS Vita) == | ||
<pre> | <pre> | ||
00 00 01 01 AC 72 45 00 F5 68 96 03 80 57 C8 1A | |||
25 99 21 A1 73 A4 89 F2 E9 96 23 E9 86 0F 74 2D | |||
</pre> | </pre> | ||
* | * Contains the console's [https://wiki.henkaku.xyz/vita/VisibleId Visible ID]. | ||
== Cmep Keyring 0x601 - ScePspIndividualKeyMeshCert first half (Test Subject 9 PS Vita) == | |||
* Contains the first half (0x20 bytes) of of the console's [https://www.psdevwiki.com/psp/Kirk#PSP_Individual_Key_Mesh_Certificate ScePspIndividualKeyMeshCert]. | |||
* Warning: the dump presented here is byte-swapped. | |||
<pre> | <pre> | ||
B9 18 4E 22 83 8B 91 6D 19 86 72 D5 FB 10 FD A3 <- byte-swapped key_mesh.derivation_seed_1 | |||
4A 4E 72 CB 02 6E 96 E9 96 B2 C3 23 B9 CF 36 A4 <- byte-swapped key_mesh.derivation_seed_0 | |||
</pre> | </pre> | ||
== | == Cmep Keyring 0x602 - ScePspIndividualKeyMeshCert second half (Test Subject 9 PS Vita) == | ||
* Contains the second half (0x20 bytes) of the console's [https://www.psdevwiki.com/psp/Kirk#PSP_Individual_Key_Mesh_Certificate ScePspIndividualKeyMeshCert]. | |||
* Warning: the dump presented here is byte-swapped. | |||
<pre> | <pre> | ||
85 4B 14 AB 00 00 00 00 00 45 72 AC 01 01 08 10 <- byte-swapped hash, byte-swapped reserved, byte-swapped fuse_id | |||
FF 9A 3E E5 A2 B9 F5 25 32 4D E0 2A 8F B1 8F B9 <- byte-swapped key_mesh.derivation_key | |||
</pre> | </pre> | ||
== | == ScePspIndividualKeyMeshCert (Test Subject 9 PS Vita) == | ||
* By byte-swapping keyrings 0x601 and 0x602 or by taking Fuse ID only and running the ScePspIndividualKeyMeshCert generation algorithm (see PSP Jig Kick flashData.prx), we can obtain ScePspIndividualKeyMeshCert. | |||
<pre> | <pre> | ||
A4 36 CF B9 23 C3 B2 96 E9 96 6E 02 CB 72 4E 4A <- key_mesh.derivation_seed_0 | |||
A3 FD 10 FB D5 72 86 19 6D 91 8B 83 22 4E 18 B9 <- key_mesh.derivation_seed_1 | |||
B9 8F B1 8F 2A E0 4D 32 25 F5 B9 A2 E5 3E 9A FF <- key_mesh.derivation_key | |||
10 08 01 01 AC 72 45 00 00 00 00 00 AB 14 4B 85 <- fuse_id, reserved, hash | |||
</pre> | </pre> | ||
== Perconsole Keyslot | = SUPER KEYS (Dumped by SDBoot glitching) = | ||
== Perconsole Keyslot 0x8 (Test Subject 6) == | |||
<pre> | <pre> | ||
D9022A0C0D9DC52A55A162EA23F50A65 | |||
</pre> | </pre> | ||
= | == Perconsole Keyslot 0x8 (Test Subject 7) == | ||
<pre> | |||
A193E1DD073BECDF6720D0616A8E815D | |||
</pre> | |||
== | == Perconsole Keyslot 0x8 (Test Subject 8) == | ||
<pre> | <pre> | ||
80D71F18E0A3F393236AE1E875AE3EF8 | |||
</pre> | </pre> | ||
== Perconsole Keyslot 0x9 (Test Subject 6) == | |||
== | |||
<pre> | <pre> | ||
4B0F736E9A1FD865B125B05BC3641EC9 | |||
</pre> | </pre> | ||
== | == Perconsole Keyslot 0x9 (Test Subject 7) == | ||
<pre> | <pre> | ||
C310134A5F5D825AC5E0BB838BA3E287 | |||
</pre> | </pre> | ||
== | == Perconsole Keyslot 0x9 (Test Subject 8) == | ||
<pre> | <pre> | ||
04937A014699DA528E6B0CF7ECCADB78 | |||
</pre> | </pre> | ||
== | == Static Keyslot 0x605 == | ||
<pre> | <pre> | ||
3B 39 E9 2E 25 B0 40 38 27 EE 32 D7 D6 49 A8 47 | |||
D7 F1 1E 24 D0 11 76 0A 79 43 37 D4 F7 40 C9 DF | |||
</pre> | </pre> | ||
== | * Universal | ||
== Perconsole Keyslot 0x606 (Test Subject 5) == | |||
<pre> | <pre> | ||
5E 75 05 CD A7 40 E8 5D 7F 82 B7 EA EA 32 CE 1C | |||
66 04 2C E9 E6 B6 F4 F1 DC AA 94 A1 06 B8 32 EF | |||
</pre> | </pre> | ||
== | == Perconsole Keyslot 0x606 (Test Subject 6) == | ||
<pre> | <pre> | ||
DD DF C7 61 C7 7F AE 89 CF 39 6F BC 30 CF 7F 60 | |||
F8 BF BC 24 E1 3F 5A CE 46 50 BC 66 2F 73 AC D4 | |||
</pre> | </pre> | ||
== | == Perconsole Keyslot 0x606 (Test Subject 7) == | ||
<pre> | <pre> | ||
72 39 DE 10 B7 F1 92 D5 78 E1 03 81 63 7F CF CF | |||
D4 44 9B 58 A1 7C 97 E5 EC F6 1D 09 40 82 7B B2 | |||
</pre> | </pre> | ||
== | == Perconsole Keyslot 0x606 (Test Subject 8) == | ||
<pre> | <pre> | ||
98 AF 08 AD B7 8A E2 83 0A 31 47 0A FD 00 B2 64 | |||
D4 E2 C5 83 E2 14 EB 57 F9 58 CD 54 C4 BA 09 4C | |||
</pre> | </pre> | ||
== | == Perconsole Keyslot 0x607 (Test Subject 5) == | ||
<pre> | <pre> | ||
F5 B1 8E B5 37 DD C4 6F 6B 59 A4 19 AD AB F4 A8 | |||
52 02 9A 0E 50 E4 FC 3F F0 93 88 EA E3 34 C7 E3 | |||
</pre> | </pre> | ||
== Perconsole Keyslot 0x607 (Test Subject 6) == | |||
<pre> | <pre> | ||
FA 87 A5 75 15 B2 88 60 57 5E 2C 2D 45 7F BA 86 | |||
55 32 A9 74 96 BF D5 B9 E8 D4 CE D7 98 19 40 97 | |||
</pre> | </pre> | ||
== | == Perconsole Keyslot 0x607 (Test Subject 7) == | ||
<pre> | <pre> | ||
7E EE 37 A4 C0 DA C7 D2 0A AA 5E DA 34 17 B4 5C | |||
45 A8 DA 4E FD 40 7D 9D E5 08 53 B4 9A 06 29 43 | |||
</pre> | </pre> | ||
== | == Perconsole Keyslot 0x607 (Test Subject 8) == | ||
<pre> | <pre> | ||
6E 1E 68 77 A7 1D 05 8B 97 55 F6 9D 2E 2A 24 1C | |||
4A 3D B7 E4 3B E8 F0 65 FA A0 8C 20 58 89 3F F2 | |||
</pre> | </pre> | ||
= Keys = | |||
== | == Bootrom == | ||
=== Personalization removal Key for SLSK (Proto) (Perconsole) (Slot 8) (Test Subject 0) === | |||
<pre> | <pre> | ||
85C688C1B3BACB16EB57B4CC35B7D590 | |||
</pre> | </pre> | ||
* | * decrypts the .enp (not ._enp!) perconsole layer of an enp file, turning it into an enc file | ||
* algo is aes-128-cbc | |||
=== Personalization removal Key for SLSK (Proto) (Perconsole) (Slot 8) (Test Subject 1) === | |||
<pre> | <pre> | ||
8B5415DC7EB5986472BF6B30D8E3E812 | |||
</pre> | </pre> | ||
=== Personalization removal Key for SLSK (Proto) (Perconsole) (Slot 8) (Test Subject 2) === | |||
<pre> | |||
95B7B3EDB2EF277FB0F78FA3970EE0D0 | |||
</pre> | |||
=== | === Personalization removal Key for SLSK (Proto) (Perconsole) (Slot 8) (Test Subject 3) === | ||
<pre> | <pre> | ||
CB0B65F7897F30310471F7CDA2CFD804 | |||
</pre> | </pre> | ||
=== Personalization removal Key for SLSK (Proto) (Perconsole) (Slot 8) (Test Subject 4) === | |||
=== SLSK | |||
<pre> | <pre> | ||
F3E408E1EDC3B513277DB99E58A15BE3 | |||
</pre> | </pre> | ||
=== Personalization removal IV for SLSK (Proto) (Perconsole) (Slot 8) === | |||
=== | |||
<pre> | <pre> | ||
FD4FA8FA4FE79430A0CA305C88E524DD | |||
</pre> | |||
=== Personalization removal KEY for SLSK (Proto) (Perconsole) (Slot 9) (JigKick) (Test Subject 0) === | |||
<pre> | |||
9E0A8285C3BE83951C78480A7AEC80FD | |||
</pre> | </pre> | ||
=== SLSK | === Personalization removal KEY for SLSK (Proto) (Perconsole) (Slot 9) (JigKick) (Test Subject 1) === | ||
<pre> | |||
686268A876650A6A6DC353F69EB82F19 | |||
</pre> | |||
=== Personalization removal KEY for SLSK (Proto) (Perconsole) (Slot 9) (JigKick) (Test Subject 2) === | |||
<pre> | <pre> | ||
E7A8ADF7B7E2BC26E3445084384FBCE1 | |||
</pre> | |||
=== Personalization removal KEY for SLSK (Proto) (Perconsole) (Slot 9) (JigKick) (Test Subject 3) === | |||
<pre> | |||
736F7501E9A15AB29800113686C946BA | |||
</pre> | |||
=== Personalization removal KEY for SLSK (Proto) (Perconsole) (Slot 9) (JigKick) (Test Subject 4) === | |||
<pre> | |||
BEA39D6443FBACAB05DA62BB95470D57 | |||
</pre> | |||
=== Personalization removal IV for SLSK (Proto) (Perconsole) (Slot 9) (JigKick) === | |||
<pre> | |||
986D5EE1E7759F4F52DB43F33FA5960A | |||
</pre> | |||
=== SLSK SHA256HMAC KEY (NonPerconsole) (Slot 0x20) === | |||
<pre> | |||
2E1FC0BF211AEE3977C96F1089A150F5 | |||
A3CB9E41314BC39F0CBEC16AF3B0B9AC | |||
</pre> | |||
* calculates header hmac (0:0x1C0) which is compared against signature at 0x1C0 size 0x100, verified with key 0 from bootrom rsa pairs | |||
* calculates encrypted body hmac + 0x10 bytes (0x2B0:end_of_body_from_header) verified against hmac at 0x190 (encrypted with double AA key and custom iv from bootrom) | |||
=== SLSK Header HMAC/CBC KEY/IV === | |||
* key | |||
<pre> | |||
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA | |||
</pre> | |||
* iv | |||
<pre> | |||
EEB5EC5CCF1CF43113F5213AD5B8D6DA | |||
</pre> | |||
* decrypts what's at 0x190 size 0x20 of .enc file using aes 256 cbc | |||
* result will be a hmac calculated with key 2E1FC0BF211AEE3977C96F1089A150F5A3CB9E41314BC39F0CBEC16AF3B0B9AC | |||
* said hmac will be from header size (usually 0x2B0) until header size plus body size (0x2B0 + ???) with body encrypted | |||
=== Factory Handshake Key === | |||
<pre> | |||
F47716E6C5649FD648538FD9773D12D1 | |||
229E118737B1D782D6A80CDB72E4B9C3 | |||
</pre> | |||
* Shared with SYSCON | |||
=== SLSK IV (Confirmed) === | |||
<pre> | |||
AF5F2CB04AC1751ABF51CEF1C8096210 | |||
</pre> | |||
* Used with AA 16x Battery key (AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA) to decrypt SLSK after depersonalization | |||
=== Bootrom RSA Key (Fallback for SLSK Validation, all fuses blown) (Proto) === | |||
<pre> | |||
3BD3D7E98A17F359F19E3AF9802B95E9 | |||
D6946CA8903136582EFC9C88F4F01E3D | |||
3101E2FA33541A231E4E45F05E8536C6 | |||
4D69B60EF4B3004D23AD72BF801B8695 | |||
EEA843BE585862A63D6B2BE7F90055A8 | |||
C690AECAD63B85EA118A79BBD510156F | |||
53D3B7623811C18F0829364ABAFB1A6C | |||
9D841F20A08831963C0D5B64FB360947 | |||
206C748AEFDB1715896BCA4D2980EE22 | |||
B0C3243FB73C3F2A0A868C587E57B77A | |||
FEBE2B983046D6428C722319A598A5C6 | |||
0EFB9C4E9FDCF793DFA3CDEEC6C8A249 | |||
42652531706D6D701B0B0C660E79D241 | |||
9D38E1B8E976BD9FB4D4CD1E6F461E86 | |||
B295C6FA10D1C7927CB266C08B3025CC | |||
76A4837EF0D8208BBA305059E23DDABC | |||
</pre> | |||
=== SLSK Verification RSA Keys === | |||
<pre> | |||
CDAE7E886C890F5EC5FF3AB72EE09D4A | |||
2369F5593A3BAD32256747103EB173E5 | |||
9E6EAD3ABD18C0474CF54A09A0500B94 | |||
CC20534F04CC8268507F0E3E109307F3 | |||
4B74885FEA456FBECEE2F04B87FDD1C5 | |||
4784CC79ECF76688CCBCDC18FB36ED20 | |||
0662C058D91619F3F50E404969A57CE9 | |||
1697F907B768094B5F0A683CD72962D6 | |||
84A12145CA84DBEE6F4B03D986A19C0E | |||
7CFCBF0006AA492F071662707CF92604 | |||
A8B7E6BBFB3FDB66C4E049A4978A523B | |||
D6E521346BA64BD8B050185730B4556E | |||
1678BB9D7384EA0FCE3E509F1227B45F | |||
FC5FBD39C42C628012C22DF47F5D4ADD | |||
C8FF6F6DF11BC1604028141F21224B5F | |||
D323C1F3B7B7DE6C1F1BFC8215C47AB1 | |||
2136E5DF66193889419EAE7D7B6AA49B | |||
258D47EBB1C3C1A20737D9400FECCA43 | |||
567613B5BED61C9645110A4BEAD9D9DA | |||
CECFED9E87A50422560490F243F53595 | |||
08C98FAB44E067FDF86A1F7ECACF9E38 | |||
A2ACA19C6740C22742CBB8E7364531CC | |||
39127BB97B18C9E0A3C8AAA44DA6BCA8 | |||
59DACBF238B75732C5858C9D73F0415F | |||
ADAEE2224E567670FA7911450495BCC1 | |||
C95B69AF831774557890C3DC9EC62BC2 | |||
830FC7639156D58A81C83557E080B970 | |||
17AF7FD4652BE8DCD1F7A2D622ABC4FC | |||
C65BBA3E466742153CE3AB595C27CC35 | |||
BA4719C5D8CB4174229AFD52B0F496A8 | |||
8A178FC4FC85290A3C87776131516782 | |||
291E56C84D624079DDF2C30C05813BD4 | |||
2956BAF256B87660D15B82108D8D516F | |||
EFA8C083CFBFD789D24DE45C4B577471 | |||
CC135976422B66FCB8CDCFA8A1FE89C1 | |||
FBF425FD672BE4C1A7CF9076ABD5735A | |||
EAC6DFB30E7800FC45AAC29A71E94766 | |||
5FF72C8A8E1971EC5A37A4D4255A5A79 | |||
C716A404C8CEAB584557B0C927A22C59 | |||
B1A530B7B355402229F648A3D53A0E36 | |||
DFF42C59E23892978EDC425DD9E3E62C | |||
8940FEF195C87DD5F66BB6A343472139 | |||
8A9660B4F4171D6D8869F5E2E467FC4D | |||
262F3A6F0634F0460586156C23C821D0 | |||
93C0ABD45AB174B303C1C09A6B3A03C0 | |||
4A077C770770EB25652F1CE6EDA6B0A8 | |||
CE3033B085EACF8AB3B387F940311DF4 | |||
B6DFAEC8A95AFA19EA2FF4F23A6A2FAF | |||
43CE217A67DCA72211AB644072D251A4 | |||
9967A771F98CD1BA4631239EED253F77 | |||
56170514BB5DFBE8A4BB7C1ABE6DAD3E | |||
CBECB7DA2174B540CDFE6FF3349EB298 | |||
3A6F299237E79CD1270E57598C10B2E6 | |||
99C381DBDBFFEE1275A9FBBA81724C9D | |||
CCC18897EDE7FA70F2EA715955DE48A2 | |||
B6D0542B736FBDCB51B85D684C5EAD89 | |||
1B224EB51D92BB26D5ED5B5EE7E0A837 | |||
4F2EE8728B73973CEFB39168D025686E | |||
89A96361BD2279C9DDE0E4A448A572D4 | |||
707AB9DE3C7BB3FB67302518DE31CBC9 | |||
491BF12F76B681496257AD20BDB8C63A | |||
E44595B82352CDCE00B9850B151BFA3E | |||
81F7197593FDB5DDD562992C21E86A28 | |||
E0CE3CA59CB0C6315B06B3483873A3AE | |||
493A79509144EF3042D01456727F3E0E | |||
8B652C4B34343EEE9439B36D91FB9037 | |||
4A4546A405BBFB192751708F54EF23B1 | |||
F19065F0BB0C306476BEAD56B4601B4A | |||
EF947A87E3FE79BAE1AEEE0F695D9A54 | |||
E03A60F8A3CDDDAECD9965F193627611 | |||
254DD9F02129C51AAE4549B0887FFDE7 | |||
5B0790D9FD81D90AAAF1AA364C5A7FC8 | |||
B4A5ACD9D3C8F3A6184812745D2F9017 | |||
98EF62812907586D6029116379A1E0FF | |||
ACA8C646FB0EA2433703327DEA866A9C | |||
7C63D5D6656F71DD65D79E67969AB256 | |||
4F813AEA955E0105F3587B6A28EAD7E6 | |||
0A00FEF6DF38CF1735502684F4ED0A81 | |||
1BD5A1A076F2DB59280C683D714FC41B | |||
4A5FFC5237E77176056F2843A4E4B8B4 | |||
DD9B97C1C59C84304950FB578266181A | |||
49E208403BCFA664B705628C94A48223 | |||
7D7E67167D717474A052C03938D1791F | |||
6ACED52A4F3F30E2ACE0226E45A5E296 | |||
D57D35D8CE3E1953C9290940EDE10CB7 | |||
3C9718F2D0D370EA887311D6A0187491 | |||
BDBC7301538897C7B76BAAFDE38CBD04 | |||
9E35957B0D09438A826E52E15F414A1C | |||
B1CFE4ABC4BEB25133CF8FC15075768A | |||
4FD106E44C7FBAD184E9105CC238CDB9 | |||
42B5167DE438425606C03B5C8481E6BC | |||
0AF7F5E183A3B4A6935188968DF8A817 | |||
AE06B4CCB6BEE8F989FBD98FAEA40EF4 | |||
5F8E207CE3BEF80284CDB7B59075A63D | |||
C59D6B826FB4E72C95206C2BB84D46B3 | |||
E60DE3D48EF1366144F3F5B22B599CEC | |||
F7DC3137EC6E0A1F8EC018023AB259F8 | |||
C2D6B282CC5A9957B58AFD6E29206B90 | |||
C565F9CC4EB14AA2DAA159A5EED38C85 | |||
B01AEB1E4F4B3DEC8E0A9A4676515ACC | |||
BD3FA08EDF85F278BD8EF51A7FBDDA96 | |||
5B88970DB139F4C9488B0D60ED6F555B | |||
AEF77CFAAB76B4798AC34A02A95D3DAE | |||
A700A9B28F55FCF47554DC10430F7A89 | |||
E44FD416C024FC830870710AF42528A1 | |||
E3F00BECEF50274A29C31C2E71302E25 | |||
077AB07427F09815D5B0D029A57AD69C | |||
044BABF08F9D2764A5E15C25CE53E320 | |||
612FC68363A34A52F9A69A9D12F31D3D | |||
C6D6D37C8B8407D9B7178F1EF19AE7C2 | |||
B1D5FB7618063AB016DE433800BDD696 | |||
6C574EC47FA34A66B0324D39D9F887EA | |||
53229DFA87ADCDEE652C35A44952A00F | |||
3E4D078C9007C43705477B234ED128E9 | |||
03EBA44D0CF85EC26B9057CC38E62778 | |||
395C9F5EDFAD71F2CBA30A40806F9225 | |||
180958F85FEF21D2419653E780EE74CF | |||
82E6B0B1AF5D2C52ACDCA913FC37BEC7 | |||
54BA1BA337EE42F598DC462DB96EEE02 | |||
9060ACD6D27E9DD58DB1C36603FD057F | |||
EFD6ECB9977F1EF5486ABA7338A4A1DF | |||
FFD5BFC2796D4469374C61495D62A781 | |||
BA97EC2739EA5FDCAC538CE891D900EA | |||
40FC0EDABD7D08000B37419E114766F4 | |||
012555D2B097CE780A8B51960F88100E | |||
5AE90798F0076D00959E17FD7416BB0C | |||
002882A1576D8B20A7859E559B4ECE54 | |||
1444E86206C77F6FFA43BF7C756B62BA | |||
E1BF0650D31FE12C9DA5024CD4645A0A | |||
E96DB6ADDEF787ABA872F3037335249D | |||
06FC3B6D03D9B9D5DCFE418F2A37896F | |||
B9D758A1549335F5099423EEF0F46B15 | |||
FB3ADC695A3FC1900665C38C0B4CA12C | |||
725149BF289C50EDDA751AE030A1006B | |||
37C0A4BD8EE780FA9D3E1A97E649A3F8 | |||
E8345CA24842D5D1176DB24D98B2FA02 | |||
7CF4C898E6E72184B25583E66FC90DD7 | |||
85B995D1B6BCCE04D783616808F45810 | |||
D3A8B978884A0B22FEE09E2D7318EA02 | |||
EA9709589068BBE7A1A3D54D486221AE | |||
7B618AE592FE76494B4434A736FCB10D | |||
3DAB19B0A034235183CAB308334227B7 | |||
422D4EA100EB81B34DD698A139FED839 | |||
BBDDAF0D06FBCD608A350399C2B5BFE7 | |||
410DCBC7D20513E7DE81D2C3B2F6B3CB | |||
7473FF0D9DA8F8AD3E807A8C48FCC319 | |||
4BCAC94497C344844636B35F3922CB80 | |||
0F6DD1D7D25929693E94A1C2462B248A | |||
60C2CD1220C8798E45DCE81953FADED3 | |||
18F136A550010B9E5AFD4E5B952A2E77 | |||
F22026188733C3A1FD128AF89820BA73 | |||
A56A23AF49E04F4DED4F78F69196AA88 | |||
042335A49C2582068E69A851E1ADF72B | |||
8ACCF7EF2821B7AD776B1C50B4FFC792 | |||
B6172CD7188AA31298C42182C634D3D3 | |||
AC32A3FFA2C324897645D3EA053D1F8D | |||
68F79CADA1A7802FA16FE7D399475731 | |||
CCA4977A9364BB312994F850095BE052 | |||
EC0A534029E63CCEA7CD9E43CACEF0B4 | |||
AE2429AA9912B7BAE7DCDF00BA9D4ADA | |||
6130CB7658FC6EC566D622B55C4F6BEE | |||
FD4BA5CAF2A4BB5F2E79820B5427CE60 | |||
1D7E92B80D1566ABED917B412F49A3D8 | |||
D5129A34B9861C1AEC99906847BAAE94 | |||
F790DACD9F0EFFAB81EEC5687D05003C | |||
B748F279727AFE1E4A1FFC07318523B8 | |||
E6EBA0EBFF95626E466E6BE41EB7EC09 | |||
1A6263C04A92E1924E4D949B305B6F91 | |||
EC0FD294876D6548582AE12FF8A39FA0 | |||
FCC11B7E7F7AFB3D1DB33A15B1ACBDA5 | |||
BE8AE8F76EDA16B3482320B30E752392 | |||
F2C465C4A07792340B96072EFBB82B92 | |||
05F683AA1AEB69C0980409B1A2120518 | |||
63F0DC654CF95AA1A219D09204F4706F | |||
A9D55BC79CBFB26FDC0130155A34B726 | |||
E6F168458EE622F725E75C2FB0ABCACA | |||
05F244401B5862D742F3732AAB702DA9 | |||
AADCB86AFE3E59B1D670670043738940 | |||
283609746209898A3D70738A56C7E748 | |||
B2471143D84B0A88BD9629198CFCD5E7 | |||
D01AD41CEB9A08E081D8F72459C70411 | |||
249053AE392DBC284E1F49098A6A06F9 | |||
E1D8670B25864B2BF37CD5CFA2B32449 | |||
8B42F2DD41ABF081DFBA07061BE4B964 | |||
794313997F0D6E0F6BCE5509F87CD4E8 | |||
3162B15938BCF989F5F7384559D600C9 | |||
EE6C7E2D9ACA36FA3E6EF6C91D98C07A | |||
9E79EE6955E8035CB49FC65EC35F2CF2 | |||
12BBABC6C6525A4FDFECC997F1D5E553 | |||
536A6FE5338182B4B001ACD49DCB677F | |||
44E7112112EF26B7EAB62B44F91A5B0B | |||
AD28B164530DC3A4FF17DBB976241EC3 | |||
FBD84775010D95618284570663BA7DDE | |||
36DE981C7641FD35D356B01A1B39ED9A | |||
2A6450F61A0F2023CBA098A43DCAC879 | |||
186AADFDC4BBE687CA8D78D9D62E96C9 | |||
3BFA87A8064988C49582AC1FC530330C | |||
716526F440A79E2AFC0EB58F9A123B7D | |||
342A48E5FEA7BEBCD4FFC8CEDF6122FE | |||
3939080A5B8CE8F03869F6447FE1B33A | |||
49B991924DBF8343F3DC72457BAE8CE5 | |||
0D291664475A1E6B564A09BE0A7FA279 | |||
4C27EBF2580D687E6116F84F1A347DCD | |||
346B1AE3B48ADEC0860C36884653A5A3 | |||
9744C2229A85BB72973CB431647C7EB5 | |||
0DDD528C09C3C2097D7CD7A6FA28DD6E | |||
8D9D3841CDDD90A413291C73F88523CA | |||
C53618E0483E09BA88CA53FD6DE785CA | |||
496905C2DEB8B75852F2C9FB948F5C15 | |||
C072C8571E5BC3163FC3FCBDF92E5B5D | |||
BA30D220C185502D7E9E0A83B2AEA098 | |||
E1F9507DEF5FD0F129076B3F7E745B44 | |||
0A2F56C8DE9591C3BC16F777B0826566 | |||
50FA1E85B1D244C0F691E893D7E0D2C3 | |||
A15AC56D069ECB0E31897EFB918FDF93 | |||
B5FA1ED6DFC7421E5439DA867ABADDEB | |||
B785A6F95CD23B4CA8255C89EF4E8D9A | |||
497FCA1C013B04BC9BEC00B265EBEDC4 | |||
FF58E990BEB594C738CA6A601796E0EE | |||
79B1339FF36E0A49AA4984419DB4B233 | |||
F761AFA5EE61172DADC669ADA72390B4 | |||
7FB83172A975DFD0E4CD04FCA627A5BC | |||
D1B249094673CA74ADF0E6F07BC5706F | |||
9904E7C40C7EA59012BBEF30AAC35DC2 | |||
B101B337AE29FA754FD10AF5FFF77B3D | |||
F77BB7A317F74801BE38B238CE98020B | |||
CA4C9268F837A03E83389EF7BDD9C7A0 | |||
2FE93FF70808240BB634458B01973CD5 | |||
A0ED95619AA09C4933CA01411B9B26CF | |||
FC633E2880CCD5A3776883CFE329FCD5 | |||
6912325EDEF3A61BB4FA5992C7A4CD13 | |||
230C1E65E99C1C71F7DDC5486FDEFCD5 | |||
632C384C40AE12676C66EBF25B859EDD | |||
3061F8388070A99479A68E5EBC794BC8 | |||
7B3D16D8B4969F78A86D06DCE61B1DCC | |||
B07720B84D8972AA2B861B2EB586837C | |||
4422481883B297364C1C763396F94AF3 | |||
432B2FC57370311AC1B2857C517EC51E | |||
5D45A31DEF78DC28422539D7A5EAC579 | |||
B0EBA8334D836668FA4F3A6FE25DBBAF | |||
55157A5C49708D923589694220173DE9 | |||
A3CE2F96E33963EA87E2067FFC3807DA | |||
AFF11869DFCB2DC208313B7ACCB393D1 | |||
44E7D5D50FFFEF11C3DEDC877B028FA4 | |||
C4705E723702E28DC84C7E355C120375 | |||
3F7DEFC9E38CBD790D4C6C326A9F48E0 | |||
8CA66BB18D1AA342B7E62049C63ED76F | |||
07ACEAE7BBDB5076BAA54F2D84E31775 | |||
97C02E539A4BC00BFCA54437463EF830 | |||
B1AC92BC339A9376F60792D61933C607 | |||
8CBD70E0752CC2099F183F6F4C8C7D5C | |||
1DF02E626AD0FD595209EC9235ED63DD | |||
D483EC895F5784D2FE640ABE4BBA2ADF | |||
115EEA30F3C1B405F4A513A581C6333B | |||
9844698FBEC9AD01A2619BFF716703D5 | |||
6A69B8EE459A06FD9A61EA1ECDF0E993 | |||
80D3AF14FBFE8E70BE3DB07595214A90 | |||
8712B756322A8667DA589F370C3867A6 | |||
1DF895CD14E53DB0E6479C975C13FFBA | |||
0C27C40B84168FFFD63CE001D334A4FD | |||
D3FC72DD9963AE825F7FD9C5EA1D9924 | |||
1DB1261DD0E31CD94D8F2657D8EC3D93 | |||
F2F08E3D7DF6FE07ED9FBE87FCEC75EF | |||
7E5FA243F5BA24C1B81E121FA07DB901 | |||
6A5F33FCE5F23BB89E108BC27718F5EA | |||
A09CF686DC15FFDEC0129928680ABE5A | |||
336FF78FA69C57741899EF7A238DE1AB | |||
CD39BD6B23B888A34D7DCDD3F57CD8A5 | |||
5D2735973E74F3C416FA1B019515B5B2 | |||
CC45367F1E769010A96ACF79B78BB8BF | |||
7BE678AEEBA54214F5DBC3B0ED3FEF22 | |||
793C9B3564F9B3B134DC87662C0014A0 | |||
5BD5F12ABD2413C8E8AC5D8CFC71EF07 | |||
E0276B083E3A2729EEA5B068F1F85331 | |||
986420BC576CD005228A4396AF000F4F | |||
95EA10E442844D84EAAD40C95796F705 | |||
7A5BA3F08ED905E179416E05BABE6D43 | |||
216D5E5F8B346CEF01DD266F5DD2ADF8 | |||
F6FB17FB08515B0B752B6A53E09EA007 | |||
FAC79327B53E568FCEF00E2E85D54C1B | |||
6BECD2639F5527F7A6F32A689013A091 | |||
1F1E011227AB565C4D5ADBF9FF02F15A | |||
00429863BA5634B4285CA2F2B5109AF1 | |||
A83314D1F3EDA27D8CE9EE568B13A575 | |||
94630701EA5BC9518339C697341EBCAB | |||
6F21B615EC1A93FD141B3190DCB6346C | |||
35E7E9C15F468104EEE83771A2FA096C | |||
27E1077F176A6A2B72927126301A91E0 | |||
8F9D7AB79E79587837981413153A4531 | |||
4517E300F97086529D73DD9F2A3AA946 | |||
29D644DFA9A730C42F3D5865E436FCE6 | |||
9A98344EAE3A3B9675CE9DA9F5877820 | |||
78876C7583D4859CE27BC6A0181F070E | |||
C12FAEC7943177837A618070D2EBE603 | |||
4058F525D70BA7690AA615D2D83B882C | |||
38C70FF2175FD11D89375104E5D59268 | |||
114910602E78EEC49DFDB30ED2D32E45 | |||
F39D530F76B5194DEEDAC6AE5BE64473 | |||
B287A1D2B3BD78EA498249A4A3F6E944 | |||
4FB4A1E306969B4E61704C39D78DFACE | |||
985116F83F1B2CB1119798740C059FC5 | |||
EB77A8C232EC13A8C004FBE259DDD369 | |||
C3B53CF8E86F2A47B01107C63261EF73 | |||
558EA2F03CE2A2E2FB7F4E8141D98206 | |||
834A3D317CF16E6756DABBE968F733BE | |||
A5C954A2CFE5D3D276E0CBC7A225B4E7 | |||
D7877384AD02EA56F09E5C82DF5C236B | |||
A054420A95F0FA959108032DEB1B7811 | |||
037BB91AB52F151D1F760EC949F4C7A1 | |||
26451A5707F7C5E9F1723D2C8F892A36 | |||
C5A0DD4B5750F5DA8A26E3F4F7B2F107 | |||
68E00410C84E69039A833153D8DA687A | |||
061C6DE184F761BC8771C6909C791AF8 | |||
D8D9927048D03600BE531BE3D7D5C51C | |||
D493B5640F4A7AACDB934797BEEDA10D | |||
102DD5329D44BEDA56570752A7BC2A9F | |||
6F4B5ACA17641CA3ADD546F59A9FBE0B | |||
DE984D1F6A88CA2764676CE785380B41 | |||
71D70E9D083C81D567366B3D951779FC | |||
2C12AEB2A865483145754B79EBA173C8 | |||
8DE96A5B2F557055A9CB4B4A299E86EF | |||
0EF6769415F8CB3A83D514CC3F70008A | |||
1E090FEB4614201D25B54202A8CB3811 | |||
D49DBDAFC4ACE6D63B6E13E67CC9730B | |||
CAE4A283424BBC14EFD89E72E6513902 | |||
AACB955CB3CCDF4A47B3948A4B0201E7 | |||
6BE4F58725AD38C481E67D4060C2D31C | |||
DBC87DBC491114E6A87C45B3EA37A227 | |||
0C5C941CEE02E8C1BCC29256DD86D0B0 | |||
160724EAF49B4363F8F65229B5202D69 | |||
F1DC00952693B75A8883AE8FF5A6B4B9 | |||
F85367D5EC06AD8AA0C765EC09590543 | |||
3DA8897BC46CEC5193C81E39EE0A574B | |||
CA73FD099805B48477B3887305EDAF9D | |||
E19B36E6DE66691CD0A8EF19ECB45BA2 | |||
898E6D9D4A0C6E678E3BEBAAF44E67BE | |||
431AF443ACA1049CAF3455F4288D6A4C | |||
C69307F7BD986F1239F846CAD5EB1CAF | |||
B5F9906E558F087984DDA69DBB43AA7B | |||
E8FF00FAD2D02DF4CEE88BF423F51BDA | |||
1F1B3944D5A17E74B7EBDEC3ED8A7078 | |||
3EDC9BCBDB76BBFAFB546CF882FE1107 | |||
9778F5ADE0126F3B357ABD48D6B6EF2C | |||
A0E303D3159E69178C2CAB41F841DE56 | |||
609EC551F154811896907D2B8691D8B8 | |||
360BD8E3062B0A46DF7778BEBA6484E3 | |||
0701B80610D59E2253AB10DB8D896426 | |||
DD111DBA5F1E31B7761C6A963056C59E | |||
70F74A7CA32DA4CB46518AF2192D0416 | |||
E9B93644B03073270DE6BA75816DBB51 | |||
F8769CF01ABDC46336466C9261597E70 | |||
106344EBD0735178E70B83CD4A187EA6 | |||
283D76AB50F838B41DD94D94D8FF1AFF | |||
23E42CC58BEE0A56ABA29A3151528C3E | |||
B0281F507A97C79EFA14DF4BC64F3F59 | |||
64EE0076934AFF3375D9E4F04DAE5E14 | |||
DF27D3F0054F40201CBBC6BCB75A9655 | |||
0A5EAAC417FB605A0014B9205325753C | |||
556328F1F096E5D50D83EB3CB335C453 | |||
E0F3B0BBF3B75277B915B7F5E9878DE3 | |||
847DF7AB55C11A75FD5353FD1B38930A | |||
6B27956CCC9505AF49E3B005711FA514 | |||
6A4ECB0F506CBADA661D466298EE1433 | |||
7C27680232FD5510D538160AD27CB490 | |||
1AEDDE48DDD6185FD743B69D9F0454E4 | |||
DF723F416684FBFFC73BB09E4588A68B | |||
E8EEA00603D07E4E37E2FA8E61CA97D6 | |||
4C3019AD267187CEFB132734825B7640 | |||
BDC147A43A1092A482EC5CCCB6890401 | |||
22F9F538433C2EFD9F4D13D5A612ECFF | |||
5C7A7CFF2E6DAD153A63D0C88E39FBAE | |||
7ADBF37C540BE6F1F4240566475EC978 | |||
1ACA6B4A5FB7AF017A4C5CDFD1503699 | |||
4F7E4D677B124C602FBD08D952FA7B47 | |||
3CA989237AB17D48090D9CD1C7CA37DA | |||
737D596487BAC92E6FFC18F1242F873B | |||
BED97C92DFF41DC45F73EEFCEAB3EC68 | |||
00321E1FA4B9DE8840B29AD648C8438F | |||
EC18D74088D6E075BB1295869DF5FDA9 | |||
3A89BF187D4CB310EB9B3D3D0666294D | |||
D234D4D96ABB1421A94321647E49E418 | |||
5295854F89D61886F905304150D418BB | |||
4C80C7C775F12FD51C3F3721237B473D | |||
C82F1176221546C6BCC22383CFE63DD8 | |||
8497D52C2C329F399841CAD263BB4D7F | |||
640C8B583FC15400FD3CE28EB6F52EC6 | |||
1E094DD0479201E59FFDAC0B7193DC11 | |||
6E98A9C9ABBB729209F5600FCC901990 | |||
804B691CE39E3CE01F8F0B2238F73C2F | |||
68747C6E590C30675F15AD230AFFDFB3 | |||
07AD55B0F6D241AD6C3FCC6903A6B25D | |||
64DCE7F683D23317C3BB8F27D93EC42F | |||
F947AD4115BAFB3DC4C57051F6AD787D | |||
341C716395E8432352776003E375E6AA | |||
E07E2174B75D26C83BC0D96F8E350C4F | |||
F7BAE27584BB6D64BF46AF0C94A6CD56 | |||
2A63807907B0F4F1C90888DB4F5A8E3D | |||
FFB073F8D7605157FE08916B3390004A | |||
0250F18BC7F05306DFC231E627F010B4 | |||
E2417DB0C6A3EE785D13F2BD48F1716A | |||
3D621C703958DC2B8ACF42D385F64927 | |||
1D56AA6077AF74F68E16B54028038A40 | |||
588E93C26CF3D71386338A4E14132CDA | |||
4E97A73BC3D01CC3A41909570F24BE41 | |||
7663161A5166D2BDBEEA969EA7FF5A5E | |||
12B8E7B4AD60E1671A3FFD6105593349 | |||
F323EF2610BB4854251B3BAC0B5A1B3E | |||
91C1426D9A89AEBDC87F39822F6B331F | |||
0793894273CBC60A07F4CB45B5D7B040 | |||
058DED872952E779BB800F81A57A3995 | |||
E319252EA178D2F82ED01656E4BAD172 | |||
2802FE57C656A6F8BD01AD104ADBAF54 | |||
E5238F1ADD7AA48968F26F71F187A245 | |||
14E8C60112A803A4241F9E57E1F7AF6A | |||
D18DB03F4A0DCBB7A736EE3CE3876E2A | |||
46053A2A12B3088377CC5FE2392938EF | |||
8CB2497089F9F56EF18A21A2B16579E8 | |||
813C055D93BB8DF483C6786DE063E8F4 | |||
116C1CBBE2BCC48292999FF2ADD6507B | |||
6002E61EE9AB734B89B89EB26377A67E | |||
F18A3E1AAAEDABAA126E07E59C696503 | |||
8D3EB0F6FA3FB302E125E34FBFEF01E3 | |||
D6F599DA74515C72CD33DCD6444A4E9C | |||
FEA0F8DE75C7FCA523B4DC6695C30F4D | |||
711E50C91441BEEDFA92F4BB93014A77 | |||
6ED4CD9A0AD9EE1FE3DB222BB93F6D5F | |||
C35F0BFD48380C556778935DF1705E55 | |||
15E00783F98814E911842AE9FD45B122 | |||
A094EB80910643477FD5CFC60C62F2A4 | |||
10030732E31894420E473CFAA43EBA8B | |||
43596E6B06E6CD67BAD69D2943A67D44 | |||
9C9FEFE25732D09B7B993EA16372B71B | |||
EC06D570BEEC94C4CEE301A77504AD00 | |||
E7C9F8E2FEDB7DB4F2404EC4605958D0 | |||
5C799199EFBC7E483A85B7A774651B7B | |||
EC1107F3C35E5F9623CC1479FA2FCAB2 | |||
606C323790EC44B77748216E8E259973 | |||
62CD59F7DB176E40B012C6C252121237 | |||
451DAB82BCF376741B1F6D0530C58E30 | |||
F97CBFAF81C1D30B3D4476B82FAEC5AF | |||
8C79E83EFD53E7C40777D0FE4A2584C0 | |||
EEDA30D2E95EFF0D5E74B2D4A7A7FB9F | |||
B16DCD1FFA3D7A090E4040D74C2D7789 | |||
D2C2351634F11395BE1A2E3888048B5D | |||
3E97F9CA56CEF2970EF4D5B047A8BAE8 | |||
FFC67DFE1218C0FA1113C26CF15F7274 | |||
E5273ED1901FF8A9681B531A66575BDD | |||
1C6C8E6BF1FA894B3C67E490AD0478EC | |||
795EB5161BAA2FF99377ACC74BA7F7EF | |||
79E41D03E8B899E7B0DC3486F33220FD | |||
0D008B128F46648DD0311BF3798143C6 | |||
1F51C08D4A5A942821CE4EF84988B411 | |||
2739D8E6E7186D34084D126B6A4F459F | |||
BD09B5DD34EF00FBB611EB2D312191DB | |||
F4ABF13038833D5DA7327CD9290FFBCE | |||
6CA3F689882D225AE7C40957E9BAD7E2 | |||
0E2A4C20664A235F28386EBFF817D077 | |||
5FAD3151B8E39F3A8CA89A4178FC6520 | |||
F90E31956A64CEEF68285A391DBD96CD | |||
1E0FAEE2D027636E50804BC47D23B90A | |||
184193FD28E2EF1CE6F782146E595DB4 | |||
798FDFB8E03625709E9998A0D8EBFE32 | |||
6A9204919336D4DF3273CFD6A5B58CAC | |||
5C2542CC4B4D89757F010254DB01009B | |||
677DEFF2D7391FBB6DA67485CB88D76C | |||
FABBA7656625D0373C761E294082653E | |||
91689D9D9B271EF47170214BCA129392 | |||
B5DB30D1F4B77B1375A45A1BDC2A3A55 | |||
2559BD1455D42F1F13CCCF7C2500EFE3 | |||
2D963059504F0D69FF6BD30CD6A95C1C | |||
077C149C3A40062A49367B4033B2C80E | |||
36A64DE9AA5E01F5A37016D777396A85 | |||
04B7B3666CCAF1DC911F90C869B199EC | |||
149BCCED50B19EB32654457712996458 | |||
34418D27DE5915D074D6E3732A65918C | |||
4C1018AA486109C8B1A3335850FEF450 | |||
BBA43308D81208C27309549590A3FD02 | |||
33E686EF6C1299096D3F8A872196EC36 | |||
0107F6ECFB56299AB71116E775D04742 | |||
A12D9C23F00051AF37252C85D60DD347 | |||
606001E3846F3621E8E66CF444D2E20C | |||
01ED73AD810421D290D824F9F08EE9A2 | |||
3DDB41E084520E6073AE5F84926A000C | |||
B53B5B63E1A888F46556D1D916577084 | |||
9ADF52F1926B6C545CA959CE9800BFE8 | |||
6BFABF64AB5C04F3D41540303489B4FE | |||
CD978EDC1DB6DC5C1DA17BFF3AA8FED5 | |||
407D7336D8027087C553B1E3C15491A1 | |||
F83FC2615EF7F647DDB9E666DB49EFFD | |||
CBB08B1DC32773C6F52558C24F467341 | |||
04B0B70938D13314924D5E20FAFA62D7 | |||
85875F49ED6F1B39C7C1C7CB859856EB | |||
69213CB98BF7665F999FB87CBF7BF87F | |||
7D7006A2F42DF2B0A8DD7576F895A650 | |||
79BBD313309FAAEEA24C3A8D3BEC8ABA | |||
81C3B008BA13765FFC0EEB39D0AFE2CC | |||
71A56CE5AF79188CF70A048E41691F2D | |||
90DE0ABCC6B9CCA235C5C105EC77CD32 | |||
915DA02507F7CF4286C375B2E5EADD0E | |||
C01D272D6236D9FCD147F2A84651242F | |||
68333929DA8542489F9EA852F160D9D8 | |||
0D25112F5330F54AE188F9F69823E81E | |||
C8D96C49FBAE295252047BB6BFE5D175 | |||
502181DA177BFD8792E4E2205C2D689C | |||
511B792980A78E5F9C12461FC498EF1A | |||
B105A1A8133FFAA93B28B4BAC6604C84 | |||
196F5DE217D71579B9B58FA214FF52EA | |||
798B258258CBBC4CAA95C6189757ECED | |||
AC373D038B695AF368EE1294655A6F98 | |||
C30D291017300033BB5EB4E4703F2337 | |||
967D0F21ECD5A0FE1DC6782034B7AC34 | |||
8A0FEAADBC6AA28CB828EF5EC4CFE49C | |||
</pre> | |||
* Only first key is used | |||
=== | === Keyseed 0 (Proto) === | ||
<pre> | <pre> | ||
1EB25643234EF6EF380F9E57A216FA22 | |||
D835FF0508BEBBE97676FA478C29C21D | |||
</pre> | </pre> | ||
=== | * Encrypt AES256ECB into Slot 8 using slot 0x206 | ||
* Obtain PCK Layer Removal SLSK From NAND Key (128 Bit) | |||
=== Keyseed 1 (Proto) === | |||
<pre> | <pre> | ||
50976238EED23234F9C746CCB07D6D71 | |||
3F5BA67BC8C097DAE52D8512084683E7 | |||
</pre> | </pre> | ||
* Encrypt AES256ECB into Slot 9 using slot 0x207 | |||
* Obtain SLSK ENP DePersonalization Key (JigKick Only) (128bit) | |||
=== | === Keyseed 2 (Proto) === | ||
<pre> | <pre> | ||
4A41DEDEFFBAC04F52602D0034DAD666 | |||
164E3CF1FC23BE4F4D0F8471A7E60563 | |||
</pre> | |||
</pre> | |||
* Encrypt AES256ECB into Slot 0x20 with key 0x344 | |||
* Obtain SLSK HMAC-SHA256 Key | |||
=== SLSK KEY IVs === | |||
<pre> | |||
B07FEB18E422167AECDB60A8EE0CA427 Index 0 | |||
69425551E9AE3945F36873F110FDA6FB Index 1 | |||
1C48B1C8A599CD59C7AECF8E469830BE Index 2 | |||
7C598FB45BCF00A9F49E5AFAD3554754 Index 3 | |||
98E3F508D16EF78C8FAE96F4168F20A6 Index 4 | |||
766410AE5109F2201DDAE41FB07F6EF6 Index 5 | |||
</pre> | </pre> | ||
=== | === Auxiliary IVs === | ||
<pre> | <pre> | ||
0962939DC5BE560F52F6BB45B34CE097 | |||
D46CF82FC8BA5D5B6436F9F7E4E20434 | |||
EA574C6CB6B11505D5DA35446D187808 | |||
8F62AAEDBD4E025BE6E8FF8E7D654704 | |||
C898610BF8E6CCC12C9BA48414CC2BCF | |||
</pre> | </pre> | ||
* Used with other possible keys besides AA key (5 possibilities) | |||
* Never seen used | |||
== Second Loader == | |||
=== | === FallBack IDPS and PSID (CEM/DEM) === | ||
<pre> | <pre> | ||
fallback cem idps | |||
00 00 00 01 01 03 00 10 90 00 00 00 C8 B4 00 CD | |||
fallback cem psid | |||
C9 E5 91 3A FD 20 52 AA 4B 85 97 51 24 F7 59 A2 | |||
fallback dem idps | |||
00 00 00 01 01 00 00 01 00 00 00 01 88 25 9E 0E | |||
fallback dem psid | |||
71 CB BB DE 6B D4 1B 24 37 A3 6E BA 3E C3 6C 93 | |||
</pre> | </pre> | ||
* This seems to be used to derive decryption for the certificate from idstorage | === Jig Auth 5 Keys (SharedKeyB SharedDataB related) === | ||
<pre> | |||
1C7FD39E8D63AA32D386413EE6A01C15C4876BF614CA954E36C1602DD7871C4F KEY | |||
051DFE9D9BEA8087F66EB8F631010D88 IV | |||
</pre> | |||
=== SMI Modulus === | |||
<pre> | |||
C618BE3270E1553B2D08660C70000616 | |||
38388DB331BFF30E7DB6334EA8F8F7EB | |||
93540B6624465ABE2AFAF01ACF0B8705 | |||
1CBAE118769183B9EA9B09C225A063BA | |||
387A23452BBCDA2949C4ABA0C66A8D1D | |||
0A44A7AE22D1AC449C9EAC5ED79A18AC | |||
1B0691B3451673965ED336C9987EF5B4 | |||
2FA6DE995FFD319A629A5E2523164E3F | |||
B9C7BDE7025E839C3B528F53E5ABB077 | |||
776C80E1C7A15720CBEA770D7674C9CD | |||
C44559F0ED538DE33F79E9334C62AD81 | |||
114B23432D736A89CE7A53FECD50E66E | |||
021F9DCC2B635E33305FD5EA8F15656D | |||
2B00E93BBC78EE97B6BDDDF8EE218289 | |||
2D6A739CA1001AD8849F2F0A2550592A | |||
4DA15742BB712E07B7933B8BFE1F2AD1 | |||
</pre> | |||
=== SMI (Slot 0x213) === | |||
<pre> | |||
AB7097356FDD49D83878540167F0C4AD85537C5A56BD15DF0EB5F7F0D9E276E6 Seed First Derivation SMI | |||
310D20077AF3BF121F21D9ADAF389CDA IV First Derivation SMI | |||
2F0AEEF98EE3965650F8485E6C0BC2C4 IV First Decryption SMI | |||
D9A2CA7FD2E5AA65134CBF9ECF036F8AACE02A42D9187A08717C0255A13AB966 Seed Second Derivation SMI | |||
0F92B97AC4353337FD222A0E7E49EB58 IV Second Derivation SMI | |||
69D7618B7DBE7B59C04DEF5169831FBF IV Second Decryption SMI | |||
</pre> | |||
=== Other Keys/IVs === | |||
<pre> | |||
62FC3C4751B32657E71E89ECE4324BE3 (Internal) (Introduced in 0.920I, removed in 0.995I, qa flag related?) | |||
</pre> | |||
=== Secure Kernel XXX Proto Keys === | |||
* Algorithm is AES 256 CBC | |||
* IV is all zeroes | |||
==== External ==== | |||
<pre> | |||
992EF70868DE1B219EC3618FA79DAEC39067FE5638116C29FC0FF7E2A58FBD9E | |||
</pre> | |||
==== Internal ==== | |||
<pre> | |||
AC78EE86799148699B9CB3F5C6CAB73A6AC45EB11F44E9151232CF8F123C7D88 | |||
</pre> | |||
== GcAuthMgr == | |||
=== Master Key Seeds === | |||
As part of gc authentication, some keys are derived using these key seeds | |||
& 0x345 and 0x348 bbmac. | |||
different key seeds are used depending on the key id used by the gamecart. | |||
==== KeyID 0x1 ==== | |||
KEYSEED: | |||
<pre> | |||
7f1fd065dd2f40b3e26579a6390b616d | |||
</pre> | |||
IV: | |||
<pre> | |||
8b14c8a1e96f30a7f101a96a3033c55b | |||
</pre> | |||
==== KeyID 0x8001 ==== | |||
KEYSEED: | |||
<pre> | |||
6f2285ed463a6e57c5f3550ddcc81feb | |||
</pre> | |||
==== KeyID 0x8002 ==== | |||
KEYSEED: | |||
<pre> | |||
da9608b528825d6d13a7af1446b8ec08 | |||
</pre> | |||
==== KeyID 0x8003 ==== | |||
KEYSEED: | |||
<pre> | |||
368b2eb5437a821862a6c95596d8c135 | |||
</pre> | |||
=== Unknown GcAuthMgr Key and IV === | |||
<pre> | |||
821C5714415E9804D6AAE324EB3DDDFE7BB73E8EC0F9E04D3D6D60BCD0CF4EE9 | |||
</pre> | |||
<pre> | |||
CEC36FCD7DB3102A80E9C2AA65734FC1 | |||
</pre> | |||
== KPRX_AUTH == | |||
keys part of kprx_auth_sm | |||
=== Bind Data HMAC Key === | |||
used for ksceSblAuthMgrDecBindData | |||
<pre> | |||
901a84fb13a744a378c5018a60f58c22 | |||
</pre> | |||
HMAC-SHA256 using this key | |||
result is the key to aes-cbc-decrypt bind data | |||
first 0x10 is key, last 0x10 is iv. | |||
== AIMGR == | |||
* All these seem to be fallback keys in case keyslot 0 (aka pck0) fails to decrypt the idstorage enc_cmac located at cert + 0xD8 | |||
* algo used is aes-128-ecb-dec | |||
* used together with keyslot 0x212 for cmac | |||
<pre> | |||
7BB73E8EC0F9E04D3D6D60BCD0CF4EE9 | |||
CEC36FCD7DB3102A80E9C2AA65734FC1 | |||
89398ED8AE6FB3B0519485893AD0E5F3 | |||
33B90F7B250879F87DB269CFC4E7FB35 | |||
</pre> | |||
* This seems to be used to derive decryption for the certificate from idstorage | |||
* used with slot 0x204 (likely iv for aes-256 master key) | |||
<pre> | |||
821C5714415E9804D6AAE324EB3DDDFE | |||
</pre> | |||
=== PSN Keys === | |||
==== X-I-4-Passphrase ==== | |||
used to aes-128-cbc encrypt X-I-4-Passphrase header of PSN authentication request: | |||
- Version 1 (used until 3.63) | |||
<pre> | |||
EA35FA34B747929A540219DBA2DA001F | |||
</pre> | |||
- Version 2 (used 3.63 onwards) | |||
<pre> | |||
886073DE0511F0581792DC66FD6CA6AF | |||
</pre> | |||
notes: | |||
the IV is all 0 in both cases | |||
PSN will still accept a version 1 passphrase which is how henkaku psn spoof works | |||
==== X-I-4-Passphrase HMAC ==== | |||
used to generate the HMAC signature for X-I-4-Passphrase | |||
<pre> | |||
4D3E171CFB60DF96D1AFA6E76FEBFB5C079A5D177919C3EF417BAFA23A0B0DE2036624F0C87A8D3659DAE19E77195146B11A767D8A35A8610D301A79BBA9342D | |||
</pre> | |||
== Communication Processor == | |||
=== ES2 fsimage1.trf Pub === | |||
<pre> | |||
A9 69 7F 9D 93 43 CA DE 68 E0 4F 9E 35 6E 6A B6 | |||
BB C7 DE 36 A4 D8 1B 98 A8 3B C1 2B E3 F6 DF 96 | |||
ED 7A 64 38 94 56 AC A9 33 BE BF BA 4F FE F0 5C | |||
F4 5F 2F 88 6F 43 4F BB C3 A0 13 48 53 30 70 C0 | |||
B7 D5 E9 C2 1E FE 53 E9 5A 60 19 DB 51 C1 2C 6B | |||
AF EB 94 E9 92 28 79 63 44 8E 59 60 63 84 B9 9F | |||
3F F3 E5 EB 6A A0 8B F3 2A 4D BA 7A 31 25 20 CE | |||
C2 B6 9B B2 0A 6D 06 40 B1 17 17 0A A2 DD A1 FB | |||
59 0A EE 7A DF C4 E8 0D FC F2 7F A5 5D DE C9 2C | |||
07 92 2F DD 05 AB 16 18 DC B7 27 AA 6F F7 00 27 | |||
A9 41 0B C8 45 E5 0E AF D4 6C 0F D9 2F F5 00 67 | |||
2D E5 64 89 C6 69 B0 AA 48 1F FD 75 E9 9E 21 A8 | |||
DC 2F 9F 9E 87 95 7B 46 BB F6 3F B7 DD BE 8B 8C | |||
A8 61 BA 34 9A 62 45 8E 85 5E E7 8C 3D D6 79 1F | |||
92 E7 64 22 14 4E 51 29 5B 13 37 E1 5C 12 6D F6 | |||
FA 0C 29 32 1B C1 D7 C0 0E 3C 19 EE F3 A3 E7 A5 | |||
</pre> | |||
=== ES2 CPUP Pub === | |||
<pre> | |||
A7 CC AE 0F 50 11 88 52 7B F3 DA CC A3 E2 31 C8 | |||
D8 70 1E 7B 91 92 73 90 70 1D E5 E7 A9 63 27 DA | |||
D8 71 67 A8 F0 13 68 AD DF E4 90 E3 25 A2 90 53 | |||
36 97 05 8F BA 77 57 66 69 80 10 AF D8 FD 7A 3F | |||
FD 26 5E 0A 52 FE 04 92 8B CE 8B 43 02 F4 C7 0F | |||
FA C3 C9 39 7F D2 4B 10 62 71 E5 7B DA 20 D2 D7 | |||
02 29 8F 6F 99 0E CF 9B 0F E0 4F F6 CC EE 17 0B | |||
55 53 04 23 20 12 D7 8E 60 19 DA B2 97 63 82 9E | |||
6A F5 AD A8 02 20 4F A5 51 63 11 79 CB FE 61 64 | |||
73 26 62 E8 57 67 41 94 9B B1 36 45 6C 11 DE 35 | |||
5F 48 72 11 D2 30 26 7D C0 5E 69 9A 26 52 AD 5C | |||
6D 74 B0 56 83 26 F4 F2 F5 B8 6A D9 56 E9 44 04 | |||
D3 A6 59 28 F4 EA 21 89 56 7C E9 98 99 11 B0 48 | |||
08 51 7F 4C 76 A8 B2 5D F1 D6 AB BE 85 95 C4 69 | |||
BF D7 E8 70 C4 F0 0A 89 61 0C 2C 9B 79 F6 25 A4 | |||
2C A2 B4 C6 B8 D3 7E 62 CE 9E C6 1A 85 6F D3 2F | |||
</pre> | |||
=== NBL Configs === | |||
==== Key ==== | |||
<pre> | <pre> | ||
3C 97 EB 60 B2 06 80 E9 5E B7 00 13 11 96 5F AE | |||
</pre> | </pre> | ||
==== IV ==== | |||
<pre> | <pre> | ||
4D 8A C9 0A E0 B3 C1 30 46 31 A8 6D 56 32 02 70 | |||
</pre> | </pre> | ||
=== Deobfuscated blob === | |||
<pre> | <pre> | ||
4D 8A C9 0A E0 B3 C1 30 46 31 A8 6D 56 32 02 70 iv blob01 aes-128-cbc | |||
3C 97 EB 60 B2 06 80 E9 5E B7 00 13 11 96 5F AE key blob01 aes-128-cbc | |||
== | A9 69 7F 9D 93 43 CA DE 68 E0 4F 9E 35 6E 6A B6 fs1 rsa | ||
BB C7 DE 36 A4 D8 1B 98 A8 3B C1 2B E3 F6 DF 96 fs1 | |||
ED 7A 64 38 94 56 AC A9 33 BE BF BA 4F FE F0 5C fs1 | |||
F4 5F 2F 88 6F 43 4F BB C3 A0 13 48 53 30 70 C0 fs1 | |||
B7 D5 E9 C2 1E FE 53 E9 5A 60 19 DB 51 C1 2C 6B fs1 | |||
AF EB 94 E9 92 28 79 63 44 8E 59 60 63 84 B9 9F fs1 | |||
3F F3 E5 EB 6A A0 8B F3 2A 4D BA 7A 31 25 20 CE fs1 | |||
C2 B6 9B B2 0A 6D 06 40 B1 17 17 0A A2 DD A1 FB fs1 | |||
59 0A EE 7A DF C4 E8 0D FC F2 7F A5 5D DE C9 2C fs1 | |||
07 92 2F DD 05 AB 16 18 DC B7 27 AA 6F F7 00 27 fs1 | |||
A9 41 0B C8 45 E5 0E AF D4 6C 0F D9 2F F5 00 67 fs1 | |||
2D E5 64 89 C6 69 B0 AA 48 1F FD 75 E9 9E 21 A8 fs1 | |||
DC 2F 9F 9E 87 95 7B 46 BB F6 3F B7 DD BE 8B 8C fs1 | |||
A8 61 BA 34 9A 62 45 8E 85 5E E7 8C 3D D6 79 1F fs1 | |||
92 E7 64 22 14 4E 51 29 5B 13 37 E1 5C 12 6D F6 fs1 | |||
FA 0C 29 32 1B C1 D7 C0 0E 3C 19 EE F3 A3 E7 A5 fs1 rsa | |||
68 48 3F BB 69 F1 04 A3 CB 0A D8 18 7F 90 0B 12 | |||
89 6F F0 68 51 B5 51 CC 75 B9 C7 01 4D B1 8F A9 | |||
0A 82 27 97 B6 CC 1D C0 2B CD 68 8E 91 C6 22 64 | |||
1B F4 36 ED 32 2D D4 F0 D2 CD C1 7F 20 35 AA 0B | |||
F4 E0 8D 02 49 BF EE 25 52 90 AC E9 40 C4 69 27 | |||
E0 C9 DF 3D 3A A0 62 98 4E B6 D3 77 41 5C C4 09 | |||
3F B8 3E 20 28 65 2D 80 70 C5 25 4A CA 0B CA D0 | |||
A7 C3 3A DC 90 EF 6B 66 D2 CD F5 0B A3 CC A0 E2 | |||
29 9E 38 D2 76 11 66 B9 2C 28 7F 75 1F 94 FF 06 | |||
74 18 EA A9 D7 C9 EF 9A 26 3D 42 8C 23 33 0D 27 | |||
41 42 67 E7 DB BC A6 B7 07 F8 C3 3D 9F 06 B0 3E | |||
CB 45 3F A6 40 22 28 A4 0A 13 8A 49 68 F3 F0 72 | |||
94 EA D9 E8 55 37 CF 8D 43 AD AF EC 51 87 40 D4 | |||
D4 D5 A5 4B AE 14 27 7E FB 42 F9 C7 81 4E 1E E5 | |||
</pre> | |||
== Ernie == | |||
=== | === Security ID (RL78) === | ||
<pre> | <pre> | ||
00 00 00 00 00 00 00 00 00 00 (it's blank LMAO) | |||
</pre> | </pre> | ||
=== | === Ernie Update AES128CBC Key 0x10/0x30/0x31/0x40/0x41 (PHAT) === | ||
<pre> | <pre> | ||
key: 12B5408FD189E223B61890F488536008 | |||
iv : 82D6528A87BC55B38EF29A45730EF130 | |||
</pre> | </pre> | ||
* supports type 0 | |||
* for block size 0x400 ONLY (block size 0x800 not supported) | |||
=== | === Ernie Updater AES128CBC Key 0x10/0x30/0x31/0x40/0x41 (PHAT) === | ||
<pre> | <pre> | ||
key: EAE43A1C48CD32A565E2CA7D8F9018DC | |||
iv: C9D9619CA151342D04602ECF0B8D6E33 | |||
</pre> | </pre> | ||
=== | * supports type 0 | ||
* for block size 0x400 ONLY (block size 0x800 not supported) | |||
* for updater and confzz firmwares ONLY | |||
* location: around 0xFXXX of syscon firmware | |||
=== Ernie Update AES128CBC Key 0x60 (PHAT) === | |||
<pre> | <pre> | ||
key: 8C9ED3908C4143AE02855794C025BE1A | |||
iv : C85AE1576D5E205FE8043573F55F4E11 | |||
</pre> | </pre> | ||
=== | * supports type 0 | ||
* location: around 0xFXXX in syscon firmware | |||
=== Ernie Updater AES128CBC Key 0x60 (PHAT) === | |||
<pre> | <pre> | ||
key: 7014BEE6136725B9FFBE9A8614DD5C2A | |||
iv: FBD11DF2E0AAEE0B9C3738163CB8B6BD | |||
</pre> | |||
* supports type 0 | |||
* for updater and confzz firmwares ONLY | |||
=== Ernie Update AES128CBC Key 0x70/0x72 (PSTV) === | |||
<pre> | |||
key: 67C34253A7DE13517EC903FE1119C04C | |||
iv : DB302673D69F0D513A635E68A470F9C1 | |||
</pre> | </pre> | ||
* aka the key for the meaning of life, universe and everything else | |||
* supports type 6 and 7 | |||
=== | === Ernie Updater AES128CBC Key 0x70/0x72 (PSTV) === | ||
<pre> | <pre> | ||
key: BE01B7FA1EC3ED641879DDE44D60486E | |||
iv : 671A74C7E50F25CF64D4341039C78705 | |||
</pre> | </pre> | ||
=== Ernie Update AES128CBC Key | * aka the key for the meaning of life, universe and everything else | ||
* supports type 6 and 7 | |||
* for updater and confzz firmwares ONLY | |||
=== Ernie Update AES128CBC Key 0x80/0x82 (PS Vita SLIM) === | |||
<pre> | <pre> | ||
key: | key: 523BEB53FCB95DC772AA1BFB0A96CD10 | ||
iv : | iv : 385D67E50CE7669ECD171FE576814343 | ||
</pre> | </pre> | ||
* supports type | * supports type 5 and 8 | ||
=== Ernie Updater AES128CBC Key | === Ernie Updater AES128CBC Key 0x80/0x82 (PS Vita SLIM) === | ||
<pre> | <pre> | ||
key: | key: DBD9450ACCA8544895663A6F472BDE7F | ||
iv: | iv : F927C6A1153DB2D65F736C3AD9E1CE76 | ||
</pre> | </pre> | ||
* supports type | * supports type 5 and 8 | ||
* for updater and confzz firmwares ONLY | |||
* for updater and confzz firmwares ONLY | |||
=== | === SERVICE 0x900 PASSPHRASE === | ||
<pre> | |||
93CE8EBEDF7F69A96F35DDE3BECB97D5 | |||
</pre> | |||
=== BStoBSid Key === | |||
<pre> | <pre> | ||
46B532E3F012E663C0694ECA7C8C58B7 | |||
</pre> | </pre> | ||
=== First Loader Jig Handshake Key === | |||
Also known as g_debug_challenge_key. See [https://wiki.henkaku.xyz/vita/Enc#Secret_debug_mode]. | |||
AES256ECB Key: | |||
<pre> | <pre> | ||
F47716E6C5649FD648538FD9773D12D1 | |||
229E118737B1D782D6A80CDB72E4B9C3 | |||
</pre> | </pre> | ||
=== Supported Keysets by Ernie === | |||
=== Ernie | |||
<pre> | <pre> | ||
0, 1, 0xB, 0xE, 0xF | |||
</pre> | </pre> | ||
=== Ernie Handshake Keysets === | |||
These keysets are stored on each side (Ernie firmware and cMeP binaries). | |||
=== | ==== Keyset 0x0 ==== | ||
===== SharedData_0 ===== | |||
<pre> | <pre> | ||
80996FBBC8B4EBA30595F4D379A23BD0 | |||
</pre> | </pre> | ||
===== SharedKey_0_A ===== | |||
<pre> | |||
EF685D2E33C7D029A1A2EE646BE39D41 | |||
</pre> | |||
=== | |||
===== SharedKey_0_B ===== | |||
<pre> | <pre> | ||
CE7867DE57575C008D998281E8DA5912 | |||
</pre> | </pre> | ||
==== Keyset 0x1 ==== | |||
=== | |||
===== SharedData_1 ===== | |||
<pre> | <pre> | ||
8C20B6FABD2236F772AA283B8C82B13E | |||
</pre> | </pre> | ||
===== SharedKey_1_A ===== | |||
=== | |||
<pre> | <pre> | ||
87DC6ECFF1CA5D709B01AEF69EA6B283 | |||
</pre> | </pre> | ||
=== | ===== SharedKey_1_B ===== | ||
<pre> | <pre> | ||
51EB8DD39B0585CE915F3BFF609C9563 | |||
</pre> | </pre> | ||
=== | ==== Keyset 0xB (command 0xA0) ==== | ||
===== SharedKey_B_A ===== | |||
<pre> | |||
BB644721CB4C55072E83177BEB3BBEE9 (2F1C) | |||
</pre> | |||
Initial key to encrypt step 2 packet. | |||
===== SharedKey_B_B ===== | |||
<pre> | <pre> | ||
DC6B6EE0F457DF0E7BAD1C5EA338027F (2F2C) | |||
</pre> | </pre> | ||
Intermediate key used to decrypt Syscon step 3 response. | |||
Ernie communication session key AES128ECB master key: | |||
<pre> | <pre> | ||
00000000000000000000000000000000 | |||
</pre> | </pre> | ||
Unused with command 0xA0. | |||
=== | ===== SharedData_B ===== | ||
<pre> | |||
CF2E93E9F94E28CCA48026134C7C77CE (2F0C) | |||
</pre> | |||
Checked in Syscon only. | |||
==== Keyset 0xE ==== | |||
==== | ===== SharedData_E ===== | ||
<pre> | <pre> | ||
AD2F322F4256C49D1848818F0FDD81BE | |||
</pre> | </pre> | ||
===== | ===== SharedKey_E_A ===== | ||
<pre> | <pre> | ||
4ACE3A668AAEBB11793C432FB8A4CE88 | |||
</pre> | </pre> | ||
===== | ===== SharedKey_E_B ===== | ||
<pre> | <pre> | ||
1CBAE93DE883557C8AA14886786BE227 | |||
</pre> | </pre> | ||
==== Keyset | ==== Keyset 0xF (command 0xD0) ==== | ||
===== | ===== SharedKey_F_A ===== | ||
<pre> | <pre> | ||
50E4C3A77264167C409C72A9B57A8609 (2F5C) | |||
</pre> | </pre> | ||
Initial key to encrypt step 2 packet. | |||
===== | ===== SharedKey_F_B ===== | ||
<pre> | <pre> | ||
9E34087C48985B4B351A63572D9B481B (2F6C) | |||
</pre> | </pre> | ||
Intermediate key used to decrypt Syscon step 3 response. | |||
===== | ===== SharedKey_F_Master ===== | ||
<pre> | <pre> | ||
EBE3460D84A41754AC441368CF0200D8 (2F7C) | |||
</pre> | </pre> | ||
Master key to generate Ernie communication session key (stored in Bigmac keyslot 0x511) by encrypting step 2 data. | |||
==== | ===== SharedData_F ===== | ||
<pre> | <pre> | ||
C86B51FB019A207F32118E55462D5008 (2F3C) | |||
</pre> | </pre> | ||
Checked by Syscon only. | |||
Step 4-5 passphrase: | |||
<pre> | <pre> | ||
B01103B0623832D62540B56333D6E11D (2F4C) | |||
</pre> | </pre> | ||
Checked by both Syscon (step 4) and cMeP (step 5) to ensure packet authenticity. | |||
Ernie | === All not known Ernie-embedded Keys === | ||
<pre> | <pre> | ||
DB D9 45 0A CC A8 54 48 95 66 3A 6F 47 2B DE 7F 21C44(USS-1002) AES KEY | |||
F9 27 C6 A1 15 3D B2 D6 5F 73 6C 3A D9 E1 CE 76 21C44(USS-1002) AES IV | |||
</pre> | </pre> | ||
=== | === JigKick Key Expansion === | ||
<pre> | <pre> | ||
$ ./aes_keyschedule.exe F47716E6C5649FD648538FD9773D12D1229E118737B1D782D6A80CD | |||
</pre> | B72E4B9C3 | ||
K00: F47716E6C5649FD648538FD9773D12D1 | |||
K01: 229E118737B1D782D6A80CDB72E4B9C3 | |||
K02: 9C2138A65945A770111628A9662B3A78 | |||
K03: 116F913B26DE46B9F0764A628292F3A1 | |||
K04: D12C0AB58869ADC5997F856CFF54BF14 | |||
K05: 074F99C12191DF78D1E7951A537566BB | |||
K06: 481FE058C0764D9D5909C8F1A65D77E5 | |||
K07: 23036C180292B360D375267A800040C1 | |||
K08: 23169895E360D508BA691DF91C346A1C | |||
K09: BF1B6E84BD89DDE46EFCFB9EEEFCBB5F | |||
K10: 83FC57BD609C82B5DAF59F4CC6C1F550 | |||
K11: 0B6388D7B6EA5533D816AEAD36EA15F2 | |||
K12: 24A5DEB844395C0D9ECCC341580D3611 | |||
K13: 61B48D55D75ED8660F4876CB39A26339 | |||
K14: 5E5ECCAA1A6790A784AB53E6DCA665F7 | |||
</pre> | |||
* Some keys are repeated in the Ernie memory dump, as it seems Ernie stores many versions of code binaries. Maybe backup bank or updater. | |||
== | == Ernie Handshake Keys (not stored in Ernie) == | ||
These keysets are stored in second_loader and in many SMs. | |||
=== Keyset 4 === | |||
Step 2 AES128ECB key: | |||
<pre> | <pre> | ||
A6CD383341CB9B0D69FD4A243E30F4B1 | |||
</pre> | </pre> | ||
Initial key to encrypt step 2 packet. | Initial key to encrypt step 2 packet. | ||
Step 3 AES128ECB key: | |||
<pre> | <pre> | ||
D3EFEDE608691946CB77E14F8DEC69FA | |||
</pre> | </pre> | ||
Intermediate key used to decrypt Syscon step 3 response. | Intermediate key used to decrypt Syscon step 3 response. | ||
Ernie communication session key AES128ECB master key: | |||
<pre> | <pre> | ||
15C7B32429F8603216F4F3E081D7C86D | |||
</pre> | </pre> | ||
Master key to generate Ernie communication session key (stored in Bigmac keyslot 0x511) by encrypting step 2 data. | Master key to generate Ernie communication session key (stored in Bigmac keyslot 0x511) by encrypting step 2 data. | ||
Step 2 passphrase: | |||
<pre> | <pre> | ||
9ABD1B275C7537F7E62AB93AB3EB76F9 | |||
</pre> | </pre> | ||
Checked by Syscon only. | Checked by Syscon only. | ||
Line 1,274: | Line 1,494: | ||
Step 4-5 passphrase: | Step 4-5 passphrase: | ||
<pre> | <pre> | ||
DC454ED5F6E8A2B1B24D34A82215B2A5 | |||
</pre> | </pre> | ||
Checked by both Syscon (step 4) and cMeP (step 5) to ensure packet authenticity. | Checked by both Syscon (step 4) and cMeP (step 5) to ensure packet authenticity. | ||
=== | === Keyset 6 === | ||
Step 2 AES128ECB key: | |||
<pre> | <pre> | ||
1053143BEAECC59FCFF1A195F8F5AFB0 | |||
</pre> | </pre> | ||
Initial key to encrypt step 2 packet. | |||
Step 3 AES128ECB key: | |||
<pre> | <pre> | ||
F90CDCBF009BA8367F841B25E8B10306 | |||
</pre> | </pre> | ||
Intermediate key used to decrypt Syscon step 3 response. | |||
Ernie communication session key AES128ECB master key: | |||
<pre> | |||
6F6374FD1A41A75269EE15832451DEBF | |||
Ernie communication session key AES128ECB master key: | |||
<pre> | |||
</pre> | </pre> | ||
Master key to generate Ernie communication session key (stored in Bigmac keyslot 0x511) by encrypting step 2 data. | Master key to generate Ernie communication session key (stored in Bigmac keyslot 0x511) by encrypting step 2 data. | ||
Line 1,335: | Line 1,520: | ||
Step 2 passphrase: | Step 2 passphrase: | ||
<pre> | <pre> | ||
B6806F9F58706D72B0E03717197D430C | |||
</pre> | </pre> | ||
Checked by Syscon only. | Checked by Syscon only. | ||
Line 1,341: | Line 1,526: | ||
Step 4-5 passphrase: | Step 4-5 passphrase: | ||
<pre> | <pre> | ||
0E08A20C8718BD3B158E2E6992202DE7 | |||
</pre> | </pre> | ||
Checked by both Syscon (step 4) and cMeP (step 5) to ensure packet authenticity. | Checked by both Syscon (step 4) and cMeP (step 5) to ensure packet authenticity. | ||
=== Keyset | === Keyset 0xC (AuthEtoI, similar to command 0xA0) === | ||
Step 2 AES128ECB key: | Step 2 AES128ECB key: | ||
<pre> | <pre> | ||
3CF54027DAE2F45C929B76927DFFD269 | |||
</pre> | </pre> | ||
Initial key to encrypt step 2 packet. | Initial key to encrypt step 2 packet. | ||
Line 1,355: | Line 1,540: | ||
Step 3 AES128ECB key: | Step 3 AES128ECB key: | ||
<pre> | <pre> | ||
39AF55239062D2F3F6CBB401EDC54C09 | |||
</pre> | </pre> | ||
Intermediate key used to decrypt Syscon step 3 response. | Intermediate key used to decrypt Syscon step 3 response. | ||
Line 1,361: | Line 1,546: | ||
Ernie communication session key AES128ECB master key: | Ernie communication session key AES128ECB master key: | ||
<pre> | <pre> | ||
00000000000000000000000000000000 | |||
</pre> | </pre> | ||
Unused with command AuthEtoI. | |||
Step 2 passphrase: | Step 2 passphrase: | ||
<pre> | <pre> | ||
4231FFB14B941DBFEB44DFF97E64EC7D | |||
4231FFB14B941DBFEB44DFF97E64EC7D | |||
</pre> | </pre> | ||
Checked in Syscon only. | Checked in Syscon only. | ||
Line 1,757: | Line 1,910: | ||
kirk7_keyC3 = 1E5B17DAC321E6B8DFE7718CA2930370 | kirk7_keyC3 = 1E5B17DAC321E6B8DFE7718CA2930370 | ||
</pre> | </pre> | ||
== IdStorage Keys == | |||
=== PS Vita IdStorage leaves 0-0x7D RSA2048 Public Key === | |||
<pre> | |||
E9 18 F0 8E F8 D1 ED 4A 5E 80 65 44 15 5D AF 3E | |||
99 CD 65 65 5C 5D FE BC BA 59 A4 AB 52 81 63 53 | |||
B1 DC 9C 0E BB 70 F7 48 57 47 9C 4C 49 00 8E E4 | |||
F7 55 93 14 71 67 DF 9C 92 8E D8 42 4A 10 75 50 | |||
D0 9F 6A 48 57 9A E3 86 BF 6B A3 0C 73 57 00 DC | |||
F7 CB 2B B3 7C 03 11 CC EC D9 0F BA A1 2E E5 EE | |||
5C D3 10 D5 0F 1D 58 C1 23 8B CD 7B 9E E6 2C 7F | |||
4C AE 11 01 8C A5 AE F0 D5 C2 8D 5E E9 F6 6F 1E | |||
37 8B B4 BD BC C0 2F 3D 3D 6E F8 E6 35 EF B6 C2 | |||
EF 82 ED AD 07 16 5A 4D A4 AB 83 76 14 9D 6F 29 | |||
6D AD DA 83 CF 0D F3 9F 9C 6B AC 79 61 B6 6F 32 | |||
60 34 99 B4 C3 9C 94 D7 1A 29 8A B4 12 D8 42 F9 | |||
69 C3 0E 47 EF 86 FD 35 E5 CD 23 E8 95 B3 E1 A3 | |||
D6 E9 CA 90 8F 46 59 FE BC B3 00 C0 9C E7 34 07 | |||
5A 7F 85 2A 5B AD 82 B8 52 85 74 6F 73 45 C2 5F | |||
4B 7A 8D 85 70 8B 6C FD AA 59 70 BF 33 00 79 D5 | |||
</pre> | |||
* Exponent is 65537. | |||
* Found in PS Vita factTest.self. | |||
* Signature is stored in PS Vita IdStorage leaf 0x7E offset 0x60. | |||
* PSP IdStorage does not have this signature. | |||
* This signature does not seem to be checked on console boot. It might be used only during manufacturing/servicing to ensure that IdStorage leaves 0-0x7D have been written correctly. This implies that IdStorage leaves 0-0x7D are not meant to be edited after manufacturing, contrarly to some other leaves. | |||
== IdStorage Certificate Keys == | == IdStorage Certificate Keys == | ||
Line 1,888: | Line 2,070: | ||
== PSM Keys == | == PSM Keys == | ||
=== | === Update HMAC Key === | ||
5AE4E16B214290E14366E5B653C4E3C3E69E4956510EADD66ACB37A077E0686E | |||
086F8BAB5030E3D82407F01B676CB8037DF20D1420C08A91A2141A3FE5DC063C | |||
how to calculate update URL: | |||
HmacSha1("NPPA00236_00", hmackey) => 87b2fc0108d5197ae7572bda397dd8a81b56839e | |||
append first 8 characters of hex encoded hmac; like such: "NPPA00236_00_87B2FC01" | |||
update xml is => http://psm-pkg.np.dl.playstation.net/psm/np/NPPA/NPPA00236_00_87B2FC01/version.xml | |||
you can get the PKG for any PSM application like so: | |||
take "appVersion" from version.xml => "1.00" | |||
build PKG link using version => http://psm-pkg.np.dl.playstation.net/psm/np/NPPA/NPPA00236_00_87B2FC01/1.00/NPPA00236_00.pkg | |||
=== | you can also get screenshots and description of the application; using /metadata.xml; for example; | ||
http://psm-pkg.np.dl.playstation.net/psm/np/NPPA/NPPA00236_00_87B2FC01/1.00/metadata.xml | |||
(note; you have to change the domain to zeus.dl.playstation.net as sony removed the "psm-pkg.np.dl.playstation.net" subdomain awhile ago) | |||
=== 'psm.pub' strong name public key === | |||
Used for verifying strong name signature of runtime's Mono/.NET assemblies; | |||
00240000048000009400000006020000002400005253413100040000110000009133D396CA929938BC68440B541D8888614E7BD475B | |||
EF719AB4F4B85B1C21FC3EF2B5F32DF0DE7C769CA90687650DA49EEBE7ADCB71479F1463E10902CB65A1F44FA2E71B3F30E108FE0F6 | |||
699D179DAED5B1A774DB1ABA104C59118544B47CDA724AEA8E6899FA760DFE0BA8656515B48AE94FDE29FC8F5BD569126C7A9AE6F3 | |||
=== PSM Developer Assistant === | |||
Keys used in the PlayStation Mobile Development Assistant and PlayStation Mobile Development Assistant for Unity applications | |||
==== "protected_kconsole_cache.dat" HMAC Key ==== | |||
B73966320E286ADC03F05465CA9E2F92388AEE236D43883135BAB0A5BD5043EA | B73966320E286ADC03F05465CA9E2F92388AEE236D43883135BAB0A5BD5043EA | ||
=== | ==== "NSXVID-PSS.VT.WW-GLOBAL.xml" RSA Private ==== | ||
-----BEGIN PRIVATE KEY----- | -----BEGIN PRIVATE KEY----- | ||
Line 1,942: | Line 2,142: | ||
* Used by the PSM Dev Assistant to sign the NSXVID-PSS.VT.WW-GLOBAL.xml file to prevent from modification. | * Used by the PSM Dev Assistant to sign the NSXVID-PSS.VT.WW-GLOBAL.xml file to prevent from modification. | ||
=== | ==== Publishing License PKCS12 Import Password ==== | ||
password | password | ||
=== | ==== Publishing License PKCS12 PEM Pass Phrase ==== | ||
password | password | ||
* PKCS12 certificate used in signing PSM Dev PSSE with PSM SDK. | * PKCS12 certificate used in signing PSM Dev PSSE with PSM SDK. | ||
(World's most secure passwords ever, impossible to crack) | |||
You can use openssl like so: | You can use openssl like so: | ||
openssl pkcs12 -in <filename> -password pass:password -passout pass:password | openssl pkcs12 -in <filename> -password pass:password -passout pass:password | ||
to view the | to view the private and public keys of a PSM Publishing license. | ||
=== | === PSM Android === | ||
These keys are labeled within the debug symbols of the Android version of PSM. | |||
=== SCE_PSM_KDBG_ACCOUNT_KEY === | ==== SCE_PSM_KDBG_ACCOUNT_KEY ==== | ||
965895DF95F5432CCBCC4B7823CBF4B3 | 965895DF95F5432CCBCC4B7823CBF4B3 | ||
=== SCE_PSM_KDBG_ACCOUNT_IV === | ==== SCE_PSM_KDBG_ACCOUNT_IV ==== | ||
00000000000000000000000000000000 | 00000000000000000000000000000000 | ||
=== SCE_PSM_KDBG_C1_KEY === | ==== SCE_PSM_KDBG_C1_KEY ==== | ||
965895DF95F5432CCBCC4B7823CBF4B3 | 965895DF95F5432CCBCC4B7823CBF4B3 | ||
=== SCE_PSM_KDBG_C1_IV === | ==== SCE_PSM_KDBG_C1_IV ==== | ||
00000000000000000000000000000000 | 00000000000000000000000000000000 | ||
=== SCE_PSM_KDBG_CONSOLE_KEY === | ==== SCE_PSM_KDBG_CONSOLE_KEY ==== | ||
8235EDC66CD14D04F793369A74C7A4FE | 8235EDC66CD14D04F793369A74C7A4FE | ||
=== SCE_PSM_KDBG_CONSOLE_IV === | ==== SCE_PSM_KDBG_CONSOLE_IV ==== | ||
00000000000000000000000000000000 | 00000000000000000000000000000000 | ||
=== SCE_PSM_KDBG_LOGINFO_KEY === | ==== SCE_PSM_KDBG_LOGINFO_KEY ==== | ||
B293993BB5977F88844A7D21DDF63BC7 | B293993BB5977F88844A7D21DDF63BC7 | ||
=== SCE_PSM_KDBG_LOGINFO_IV === | ==== SCE_PSM_KDBG_LOGINFO_IV ==== | ||
00000000000000000000000000000000 | 00000000000000000000000000000000 | ||
=== SCE_PSM_KDBG_V1_KEY === | ==== SCE_PSM_KDBG_V1_KEY ==== | ||
14E5A03B1E62D483F88769986EDB1140 | 14E5A03B1E62D483F88769986EDB1140 | ||
=== SCE_PSM_KDBG_V1_IV === | ==== SCE_PSM_KDBG_V1_IV ==== | ||
00000000000000000000000000000000 | 00000000000000000000000000000000 | ||
=== SCE_PSM_HEADER_SIGNATURE_PUB_KEY === | ==== SCE_PSM_HEADER_SIGNATURE_PUB_KEY ==== | ||
3082010A0282010100A98F6B27F5AFF0F96C7411A337DFCF723C37BEF6FF6552B | 3082010A0282010100A98F6B27F5AFF0F96C7411A337DFCF723C37BEF6FF6552B | ||
Line 2,014: | Line 2,212: | ||
F2EE34F88702030100010000 | F2EE34F88702030100010000 | ||
=== SCE_PSM_WHOLE_SIGNATURE_PUB_KEY === | ==== SCE_PSM_WHOLE_SIGNATURE_PUB_KEY ==== | ||
3082010A0282010100D452C18752BDE6289ACEB862AD32145322C13EEC82F5675 | 3082010A0282010100D452C18752BDE6289ACEB862AD32145322C13EEC82F5675 | ||
Line 2,026: | Line 2,224: | ||
655F4CDE0F02030100010000 | 655F4CDE0F02030100010000 | ||
=== internalKey (KeyStore) === | ==== internalKey (KeyStore) ==== | ||
534B4257020000000000000010000000002F27E9ECD4606C3CE0BCFE99E2AE5EB | 534B4257020000000000000010000000002F27E9ECD4606C3CE0BCFE99E2AE5EB | ||
Line 2,034: | Line 2,232: | ||
E83746A9819C60AB7ED23B8D7685612A831C41000000 | E83746A9819C60AB7ED23B8D7685612A831C41000000 | ||
=== internalIcvKey (KeyStore) === | ==== internalIcvKey (KeyStore) ==== | ||
534B4257020000000000000010000000002F27E9ECD4606C3CE0BCFE99E2AE5EB | 534B4257020000000000000010000000002F27E9ECD4606C3CE0BCFE99E2AE5EB | ||
Line 2,041: | Line 2,239: | ||
C026F69D7A98767567BF04C95074B4C00000000000000000000000000000000BB | C026F69D7A98767567BF04C95074B4C00000000000000000000000000000000BB | ||
6E2E9E14AB8D04309918ABD4186B5798F48C78000000 | 6E2E9E14AB8D04309918ABD4186B5798F48C78000000 | ||
=== PSSE (PlayStation Suite Encryption) === | |||
PSSE is the encryption of PSM application files, | |||
the whole game is encrypted and it server a similar function as PFS for the PSVita. | |||
=== | ==== Header IV ==== | ||
000102030405060708090A0B0C0D0E0F | 000102030405060708090A0B0C0D0E0F | ||
=== | ==== Header Key ==== | ||
4E298B40F531F469D21F75B133C307BE | 4E298B40F531F469D21F75B133C307BE | ||
=== | ==== App Key ==== | ||
For decrypting PSSE files with IP9100-NPXS10074_00-0000000000000000 as content id | For decrypting PSSE files with IP9100-NPXS10074_00-0000000000000000 as content id | ||
A8693C4DF0AEEDBC9ABFD8213692912D | A8693C4DF0AEEDBC9ABFD8213692912D | ||
=== Debug | ==== Debug Header Key ==== | ||
When you encrypt files locally for use in PSM Dev Assistant, using PSM SDK's "psm_encryptor64.dll" | When you encrypt files locally for use in PSM Dev Assistant, using PSM SDK's "psm_encryptor64.dll" | ||
the following header key is used INSTEAD of the retail one. | the following header key is used INSTEAD of the retail one. | ||
00112233445566778899AABBCCDDEEFF | 00112233445566778899AABBCCDDEEFF | ||
=== Hash Account ID === | |||
used for calculating "Unique ID" in | |||
Sce.PlayStation.Core.Services.AccountInformation.UniqueID | |||
==== Hash Account ID HMAC-SHA256 key ==== | |||
BDEE3E0B93073749856F25CCDB443AFB0FAB94287493DC1AD0C5697E2A7AE14E | |||
==== Hash Account ID AES-128-CBC Key ==== | |||
5AA3DB8FE6AEE26CD185B086F5BD78A4 | |||
==== Hash Account ID AES-128-CBC Iv ==== | |||
00000000000000000000000000000000 | |||
How to calculate UniqueID: | |||
get psn accountid; => 0123456789abcdef (example) | |||
sha256hmac(accountid, hmackey) => 4653ec6275f410c47d280a3688a554a579a7e7c9f52599381ae9ee4a1b6220e3 | |||
trim hmac to first 8 bytes => 4653ec6275f410c4 | |||
append trimmed hmac to accountid => 0123456789abcdef4653ec6275f410c4 | |||
aes128cbc(accountid + trimhmac, key, iv) => c7656d883573d94809c8fa05f511d84f | |||
so "c7656d883573d94809c8fa05f511d84f" is the "UniqueID" | |||
== EncDec Keys == | == EncDec Keys == | ||
Line 3,089: | Line 3,316: | ||
! Type !! Version !! Modulus !! Usage || Notes | ! Type !! Version !! Modulus !! Usage || Notes | ||
|- | |- | ||
| 0 and 1 || 1.00+ || | | 0 and 1 || 1.00+ || | ||
9CCCE3A536FA641B2D1354EE98F093C2 | 9CCCE3A536FA641B2D1354EE98F093C2 | ||
68470F722C024B86CD60274E08E0067A | 68470F722C024B86CD60274E08E0067A | ||
Line 3,173: | Line 3,400: | ||
! Type !! Version !! Modulus !! Usage || Notes | ! Type !! Version !! Modulus !! Usage || Notes | ||
|- | |- | ||
| PSP || 1.00+ || | | PSP || 1.00+ || | ||
BBDB6AA32E3B51A6D4708D5FC9899919 | BBDB6AA32E3B51A6D4708D5FC9899919 | ||
395A2AAD83E98F4864C3BA43A5D6906F | 395A2AAD83E98F4864C3BA43A5D6906F | ||
Line 3,245: | Line 3,472: | ||
== NID generation suffixes == | == NID generation suffixes == | ||
* | * The algorithm is sha1(name + suffix). | ||
=== No suffix === | === No suffix === | ||
Line 3,251: | Line 3,478: | ||
For some PSP and PS Vita old NIDs, there was no suffix at all: algo was simply sha1(name). | For some PSP and PS Vita old NIDs, there was no suffix at all: algo was simply sha1(name). | ||
=== PS3 NONAME | === PS3 NONAME suffix === | ||
<pre> | <pre>"0xbc5eba9e042504905b64274994d9c41f"</pre> | ||
* Note that this ASCII string is used but not the hexadecimal value for it. | |||
=== PS3 default suffix === | === PS3 default suffix === | ||
Line 3,261: | Line 3,488: | ||
<pre>6759659904250490566427499489741A</pre> | <pre>6759659904250490566427499489741A</pre> | ||
=== PS Vita NONAME | * Note that this hexadecimal value is used but not the ASCII string for it. | ||
=== PS Vita NONAME suffix === | |||
<pre>c1b886af5c31846467e7ba5e2cffd64a</pre> | <pre>c1b886af5c31846467e7ba5e2cffd64a</pre> | ||
* Note that this hexadecimal value is used but not the ASCII string for it. | |||
== SceKrm == | == SceKrm == |
Latest revision as of 20:10, 10 August 2024
Useful Information[edit | edit source]
Location[edit | edit source]
For deroad's scetool, keyfiles should be placed in ~/.vita
or %userprofile%\vitakeys
.
Naming Conventions[edit | edit source]
naming:
- file prefix: pkg
- file suffix: 092 103 105 106 150 151... etc.
- key file (erk): %s-key-%s
- iv file (riv): %s-iv-%s
- ctype file (curvetype): %s-ctype-%s
- pub file (public): %s-pub-%s
- priv file (private): %s-priv-%s
Per-console keys[edit | edit source]
See Kirk documentation for usage of PSP-related individual seeds.
Cmep Keyring 0x600 - Visible ID (Test Subject 9 PS Vita)[edit | edit source]
00 00 01 01 AC 72 45 00 F5 68 96 03 80 57 C8 1A 25 99 21 A1 73 A4 89 F2 E9 96 23 E9 86 0F 74 2D
- Contains the console's Visible ID.
Cmep Keyring 0x601 - ScePspIndividualKeyMeshCert first half (Test Subject 9 PS Vita)[edit | edit source]
- Contains the first half (0x20 bytes) of of the console's ScePspIndividualKeyMeshCert.
- Warning: the dump presented here is byte-swapped.
B9 18 4E 22 83 8B 91 6D 19 86 72 D5 FB 10 FD A3 <- byte-swapped key_mesh.derivation_seed_1 4A 4E 72 CB 02 6E 96 E9 96 B2 C3 23 B9 CF 36 A4 <- byte-swapped key_mesh.derivation_seed_0
Cmep Keyring 0x602 - ScePspIndividualKeyMeshCert second half (Test Subject 9 PS Vita)[edit | edit source]
- Contains the second half (0x20 bytes) of the console's ScePspIndividualKeyMeshCert.
- Warning: the dump presented here is byte-swapped.
85 4B 14 AB 00 00 00 00 00 45 72 AC 01 01 08 10 <- byte-swapped hash, byte-swapped reserved, byte-swapped fuse_id FF 9A 3E E5 A2 B9 F5 25 32 4D E0 2A 8F B1 8F B9 <- byte-swapped key_mesh.derivation_key
ScePspIndividualKeyMeshCert (Test Subject 9 PS Vita)[edit | edit source]
- By byte-swapping keyrings 0x601 and 0x602 or by taking Fuse ID only and running the ScePspIndividualKeyMeshCert generation algorithm (see PSP Jig Kick flashData.prx), we can obtain ScePspIndividualKeyMeshCert.
A4 36 CF B9 23 C3 B2 96 E9 96 6E 02 CB 72 4E 4A <- key_mesh.derivation_seed_0 A3 FD 10 FB D5 72 86 19 6D 91 8B 83 22 4E 18 B9 <- key_mesh.derivation_seed_1 B9 8F B1 8F 2A E0 4D 32 25 F5 B9 A2 E5 3E 9A FF <- key_mesh.derivation_key 10 08 01 01 AC 72 45 00 00 00 00 00 AB 14 4B 85 <- fuse_id, reserved, hash
SUPER KEYS (Dumped by SDBoot glitching)[edit | edit source]
Perconsole Keyslot 0x8 (Test Subject 6)[edit | edit source]
D9022A0C0D9DC52A55A162EA23F50A65
Perconsole Keyslot 0x8 (Test Subject 7)[edit | edit source]
A193E1DD073BECDF6720D0616A8E815D
Perconsole Keyslot 0x8 (Test Subject 8)[edit | edit source]
80D71F18E0A3F393236AE1E875AE3EF8
Perconsole Keyslot 0x9 (Test Subject 6)[edit | edit source]
4B0F736E9A1FD865B125B05BC3641EC9
Perconsole Keyslot 0x9 (Test Subject 7)[edit | edit source]
C310134A5F5D825AC5E0BB838BA3E287
Perconsole Keyslot 0x9 (Test Subject 8)[edit | edit source]
04937A014699DA528E6B0CF7ECCADB78
Static Keyslot 0x605[edit | edit source]
3B 39 E9 2E 25 B0 40 38 27 EE 32 D7 D6 49 A8 47 D7 F1 1E 24 D0 11 76 0A 79 43 37 D4 F7 40 C9 DF
- Universal
Perconsole Keyslot 0x606 (Test Subject 5)[edit | edit source]
5E 75 05 CD A7 40 E8 5D 7F 82 B7 EA EA 32 CE 1C 66 04 2C E9 E6 B6 F4 F1 DC AA 94 A1 06 B8 32 EF
Perconsole Keyslot 0x606 (Test Subject 6)[edit | edit source]
DD DF C7 61 C7 7F AE 89 CF 39 6F BC 30 CF 7F 60 F8 BF BC 24 E1 3F 5A CE 46 50 BC 66 2F 73 AC D4
Perconsole Keyslot 0x606 (Test Subject 7)[edit | edit source]
72 39 DE 10 B7 F1 92 D5 78 E1 03 81 63 7F CF CF D4 44 9B 58 A1 7C 97 E5 EC F6 1D 09 40 82 7B B2
Perconsole Keyslot 0x606 (Test Subject 8)[edit | edit source]
98 AF 08 AD B7 8A E2 83 0A 31 47 0A FD 00 B2 64 D4 E2 C5 83 E2 14 EB 57 F9 58 CD 54 C4 BA 09 4C
Perconsole Keyslot 0x607 (Test Subject 5)[edit | edit source]
F5 B1 8E B5 37 DD C4 6F 6B 59 A4 19 AD AB F4 A8 52 02 9A 0E 50 E4 FC 3F F0 93 88 EA E3 34 C7 E3
Perconsole Keyslot 0x607 (Test Subject 6)[edit | edit source]
FA 87 A5 75 15 B2 88 60 57 5E 2C 2D 45 7F BA 86 55 32 A9 74 96 BF D5 B9 E8 D4 CE D7 98 19 40 97
Perconsole Keyslot 0x607 (Test Subject 7)[edit | edit source]
7E EE 37 A4 C0 DA C7 D2 0A AA 5E DA 34 17 B4 5C 45 A8 DA 4E FD 40 7D 9D E5 08 53 B4 9A 06 29 43
Perconsole Keyslot 0x607 (Test Subject 8)[edit | edit source]
6E 1E 68 77 A7 1D 05 8B 97 55 F6 9D 2E 2A 24 1C 4A 3D B7 E4 3B E8 F0 65 FA A0 8C 20 58 89 3F F2
Keys[edit | edit source]
Bootrom[edit | edit source]
Personalization removal Key for SLSK (Proto) (Perconsole) (Slot 8) (Test Subject 0)[edit | edit source]
85C688C1B3BACB16EB57B4CC35B7D590
- decrypts the .enp (not ._enp!) perconsole layer of an enp file, turning it into an enc file
- algo is aes-128-cbc
Personalization removal Key for SLSK (Proto) (Perconsole) (Slot 8) (Test Subject 1)[edit | edit source]
8B5415DC7EB5986472BF6B30D8E3E812
Personalization removal Key for SLSK (Proto) (Perconsole) (Slot 8) (Test Subject 2)[edit | edit source]
95B7B3EDB2EF277FB0F78FA3970EE0D0
Personalization removal Key for SLSK (Proto) (Perconsole) (Slot 8) (Test Subject 3)[edit | edit source]
CB0B65F7897F30310471F7CDA2CFD804
Personalization removal Key for SLSK (Proto) (Perconsole) (Slot 8) (Test Subject 4)[edit | edit source]
F3E408E1EDC3B513277DB99E58A15BE3
Personalization removal IV for SLSK (Proto) (Perconsole) (Slot 8)[edit | edit source]
FD4FA8FA4FE79430A0CA305C88E524DD
Personalization removal KEY for SLSK (Proto) (Perconsole) (Slot 9) (JigKick) (Test Subject 0)[edit | edit source]
9E0A8285C3BE83951C78480A7AEC80FD
Personalization removal KEY for SLSK (Proto) (Perconsole) (Slot 9) (JigKick) (Test Subject 1)[edit | edit source]
686268A876650A6A6DC353F69EB82F19
Personalization removal KEY for SLSK (Proto) (Perconsole) (Slot 9) (JigKick) (Test Subject 2)[edit | edit source]
E7A8ADF7B7E2BC26E3445084384FBCE1
Personalization removal KEY for SLSK (Proto) (Perconsole) (Slot 9) (JigKick) (Test Subject 3)[edit | edit source]
736F7501E9A15AB29800113686C946BA
Personalization removal KEY for SLSK (Proto) (Perconsole) (Slot 9) (JigKick) (Test Subject 4)[edit | edit source]
BEA39D6443FBACAB05DA62BB95470D57
Personalization removal IV for SLSK (Proto) (Perconsole) (Slot 9) (JigKick)[edit | edit source]
986D5EE1E7759F4F52DB43F33FA5960A
SLSK SHA256HMAC KEY (NonPerconsole) (Slot 0x20)[edit | edit source]
2E1FC0BF211AEE3977C96F1089A150F5 A3CB9E41314BC39F0CBEC16AF3B0B9AC
- calculates header hmac (0:0x1C0) which is compared against signature at 0x1C0 size 0x100, verified with key 0 from bootrom rsa pairs
- calculates encrypted body hmac + 0x10 bytes (0x2B0:end_of_body_from_header) verified against hmac at 0x190 (encrypted with double AA key and custom iv from bootrom)
SLSK Header HMAC/CBC KEY/IV[edit | edit source]
- key
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
- iv
EEB5EC5CCF1CF43113F5213AD5B8D6DA
- decrypts what's at 0x190 size 0x20 of .enc file using aes 256 cbc
- result will be a hmac calculated with key 2E1FC0BF211AEE3977C96F1089A150F5A3CB9E41314BC39F0CBEC16AF3B0B9AC
- said hmac will be from header size (usually 0x2B0) until header size plus body size (0x2B0 + ???) with body encrypted
Factory Handshake Key[edit | edit source]
F47716E6C5649FD648538FD9773D12D1 229E118737B1D782D6A80CDB72E4B9C3
- Shared with SYSCON
SLSK IV (Confirmed)[edit | edit source]
AF5F2CB04AC1751ABF51CEF1C8096210
- Used with AA 16x Battery key (AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA) to decrypt SLSK after depersonalization
Bootrom RSA Key (Fallback for SLSK Validation, all fuses blown) (Proto)[edit | edit source]
3BD3D7E98A17F359F19E3AF9802B95E9 D6946CA8903136582EFC9C88F4F01E3D 3101E2FA33541A231E4E45F05E8536C6 4D69B60EF4B3004D23AD72BF801B8695 EEA843BE585862A63D6B2BE7F90055A8 C690AECAD63B85EA118A79BBD510156F 53D3B7623811C18F0829364ABAFB1A6C 9D841F20A08831963C0D5B64FB360947 206C748AEFDB1715896BCA4D2980EE22 B0C3243FB73C3F2A0A868C587E57B77A FEBE2B983046D6428C722319A598A5C6 0EFB9C4E9FDCF793DFA3CDEEC6C8A249 42652531706D6D701B0B0C660E79D241 9D38E1B8E976BD9FB4D4CD1E6F461E86 B295C6FA10D1C7927CB266C08B3025CC 76A4837EF0D8208BBA305059E23DDABC
SLSK Verification RSA Keys[edit | edit source]
CDAE7E886C890F5EC5FF3AB72EE09D4A 2369F5593A3BAD32256747103EB173E5 9E6EAD3ABD18C0474CF54A09A0500B94 CC20534F04CC8268507F0E3E109307F3 4B74885FEA456FBECEE2F04B87FDD1C5 4784CC79ECF76688CCBCDC18FB36ED20 0662C058D91619F3F50E404969A57CE9 1697F907B768094B5F0A683CD72962D6 84A12145CA84DBEE6F4B03D986A19C0E 7CFCBF0006AA492F071662707CF92604 A8B7E6BBFB3FDB66C4E049A4978A523B D6E521346BA64BD8B050185730B4556E 1678BB9D7384EA0FCE3E509F1227B45F FC5FBD39C42C628012C22DF47F5D4ADD C8FF6F6DF11BC1604028141F21224B5F D323C1F3B7B7DE6C1F1BFC8215C47AB1 2136E5DF66193889419EAE7D7B6AA49B 258D47EBB1C3C1A20737D9400FECCA43 567613B5BED61C9645110A4BEAD9D9DA CECFED9E87A50422560490F243F53595 08C98FAB44E067FDF86A1F7ECACF9E38 A2ACA19C6740C22742CBB8E7364531CC 39127BB97B18C9E0A3C8AAA44DA6BCA8 59DACBF238B75732C5858C9D73F0415F ADAEE2224E567670FA7911450495BCC1 C95B69AF831774557890C3DC9EC62BC2 830FC7639156D58A81C83557E080B970 17AF7FD4652BE8DCD1F7A2D622ABC4FC C65BBA3E466742153CE3AB595C27CC35 BA4719C5D8CB4174229AFD52B0F496A8 8A178FC4FC85290A3C87776131516782 291E56C84D624079DDF2C30C05813BD4 2956BAF256B87660D15B82108D8D516F EFA8C083CFBFD789D24DE45C4B577471 CC135976422B66FCB8CDCFA8A1FE89C1 FBF425FD672BE4C1A7CF9076ABD5735A EAC6DFB30E7800FC45AAC29A71E94766 5FF72C8A8E1971EC5A37A4D4255A5A79 C716A404C8CEAB584557B0C927A22C59 B1A530B7B355402229F648A3D53A0E36 DFF42C59E23892978EDC425DD9E3E62C 8940FEF195C87DD5F66BB6A343472139 8A9660B4F4171D6D8869F5E2E467FC4D 262F3A6F0634F0460586156C23C821D0 93C0ABD45AB174B303C1C09A6B3A03C0 4A077C770770EB25652F1CE6EDA6B0A8 CE3033B085EACF8AB3B387F940311DF4 B6DFAEC8A95AFA19EA2FF4F23A6A2FAF 43CE217A67DCA72211AB644072D251A4 9967A771F98CD1BA4631239EED253F77 56170514BB5DFBE8A4BB7C1ABE6DAD3E CBECB7DA2174B540CDFE6FF3349EB298 3A6F299237E79CD1270E57598C10B2E6 99C381DBDBFFEE1275A9FBBA81724C9D CCC18897EDE7FA70F2EA715955DE48A2 B6D0542B736FBDCB51B85D684C5EAD89 1B224EB51D92BB26D5ED5B5EE7E0A837 4F2EE8728B73973CEFB39168D025686E 89A96361BD2279C9DDE0E4A448A572D4 707AB9DE3C7BB3FB67302518DE31CBC9 491BF12F76B681496257AD20BDB8C63A E44595B82352CDCE00B9850B151BFA3E 81F7197593FDB5DDD562992C21E86A28 E0CE3CA59CB0C6315B06B3483873A3AE 493A79509144EF3042D01456727F3E0E 8B652C4B34343EEE9439B36D91FB9037 4A4546A405BBFB192751708F54EF23B1 F19065F0BB0C306476BEAD56B4601B4A EF947A87E3FE79BAE1AEEE0F695D9A54 E03A60F8A3CDDDAECD9965F193627611 254DD9F02129C51AAE4549B0887FFDE7 5B0790D9FD81D90AAAF1AA364C5A7FC8 B4A5ACD9D3C8F3A6184812745D2F9017 98EF62812907586D6029116379A1E0FF ACA8C646FB0EA2433703327DEA866A9C 7C63D5D6656F71DD65D79E67969AB256 4F813AEA955E0105F3587B6A28EAD7E6 0A00FEF6DF38CF1735502684F4ED0A81 1BD5A1A076F2DB59280C683D714FC41B 4A5FFC5237E77176056F2843A4E4B8B4 DD9B97C1C59C84304950FB578266181A 49E208403BCFA664B705628C94A48223 7D7E67167D717474A052C03938D1791F 6ACED52A4F3F30E2ACE0226E45A5E296 D57D35D8CE3E1953C9290940EDE10CB7 3C9718F2D0D370EA887311D6A0187491 BDBC7301538897C7B76BAAFDE38CBD04 9E35957B0D09438A826E52E15F414A1C B1CFE4ABC4BEB25133CF8FC15075768A 4FD106E44C7FBAD184E9105CC238CDB9 42B5167DE438425606C03B5C8481E6BC 0AF7F5E183A3B4A6935188968DF8A817 AE06B4CCB6BEE8F989FBD98FAEA40EF4 5F8E207CE3BEF80284CDB7B59075A63D C59D6B826FB4E72C95206C2BB84D46B3 E60DE3D48EF1366144F3F5B22B599CEC F7DC3137EC6E0A1F8EC018023AB259F8 C2D6B282CC5A9957B58AFD6E29206B90 C565F9CC4EB14AA2DAA159A5EED38C85 B01AEB1E4F4B3DEC8E0A9A4676515ACC BD3FA08EDF85F278BD8EF51A7FBDDA96 5B88970DB139F4C9488B0D60ED6F555B AEF77CFAAB76B4798AC34A02A95D3DAE A700A9B28F55FCF47554DC10430F7A89 E44FD416C024FC830870710AF42528A1 E3F00BECEF50274A29C31C2E71302E25 077AB07427F09815D5B0D029A57AD69C 044BABF08F9D2764A5E15C25CE53E320 612FC68363A34A52F9A69A9D12F31D3D C6D6D37C8B8407D9B7178F1EF19AE7C2 B1D5FB7618063AB016DE433800BDD696 6C574EC47FA34A66B0324D39D9F887EA 53229DFA87ADCDEE652C35A44952A00F 3E4D078C9007C43705477B234ED128E9 03EBA44D0CF85EC26B9057CC38E62778 395C9F5EDFAD71F2CBA30A40806F9225 180958F85FEF21D2419653E780EE74CF 82E6B0B1AF5D2C52ACDCA913FC37BEC7 54BA1BA337EE42F598DC462DB96EEE02 9060ACD6D27E9DD58DB1C36603FD057F EFD6ECB9977F1EF5486ABA7338A4A1DF FFD5BFC2796D4469374C61495D62A781 BA97EC2739EA5FDCAC538CE891D900EA 40FC0EDABD7D08000B37419E114766F4 012555D2B097CE780A8B51960F88100E 5AE90798F0076D00959E17FD7416BB0C 002882A1576D8B20A7859E559B4ECE54 1444E86206C77F6FFA43BF7C756B62BA E1BF0650D31FE12C9DA5024CD4645A0A E96DB6ADDEF787ABA872F3037335249D 06FC3B6D03D9B9D5DCFE418F2A37896F B9D758A1549335F5099423EEF0F46B15 FB3ADC695A3FC1900665C38C0B4CA12C 725149BF289C50EDDA751AE030A1006B 37C0A4BD8EE780FA9D3E1A97E649A3F8 E8345CA24842D5D1176DB24D98B2FA02 7CF4C898E6E72184B25583E66FC90DD7 85B995D1B6BCCE04D783616808F45810 D3A8B978884A0B22FEE09E2D7318EA02 EA9709589068BBE7A1A3D54D486221AE 7B618AE592FE76494B4434A736FCB10D 3DAB19B0A034235183CAB308334227B7 422D4EA100EB81B34DD698A139FED839 BBDDAF0D06FBCD608A350399C2B5BFE7 410DCBC7D20513E7DE81D2C3B2F6B3CB 7473FF0D9DA8F8AD3E807A8C48FCC319 4BCAC94497C344844636B35F3922CB80 0F6DD1D7D25929693E94A1C2462B248A 60C2CD1220C8798E45DCE81953FADED3 18F136A550010B9E5AFD4E5B952A2E77 F22026188733C3A1FD128AF89820BA73 A56A23AF49E04F4DED4F78F69196AA88 042335A49C2582068E69A851E1ADF72B 8ACCF7EF2821B7AD776B1C50B4FFC792 B6172CD7188AA31298C42182C634D3D3 AC32A3FFA2C324897645D3EA053D1F8D 68F79CADA1A7802FA16FE7D399475731 CCA4977A9364BB312994F850095BE052 EC0A534029E63CCEA7CD9E43CACEF0B4 AE2429AA9912B7BAE7DCDF00BA9D4ADA 6130CB7658FC6EC566D622B55C4F6BEE FD4BA5CAF2A4BB5F2E79820B5427CE60 1D7E92B80D1566ABED917B412F49A3D8 D5129A34B9861C1AEC99906847BAAE94 F790DACD9F0EFFAB81EEC5687D05003C B748F279727AFE1E4A1FFC07318523B8 E6EBA0EBFF95626E466E6BE41EB7EC09 1A6263C04A92E1924E4D949B305B6F91 EC0FD294876D6548582AE12FF8A39FA0 FCC11B7E7F7AFB3D1DB33A15B1ACBDA5 BE8AE8F76EDA16B3482320B30E752392 F2C465C4A07792340B96072EFBB82B92 05F683AA1AEB69C0980409B1A2120518 63F0DC654CF95AA1A219D09204F4706F A9D55BC79CBFB26FDC0130155A34B726 E6F168458EE622F725E75C2FB0ABCACA 05F244401B5862D742F3732AAB702DA9 AADCB86AFE3E59B1D670670043738940 283609746209898A3D70738A56C7E748 B2471143D84B0A88BD9629198CFCD5E7 D01AD41CEB9A08E081D8F72459C70411 249053AE392DBC284E1F49098A6A06F9 E1D8670B25864B2BF37CD5CFA2B32449 8B42F2DD41ABF081DFBA07061BE4B964 794313997F0D6E0F6BCE5509F87CD4E8 3162B15938BCF989F5F7384559D600C9 EE6C7E2D9ACA36FA3E6EF6C91D98C07A 9E79EE6955E8035CB49FC65EC35F2CF2 12BBABC6C6525A4FDFECC997F1D5E553 536A6FE5338182B4B001ACD49DCB677F 44E7112112EF26B7EAB62B44F91A5B0B AD28B164530DC3A4FF17DBB976241EC3 FBD84775010D95618284570663BA7DDE 36DE981C7641FD35D356B01A1B39ED9A 2A6450F61A0F2023CBA098A43DCAC879 186AADFDC4BBE687CA8D78D9D62E96C9 3BFA87A8064988C49582AC1FC530330C 716526F440A79E2AFC0EB58F9A123B7D 342A48E5FEA7BEBCD4FFC8CEDF6122FE 3939080A5B8CE8F03869F6447FE1B33A 49B991924DBF8343F3DC72457BAE8CE5 0D291664475A1E6B564A09BE0A7FA279 4C27EBF2580D687E6116F84F1A347DCD 346B1AE3B48ADEC0860C36884653A5A3 9744C2229A85BB72973CB431647C7EB5 0DDD528C09C3C2097D7CD7A6FA28DD6E 8D9D3841CDDD90A413291C73F88523CA C53618E0483E09BA88CA53FD6DE785CA 496905C2DEB8B75852F2C9FB948F5C15 C072C8571E5BC3163FC3FCBDF92E5B5D BA30D220C185502D7E9E0A83B2AEA098 E1F9507DEF5FD0F129076B3F7E745B44 0A2F56C8DE9591C3BC16F777B0826566 50FA1E85B1D244C0F691E893D7E0D2C3 A15AC56D069ECB0E31897EFB918FDF93 B5FA1ED6DFC7421E5439DA867ABADDEB B785A6F95CD23B4CA8255C89EF4E8D9A 497FCA1C013B04BC9BEC00B265EBEDC4 FF58E990BEB594C738CA6A601796E0EE 79B1339FF36E0A49AA4984419DB4B233 F761AFA5EE61172DADC669ADA72390B4 7FB83172A975DFD0E4CD04FCA627A5BC D1B249094673CA74ADF0E6F07BC5706F 9904E7C40C7EA59012BBEF30AAC35DC2 B101B337AE29FA754FD10AF5FFF77B3D F77BB7A317F74801BE38B238CE98020B CA4C9268F837A03E83389EF7BDD9C7A0 2FE93FF70808240BB634458B01973CD5 A0ED95619AA09C4933CA01411B9B26CF FC633E2880CCD5A3776883CFE329FCD5 6912325EDEF3A61BB4FA5992C7A4CD13 230C1E65E99C1C71F7DDC5486FDEFCD5 632C384C40AE12676C66EBF25B859EDD 3061F8388070A99479A68E5EBC794BC8 7B3D16D8B4969F78A86D06DCE61B1DCC B07720B84D8972AA2B861B2EB586837C 4422481883B297364C1C763396F94AF3 432B2FC57370311AC1B2857C517EC51E 5D45A31DEF78DC28422539D7A5EAC579 B0EBA8334D836668FA4F3A6FE25DBBAF 55157A5C49708D923589694220173DE9 A3CE2F96E33963EA87E2067FFC3807DA AFF11869DFCB2DC208313B7ACCB393D1 44E7D5D50FFFEF11C3DEDC877B028FA4 C4705E723702E28DC84C7E355C120375 3F7DEFC9E38CBD790D4C6C326A9F48E0 8CA66BB18D1AA342B7E62049C63ED76F 07ACEAE7BBDB5076BAA54F2D84E31775 97C02E539A4BC00BFCA54437463EF830 B1AC92BC339A9376F60792D61933C607 8CBD70E0752CC2099F183F6F4C8C7D5C 1DF02E626AD0FD595209EC9235ED63DD D483EC895F5784D2FE640ABE4BBA2ADF 115EEA30F3C1B405F4A513A581C6333B 9844698FBEC9AD01A2619BFF716703D5 6A69B8EE459A06FD9A61EA1ECDF0E993 80D3AF14FBFE8E70BE3DB07595214A90 8712B756322A8667DA589F370C3867A6 1DF895CD14E53DB0E6479C975C13FFBA 0C27C40B84168FFFD63CE001D334A4FD D3FC72DD9963AE825F7FD9C5EA1D9924 1DB1261DD0E31CD94D8F2657D8EC3D93 F2F08E3D7DF6FE07ED9FBE87FCEC75EF 7E5FA243F5BA24C1B81E121FA07DB901 6A5F33FCE5F23BB89E108BC27718F5EA A09CF686DC15FFDEC0129928680ABE5A 336FF78FA69C57741899EF7A238DE1AB CD39BD6B23B888A34D7DCDD3F57CD8A5 5D2735973E74F3C416FA1B019515B5B2 CC45367F1E769010A96ACF79B78BB8BF 7BE678AEEBA54214F5DBC3B0ED3FEF22 793C9B3564F9B3B134DC87662C0014A0 5BD5F12ABD2413C8E8AC5D8CFC71EF07 E0276B083E3A2729EEA5B068F1F85331 986420BC576CD005228A4396AF000F4F 95EA10E442844D84EAAD40C95796F705 7A5BA3F08ED905E179416E05BABE6D43 216D5E5F8B346CEF01DD266F5DD2ADF8 F6FB17FB08515B0B752B6A53E09EA007 FAC79327B53E568FCEF00E2E85D54C1B 6BECD2639F5527F7A6F32A689013A091 1F1E011227AB565C4D5ADBF9FF02F15A 00429863BA5634B4285CA2F2B5109AF1 A83314D1F3EDA27D8CE9EE568B13A575 94630701EA5BC9518339C697341EBCAB 6F21B615EC1A93FD141B3190DCB6346C 35E7E9C15F468104EEE83771A2FA096C 27E1077F176A6A2B72927126301A91E0 8F9D7AB79E79587837981413153A4531 4517E300F97086529D73DD9F2A3AA946 29D644DFA9A730C42F3D5865E436FCE6 9A98344EAE3A3B9675CE9DA9F5877820 78876C7583D4859CE27BC6A0181F070E C12FAEC7943177837A618070D2EBE603 4058F525D70BA7690AA615D2D83B882C 38C70FF2175FD11D89375104E5D59268 114910602E78EEC49DFDB30ED2D32E45 F39D530F76B5194DEEDAC6AE5BE64473 B287A1D2B3BD78EA498249A4A3F6E944 4FB4A1E306969B4E61704C39D78DFACE 985116F83F1B2CB1119798740C059FC5 EB77A8C232EC13A8C004FBE259DDD369 C3B53CF8E86F2A47B01107C63261EF73 558EA2F03CE2A2E2FB7F4E8141D98206 834A3D317CF16E6756DABBE968F733BE A5C954A2CFE5D3D276E0CBC7A225B4E7 D7877384AD02EA56F09E5C82DF5C236B A054420A95F0FA959108032DEB1B7811 037BB91AB52F151D1F760EC949F4C7A1 26451A5707F7C5E9F1723D2C8F892A36 C5A0DD4B5750F5DA8A26E3F4F7B2F107 68E00410C84E69039A833153D8DA687A 061C6DE184F761BC8771C6909C791AF8 D8D9927048D03600BE531BE3D7D5C51C D493B5640F4A7AACDB934797BEEDA10D 102DD5329D44BEDA56570752A7BC2A9F 6F4B5ACA17641CA3ADD546F59A9FBE0B DE984D1F6A88CA2764676CE785380B41 71D70E9D083C81D567366B3D951779FC 2C12AEB2A865483145754B79EBA173C8 8DE96A5B2F557055A9CB4B4A299E86EF 0EF6769415F8CB3A83D514CC3F70008A 1E090FEB4614201D25B54202A8CB3811 D49DBDAFC4ACE6D63B6E13E67CC9730B CAE4A283424BBC14EFD89E72E6513902 AACB955CB3CCDF4A47B3948A4B0201E7 6BE4F58725AD38C481E67D4060C2D31C DBC87DBC491114E6A87C45B3EA37A227 0C5C941CEE02E8C1BCC29256DD86D0B0 160724EAF49B4363F8F65229B5202D69 F1DC00952693B75A8883AE8FF5A6B4B9 F85367D5EC06AD8AA0C765EC09590543 3DA8897BC46CEC5193C81E39EE0A574B CA73FD099805B48477B3887305EDAF9D E19B36E6DE66691CD0A8EF19ECB45BA2 898E6D9D4A0C6E678E3BEBAAF44E67BE 431AF443ACA1049CAF3455F4288D6A4C C69307F7BD986F1239F846CAD5EB1CAF B5F9906E558F087984DDA69DBB43AA7B E8FF00FAD2D02DF4CEE88BF423F51BDA 1F1B3944D5A17E74B7EBDEC3ED8A7078 3EDC9BCBDB76BBFAFB546CF882FE1107 9778F5ADE0126F3B357ABD48D6B6EF2C A0E303D3159E69178C2CAB41F841DE56 609EC551F154811896907D2B8691D8B8 360BD8E3062B0A46DF7778BEBA6484E3 0701B80610D59E2253AB10DB8D896426 DD111DBA5F1E31B7761C6A963056C59E 70F74A7CA32DA4CB46518AF2192D0416 E9B93644B03073270DE6BA75816DBB51 F8769CF01ABDC46336466C9261597E70 106344EBD0735178E70B83CD4A187EA6 283D76AB50F838B41DD94D94D8FF1AFF 23E42CC58BEE0A56ABA29A3151528C3E B0281F507A97C79EFA14DF4BC64F3F59 64EE0076934AFF3375D9E4F04DAE5E14 DF27D3F0054F40201CBBC6BCB75A9655 0A5EAAC417FB605A0014B9205325753C 556328F1F096E5D50D83EB3CB335C453 E0F3B0BBF3B75277B915B7F5E9878DE3 847DF7AB55C11A75FD5353FD1B38930A 6B27956CCC9505AF49E3B005711FA514 6A4ECB0F506CBADA661D466298EE1433 7C27680232FD5510D538160AD27CB490 1AEDDE48DDD6185FD743B69D9F0454E4 DF723F416684FBFFC73BB09E4588A68B E8EEA00603D07E4E37E2FA8E61CA97D6 4C3019AD267187CEFB132734825B7640 BDC147A43A1092A482EC5CCCB6890401 22F9F538433C2EFD9F4D13D5A612ECFF 5C7A7CFF2E6DAD153A63D0C88E39FBAE 7ADBF37C540BE6F1F4240566475EC978 1ACA6B4A5FB7AF017A4C5CDFD1503699 4F7E4D677B124C602FBD08D952FA7B47 3CA989237AB17D48090D9CD1C7CA37DA 737D596487BAC92E6FFC18F1242F873B BED97C92DFF41DC45F73EEFCEAB3EC68 00321E1FA4B9DE8840B29AD648C8438F EC18D74088D6E075BB1295869DF5FDA9 3A89BF187D4CB310EB9B3D3D0666294D D234D4D96ABB1421A94321647E49E418 5295854F89D61886F905304150D418BB 4C80C7C775F12FD51C3F3721237B473D C82F1176221546C6BCC22383CFE63DD8 8497D52C2C329F399841CAD263BB4D7F 640C8B583FC15400FD3CE28EB6F52EC6 1E094DD0479201E59FFDAC0B7193DC11 6E98A9C9ABBB729209F5600FCC901990 804B691CE39E3CE01F8F0B2238F73C2F 68747C6E590C30675F15AD230AFFDFB3 07AD55B0F6D241AD6C3FCC6903A6B25D 64DCE7F683D23317C3BB8F27D93EC42F F947AD4115BAFB3DC4C57051F6AD787D 341C716395E8432352776003E375E6AA E07E2174B75D26C83BC0D96F8E350C4F F7BAE27584BB6D64BF46AF0C94A6CD56 2A63807907B0F4F1C90888DB4F5A8E3D FFB073F8D7605157FE08916B3390004A 0250F18BC7F05306DFC231E627F010B4 E2417DB0C6A3EE785D13F2BD48F1716A 3D621C703958DC2B8ACF42D385F64927 1D56AA6077AF74F68E16B54028038A40 588E93C26CF3D71386338A4E14132CDA 4E97A73BC3D01CC3A41909570F24BE41 7663161A5166D2BDBEEA969EA7FF5A5E 12B8E7B4AD60E1671A3FFD6105593349 F323EF2610BB4854251B3BAC0B5A1B3E 91C1426D9A89AEBDC87F39822F6B331F 0793894273CBC60A07F4CB45B5D7B040 058DED872952E779BB800F81A57A3995 E319252EA178D2F82ED01656E4BAD172 2802FE57C656A6F8BD01AD104ADBAF54 E5238F1ADD7AA48968F26F71F187A245 14E8C60112A803A4241F9E57E1F7AF6A D18DB03F4A0DCBB7A736EE3CE3876E2A 46053A2A12B3088377CC5FE2392938EF 8CB2497089F9F56EF18A21A2B16579E8 813C055D93BB8DF483C6786DE063E8F4 116C1CBBE2BCC48292999FF2ADD6507B 6002E61EE9AB734B89B89EB26377A67E F18A3E1AAAEDABAA126E07E59C696503 8D3EB0F6FA3FB302E125E34FBFEF01E3 D6F599DA74515C72CD33DCD6444A4E9C FEA0F8DE75C7FCA523B4DC6695C30F4D 711E50C91441BEEDFA92F4BB93014A77 6ED4CD9A0AD9EE1FE3DB222BB93F6D5F C35F0BFD48380C556778935DF1705E55 15E00783F98814E911842AE9FD45B122 A094EB80910643477FD5CFC60C62F2A4 10030732E31894420E473CFAA43EBA8B 43596E6B06E6CD67BAD69D2943A67D44 9C9FEFE25732D09B7B993EA16372B71B EC06D570BEEC94C4CEE301A77504AD00 E7C9F8E2FEDB7DB4F2404EC4605958D0 5C799199EFBC7E483A85B7A774651B7B EC1107F3C35E5F9623CC1479FA2FCAB2 606C323790EC44B77748216E8E259973 62CD59F7DB176E40B012C6C252121237 451DAB82BCF376741B1F6D0530C58E30 F97CBFAF81C1D30B3D4476B82FAEC5AF 8C79E83EFD53E7C40777D0FE4A2584C0 EEDA30D2E95EFF0D5E74B2D4A7A7FB9F B16DCD1FFA3D7A090E4040D74C2D7789 D2C2351634F11395BE1A2E3888048B5D 3E97F9CA56CEF2970EF4D5B047A8BAE8 FFC67DFE1218C0FA1113C26CF15F7274 E5273ED1901FF8A9681B531A66575BDD 1C6C8E6BF1FA894B3C67E490AD0478EC 795EB5161BAA2FF99377ACC74BA7F7EF 79E41D03E8B899E7B0DC3486F33220FD 0D008B128F46648DD0311BF3798143C6 1F51C08D4A5A942821CE4EF84988B411 2739D8E6E7186D34084D126B6A4F459F BD09B5DD34EF00FBB611EB2D312191DB F4ABF13038833D5DA7327CD9290FFBCE 6CA3F689882D225AE7C40957E9BAD7E2 0E2A4C20664A235F28386EBFF817D077 5FAD3151B8E39F3A8CA89A4178FC6520 F90E31956A64CEEF68285A391DBD96CD 1E0FAEE2D027636E50804BC47D23B90A 184193FD28E2EF1CE6F782146E595DB4 798FDFB8E03625709E9998A0D8EBFE32 6A9204919336D4DF3273CFD6A5B58CAC 5C2542CC4B4D89757F010254DB01009B 677DEFF2D7391FBB6DA67485CB88D76C FABBA7656625D0373C761E294082653E 91689D9D9B271EF47170214BCA129392 B5DB30D1F4B77B1375A45A1BDC2A3A55 2559BD1455D42F1F13CCCF7C2500EFE3 2D963059504F0D69FF6BD30CD6A95C1C 077C149C3A40062A49367B4033B2C80E 36A64DE9AA5E01F5A37016D777396A85 04B7B3666CCAF1DC911F90C869B199EC 149BCCED50B19EB32654457712996458 34418D27DE5915D074D6E3732A65918C 4C1018AA486109C8B1A3335850FEF450 BBA43308D81208C27309549590A3FD02 33E686EF6C1299096D3F8A872196EC36 0107F6ECFB56299AB71116E775D04742 A12D9C23F00051AF37252C85D60DD347 606001E3846F3621E8E66CF444D2E20C 01ED73AD810421D290D824F9F08EE9A2 3DDB41E084520E6073AE5F84926A000C B53B5B63E1A888F46556D1D916577084 9ADF52F1926B6C545CA959CE9800BFE8 6BFABF64AB5C04F3D41540303489B4FE CD978EDC1DB6DC5C1DA17BFF3AA8FED5 407D7336D8027087C553B1E3C15491A1 F83FC2615EF7F647DDB9E666DB49EFFD CBB08B1DC32773C6F52558C24F467341 04B0B70938D13314924D5E20FAFA62D7 85875F49ED6F1B39C7C1C7CB859856EB 69213CB98BF7665F999FB87CBF7BF87F 7D7006A2F42DF2B0A8DD7576F895A650 79BBD313309FAAEEA24C3A8D3BEC8ABA 81C3B008BA13765FFC0EEB39D0AFE2CC 71A56CE5AF79188CF70A048E41691F2D 90DE0ABCC6B9CCA235C5C105EC77CD32 915DA02507F7CF4286C375B2E5EADD0E C01D272D6236D9FCD147F2A84651242F 68333929DA8542489F9EA852F160D9D8 0D25112F5330F54AE188F9F69823E81E C8D96C49FBAE295252047BB6BFE5D175 502181DA177BFD8792E4E2205C2D689C 511B792980A78E5F9C12461FC498EF1A B105A1A8133FFAA93B28B4BAC6604C84 196F5DE217D71579B9B58FA214FF52EA 798B258258CBBC4CAA95C6189757ECED AC373D038B695AF368EE1294655A6F98 C30D291017300033BB5EB4E4703F2337 967D0F21ECD5A0FE1DC6782034B7AC34 8A0FEAADBC6AA28CB828EF5EC4CFE49C
- Only first key is used
Keyseed 0 (Proto)[edit | edit source]
1EB25643234EF6EF380F9E57A216FA22 D835FF0508BEBBE97676FA478C29C21D
- Encrypt AES256ECB into Slot 8 using slot 0x206
- Obtain PCK Layer Removal SLSK From NAND Key (128 Bit)
Keyseed 1 (Proto)[edit | edit source]
50976238EED23234F9C746CCB07D6D71 3F5BA67BC8C097DAE52D8512084683E7
- Encrypt AES256ECB into Slot 9 using slot 0x207
- Obtain SLSK ENP DePersonalization Key (JigKick Only) (128bit)
Keyseed 2 (Proto)[edit | edit source]
4A41DEDEFFBAC04F52602D0034DAD666 164E3CF1FC23BE4F4D0F8471A7E60563
- Encrypt AES256ECB into Slot 0x20 with key 0x344
- Obtain SLSK HMAC-SHA256 Key
SLSK KEY IVs[edit | edit source]
B07FEB18E422167AECDB60A8EE0CA427 Index 0 69425551E9AE3945F36873F110FDA6FB Index 1 1C48B1C8A599CD59C7AECF8E469830BE Index 2 7C598FB45BCF00A9F49E5AFAD3554754 Index 3 98E3F508D16EF78C8FAE96F4168F20A6 Index 4 766410AE5109F2201DDAE41FB07F6EF6 Index 5
Auxiliary IVs[edit | edit source]
0962939DC5BE560F52F6BB45B34CE097 D46CF82FC8BA5D5B6436F9F7E4E20434 EA574C6CB6B11505D5DA35446D187808 8F62AAEDBD4E025BE6E8FF8E7D654704 C898610BF8E6CCC12C9BA48414CC2BCF
- Used with other possible keys besides AA key (5 possibilities)
- Never seen used
Second Loader[edit | edit source]
FallBack IDPS and PSID (CEM/DEM)[edit | edit source]
fallback cem idps 00 00 00 01 01 03 00 10 90 00 00 00 C8 B4 00 CD fallback cem psid C9 E5 91 3A FD 20 52 AA 4B 85 97 51 24 F7 59 A2 fallback dem idps 00 00 00 01 01 00 00 01 00 00 00 01 88 25 9E 0E fallback dem psid 71 CB BB DE 6B D4 1B 24 37 A3 6E BA 3E C3 6C 93
[edit | edit source]
1C7FD39E8D63AA32D386413EE6A01C15C4876BF614CA954E36C1602DD7871C4F KEY 051DFE9D9BEA8087F66EB8F631010D88 IV
SMI Modulus[edit | edit source]
C618BE3270E1553B2D08660C70000616 38388DB331BFF30E7DB6334EA8F8F7EB 93540B6624465ABE2AFAF01ACF0B8705 1CBAE118769183B9EA9B09C225A063BA 387A23452BBCDA2949C4ABA0C66A8D1D 0A44A7AE22D1AC449C9EAC5ED79A18AC 1B0691B3451673965ED336C9987EF5B4 2FA6DE995FFD319A629A5E2523164E3F B9C7BDE7025E839C3B528F53E5ABB077 776C80E1C7A15720CBEA770D7674C9CD C44559F0ED538DE33F79E9334C62AD81 114B23432D736A89CE7A53FECD50E66E 021F9DCC2B635E33305FD5EA8F15656D 2B00E93BBC78EE97B6BDDDF8EE218289 2D6A739CA1001AD8849F2F0A2550592A 4DA15742BB712E07B7933B8BFE1F2AD1
SMI (Slot 0x213)[edit | edit source]
AB7097356FDD49D83878540167F0C4AD85537C5A56BD15DF0EB5F7F0D9E276E6 Seed First Derivation SMI 310D20077AF3BF121F21D9ADAF389CDA IV First Derivation SMI 2F0AEEF98EE3965650F8485E6C0BC2C4 IV First Decryption SMI D9A2CA7FD2E5AA65134CBF9ECF036F8AACE02A42D9187A08717C0255A13AB966 Seed Second Derivation SMI 0F92B97AC4353337FD222A0E7E49EB58 IV Second Derivation SMI 69D7618B7DBE7B59C04DEF5169831FBF IV Second Decryption SMI
Other Keys/IVs[edit | edit source]
62FC3C4751B32657E71E89ECE4324BE3 (Internal) (Introduced in 0.920I, removed in 0.995I, qa flag related?)
Secure Kernel XXX Proto Keys[edit | edit source]
- Algorithm is AES 256 CBC
- IV is all zeroes
External[edit | edit source]
992EF70868DE1B219EC3618FA79DAEC39067FE5638116C29FC0FF7E2A58FBD9E
Internal[edit | edit source]
AC78EE86799148699B9CB3F5C6CAB73A6AC45EB11F44E9151232CF8F123C7D88
GcAuthMgr[edit | edit source]
Master Key Seeds[edit | edit source]
As part of gc authentication, some keys are derived using these key seeds & 0x345 and 0x348 bbmac. different key seeds are used depending on the key id used by the gamecart.
KeyID 0x1[edit | edit source]
KEYSEED:
7f1fd065dd2f40b3e26579a6390b616d
IV:
8b14c8a1e96f30a7f101a96a3033c55b
KeyID 0x8001[edit | edit source]
KEYSEED:
6f2285ed463a6e57c5f3550ddcc81feb
KeyID 0x8002[edit | edit source]
KEYSEED:
da9608b528825d6d13a7af1446b8ec08
KeyID 0x8003[edit | edit source]
KEYSEED:
368b2eb5437a821862a6c95596d8c135
Unknown GcAuthMgr Key and IV[edit | edit source]
821C5714415E9804D6AAE324EB3DDDFE7BB73E8EC0F9E04D3D6D60BCD0CF4EE9
CEC36FCD7DB3102A80E9C2AA65734FC1
KPRX_AUTH[edit | edit source]
keys part of kprx_auth_sm
Bind Data HMAC Key[edit | edit source]
used for ksceSblAuthMgrDecBindData
901a84fb13a744a378c5018a60f58c22
HMAC-SHA256 using this key result is the key to aes-cbc-decrypt bind data first 0x10 is key, last 0x10 is iv.
AIMGR[edit | edit source]
- All these seem to be fallback keys in case keyslot 0 (aka pck0) fails to decrypt the idstorage enc_cmac located at cert + 0xD8
- algo used is aes-128-ecb-dec
- used together with keyslot 0x212 for cmac
7BB73E8EC0F9E04D3D6D60BCD0CF4EE9 CEC36FCD7DB3102A80E9C2AA65734FC1 89398ED8AE6FB3B0519485893AD0E5F3 33B90F7B250879F87DB269CFC4E7FB35
- This seems to be used to derive decryption for the certificate from idstorage
- used with slot 0x204 (likely iv for aes-256 master key)
821C5714415E9804D6AAE324EB3DDDFE
PSN Keys[edit | edit source]
X-I-4-Passphrase[edit | edit source]
used to aes-128-cbc encrypt X-I-4-Passphrase header of PSN authentication request:
- Version 1 (used until 3.63)
EA35FA34B747929A540219DBA2DA001F
- Version 2 (used 3.63 onwards)
886073DE0511F0581792DC66FD6CA6AF
notes: the IV is all 0 in both cases PSN will still accept a version 1 passphrase which is how henkaku psn spoof works
X-I-4-Passphrase HMAC[edit | edit source]
used to generate the HMAC signature for X-I-4-Passphrase
4D3E171CFB60DF96D1AFA6E76FEBFB5C079A5D177919C3EF417BAFA23A0B0DE2036624F0C87A8D3659DAE19E77195146B11A767D8A35A8610D301A79BBA9342D
Communication Processor[edit | edit source]
ES2 fsimage1.trf Pub[edit | edit source]
A9 69 7F 9D 93 43 CA DE 68 E0 4F 9E 35 6E 6A B6 BB C7 DE 36 A4 D8 1B 98 A8 3B C1 2B E3 F6 DF 96 ED 7A 64 38 94 56 AC A9 33 BE BF BA 4F FE F0 5C F4 5F 2F 88 6F 43 4F BB C3 A0 13 48 53 30 70 C0 B7 D5 E9 C2 1E FE 53 E9 5A 60 19 DB 51 C1 2C 6B AF EB 94 E9 92 28 79 63 44 8E 59 60 63 84 B9 9F 3F F3 E5 EB 6A A0 8B F3 2A 4D BA 7A 31 25 20 CE C2 B6 9B B2 0A 6D 06 40 B1 17 17 0A A2 DD A1 FB 59 0A EE 7A DF C4 E8 0D FC F2 7F A5 5D DE C9 2C 07 92 2F DD 05 AB 16 18 DC B7 27 AA 6F F7 00 27 A9 41 0B C8 45 E5 0E AF D4 6C 0F D9 2F F5 00 67 2D E5 64 89 C6 69 B0 AA 48 1F FD 75 E9 9E 21 A8 DC 2F 9F 9E 87 95 7B 46 BB F6 3F B7 DD BE 8B 8C A8 61 BA 34 9A 62 45 8E 85 5E E7 8C 3D D6 79 1F 92 E7 64 22 14 4E 51 29 5B 13 37 E1 5C 12 6D F6 FA 0C 29 32 1B C1 D7 C0 0E 3C 19 EE F3 A3 E7 A5
ES2 CPUP Pub[edit | edit source]
A7 CC AE 0F 50 11 88 52 7B F3 DA CC A3 E2 31 C8 D8 70 1E 7B 91 92 73 90 70 1D E5 E7 A9 63 27 DA D8 71 67 A8 F0 13 68 AD DF E4 90 E3 25 A2 90 53 36 97 05 8F BA 77 57 66 69 80 10 AF D8 FD 7A 3F FD 26 5E 0A 52 FE 04 92 8B CE 8B 43 02 F4 C7 0F FA C3 C9 39 7F D2 4B 10 62 71 E5 7B DA 20 D2 D7 02 29 8F 6F 99 0E CF 9B 0F E0 4F F6 CC EE 17 0B 55 53 04 23 20 12 D7 8E 60 19 DA B2 97 63 82 9E 6A F5 AD A8 02 20 4F A5 51 63 11 79 CB FE 61 64 73 26 62 E8 57 67 41 94 9B B1 36 45 6C 11 DE 35 5F 48 72 11 D2 30 26 7D C0 5E 69 9A 26 52 AD 5C 6D 74 B0 56 83 26 F4 F2 F5 B8 6A D9 56 E9 44 04 D3 A6 59 28 F4 EA 21 89 56 7C E9 98 99 11 B0 48 08 51 7F 4C 76 A8 B2 5D F1 D6 AB BE 85 95 C4 69 BF D7 E8 70 C4 F0 0A 89 61 0C 2C 9B 79 F6 25 A4 2C A2 B4 C6 B8 D3 7E 62 CE 9E C6 1A 85 6F D3 2F
NBL Configs[edit | edit source]
Key[edit | edit source]
3C 97 EB 60 B2 06 80 E9 5E B7 00 13 11 96 5F AE
IV[edit | edit source]
4D 8A C9 0A E0 B3 C1 30 46 31 A8 6D 56 32 02 70
Deobfuscated blob[edit | edit source]
4D 8A C9 0A E0 B3 C1 30 46 31 A8 6D 56 32 02 70 iv blob01 aes-128-cbc 3C 97 EB 60 B2 06 80 E9 5E B7 00 13 11 96 5F AE key blob01 aes-128-cbc A9 69 7F 9D 93 43 CA DE 68 E0 4F 9E 35 6E 6A B6 fs1 rsa BB C7 DE 36 A4 D8 1B 98 A8 3B C1 2B E3 F6 DF 96 fs1 ED 7A 64 38 94 56 AC A9 33 BE BF BA 4F FE F0 5C fs1 F4 5F 2F 88 6F 43 4F BB C3 A0 13 48 53 30 70 C0 fs1 B7 D5 E9 C2 1E FE 53 E9 5A 60 19 DB 51 C1 2C 6B fs1 AF EB 94 E9 92 28 79 63 44 8E 59 60 63 84 B9 9F fs1 3F F3 E5 EB 6A A0 8B F3 2A 4D BA 7A 31 25 20 CE fs1 C2 B6 9B B2 0A 6D 06 40 B1 17 17 0A A2 DD A1 FB fs1 59 0A EE 7A DF C4 E8 0D FC F2 7F A5 5D DE C9 2C fs1 07 92 2F DD 05 AB 16 18 DC B7 27 AA 6F F7 00 27 fs1 A9 41 0B C8 45 E5 0E AF D4 6C 0F D9 2F F5 00 67 fs1 2D E5 64 89 C6 69 B0 AA 48 1F FD 75 E9 9E 21 A8 fs1 DC 2F 9F 9E 87 95 7B 46 BB F6 3F B7 DD BE 8B 8C fs1 A8 61 BA 34 9A 62 45 8E 85 5E E7 8C 3D D6 79 1F fs1 92 E7 64 22 14 4E 51 29 5B 13 37 E1 5C 12 6D F6 fs1 FA 0C 29 32 1B C1 D7 C0 0E 3C 19 EE F3 A3 E7 A5 fs1 rsa 68 48 3F BB 69 F1 04 A3 CB 0A D8 18 7F 90 0B 12 89 6F F0 68 51 B5 51 CC 75 B9 C7 01 4D B1 8F A9 0A 82 27 97 B6 CC 1D C0 2B CD 68 8E 91 C6 22 64 1B F4 36 ED 32 2D D4 F0 D2 CD C1 7F 20 35 AA 0B F4 E0 8D 02 49 BF EE 25 52 90 AC E9 40 C4 69 27 E0 C9 DF 3D 3A A0 62 98 4E B6 D3 77 41 5C C4 09 3F B8 3E 20 28 65 2D 80 70 C5 25 4A CA 0B CA D0 A7 C3 3A DC 90 EF 6B 66 D2 CD F5 0B A3 CC A0 E2 29 9E 38 D2 76 11 66 B9 2C 28 7F 75 1F 94 FF 06 74 18 EA A9 D7 C9 EF 9A 26 3D 42 8C 23 33 0D 27 41 42 67 E7 DB BC A6 B7 07 F8 C3 3D 9F 06 B0 3E CB 45 3F A6 40 22 28 A4 0A 13 8A 49 68 F3 F0 72 94 EA D9 E8 55 37 CF 8D 43 AD AF EC 51 87 40 D4 D4 D5 A5 4B AE 14 27 7E FB 42 F9 C7 81 4E 1E E5
Ernie[edit | edit source]
Security ID (RL78)[edit | edit source]
00 00 00 00 00 00 00 00 00 00 (it's blank LMAO)
Ernie Update AES128CBC Key 0x10/0x30/0x31/0x40/0x41 (PHAT)[edit | edit source]
key: 12B5408FD189E223B61890F488536008 iv : 82D6528A87BC55B38EF29A45730EF130
- supports type 0
- for block size 0x400 ONLY (block size 0x800 not supported)
Ernie Updater AES128CBC Key 0x10/0x30/0x31/0x40/0x41 (PHAT)[edit | edit source]
key: EAE43A1C48CD32A565E2CA7D8F9018DC iv: C9D9619CA151342D04602ECF0B8D6E33
- supports type 0
- for block size 0x400 ONLY (block size 0x800 not supported)
- for updater and confzz firmwares ONLY
- location: around 0xFXXX of syscon firmware
Ernie Update AES128CBC Key 0x60 (PHAT)[edit | edit source]
key: 8C9ED3908C4143AE02855794C025BE1A iv : C85AE1576D5E205FE8043573F55F4E11
- supports type 0
- location: around 0xFXXX in syscon firmware
Ernie Updater AES128CBC Key 0x60 (PHAT)[edit | edit source]
key: 7014BEE6136725B9FFBE9A8614DD5C2A iv: FBD11DF2E0AAEE0B9C3738163CB8B6BD
- supports type 0
- for updater and confzz firmwares ONLY
Ernie Update AES128CBC Key 0x70/0x72 (PSTV)[edit | edit source]
key: 67C34253A7DE13517EC903FE1119C04C iv : DB302673D69F0D513A635E68A470F9C1
- aka the key for the meaning of life, universe and everything else
- supports type 6 and 7
Ernie Updater AES128CBC Key 0x70/0x72 (PSTV)[edit | edit source]
key: BE01B7FA1EC3ED641879DDE44D60486E iv : 671A74C7E50F25CF64D4341039C78705
- aka the key for the meaning of life, universe and everything else
- supports type 6 and 7
- for updater and confzz firmwares ONLY
Ernie Update AES128CBC Key 0x80/0x82 (PS Vita SLIM)[edit | edit source]
key: 523BEB53FCB95DC772AA1BFB0A96CD10 iv : 385D67E50CE7669ECD171FE576814343
- supports type 5 and 8
Ernie Updater AES128CBC Key 0x80/0x82 (PS Vita SLIM)[edit | edit source]
key: DBD9450ACCA8544895663A6F472BDE7F iv : F927C6A1153DB2D65F736C3AD9E1CE76
- supports type 5 and 8
- for updater and confzz firmwares ONLY
SERVICE 0x900 PASSPHRASE[edit | edit source]
93CE8EBEDF7F69A96F35DDE3BECB97D5
BStoBSid Key[edit | edit source]
46B532E3F012E663C0694ECA7C8C58B7
First Loader Jig Handshake Key[edit | edit source]
Also known as g_debug_challenge_key. See [1].
AES256ECB Key:
F47716E6C5649FD648538FD9773D12D1 229E118737B1D782D6A80CDB72E4B9C3
Supported Keysets by Ernie[edit | edit source]
0, 1, 0xB, 0xE, 0xF
Ernie Handshake Keysets[edit | edit source]
These keysets are stored on each side (Ernie firmware and cMeP binaries).
Keyset 0x0[edit | edit source]
[edit | edit source]
80996FBBC8B4EBA30595F4D379A23BD0
[edit | edit source]
EF685D2E33C7D029A1A2EE646BE39D41
[edit | edit source]
CE7867DE57575C008D998281E8DA5912
Keyset 0x1[edit | edit source]
[edit | edit source]
8C20B6FABD2236F772AA283B8C82B13E
[edit | edit source]
87DC6ECFF1CA5D709B01AEF69EA6B283
[edit | edit source]
51EB8DD39B0585CE915F3BFF609C9563
Keyset 0xB (command 0xA0)[edit | edit source]
[edit | edit source]
BB644721CB4C55072E83177BEB3BBEE9 (2F1C)
Initial key to encrypt step 2 packet.
[edit | edit source]
DC6B6EE0F457DF0E7BAD1C5EA338027F (2F2C)
Intermediate key used to decrypt Syscon step 3 response.
Ernie communication session key AES128ECB master key:
00000000000000000000000000000000
Unused with command 0xA0.
[edit | edit source]
CF2E93E9F94E28CCA48026134C7C77CE (2F0C)
Checked in Syscon only.
Keyset 0xE[edit | edit source]
[edit | edit source]
AD2F322F4256C49D1848818F0FDD81BE
[edit | edit source]
4ACE3A668AAEBB11793C432FB8A4CE88
[edit | edit source]
1CBAE93DE883557C8AA14886786BE227
Keyset 0xF (command 0xD0)[edit | edit source]
[edit | edit source]
50E4C3A77264167C409C72A9B57A8609 (2F5C)
Initial key to encrypt step 2 packet.
[edit | edit source]
9E34087C48985B4B351A63572D9B481B (2F6C)
Intermediate key used to decrypt Syscon step 3 response.
[edit | edit source]
EBE3460D84A41754AC441368CF0200D8 (2F7C)
Master key to generate Ernie communication session key (stored in Bigmac keyslot 0x511) by encrypting step 2 data.
[edit | edit source]
C86B51FB019A207F32118E55462D5008 (2F3C)
Checked by Syscon only.
Step 4-5 passphrase:
B01103B0623832D62540B56333D6E11D (2F4C)
Checked by both Syscon (step 4) and cMeP (step 5) to ensure packet authenticity.
All not known Ernie-embedded Keys[edit | edit source]
DB D9 45 0A CC A8 54 48 95 66 3A 6F 47 2B DE 7F 21C44(USS-1002) AES KEY F9 27 C6 A1 15 3D B2 D6 5F 73 6C 3A D9 E1 CE 76 21C44(USS-1002) AES IV
JigKick Key Expansion[edit | edit source]
$ ./aes_keyschedule.exe F47716E6C5649FD648538FD9773D12D1229E118737B1D782D6A80CD B72E4B9C3 K00: F47716E6C5649FD648538FD9773D12D1 K01: 229E118737B1D782D6A80CDB72E4B9C3 K02: 9C2138A65945A770111628A9662B3A78 K03: 116F913B26DE46B9F0764A628292F3A1 K04: D12C0AB58869ADC5997F856CFF54BF14 K05: 074F99C12191DF78D1E7951A537566BB K06: 481FE058C0764D9D5909C8F1A65D77E5 K07: 23036C180292B360D375267A800040C1 K08: 23169895E360D508BA691DF91C346A1C K09: BF1B6E84BD89DDE46EFCFB9EEEFCBB5F K10: 83FC57BD609C82B5DAF59F4CC6C1F550 K11: 0B6388D7B6EA5533D816AEAD36EA15F2 K12: 24A5DEB844395C0D9ECCC341580D3611 K13: 61B48D55D75ED8660F4876CB39A26339 K14: 5E5ECCAA1A6790A784AB53E6DCA665F7
- Some keys are repeated in the Ernie memory dump, as it seems Ernie stores many versions of code binaries. Maybe backup bank or updater.
Ernie Handshake Keys (not stored in Ernie)[edit | edit source]
These keysets are stored in second_loader and in many SMs.
Keyset 4[edit | edit source]
Step 2 AES128ECB key:
A6CD383341CB9B0D69FD4A243E30F4B1
Initial key to encrypt step 2 packet.
Step 3 AES128ECB key:
D3EFEDE608691946CB77E14F8DEC69FA
Intermediate key used to decrypt Syscon step 3 response.
Ernie communication session key AES128ECB master key:
15C7B32429F8603216F4F3E081D7C86D
Master key to generate Ernie communication session key (stored in Bigmac keyslot 0x511) by encrypting step 2 data.
Step 2 passphrase:
9ABD1B275C7537F7E62AB93AB3EB76F9
Checked by Syscon only.
Step 4-5 passphrase:
DC454ED5F6E8A2B1B24D34A82215B2A5
Checked by both Syscon (step 4) and cMeP (step 5) to ensure packet authenticity.
Keyset 6[edit | edit source]
Step 2 AES128ECB key:
1053143BEAECC59FCFF1A195F8F5AFB0
Initial key to encrypt step 2 packet.
Step 3 AES128ECB key:
F90CDCBF009BA8367F841B25E8B10306
Intermediate key used to decrypt Syscon step 3 response.
Ernie communication session key AES128ECB master key:
6F6374FD1A41A75269EE15832451DEBF
Master key to generate Ernie communication session key (stored in Bigmac keyslot 0x511) by encrypting step 2 data.
Step 2 passphrase:
B6806F9F58706D72B0E03717197D430C
Checked by Syscon only.
Step 4-5 passphrase:
0E08A20C8718BD3B158E2E6992202DE7
Checked by both Syscon (step 4) and cMeP (step 5) to ensure packet authenticity.
Keyset 0xC (AuthEtoI, similar to command 0xA0)[edit | edit source]
Step 2 AES128ECB key:
3CF54027DAE2F45C929B76927DFFD269
Initial key to encrypt step 2 packet.
Step 3 AES128ECB key:
39AF55239062D2F3F6CBB401EDC54C09
Intermediate key used to decrypt Syscon step 3 response.
Ernie communication session key AES128ECB master key:
00000000000000000000000000000000
Unused with command AuthEtoI.
Step 2 passphrase:
4231FFB14B941DBFEB44DFF97E64EC7D
Checked in Syscon only.
Keyset 0xE[edit | edit source]
Step 2 AES128ECB key:
E55364616CA8C3DD2859B1D913E1CC15
Initial key to encrypt step 2 packet.
Step 3 AES128ECB key:
02DA870FB5983DE568E324DDF5330C9D
Intermediate key used to decrypt Syscon step 3 response.
Ernie communication session key AES128ECB master key:
D606A99E381A4B440DB9A8A87F608F1B
Master key to generate Ernie communication session key (stored in Bigmac keyslot 0x511) by encrypting step 2 data.
Step 2 passphrase:
8082307DA258780D5088C40218B98EFC
Checked by Syscon only.
Step 4-5 passphrase:
D14A64DF4011E110325E159602F23BA7
Checked by both Syscon (step 4) and cMeP (step 5) to ensure packet authenticity.
Ernie SNVS Keys[edit | edit source]
Prototype Ernie SNVS Keys (min FW < 0.996)[edit | edit source]
Maybe also eMMC Keys.
These constant keys are used instead of per-console keys stored in Bigmac keyslots 0x502-0x504.
AES XTS Tweak Key[edit | edit source]
E122F9C47E1C94F082536A1F244B9A9C E08DA5E8E122F9C47E1C94F082536A1F
AES XTS Decryption Key[edit | edit source]
244B9A9CE08DA5E8E122F9C47E1C94F0 82536A1F244B9A9CE08DA5E8E122F9C4
HMAC-SHA256 Key[edit | edit source]
EDF481EF0AFF55CD1A643E8A7AF50911 36A7749CEDF481EF0AFF55CD1A643E8A
Mystery update_service_sm Keys[edit | edit source]
These keys are found in update_service_sm and are used for something unknown. They are not used by the PS Vita.
SCE WaterMark External (Not Used)[edit | edit source]
Exponent: 0x10001
P[edit | edit source]
EA236F5002D0B5EB937ED04E5A100276 26A47DB379E2B3049EA2CC6ED5E48B5A A8BA066A7827D2D5D83C238F7BA807B9 43E07616C77E69AA2A2FC447C3FC5A1B BB4678E6931078DA24DF6904E8F5C628 EFC79548F49D7665A8FA40B4B24679AB B4AADD00AF0829B0CB97A2A6FD44E813 BFCC06C46B1DB91E4CB30C992B255E21
Q[edit | edit source]
E22A87F84528A12EB31AAA6A8FC4D6EF 6352133A4D6ABDF917A0967370307E65 98216D4A251FFAFDDF41F79CFAF477D6 B7A513B953E0F42D27C5687EBE39FFF9 A48C6000D34F5FFE92FE1967C5B6E42A CC38FDB71294042FA0695F19C502FAD1 BD125672C0C20AD029B75379CCE2BBAA D88FE9EC4B3C18269CEEE87DA330DF99
DP[edit | edit source]
75F155A0335AD9590ADA85AA025A3033 3E31FC140DA0F1D6B0E6871E89E66F80 42A03A9D255BC22BF09A12BBB369A842 5DFBD2E094AB8C24A8CD990D219F9BF0 7E3CF8A8058AF5A5C58F38C2BD6B18E0 0431407518ABBD39668E714BD4C60582 46270FDEC94CCE5B7DA32BCEFCA3DA58 207471303E5921A82EB0BEF6E53214A1
DQ[edit | edit source]
2948B0373E9093138E3810E190CAD29D 32191A4F6B304FEB3747E60EBE6CEBB5 A9D67837AF9D2DD8C7B727F6ECCC514F CD880198B3D9FD587CC9093111924ECA 8821E3A862EA3B50A20E661ECE357B62 E0928AA5AF6B7B742228F9E61F5352EB 9442D3AAF0CABAE492A8D741058861CF 66E6A641AEDE125E82090E4158D7A409
DinvQ[edit | edit source]
68A77889A624A12BFF7013D4A390B101 77F18C6E2AA0894408B328F78A1DF319 B9C243C815C293A8B080C40849B811CE 1168821C3AF49F6B771F3DE4396F731E 4402679475F5379077B70FA44F495B1B 36B89F7E62C37333344F54FAE248CB69 EB92F540E65F50A1D19F98AA476EF103 71648229865145C3FE240F4BD6D83254
Modulus[edit | edit source]
CEDA2E70A6E473CB8F6CCBC808B75C88 C3B31125793EE135DDF2D36D68C22011 77079AF5234E8774B0634C6EAD9918C1 8024C67A4A4F4060B6C7AFE5E4BE6BE1 132CB334D0FABEBF64F5B23E711F8AF9 E7DE33C93239AD416DB61408A92CD768 687DCD5C37F2771F508790C461B3C475 8C5147FBE9C3A1F3A51898FD44BB6BAD ACEF2EB5CA7D48EFFDC27E9350A9A29C DBC478D5B8B64953DAEEF6A610E90B8A D6F5A65C3E44662F028F4415268BF184 B939E6FB0C754D8B29C6C82B654B46F6 6ACC1E29B7A359A88BB42CCD21D3D0A8 54065DF50A34A6D8B80C5E76583E0EB0 DA4A7E60032476DDFA6C94FC4056CBE2 B2E6841E502D53673F67B42DFF8400B9
Private[edit | edit source]
B3D81690734A253352DBF0C15672B5CD 62F9096B5F634043A9593A61E1B70652 A8FEBFC76A8F184E681DAD927CF4A305 79F87F684BBB63E9B2812379E9CB75D8 16E7C257A56A9CF5A33DCB5F66D359ED B59F07BF621FAB773B8017230093B025 62D41DFC93D807A1FE4E1F9BDEA681A5 01FE996B78EF529B976B2F78E48D5F2B ECFDBE4744369BC8889AEC72B2FD4685 0666D3BE61B21A85AB145240E4D4374A 7FFEFF13A77076B6C9297E3BF0DB6A64 B39B6175B86EAE1DDB02AEECA452C931 506D31BE5B1129A9883117A90BF579EA 0AD2DE86EFBB8E7C8275CC6E01B4296D 90F567B310DA64E0A356018C25D11241 71A21254346E24B2DD883480618DBC01
SCE WaterMark Internal (Not Used)[edit | edit source]
Exponent: 0x10001
P[edit | edit source]
E2946A07650E5C657AC662EB1A6DD6DF E44618AF35247EEF5E54559F581DBEAD 1AC2CF038ABF663344366F76E323F382 1A3F3699C972664E636E1373130E8AA3 71721B530CA58B8EA30E338AD1827FAC 8147AFE207B116CCEC9EB9D9C5A8D48F 788A98CE6B5E2A99FE27F7197A5D6548 93C84D4292F394C1A4CD6D09FF06F7E5
Q[edit | edit source]
D369EC809646C3D07EBA35124F20FA33 D7ADC2E1C1A31D5909533F88CEEE6AD3 BF0FDFAFE67165DAF7229CA4F230CB7C 2C7D4525A942637ABCB843A8C2388B27 88848689DA3423A0D9CA8837A7BC1D9D D5A89374689B77BC53C0FFB196A2A0F3 1D81E81F302A544C18942A44F08B8CF9 36D66ACA38512B5C5550AE178887151B
DP[edit | edit source]
2FB4FE2A366DF2A86F546C2982741425 2A24543837E14A54CE30C5A27A6430EC B3D0C6D3C11811C5C39C0E9622B74423 65B15FA6BBD2B995D1BBB09EAF2985A9 6A4E9350463E69070C70060C3996D799 13D36B461546853D7AA8E50AE4626AF7 1673603F3E3E228C30066C31D220EE1D 7CF854C42ABADCDC74FDC7F2ADDEE2BD
DQ[edit | edit source]
47054E6DE40DE1BA28D864FBC1995274 180047778F953C46ACDB4A7CAB076CDB B5539FD17798A09EEE66B238B723AD38 09BA0B809B5BB20F89565D6453DAAAE4 9CF7E83A67131CE4EC451D7D94DB9D17 68AF38D9E24A57EEEC33E9B1BEE8E328 C8C0DB399EF4995CF6E4CF4E598087DB 3090D74F179C2CF4D7B442C7A515BC01
DinvQ[edit | edit source]
5B917A6768A9912815A0F09D2A8AA77D 72F1230A81987BB9452EF03BE0B5B63F 10AA391219D3EA92A3F2330F6899B458 DF04818DF79E126E84293595EBC60275 D96FC1D4DEAA024FF59E4187934BCDA2 B11BD26D941E6FC4E979BD12DB197D2A D6EE300BA0E0A46CF2531B84F5F0102B B714B9D176C46A8BDF3CFA8CD4DF6EDF
Modulus[edit | edit source]
BB1E13963648B5EC36EC4DDD00DD3752 53B47A3FD452BB67F1FB8B0967DDAB08 AA82456200CC9006D27DD00144F36C5C 98EF4A2C53074C654978F49AE82E2589 887E2DF24E748BDB1B2EE222F8C6EC6E 0DF3C32666209882C008D66AEE35F18F D8A810B886B1A926C3C96906482FAB7B 103EF76900FE7C1DF13041051398CAE8 83B8485069F98CB78CD275C96714DB22 C91CF19B4BE2C77AC228C93DFA0B09DA ADE4ACFDA26D66DFFD18DDE58895A34C A6377C2594603FE41E0C5062150761D8 73FB5394D1032FC0929F9ED6C5BE051B 039C6C5BF5D92BEBC3EC83EC06E3CC7B 5EC1BCE445622741CD60BE2DDCF83848 BC86B3EBF987C438320B6DEAD9D4EE27
Private[edit | edit source]
57CA38AE5531B008EF8BD6CC45C78459 1FE4A126A95B5789E1427F6D1E4A2620 9EBF18066F118AD1689896AAC1CAE3A0 5E3086C05D042397B1ED09F653D0B2D3 E03233246822CE2B3289C0975FD914BC 5DD76C4BEBC687477109B46FDEEB7836 611419243A2DC88AE378EFC97EBCBEDB B23798A4AF4EB6B4E5A01A21639C6036 0177A834BD946F442BF650F59030FF2F 28A18A31B6D45463FF8A7701764916C1 8E7A12B0848146B1FB1120405DD5A848 0D0C0C97DE5C2FC162362FCA01C71AE7 87C4040DA1D36EFAA318F91960FAB59E 76251FE9F34A91DCD2938FAFE2DA2E93 F2B6F53739616158064D1D3546F25B8C 8E9AA4D58542F3FDC91793ABD8EA6061
PKG HMAC Keys[edit | edit source]
- present in 0.920 os0 update_service_sm I
DBE1A473887A076D204B6CE361EFE4B9 C540E10B7EEE29C0A225CDAE10E6134C 59D6CDA0F426D9F0B4F8C5BAA0EF397B D38FB0F9B9100B4615816B1F6810D651 F8EAFE04E0A66FCDDCD6CD2746DEBBEE 81C614EED15E02CFA9D1F87F64AE7597 B38B2AA048A3E0B14DA36904B01E4DAA C1317E63E6DE80196EBE2D0CC2715494 A6E0B640BEEC23CC82DEDE0A227C5A58 89D238906A7EFE369596A1346F0B3547 2654F43DEE032837601A3246514DF4E2 E109829A60ABD62521EFE0FAC812E6DD 8D814CE4C9C3298346F74079F077A2C8 4BA0EA40E7BF55305F24976E2E3F7D97 D37DC6B65149FF8560199FABF74A495E 569EFEB78B4E128F914367C953405C13 5C93D3939B27B2CABD19848FF9075E81 00C92BBC9D4B5D1A4D135ADDE1FBD71B 66B724BDBA101D6A3057234895393610 91ED466F251A38EE90825F6287DC8C77 C7939B509967CE44A815F3D3A69F3BCA 24080619F39B8B0D3EC22BFBE584D7C2 B7124FD11B94F8004AD477AE689D0C1D B3B4E59E880163B279C83671F22FD285 7721C65140A2CA799F366C7275C09F9D A03F12CC9D71C4BE21209167D403E834 9A831933A1D109D24DC850246D39EEEC CA64137119A95F5FB57E0EC310C2A73E AF92C200B8EBCA305C1D1273B636F912 B23247A4C573A69BA525D3AD5177F3EE C45764EF426B6DA37AB25C37D5EE99AB 7ABDFCC9ED82C94C3016EDD295872061 C80EAAB7E368851BCC3319D806D5B5E6 AF613993B86F437AF05528219C549256 AC26FE362692EC55152E706CBB078A7A 0B35A20425BD8A18C581622359EEF7AE B68C19699474A019CA7BAE575B1F5B7C 6DD7A4C115B208666A9A93418DA224B7 A202B21059BEA357A96B5A6D7AF01E9E 97CF303CA1207F58743E83CED77700BF
KIRK command 7 New Keys[edit | edit source]
kirk7_key80 = 83FFF149A687A5C5CD95779352C8BF66 kirk7_key81 = D83D2D277CE2DE154A4E2AA6D1E8D20B kirk7_key82 = 4C5C71519F62A5FE5EF36D4B075BE2F3 kirk7_key83 = 8005EF43124F650A9DF158F72A509C10 kirk7_keyC0 = BF57AEF02DC587F327C8C3F8BDECA5EE kirk7_keyC1 = 9FFF2EECED8476D900DFD579E1AAAB63 kirk7_keyC2 = 04460D61F563D46C0C4EB9AAE5466E84 kirk7_keyC3 = 1E5B17DAC321E6B8DFE7718CA2930370
IdStorage Keys[edit | edit source]
PS Vita IdStorage leaves 0-0x7D RSA2048 Public Key[edit | edit source]
E9 18 F0 8E F8 D1 ED 4A 5E 80 65 44 15 5D AF 3E 99 CD 65 65 5C 5D FE BC BA 59 A4 AB 52 81 63 53 B1 DC 9C 0E BB 70 F7 48 57 47 9C 4C 49 00 8E E4 F7 55 93 14 71 67 DF 9C 92 8E D8 42 4A 10 75 50 D0 9F 6A 48 57 9A E3 86 BF 6B A3 0C 73 57 00 DC F7 CB 2B B3 7C 03 11 CC EC D9 0F BA A1 2E E5 EE 5C D3 10 D5 0F 1D 58 C1 23 8B CD 7B 9E E6 2C 7F 4C AE 11 01 8C A5 AE F0 D5 C2 8D 5E E9 F6 6F 1E 37 8B B4 BD BC C0 2F 3D 3D 6E F8 E6 35 EF B6 C2 EF 82 ED AD 07 16 5A 4D A4 AB 83 76 14 9D 6F 29 6D AD DA 83 CF 0D F3 9F 9C 6B AC 79 61 B6 6F 32 60 34 99 B4 C3 9C 94 D7 1A 29 8A B4 12 D8 42 F9 69 C3 0E 47 EF 86 FD 35 E5 CD 23 E8 95 B3 E1 A3 D6 E9 CA 90 8F 46 59 FE BC B3 00 C0 9C E7 34 07 5A 7F 85 2A 5B AD 82 B8 52 85 74 6F 73 45 C2 5F 4B 7A 8D 85 70 8B 6C FD AA 59 70 BF 33 00 79 D5
- Exponent is 65537.
- Found in PS Vita factTest.self.
- Signature is stored in PS Vita IdStorage leaf 0x7E offset 0x60.
- PSP IdStorage does not have this signature.
- This signature does not seem to be checked on console boot. It might be used only during manufacturing/servicing to ensure that IdStorage leaves 0-0x7D have been written correctly. This implies that IdStorage leaves 0-0x7D are not meant to be edited after manufacturing, contrarly to some other leaves.
IdStorage Certificate Keys[edit | edit source]
IdStorage Certificates ECDSA Public Keys (160 bit)[edit | edit source]
PSP Certificates[edit | edit source]
4004C80BD9C8BA38221065923E324B5F0EC165ED6CFF7D9F2C420B84DFDA6E96C0AEE29927BCAF1E Sec.0 PSP IDPS 06485FD029853B552F7EFDD67A2DE7A1A4E25537B2459D8786426D5B27EFA5A9311CB8ABABFA0ECE Sec.1 PSP IDPS 3F8C34F210AEC48E1520FF2A44899E054A0DA33DF8B9754B09C0EC7E61867A5126FE6926972196F5 Sec.2 PSP IDPS CCB3440DC4836DD519E13B2805B30870DCAEE462136B3888651A98E02B29FA0CD34F1616F1ED5786 Sec.3 PSP IDPS 08B336925C2B445D03A9BE51B9AABF54E4CC142EA72A23BB8060B03B71CDE0772DE82AD8931648D6 Sec.4 PSP IDPS 4F0A2BC9987640860E22EE5D86087C9692470BDF59DC4C1F2E38F92CE7B66875B59ED10C9D84FA6A Sec.5 PSP PSID
PS3 Certificates[edit | edit source]
94D100BE6E24991D65D93F3DA938858CEC2D133051F47DB4287AC86631719B31573EF7CCE071CA8A Sec.0 PS3 IDPS 071984A1F27D1E91196410D57C828AF7115BF1A32071AA1EC25B7FBF4884F5322A26483C46D8B43C Sec.1 PS3 IDPS 1B6389CECD99843CA088E325C796F510A151C1545C5DE4E37A1D892D2504A8604C094F59063D589F Sec.2 PS3 IDPS 17BE639B87F138049D94398E8929DE535D1CB0DC5E7C04D720D2F3DE86F9B581DD1B6F7CDCF80DE4 Sec.4 PS3 IDPS 4B4F044420207907E3BC7D5423FF4D05E9DAA10B1F973327F7FEDEAE498BC656FF7C7459C9B993F4 Sec.5 PS3 IDPS 1F960A3BD61462553A0DC015AEC66C818CBAA8F62F733AC9F0C287D496F321058AC26669ECBED3DB Sec.6 PS3 PSID
IdStorage Certificates ECDSA Public Keys (224 bit)[edit | edit source]
PS Vita Certificates[edit | edit source]
1A9146C3AB04FBA1C32027C47C7906947CC2AB1E247AF59A8D714AF44CA559E78A2C164A77DAD5A878F516E4D905D810C73C39E70EA93198 Sec.0 PS Vita IDPS A17772FD3E86091EAE2B246D5E05CE80A8E24A03C6764D26CD2443AE3DD656F919A10F87C67CB2AE280D0751E15ECD3C4FDFC9D71D7F067C Sec.1 PS Vita IDPS 056891AE27047A7D5DE88C57612E1A7D0A7CCD369E8CF2F8F374FEA34155B20B613236C2BDFFE8187AC09C7EDF194D81A440BEB91DC6F257 Sec.2 PS Vita IDPS 6B0AB6A5570334E8B559CC06BA811618ADD2A1EC587A98D35A04E8B98B1D5903711469EE3049B06E1EC81EEB72A9E181D5920B453CF2C21F Sec.3 PS Vita IDPS 1C1816019AE3F8955021892257535F0E92D988E11EA45C2E908E2E208C10F3D7F3ED189EEFC027C8A91B6770A727402423CE976A3435FF8A Sec.4 PS Vita IDPS 108464CCDB76611475AEA911FBD1D476FF41F1C70D811031C552DB9B85E9941A3FD79644B717E0FEE48C4CF7387CF10E900BDBC2D7A35F5D Sec.5 PS Vita PSID
GC Auth Mgr ECDSA Keys[edit | edit source]
160 bit Curve[edit | edit source]
p=FFFFFFFFFFFFFFFF00000001FFFFFFFFFFFFFFFF a=FFFFFFFFFFFFFFFF00000001FFFFFFFFFFFFFFFC b=A68BEDC33418029C1D3CE33B9A321FCCBB9E0F0B N=FFFFFFFFFFFFFFFEFFFFB5AE3C523E63944F2127 Gx=128EC4256487FD8FDF64E2437BC0A1F6D5AFDE2C Gy=5958557EB1DB001260425524DBC379D5AC5F4ADF
160 bit Public Key[edit | edit source]
Qx:55D73E67B84E15B2F28C3B1F6C9DCE2911E3B4ED Qy:0333EEDA263BC89B7696AB5C6B69E18BF1785A80
160 bit Private Key[edit | edit source]
53CCC36EDFADBE245583270552D23B22518EE3A8
- Seen on FW 3.70.
- Used by Kirk command 0x21 (related to new PS Vita NPDRM PKG files).
224 bit Curve[edit | edit source]
p=A53E113E46D8C9C1F09D9BCB2A5373D379F69DA28D09999FED57A90F a=A53E113E46D8C9C1F09D9BCB2A5373D379F69DA28D09999FED57A90C b=9065941D29374A8F11DD1E540189434E4A6EBFAF5477F6C172F6855E N=A53E113E46D8C9C1F09D9BCB2A522698DEEF58DB1AD9AB7F04E3AE7F Gx=7E06098247E6B59F3110BCBB3AB6C250BC5AB06C032DAD43684C248F Gy=0BD9418DE8E3E45D2D701E0237FD7F2ADE0D48B74CEEF2F1C8AC484E
224 bit Public Key[edit | edit source]
Qx:5F9D171A2BDDA8D40878BF985AC326ED5EFF43C9376C77EC0A00C7BB Qy:A344E44E6EAC255235F954F5B617C7BD49F180262454AAE1B62A9F2C
Qx:67002D9BB8E42D2BF9610B27FEAB9B34561550921312DFEE7A3A86EC Qy:6CA714426F6D4E9609A638BF4AFB182BFA50C82FF2B4C5EC6CCD9765
224 bit Private Key[edit | edit source]
767436A6999D88480EC856F55CEABB4396859E374599403921F55598
- Seen on FW 1.50.
- Used by Kirk command 0x22.
607A2E5568B4B9A032F45253CFED20DB2E6E446C3782E82A1AB9C923
- Seen on FW 3.70.
- Used by Kirk command 0x22.
MSIF Key / Memory Card Auth Key[edit | edit source]
D419A2EB9D61A52F4FA28B27E32FCDD7E0048D443D63C92C0B27135541D92EC4
PocketStation Keys[edit | edit source]
texture.enc key[edit | edit source]
5B27B12FCB513F79A3B610D912B09CF5
texture.enc iv[edit | edit source]
72D859C6642BE65CF0BE141B84B93AA8
MCX.BIN key[edit | edit source]
81D9CCE971A9499B04ADDC48307F0792
MCX.BIN iv[edit | edit source]
13C2E7694BEC696D52CF00092AC1F272
PSM Keys[edit | edit source]
Update HMAC Key[edit | edit source]
5AE4E16B214290E14366E5B653C4E3C3E69E4956510EADD66ACB37A077E0686E 086F8BAB5030E3D82407F01B676CB8037DF20D1420C08A91A2141A3FE5DC063C
how to calculate update URL:
HmacSha1("NPPA00236_00", hmackey) => 87b2fc0108d5197ae7572bda397dd8a81b56839e
append first 8 characters of hex encoded hmac; like such: "NPPA00236_00_87B2FC01"
update xml is => http://psm-pkg.np.dl.playstation.net/psm/np/NPPA/NPPA00236_00_87B2FC01/version.xml
you can get the PKG for any PSM application like so:
take "appVersion" from version.xml => "1.00"
build PKG link using version => http://psm-pkg.np.dl.playstation.net/psm/np/NPPA/NPPA00236_00_87B2FC01/1.00/NPPA00236_00.pkg
you can also get screenshots and description of the application; using /metadata.xml; for example;
http://psm-pkg.np.dl.playstation.net/psm/np/NPPA/NPPA00236_00_87B2FC01/1.00/metadata.xml
(note; you have to change the domain to zeus.dl.playstation.net as sony removed the "psm-pkg.np.dl.playstation.net" subdomain awhile ago)
'psm.pub' strong name public key[edit | edit source]
Used for verifying strong name signature of runtime's Mono/.NET assemblies;
00240000048000009400000006020000002400005253413100040000110000009133D396CA929938BC68440B541D8888614E7BD475B EF719AB4F4B85B1C21FC3EF2B5F32DF0DE7C769CA90687650DA49EEBE7ADCB71479F1463E10902CB65A1F44FA2E71B3F30E108FE0F6 699D179DAED5B1A774DB1ABA104C59118544B47CDA724AEA8E6899FA760DFE0BA8656515B48AE94FDE29FC8F5BD569126C7A9AE6F3
PSM Developer Assistant[edit | edit source]
Keys used in the PlayStation Mobile Development Assistant and PlayStation Mobile Development Assistant for Unity applications
"protected_kconsole_cache.dat" HMAC Key[edit | edit source]
B73966320E286ADC03F05465CA9E2F92388AEE236D43883135BAB0A5BD5043EA
"NSXVID-PSS.VT.WW-GLOBAL.xml" RSA Private[edit | edit source]
-----BEGIN PRIVATE KEY----- MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQCxl+8fRzDzyWb0 89L9ssKWMO4IYJATVV/qsGPqL5XtgjqlSY6dV3QHWtdiqm4B9h8cy325+XEORMC8 oErllSl7yovu956/D5laLLGqRkyFPcNer+DOjO99bDfJTTV1bSHuwc9oo3mJn6AO WuiY3aguCIYxNgSlDsfavjmCDXa3Q85hFOxJnn7HlM4X6rNxFi9y48LqUrDyWw0L bs+07bqNLoYHXtMoZcNQHqNmGtIHGx4RuFzZ4hduorjNsmSKHiQSz+ydJgJWtLJO tC2EM8zj8zStmlDiMTyAqKPHjENp4FBLoF87PISLsbyf4dTdWk35TvnsU/+tGVyH bVNcEAzvAgMBAAECggEBAKSil//kDIKD/BkrDDc6h9+aHqDPe+EgbVnxCb8pPBFB gEKIbVh5oUvMMA38txzEYNVd5AELOH6kyBRVePlajWmAPLddAOJYgK6y7kVPBFMl Db/yxjJVPxODxjeshtmEQUfIjhGQMvSdcVC9gBFusyFxr41haW7mw+mKHV/uQVbk TM/ZnEaN2Zrl7FfCUwXa3qyMrwj01bbAXXEqdM9ZF3UIXCLzihtNDKPAbpcVoQXH fItXVFeHjXqVCOVcKTI1PgElM6Q7VsVsU4pJGOmKy2gFbKqF4eniDK6gdGitbVpp rlXIrS2P8ZOfT+fSMjLbrr+mJEc2np4LYFlEHcJgtkkCgYEAwMrmf1LasiU/sijh 0fOTV6TXefSrOxnpiq9Qs/oTSZ5USTh5FrunF0dX5Isy4XjYKWfIVwVl9LnAXRqR QTiHkbFon2KMYYyQfDUe4T9kuX6cAqp8WjBaivxs8chErM8rzZns62bR1B9+/IX4 VIiHA1jfP9eiCl+1lMhhnnNIHX0CgYEA69Ffc2w5UCJ1cHxu8dR9V4otY57vBJFN 2Svb8h3kJnO9LfU/RYMeXTgJSklh9Tw/zXPOMEQnxi7LocrDd1713vQTTspT3wWd 3AJ25l0BP3NGnbEtGwv6It+VnUULr964vOUv/bl4UMQs52JsnxURts+GPZ3gAF1S U2AVxvVej9sCgYBAk7Yhb99RTKjJRGhfqvbvpIeIkivI4CUaDx85KcrMHfydig0F UFXntj36j6W7YH8HX3v7qhM8pfuJNBzze7vtUT96I8hh5HOBJ0nwqQtUFtSrD/AX RZsOcv8K/coDGGHTvHtfXlFqfCJM85L6vcB7nokpGVFtqCFqdLQ+Ht9JAQKBgQCU Ao/0dCLs5xPrDE7ePk6FmVavxlui9Eh2XI7qQlSmxdIhfGLAEHIIdFlwZOq076Hk JCFwLfcA7vIklI1m6RVNYMiVlWxa+L2CD5HtOMbFumbCJyh2Z2gSZ18SnPme4x30 ga1DhRu9JcRBXodqueCqa0qIdgTYdbpsVkyU2gEGLQKBgGotuH/yrXNfifTc6Y24 TSaqk/Dq6OvQOEFSIzgOzaQhWvwZjlz3uOnmi3vUo/guG9q/J1JWucWoXNXkkcmb trc3RYwzy6Rn+0uGHGA91e2bn6vT6PLNOgNUE7YCRDJe5DsDYHtUNILNbRVdSvNs rnh1i22Y3zLWChh3swswqgf7 -----END PRIVATE KEY-----
- Used by the PSM Dev Assistant to sign the NSXVID-PSS.VT.WW-GLOBAL.xml file to prevent from modification.
Publishing License PKCS12 Import Password[edit | edit source]
password
Publishing License PKCS12 PEM Pass Phrase[edit | edit source]
password
- PKCS12 certificate used in signing PSM Dev PSSE with PSM SDK.
(World's most secure passwords ever, impossible to crack)
You can use openssl like so:
openssl pkcs12 -in <filename> -password pass:password -passout pass:password
to view the private and public keys of a PSM Publishing license.
PSM Android[edit | edit source]
These keys are labeled within the debug symbols of the Android version of PSM.
SCE_PSM_KDBG_ACCOUNT_KEY[edit | edit source]
965895DF95F5432CCBCC4B7823CBF4B3
SCE_PSM_KDBG_ACCOUNT_IV[edit | edit source]
00000000000000000000000000000000
SCE_PSM_KDBG_C1_KEY[edit | edit source]
965895DF95F5432CCBCC4B7823CBF4B3
SCE_PSM_KDBG_C1_IV[edit | edit source]
00000000000000000000000000000000
SCE_PSM_KDBG_CONSOLE_KEY[edit | edit source]
8235EDC66CD14D04F793369A74C7A4FE
SCE_PSM_KDBG_CONSOLE_IV[edit | edit source]
00000000000000000000000000000000
SCE_PSM_KDBG_LOGINFO_KEY[edit | edit source]
B293993BB5977F88844A7D21DDF63BC7
SCE_PSM_KDBG_LOGINFO_IV[edit | edit source]
00000000000000000000000000000000
SCE_PSM_KDBG_V1_KEY[edit | edit source]
14E5A03B1E62D483F88769986EDB1140
SCE_PSM_KDBG_V1_IV[edit | edit source]
00000000000000000000000000000000
SCE_PSM_HEADER_SIGNATURE_PUB_KEY[edit | edit source]
3082010A0282010100A98F6B27F5AFF0F96C7411A337DFCF723C37BEF6FF6552B 8E5A3EEE3672CF0366EA0442B7913018C7355C0F2336DE496DCADE8BF5A32D1DB 25705D5A9A11C06FFF6801776BFF871FDDDC4EA4CAF49886E02D4835B3DCC9674 457E4E66744CB997155271C211E2FAE0ECEA5FABD91719766C488860072E81CCC 7B5DFEA0907D25E60CCB28500D3FDC9CC244DBBAED7A41FDA571C27D87E92B17E 34B0289329EB0FEFED4682F1679D89FF00D2A78F78B8A05A9B4D7306E992AAE7B 7A0E9ADDF4F4BC286E1E52A80AB2DF31012B18B996670446F07AF2307A7FFCBC4 5ADB3B815B659536A7AADA813FD303156C792E28157001DC7BB9AF93A59A607E4 F2EE34F88702030100010000
SCE_PSM_WHOLE_SIGNATURE_PUB_KEY[edit | edit source]
3082010A0282010100D452C18752BDE6289ACEB862AD32145322C13EEC82F5675 E9DA96B51CCAA68488F2B5E09E1C1DEFE7A27ECB5EACF473A9D15171F43EE32DA 03E7BA07182B408540C37CD8AA357F4DCD12295AD3901D6A0D6D41665BA7084B1 A98DFE15A1F0B3A2A4B4D0A00A1CD8BA5B09E80BC4E2C588357C0F2E285C05055 6DC971A43FEA4C056CF2DFD8BB2EE975F67F76878E1FB01E7A23F87FD5732864D D62B2C3FFD4BCF184923A3706819467723AA508FC53E80F6E5A57CF3E7B1BB0A3 988037656CBB2FC70BDF344B5683E4943D08C609D44DFDAE90C5300C5CDE7C2D8 9035B20FC189F9DBC34BEB6478D6B32183FB886133B04C1962EEEDA7FFD47DB80 655F4CDE0F02030100010000
internalKey (KeyStore)[edit | edit source]
534B4257020000000000000010000000002F27E9ECD4606C3CE0BCFE99E2AE5EB F000102030405060708090A0B0C0D0E0FB747787D7742E60223E2B7C58E4F0F6C 00000001A02C5BA09F9DD01D40D19006A5A9E5C2F1AD690470726F74000000109 0AD6840B2876C1B5B580B0B39B1292F0000000000000000000000000000000089 E83746A9819C60AB7ED23B8D7685612A831C41000000
internalIcvKey (KeyStore)[edit | edit source]
534B4257020000000000000010000000002F27E9ECD4606C3CE0BCFE99E2AE5EB F000102030405060708090A0B0C0D0E0F0458D907E9B5EF926EA235615A4C09AF 000000018AE457BF9465071664521E2C0468FA010D8260CD70726F7400000010F C026F69D7A98767567BF04C95074B4C00000000000000000000000000000000BB 6E2E9E14AB8D04309918ABD4186B5798F48C78000000
PSSE (PlayStation Suite Encryption)[edit | edit source]
PSSE is the encryption of PSM application files, the whole game is encrypted and it server a similar function as PFS for the PSVita.
Header IV[edit | edit source]
000102030405060708090A0B0C0D0E0F
Header Key[edit | edit source]
4E298B40F531F469D21F75B133C307BE
App Key[edit | edit source]
For decrypting PSSE files with IP9100-NPXS10074_00-0000000000000000 as content id
A8693C4DF0AEEDBC9ABFD8213692912D
Debug Header Key[edit | edit source]
When you encrypt files locally for use in PSM Dev Assistant, using PSM SDK's "psm_encryptor64.dll" the following header key is used INSTEAD of the retail one.
00112233445566778899AABBCCDDEEFF
Hash Account ID[edit | edit source]
used for calculating "Unique ID" in Sce.PlayStation.Core.Services.AccountInformation.UniqueID
Hash Account ID HMAC-SHA256 key[edit | edit source]
BDEE3E0B93073749856F25CCDB443AFB0FAB94287493DC1AD0C5697E2A7AE14E
Hash Account ID AES-128-CBC Key[edit | edit source]
5AA3DB8FE6AEE26CD185B086F5BD78A4
Hash Account ID AES-128-CBC Iv[edit | edit source]
00000000000000000000000000000000
How to calculate UniqueID:
get psn accountid; => 0123456789abcdef (example)
sha256hmac(accountid, hmackey) => 4653ec6275f410c47d280a3688a554a579a7e7c9f52599381ae9ee4a1b6220e3
trim hmac to first 8 bytes => 4653ec6275f410c4
append trimmed hmac to accountid => 0123456789abcdef4653ec6275f410c4
aes128cbc(accountid + trimhmac, key, iv) => c7656d883573d94809c8fa05f511d84f
so "c7656d883573d94809c8fa05f511d84f" is the "UniqueID"
EncDec Keys[edit | edit source]
External[edit | edit source]
01: 4E953B7F820562D4C94DB42034D0E26F6B855BDA78A53DDBA5FE92473DE6A1B3 02: EA3B52CB07B80B242E772B7FD70B74433DAECD531F97BD1266CBD2FC63139183 03: 631A57F5462BA3FD177F973F2062EC4826D0935D0DC65DEEF6C99E8AC69511C7 (Passphrase) 04: 24B5B7E071927DEB44C3F5D29EFCADF5CBB923972283EC15370A0AF26F98FB95 05: 569C77212725F9FEF41661F15978A6744C0F029FACE221D751958CA085FE6153 (Passphrase) 06: DEAD01085F00D513C35DB4C51EE2EC2750E5A0CBEF8147B4020805068A2BF34B 07: FCDF261E1D91D3DF790B1B8989E046EB5BE0EB772EAF4BE3F6F58C02C4296C52 08: E081D77FFDD4C000BA5E6C6F7BD89D8681590DDF5AC2BF59F42EF5AD48B032E7 09: 5CB92AAD7C977D1DADAF984F2272422B501AD73CC07761E3FAB9893D5B9796E5 10: F7413D73398A51B0EBF9FAD5BE26F76C21C766B351E4686F45B159A7E37E3DD2 11: 397410772097765634EB696EF5827F073484844DF54FAF2BEFBECBC031F3CAD5 12: 5D5DC4065A8F77D360F4FAF369512F0D6B38F2B4117A44A2F8E23CC0E4EB3C25 13: B4D1061ABEADF11A72F34632D7C2D4203583765B462F74FB6D200740E4D6460B 14: DEF0247032D97B7D1F26825AC86F9A6CAABFA3703E48492C9EC6523F317557F7 15: 704D524C293CBFBAEE284DA219A74304CF3F7E86DC1A989939349B62A7679742 16: 4CC2EE15AA17D0876EFC88DF22C8B4EB6ECDAA407E5C2931B7A946E95BEECD50 17: F083FE77B664DDECE7707682A63176581A1B5841E66088F5889E43574A2F8208 18: 5B596C1D36C4C6F078995F942F680FC13FA0AD8AB154E7AF0505A797006C85A9 19: 1F3558EDC5AC0B5F7ED2EDAB8E713760C375835E6912EE5758D3D6D6E7A58D40 20: 21B66BAE9C895D95757148DE3E471E94CE8A254B9520657B34C92DCE6B66DDA6
Internal[edit | edit source]
01: 5811E08CE7C304BD38AF116252A9074703AE23EF1C80CBD55A407A3322C0286D 02: 135521CCC5A50572F9E69A93C1E41FFD30D7FE1F6F993E27F427364D18F45D2C 03: 9CDA12AE5607B2355161FF1B178C62DFFA428C1C29C505290D6B5580691E1FF1 04: 4A37E813D3044A72BC0BDC7E267C15070E44F9205B969743A7CF65498A026BF3 05: C197B0F923F92BB7E64B81F841057DE06123B6FA5447506E7EE0F9EFEAE89289 06: 155F7DCAEF58D2E5CB92286FF57A4DA1FB5623D83B62ABE438B6B92D04CF6DC4 07: C8BFADC3856B9CCB347D07428BB01FC150D2DDD8E799DA555398D3512781C8A3 08: B6CBB3E7C258AFC744F536622096FF3572603D3B349F6D2AB1D7748ABE28D003 09: D30ACA5121A4DF81B38085557F356B70E5F962B1CE116A83A6498402DBAE3140 10: CD053F1B107CE42875EBFD94095ABFA619B31FD2E2677B740039A3E500188454
Prototype[edit | edit source]
01: 5811E08CE7C304BD38AF116252A9074703AE23EF1C80CBD55A407A3322C0286D 02: 500AF8A3EC80F3F42E89D18DEC2BB799548CCAF3D5BA578AE6E5CD0DCA2748E9 03: 49BE3301F6E35174EA36D47023F9D61CD99ACE5777C9D68E304AEEA9B88AEE1F 04: 24B5DECE1EAC6F10E6671B47370CDD3AD08440422A29162F3EE7528793943BD1 05: 8E13D964BE8377845DEB09596EAFA0A58CC524DE003C4D63CF98AAAC60BE6C04 06: F96C4721373759EC6F4A9DCEEFCE266C40C87C702EE22D936E25D075A98FEC88 07: 63A4ED2233D2F468C4C2A2E6BBF3854A326895D7826100CB5D50F946CF3312E4 08: 36E8F8B5196CFF961443C0BFDA702852000C1E6BBE5EDE78AFF3BB08D88AC6AC 09: E137A8068F015BBA1D1ABBFD5753D1F9436E55B0F277818A841C66CAC99475BF 10: A788C670A1E8AB723CEB3016C21BA1A1EE817F6BE5EF12DA4D0FE21F4D5DFAA3
QAF Keys[edit | edit source]
Token External Modulus[edit | edit source]
D2 CE 7D 0F 4B FC A7 88 B0 66 8F 65 6D 4F 56 C2 A9 95 CF 75 02 52 91 36 81 A3 50 44 8F 3A 09 1E BA 02 12 37 9F 72 D7 A8 D7 C2 9A E4 E2 8D 5D 62 84 FA D5 39 A0 70 B1 12 51 FC 55 F2 B5 59 D3 0F 51 76 29 C7 38 CF B8 95 0D B6 02 BA D2 1D 92 78 D1 DD 75 41 C0 A2 27 A6 E0 2F 1B 26 1D A7 DD 08 8F 2F 43 99 AE 54 BB 8D 1C E5 97 63 05 07 18 8C A9 AB EF 57 26 64 3D 22 F4 CD 78 09 DE C5 6F 0B FF 16 CC 24 44 35 EF B6 19 F6 19 2E BF FA 5F FE A6 F5 76 66 46 32 18 BB 7C B0 78 A8 C4 E9 86 16 01 F9 A6 B7 DE 41 DD E5 1C A5 8D 2D 85 F8 4F 54 D2 40 BA A6 9F 70 68 32 5B BD 13 ED 2F 6E 34 4F 8D 54 9E F7 A9 A5 9B 7C 5F 89 B3 21 B0 91 20 00 81 56 0A 02 17 3A 48 DC 9A 6D FF 25 C4 FC 56 3D 13 B9 E3 81 37 83 05 D6 22 3B 87 C9 72 3A 8E 9B 7F B4 FE 39 FF 16 9F A8 ED EE CB 8B A9 62 8E 77
Token Internal Modulus[edit | edit source]
CF E6 7B BB B3 5F 31 91 5C F5 B4 1B 57 95 A3 A3 5B 2C 76 B3 97 85 F3 4D A8 F4 72 67 A3 07 01 BC CD BF 75 A2 AD 94 67 BD E0 C4 19 9A A0 2A B8 7F AF 37 93 7F 3B 7D BC 57 F6 CA 62 D9 68 55 B8 6A F6 97 A8 71 78 B3 7A 26 4E 4F 81 47 12 41 E9 10 04 E5 9F 19 1A 31 2E B9 29 14 2A 90 79 CE 89 6B 3D FE DF E9 58 87 B1 9D DF B1 00 59 DA 1F 61 00 55 D5 C4 EF AE 92 7A 18 7E 85 81 5C 32 6F D1 A1 2A 2B 56 B7 84 DA 71 2B 54 CA DC 01 9C 2B 13 16 53 D5 D4 49 6C F7 C3 DE F2 E6 9E 8F 97 26 6E 2D 84 D0 07 1A 80 15 0F 0A 4F 9E 3B D2 7F 4D 79 D8 E5 8F D7 73 62 7B 4D DD 93 CE AB 90 D5 9F EB B0 2E 81 3F BA 9D 5A DB A0 88 72 AB 92 C5 B2 5A EA 96 F0 C2 DD AE 1F FD 82 21 5F 26 2A 34 11 C7 3B 09 33 16 1F AB FA BA D3 29 1A 29 4A D6 5E AD A1 A7 ED 6D 30 3F 17 D1 76 61 8E 52 2E 09 4B DC C3
Internal Token Encryption Keys[edit | edit source]
OLD KEY[edit | edit source]
A3822022A2B98951B7835E196C004BDF28E89C645EB368FCFD94495D128F0EFC
KEY[edit | edit source]
0E04E91805B1BA0E07474DD257A6063AB60D1296B6DAC572AC3E036D88770F2C
OLD IV[edit | edit source]
E588E6312554F4DC665F057877D878A4
IV[edit | edit source]
456286F824DAB499BCFD78928C1BA93F
CMAC KEY[edit | edit source]
0E04E91805B1BA0E07474DD257A6063AB60D1296B6DAC572AC3E036D88770F2C
Proto Token Encryption Keys[edit | edit source]
KEY[edit | edit source]
B64C38B4EFDD74C929090B985A215999FC6826244DB5EC2D5D832636560315AF
IV[edit | edit source]
695570C72F2384EA2D439106CFB2B3CF
External Token Encryption Keys[edit | edit source]
KEY[edit | edit source]
6C1C31251E7BF435F3E232ECDBFCB9D647A31A4D2954F1CC718FA92F63E30A73
IV[edit | edit source]
11295CABDE7337EC8F29DD451D387CB2
CMAC KEY[edit | edit source]
6C1C31251E7BF435F3E232ECDBFCB9D647A31A4D2954F1CC718FA92F63E30A73
F00D keys[edit | edit source]
TO BE !MERGED! WITH [2].
Module | Algorithm | Keyset (Internal / Prototype / External) | Version | Comments | ERK | RIV | PUBLIC |
---|---|---|---|---|---|---|---|
Secure ENC: second_loader and secure_kernel | AES128-CBC | ALL (SD, DEM, CEM, PDEL, PTEL, PCH, VTE) |
0.930 - 3.69 | 0x10 = data size; 0x20 = hash; 0x40 = version; 0xE0 = Encrypted header (0x1E0); 0x2C0 = data segment. | AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA |
AF5F2CB04AC1751ABF51CEF1C8096210 |
unknown |
Secure ENC: second_loader and secure_kernel | AES128-CBC | ALL (SD, DEM, CEM, PDEL, PTEL, PCH, VTE) |
3.70 - 3.74 | 0x10 = data size; 0x20 = hash; 0x40 = version; 0xE0 = Encrypted header (0x1E0); 0x2C0 = data segment. | 7CE42822813F360928801C59E01622AB 7CE42822813F360928801C59E01622AB8E0840ABC5A27AE768F9C7B06C7C6EE0 (full keyslot) |
AF5F2CB04AC1751ABF51CEF1C8096210 |
unknown |
SPKG | Certified File | Internal (System Debugger) |
0.920+ | n/a | 23F1D525244266E6DA7A52DA9446318301EE8CC58D54901AE94D93010F7DEE6B |
3721F7C05DE5F55ECC39BDDB4A6C585D |
BD824E911F2F61AEC796A1B930D181A5 27B49C798F46945982603ED32FFE0AAA 3DBF62E85858589D81A92917F8CCF139 0E6537D83DFC56DCC17D81EBE5F7FCE8 AF002397F9EBF1867EB4A461ADF5E8AB FF2127CBA6467EAACC5E19ADBD1290BA 824E14D1443A438DFD19AD0A189C8F3C B641731DA5175D0F4D1804C0D74DF334 C1C9D53BB8DFE89258F70957E30DB72B 39404A68B8C547BCEC7A93E18E40BD1C CD3B3F4488F8E39C222E25CC37D40D0B 9AE63E86F9EDB26F1E24A05DB3AE683A 56FD5FD62FB530ED5F891B4E546A5B20 4CB4E9E478C89E849C33110B8C88A1FD 125E83D5CA1452248AF145F68150B122 FE308F579A450220875C4747A94952E1 |
SPKG | Certified File | Proto |
0.920+ | n/a | FA88E5B5CBB49603DF689F139045E7C3C9C7E33B5923DF54E4C5FE5298B4FD32 |
5EAA69AB35E737EC22C721A916E00263 |
D73C9A8F35254C08C82B1CAA8284D5BE E0335393BCB317FFC144899ED31F6419 46C58D0593AB150937471082FE41EBD8 46054B9C951AB5CB0691B58409BDD692 9A361E2E5F59FCE12214887F44359C6C DCB0F50C66894D03317D5E706D44D8FB F05641D7EDA0A5C6B25FA7A37738E654 D03653A520E222F0A28AD8E214089F76 E9A14B71BAD37167F04952D6FC6F6E10 682FFFA6C48C33E24CE494616EF4697D 02AE4FDB9995A74C3F0BC2FDA0DA84D3 9CFCBCB6F1F38184973E6763BFFF8527 B84A917A5517FED4D3DAFA34F0AB8BDC 3FD41E2DB107E56DF6CBE698DFB6ACCA 0AAD445C2D23AE2DD4F5A5D48EBB851D 5A91B960931D96386A4CBCC1F8AC6C35 |
SPKG | Certified File | External (PDEL, PTEL, PCH) |
1.03+ | n/a | 2E6F4751D15B06C51F572A9306E52DD7007EA56A31D459EC6D3681AB08625501 |
B3D541A568751DF8F4833BAB4EFE0537 |
BB601FB5D4E48DF0377935B275956F17 5612A888241F2FB3C5EE24524CD0E18D ED32E72BF2215542755942F709495864 AC23CEA18D84F868A2CBD1D808AC8633 9B891283CAA01673B55926585A193184 E394E7B1C5726AEFAD11DD63C036BC68 3DC5521318C45DDCD3F256F3216138C3 07843CE5633DD4FE3EB64520B696F02B EBC3AE6A44AF75798D1E51C9B0E0E44E 9662D0BF10C7A1C92C4346AAEF860E96 9072A42E363B854821A399BD340FDA15 C68EEA8F5E922E78E92920F89F5FE999 9442A1765BA903A0CC7A933E39D38FDC 6C9832D77B04316E9B60C1A18F38F7A3 7165CB70A438C03225E2575D9F95FB3F CBB658D9C0DED6C23A0E03A150D4FE99 |
BOOT | Certified File | Internal System Debugger |
0.920+ | n/a | 9D3F28DE30DED1D503DB6FA762A571C422A88D0F361899EF36D357059C72EC43 |
30E43CFB57D418A5A0D32A9939D23501 |
C8195172CB70B06A29FAEF059251754B 87DEE210A6C35CBA5367D5965BAD4A43 06F7E5B1CB2B135CB240349CAB66B5F2 208F3FBBFB3B2D01E0059BF64C4DE894 F716F8AB18057F52ACE45940A7D67604 80B4E9E993E5010AFD5492028BBCA663 D3E59032AD52D0712CDF169274798323 52855F4688420157D02B28DB22E760CD 81DEAA802BE2D1E5A33FB51F6B3713E8 F524F34CFEAB50C5593366657C3C7090 7516B0227E93672FB4D5E3A3D64A0743 6B5A6CC514F2D76F3AC5BDF38DC08D6A 007336A88690EFF5BCA98DCB13B52E2B 713CBFECDA9825AAD6BBE41EE4BB1A5A AA052741E71586CBF5BAB7670F997B0D 23E43C08C6A1313E6A3E52A5E714D01B |
BOOT | Certified File | Proto |
0.920+ | n/a | 9EE16CA4AADD77F53BEE0F4AE3D45326D009806D2DE9942CE0836E43DC5DD1CE |
CFBA84A87EE29C9A521CA20691485E45 |
CD45B1D60A1727A7579258E70B5641AB FB02183E9689270D266D3A5093BC5FBD 9AF6479332770AAA0892A9A59C5099B9 C8C074BA7D3DFC3865892C4D28F4669D 6F89CC77464EA9005F581DE523C177F7 0F0AF3E721CE46430B5DE5897CFF1BA6 A6F329958AE7235A9EAA35078A39F6A3 82C061F9DDD4352429D7ABB1E62ECFEB 1CB815EAED057B48053ED1A57CFAB1AD 043D130876277DDBDCE31CA8FC14BBF7 63102A2A60F70B97A88301B43A734473 462A85398AC474914A42314EBC581FB0 E2333B08A8653532FF9BC53E64B42B36 8F0E8208A42CDB7FD148E8A43F899CD9 35C28806E22008EA72482FDB863F98A7 54DAA6F430BB637E9EAD075179EEF11D |
BOOT | Certified File | External (PDEL, PTEL, PCH) |
1.03 - 1.692 | n/a | 7A7FB1560DCD121CEA5E11B90124B13282752F2D5B95D75036AB3A29BB3BD2AB |
6C71642A042A041F1EE3094070B009BE |
C6F09DAC32179DC85881C5BAE1A27D04 3B8D114DE4349718EB3579BDF7FDE9A1 693B3F5AA21DCBAC926D2261CC252DCD BC1CA6D7896B4B6C2546F87F61FC676B 83E42358CF1EEE07A1080E23ECDE80A4 19BC64020A8EA4FA46FB3308871070A5 5725EFBCD065CF6A3B327AA7D0C398A6 C36603F1A2060ACF3A0040DF907FBDED 3A8417DD33798518CC83D1A91F7AE8DB 1B1DEBB151266B952A0F839E1F9C68D2 56371E5525E70607BAD72EB62B38FF2D F4556A453A43BC215EF1ACE115568FB6 79B61FBD7A110CB966D26EF159A1FD0E 17752208CE8E7E75F42D4F5BBEF9DD6F 8C99700D214C9C8A5EFA0C55024A9DBC 07586D7FBD2C1DF72DEB8B442C0A8823 |
BOOT | Certified File | External (PDEL, PTEL, PCH) |
1.80-3.61 | n/a | B1B936B512F9A16E51B948622B26F15C53680C77AC332EC25846B839520393EC |
90D527BAF7296B5B6A576CFA6B54D266 |
ACE1841824FEC57D354ADB3C0572CFCF 64F8F3BFCDC732DD4F2E6E4A08A5E53E 66182123EF1074E64ADA5FE2279A7EF1 CB0C61A29A2BBFF21214C13BE7AC453C 411093FA2F2511E0E032BDBA4E73C182 9DABB08167E0A4F10885F6423C2EB136 F55149AA64E7A1AD0D8C47FAAC861511 06B96208CE9669EBAAA09B8ABD816526 D7D56CD692EB6A1405FE021375E4975E E377A8E51C44C471FABD532C23B7543C 0463DE144DF6D4FD75CFFA952CF53B07 46419684FB62EE341F3AAE9096BA6099 532D160DED09DE3EA7FCE3C1EEAD7135 95D242DA023360A560DC31E4ADF58F16 94082DBC66622D683564983AEC351BAC 3774A53F49AB3761CB40C9A2485D3249 |
BOOT | Certified File | External (PDEL, PTEL, PCH) |
3.63-3.69 | n/a | 426FD1D33FEBBFAC560B7957B94F445AE5F1DED2AA70F74DB944645DC439122F |
995F1364BB9735FA448B18D886150C85 |
B19901417A312E32F8B7C394176F1BD4 868E5C01C4B0EFD2F5E2C2FC46DD0F61 4F59D9538469E0FDDA78F49D38E81108 2F63933680A356CE5F201FA8D80643C9 FF48D4BD2EE885AA9CC8597A4C212B0F 942BBE32A1146F815643E1CD4B1E2FF4 A5343E79012FF82F945132882FB7D18D 19CC51E7BCC4D1DC56562108694A4694 A999AEC96943086A6FBABE874285363E 5E5BD1881C9A6CA80870B1D09B613876 8F07DE8F726CC574B7152FE83E816FB0 87469CBD9E39EE660950727C42B15F2C 6ED86B3FD6DD98CF416B0212C5A788AE F6F0AA29AABC7FCF175CC61D7E460EAA A7DF2E9993A34B0F2768E6F935D831B9 79FE4E2A37CBC7C603AF68457EA5906D |
SECURE | Certified File | Internal (System Debugger) |
0.920+ | n/a | AED9D76EE1E29290002BFF32D4B0656EEE40FBDA4F8B55BE5BE0ED83530F27D2 |
DB50912F2416B54F7F36227169ECE500 |
D970E1ECEE27CBA9EACA424950D74C43 90022429265D38FD0AC1ADC2FDC9C569 F696A857F2E86D609F448611C1E2FFAB 2CEF575B92DF78182B2F0BBF3EFBA62F 5800B22EC649E2870E6B0829EC9BB4C9 04D24A99F269C960FA3E12314D8F08D5 124C671F7C92900DE0EF45CBB4415C2D 1AFE74A40633804A05D9A789916EDAB5 2A71B6DDCB0AE21B810C4FA69CE5AE59 0250747394F88E3A711A9A1D92E65857 383EB0F6D81D7ACD003EB2033B7029AE 44E500ED82179F3B1DC37EE89E2D6DF5 A5784339F714C1281392BADEC780F569 CB0D8AD41CF1568D7B7DFD96F975C07C F53615766E6ACB7C70C5125BFCD9E9ED 219BBCDC34BF4B420ECF4A62AA185D47 |
SECURE | Certified File | Proto |
0.920+ | n/a | B982589B568CDD4055433747DF19644A8D1B479B17CA44ECE5E82694550FEC74 |
BECEDF96543939032CC4DD7D95E47720 |
DD60E4C2FDA981B3FAA32CB4F2B5A080 54C9AC1D4925DA062553EEC935987EC9 5FF81E009F4F071AFCD97432F06CC1BD 0EB2930D69651DA532B72F7F79FDDF1D B49555B5F5A7EEBC11DD4931FF3F0A4B A3A62B9709F9FD8FB8E5C787EC2362C8 749741F5DB1665AC03E919E6E155A998 C076670F7F4F0376FC4D34AFD4B841A9 ECA8AB6D8668B79F853F86B2CD9B0233 A6345ED5431A8A7AEAFD458DD6026EE3 1A8F1D37D50756139B7D3931CA4A3A59 0AD553A6A5109B9214D8ED4589E9EB71 02D8686E6018348A9FBD1B182A0F2D77 D51857DC4149E93BE0419CC7B8846CA8 4BE498BF3E16EC53CF06B54C7F8B560C 4DDB3E243F8538B00AD112AD2FE83759 |
SECURE | Certified File | External (PDEL, PTEL, PCH) |
1.03 - 1.692 | n/a | 9D4E4CE92EA1C4576EB9601EC43EC03AAE8EC324ECF6DE01E918E61D2223EE55 |
CFEA3CCBA454D3279AD7CB0510431434 |
AD3229A94BCC5E46D203B4A0806910C5 BE028CB2931570A19DB38A7B6EBB3A7F F9893F14A5FA1ABC65250EA6AB3DA66C A9A0B8C08D7C54C6AFE3E34FB46C99F9 CA27E6D96785150695F8BB0CE1E22DFA E8AA635BF156B72A2F7D8959841B2E16 6BDFA121823F018E6D34228FDC80D2D1 B3BEBE096742327E1FCE7C2FFDC277E5 C3E34E6B070C35AE1C114746C412A196 451AF788A8989025C35AE2239915C5C8 0B9614079007D17BB8A080ECB0639452 C4DE1A9B66451148FBA841CD64EC3557 A3E9E3D77630F62E4937D7ACC604B91F B5A68A8E49D1E1577D8ECD11FBB73640 C2FE42F9B330CE8926DD83B8A0877A84 CF79A4786A0C2489F6398CDC37E31E9F |
SECURE | Certified File | External (PDEL, PTEL, PCH) |
1.80 - 3.61 | n/a | B1B6FEB39A8BD7A2AC584D435E150C624F560D3EFB03E745C575E0844569E2D0 |
89B4E6BAB03B03D49BF0FC927FEA8659 |
C9F97FAFB842FBD73A6CC06945B30A28 E949831AC895B734243E176B839C2710 48EF91BBF0D55EB88BB1A3A7853701CE 23460FA789A04754F0D32C9201DBD61C B25276896847A483C20120334EC934E2 EBD6A4F2A8D9D55D2F9AE5A99BA6D940 065F3FDCB02F9990D4ED6A9EBB936A1B FBFA9F8AF1EBFC703A8BD8DC93CDF0EB B9F955D64BE7B928CD256447D1FFEAE5 83884631F209ADD00D612F40CBA29219 DF7785CB23BC97327709FF147D1762C5 0D5AEA6F56758362F19514FA51A36BEE 95CE7C332655E247496C922EB1AA209F 0437651417DE214F9DA8BB6919371E63 E1759CB5A7962583D7B0866CB6EB1A1F BDB7D3F4DBD90A45617A2AA37B414971 |
SECURE | Certified File | External (PDEL, PTEL, PCH) |
3.63-3.69 | n/a | 59AC7F05E115D758201A3F3461BCA0D42BD186F00CFC24263973F622AD9ED30C |
A053B00BA4BF880799B4265C6BC064B5 |
E8722B48CE574F27EEDC480ACBD025E3 B754A5996198848DF654C7459EF6B205 3E3CFD14C5046EF56465789A6754A86C B96EA9F572CE4F7EB8033491EF516DCC B8DAE33144AABF0571723DFE822297F2 3D3035604A737F6F211ACDE3E34AA1FF D6FD515DD00EED22934497B5746945A1 2F1277226A31A091A8F7F4A67BC30830 76FE1FE278967CECF34B671C7065BA68 D9D0AE8E781FF86C3C914589D92106AA 3450DFA6421D755109C02C6ABEB6EE28 D1083EDBE9B0F496F182D92F0957DA54 DB1330210DCAB08D175FB6B9F7666860 A5F8C6ACE4DBF798BB348415E0EE43B5 979BB70EC065BAD41BBE225237D362FC 681CC31DC200E22605F4A07905401EC7 |
SRVK | Certified File | Internal (System Debugger) |
0.920+ | n/a | EAB14F9BE15EAEC1603BE63C9FCDE4099D601FB0E9FC4DF250B8DEC635987A1C |
30B9E61707993B635D0E182446DB0B8D |
9C8F5072013F914C15408EDE85D37E4C 0B6CEA08AAA321680C0E11DD299D2A45 0671B8247E8405F58EC0DCB33E1BCD8D 40E790650149E6DD2C62FEBA196FE4FE AAD72E69CF22D217294F61E1A88FF33F 45255E853D0C2E1D206287ED76DB1C8C D75812DD7C36CFAC0A97F30F07F02ED3 E8A79A7780696EB4FD24829E0D7FD054 1FE4BF490415D9E0CC2116B703E2947E 5269B63941FF511C183E4D2A0818F931 988DF36EF8DC972EE2709336018C9ED5 B7ED68341FFB229E82C97E5CE900ACF3 E5EA2E86BFD32A4BD0D6DBE17713DA78 3626911CF92C05EA5AE879A3272134CF 35D567D5FBC159DEA20A1B0550A12F11 E9E54DAA84889CF10B72C59E7569DDC1 |
SRVK | Certified File | Proto |
0.920+ | n/a | A603AA68753CEE3E186C81900A862DCDB13505D39FC59C62BBFAD94C526B8A06 |
352F596CFB513A148B95F9D78E57E755 |
|
SRVK | Certified File | External (PDEL, PTEL, PCH) |
1.03 - 1.692 | n/a | 4648164DB9E67009456C7CA6F2378835FD678539B36B3DE6F1C604B7D4258141 |
6EC8AD67993DAE75675F0AFFDE5C41F3 |
EE55BE9D6B5FF27E9D87BD5F40F8ACDF F59DB8CEE4777A8ED0C7FFD2B7C3C596 B25796C0D8692C8204684D6B27D6E955 3ACE2D99B998AEF37689416819BEC3EB 6A4E8B3DC2BBE7AA961BB93536B05FAE D8EE17BF4A875930E40DDE3BDC5AED0D 79D62DB3E059851FD91F41BD4F8E4CBC C5666E2850D34B28569AA0E5FCB67438 5C589F619B87AB4F274247DAB757E345 4E73B6980C6E7579B77D484205E89C91 7CD8B573BBC4D90BA2730267F4F72DCE 39DB6F8BC1273A3C15CAE1273723BE99 77B4F7E283AB01174A1E1B93231736DD 76B9F9CFDB2B94C6B6CD927EEBAEF99F 2A8F4F6E91667A6212E90A17FD1B86F4 0DF73E8B33DC4E629937C39C6F4F4343 |
SRVK | Certified File | External (PDEL, PTEL, PCH) |
1.80 - 3.69 | n/a | DAE4B0F901E338DEFF3CCDBDEA1E2FDEA9926BB98CB182443CC0C0F7FAE428EE |
18D925FA885C7E28A9CFF458C24D8BED |
B09BFB3EA696732FF3096F91954F613E 797BC7531F81F6CF31432F143BDF8D5A B9D4362A382971F6892280615FB372F3 37DE2B95C672CFFED65C9551C52F94DA C6694D62CFB90BD64C6249A550B43A66 E5761606A066E75C2593BFEB72D2F53F 6C39D2AEB1559868A7DFCD7DF82802B9 39AAF84A8BDFC7F88DE442980206FC88 50A9EB1CE2F98494ED9F8C2502756047 7D3DFF61016B056A9CABE958ACE107DE 7D0B629DAE53093F1BBE9BC88B8D70DA 9BE0D0EF1E744EDA8E3EA0D54628AB43 2B448C595EC02257141FDBFA509E27E6 5C8DB64C9FC8268BF52AA4FE5F3D97D8 0ED063D2DB8C289D87C6E31DFE091CA8 C0CF7F28CA204151F50F416E7DFAF4A5 |
KERNEL | Certified File | Internal (System Debugger) |
0.920+ | n/a | 74F6D2A1D2A093AE32B83337E0AE4AD2E6D93B034F5BF3B68DB77131883310D4 |
926AB55BDADC45DBB610E90E56A0368C |
C2F385A70C3ABA5BEF408374C29CB022 DDB2B1E24C4F06174AA37EFC38AAEF4B D1813C86500B1BB8E7C6FD13FD3EE071 2BC384C43488F67D1239B088D34C7263 8612F7402B218E733D02939FEB3EF087 604F481BD17821258585FE52DFDC9047 98396F34DC69CBCA782D8A3BBEB1AB49 80DC0004435E77BDDDFEC9D6BB80FA06 5E0B5751416C23EFBEC40DFC42B05086 CC1CCE7AF7CFC2404DFCCE05F5BFD56F 3FEAA9738536AC356E0D028B4098C449 12E096CB3575D2900F06DB5DDED3B36B 6844F4860B9753BA9981ECB74EDB3828 476DED1BD9A9784D3B69C801688C3DE5 8325CA05160CD9C362BEF13740E0E5B9 2C14A62B925FCDA754B2B106BA42EF1D |
KERNEL | Certified File | Proto |
0.920+ | n/a | 61E7E786BB6F67570A71FC92E73885439CD16B96BC7C37C200EF11D3446FCF69 |
99E8B68EE784FDAFC3294B8E55F0C529 |
DE8F9031E864B17AC0ED93F8B2860398 3AEF4CCC7992E254D1321B3BBF7B8819 EBE814C8BFDF6353F29254CC01DDCB4F 5512999091BB5A62BB6C29B0C484AFB3 155B03F706CB3830BA0BD05439DF1416 0CDB19113399D08264DF47DF73677330 7B34E5339A5B14F5D2807D568DC3BBA0 4C5FDCAC10F92DA8E3A13DB4F0AF3950 C8A2D5FE02710E6D2344FFCBDE0CE6B4 E7AEA5F4BA097189A9E2E5511BB5DD17 034308B80419328FD42505CAFE71415D F5F6D7E01B92580E1A8EC772AA668493 6B19CDE2CC0C126D0B1846D47DD16D3F 434954FC580C4D167346281FDC87E0FA 4C2E08E91DBB2FF1933A0681771D0156 11EED19741166265E0C827C20AB7237D |
KERNEL | Certified File | External (PDEL, PTEL, PCH) |
1.03-1.692 | n/a | B4AAF62D48FBD898C240308A9773AFE57B8A18D783F0B37932BB21B51386A9A0 |
8CD162C5C613376F3E4BEA0B8FD5A3D0 |
BC25A8ADC24861B587E9EBCB0D73F5BE 16C3CDB2606608BF68211AB44514F275 5C14F6B24A6692D7E41B75AA44C59FAA 7EF7B5993F5E311F50295A01DD8D2E84 3EB00B95E49465E1C0A52BEC3CDE3587 93745FD915E04F3E02E8340782602339 266923DCE27AAF46336DF0A3F6A984BA E44343C20B47C90400250F8152025EAA 0247BD882123F21B5310897A8B185039 1E049E2593E6313162A7502CE2E7BF18 63C5FC3A11197036691FCE8C967D9760 8F33DCC48D65C720C249FDBFC6797A83 27F1B1E53878699BFB37254B3680170C D78F9087C925D5863DBC94B890521F8E 56DBBC91925F610420691B8863252DDE 28BFC407D97A7E053C6A26EA123BA027 |
KERNEL | Certified File | External (PDEL, PTEL, PCH) |
1.80-3.61 - Decrypts scePd | n/a | 849AF7E8DE5B9C28C38CA74963FCF155E0F200FB08185E46CDA87790AAA10D72 |
88710E219454A3CBF6D382D4BBD22BFC |
C0C47F0C9944A43A642B59E0CDA30411 892574373FC07C5F9D9D4D9E36C8AE39 06FD2A3DEE77185D0C46E56EB95D8B6A EA96E390A7E91B21C15644EFE5A921A8 3BC63C1D8630C7340CDE67E239C0D0D4 263B334296B25A647410F1F8912726C7 0E5B75F4EDAD6B32767CD2BC7FDC6A8B 784E2ACD9DA7199CAA252B29CBF40938 8B2A6D6739BDC493AD1085978A29FB1F 1D3804F68CD3F0278452FFFAB6537E1A A998F041CAE53D6DF7DE98EA7A3B8129 11481B1134449C63A84663FDE24B9187 98A9906A3F4FCFDE4920D23F73BE9FB5 D739AEAC98B51857D9A7648A9AA311E1 5029D7A99514D5B14F9E52B00D6E7D30 A7DD31E4388C4E09EA55663EB51EE1A1 |
KERNEL | Certified File | External (PDEL, PTEL, PCH) |
3.63-3.69 - Decrypts scePd | n/a | 18E26DF712C362769D4F5E70460D28D88B7B991733DE692C2B9463B41FF4B925 |
5B13077EEA801FC77D492050801FA507 |
CD3A2672EE97FE68CBB2E03B176623F4 1BF380BD41015EE440E5766FE55FFF1F D8F2B9ABC3C71E582A4BF4C6F417646F A15E0503DA3CA42792BB3FDDED006821 D5C10F67C122D3D902D830BA34E642F7 2B71DDD9D0B79EAAD651EA91E332CEDD 014744468AB8B5788FDDDA41D5AF3618 424AC7671058CDE89450AFB452357080 A8A5718E5702F10DFF1BFC8F41B34328 776E2B08E36D02717A96C90EFEE17C1E 23BCDAB01F7912DADF8A256C4C474849 1591EB8830133CA43C800A13142E93C4 94F85B346AADEA0B6067DD6F9BDD9C0A 2BA7F83557EFBFC420EAD81F828A20D0 1B2296358D7E3CC2D9C4C177901260DF 115C1876101F02739C1DC64DB100DF55 |
USER | Certified File | Internal (System Debugger) |
0.920+ | n/a | 322D706CB6EBEA14DEF7BFE45F812971347DC95CD7697C16A71EA4B2A1E12C0D |
31FA2E606031EDF39665B5616E9F937D |
ADF0C3B17044488306735EDC7A0B326F 3BAD99AF586B233958B82C921DDE3EC5 67B69DAB66FC674F7C4E99DD49679244 8F012C7136E68E21CFEFDA257D4D18EC A7040BB9972C5AB9B30BCEE77C3C9AAD 6CBB34B7A83766159B041DD02EBD4AEA CB491F1818E640FCB1C145A14993B92C 05D5207D6B9FEF460E621A48403438DD 25CAE7A8934001BC89EC98ADBB1436C3 1AC0D4EBB5592BB548AEF8A2585585BC 1B3F4625E35BE3B85930B7E36FAA38E4 B1B21D1960D66376FAB1CF6F0ECB3364 3BD5B4D8DF8323634F7B61AFBCF8928F C07893F10C1485C315961A76C25B49C2 D0EC8348F3F67405687270FCA1CC2B50 C0B8CF62DE5D852B61ADE9DEE8F17CB3 |
USER | Certified File | Proto |
0.920+ | n/a | 8D355E70736EF7AA508D640D8D382B19D9C8747C4A8273A6D5707F227F49592E |
BEB4819878915F3025978538693B3EBB |
B3BD307380603F37EDAFC51BF1B483BD 5A5F936DA2003F6DBB55A2F1AEA147D7 A974EE44884587F726630D0A087A3F1E CD232F5710B8AEEB370BB07A84E28F36 59A8D66E8CE731E714D9C7BC599544AE 590C760F37B218FE31D0460B2C5EF403 F29DD48F9D5378CDF637782CBCED1B49 470AD0555F5152C88B5FDF42B9E60A90 3995F564B2FDE507376F6A0E6CFF105A B4568525E94AC44B616AAA040B26B2DC F4E87E360EEB706EFE4E52CD585FB36C F094098D7D6A8A7DF313AE8EEDA0CD6C C92B49525F821677C7C4A5EB7CDE6729 27EDC1F5527696229021496C5788EFA7 19836EC439EEDD4235CECD97CDED8FE8 AD5D4F47388B04572B6C4FDF9BDC6485 |
USER 0 | Certified File | External (PDEL, PTEL, PCH) |
1.03-3.69 | n/a | C9AFB5CDE420F208B68E8C114778A55CA16E38C376490360111F21633FAF80BB |
92CE0F89324414E756B824DE1CBCCA6B |
F105999A3404267136749C8B0D1887E1 70BE5FE6F543429A5FDC4A566955A376 3157D45EF1253E8A7BD89019E100ADBF C1519E1F52F761C3710F95D214320E3B FEF2FA82DE6CBB56BFA337D434DC2170 0FDA88E936CFE3078FFB69D1149DB544 D2B551599DB673B2C5DCDAFF6A827B6C 4192898A892B61684D5F21635CF204C2 E114D16EB04AC7DE92ED35B9D89933F1 C7E4C64AA945ACC5301CDB1A4EA70F70 50DAE29E67D289A8818D364A8C190FE7 8237C552C61D393A5A84B5B6CFEBE3BA 2E514DFEDA33A81D5CE09DA1B4154209 B6B1B4C4BB2994304B31594A483E09CF 7C428F7E54D6A9B4DED5B4A15A0ABB88 8389ADC1BDD663F739F770166909F635 |
USER 1 | Certified File | External (PDEL, PTEL, PCH) |
1.03-3.69 | n/a | 613AD6EAC63D4E14F51A8C6AF18C66621968323B6F205B5E515C16D77BB06671 |
ADBDAA5041B2094CF2B359301DE64171 |
A4AA9F81AE21F8EBC9DA36BB9A1BAE75 25841DB46272C5794BB36E3DB249C6C4 8081EF602F7940C67AD3F90EE5A84CB0 AE3AACDB08C6CD14D3AE3FC073C1AA65 9E878F4AAFE3BB1AE3CA1D261B0E7FAE 82B4BC7F0E1B18D9E46EE3B74B1571F7 743F7DE787E09F9B1B5B8B36FB33EDE1 A15BC53B5D435F3698A9118B9566C51A 056D66099F11494250827BA2810C30F2 AF98EF312615D673F8CAD88CFBC727B9 AE5C2A335FDACCF7D66FB156064BFB7C DD63CC3A91CBFDFE056DCB1426A204D3 71513763B8AE8C1CC5E54B36A6AC33B2 BD5964ACD557518A4E6D70803DF9C451 8DBE5612F2737DEC0ADB36A86D694E24 FD4D0EA3E6CBF2EC7D6B0CBCCBC59F41 |
USER 2 | Certified File | External (PDEL, PTEL, PCH) |
1.03-1.692 | n/a | 0F2041269B26D6B7EF143E35E83E914629A92F50F3A4CEE14CDFF63AEC641117 |
07EF64437F0CB6995E6D785E42796C83 |
9EE60F144BDA881AA55B37CD84703625 48DB93EB8DE5CCEC8A75E19E960BF3F1 D64FBB33B2E4BD4FB26AECEE18196963 4519D2DD04D126F0B2834A1159D197DA AE80AC5D4602A5D16FD7599EE4711264 4E5E5C1FF039AF4ABCA339F7E0E6AA97 5513041B48D9B04D62E1A1889DBE8711 0E58DACC43A9A23377683CC68487C1D6 32EECB9E0AE5E6B76E51253BF66D599F EE8BDFA216760CFD0527801DBEA23F63 EA03879A841BCDF21F32A122427B000F B2A05C5F66FBF2D91C5C2E09478CC2F6 BA36121F902B718646DA4F13BD9348DC 8C355573B8024322F85519703F0941F1 05BFFE6668A736AA7F8D3C6C318CEDC2 D47D820FC4EB496D0299BD1C5A5E69B9 |
USER 3 | Certified File | External (PDEL, PTEL, PCH) |
1.80-3.61 | n/a | 3AFADA34660C6515B539EBBBC79C9C0ADA4337C32652CA03C6DD21A1D612D8F4 |
7F98A137869B91B1EB9604F81FD74C50 |
B0F9349CC3908CF5DE59900E0837E840 71BD8B5DC2621F48130D3200CB5ED0FC 7475A87AE58A2F525BB09B2D9D3C2D57 5A6C30A02B0A80C6677A9F987162AA88 38E1013D6ADEF1AB207D15166F639B27 C47BAAD813FD07570773CD2429EF912E 04E8AAE52EC7F4E91918293DDEF24051 657F22C5D7564AD697081C6ECDDB43A3 243156468B968AFAA867F7A20C110625 EF05E0A2D553BED2CE1B7FC8D53DB774 51330B73E1C1C28F604D9D21985C7975 37924F65B814C5248A7638C51EFCEA87 AAE7F94ACFA8607C0EA018BE01BC4BF4 FD23CF08752DCB5FC05B61C4997BB623 E6C9C8A6E09067EEB3E4C7F6B41884F0 73DAC52E4D790590FAF84E5FDD35897B |
USER 4 | Certified File | External (PDEL, PTEL, PCH) |
1.80-3.61 | n/a | 8FF491B36713E8AA38DE30B303689657F07AE70A8A8B1D7867441C52DB39C806 |
D9CC7E26CE99053E48F9BEF1CB93C184 |
CB93C1849D2058478063D1F64E259AF6 5C649AB78CC1566CC4D24082E5BE1A13 861D25617D3BEE9E16F451788E102217 504804AF65E8FF1CD52A773476449B26 77BC6C8E008B540F0683413CF0FF3A79 334406DED5CB92CBBB61413C349FF482 27FA733BD2F0FC36156716481492F8D8 04C2F29A75D60BE87DD0EBFCA35DB661 B0A92C6A38F294D40A67C6FB797E8445 01A4680EF6F73FAED3DAD2EE39C67E85 64F74683C4890F217BD426A9443162E6 7D051FB2292AEDD0F228923BB7523A80 4FB4098D0B7F92662BB0B26162B16E2D 76F7311B8E5ECF89337FD081C401A205 DDC4904BDCC82BEFE651C3C7F07F556A B1CC5AF7BC3E4F81B9DBE89955FF870B |
USER 5 | Certified File | External (PDEL, PTEL, PCH) |
3.63-3.69 | n/a | 4D71B2FB3D4359FB34445305C88A5E82FA12D34A8308F312AA34B58F6112253A |
04A27133FF0205C96B7F45A60D7D417B |
B734B41FDB38573145086C3CE86FAFAB E006A877E951505A0F062CA79C9570EC A60E5DF0C277AECF55ABBED18B1522FD 52543CFF7BB8898EA0794855DF716E88 1EB89F8E2958DD676EB95FF217234426 28CA52FAA89CCDB3FC46BF1D123FC950 CC65DBACEE555B04FDD4187AC6A3D090 61FB57D9ACB1A592094B227C2E21FDD9 5A757528A41BD79F385F7C3C80F850E2 60B544E8EF68B8897907495314BA3DB5 DC10B328E040BCF1AE54A8A59D35C691 52EF11FD085772F5206EC689A89D890C 9A7CDC9951CBB41C0D51615C38A4AE2C 05B29D0F5A63726F8623A5F3CAFA4C97 29E86ED692CD1775023A449C0BD8FF5E 7A7A2E6689D7CC53C6F881484A858D2B |
APP 0 | Certified File | External (PDEL, PTEL, PCH) |
1.03-3.69 | n/a | 5661E5FB20CFD1D1DFF50C1E59A6EA977D0AA5C5770F53B9CDD4E9451FFF55CB |
23D02FF79BF430E2D123869BF0CACAA0 |
BD7D071818433B4312BA784DB296ABD0 9FA25FDF385CF15E808065AB3AEEE183 2BEE04ACDE465D0916B7BEFBF3718A1F 8B64DE685EECC96FBB196116FDA91E88 0D9316BB05B50FC9C35E37E9267C8B15 59AD9DAC4F2B418B059A1EFDA848FCE4 9E87824CFF25B7CCA0B6642EB0A4C4F5 A7FC828EBE034D6E56226A148EAE5112 2E1783ED2DE85C7B95882F4352FEC904 32699E452DB74A01A163303593D60CE4 270FB6C1F349C97AEAF7D2DDB6EFDA43 69A36C2F2A55B7E17D0C36CD60CF4BB4 0D6D82495E65B7BCCCF2A6D032BECAF4 FB044471DF10B77CC84F887E953D2B11 3661EEF0EC70863E552DEBFFA398C976 741D2CCFC5C2C37BDEFADD32DC68B267 |
APP 1 | Certified File | External (PDEL, PTEL, PCH) |
1.03-1.692 | n/a | 4181B2DF5F5D94D3C80B7D86EACF1928533A49BA58EDE2B43CDEE7E572568BD4 |
B1678C0543B6C1997B63A6F4F3C8FD33 |
C2C6F85A213CADCC1F71B6DDC2FA7ED1 CCAEA81EA4D1468D160B0EF3AD3EC64C B79B094507FD03B36D7644704659C927 EC510EBEF47A7262E46E8A691F166974 11CE34E1DDE5A142D49932D0DACEC936 2AD3BC2D118050422861D4FF49FADBC8 853D5D3326D84AF9AF0803C2B3B1844D 0A085D61C444D1AC44948E3C077D093F 9E8AB4AC7BA091942DDFCAF22363A6B2 02B6CF071BA6348C91B4E0DA1C010364 26F5DEB53C53657A613AFE6C07F582C2 6E808FB6892C0E2D98F3CF5838B0CFCC AF4BA3CC61053D046D7C25B27EEBBD62 75FD6B83F0934EAB34E838B2499DEE7A AB4473A630B5DAD6FDA8D857A10118A4 354333792E433B0A3CD871D3641FFDE7 |
APP 2 | Certified File | External (PDEL, PTEL, PCH) |
1.80-3.61 | n/a | 5282582F17F068F89A260AAFB71C58928F45A8D08C681376B07FF9EAB1114226 |
29672DF43E426F41AF46D42E8437D449 |
A19E248D2CCB21C3A6632DDB77D2715B 36487AB9C8D2DD7B63175DE8CE4D21A5 6EC799E54CFDCBE3595DB051BAE09DF5 2AD8D43B06CF5AEBDCA9F6001DBD5051 E725678A4E9952A08C5A1C7F3DC2BCF4 3C9769DC7946CF304E837ACCCC2F531A DA3871F66D81B6F55B7650F88CD58E45 1C0761CEDD7B5F3D2509C6A4991542CE 31B5F37B9CF2EA8C268995177106E49E 852998BA76F0F01D715F04FA55F4D402 CFB455DADD24E3B6F427CE16305FFC82 ED9438E3DE81717004742F72C458F76D F5BD26ADD4122B011A38A00F99CA96AF 18C249B0B17D66894A0F8E82DCB1BE8F E185B3D5468761AD744BFDA651D6A789 50193A11B176E018D703B92C78D5213D |
APP 3 | Certified File | External (PDEL, PTEL, PCH) |
1.80-3.61 | n/a | 270CBA370061B87077672ADB5142D18844AAED352A9CCEE63602B0D740594334 |
1CF2454FBF47D76221B91AFC3B608C28 |
D7E446AEAA4C55A573862BFDBF8DAA07 375DD089153FBAB46235A51F7387CF4B 31ED1092AADEB1EF49D95E91C8223C67 B8CE2188A9A3361618D196FF9C29DC60 C7C9B1FD07066E92C4ED489E3AC8F7B9 78F35D2C41257DAF99158749EB6F1F01 81AD70E3073DF69D5F87BD7AFB71AFFE BAEA7773A3402EA48F8678C12EECF73F A231FD3A7AE503DEB833C054485C5C1A 28DD916DC774B95CC06325080E4149D8 8077EF5AD44F7CB7595224C7C040FE4D 38D6DBEB5AD2483ED3BE11F1727CDCBD 93C331E853F6B61334F4F1C2AA8DD8E5 FD9DBA244BAEAC5474B8E11187349C0D 980ABE7496289B5C5E6A703985385022 951C4CB7F8B3DBBF2C251F2F4C1D8897 |
APP 4 | Certified File | External (PDEL, PTEL, PCH) |
3.63-3.69 | n/a | A782BC5A9EDDFC49A513FF3E592C4677A8C8920F23C9F11F2558FB9D99A43868 |
559B5E658559EB65EBF892C274E098A9 |
DB05337883920C1BCBAAA04A8DCBEFB8 71BDB49AEFF764FFA79D10B2F4948F53 6940C80D133E143F2A40BD165C212723 2E2862D381FFA72FF535E7AB50D15E1A 5C7A1A020012AFFBEF3EA55AA017B441 B9708A457E7731ABAA299CC36D285EBE 71DDF1C49EDE34E1C20BCA31FABDDF98 0E0EC8784005489D4EFB7633D0147D4C 89E5CBC81534F26D7E49B1BD2612D6D4 30040D4CF7D6D8935DA3DFB231597894 B86D3C9E253A61C4B9078B51486C5735 E5D120C8312A69363B4A41B1BAD65D2C 639616FFA79888243F88D6D2E3FE7D0C 3DDCA87166213D027634A9B3DF649549 353F1086D43D3A09EDE21798556DFF77 63970940DC25930E5C9DDA7B9E243735 |
APP 5 | Certified File | External (PDEL, PTEL, PCH) |
3.63-3.69 | n/a | 12D64D0172495226010A687DE245A73DE028B3561E25E69BABC325636F3CAE0A |
F149EED1757E5A915B24309795BFC380 |
D11F5A2D844D1C94FB86462FD53A0B23 3D1A2BF17407A3F97A4BEEA8A53B13EA B6E2BF4A7E490AF11CBB5E14BEFEEBED 0A14DD56ACC1F9B91A8C08CAAF472D81 A87402CD4EB75133B73F3FB4F03AAFB6 90C29D02836AA784BAB0EEE872332860 DDD02E8751181B523A9BB169433FFF69 61DD9B6CA60A0E573889D5FF30C192E1 B36A89FEF7F3DBE97C860015D6EC2A21 763029A8A1CFEE950BCCDE722EFA276E 978E095D31F5E44FFE093827FBF67C2D 904FF4EA0930D846C770813F1E6F1A13 105198626CF44F54046815173BE13F59 3C0CA9A11BD02BB1735967D3BFCC704F E7FBAF844B2814171850E2BD239ECCBC 6EFBD836EABF99844F2C8A862CFB52D3 |
NPDRM 0 - for 0,1,2 APP | Certified File | External (PDEL, PTEL, PCH) |
1.03-1.692 | n/a | C10368BF3D2943BC6E5BD05E46A9A7B6 |
00000000000000000000000000000000 |
n/a |
NPDRM 1 - for 3,4,5 APP | Certified File | External (PDEL, PTEL, PCH) |
1.80-3.69 | n/a | 16419DD3BFBE8BDC596929B72CE237CD |
00000000000000000000000000000000 |
n/a |
PUP watermark (SCEWM) | AES128-CBC | Internal (System Debugger) |
0.920+ | decrypts the whole block | AB7097356FDD49D83878540167F0C4AD |
85537C5A56BD15DF0EB5F7F0D9E276E6 |
n/a |
Compat SM IPL | XOR | Internal (System Debugger) |
0.920+ | XOR the IPL header with that key and decrypt with Kirk 1 | 8241A9C6421299C50EE399BA66327D73 1451D946F7325358B1AE297DF603911A 3A5B717506680D4B67EBD0F97D79C055 0674090D425A9541AA2B0F17985D5C21 |
n/a |
n/a |
Compat SM IPL | XOR | External (PDEL,PTEL,PCH) |
1.03+ | XOR the IPL header with that key and decrypt with Kirk | 283406246A9B9C9F095CF02D98307332 ECAA97CBAAC70B101235E77D84A9FD16 9142DEB5EBD909846A1864D2FEB81ECD 0750D863130BF190279D46DBA0449AF1 | ||
Compat SM IPL | XOR | External (PDEL, PTEL, PCH) |
3.60 | XOR the IPL header with that key and decrypt with Kirk 1 | 59AD29D3E66279F1AF532C627992DECB 56A8B99C68A5095818F352DC9BC7FB8F 3D43707D2FBB723C12360C8E81BE031E 012F20D268DA7CCD2021D5560FE62702 |
n/a |
n/a |
act_sm cmd 2 | AES-256-CBC | ALL (SD, DEM, PDEL, PTEL) |
0.920+ | 2.10+ require an additional RSA signature as act.sig | 846D2DFD77D3C2E5F0E17EB18CC786928B881E2E17AE0CD8FDE88809D0D033C5 |
C8A040662B10A1986A1894E94FBEFCF0 |
n/a |
act_sm cmd 1 | AES-256-CBC | ALL (SD, DEM) |
0.940-0.995 | 2.10+ require an additional RSA signature as act.sig | 3D1EFB3CFED42A5F871213D4CF1E3B7A65F927E23811B594215D616BE59DA4D8 |
D57E3699983302611632DE33B197A43C |
n/a |
act_sm NVS 0x520 CMAC | AES-256-CMAC | ALL (SD, DEM, PDEL, PTEL, PCH, VTE) |
0.940-3.70 | 5A91FC74A82BE3F2B8F4DB6070A099A2BDF00E7BF00E7BF08B685534A0646D87 |
n/a | ||
act_sm unk | unk | ALL (SD, DEM, PDEL, PTEL, PCH, VTE) |
0.940-3.70 | 18EDD96BB0E98108314ED06F5176208455E0F5DA5921EBF29D079E13D30E1EC015257C3912266368C5C2DE01CF270055 |
n/a |
n/a | |
act_sm RSA PUB | RSA | ALL (SD, DEM) |
2.10+ | 2.10+ require an additional RSA signature as act.sig | n/a |
n/a |
A844CC0E308B55E9113FA511FF257FA6 431AFECFC360264355DCDD07B5D9610E 92BBA8842226B027BB18B5A596B1FFAF 41466E167B6BB7CEE8B6AD264469D58E 9E1CC8DC8677A0ACFFC6CD6B6060E96B 971D54063C6C38484C2C8D2F9CD1EC70 ACB808C577EFA70785F86C86977D7A0C 6939E7221939512484DC399966EA6EE2 28DBCD99F74CBC179BCE59FC76CAF6FC D9B65FA6B3EB113A58F71FDD16B249B6 1C8AF859819F5E311E871E475B424263 5A79B0C8DE2713E6D5847215B28E037C 5181E51CC7A3E8A65BD4041A6FD74277 FC2A3E63434B549BB62BDC649FA212A0 3FFEA5A3893B93C620C2642A7179289B 981B7CFB681E0577DD3EBC1747245239 |
PSVIMG Master Key[edit | edit source]
This AES128-ECB key is used for PSVIMG Key Derivation.
A9FA5A62799FCC4C726B4E2CE3506D38
NPDRM PKG Keys[edit | edit source]
These AES128-CTR keys are used in NPDRM PKG file decryption.
PS Vita, PS Vita Livearea and PSM PKGs use a different algorithm than PS3 and PSP PKGs: you first encrypt the IV with the correct type of key, then use the result as the actual key for the CTR. Every PKG will use a different key as a result of this.
Type | Version | ERK |
---|---|---|
PSP | 1.00+ | 07F2C68290B50D2C33818D709B60E62B
|
PS Vita | 1.00+ Type 2 | E31A70C9CE1DD72BF3C0622963F2ECCB
|
PS Vita Livearea | 1.00+ Type 3 | 423ACA3A2BD5649F9686ABAD6FD8801F
|
PSM | 1.00+ Type 4 | AF07FD59652527BAF13389668B17D9EA
|
index.dat Keys[edit | edit source]
These AES-CBC 256-bit keys are used in vs0:vsh/etc/index.dat
file decryption.
Type | Version | IV | KEY |
---|---|---|---|
index.dat | 0.945.040-1.692.000 | 37FA4ED2B6618B59B34F770FBB92947B
|
06CC2E8FD40805A736F17CF2C13D58A6C8CF107E9E4A66AE25D39CA21C2531CC
|
index.dat | 1.800.071-3.740.011 | 37FA4ED2B6618B59B34F770FBB92947B |
|
Title Update Download Link keyset[edit | edit source]
This HMAC key is for downloading game title updates. See link here for details.
Compiled GUI App: Vita Tools
Type | Version | HMAC |
---|---|---|
Title Update | 1.00+ | E5E278AA1EE34082A088279C83F9BBC806821C52F2AB5D2B4ABD995450355114
|
LiveArea Update HMAC Key[edit | edit source]
For resolving the PKG link to LiveArea Update Packages.
D8DBED766EABCD68D47DDBED9D3CA825837DE8AA789B7FF92D9A1594FCD8EAC4
PFS Keys[edit | edit source]
Type | Version | ERK | Usage |
---|---|---|---|
PFS EncKey | 1.00+ | 00298CDF4428E72C8785DAE0923C60BD |
|
PFS Secret | 1.00+ | 8C5D3A4B9D9BF4B453BCE6CDC34331D8 |
Check HMAC at position 0x30 of file sealedkey, from the first 0x30 bytes of the file |
Passcode / Keystone Keys[edit | edit source]
Type | Version | ERK | Usage |
---|---|---|---|
Keystone HMAC Key | 1.00+ | 310C2F2D70A62226F4582B4FF03E24196EEF01EF73A8981F2504BD50549A478F |
|
Passcode HMAC Key | 1.00+ | 543E368DF6629D682CD5A43644B1B2D733F0F2964DCD2CE8E9CB95D76C9DD928 |
NPDRM/PSM RIF Name Key[edit | edit source]
This key is used to calculate RIF name (file path).
19DD4FB989482BD4CB9EC9C79A2EFBD0
RIF RSA Keys[edit | edit source]
Type | Version | Modulus | Usage | Notes |
---|---|---|---|---|
0 and 1 | 1.00+ |
9CCCE3A536FA641B2D1354EE98F093C2 68470F722C024B86CD60274E08E0067A 3CB0DBA3D33DB2ACE44AA070B10B612A C4546E51B5EDFA23F5ED507F23365F9A 0A09C1807D43E6172225AEB81630AC59 79C4A534460A41A6207E6B426F3DF8CA A0FBA7ED2B6A474C2AAB50A92DC743F2 232228FAC48FED218A8190F0423AD00C 595DCB410D18845DA90CCF2FDFD6B90E 23074B52B57C4866B93DD6A7C7336D74 D26D9E30D8A1B1C94459F34312AB0A46 B1B281D22B38809352A487C00D60340F EAC1834BCF88DA25D980B37847087574 27D40948493D2F5A8FEEB5B74B2961FF B4E7F3832207CE6481F07E88164E3208 1801B68F8D141541CED6D7D966A08DCB |
PS3 Rifs | Inside SceNpDrm |
2 | 1.00+ |
8F347CAE575CE487ADC5482E64D041AB C32F1012E4B69478904738A8145D62BF F98C6D2C361B75D3C165E42B999A5B63 6B914889EBB5F216362A8BDDD72AE8D0 A45A730F79A3E9BB513895754C142874 70213CEE44C675178F01E09A6BB0C451 5C1DB9C9BF40F1481E361EFC7F9F236D 183C59A1B7F0136BAF10A62FA92ABDD5 E852B9EC2C1B17B080C1D31FB288954B F94F93B0419CFCEB8673E93874A34027 17F8B1DA761876C6CADAF9FD11B6EA50 F800D2EB33AB217EFF4C603FEA56C299 138A5F2912EAB936BFA879CFBCC8FA19 A64404C79F61B80C3DF68A466208870B 1C7BEE3AC4F2056AF3EF64CCE10D311F B3D7F42C73EDF33163435F0AFA727507 |
Inside SceNpDrm | |
3 | 1.00+ |
A6E0B2D4B582C0E204808C4583AB7607 6B3496B96FFC90174AB1E03567B4FCD7 69406D9DE3A8CEEBA2E7D4CDB23E2BEE 471C53D2F71B9DD82233CDD8168BE3A5 67592D7ED55FB45C717917756FFCB39E C755157AB97F89F7BC1E7592F54755ED BA4914F08F0C77E0B3EAFF9CEE876F3B 713E6581EC09E5173E212B612DA70DB3 66039B320802E0228B9E422E3C814B4C F8C50207DA9EC689B5F4456173446356 8AB65363DAAB3C605C9DA80DF7756480 68BB375E99A8FAA80269E094D775A781 EBFE0B7C39DB82272049852C4395B8BF 67A9E25CBFCFD40BE6B2C1895CE63534 E552D7C4F04659A7CD3C59841E2C242D 26501EB4FF1C553BA90F320428A760F3 |
Inside SceNpDrm | |
4 and 5 | 1.80?+ |
F30CA7B21C19D18794607698EF935DB9 FAF6CDB684EC36587465DF1F43F7CEAB 5ABCCDE0B38259591462D5F65C9AF5A6 A2F1CC2F87F00C0228AA37CF19841065 93F84ABB14AC57A70188B158A68DB1F1 37891DE69ECE1DB876AC74B4F6B15601 4B06CFD017C32BFB07A3271EF466F19A 26294197C5972B34BB2E3CBF585A429B A9124FC50E2E483B0A5C90F1A04988B3 96A2A0B59A411AF90D1B914C528E1606 013A411AB7690F2BD622F8D5BA3AD03C AF8CFD581887BF34E74782E226FFAB27 CF5E40184341663286491EC0743A4019 24B0EC6061155E72A18784E67C878CA5 1F9D49DA923881F432CDD9342F1F923C D380CC417592606E84F71B0173E41967 |
Inside SceNpDrm |
- RSA Exponent is 65537 (0x10001)
RSA PKG Keys[edit | edit source]
Type | Version | Modulus | Usage | Notes |
---|---|---|---|---|
PSP | 1.00+ |
BBDB6AA32E3B51A6D4708D5FC9899919 395A2AAD83E98F4864C3BA43A5D6906F 476E73535BFA8EF9C3720826A1F227B8 FF06F69F39963987635EBFFBCA51D0FB 8ED6BF178BBEA8F6AEDD64B401392905 3F169B7EAD97698E75C060ADADCC7026 EFFE531672F9DD1A11718D4A4E5D43A1 625F53360699257CEA1A051499C31FF7 E4AFCCB9A9DA2E7031C8E468C1612D1A 0EBC22F42B30A2E53D802BC5ACE8A719 8B909202ACBC234E7FC7D8321137B3B2 AD0F0D0985DC891363FAA3AD8D379AD6 5A7194AEA09DC2907BD3C88896565457 A659A662AAD4E6FB4018B2CDF1886C43 E16AADE1ABA75E8879F6B9D545C7C4D0 2567107CDE1C1ACC43E51BBFB8519DD5 |
Inside SceNpDrm | |
PSV | 1.00+ |
85D72F79A67C9A04D2691B1D2D30274A 731CF624E3BC68FE8B3BAD9DEFB50784 C4BBAF63D5CC431119911288854E38EA 61D7571B33EB12C7AD3BCD4610FA1CA1 B4C77D204550D6F72AB1E680A4609CCF 890B953AAC6CDCDAED9F102729843914 CA4A88BCB88D41EE0DC0E4D3E657A795 012807C500AE13A0B44247D5E40B5F9E 4ACEF46C0FA2882DF3F510961C6B8AE1 139EE661350CDD8C7A5D4F9C1CD55E04 49CB0065A88CF6376664F6C4F522AFC9 C556F16A36DA79F822D28D3C2F63DDD1 18E62B162BC73E2BE1B13F8391EEE462 70D820C8BBF3A023683EA1D079D7B4D6 F2F557A73A168AA23F882ACFDBA9A0B3 7C7EAEAE6B88B869DECDD6892813A6C3 |
Inside SceNpDrm | |
Live Area | 1.00+ |
8E5C3B05CECFC0CA1328C25009D740B2 7376208F678AC454D015BB3E67B37D05 B09990B67F6C0FE63E30AC7CC93CB2A1 C83517CCCDF37AE7A2DE3E1F817919B1 944F5ABC9C00C846D01A9A5E014FF15C 3B840669AE25D06BA0449EF6ED1C14D7 23EBA9151756B94DA5265F93AE364816 BE152285B01A56E380F285AD2106D6B5 41D950B2C84BA68559B3A10115403780 8A85884D3A74612AF76F68B646A70FEB 0EF244876671B7CB2FF0D1CC926B7CFF 8C440C12AE322E3A1EA2856EFCA24BD9 B8967C3F26038EF44B26AF23A684814B CE28806B81DC9227CE387F3820AF13FB A964F3A343D692154EEBEB917ABE861E 84EEAD728C30A33473895376E9FDC62D |
Inside SceNpDrm |
- RSA exponent is 65537 (0x10001)
registry.db0 XOR Key[edit | edit source]
This key is used by SceRegistryMgr to decode os0:kd/registry.db0
.
89FA9548CB6D779DA22534FDA935596E
Database Reconstruction Magic[edit | edit source]
BEBAFECA (or CAFEBABE byteswapped)
NID generation suffixes[edit | edit source]
- The algorithm is sha1(name + suffix).
No suffix[edit | edit source]
For some PSP and PS Vita old NIDs, there was no suffix at all: algo was simply sha1(name).
PS3 NONAME suffix[edit | edit source]
"0xbc5eba9e042504905b64274994d9c41f"
- Note that this ASCII string is used but not the hexadecimal value for it.
PS3 default suffix[edit | edit source]
6759659904250490566427499489741A
- Note that this hexadecimal value is used but not the ASCII string for it.
PS Vita NONAME suffix[edit | edit source]
c1b886af5c31846467e7ba5e2cffd64a
- Note that this hexadecimal value is used but not the ASCII string for it.
SceKrm[edit | edit source]
// key1 main (secp256r1 based) D : 0xAAB9B284FC9B0476C43C5559EEE2A1E19AAA92C5E4C234DD67F43297C714E728 Qx: 0xDE62FA3452DABD3C60067D375B3A52CE94CC77ED3E7238869EE05FE7822A5653 Qy: 0x71EC7D5C167B8DA2429AF960F5B84F4741D49233F1008D081142D1CAA07F0D8F // key1 failback (unknown curve based) D : 0x4B35AEC3D94F02078118971D71286D59A26F0FE958118A5206229477ED3A5775 Qx: 0x88657D5551E48855289D0AB827C82A35F00B5F523D24694BEA1606F8BE18D925 Qy: 0xB761CC3BAD42EA379367B995E1BEA5611823267675959EEAB5975D336F59B3A9 // key2 main (secp256r1 based) D : 0xA7B032E2ABB0C17AA91C2EB5F615E10DE3BE18A7E0CA98874F978FE65122A215 Qx: 0x1E10B4130F22D336A88B195252D6CFEA7574C942089E365622FDE221DC9E944A Qy: 0xD563C129375B9C39FE572CD634B6BBC4141ED51D47536F3ECCF291CAF11C4460 // key2 failback (unknown curve based) D: 0x8E5F93EB6EEAFCB1AC0B6A35AEA043A4C7DEFE94397E5787937024DB32A2B47F Qx: 0x33A31120E507FAED9EB3CBCD7789ABC012913C0DF14DDD98760B0DBF009C466A Qy: 0x25001960EB067612E5CA9177E37B42E8862801BA2C45A95FA494C0E51FBF4C66
ePSP Keys[edit | edit source]
ePSP PRX Decryption 16-Byte Tag Keys[edit | edit source]
These keys are used to decrypt the ePSP firmware PRX files stored in pcff.elf
Shared between Retail/Testing Tool/Development Tool firmwares
Firmware | Usage | Key | Tag | KIRK CMD7 Seed |
---|---|---|---|---|
0xE8, 0xBE, 0x2F, 0x06, 0xB1, 0x05, 0x2A, 0xB9, 0x18, 0x18, 0x03, 0xE3, 0xEB, 0x64, 0x7D, 0x26 |
0x457B0AF0 | |||
0xD4, 0x35, 0x18, 0x02, 0x29, 0x68, 0xFB, 0xA0, 0x6A, 0xA9, 0xA5, 0xED, 0x78, 0xFD, 0x2E, 0x9D |
0x457B80F0 | |||
0x08, 0x57, 0xC2, 0x49, 0x15, 0xD6, 0x2C, 0xDB, 0x62, 0xBE, 0x86, 0x6C, 0x75, 0x19, 0xDC, 0x4D |
0x457B9AF0 | |||
0x48, 0x58, 0xAA, 0x38, 0x78, 0x9A, 0x6C, 0x0D, 0x42, 0xEA, 0xC8, 0x19, 0x23, 0x34, 0x4D, 0xF0 |
0x4C949AF0 | |||
0x20, 0x00, 0x5B, 0x67, 0x48, 0x77, 0x02, 0x60, 0xCF, 0x0C, 0xAB, 0x7E, 0xAE, 0x0C, 0x55, 0xA1 |
0x4C949BF0 | |||
0x3F, 0x67, 0x09, 0xA1, 0x47, 0x71, 0xD6, 0x9E, 0x27, 0x7C, 0x7B, 0x32, 0x67, 0x0E, 0x65, 0x8A |
0x4C949CF0 | |||
0x9B, 0x92, 0x99, 0x91, 0xA2, 0xE8, 0xAA, 0x4A, 0x87, 0x10, 0xA0, 0x9A, 0xBF, 0x88, 0xC0, 0xAC |
0x4C949DF0 | |||
0x90, 0x22, 0x66, 0xE9, 0x59, 0x11, 0x9B, 0x99, 0x67, 0x39, 0x49, 0x81, 0xAB, 0x98, 0x08, 0xA6 |
0x4C949EF0 | |||
0xA0, 0xA5, 0x55, 0x0A, 0xFA, 0xB2, 0x16, 0x62, 0x05, 0xDC, 0x4B, 0x8E, 0xDA, 0xD5, 0xA5, 0xCA |
0x4C949FF0 | |||
0x78, 0x96, 0xAE, 0x9C, 0xE7, 0x89, 0x2D, 0xF5, 0x34, 0x9C, 0x29, 0x36, 0xD1, 0xF9, 0xE8, 0x3C |
0x4C94A0F0 | |||
0x71, 0x44, 0x53, 0xB6, 0xE6, 0x75, 0x3F, 0xF0, 0x8D, 0x5E, 0xB4, 0xB2, 0xEA, 0x06, 0x23, 0x6A |
0x4C94A1F0 |
ePSP IPL Xor Keys[edit | edit source]
These keys are used to xor the KIRK header of the ePSP IPL stored in os0/kd/pcbc.elf
Shared between Retail/Testing Tool/Development Tool firmwares
Firmware | Key |
---|---|
0x82, 0x41, 0xa9, 0xc6, 0x42, 0x12, 0x99, 0xc5, 0x0e, 0xe3, 0x99, 0xba, 0x66, 0x32, 0x7d, 0x73, 0x14, 0x51, 0xd9, 0x46, 0xf7, 0x32, 0x53, 0x58, 0xb1, 0xae, 0x29, 0x7d, 0xf6, 0x03, 0x91, 0x1a, 0x3a, 0x5b, 0x71, 0x75, 0x06, 0x68, 0x0d, 0x4b, 0x67, 0xeb, 0xd0, 0xf9, 0x7d, 0x79, 0xc0, 0x55, 0x06, 0x74, 0x09, 0x0d, 0x42, 0x5a, 0x95, 0x41, 0xaa, 0x2b, 0x0f, 0x17, 0x98, 0x5d, 0x5c, 0x21 | |
0x28, 0x34, 0x06, 0x24, 0x6a, 0x9b, 0x9c, 0x9f, 0x09, 0x5c, 0xf0, 0x2d, 0x98, 0x30, 0x73, 0x32, 0xec, 0xaa, 0x97, 0xcb, 0xaa, 0xc7, 0x0b, 0x10, 0x12, 0x35, 0xe7, 0x7d, 0x84, 0xa9, 0xfd, 0x16, 0x91, 0x42, 0xde, 0xb5, 0xeb, 0xd9, 0x09, 0x84, 0x6a, 0x18, 0x64, 0xd2, 0xfe, 0xb8, 0x1e, 0xcd, 0x07, 0x50, 0xd8, 0x63, 0x13, 0x0b, 0xf1, 0x90, 0x27, 0x9d, 0x46, 0xdb, 0xa0, 0x44, 0x9a, 0xf1 |