PDA

View Full Version : Toyota DST40 key diversification algo



devzzo
11th February, 2023, 01:12 AM
Hey all,

I was wondering if anyone is willing to share the algorithm used to derive the DST40 key from publicly readable transponder data? I know of a related work for DST80 (the "Dismantling DST80-based Immobiliser Systems" paper) where it's based on pg1, pg2, and serial, but was unable to find anything concrete for DST40 devices.

Any pointers will be greatly appreciated!

devzzo
14th February, 2023, 11:25 AM
Bumping the topic up, as this might be of general interest to everyone.

wakawaka
18th September, 2023, 03:14 PM
Anyone have info on this

avital
18th September, 2023, 06:54 PM
Hey all,

I was wondering if anyone is willing to share the algorithm used to derive the DST40 key from publicly readable transponder data? I know of a related work for DST80 (the "Dismantling DST80-based Immobiliser Systems" paper) where it's based on pg1, pg2, and serial, but was unable to find anything concrete for DST40 devices.

Any pointers will be greatly appreciated!


this algorithm is one-way, so it is not possible to reverse the function to obtain the cryptokey, decoding the cryptokey is done using a different method.