ESPHome 2026.6.0-dev
Loading...
Searching...
No Matches
xiaomi_ble.cpp
Go to the documentation of this file.
1#include "xiaomi_ble.h"
3#include "esphome/core/log.h"
4
5#ifdef USE_ESP32
6
7#include <vector>
8#include <esp_idf_version.h>
9#if ESP_IDF_VERSION >= ESP_IDF_VERSION_VAL(6, 0, 0)
10#include <psa/crypto.h>
11#else
12#include "mbedtls/ccm.h"
13#endif
14
16
17static const char *const TAG = "xiaomi_ble";
18
19// Maximum bytes to log in very verbose hex output (covers largest packet of ~24 bytes)
20static constexpr size_t XIAOMI_MAX_LOG_BYTES = 32;
21
22bool parse_xiaomi_value(uint16_t value_type, const uint8_t *data, uint8_t value_length, XiaomiParseResult &result) {
23 // button pressed, 3 bytes, only byte 3 is used for supported devices so far
24 if ((value_type == 0x1001) && (value_length == 3)) {
25 result.button_press = data[2] == 0;
26 return true;
27 }
28 // motion detection, 1 byte, 8-bit unsigned integer
29 else if ((value_type == 0x0003) && (value_length == 1)) {
30 result.has_motion = data[0];
31 }
32 // temperature, 2 bytes, 16-bit signed integer (LE), 0.1 °C
33 else if ((value_type == 0x1004) && (value_length == 2)) {
34 const int16_t temperature = encode_uint16(data[1], data[0]);
35 result.temperature = temperature / 10.0f;
36 }
37 // humidity, 2 bytes, 16-bit signed integer (LE), 0.1 %
38 else if ((value_type == 0x1006) && (value_length == 2)) {
39 const int16_t humidity = encode_uint16(data[1], data[0]);
40 result.humidity = humidity / 10.0f;
41 }
42 // illuminance (+ motion), 3 bytes, 24-bit unsigned integer (LE), 1 lx
43 else if (((value_type == 0x1007) || (value_type == 0x000F)) && (value_length == 3)) {
44 const uint32_t illuminance = encode_uint24(data[2], data[1], data[0]);
45 result.illuminance = illuminance;
46 result.is_light = illuminance >= 100;
47 if (value_type == 0x0F)
48 result.has_motion = true;
49 }
50 // soil moisture, 1 byte, 8-bit unsigned integer, 1 %
51 else if ((value_type == 0x1008) && (value_length == 1)) {
52 result.moisture = data[0];
53 }
54 // conductivity, 2 bytes, 16-bit unsigned integer (LE), 1 µS/cm
55 else if ((value_type == 0x1009) && (value_length == 2)) {
56 const uint16_t conductivity = encode_uint16(data[1], data[0]);
57 result.conductivity = conductivity;
58 }
59 // battery / MiaoMiaoce battery, 1 byte, 8-bit unsigned integer, 1 %
60 else if ((value_type == 0x100A || value_type == 0x4803) && (value_length == 1)) {
61 result.battery_level = data[0];
62 }
63 // temperature + humidity, 4 bytes, 16-bit signed integer (LE) each, 0.1 °C, 0.1 %
64 else if ((value_type == 0x100D) && (value_length == 4)) {
65 const int16_t temperature = encode_uint16(data[1], data[0]);
66 const int16_t humidity = encode_uint16(data[3], data[2]);
67 result.temperature = temperature / 10.0f;
68 result.humidity = humidity / 10.0f;
69 }
70 // formaldehyde, 2 bytes, 16-bit unsigned integer (LE), 0.01 mg / m3
71 else if ((value_type == 0x1010) && (value_length == 2)) {
72 const uint16_t formaldehyde = encode_uint16(data[1], data[0]);
73 result.formaldehyde = formaldehyde / 100.0f;
74 }
75 // on/off state, 1 byte, 8-bit unsigned integer
76 else if ((value_type == 0x1012) && (value_length == 1)) {
77 result.is_active = data[0];
78 }
79 // mosquito tablet, 1 byte, 8-bit unsigned integer, 1 %
80 else if ((value_type == 0x1013) && (value_length == 1)) {
81 result.tablet = data[0];
82 }
83 // idle time since last motion, 4 byte, 32-bit unsigned integer, 1 min
84 else if ((value_type == 0x1017) && (value_length == 4)) {
85 const uint32_t idle_time = encode_uint32(data[3], data[2], data[1], data[0]);
86 result.idle_time = idle_time / 60.0f;
87 result.has_motion = !idle_time;
88 } else if ((value_type == 0x1018) && (value_length == 1)) {
89 result.is_light = data[0];
90 }
91 // MiaoMiaoce temperature, 4 bytes, float, 0.1 °C
92 else if ((value_type == 0x4C01) && (value_length == 4)) {
93 const uint32_t int_number = encode_uint32(data[3], data[2], data[1], data[0]);
94 float temperature;
95 std::memcpy(&temperature, &int_number, sizeof(temperature));
96 result.temperature = temperature;
97 }
98 // MiaoMiaoce humidity, 1 byte, 8-bit unsigned integer, 1 %
99 else if ((value_type == 0x4C02) && (value_length == 1)) {
100 result.humidity = data[0];
101 }
102 // XMWSDJ04MMC humidity, 4 bytes, float, 0.1 °C
103 else if ((value_type == 0x4C08) && (value_length == 4)) {
104 const uint32_t int_number = encode_uint32(data[3], data[2], data[1], data[0]);
105 float humidity;
106 std::memcpy(&humidity, &int_number, sizeof(humidity));
107 result.humidity = humidity;
108 } else {
109 return false;
110 }
111
112 return true;
113}
114
115bool parse_xiaomi_message(const std::vector<uint8_t> &message, XiaomiParseResult &result) {
116 result.has_encryption = message[0] & 0x08; // update encryption status
117 if (result.has_encryption) {
118 ESP_LOGVV(TAG, "parse_xiaomi_message(): payload is encrypted, stop reading message.");
119 return false;
120 }
121
122 // Data point specs
123 // Byte 0: type
124 // Byte 1: fixed 0x10
125 // Byte 2: length
126 // Byte 3..3+len-1: data point value
127
128 if (result.raw_offset < 0 || static_cast<size_t>(result.raw_offset) >= message.size()) {
129 ESP_LOGVV(TAG, "parse_xiaomi_message(): raw_offset (%d) exceeds message size (%d)!", result.raw_offset,
130 message.size());
131 return false;
132 }
133 const uint8_t *payload = message.data() + result.raw_offset;
134 uint8_t payload_length = message.size() - result.raw_offset;
135 uint8_t payload_offset = 0;
136 bool success = false;
137
138 if (payload_length < 4) {
139 ESP_LOGVV(TAG, "parse_xiaomi_message(): payload has wrong size (%d)!", payload_length);
140 return false;
141 }
142
143 while (payload_length > 3) {
144 if (payload[payload_offset + 1] != 0x10 && payload[payload_offset + 1] != 0x00 &&
145 payload[payload_offset + 1] != 0x4C && payload[payload_offset + 1] != 0x48) {
146 ESP_LOGVV(TAG, "parse_xiaomi_message(): fixed byte not found, stop parsing residual data.");
147 break;
148 }
149
150 const uint8_t value_length = payload[payload_offset + 2];
151 if ((value_length < 1) || (value_length > 4) || (payload_length < (3 + value_length))) {
152 ESP_LOGVV(TAG, "parse_xiaomi_message(): value has wrong size (%d)!", value_length);
153 break;
154 }
155
156 const uint16_t value_type = encode_uint16(payload[payload_offset + 1], payload[payload_offset + 0]);
157 const uint8_t *data = &payload[payload_offset + 3];
158
159 if (parse_xiaomi_value(value_type, data, value_length, result))
160 success = true;
161
162 payload_length -= 3 + value_length;
163 payload_offset += 3 + value_length;
164 }
165
166 return success;
167}
168
169optional<XiaomiParseResult> parse_xiaomi_header(const esp32_ble_tracker::ServiceData &service_data) {
170 XiaomiParseResult result;
171 if (!service_data.uuid.contains(0x95, 0xFE)) {
172 ESP_LOGVV(TAG, "parse_xiaomi_header(): no service data UUID magic bytes.");
173 return {};
174 }
175
176 auto raw = service_data.data;
177 if (raw.size() < 5) {
178 ESP_LOGVV(TAG, "parse_xiaomi_header(): service data too short (%d).", raw.size());
179 return {};
180 }
181 result.has_data = raw[0] & 0x40;
182 result.has_capability = raw[0] & 0x20;
183 result.has_encryption = raw[0] & 0x08;
184
185 if (!result.has_data) {
186 ESP_LOGVV(TAG, "parse_xiaomi_header(): service data has no DATA flag.");
187 return {};
188 }
189
190 static uint8_t last_frame_count = 0;
191 if (last_frame_count == raw[4]) {
192 ESP_LOGVV(TAG, "parse_xiaomi_header(): duplicate data packet received (%d).", static_cast<int>(last_frame_count));
193 result.is_duplicate = true;
194 return {};
195 }
196 last_frame_count = raw[4];
197 result.is_duplicate = false;
198 result.raw_offset = result.has_capability ? 12 : 11;
199
200 const uint16_t device_uuid = encode_uint16(raw[3], raw[2]);
201
202 if (device_uuid == 0x0098) { // MiFlora
204 result.name = "HHCCJCY01";
205 } else if (device_uuid == 0x01aa) { // round body, segment LCD
207 result.name = "LYWSDCGQ";
208 } else if (device_uuid == 0x015d) { // FlowerPot, RoPot
210 result.name = "HHCCPOT002";
211 } else if (device_uuid == 0x02df) { // Xiaomi (Honeywell) formaldehyde sensor, OLED display
213 result.name = "JQJCY01YM";
214 } else if (device_uuid == 0x03dd) { // Philips/Xiaomi BLE nightlight
216 result.name = "MUE4094RT";
217 result.raw_offset -= 6;
218 } else if (device_uuid == 0x0347 || // ClearGrass-branded, round body, e-ink display
219 device_uuid == 0x0B48) { // Qingping-branded, round body, e-ink display — with bindkeys
221 result.name = "CGG1";
222 } else if (device_uuid == 0x03bc) { // VegTrug Grow Care Garden
224 result.name = "GCLS002";
225 } else if (device_uuid == 0x045b) { // rectangular body, e-ink display
227 result.name = "LYWSD02";
228 } else if (device_uuid == 0x2542) { // rectangular body, e-ink display — with bindkeys
230 result.name = "LYWSD02MMC";
231 if (raw.size() == 19)
232 result.raw_offset -= 6;
233 } else if (device_uuid == 0x040a) { // Mosquito Repellent Smart Version
235 result.name = "WX08ZM";
236 } else if (device_uuid == 0x0576) { // Cleargrass (Qingping) alarm clock, segment LCD
238 result.name = "CGD1";
239 } else if (device_uuid == 0x066F) { // Cleargrass (Qingping) Temp & RH Lite
241 result.name = "CGDK2";
242 } else if (device_uuid == 0x055b) { // small square body, segment LCD, encrypted
244 result.name = "LYWSD03MMC";
245 } else if (device_uuid == 0x1203) { // small square body, e-ink display, encrypted
247 result.name = "XMWSDJ04MMC";
248 if (raw.size() == 19)
249 result.raw_offset -= 6;
250 } else if (device_uuid == 0x07f6) { // Xiaomi-Yeelight BLE nightlight
252 result.name = "MJYD02YLA";
253 if (raw.size() == 19)
254 result.raw_offset -= 6;
255 } else if (device_uuid == 0x06d3) { // rectangular body, e-ink display with alarm
257 result.name = "MHOC303";
258 } else if (device_uuid == 0x0387) { // square body, e-ink display
260 result.name = "MHOC401";
261 } else if (device_uuid == 0x0A83) { // Qingping-branded, motion & ambient light sensor
263 result.name = "CGPR1";
264 if (raw.size() == 19)
265 result.raw_offset -= 6;
266 } else if (device_uuid == 0x0A8D) { // Xiaomi Mi Motion Sensor 2
268 result.name = "RTCGQ02LM";
269 if (raw.size() == 19)
270 result.raw_offset -= 6;
271 } else {
272 ESP_LOGVV(TAG, "parse_xiaomi_header(): unknown device, no magic bytes.");
273 return {};
274 }
275
276 return result;
277}
278
279bool decrypt_xiaomi_payload(std::vector<uint8_t> &raw, const uint8_t *bindkey, const uint64_t &address) {
280 if ((raw.size() != 19) && ((raw.size() < 22) || (raw.size() > 24))) {
281 ESP_LOGVV(TAG, "decrypt_xiaomi_payload(): data packet has wrong size (%d)!", raw.size());
282#if ESPHOME_LOG_LEVEL >= ESPHOME_LOG_LEVEL_VERY_VERBOSE
283 char hex_buf[format_hex_pretty_size(XIAOMI_MAX_LOG_BYTES)];
284#endif
285 ESP_LOGVV(TAG, " Packet : %s", format_hex_pretty_to(hex_buf, raw.data(), raw.size()));
286 return false;
287 }
288
289 uint8_t mac_reverse[6] = {0};
290 mac_reverse[5] = (uint8_t) (address >> 40);
291 mac_reverse[4] = (uint8_t) (address >> 32);
292 mac_reverse[3] = (uint8_t) (address >> 24);
293 mac_reverse[2] = (uint8_t) (address >> 16);
294 mac_reverse[1] = (uint8_t) (address >> 8);
295 mac_reverse[0] = (uint8_t) (address >> 0);
296
297 XiaomiAESVector vector{.key = {0},
298 .plaintext = {0},
299 .ciphertext = {0},
300 .authdata = {0x11},
301 .iv = {0},
302 .tag = {0},
303 .keysize = 16,
304 .authsize = 1,
305 .datasize = 0,
306 .tagsize = 4,
307 .ivsize = 12};
308
309 vector.datasize = (raw.size() == 19) ? raw.size() - 12 : raw.size() - 18;
310 int cipher_pos = (raw.size() == 19) ? 5 : 11;
311
312 const uint8_t *v = raw.data();
313
314 memcpy(vector.key, bindkey, vector.keysize);
315 memcpy(vector.ciphertext, v + cipher_pos, vector.datasize);
316 memcpy(vector.tag, v + raw.size() - vector.tagsize, vector.tagsize);
317 memcpy(vector.iv, mac_reverse, 6); // MAC address reverse
318 memcpy(vector.iv + 6, v + 2, 3); // sensor type (2) + packet id (1)
319 memcpy(vector.iv + 9, v + raw.size() - 7, 3); // payload counter
320
321#if ESP_IDF_VERSION >= ESP_IDF_VERSION_VAL(6, 0, 0)
322 // PSA AEAD expects ciphertext + tag concatenated
323 uint8_t ct_with_tag[sizeof(vector.ciphertext) + sizeof(vector.tag)];
324 memcpy(ct_with_tag, vector.ciphertext, vector.datasize);
325 memcpy(ct_with_tag + vector.datasize, vector.tag, vector.tagsize);
326 size_t ct_with_tag_size = vector.datasize + vector.tagsize;
327
328 psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
329 psa_set_key_type(&attributes, PSA_KEY_TYPE_AES);
330 psa_set_key_bits(&attributes, vector.keysize * 8);
331 psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_DECRYPT);
332 psa_set_key_algorithm(&attributes, PSA_ALG_AEAD_WITH_SHORTENED_TAG(PSA_ALG_CCM, vector.tagsize));
333
334 mbedtls_svc_key_id_t key_id;
335 if (psa_import_key(&attributes, vector.key, vector.keysize, &key_id) != PSA_SUCCESS) {
336 ESP_LOGVV(TAG, "decrypt_xiaomi_payload(): psa_import_key() failed.");
337 return false;
338 }
339
340 size_t plaintext_length;
341 psa_status_t status = psa_aead_decrypt(key_id, PSA_ALG_AEAD_WITH_SHORTENED_TAG(PSA_ALG_CCM, vector.tagsize),
342 vector.iv, vector.ivsize, vector.authdata, vector.authsize, ct_with_tag,
343 ct_with_tag_size, vector.plaintext, vector.datasize, &plaintext_length);
344 psa_destroy_key(key_id);
345 bool decrypt_ok = (status == PSA_SUCCESS && plaintext_length == vector.datasize);
346#else
347 mbedtls_ccm_context ctx;
348 mbedtls_ccm_init(&ctx);
349
350 int ret = mbedtls_ccm_setkey(&ctx, MBEDTLS_CIPHER_ID_AES, vector.key, vector.keysize * 8);
351 if (ret) {
352 ESP_LOGVV(TAG, "decrypt_xiaomi_payload(): mbedtls_ccm_setkey() failed.");
353 mbedtls_ccm_free(&ctx);
354 return false;
355 }
356
357 ret = mbedtls_ccm_auth_decrypt(&ctx, vector.datasize, vector.iv, vector.ivsize, vector.authdata, vector.authsize,
358 vector.ciphertext, vector.plaintext, vector.tag, vector.tagsize);
359 mbedtls_ccm_free(&ctx);
360 bool decrypt_ok = (ret == 0);
361#endif
362
363 if (!decrypt_ok) {
364 uint8_t mac_address[6] = {0};
365 memcpy(mac_address, mac_reverse + 5, 1);
366 memcpy(mac_address + 1, mac_reverse + 4, 1);
367 memcpy(mac_address + 2, mac_reverse + 3, 1);
368 memcpy(mac_address + 3, mac_reverse + 2, 1);
369 memcpy(mac_address + 4, mac_reverse + 1, 1);
370 memcpy(mac_address + 5, mac_reverse, 1);
371 ESP_LOGVV(TAG, "decrypt_xiaomi_payload(): authenticated decryption failed.");
372#if ESPHOME_LOG_LEVEL >= ESPHOME_LOG_LEVEL_VERY_VERBOSE
373 char mac_buf[MAC_ADDRESS_PRETTY_BUFFER_SIZE];
374 format_mac_addr_upper(mac_address, mac_buf);
375 char hex_buf[format_hex_pretty_size(XIAOMI_MAX_LOG_BYTES)];
376#endif
377 ESP_LOGVV(TAG, " MAC address : %s", mac_buf);
378 ESP_LOGVV(TAG, " Packet : %s", format_hex_pretty_to(hex_buf, raw.data(), raw.size()));
379 ESP_LOGVV(TAG, " Key : %s", format_hex_pretty_to(hex_buf, vector.key, vector.keysize));
380 ESP_LOGVV(TAG, " Iv : %s", format_hex_pretty_to(hex_buf, vector.iv, vector.ivsize));
381 ESP_LOGVV(TAG, " Cipher : %s", format_hex_pretty_to(hex_buf, vector.ciphertext, vector.datasize));
382 ESP_LOGVV(TAG, " Tag : %s", format_hex_pretty_to(hex_buf, vector.tag, vector.tagsize));
383 return false;
384 }
385
386 // replace encrypted payload with plaintext
387 uint8_t *p = vector.plaintext;
388 for (std::vector<uint8_t>::iterator it = raw.begin() + cipher_pos; it != raw.begin() + cipher_pos + vector.datasize;
389 ++it) {
390 *it = *(p++);
391 }
392
393 // clear encrypted flag
394 raw[0] &= ~0x08;
395
396 ESP_LOGVV(TAG, "decrypt_xiaomi_payload(): authenticated decryption passed.");
397#if ESPHOME_LOG_LEVEL >= ESPHOME_LOG_LEVEL_VERY_VERBOSE
398 char hex_buf[format_hex_pretty_size(XIAOMI_MAX_LOG_BYTES)];
399#endif
400 ESP_LOGVV(TAG, " Plaintext : %s, Packet : %d",
401 format_hex_pretty_to(hex_buf, raw.data() + cipher_pos, vector.datasize), static_cast<int>(raw[4]));
402
403 return true;
404}
405
406bool report_xiaomi_results(const optional<XiaomiParseResult> &result, const char *address) {
407 if (!result.has_value()) {
408 ESP_LOGVV(TAG, "report_xiaomi_results(): no results available.");
409 return false;
410 }
411
412 ESP_LOGD(TAG, "Got Xiaomi %s (%s):", result->name.c_str(), address);
413
414 if (result->temperature.has_value()) {
415 ESP_LOGD(TAG, " Temperature: %.1f°C", *result->temperature);
416 }
417 if (result->humidity.has_value()) {
418 ESP_LOGD(TAG, " Humidity: %.1f%%", *result->humidity);
419 }
420 if (result->battery_level.has_value()) {
421 ESP_LOGD(TAG, " Battery Level: %.0f%%", *result->battery_level);
422 }
423 if (result->conductivity.has_value()) {
424 ESP_LOGD(TAG, " Conductivity: %.0fµS/cm", *result->conductivity);
425 }
426 if (result->illuminance.has_value()) {
427 ESP_LOGD(TAG, " Illuminance: %.0flx", *result->illuminance);
428 }
429 if (result->moisture.has_value()) {
430 ESP_LOGD(TAG, " Moisture: %.0f%%", *result->moisture);
431 }
432 if (result->tablet.has_value()) {
433 ESP_LOGD(TAG, " Mosquito tablet: %.0f%%", *result->tablet);
434 }
435 if (result->is_active.has_value()) {
436 ESP_LOGD(TAG, " Repellent: %s", (*result->is_active) ? "on" : "off");
437 }
438 if (result->has_motion.has_value()) {
439 ESP_LOGD(TAG, " Motion: %s", (*result->has_motion) ? "yes" : "no");
440 }
441 if (result->is_light.has_value()) {
442 ESP_LOGD(TAG, " Light: %s", (*result->is_light) ? "on" : "off");
443 }
444 if (result->button_press.has_value()) {
445 ESP_LOGD(TAG, " Button: %s", (*result->button_press) ? "pressed" : "");
446 }
447
448 return true;
449}
450
452 // Previously the message was parsed twice per packet, once by XiaomiListener::parse_device()
453 // and then again by the respective device class's parse_device() function. Parsing the header
454 // here and then for each device seems to be unnecessary and complicates the duplicate packet filtering.
455 // Hence I disabled the call to parse_xiaomi_header() here and the message parsing is done entirely
456 // in the respective device instance. The XiaomiListener class is defined in __init__.py and I was not
457 // able to remove it entirely.
458
459 return false; // with true it's not showing device scans
460}
461
462} // namespace esphome::xiaomi_ble
463
464#endif
uint8_t address
Definition bl0906.h:4
uint8_t raw[35]
Definition bl0939.h:0
uint8_t status
Definition bl0942.h:8
bool contains(uint8_t data1, uint8_t data2) const
Definition ble_uuid.cpp:112
bool parse_device(const esp32_ble_tracker::ESPBTDevice &device) override
const LogString * message
Definition component.cpp:35
bool decrypt_xiaomi_payload(std::vector< uint8_t > &raw, const uint8_t *bindkey, const uint64_t &address)
optional< XiaomiParseResult > parse_xiaomi_header(const esp32_ble_tracker::ServiceData &service_data)
bool parse_xiaomi_value(uint16_t value_type, const uint8_t *data, uint8_t value_length, XiaomiParseResult &result)
bool parse_xiaomi_message(const std::vector< uint8_t > &message, XiaomiParseResult &result)
bool report_xiaomi_results(const optional< XiaomiParseResult > &result, const char *address)
constexpr uint32_t encode_uint24(uint8_t byte1, uint8_t byte2, uint8_t byte3)
Encode a 24-bit value given three bytes in most to least significant byte order.
Definition helpers.h:863
char * format_hex_pretty_to(char *buffer, size_t buffer_size, const uint8_t *data, size_t length, char separator)
Format byte array as uppercase hex to buffer (base implementation).
Definition helpers.cpp:340
constexpr size_t format_hex_pretty_size(size_t byte_count)
Calculate buffer size needed for format_hex_pretty_to with separator: "XX:XX:...:XX\0".
Definition helpers.h:1386
constexpr uint32_t encode_uint32(uint8_t byte1, uint8_t byte2, uint8_t byte3, uint8_t byte4)
Encode a 32-bit value given four bytes in most to least significant byte order.
Definition helpers.h:867
constexpr uint16_t encode_uint16(uint8_t msb, uint8_t lsb)
Encode a 16-bit value given the most and least significant byte.
Definition helpers.h:859
char * format_mac_addr_upper(const uint8_t *mac, char *output)
Format MAC address as XX:XX:XX:XX:XX:XX (uppercase, colon separators)
Definition helpers.h:1453
static void uint32_t
enum esphome::xiaomi_ble::XiaomiParseResult::@197 type
uint16_t temperature
Definition sun_gtil2.cpp:12