ESPHome 2026.5.0-dev
Loading...
Searching...
No Matches
xiaomi_ble.cpp
Go to the documentation of this file.
1#include "xiaomi_ble.h"
3#include "esphome/core/log.h"
4
5#ifdef USE_ESP32
6
7#include <vector>
8#include <esp_idf_version.h>
9#if ESP_IDF_VERSION >= ESP_IDF_VERSION_VAL(6, 0, 0)
10#include <psa/crypto.h>
11#else
12#include "mbedtls/ccm.h"
13#endif
14
15namespace esphome {
16namespace xiaomi_ble {
17
18static const char *const TAG = "xiaomi_ble";
19
20// Maximum bytes to log in very verbose hex output (covers largest packet of ~24 bytes)
21static constexpr size_t XIAOMI_MAX_LOG_BYTES = 32;
22
23bool parse_xiaomi_value(uint16_t value_type, const uint8_t *data, uint8_t value_length, XiaomiParseResult &result) {
24 // button pressed, 3 bytes, only byte 3 is used for supported devices so far
25 if ((value_type == 0x1001) && (value_length == 3)) {
26 result.button_press = data[2] == 0;
27 return true;
28 }
29 // motion detection, 1 byte, 8-bit unsigned integer
30 else if ((value_type == 0x0003) && (value_length == 1)) {
31 result.has_motion = data[0];
32 }
33 // temperature, 2 bytes, 16-bit signed integer (LE), 0.1 °C
34 else if ((value_type == 0x1004) && (value_length == 2)) {
35 const int16_t temperature = encode_uint16(data[1], data[0]);
36 result.temperature = temperature / 10.0f;
37 }
38 // humidity, 2 bytes, 16-bit signed integer (LE), 0.1 %
39 else if ((value_type == 0x1006) && (value_length == 2)) {
40 const int16_t humidity = encode_uint16(data[1], data[0]);
41 result.humidity = humidity / 10.0f;
42 }
43 // illuminance (+ motion), 3 bytes, 24-bit unsigned integer (LE), 1 lx
44 else if (((value_type == 0x1007) || (value_type == 0x000F)) && (value_length == 3)) {
45 const uint32_t illuminance = encode_uint24(data[2], data[1], data[0]);
46 result.illuminance = illuminance;
47 result.is_light = illuminance >= 100;
48 if (value_type == 0x0F)
49 result.has_motion = true;
50 }
51 // soil moisture, 1 byte, 8-bit unsigned integer, 1 %
52 else if ((value_type == 0x1008) && (value_length == 1)) {
53 result.moisture = data[0];
54 }
55 // conductivity, 2 bytes, 16-bit unsigned integer (LE), 1 µS/cm
56 else if ((value_type == 0x1009) && (value_length == 2)) {
57 const uint16_t conductivity = encode_uint16(data[1], data[0]);
58 result.conductivity = conductivity;
59 }
60 // battery / MiaoMiaoce battery, 1 byte, 8-bit unsigned integer, 1 %
61 else if ((value_type == 0x100A || value_type == 0x4803) && (value_length == 1)) {
62 result.battery_level = data[0];
63 }
64 // temperature + humidity, 4 bytes, 16-bit signed integer (LE) each, 0.1 °C, 0.1 %
65 else if ((value_type == 0x100D) && (value_length == 4)) {
66 const int16_t temperature = encode_uint16(data[1], data[0]);
67 const int16_t humidity = encode_uint16(data[3], data[2]);
68 result.temperature = temperature / 10.0f;
69 result.humidity = humidity / 10.0f;
70 }
71 // formaldehyde, 2 bytes, 16-bit unsigned integer (LE), 0.01 mg / m3
72 else if ((value_type == 0x1010) && (value_length == 2)) {
73 const uint16_t formaldehyde = encode_uint16(data[1], data[0]);
74 result.formaldehyde = formaldehyde / 100.0f;
75 }
76 // on/off state, 1 byte, 8-bit unsigned integer
77 else if ((value_type == 0x1012) && (value_length == 1)) {
78 result.is_active = data[0];
79 }
80 // mosquito tablet, 1 byte, 8-bit unsigned integer, 1 %
81 else if ((value_type == 0x1013) && (value_length == 1)) {
82 result.tablet = data[0];
83 }
84 // idle time since last motion, 4 byte, 32-bit unsigned integer, 1 min
85 else if ((value_type == 0x1017) && (value_length == 4)) {
86 const uint32_t idle_time = encode_uint32(data[3], data[2], data[1], data[0]);
87 result.idle_time = idle_time / 60.0f;
88 result.has_motion = !idle_time;
89 } else if ((value_type == 0x1018) && (value_length == 1)) {
90 result.is_light = data[0];
91 }
92 // MiaoMiaoce temperature, 4 bytes, float, 0.1 °C
93 else if ((value_type == 0x4C01) && (value_length == 4)) {
94 const uint32_t int_number = encode_uint32(data[3], data[2], data[1], data[0]);
95 float temperature;
96 std::memcpy(&temperature, &int_number, sizeof(temperature));
97 result.temperature = temperature;
98 }
99 // MiaoMiaoce humidity, 1 byte, 8-bit unsigned integer, 1 %
100 else if ((value_type == 0x4C02) && (value_length == 1)) {
101 result.humidity = data[0];
102 }
103 // XMWSDJ04MMC humidity, 4 bytes, float, 0.1 °C
104 else if ((value_type == 0x4C08) && (value_length == 4)) {
105 const uint32_t int_number = encode_uint32(data[3], data[2], data[1], data[0]);
106 float humidity;
107 std::memcpy(&humidity, &int_number, sizeof(humidity));
108 result.humidity = humidity;
109 } else {
110 return false;
111 }
112
113 return true;
114}
115
116bool parse_xiaomi_message(const std::vector<uint8_t> &message, XiaomiParseResult &result) {
117 result.has_encryption = message[0] & 0x08; // update encryption status
118 if (result.has_encryption) {
119 ESP_LOGVV(TAG, "parse_xiaomi_message(): payload is encrypted, stop reading message.");
120 return false;
121 }
122
123 // Data point specs
124 // Byte 0: type
125 // Byte 1: fixed 0x10
126 // Byte 2: length
127 // Byte 3..3+len-1: data point value
128
129 if (result.raw_offset < 0 || static_cast<size_t>(result.raw_offset) >= message.size()) {
130 ESP_LOGVV(TAG, "parse_xiaomi_message(): raw_offset (%d) exceeds message size (%d)!", result.raw_offset,
131 message.size());
132 return false;
133 }
134 const uint8_t *payload = message.data() + result.raw_offset;
135 uint8_t payload_length = message.size() - result.raw_offset;
136 uint8_t payload_offset = 0;
137 bool success = false;
138
139 if (payload_length < 4) {
140 ESP_LOGVV(TAG, "parse_xiaomi_message(): payload has wrong size (%d)!", payload_length);
141 return false;
142 }
143
144 while (payload_length > 3) {
145 if (payload[payload_offset + 1] != 0x10 && payload[payload_offset + 1] != 0x00 &&
146 payload[payload_offset + 1] != 0x4C && payload[payload_offset + 1] != 0x48) {
147 ESP_LOGVV(TAG, "parse_xiaomi_message(): fixed byte not found, stop parsing residual data.");
148 break;
149 }
150
151 const uint8_t value_length = payload[payload_offset + 2];
152 if ((value_length < 1) || (value_length > 4) || (payload_length < (3 + value_length))) {
153 ESP_LOGVV(TAG, "parse_xiaomi_message(): value has wrong size (%d)!", value_length);
154 break;
155 }
156
157 const uint16_t value_type = encode_uint16(payload[payload_offset + 1], payload[payload_offset + 0]);
158 const uint8_t *data = &payload[payload_offset + 3];
159
160 if (parse_xiaomi_value(value_type, data, value_length, result))
161 success = true;
162
163 payload_length -= 3 + value_length;
164 payload_offset += 3 + value_length;
165 }
166
167 return success;
168}
169
170optional<XiaomiParseResult> parse_xiaomi_header(const esp32_ble_tracker::ServiceData &service_data) {
171 XiaomiParseResult result;
172 if (!service_data.uuid.contains(0x95, 0xFE)) {
173 ESP_LOGVV(TAG, "parse_xiaomi_header(): no service data UUID magic bytes.");
174 return {};
175 }
176
177 auto raw = service_data.data;
178 if (raw.size() < 5) {
179 ESP_LOGVV(TAG, "parse_xiaomi_header(): service data too short (%d).", raw.size());
180 return {};
181 }
182 result.has_data = raw[0] & 0x40;
183 result.has_capability = raw[0] & 0x20;
184 result.has_encryption = raw[0] & 0x08;
185
186 if (!result.has_data) {
187 ESP_LOGVV(TAG, "parse_xiaomi_header(): service data has no DATA flag.");
188 return {};
189 }
190
191 static uint8_t last_frame_count = 0;
192 if (last_frame_count == raw[4]) {
193 ESP_LOGVV(TAG, "parse_xiaomi_header(): duplicate data packet received (%d).", static_cast<int>(last_frame_count));
194 result.is_duplicate = true;
195 return {};
196 }
197 last_frame_count = raw[4];
198 result.is_duplicate = false;
199 result.raw_offset = result.has_capability ? 12 : 11;
200
201 const uint16_t device_uuid = encode_uint16(raw[3], raw[2]);
202
203 if (device_uuid == 0x0098) { // MiFlora
205 result.name = "HHCCJCY01";
206 } else if (device_uuid == 0x01aa) { // round body, segment LCD
208 result.name = "LYWSDCGQ";
209 } else if (device_uuid == 0x015d) { // FlowerPot, RoPot
211 result.name = "HHCCPOT002";
212 } else if (device_uuid == 0x02df) { // Xiaomi (Honeywell) formaldehyde sensor, OLED display
214 result.name = "JQJCY01YM";
215 } else if (device_uuid == 0x03dd) { // Philips/Xiaomi BLE nightlight
217 result.name = "MUE4094RT";
218 result.raw_offset -= 6;
219 } else if (device_uuid == 0x0347 || // ClearGrass-branded, round body, e-ink display
220 device_uuid == 0x0B48) { // Qingping-branded, round body, e-ink display — with bindkeys
222 result.name = "CGG1";
223 } else if (device_uuid == 0x03bc) { // VegTrug Grow Care Garden
225 result.name = "GCLS002";
226 } else if (device_uuid == 0x045b) { // rectangular body, e-ink display
228 result.name = "LYWSD02";
229 } else if (device_uuid == 0x2542) { // rectangular body, e-ink display — with bindkeys
231 result.name = "LYWSD02MMC";
232 if (raw.size() == 19)
233 result.raw_offset -= 6;
234 } else if (device_uuid == 0x040a) { // Mosquito Repellent Smart Version
236 result.name = "WX08ZM";
237 } else if (device_uuid == 0x0576) { // Cleargrass (Qingping) alarm clock, segment LCD
239 result.name = "CGD1";
240 } else if (device_uuid == 0x066F) { // Cleargrass (Qingping) Temp & RH Lite
242 result.name = "CGDK2";
243 } else if (device_uuid == 0x055b) { // small square body, segment LCD, encrypted
245 result.name = "LYWSD03MMC";
246 } else if (device_uuid == 0x1203) { // small square body, e-ink display, encrypted
248 result.name = "XMWSDJ04MMC";
249 if (raw.size() == 19)
250 result.raw_offset -= 6;
251 } else if (device_uuid == 0x07f6) { // Xiaomi-Yeelight BLE nightlight
253 result.name = "MJYD02YLA";
254 if (raw.size() == 19)
255 result.raw_offset -= 6;
256 } else if (device_uuid == 0x06d3) { // rectangular body, e-ink display with alarm
258 result.name = "MHOC303";
259 } else if (device_uuid == 0x0387) { // square body, e-ink display
261 result.name = "MHOC401";
262 } else if (device_uuid == 0x0A83) { // Qingping-branded, motion & ambient light sensor
264 result.name = "CGPR1";
265 if (raw.size() == 19)
266 result.raw_offset -= 6;
267 } else if (device_uuid == 0x0A8D) { // Xiaomi Mi Motion Sensor 2
269 result.name = "RTCGQ02LM";
270 if (raw.size() == 19)
271 result.raw_offset -= 6;
272 } else {
273 ESP_LOGVV(TAG, "parse_xiaomi_header(): unknown device, no magic bytes.");
274 return {};
275 }
276
277 return result;
278}
279
280bool decrypt_xiaomi_payload(std::vector<uint8_t> &raw, const uint8_t *bindkey, const uint64_t &address) {
281 if ((raw.size() != 19) && ((raw.size() < 22) || (raw.size() > 24))) {
282 ESP_LOGVV(TAG, "decrypt_xiaomi_payload(): data packet has wrong size (%d)!", raw.size());
283#if ESPHOME_LOG_LEVEL >= ESPHOME_LOG_LEVEL_VERY_VERBOSE
284 char hex_buf[format_hex_pretty_size(XIAOMI_MAX_LOG_BYTES)];
285#endif
286 ESP_LOGVV(TAG, " Packet : %s", format_hex_pretty_to(hex_buf, raw.data(), raw.size()));
287 return false;
288 }
289
290 uint8_t mac_reverse[6] = {0};
291 mac_reverse[5] = (uint8_t) (address >> 40);
292 mac_reverse[4] = (uint8_t) (address >> 32);
293 mac_reverse[3] = (uint8_t) (address >> 24);
294 mac_reverse[2] = (uint8_t) (address >> 16);
295 mac_reverse[1] = (uint8_t) (address >> 8);
296 mac_reverse[0] = (uint8_t) (address >> 0);
297
298 XiaomiAESVector vector{.key = {0},
299 .plaintext = {0},
300 .ciphertext = {0},
301 .authdata = {0x11},
302 .iv = {0},
303 .tag = {0},
304 .keysize = 16,
305 .authsize = 1,
306 .datasize = 0,
307 .tagsize = 4,
308 .ivsize = 12};
309
310 vector.datasize = (raw.size() == 19) ? raw.size() - 12 : raw.size() - 18;
311 int cipher_pos = (raw.size() == 19) ? 5 : 11;
312
313 const uint8_t *v = raw.data();
314
315 memcpy(vector.key, bindkey, vector.keysize);
316 memcpy(vector.ciphertext, v + cipher_pos, vector.datasize);
317 memcpy(vector.tag, v + raw.size() - vector.tagsize, vector.tagsize);
318 memcpy(vector.iv, mac_reverse, 6); // MAC address reverse
319 memcpy(vector.iv + 6, v + 2, 3); // sensor type (2) + packet id (1)
320 memcpy(vector.iv + 9, v + raw.size() - 7, 3); // payload counter
321
322#if ESP_IDF_VERSION >= ESP_IDF_VERSION_VAL(6, 0, 0)
323 // PSA AEAD expects ciphertext + tag concatenated
324 uint8_t ct_with_tag[sizeof(vector.ciphertext) + sizeof(vector.tag)];
325 memcpy(ct_with_tag, vector.ciphertext, vector.datasize);
326 memcpy(ct_with_tag + vector.datasize, vector.tag, vector.tagsize);
327 size_t ct_with_tag_size = vector.datasize + vector.tagsize;
328
329 psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
330 psa_set_key_type(&attributes, PSA_KEY_TYPE_AES);
331 psa_set_key_bits(&attributes, vector.keysize * 8);
332 psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_DECRYPT);
333 psa_set_key_algorithm(&attributes, PSA_ALG_AEAD_WITH_SHORTENED_TAG(PSA_ALG_CCM, vector.tagsize));
334
335 mbedtls_svc_key_id_t key_id;
336 if (psa_import_key(&attributes, vector.key, vector.keysize, &key_id) != PSA_SUCCESS) {
337 ESP_LOGVV(TAG, "decrypt_xiaomi_payload(): psa_import_key() failed.");
338 return false;
339 }
340
341 size_t plaintext_length;
342 psa_status_t status = psa_aead_decrypt(key_id, PSA_ALG_AEAD_WITH_SHORTENED_TAG(PSA_ALG_CCM, vector.tagsize),
343 vector.iv, vector.ivsize, vector.authdata, vector.authsize, ct_with_tag,
344 ct_with_tag_size, vector.plaintext, vector.datasize, &plaintext_length);
345 psa_destroy_key(key_id);
346 bool decrypt_ok = (status == PSA_SUCCESS && plaintext_length == vector.datasize);
347#else
348 mbedtls_ccm_context ctx;
349 mbedtls_ccm_init(&ctx);
350
351 int ret = mbedtls_ccm_setkey(&ctx, MBEDTLS_CIPHER_ID_AES, vector.key, vector.keysize * 8);
352 if (ret) {
353 ESP_LOGVV(TAG, "decrypt_xiaomi_payload(): mbedtls_ccm_setkey() failed.");
354 mbedtls_ccm_free(&ctx);
355 return false;
356 }
357
358 ret = mbedtls_ccm_auth_decrypt(&ctx, vector.datasize, vector.iv, vector.ivsize, vector.authdata, vector.authsize,
359 vector.ciphertext, vector.plaintext, vector.tag, vector.tagsize);
360 mbedtls_ccm_free(&ctx);
361 bool decrypt_ok = (ret == 0);
362#endif
363
364 if (!decrypt_ok) {
365 uint8_t mac_address[6] = {0};
366 memcpy(mac_address, mac_reverse + 5, 1);
367 memcpy(mac_address + 1, mac_reverse + 4, 1);
368 memcpy(mac_address + 2, mac_reverse + 3, 1);
369 memcpy(mac_address + 3, mac_reverse + 2, 1);
370 memcpy(mac_address + 4, mac_reverse + 1, 1);
371 memcpy(mac_address + 5, mac_reverse, 1);
372 ESP_LOGVV(TAG, "decrypt_xiaomi_payload(): authenticated decryption failed.");
373#if ESPHOME_LOG_LEVEL >= ESPHOME_LOG_LEVEL_VERY_VERBOSE
374 char mac_buf[MAC_ADDRESS_PRETTY_BUFFER_SIZE];
375 format_mac_addr_upper(mac_address, mac_buf);
376 char hex_buf[format_hex_pretty_size(XIAOMI_MAX_LOG_BYTES)];
377#endif
378 ESP_LOGVV(TAG, " MAC address : %s", mac_buf);
379 ESP_LOGVV(TAG, " Packet : %s", format_hex_pretty_to(hex_buf, raw.data(), raw.size()));
380 ESP_LOGVV(TAG, " Key : %s", format_hex_pretty_to(hex_buf, vector.key, vector.keysize));
381 ESP_LOGVV(TAG, " Iv : %s", format_hex_pretty_to(hex_buf, vector.iv, vector.ivsize));
382 ESP_LOGVV(TAG, " Cipher : %s", format_hex_pretty_to(hex_buf, vector.ciphertext, vector.datasize));
383 ESP_LOGVV(TAG, " Tag : %s", format_hex_pretty_to(hex_buf, vector.tag, vector.tagsize));
384 return false;
385 }
386
387 // replace encrypted payload with plaintext
388 uint8_t *p = vector.plaintext;
389 for (std::vector<uint8_t>::iterator it = raw.begin() + cipher_pos; it != raw.begin() + cipher_pos + vector.datasize;
390 ++it) {
391 *it = *(p++);
392 }
393
394 // clear encrypted flag
395 raw[0] &= ~0x08;
396
397 ESP_LOGVV(TAG, "decrypt_xiaomi_payload(): authenticated decryption passed.");
398#if ESPHOME_LOG_LEVEL >= ESPHOME_LOG_LEVEL_VERY_VERBOSE
399 char hex_buf[format_hex_pretty_size(XIAOMI_MAX_LOG_BYTES)];
400#endif
401 ESP_LOGVV(TAG, " Plaintext : %s, Packet : %d",
402 format_hex_pretty_to(hex_buf, raw.data() + cipher_pos, vector.datasize), static_cast<int>(raw[4]));
403
404 return true;
405}
406
407bool report_xiaomi_results(const optional<XiaomiParseResult> &result, const char *address) {
408 if (!result.has_value()) {
409 ESP_LOGVV(TAG, "report_xiaomi_results(): no results available.");
410 return false;
411 }
412
413 ESP_LOGD(TAG, "Got Xiaomi %s (%s):", result->name.c_str(), address);
414
415 if (result->temperature.has_value()) {
416 ESP_LOGD(TAG, " Temperature: %.1f°C", *result->temperature);
417 }
418 if (result->humidity.has_value()) {
419 ESP_LOGD(TAG, " Humidity: %.1f%%", *result->humidity);
420 }
421 if (result->battery_level.has_value()) {
422 ESP_LOGD(TAG, " Battery Level: %.0f%%", *result->battery_level);
423 }
424 if (result->conductivity.has_value()) {
425 ESP_LOGD(TAG, " Conductivity: %.0fµS/cm", *result->conductivity);
426 }
427 if (result->illuminance.has_value()) {
428 ESP_LOGD(TAG, " Illuminance: %.0flx", *result->illuminance);
429 }
430 if (result->moisture.has_value()) {
431 ESP_LOGD(TAG, " Moisture: %.0f%%", *result->moisture);
432 }
433 if (result->tablet.has_value()) {
434 ESP_LOGD(TAG, " Mosquito tablet: %.0f%%", *result->tablet);
435 }
436 if (result->is_active.has_value()) {
437 ESP_LOGD(TAG, " Repellent: %s", (*result->is_active) ? "on" : "off");
438 }
439 if (result->has_motion.has_value()) {
440 ESP_LOGD(TAG, " Motion: %s", (*result->has_motion) ? "yes" : "no");
441 }
442 if (result->is_light.has_value()) {
443 ESP_LOGD(TAG, " Light: %s", (*result->is_light) ? "on" : "off");
444 }
445 if (result->button_press.has_value()) {
446 ESP_LOGD(TAG, " Button: %s", (*result->button_press) ? "pressed" : "");
447 }
448
449 return true;
450}
451
453 // Previously the message was parsed twice per packet, once by XiaomiListener::parse_device()
454 // and then again by the respective device class's parse_device() function. Parsing the header
455 // here and then for each device seems to be unnecessary and complicates the duplicate packet filtering.
456 // Hence I disabled the call to parse_xiaomi_header() here and the message parsing is done entirely
457 // in the respective device instance. The XiaomiListener class is defined in __init__.py and I was not
458 // able to remove it entirely.
459
460 return false; // with true it's not showing device scans
461}
462
463} // namespace xiaomi_ble
464} // namespace esphome
465
466#endif
uint8_t address
Definition bl0906.h:4
uint8_t raw[35]
Definition bl0939.h:0
uint8_t status
Definition bl0942.h:8
bool contains(uint8_t data1, uint8_t data2) const
Definition ble_uuid.cpp:112
bool parse_device(const esp32_ble_tracker::ESPBTDevice &device) override
const char * message
Definition component.cpp:35
bool decrypt_xiaomi_payload(std::vector< uint8_t > &raw, const uint8_t *bindkey, const uint64_t &address)
optional< XiaomiParseResult > parse_xiaomi_header(const esp32_ble_tracker::ServiceData &service_data)
bool parse_xiaomi_value(uint16_t value_type, const uint8_t *data, uint8_t value_length, XiaomiParseResult &result)
bool parse_xiaomi_message(const std::vector< uint8_t > &message, XiaomiParseResult &result)
bool report_xiaomi_results(const optional< XiaomiParseResult > &result, const char *address)
Providing packet encoding functions for exchanging data with a remote host.
Definition a01nyub.cpp:7
constexpr uint32_t encode_uint24(uint8_t byte1, uint8_t byte2, uint8_t byte3)
Encode a 24-bit value given three bytes in most to least significant byte order.
Definition helpers.h:885
char * format_hex_pretty_to(char *buffer, size_t buffer_size, const uint8_t *data, size_t length, char separator)
Format byte array as uppercase hex to buffer (base implementation).
Definition helpers.cpp:409
constexpr size_t format_hex_pretty_size(size_t byte_count)
Calculate buffer size needed for format_hex_pretty_to with separator: "XX:XX:...:XX\0".
Definition helpers.h:1368
constexpr uint32_t encode_uint32(uint8_t byte1, uint8_t byte2, uint8_t byte3, uint8_t byte4)
Encode a 32-bit value given four bytes in most to least significant byte order.
Definition helpers.h:889
constexpr uint16_t encode_uint16(uint8_t msb, uint8_t lsb)
Encode a 16-bit value given the most and least significant byte.
Definition helpers.h:881
char * format_mac_addr_upper(const uint8_t *mac, char *output)
Format MAC address as XX:XX:XX:XX:XX:XX (uppercase, colon separators)
Definition helpers.h:1435
static void uint32_t
enum esphome::xiaomi_ble::XiaomiParseResult::@197 type
uint16_t temperature
Definition sun_gtil2.cpp:12