Hi,
a new Sensor appeared which might be similar to the already implemented GT-WT-02?
I'm not a programmer and hope someone can help including support for this Device.
I needed to set -f to 434101100 to get some output with the -a and -A flags. No clue if this matters somehow.... Other sensors seem to work just fine when running bare "rtl_433"
Sample data is provided below. Please let me know If I can be of any help.
Many thanks & Greetings
Marcus
Temperature / Humidity Display
Manual TX Push Button
Unit Push Button °C/F
Channel slide switch 1-3
Battery Indicator on LCD
Output for:
Sensor 1
Temperature: 26,4 °C
Humidity: 53%
Channel: 1
Bat: Good
Manual Button pressed: yes
`Detected OOK package 2019-09-12 18:37:01
Analyzing pulses...
Total count: 1035, width: 962.21 ms (240552 S)
Pulse width distribution:
[ 0] count: 92, width: 828 us [704;856] ( 207 S)
[ 1] count: 322, width: 588 us [576;612] ( 147 S)
[ 2] count: 621, width: 220 us [204;248] ( 55 S)
Gap width distribution:
[ 0] count: 92, width: 872 us [856;892] ( 218 S)
[ 1] count: 322, width: 264 us [244;280] ( 66 S)
[ 2] count: 620, width: 628 us [608;648] ( 157 S)
Pulse period distribution:
[ 0] count: 92, width: 1704 us [1580;1720] ( 426 S)
[ 1] count: 942, width: 852 us [840;868] ( 213 S)
Level estimates [high, low]: 1000, 7
RSSI: -12.1 dB SNR: 21.0 dB Noise: -33.1 dB
Frequency offsets [F1, F2]: 754, 0 (+2.9 kHz, +0.0 kHz)
Guessing modulation: Pulse Width Modulation with sync/delimiter
Attempting demodulation... short_width: 220, long_width: 588, reset_limit: 896, sync_width: 828
Use a flex decoder with -X 'n=name,m=OOK_PWM,s=220,l=588,r=896,g=0,t=0,y=828'
pulse_demod_pwm(): Analyzer Device
bitbuffer:: Number of rows: 24
[00] {41} 17 ca be f7 7a 80 : 00010111 11001010 10111110 11110111 01111010 1
[01] {41} 17 ca be f7 7a 80 : 00010111 11001010 10111110 11110111 01111010 1
[02] {41} 17 ca be f7 7a 80 : 00010111 11001010 10111110 11110111 01111010 1
[03] {41} 17 ca be f7 7a 80 : 00010111 11001010 10111110 11110111 01111010 1
[04] {41} 17 ca be f7 7a 80 : 00010111 11001010 10111110 11110111 01111010 1
[05] {41} 17 ca be f7 7a 80 : 00010111 11001010 10111110 11110111 01111010 1
[06] {41} 17 ca be f7 7a 80 : 00010111 11001010 10111110 11110111 01111010 1
[07] {41} 17 ca be f7 7a 80 : 00010111 11001010 10111110 11110111 01111010 1
[08] {41} 17 ca be f7 7a 80 : 00010111 11001010 10111110 11110111 01111010 1
[09] {41} 17 ca be f7 7a 80 : 00010111 11001010 10111110 11110111 01111010 1
[10] {41} 17 ca be f7 7a 80 : 00010111 11001010 10111110 11110111 01111010 1
[11] {41} 17 ca be f7 7a 80 : 00010111 11001010 10111110 11110111 01111010 1
[12] {41} 17 ca be f7 7a 80 : 00010111 11001010 10111110 11110111 01111010 1
[13] {41} 17 ca be f7 7a 80 : 00010111 11001010 10111110 11110111 01111010 1
[14] {41} 17 ca be f7 7a 80 : 00010111 11001010 10111110 11110111 01111010 1
[15] {41} 17 ca be f7 7a 80 : 00010111 11001010 10111110 11110111 01111010 1
[16] {41} 17 ca be f7 7a 80 : 00010111 11001010 10111110 11110111 01111010 1
[17] {41} 17 ca be f7 7a 80 : 00010111 11001010 10111110 11110111 01111010 1
[18] {41} 17 ca be f7 7a 80 : 00010111 11001010 10111110 11110111 01111010 1
[19] {41} 17 ca be f7 7a 80 : 00010111 11001010 10111110 11110111 01111010 1
[20] {41} 17 ca be f7 7a 80 : 00010111 11001010 10111110 11110111 01111010 1
[21] {41} 17 ca be f7 7a 80 : 00010111 11001010 10111110 11110111 01111010 1
[22] {41} 17 ca be f7 7a 80 : 00010111 11001010 10111110 11110111 01111010 1
[23] {41} 17 ca be f7 7a 80 : 00010111 11001010 10111110 11110111 01111010 1
Output for:
Sensor 1
Temperature: 26,1 °C
Humidity: 48%
Channel: 1
Bat: Good
Manual Button pressed: yes
`[00] {41} 17 cf be fa 6a 80 : 00010111 11001111 10111110 11111010 01101010 1
Output for:
Sensor 1
Batteries changed !
Temperature: 26,1 °C
Humidity: 48%
Channel: 1
Bat: Good
Manual Button pressed: yes
[00] {41} 17 cf be fa 6a 80 : 00010111 11001111 10111110 11111010 01101010 1
Output for:
Sensor 1
Batteries changed !
Temperature: 26,1 °C
Humidity: 48%
Channel: 1
Bat: Good
Manual Button pressed: No
[00] {41} 17 cf fe fa ea 80 : 00010111 11001111 11111110 11111010 11101010 1
Output for:
Sensor 2
Temperature: 23,8 °C
Humidity: 48%
Channel: 2
Bat LOW
Manual Button pressed: No
[00] {41} 01 cf 6f 11 b2 80 : 00000001 11001111 01101111 00010001 10110010 1
Output for:
Sensor 2
Batteries changed!
Temperature: -4,4 °C
Humidity: 55%
Channel: 3
Bat Good
Manual Button pressed: No
[00] {41} 01 c8 d0 2b 76 80 : 00000001 11001000 11010000 00101011 01110110 1
Hi, can you supply some signal samples?
Hi Merbanan,
sure thing! Please let me know what type of sample you need.
Thanks.
https://github.com/merbanan/rtl_433#supporting-additional-devices-and-test-data
Follow the instructions in the previous post.
Thank you merbanan,
I tried my best to provide as much data as possible. I joined github only for this request and I dont really have a clue how things work here... However I think I was able to add my description and files in https://github.com/merbanan/rtl_433_tests/pull/302
Regards
@sPrinGfieldd I figured out the fields, see this BitBench. I'll add a decoder soon.
I've added the decoder, but the checksum is unknown. If possible grab many unique codes and post here.
E.g add
bitrow_printf(b, 40, "%s: ", __func__);
here after
b = bitbuffer->bb[row];
Thank you zuckschwerdt, really appreciate your work! :1st_place_medal:
I owe you some Beers or Coffes or something... If there is a way to make a donation let me know...
The decoding works and the values seem to be perfectly correct. I changed the src and set up some monitoring. Once I have 50 or so unique samples I will let you know. here
Here you go.
gt_wt_03_decode: {40} 01 cb ef 41 9a : 00000001 11001011 11101111 01000001 10011010
gt_wt_03_decode: {40} 01 cb ef 43 5e : 00000001 11001011 11101111 01000011 01011110
gt_wt_03_decode: {40} 01 cc ef 3d cc : 00000001 11001100 11101111 00111101 11001100
gt_wt_03_decode: {40} 01 cc ef 3f 08 : 00000001 11001100 11101111 00111111 00001000
gt_wt_03_decode: {40} 01 cc ef 40 d6 : 00000001 11001100 11101111 01000000 11010110
gt_wt_03_decode: {40} 01 cd ef 3b e2 : 00000001 11001101 11101111 00111011 11100010
gt_wt_03_decode: {40} 01 cd ef 3c cc : 00000001 11001101 11101111 00111100 11001100
gt_wt_03_decode: {40} 01 ce ef 36 be : 00000001 11001110 11101111 00110110 10111110
gt_wt_03_decode: {40} 01 ce ef 39 80 : 00000001 11001110 11101111 00111001 10000000
gt_wt_03_decode: {40} 01 cf ef 32 54 : 00000001 11001111 11101111 00110010 01010100
gt_wt_03_decode: {40} 01 cf ef 34 18 : 00000001 11001111 11101111 00110100 00011000
gt_wt_03_decode: {40} 01 d0 ef 14 46 : 00000001 11010000 11101111 00010100 01000110
gt_wt_03_decode: {40} 01 d0 ef 1b 78 : 00000001 11010000 11101111 00011011 01111000
gt_wt_03_decode: {40} 01 d0 ef 1c 56 : 00000001 11010000 11101111 00011100 01010110
gt_wt_03_decode: {40} 01 d0 ef 2f 90 : 00000001 11010000 11101111 00101111 10010000
gt_wt_03_decode: {40} 01 d1 ef 12 68 : 00000001 11010001 11101111 00010010 01101000
gt_wt_03_decode: {40} 01 d1 ef 13 0a : 00000001 11010001 11101111 00010011 00001010
gt_wt_03_decode: {40} 01 d1 ef 1b 1a : 00000001 11010001 11101111 00011011 00011010
gt_wt_03_decode: {40} 01 d1 ef 2b 7a : 00000001 11010001 11101111 00101011 01111010
gt_wt_03_decode: {40} 01 d2 ef 11 68 : 00000001 11010010 11101111 00010001 01101000
gt_wt_03_decode: {40} 01 d2 ef 13 ac : 00000001 11010010 11101111 00010011 10101100
gt_wt_03_decode: {40} 01 d2 ef 17 24 : 00000001 11010010 11101111 00010111 00100100
gt_wt_03_decode: {40} 01 d2 ef 1c 92 : 00000001 11010010 11101111 00011100 10010010
gt_wt_03_decode: {40} 01 d2 ef 1d f0 : 00000001 11010010 11101111 00011101 11110000
gt_wt_03_decode: {40} 01 d2 ef 25 80 : 00000001 11010010 11101111 00100101 10000000
gt_wt_03_decode: {40} 01 d3 ef 1d 92 : 00000001 11010011 11101111 00011101 10010010
gt_wt_03_decode: {40} 0f c8 df b1 e0 : 00001111 11001000 11011111 10110001 11100000
gt_wt_03_decode: {40} 0f ca df 41 c4 : 00001111 11001010 11011111 01000001 11000100
gt_wt_03_decode: {40} 0f cb df 23 a2 : 00001111 11001011 11011111 00100011 10100010
gt_wt_03_decode: {40} 0f cb df 24 8c : 00001111 11001011 11011111 00100100 10001100
gt_wt_03_decode: {40} 0f cb df 3f 1a : 00001111 11001011 11011111 00111111 00011010
gt_wt_03_decode: {40} 0f cb df 40 c4 : 00001111 11001011 11011111 01000000 11000100
gt_wt_03_decode: {40} 0f cc df 1f 74 : 00001111 11001100 11011111 00011111 01110100
gt_wt_03_decode: {40} 0f cc df 20 2a : 00001111 11001100 11011111 00100000 00101010
gt_wt_03_decode: {40} 0f cc df 21 48 : 00001111 11001100 11011111 00100001 01001000
gt_wt_03_decode: {40} 0f cc df 22 ee : 00001111 11001100 11011111 00100010 11101110
gt_wt_03_decode: {40} 0f cc df 3c 92 : 00001111 11001100 11011111 00111100 10010010
gt_wt_03_decode: {40} 0f cc df 3d f0 : 00001111 11001100 11011111 00111101 11110000
gt_wt_03_decode: {40} 0f cd df 1b 9e : 00001111 11001101 11011111 00011011 10011110
gt_wt_03_decode: {40} 0f cd df 1d d2 : 00001111 11001101 11011111 00011101 11010010
gt_wt_03_decode: {40} 0f cd df 1e 74 : 00001111 11001101 11011111 00011110 01110100
gt_wt_03_decode: {40} 0f cd df 39 1a : 00001111 11001101 11011111 00111001 00011010
gt_wt_03_decode: {40} 0f ce df 0f 90 : 00001111 11001110 11011111 00001111 10010000
gt_wt_03_decode: {40} 0f ce df 12 4a : 00001111 11001110 11011111 00010010 01001010
gt_wt_03_decode: {40} 0f ce df 34 46 : 00001111 11001110 11011111 00110100 01000110
gt_wt_03_decode: {40} 0f ce df 38 de : 00001111 11001110 11011111 00111000 11011110
gt_wt_03_decode: {40} 0f ce df ca fa : 00001111 11001110 11011111 11001010 11111010
gt_wt_03_decode: {40} 0f cf df 0d 36 : 00001111 11001111 11011111 00001101 00110110
gt_wt_03_decode: {40} 0f cf df 32 68 : 00001111 11001111 11011111 00110010 01101000
gt_wt_03_decode: {40} 0f d0 df 09 a0 : 00001111 11010000 11011111 00001001 10100000
gt_wt_03_decode: {40} 0f d0 df 0a 06 : 00001111 11010000 11011111 00001010 00000110
gt_wt_03_decode: {40} 0f d0 df 2e ce : 00001111 11010000 11011111 00101110 11001110
gt_wt_03_decode: {40} 0f d1 df 06 fc : 00001111 11010001 11011111 00000110 11111100
gt_wt_03_decode: {40} 0f d1 df 22 34 : 00001111 11010001 11011111 00100010 00110100
gt_wt_03_decode: {40} 0f d1 df 29 82 : 00001111 11010001 11011111 00101001 10000010
gt_wt_03_decode: {40} 0f d2 df 0f 28 : 00001111 11010010 11011111 00001111 00101000
gt_wt_03_decode: {40} 0f d2 df 1a e2 : 00001111 11010010 11011111 00011010 11100010
gt_wt_03_decode: {40} 0f d6 df f5 94 : 00001111 11010110 11011111 11110101 10010100
gt_wt_03_decode: {40} 0f d8 df f6 6e : 00001111 11011000 11011111 11110110 01101110
gt_wt_03_decode: {40} 0f d8 df f8 32 : 00001111 11011000 11011111 11111000 00110010
gt_wt_03_decode: {40} 17 c7 ff 3f f2 : 00010111 11000111 11111111 00111111 11110010
gt_wt_03_decode: {40} 17 c8 ff 3e ae : 00010111 11001000 11111111 00111110 10101110
gt_wt_03_decode: {40} 17 c9 ff 39 e2 : 00010111 11001001 11111111 00111001 11100010
gt_wt_03_decode: {40} 17 c9 ff 3b 26 : 00010111 11001001 11111111 00111011 00100110
gt_wt_03_decode: {40} 17 c9 ff 3c 08 : 00010111 11001001 11111111 00111100 00001000
gt_wt_03_decode: {40} 17 ca ff 36 7a : 00010111 11001010 11111111 00110110 01111010
gt_wt_03_decode: {40} 17 ca ff 39 44 : 00010111 11001010 11111111 00111001 01000100
gt_wt_03_decode: {40} 17 cb ff 33 f2 : 00010111 11001011 11111111 00110011 11110010
gt_wt_03_decode: {40} 17 cb ff 36 18 : 00010111 11001011 11111111 00110110 00011000
gt_wt_03_decode: {40} 17 cc ff 11 58 : 00010111 11001100 11111111 00010001 01011000
gt_wt_03_decode: {40} 17 cc ff 19 48 : 00010111 11001100 11111111 00011001 01001000
gt_wt_03_decode: {40} 17 cc ff 30 7a : 00010111 11001100 11111111 00110000 01111010
gt_wt_03_decode: {40} 17 cc ff 33 dc : 00010111 11001100 11111111 00110011 11011100
gt_wt_03_decode: {40} 17 cd ff 0e 24 : 00010111 11001101 11111111 00001110 00100100
gt_wt_03_decode: {40} 17 cd ff 16 14 : 00010111 11001101 11111111 00010110 00010100
gt_wt_03_decode: {40} 17 cd ff 17 76 : 00010111 11001101 11111111 00010111 01110110
gt_wt_03_decode: {40} 17 cd ff 18 48 : 00010111 11001101 11111111 00011000 01001000
gt_wt_03_decode: {40} 17 cd ff 19 2a : 00010111 11001101 11111111 00011001 00101010
gt_wt_03_decode: {40} 17 cd ff 2e 64 : 00010111 11001101 11111111 00101110 01100100
gt_wt_03_decode: {40} 17 ce ff 0a 0a : 00010111 11001110 11111111 00001010 00001010
gt_wt_03_decode: {40} 17 ce ff 0b 68 : 00010111 11001110 11111111 00001011 01101000
gt_wt_03_decode: {40} 17 ce ff 12 3a : 00010111 11001110 11111111 00010010 00111010
gt_wt_03_decode: {40} 17 ce ff 29 ec : 00010111 11001110 11111111 00101001 11101100
gt_wt_03_decode: {40} 17 cf ff 06 f0 : 00010111 11001111 11111111 00000110 11110000
gt_wt_03_decode: {40} 17 cf ff 08 ac : 00010111 11001111 11111111 00001000 10101100
gt_wt_03_decode: {40} 17 cf ff 15 76 : 00010111 11001111 11111111 00010101 01110110
gt_wt_03_decode: {40} 17 cf ff 16 d0 : 00010111 11001111 11111111 00010110 11010000
gt_wt_03_decode: {40} 17 cf ff 24 74 : 00010111 11001111 11111111 00100100 01110100
gt_wt_03_decode: {40} 17 d0 ff 06 ee : 00010111 11010000 11111111 00000110 11101110
gt_wt_03_decode: {40} 17 d0 ff 07 8c : 00010111 11010000 11111111 00000111 10001100
gt_wt_03_decode: {40} 17 d0 ff 0a 76 : 00010111 11010000 11111111 00001010 01110110
gt_wt_03_decode: {40} 17 d0 ff 13 24 : 00010111 11010000 11111111 00010011 00100100
gt_wt_03_decode: {40} 17 d0 ff 1b 34 : 00010111 11010000 11111111 00011011 00110100
gt_wt_03_decode: {40} 17 d0 ff 1f bc : 00010111 11010000 11111111 00011111 10111100
gt_wt_03_decode: {40} 17 d2 ff 12 82 : 00010111 11010010 11111111 00010010 10000010
gt_wt_03_decode: {40} 2f bd 0d 7a 00 : 00101111 10111101 00001101 01111010 00000000
gt_wt_03_decode: {40} 3e c9 df 40 02 : 00111110 11001001 11011111 01000000 00000010
gt_wt_03_decode: {40} 3e ca df 27 4a : 00111110 11001010 11011111 00100111 01001010
gt_wt_03_decode: {40} 3e ca df 29 16 : 00111110 11001010 11011111 00101001 00010110
gt_wt_03_decode: {40} 3e ca df 2f 5a : 00111110 11001010 11011111 00101111 01011010
gt_wt_03_decode: {40} 3e ca df 3c dc : 00111110 11001010 11011111 00111100 11011100
gt_wt_03_decode: {40} 3e ca df 3e 18 : 00111110 11001010 11011111 00111110 00011000
gt_wt_03_decode: {40} 3e cb df 3a f2 : 00111110 11001011 11011111 00111010 11110010
gt_wt_03_decode: {40} 3e cc df 12 8c : 00111110 11001100 11011111 00010010 10001100
gt_wt_03_decode: {40} 3e cc df 1a 9c : 00111110 11001100 11011111 00011010 10011100
gt_wt_03_decode: {40} 3e cc df 1b fe : 00111110 11001100 11011111 00011011 11111110
gt_wt_03_decode: {40} 3e cc df 1d b2 : 00111110 11001100 11011111 00011101 10110010
gt_wt_03_decode: {40} 3e cc df 39 7a : 00111110 11001100 11011111 00111001 01111010
gt_wt_03_decode: {40} 3e cd df 02 ce : 00111110 11001101 11011111 00000010 11001110
gt_wt_03_decode: {40} 3e cd df 35 80 : 00111110 11001101 11011111 00110101 10000000
gt_wt_03_decode: {40} 3e cd df 38 7a : 00111110 11001101 11011111 00111000 01111010
gt_wt_03_decode: {40} 3e cd df 39 18 : 00111110 11001101 11011111 00111001 00011000
gt_wt_03_decode: {40} 3e ce df 33 6a : 00111110 11001110 11011111 00110011 01101010
gt_wt_03_decode: {40} 3e cf df 2f b0 : 00111110 11001111 11011111 00101111 10110000
gt_wt_03_decode: {40} 3e d0 de ec ea : 00111110 11010000 11011110 11101100 11101010
gt_wt_03_decode: {40} 3e d1 df 2a 26 : 00111110 11010001 11011111 00101010 00100110
gt_wt_03_decode: {40} 3e d2 df 22 90 : 00111110 11010010 11011111 00100010 10010000
gt_wt_03_decode: {40} 3e d3 de dc 2c : 00111110 11010011 11011110 11011100 00101100
gt_wt_03_decode: {40} 3e d4 df 1b ce : 00111110 11010100 11011111 00011011 11001110
gt_wt_03_decode: {40} 3e d6 de cf 40 : 00111110 11010110 11011110 11001111 01000000
gt_wt_03_decode: {40} 3e d6 df 10 bc : 00111110 11010110 11011111 00010000 10111100
gt_wt_03_decode: {40} 3e d9 de c6 0c : 00111110 11011001 11011110 11000110 00001100
gt_wt_03_decode: {40} 3e d9 df 00 a2 : 00111110 11011001 11011111 00000000 10100010
gt_wt_03_decode: {40} 3e db de cd 7e : 00111110 11011011 11011110 11001101 01111110
gt_wt_03_decode: {40} 3e db de ea 10 : 00111110 11011011 11011110 11101010 00010000
gt_wt_03_decode: {40} ce ff 2a 4a 80 : 11001110 11111111 00101010 01001010 10000000
Thank you for the kudos. Spread the word, write a blog entry, help others. Also, you did the heavy lifting analyzing and documenting the sensor :)
Ah, great! how many different sensors do you have? 4?
Yes, 4 is correct. :)
I will most likely buy some more. Since I can attach them to my openHAB installation now.
{40} 0f cc df 20 2a : 00001111 11001100 11011111 00100000 00101010
{40} 0f cc df 21 48 : 00001111 11001100 11011111 00100001 01001000
{40} 0f cc df 22 ee : 00001111 11001100 11011111 00100010 11101110
-> looks like not a checksum
-> looks like 1 bit difference change all 8 last bits, so most likely a 8bit crc
./bruteforce-crc --width 8 --start 0 --end 31 --offs-crc 32 --file bits --verbose 1
Warning: input reflection only works if range start ... end is N * 8 bit with N > 0
Extracted message with crc 002a
Extracted message with crc 0048
Extracted message with crc 00ee
Warning: ignoring line from input file
Extracted 3 messages and CRC values
CRC Width : 8
Truncated Polynomial : 0x0 to 0xff
Initial value : 0x0 to 0xff
final xor : 0x0
Probe reflect in : false
{robe reflect out : false
Number of threads : 4
Number of test vectors : 3
No model found.
01 d2 ef 1c {92}
01 d3 ef 1d {92}
2^3 == c^d = 1
0f cb df 3f {1a}
0f cd df 39 {1a}
b^d == f^9 = 6
3e ca df 3e {18}
3e cd df 39 {18}
a^d == e^9 = 7
So there seems to be a linear xor relation.
Confirmed. For single bits (counted from the right) we get
bit 0 : 0x62
bit 1 : 0xc4
bit 2 : 0x88
bit 3 : 0x10
bit 4 : 0x20
bit 5 : 0x40
bit 16 : 0x62
bit 17 : 0xc4
Not a standard LFSR digest but some other length 16 generator. BitBench.
@sPrinGfieldd if you can grab more unique lines (a few hunderd more) we can reverse the checksum trivialy.
Just a guess but the sequence probably looks like this.
Ok, I will grab more.
Would it be of any help to generate certain conditions/values?
Also I'm having some troubles to redirect this " bitrow_printf(b, 40, "%s: ", __func__);" output to a file. Currently I just copy&paste the scrollback buffer and grep for "gt_wt_03_decode" , filter out obviously wrong values for example "10000000 00000000 00000000 00000000 00000000" , remove duplicates and sort all afterwards.
Do you want to have the output pasted here or would you prefer pastebin / rtl_433_test ?
You can add it to a file and attach it to the PR.
Yes, just drag-and-drop upload the file here. To grab the output you probably need to add
2> logfile.txt
2> logfile.txt works! thx. That makes things a lot easier.
I will let it run for some time and produce some changes.
Completing the sequence gives this:
00000100 11000100
00000010 01100010
00000001 00110001
10000000 10011000
01000000 01001100
00100000 00100110
00010000 00010011
10001000 00001001
11000100 00000100
01100010 00000010
00110001 00000001
10011000 10000000
01001100 01000000
00100110 00100000
00010011 00010000
00001001 10001000
00000100 11000100
00000010 01100010
That looks like a nice pattern. Does that mean the polynomial is some of the following?
00000001 00110001 -> x^8 + x^5 + x4 + 1
00010000 00010011 -> x^12 + x^4 + x + 1
10001000 00001001 -> x^15 + x^11 + x^3 + 1
00110001 00000001 -> x^13 + x^12 + x^8 + 1
Ah, you mean the check could be some 8 bits of a CRC-16? Interesting, I'll have to try that.
Btw. the missing "middle" bits could be 01, 10, or 11 – can't be inferred.
I don't really know what I am doing. I just completed the pattern and rotated it through 16 bit space. My question was if the LSFR taps correspond to one of the 4 layouts.
It's one right shift or rotate per bit, but since we didn't observe a LSB dropping out it's not clear what happens. Could be a 16-bit rotate, could be some generator xor'ed in.
Ok, I now see that for the 16 bit space rotated LSFR 2 bits are unknown. The 10 guess does not match a maximal LFSR polynomial. It seems that max is 5 terms, thus if it rotates 11 could be correct.
00000110 11000100
00000011 01100010
00000001 10110001 x^8 + x^7 + x^5 + x^4 + 1
10000000 11011000
01000000 01101100
00100000 00110110
00010000 00011011 x^12 + x^4 + x^3 + x + 1
10001000 00001101 x^15 + x^11 + x^3 + x^2 + 1
11000100 00000110
01100010 00000011 x^14 + x^13 + x^9 + x + 1
10110001 00000001 x^15 + x^13 + x^12 +x^8 + 1
11011000 10000000
01101100 01000000
00110110 00100000
00011011 00010000
00001101 10001000
00000110 11000100
00000011 01100010
And the polynomial should match one of these entries:
http://users.ece.cmu.edu/~koopman/lfsr/16.dat.gz
An optimal 8-bit LFSR can produce a cycle of 256 keys. But this pattern looks more like a cycle of 16 keys (key 16 == key 0). It might be a simple 16 bit rotate. We really need to see a LSB dropping out, then it's either coming back as MSB or a generator term is applied.
I just grabbed my "lab" equipment, manually emulated the sensors and made additional measurements to get the ranges right while you were doing math magics and the data is recording. The Sensors Humidity Range: 20% 95% (not showing Lo or Hi). While on rtl_433 100% is shown for values > 90%, so this needs to be changed in the src.
Temperature range is -50.0°C (-50.1 shown as Lo) to +70.0°C (+70.1°C is shown as Hi).
The Device ID is fixed and does not change.
Fun fact - It dies on temp sensor resistance < 2R. The Humidity Sensor IO can handle short circuit.
Sensor ID 193 was donated during the process :-)
Oops. Farewell ID193, you were unique – up to 8 bits that is.
Since you are not shy to poke things until the magic smoke escapes: can you get the battery_low flag voltage and the cut out voltage?
Sure. I will provide that later.
Attached is the current output, including the previous ones which seems to contain some invalid IDs or neighbour Sensors. It is still running - so just let me know if more is required.
gt_wt03_Samples_09172019_1.txt
Valid Sensor IDs afaik:
ID:193 example: {40} c1 2e 21 00 f1 : 11000001 00101110 00100001 00000000 11110001
ID:240 example: {40} f0 30 10 46 41 : 11110000 00110000 00010000 01000110 01000001
ID:254 example: {40} fe 4a 20 2c 5d : 11111110 01001010 00100000 00101100 01011101
ID:232 example: {40} e8 3d 00 51 a5 : 11101000 00111101 00000000 01010001 10100101
PCB Pictures:


Single bits broken out there is some strangeness in the MSB. Most lines have many duplicates with identical pattern though.
4 : 000063e85f01 fe -> 000063e85f11 ee | 10 (2 x)
8 : 000009c12811 f5 -> 000009c12911 f4 | 01 (12 x)
9 : 00002fe85d11 ea -> 00002fe85f11 e8 | 02 (7 x)
10 : 000049f04900 94 -> 000049f04d00 90 | 04
10 : 00004de85911 ef -> 00004de85d11 eb | 04
10 : 0000d1e85310 0a -> 0000d1e85710 8e | 84 <-oops
11 : 00008df04700 98 -> 00008df04f00 90 | 08
11 : 0000adfe300f fe -> 0000adfe380f 76 | 88 <-oops
25 : 0000ade85510 92 -> 0000afe85510 23 | b1 <-oops
25 : 0000f1e8149f 52 -> 0000f3e8149f 63 | 31
25 : 0000f5c11a11 99 -> 0000f7c11a11 a8 | 31
26 : 0000bbfe350f a0 -> 0000bffe350f c2 | 62 (2 x)
27 : 000035fe310f f3 -> 00003dfe310f 37 | c4
28 : 000001e85f11 ef -> 000011e85f11 e7 | 08 (19 x)
29 : 00000fe85f11 f8 -> 00002fe85f11 e8 | 10 (6 x)
31 : 00000df04f00 50 -> 00008df04f00 90 | c0 (2 x)
U=<2,65V +- ~5% Battery indicator
U=>2.10V +- 5% plausible readings
U=2,00V +- ~5% Temperature offset -5°C Humidity offset unknown
U=<1,95V +- ~5% does not initialize anymore
U=1,90V +- 5% temperature offset -15°C
U=1,80V +- 5% Display is showing refresh pattern
U=1.75V +- ~5% TX causes cut out
Since the Sensor is not initializing under 1,95V I strongly believe that the Voltage drop of the batteries when TXing ( TX draws about 0.04A @ 3V) causes the Device to fail at something 2V'ish... it does not work anymore when the Voltage rises again afterwards.
That's a far better analysis then most our sensors got! Very interesting.
... never thought about this before too... But this actually indicates that there is a real thing of beauty going on under this blob of plastic. Someone thought about a secure fail state. and made sure the device fails at a certain point - when it becomes unreliable. And even better... it stays there until someone changes the batteries.
Batteries are known to rise their voltage slowly again - even if they are technically dead/empty. This could in the worst case cause a permanent TX or just horribly wrong measurement data.
If I interpret the question marks correctly ... Then it means - more samples are appreciated ?
Yeah, that would be nice.
I think we need a huge amount of messages. Can you run it over night also?
yes, will do.
The last list cooks down to this. It suggests a cycle of only 8 keys with a reset at bit 7 or 8 – which are the missing keys :(
Using a start key of 0x62, rolling left and reset to 0x31 or 0xb1 on key=0, process bits LSB to MSB in each byte gives a pretty much fixed output (after xor'ing chk) – nearly there!
as before - without duplicates, including everything previously recorded.
gt_wt03_Samples_09192019_3.txt
oops, forgot to highlight the "liekly invalid lines" ... everything starting with 00* up to line 125
Nice! The final missing key entry is in there. And it's …drum roll… 0. That's stupid design.
See BitBench.
So for each byte it starts with 0x62 and shifts left (no rollover) after each bit (with bits going LSB to MSB). Which results in a key 0x00 for the last bit because 0x62 doe not have the LSB set.
(Or process the bits the other way around "first-on-air-first-processed", then you need to shift 0x3100 right, taking the low byte as key.)
Btw. the invalid first 125 lines seem to just be inverted.
Side note: 0x31 is a very common CRC-8 poly, that makes this checksum look like a badly botched attempt to implement CRC :)
Dunno... Might that be related to the Device IDs I have available? Or the surrounding conditions / button presses, Temperatures/ Humidities etc.?
However. I think this is done and can be closed! After the quart of my sdr warmed up - everything seems to work just fine. Btw. will rtl_433 output anything to mqtt if the checksum is invalid? Or do I need to catch that condition in my "client" ?
Thx for all the magic! Next time when I get an "unknown" sensor, I know what to do :)
Everything rtl_433 sees with an invalid checksum is very likely bad data or not the assumed protocol after all. It's dropped silently. You will only see valid outputs. If the sensors stop working you can run with -v to look for "Invalid checksum" notes.
@zuckschwerdt the complexity of the algorithm matches the device. Anyway I don't really follow the process how actually figure out all the details. It would be really nice if we could add some kind of documentation regarding that. We have plenty of real cases to use as example.
Agreed. I used a tool to break out all the single bit changes and from the byte-wise repeating pattern inferred the rest. I need to clean up and publish those tools when time allows. I also have tools to brute-force LFSRs, 8 bit and 16-bit with e.g. Fibonacci, Galois and comparable series with bit/byte reflect tests. It's a mess currently ;)
Btw. this can also be seen as lower byte of a (degenerate) reverse (shift left) Galois/Fibonacci LFSR-16, gen 0x00, init 0x62 resetting at every byte. The key list would be: 0062 00c4 0188 0310 0620 0c40 1880 3100.
Or similar a forward (shift right) Galois/Fibonacci LFSR-16, gen 0x00, init 0x3100, going MSB to LSB in the data bits here.
Not sure which algorithm the device designer mangled actually ;)
great finding!. Does this have any effect on the resulting Checksum ?
In my limited mathematical understanding 1+2 = 2+1 .
By the way who is supposed to close this issue ?
It was just a remark on how the designer butchered a checksum so much it isn't even clear what it was anymore. (For your math example you imply a commutative property, that's generally not true for checksums ;)
If everything works well please close.
I consider this implemented. Closing.
Most helpful comment
@sPrinGfieldd I figured out the fields, see this BitBench. I'll add a decoder soon.