How to get Tandberg AutoRoll working with Oscam and Dreambox

bigs15

Senior Member
Messages
435
AU keys:
T <key index (hex)> MK <key>

64 keys are needed:

T 40 MK 1122334455667788
T 41 MK 1122334455667788
...
T 7F MK 1122334455667788

How to get Tandberg AutoRoll ?
 

kebien

Well Known Member
Messages
1,329
This the deal
The 64 keys are in the stream,come in the EMM pid.
You would have to log emm and extract this keys,which are not encrypted,and place it in the softcam file.

There is a catch : next key roll ,this key might be different,and you would have to load 64 new keys.

I do not think autoroll will work until oscam can grab this keys on its own,write it to a temporary file (would bee too much memory needed),and use this key to get new ECM key.
 

Ragnarok

Donating Member
Messages
336
@Kebien There is no reason OscamEMU should not work the keys do not take up as much space as a copying a large softcam.key to ram which OscamEMU does. unless it's implemented badly.

They way i understand it. The 64 keys are Rom keys, they stay the same as they are in the firmware ( though it is possible they could change later in a software update ) , These decrypt keys in the 82 emm able which are held in ram and change regularly of which there are upto 64 again, the keys from the 82 table are used to decrypt the actual ECM keys in table 83 emm. The RAM keys should stay upto date in the EMM stream and take up way less space than a big softcam.key in ram.

by the look of it the author of OSCAMEMU patch may have got it working. The latest POC.exe caches the table 83 emms containing the ecm keys later decrypts them if/when the correct ram keys become available. You might need to have have to be a bit more patience if oscamemu is not caching the table 83 emms to decrypt later ( like POC.exe v1.6 ) and clear the ram keys if they get stored in the softcam.key 00-3f, as you would not want to be decrypting ecm keys with the wrong ram keys in the future on a feed or channel from another provider, that will give you false ECM keys.

I haven't had chance to test it yet.
 
Last edited:

kebien

Well Known Member
Messages
1,329
@Kebien There is no reason OscamEMU should not work the keys do not take up as much space as a copying a large softcam.key to ram which OscamEMU does. unless it's implemented badly.

They way i understand it. The 64 keys are Rom keys, they stay the same as they are in the firmware ( though it is possible they could change later in a software update ) , These decrypt keys in the 82 emm able which are held in ram and change regularly of which there are upto 64 again, the keys from the 82 table are used to decrypt the actual ECM keys in table 83 emm. The RAM keys should stay upto date in the EMM stream and take up way less space than a big softcam.key in ram.

by the look of it the author of OSCAMEMU patch may have got it working. The latest POC.exe caches the table 83 emms containing the ecm keys later decrypts them if/when the correct ram keys become available. You might need to have have to be a bit more patience if oscamemu is not caching the table 83 emms to decrypt later ( like POC.exe v1.6 ) and clear the ram keys if they get stored in the softcam.key 00-3f, as you would not want to be decrypting ecm keys with the wrong ram keys in the future on a feed or channel from another provider, that will give you false ECM keys.

I haven't had chance to test it yet.
Ok,I thought the 64 keys were the stream keys,not the rom keys.(would they be better embedded in oscam binary?)
The idea about ram holding keys is good,all depend on how much space is available.
I welcome the idea of autoroll since you would not need more than 10 seconds tuning a feed and get the ECM keys and get video going.
 

Ragnarok

Donating Member
Messages
336
Ok,I thought the 64 keys were the stream keys,not the rom keys.(would they be better embedded in oscam binary?)
The idea about ram holding keys is good,all depend on how much space is available.
I welcome the idea of autoroll since you would not need more than 10 seconds tuning a feed and get the ECM keys and get video going.

There are 64 rom keys and their is enough key space for 64 ram key indexes too.

I've extracted the keys and tested it, I never spotted it working the first time. however from an oscam restart and all Tandberg keys removed from the softcam.key. It works pretty good I'd say 10- 20 seconds and the picture is on screen it's got the new ECM key(s) in real time.

The down side is a weak signal plays havoc. I left my receiver recording the Premier League Netbusters and the signal wasn't great while I went out and comeback to find when the signal got weak it started writing corrupt keys to the softcam .key, maybe some corrupt ram keys too. somthing went wrong, it's hard to tell if Oscamemu actually has implemented any error checking or it was just a 1 off. No body has talked must about error checking yet in the challenge thread.

Would be interesting to post but their are actual working keys in their too.

Then there is the other discussion, I can post these keys however, where would they belong? Is it a good bad idea to post these keys? It's always bad to post AU keys! We already Have POC.exe why not just post them anyway!!!!....................... on and on until someone closes a thread.

For now I'm not posting them, no one else has who has played a far bigger part in this has yet and I don't want to upset the apple cart. I don't know what the consensus is yet.

All the info is there, it's dead easy to find them with the info posted in http://www.sat-universe.com/showthread.php?t=295303, it's all there and anyone with a sharp mind should be able to figure out another way to get them without hunting through the firmware of a tandberg box, I did it both ways anyway and used the 3 rom keys posted in the thread to confirm, but the info 007.4 posted in that thread makes it a breeze. 007.4 really played a damned good part in making this all possible.

on a side note, and more interesting to me is how Colibri.DVB's explanations are great to help understand whats really going on under the hood without giving too much away.
 
Last edited:

abra26

Senior Member
Messages
263
I've extracted the keys and tested it, I never spotted it working the first time. however from an oscam restart and all Tandberg keys removed from the softcam.key. It works pretty good I'd say 10- 20 seconds and the picture is on screen it's got the new ECM key(s) in real time.

The down side is a weak signal plays havoc. I left my receiver recording the Premier League Netbusters and the signal wasn't great while I went out and comeback to find when the signal got weak it started writing corrupt keys to the softcam .key, maybe some corrupt ram keys too. somthing went wrong, it's hard to tell if Oscamemu actually has implemented any error checking or it was just a 1 off. No body has talked must about error checking yet in the challenge thread.

Would be interesting to post but their are actual working keys in their too.

Then there is the other discussion, I can post these keys however, where would they belong? Is it a good bad idea to post these keys? It's always bad to post AU keys! We already Have POC.exe why not just post them anyway!!!!....................... on and on until someone closes a thread.

For now I'm not posting them, no one else has who has played a far bigger part in this has yet and I don't want to upset the apple cart. I don't know what the consensus is yet.

All the info is there, it's dead easy to find them with the info posted in http://www.sat-universe.com/showthread.php?t=295303, it's all there and anyone with a sharp mind should be able to figure out another way to get them without hunting through the firmware of a tandberg box, I did it both ways anyway and used the 3 rom keys posted in the thread to confirm, but the info 007.4 posted in that thread makes it a breeze. 007.4 really played a damned good part in making this all possible.

on a side note, and more interesting to me is how Colibri.DVB's explanations are great to help understand whats really going on under the hood without giving too much away.

I agree !!! :thum: And I think it's NOT good idea to post that keys. It's just in firmware and as you said, everyone with a sharp mind can extract it! ;)
 

nautilus7

VIP
Messages
607
Hi, tested today with English Premier League feeds.

With feed at 11020 @ 7.0E everything was ok. I was able to decrypt the feed by just the AU keys.

With feeds at 11638 @ 10.0E I had no luck. It seems there are only "82" packets there, while at the other feeds there are "83" packets aswell.
 

Peerate

Senior Member
Messages
117
Yes it works but I had to setup my OScam little bit more to make it working

In Users-->[User Name] I had to change AU filed from blank to "emulator" , also works with value '1' but it sends emms to your (or your friend's) card server and in some cases may cause problems there, so I just put "emulator"

rxoYRfY.jpg


and then on Oscam status page, column AU changed to ACTIVE

fQuxtQR.jpg


and after minute or two keys have been added to softcam.keys

Also I may confirm that it doesn't work on Arena Sport on 39 and on mini mux FOX/Nat Geo HD on 42 east.
 

Ragnarok

Donating Member
Messages
336
It won't, the 83 table emm's aren't being broadcast. If you arent sure set up your oscam to log global emm's then look for emms starting 83. all Tandberg emms are global type.
 
Last edited:

Ragnarok

Donating Member
Messages
336
If they do change ecm key, they'll probably have to push out the emm's and make sure everyone has them first. it looks like there are no plans currently to change ECM key.
 
Top