How to reverse engineer the data sent from a 433MHz temperature sensor?

Viewed 60

First off, I apologize if my question is too specialized or does not belong here. If you believe there is a better place to ask this question, please suggest.

My main goal is to transmit the measured temperature from my microcontroller to a wireless thermometer that I bought some time ago. The temperature sensor for the thermometer is wireless and uses a certain protocol to transmit the data to the thermometer. In order to do this, I need to understand the protocol that is being used. Once I understand this, I can program the microcontroller to send my own packets. This is mostly just an exercise to practice reverse engineering and embedded programming. Here is a link to the thermometer/sensor combo.

Using my SDR, I was able to monitor the wireless sensor, record a few samples of different temperatures and view them in Audacity. I was able figure out a few things about the protocol by comparing the recorded samples.

  1. The data is transmitted from the sensor every 40-50 seconds, in 33 bit packets. The packet is repeated 4 times per transmission. The data is OOK PWM modulated, with a 0 being a short pulse and a 1 being a long pulse.

Entire Transmission, 4 equal packets.

  1. Each transmission is prefixed with a 'start sequence' and each packet is separated by a 'delimiter sequence'.

Single Packet with Start and Delimiter Sequence.

  1. The packet takes the form of xxxx xxxx xxxx x tttt tttt tttt cccc cccc, where t is the temperature bits, c is probably type of checksum and x is probably some type of id/address, battery indicator or header.

Breakdown of Packet.

  1. The x bits do not change unless I power down the sensor, so I'm not particularly worried about them as I assume that I'll be able to leave them the same in my own transmissions. the 12 t bits hold the temperature in binary, with the temperature in Celsius calculated as follows:

    temp_Celsius = temp/20 - 50
    
    Example from above packet: b011000001110 = 1551
    1551/20 - 50 = 27.5 C -> 81.5 F
    

This works for all of my recorded samples. My main problem is trying to figure out the last 8 c bits. Since the protocol seems relatively simple, I do not think it should be an overly complicated checksum/crc, but I haven't been able to figure it out. I have tried using CRC RevEng but could not find an appropriate model.

So pretty much all I am trying to figure out at this point is how the last 8 c bits are calculated, but I would also be interested to learn what info the first 13 x bits holds. Hopefully one of you sees a pattern that I am missing.

Sample Packets:

    binary:
    ? xxxxxxxxxxxx tttttttttttt cccccccc
    -----------------------------------------
    0 111000000010 011000001111 11000000            //27.5C, 81.5F 
    0 111000000010 011000100111 11111000            //28.7C, 83.6F
    0 111000000010 011000100001 11110010            //28.4C, 83.1F
    0 111000000010 011000000011 11010100            //28.4C, 83.1F
    0 111000000010 010111101101 10111110            //25.8C, 78.4F
    0 111000000010 010110101011 01111111            //22.5C, 72.5F
    0 111000000010 010011101000 10111010            //12.8C, 55.0F
    0 111000000010 010010000100 01010110            // 7.8C, 46.0F
    0 111000000010 001111101111 10111110            // 0.3C, 32.5F

    hex:
    ? xxx ttt cc
    --------------
    0 E02 60F C0            //27.5C, 81.5F
    0 E02 627 F8            //28.7C, 83.6F
    0 E02 621 F2            //28.4C, 83.1F
    0 E02 603 D4            //28.4C, 83.1F
    0 E02 5ED BE            //25.8C, 78.4F
    0 E02 5AB 7F            //22.5C, 72.5F
    0 E02 4E8 BA            //12.8C, 55.0F
    0 E02 484 56            // 7.8C, 46.0F
    0 E02 3EF BE            // 0.3C, 32.5F

Things I have tried:

  • Searching for a CRC model using RevEng
  • Online CRC calculators
  • Searching for my particular sensor or similar ones in RTL433. There are other LaCrosse devices in this program but none seem to have the same protocol as mine.

Any and all criticism/help is appreciated, thanks.

0 Answers
Related