Files
revkit/tools
tkgstratorandClaude Sonnet 4.6 661af0abac feat(crypto): implement build_scheme_data_352() for complete 352B appboot scheme_data
Reverse-engineered the full 352B key 33.6 scheme_data structure from iOS MSL
appboot captures and implemented NetflixCrypto.build_scheme_data_352().

Structure (verified against real captures):
  [0:135]   - Fixed 135B CBOR header (IOS_SCHEME_DATA_HEADER_135B constant)
  [135:263] - 128B TFIT-WB-AES-128-ECB(DH_pub_key) output
  [263:352] - 89B CFB-chain encrypted CBOR tail (IV = TFIT[-16:])

Tail plaintext (82B + 7B PKCS#7 padding):
  key 30: tstr "AUTHENTICATED_DH"
  key 22: uint64 message_id (random per-request)
  key 40: bool false
  key 21: bool true
  key 24: uint64 timestamp (UNIX seconds)

- Add IOS_SCHEME_DATA_HEADER_135B constant to constants.py
- Add NetflixCrypto.build_scheme_data_352() to crypto.py
- Replace old build_key336_scheme_data() / build_key_request_data() in
  test_appboot_e2e.py with the new API (removes incorrect nonce-xor structure)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-09 17:19:32 +00:00
..