用于基于 Nordic Semiconductor nRF24LU1+ 的 USB 适配器和开发板的固件及研究工具。
在 Ubuntu 上安装依赖:
sudo apt-get install sdcc binutils python python-pip
sudo pip install -U pip
sudo pip install -U -I pyusb
sudo pip install -U platformio
以下硬件已经过测试并确认可用。
make
nRF24LU1+ 芯片自带出厂烧录的引导加载程序,占用闪存最顶部的 2KB。CrazyRadio 固件和 RFStorm 研究固件支持通过 USB 命令进入 Nordic 引导加载程序。
如果适配器和开发板运行以下固件之一,则可以通过 USB 进行编程:
通过 USB 烧录固件:
sudo make install
最常见的 Unifying 适配器基于 nRF24LU1+,但有些使用 Texas Instruments 的芯片。 此固件仅支持型号为 C-U0007 的 nRF24LU1+ 版本。烧录 脚本会自动检测插入的适配器类型,并且只会尝试烧录 nRF24LU1+ 版本。
通过 USB 将固件烧录到 Logitech Unifying 适配器:
sudo make logitech_install
下载并解压 Logitech 固件镜像,其文件名将是 RQR_012_005_00028.hex 或类似名称。然后,运行以下命令将 Logitech 固件烧录到适配器:
sudo ./prog/usb-flasher/logitech-usb-restore.py [path-to-firmware.hex]
如果您的适配器或开发板变砖,您也可以使用 Teensy 通过 SPI 进行编程。
此方式仅在 Teensy 3.1/3.2 上测试过,但也很可能适用于其他 Arduino 变体。
platformio run --project-dir teensy-flasher --target upload
| Teensy | CrazyRadio PA | SparkFun nRF24LU1+ 开发板 |
|---|---|---|
| GND | 9 | GND |
| 8 | 3 | RESET |
| 9 | 2 | PROG |
| 10 | 10 | P0.3 |
| 11 | 6 | P0.1 |
| 12 | 8 | P0.2 |
| 13 | 4 | P0.0 |
| 3.3V | 5 | VIN |
sudo make spi_install
伪混杂模式设备发现工具,可扫描一组信道并打印解码后的增强型 Shockburst 数据包。
usage: ./nrf24-scanner.py [-h] [-c N [N ...]] [-v] [-l] [-p PREFIX] [-d DWELL]
optional arguments:
-h, --help show this help message and exit
-c N [N ...], --channels N [N ...] RF channels
-v, --verbose Enable verbose output
-l, --lna Enable the LNA (for CrazyRadio PA dongles)
-p PREFIX, --prefix PREFIX Promiscuous mode address prefix
-d DWELL, --dwell DWELL Dwell time per channel, in milliseconds
扫描信道 1-5 上的设备
./nrf24-scanner.py -c {1..5}
在所有信道上扫描地址以 0xA9 开头的设备
./nrf24-scanner.py -p A9
设备跟踪嗅探器,可跟踪特定 nRF24 设备的跳频,并打印该设备解码后的增强型 Shockburst 数据包。
usage: ./nrf24-sniffer.py [-h] [-c N [N ...]] [-v] [-l] -a ADDRESS [-t TIMEOUT] [-k ACK_TIMEOUT] [-r RETRIES]
optional arguments:
-h, --help show this help message and exit
-c N [N ...], --channels N [N ...] RF channels
-v, --verbose Enable verbose output
-l, --lna Enable the LNA (for CrazyRadio PA dongles)
-a ADDRESS, --address ADDRESS Address to sniff, following as it changes channels
-t TIMEOUT, --timeout TIMEOUT Channel timeout, in milliseconds
-k ACK_TIMEOUT, --ack_timeout ACK_TIMEOUT ACK timeout in microseconds, accepts [250,4000], step 250
-r RETRIES, --retries RETRIES Auto retry limit, accepts [0,15]
在所有信道上嗅探来自地址 61:49:66:82:03 的数据包
./nrf24-sniffer.py -a 61:49:66:82:03
星型网络映射器,通过更改指定地址的最后一个字节,并在信道列表中的每个信道上探测 256 个可能的地址,来发现星型网络中的活动地址。
usage: ./nrf24-network-mapper.py [-h] [-c N [N ...]] [-v] [-l] -a ADDRESS [-p PASSES] [-k ACK_TIMEOUT] [-r RETRIES]
optional arguments:
-h, --help show this help message and exit
-c N [N ...], --channels N [N ...] RF channels
-v, --verbose Enable verbose output
-l, --lna Enable the LNA (for CrazyRadio PA dongles)
-a ADDRESS, --address ADDRESS Known address
-p PASSES, --passes PASSES Number of passes (default 2)
-k ACK_TIMEOUT, --ack_timeout ACK_TIMEOUT ACK timeout in microseconds, accepts [250,4000], step 250
-r RETRIES, --retries RETRIES Auto retry limit, accepts [0,15]
映射地址 61:49:66:82:03 所属的星型网络
./nrf24-network-mapper.py -a 61:49:66:82:03
nRF24LU1+ 芯片包含一种用于发射连续音调的测试机制,如果您拥有 SDR,则可以验证其频率。设备之间的频率偏移可能导致意外行为。例如,一块经过测试的 SparkFun 开发板存在约 300kHz 的频率偏移,导致它在两个相邻信道上收到数据包。
此脚本将使收发器在传入的第一个信道上发射音调。
usage: ./nrf24-continuous-tone-test.py [-h] [-c N [N ...]] [-v] [-l]
optional arguments:
-h, --help show this help message and exit
-c N [N ...], --channels N [N ...] RF channels
-v, --verbose Enable verbose output
-l, --lna Enable the LNA (for CrazyRadio PA dongles)
在 2405MHz 频率上发射连续音调
./nrf24-continuous-tone-test.py -c 5