Thursday, July 30, 2015

[SOLVED] Vodafone Data SIM on Galaxy S5 issues - Problemi SIM Dati Vodafone su Galaxy S5

Let's start with the precondition of my current adventure :

I have following devices at hand :
- Samsung Galaxy S5 running stock Android Lollipop (5.0) Baseband G900FXXU1BOD3 ;
- Samsung Galaxy S2 running stock Android ICS 4.0.4 ;
- Samsung Galaxy TAB 8.9 (GT-P7300) running stock Android ICS 4.0.4 (Baseband P7300XXLQ6) ;
- Alcatel Onetouch x215s USB-dongle 3G (TIM branded, but not locked) ;

I happen to be in the possession of following SIM-cards :
- Data SIM Vodafone Italy - Giga Maxi (10GB traffic on APN : web.omnitel.it) ;
- Voice SIM TIM Italy - SuperGiga (20GB traffic on APN : ibox.tim.it) ;
- Voice SIM Proximus Belgium - 5GB Data and 300MB Roaming on APN: internet.proximus.be ;

I'm currently on vacation in Italy and I have a fairly good coverage with TIM and VODAFONE where I currently reside. TIM seems to lack capacity : HSPA and HSPA+ almost never exceeds 500kbit (up/down). LTE is not available in my area. Vodafone seems to have a better base-station position and I have HSPA and 4G (LTE) with a surprising good speed (for the area I'm in) : during day 6Mb down/2Mb up, in calm period upto 12Mb down/ 8Mb up. This is ... when I manage to register on the network.

Here comes the catch.

When I put my Belgian SIM in any of my devices it just works. The APN is automatically selected and everything works just fine.

s2 + Proximus SIM : Connection is 3G (HSPA,HSPA+) on Vodafone network : speed > 2Mb  up/down;
s5 + Proximus SIM : Connection is 4G (LTE) on Vodafone network : speed > 5Mb up/down ;
Tab 8.9 + Proximus SIM : Connection is 3G on Vodafone network : speed similar to S2 ;

This of course is unsustainable because of my ridiculous small roaming allowance (300MB).

So I try to put my TIM Italy SIM in my devices. The APN is automatically selected and everything works just fine. On the Galaxy TAB I need to delete the wap.tim.it APN.

On all the devices data voice and data works OK, limited by the available bandwidth on the base-station in my area. With some luck 500kb, once in a while almost 1Mb but most of the time rather 200kb. A lot of switching between HSPA,HSPA+,UMTS (you see constant switching between H,H+,3G).

My initial plan was to stick with  the TIM Data plan and use a hotspot to share the 20GB with my family. Well, you imagine already ... with the constant switching between the different modes and the low bandwidth, the Wifi Hotspot isn't capable of delivering a useful bandwidth to the different clients around (2 Mobile Phones and a laptop). Even with 1 device connected, it isn't going anywhere.

Because the Proximus SIM is roaming on Vodafone, and it has a really decent bandwidth in 3G and 4G, I got myself a Data SIM with a data plan of 10GB. In the shop they assured me that it would work on my SGS5. I only need to assign the right APN (web.omnitel.it).

That's the theory. In practice, during my first try (4hours after activation of the SIM) nothing useful happened. My SIM registered on the network, but it didn't get any data-connection on web.omnitel.it.

The Vodafone Data SIM is delivered with 3 APN preconfigured :
- mobile.vodafone.it : for regular browsing ;
- web.omnitel.it : for tethered browsing - needed for Giga Maxi data plan ;
- mms : of course for MMS use ;

Whenever I activated the web.omnitel.it APN, it would revert a couple of seconds later (while still in the APN menu) to mobile.vodafone.it. It got me suspicious because I was told, it would eat into my prepaid credit on my account.

After a couple of hours messing around with the Vodafone SIM, rebooting, etc etc I got the connection working and I could test my setup for a while ... until the next morning ... it wouldn't connect anymore.

When I install the Vodafone Data SIM in my other devices, none of them work. The data symbol (G,E,3G,H,H+ or 4G) never lights up. Regardless of what I do (order of events, APN settings, reverting back to standard, etc etc).

Only exception is my SGS5 where I need to perform following trick to make it work.

 Insert Proximus SIM into SGS5 and let the SIM register on the Vodafone network. Data is ON.
Deactivate Data, shutdown phone and swap SIM with Vodafone SIM.
Switch on SGS5 and let it register on the Vodafone network.
Activate Hotspot. Let it create hotspot and make sure it is up. Connect a client to the hotspot (other phone or laptop).
Now activate data and make sure the right APN is active (web.omnitel.it).
Now reconnect a wifi client to the hotspot. You should get internet access.
If not, then disable and enable hotspot on SGS5. Reconnect the wifi client.

If this sequence is not respected, symptoms are :
- No data-connection at all on SGS5 : no matter what you do, no way to get data connection up ;
- Data-connection is working for SGS5 but the hotspot wifi clients have no internet access after a few seconds ;

In both cases, you have to swap SIM's and apply the above procedure carefully.

Whenever the Wifi Hotspot is deactivated (after timeout specified in Android or manual) the data connection may again be lost. Only way is to proceed with the SIM-swap procedure.
Trying without SIM-swap doesn't work. There needs to be a new combination provider/SIM/mobile phone before retrying a registration of the data SIM. Don't ask me why (I'm just guessing).

I tried to speak to customer service, but they don't seem to grasp the problem. And because I'm using my own workaround, they don't seem to bother much. Because I don't have a voice-plan with Vodafone, I can't really call them, so I tried Twitter but it's slow and the 130 char limitation is not helping either.

One could argue that I'm pushing the limits by using a Data SIM on my SGS5, instead of using a Mifi device, a 4G-USB dongle or just the tablet as advertised on their website.
But even on my Galaxy Tab 8.9, it doesn't seem to work out of the box.I tried to extend the connection type by adding 'internet' to the pre-exisiting 'dun' type to no avail.

I'm going to the shop tomorrow with my gear and will show them what is going on with my SGS5. If they could just fix my SGS5, I would be very happy.

And next year, I'll get myself a Mifi or a cheap 4G-dongle on my NS-1500 Openwrt box. Any suggestions are welcome.


[UPDATE]
Went to the store, and they were in total disbelieve. They saw my actual data traffic I used in the last couple of days and they thought my SIM was fine. Until I asked the storemanager to install the data SIM in his device : he couldn't even send text-messages with my SIM.
Conclusion : they performed a RESET of the SIM because there was a configuration issue with the SIM. The reset procedure takes between 15 and 30' and when I switched-on my phone after this 'reset'-period, everything was working just fine without any workaround. Pfew !










Sunday, February 1, 2015

LUA and ESP-8266 - What a wonderful world !

Guess what, I bumped onto a blogpost discussing a cheap Wifi-module for Arduino. A sub 5USD module with an embedded ARM processor on board. Unbeatable price and feature set !

After doing some research, I bought the ESP-12 module on Aliexpress :
It's a stamp-sized module, with a serial port and a bunch of GPIO's :
I connected my USB-Serial convertor (I have a CH340G with selectable 3.3/5V) and after figuring out the correct pinout , I flashed the LUA-firmware on it.

ESP8266CH340G-SerialUSB
VCCVCC
GNDGND
RXTX
TXRX

Holding GPIO15 = LOW, and CH_PD = HIGH activates the module.
Communication is possible @9600,8,N,1 in this mode.
Holding GPIO0 = LOW, brings the module in bootstrap mode and download of a new firmware is possible.

I chose to upload a new firmware :  nodemcu-firmware using the esp8266flasher.exe software.

From then on, you can talk to the module using the Serial.line and setup the module by either executing commands or by writing the lua.init file. I used a textfile with commands, allowing easy push to the ESP-module.
When reusing existing code, it is important to check the GPIO-mapping. In my case the LUA-Gpio's map as follows to the Hardware pins :

This means that IO (7) is actually using hw-pin GPIO13 !

Once the Module has been connected to the Wifi-AP, everything is straightforward.

Sending a command :
<< http://192.168.2.108/gpio7=0 >> will clear  GPIO13 on the board !
<< http://192.168.2.108/gpio7=1 >> will set  GPIO13 on the board !

Imagine what you could do !




Sunday, January 18, 2015

Using Computer Mouse as Scanning Device for Arduino

I happened to have a wireless keyboard/mouse combo lying around with a broken USB-dongle. Basically unusable for regular use, but of course ideal for some thinkering.

I recently read an article about using the image sensor as input device for Arduino or other MCU and I wondered if I could repurpose my mouse for this.

So, I took my mouse apart and found out it is based on the Avago ADNS-5030.

I first cut all the traces going to the local microcontroller, solder some pins on the sensor and hooked up my Arduino Mini Pro 3.3V/8Mhz as follows, I took the 3.3V power from the Arduino too :


NameADNS5030Mini Pro
VCC7VCC
GND6GND
NRST39
NCS48
CLK513
MOSI811
MISO112
Reading the datasheet, shows SPI has to be configured in SPIMODE 2 (Pol=1, Pha = 0). Clockspeed is 1Mhz, so the DIVIDER is set to 4.

A quick check allow to verify register 0/1 and to read ChipId and Revision, respectively 0x11 and 0x00.

I ran a small demo reading the Motion-register and reading the dX and dY movement. No big deal.

Now I wanted to make sure I could readout the 15x15 pixel imagesensor. For this you need to readout the Grabber-register (0x0B), check that the MSB is '1' and then use the 7 remaining bits as intensity.

I connected my IL9301 TFT screen to my Arduino and used the Adafruit GFX library to draw the pixels on the screen.

On the software side it's a bit tricky because IL9301 works in SPIMODE=3 and divider 2, so we are changing the SPI-parameters on the fly to make it happen.

This is the setup :
The image sensor has approx. 0,1mm pixel resolution, the 'e' on the TFT-screen corresponds to 1 character from the cardboard.


Sunday, January 4, 2015

Nokia USB Serial Cable hack for my Arduino Mini Pro

I happen to have a Nokia USB Serial Cable lying around. I used it to program my Openwrt router.
It was perfectly fine. I had cut of the Nokia connector and I used the 3 wires:

WireSignal
Black + ShieldGND
WhiteRX
GreenTX

This worked perfectly fine for all 3.3v gear connected to the serial lines.
Until the day I wanted to connect my Arduino Mini Pro (3V/8Mhz).

It worked ok, but there were 2 drawbacks :
- I needed to provide separate power to the Arduino ;
- Programming from the Arduino IDE, requires a manual RESET of the Arduino to start the download ;

After some research, I found out the Cable uses a PL-2303HX chip. On PIN 2, there's the DTR-signal  but it isn't connected. The Arduino IDE using this signal to issue a reset to the processor in order to put the chip in download mode.

So, I performed following changes :
- Cut trace leading to Black lead between the 2 solder pads ;
- Solder Red wire from Capacitor to Red wire ;

- Solder Blue wire from PIN 2 to Black wire ;




This effectively puts 3.3v on the RED wire, DTR on the black and leaves RX/TX/GND as before.

Works as a charm. I soldered some Dupont-lines to the end of the Nokia Cable, heatshrinked the connections and finally inserted the PL-2303 board back into the moulded housing and glued everything nice and thightly. In order to avoid confusion, I used BLACK for GND and GRAY for DTR.




WireSignalMini Pro
BlackGNDGND
WhiteRXRX
GreenTXTX
Red3.3VVCC
GrayDTRGRN

Saturday, November 29, 2014

Porting MZXT06A to Arduino

After having tested the MZXT06A LCD with my Raspberry Pi, I was wondering how much performance I would get out of a Arduino, knowing the processing power is much much smaller on a Arduino Uno or Mini Pro.

First thing  I did was figuring out how to connect the LCD-Board on the Arduino.
Turns out the Raspberry Pi driver is actually only using the MOSI/CLK signals and it is using the MISO/CE and GPIO25 as standard GPIO to interface the LCD-board.

A word about the MZXT06A. It is actually interfaced using a Altera EPM3213 PLD-chip. It's kind of weird because the LCD-controller has 18-bit RGB connectivity, but also 16-bit RGB over SPI. So what the EPLD does, is providing a true 18bit RGB interface over SPI.
The Altera  chip needs 3V power, but it's interface pins are 5V tolerant. This explains why a lot of people are capable of interfacing with 5V-Arduino boards. If you use a 3V Arduino, all will be fine.

I use the Arduino Mini Pro, running at 3.3V and 8 Mhz.

I connected the Display as follows :

- Arduino MOSI (11) : to pin 6 (LCD-SCI)
- Arduino CLK (13): to pin 7 (LCD-SCL)

- Arduino D2 (2) : to pin 5 (LCD-CS)
- Arduino D5 (5) : to pin 4 (LCD-RS)
- Arduino D9 (9) : to pin 3 (LCD-RST)

VCC,LED need 3V
GND goes to GND

Once connected, the display backlight should light up.

I have ported portions of the MZXT06A source-code to Arduino as a proof of concept.
I am now able to fill rectangles, draw circles and draw dots.
I havent figured out what goes wrong with the display_char function. I have put the font-data in PROGMEM because of the lack of dataspace on my Arduino, but no luck. It draws something, but it looks like random data (within the 8x16 characterspace).
Update: found the mistake with display_char. If one stores data in PROGMEM, one has to retrieve this data using a special function "pgm_read_byte_near" referencing the data using a pointer.


Performance is pretty good, considering the 8Mhz MEGA328P.
The display draws approx. 90mA of current and it fills a full frame at 1fps writing 1 byte at the time.
I'm sure this can be optimized.
Update: only way to speed up is to use a higher clock-rate. Currently the interface runs at half the processor speed and it's not the SPI-speed, but rather the CPU which is the bottleneck. Will try later on the Arduino Uno. Should run much faster.

If you need the code for your Arduino, just let me know.

Tuesday, November 25, 2014

Interfacing MZTX06A 2.2" TFT Screen on Raspberry Pi

I recently bought a 2.2" TFT screen with SPI interface and 320x240 pixel resolution on Deal Extreme.
According to the very rudimentary documentation it needs to be connected like this :





lcd pin lcd name Rpi pin Rpi name
1 LED+ 1 3.3V
2 VDD- 17 3.3V
3 /RST- 22 GPIO25
4 RS- 21 MISO
5 /CS- 26
6 SCI- 19 MOSI
7 SCL- 23 SCLK
8 GND 25 GND

After getting the MZTX06A software from github :
 https://github.com/yaolet/mztx06a.git
and launching the makefile, the resulting MZTX06A executable copies the /dev/fb content to the screen. Here below the result when launched directly from rc.local ...














In order to match framebuffer and screen resolution, one has to modify /boot/config.txt and uncomment the lines with Horizontal and vertical screen resolution. Please use 320 and 240 in order to avoid blurred screens.

This method works flawlessly with X. Just startx and watch. Unfortunately 320x240 pixels doesn't leave much space for actual work. Most user interfaces are not suited for low-res.

Tuesday, June 12, 2012

Recovering lost ODS Spreadsheet on USB Key

This weekend I mistakenly wrote a Linux image onto my USB Key instead of my SD Card. The result was a 25% overwritten 8GB USB Thumbdrive.
Recovering the data using Recuva didn't really work because of the origial FAT32 partition got overwritten with a FAT and ext4 partition. To make things worse both the first and second FAT was lost.
Doing some deepscanning allowed to retrieve apparently useful data, only to discover the recovery process wasn't able to create valid files. For fragmented files the recovery process used the first cluster and grabbed sequential clusters resulted in mixed up filefragments from differents files into the recovered file. What a disaster !
One of the files I desperately needed to recover was a 1850 Kbyte OpenOffice spreadsheet in ODS-format. Opening the file in  OpenOffice resulted in a 'corrupted file, do you want to repair' message and an empty file.
A bit of research pointed out that ODS-files are actually zipped containers containing the actual formating and content. In my case  bits of a PPT file, a MP3 file and other junk was mixed into the recovered file by the recovery process.
Finally I ended up using iBored as a forensic tool to perform some manual carving on the residual data on the thumbdrive.
By looking at a normal ODS-file, I identified the different zones of the OpenDocument format. Special markers in the zipped structure of the ODS-format are '50 4B 03 04' and '50 4B 07 08'. Other interesting and easily identified markers were the file and XML-tags contained in the ODS-file format, like 'META-INF/manifest', 'content.xml' and 'meta.xml'.
The thumbdrive happened to have 128 sector clusters (64KB) and the first cluster recovered by Recuva happened to be the correct start of the file. Knowing that one file only occupies 1 cluster and that sudden change of content inside consecutive clusters or zeroed sectors at the end of the cluster mean there's a rupture in the cluster sequence, I was able to verify the signature of the clusters following the first valid cluster of the file I was trying to recover. Using iBored as a rudimentary diskeditor, I first searched for the 'META-INF/manifest' string typically found at the end of the ODS document. It allowed me to pinpoint the end of the file approximately 7795 sectors after the first sector. I made a list of cluster boundaries and started identifying the content of the cluster by looking at typical signatures like 'MZ ...', directory entry-structures,  typical binary or DLL structures, plain text and randomized data.
Although zipped structures don't contain any internal indexes, they are characterized by the heavy compression and the full use of the 8-bit space, containing no wasted spaces with repeated values or patterns. 47 clusters could be eliminated as cluster belonging to the lost file. Looking at the remaining clusters it looked as if the file was stored in 2 chunks with some garbage inbetween.
Using the write block functionality of iBored, I wrote out the 2 chunks to the harddrive and reassembled the original file by doing a binary copy :
copy /b chunk1+chunk2 final.ods
By opening the resulting file in 7-zip, I could validate the correctness of the assembled data.
Opening the file in OpenOffice resulted in a 'Corrupted file - do you want to correct ?' and Calc was able to repair the inconsistencies without loosing any data or formatting information.
YAY !