Skip to content

Latest commit

 

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

ELKSMART USB-C IR Blaster, reverse engineered

This is a USB-C infrared blaster that costs about 876 JPY. It comes with a vendor iOS app and no documentation. This repo contains the protocol, worked out from scratch, and IRDongleLab: a replacement iOS app that learns a code from a physical remote and sends it back out.

Status: working. Learning and transmitting both work from the custom app, and learned commands can be saved with names.

→ Read the full write-up

The AliExpress listing for a USB-C smart IR blaster dongle, with the two dongle variants outlined in a blue box.
The device, boxed in blue. Type-C Smart IR Blaster, USB `045C:0132`, sold under several names across the Ocrustar family.

The key finding

On iOS the dongle communicates over iAP2, not raw USB. That difference is what makes the protocol work or fail.

The Android app splits its payload into 62-byte chunks and adds checksum bytes. It has to, because on Android it talks to the device over raw USB and must handle the transport framing itself.

On iOS you must not do this. Over an EASession, write the complete application frame in one piece and let iOS handle the iAP2 packetization. If you copy the Android framing, you are packetizing data that iOS is about to packetize again, and the dongle ignores it.

What is in here

Path What it is
elksmart_ir_reverse_engineering.md The full write-up: USB descriptors, the iAP2 session, frame layout, learn and transmit flows, and the dead ends.
app/ IRDongleLab, the replacement iOS app. SwiftUI, ExternalAccessory, no third-party packages.
app/Core.swift Session handling, frame construction, Keychain-backed key storage.
app/REMOTE_EXPORT_FORMAT.md The on-disk format for a saved remote.
docs/irdongle_diagnostics.log A real session capture, kept as evidence for the claims in the write-up.
app/deploy.sh Builds, installs and launches the app on a device over the network using devicectl. Stops at the first failure and reports what went wrong.

How the protocol was worked out

The vendor's Android app was the reference. Its APK (Ocrustar remote control 7.2.6, downloaded from APKPure) was decompiled and read to work out the frame layout and the command set. Every conclusion was then tested against the real device from the iOS side.

The APK and the decompiled vendor sources are not in this repository. They are not mine to redistribute. What is here is the protocol description written from the analysis, and original code that implements it. Anyone wanting to repeat the work can obtain the same APK themselves.

Infrared light is invisible, so two tools were used to confirm the dongle was actually transmitting: an Apple Studio Display camera, which shows infrared as a faint purple glow, and an Arduino with a KY-022 receiver that prints the raw pulse timings.

A feature that does not work well

The app has an optional feature that photographs a physical remote and asks Gemini to find the buttons, so a learned code can be labelled without typing. Here is what the detector actually returned on a real photo:

A contact sheet of cropped image regions. Five show real remote-control button glyphs; nine are crops of wood grain from the desk surface.
Five real buttons. Nine crops of the desk.

It finds the button symbols, but it is just as confident about the wood grain of the desk underneath. This is included so you can see how well the feature actually works. The rest of the app does not depend on it.

Building it

cd app
DEVICE_UUID=<your device UUID> ./deploy.sh

Before building, set DEVELOPMENT_TEAM in IRDongleLab.xcodeproj/project.pbxproj to your own Apple team ID. It is set to REPLACEME in this repo. The device UUID is a placeholder for the same reason.

The optional photo-to-buttons feature calls the Gemini API and needs an API key. The app stores that key in the iOS Keychain. No key is included in this repo, and the app works without one.

Rights

The write-up, IRDongleLab and the scripts are original work, published for reference.

The device, its firmware, the vendor applications, and the Ocrustar and ELKSMART names belong to their owners. No vendor files are included here. This was a personal project to make hardware I bought work with software I control.

About

A cheap USB-C IR blaster with Windows and Android-only software, reverse engineered to a working custom iOS app over iAP2. The finding: Android's raw-USB fragmentation and checksums must not be reproduced over an ExternalAccessory session.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages