I extracted the RSA key from the Strong Srt7840 firmware (Italian decoder) with the nagra Merlin (Tvsat) encoding and this is a 2048 bit key in X.509 format, the verification is correct. In one section of the firmware there is in fact : BEGIN PUBLIC KEY and then END PUBLIC KEY. I also have the N Modulus of that RSA key that I derived and the public exponent. I need to understand the role of this key within the Nagravision Merlin CAK7.
I also study other CAK7 firmware outside tvsat especially CWPK and NUID how to find some 0day inside. as soon as I find some interesting stuff I'll throw it into the code in the C programming language with OpenSSL used by Tvsat decoders. I'm also developing a private nagravision3 emulator, for the moment it only covers Tiger coding but I may also get to Merlin.
Schermata a 2023-12-21 10-39-05.png
Schermata a 2023-12-21 10-42-04.png