-\r
-                       //  decode key here)\r
-                       ks2 = ar_enc ^ prng_successor(nt, 64);\r
-                       ks3 = at_enc ^ prng_successor(nt, 96);\r
-                       revstate = lfsr_recovery64(ks2, ks3);\r
-                       lfsr_rollback_word(revstate, 0, 0);\r
-                       lfsr_rollback_word(revstate, 0, 0);\r
-                       lfsr_rollback_word(revstate, nr_enc, 1);\r
-                       lfsr_rollback_word(revstate, uid ^ nt, 0);\r
-\r
-                       crypto1_get_lfsr(revstate, &lfsr);\r
-                       printf("key> %x%x\n", (unsigned int)((lfsr & 0xFFFFFFFF00000000) >> 32), (unsigned int)(lfsr & 0xFFFFFFFF));\r
-                       AddLogUint64(logHexFileName, "key> ", lfsr);\r
+                       at_enc_par = parity;\r
+                       if (!traceCrypto1) {\r
+\r
+                               //  decode key here)\r
+                               ks2 = ar_enc ^ prng_successor(nt, 64);\r
+                               ks3 = at_enc ^ prng_successor(nt, 96);\r
+                               revstate = lfsr_recovery64(ks2, ks3);\r
+                               lfsr_rollback_word(revstate, 0, 0);\r
+                               lfsr_rollback_word(revstate, 0, 0);\r
+                               lfsr_rollback_word(revstate, nr_enc, 1);\r
+                               lfsr_rollback_word(revstate, uid ^ nt, 0);\r
+\r
+                               crypto1_get_lfsr(revstate, &lfsr);\r
+                               crypto1_destroy(revstate);\r
+                               ui64Key = lfsr;\r
+                               printf("key> probable key:%x%x Prng:%s ks2:%08x ks3:%08x\n", \r
+                                       (unsigned int)((lfsr & 0xFFFFFFFF00000000) >> 32), (unsigned int)(lfsr & 0xFFFFFFFF), \r
+                                       validate_prng_nonce(nt) ? "WEAK": "HARDEND",\r
+                                       ks2,\r
+                                       ks3);\r
+                               AddLogUint64(logHexFileName, "key> ", lfsr);\r
+                       } else {\r
+                               if (validate_prng_nonce(nt)) {\r
+                                       struct Crypto1State *pcs;\r
+                                       pcs = crypto1_create(ui64Key);\r
+                                       uint32_t nt1 = crypto1_word(pcs, nt_enc ^ uid, 1) ^ nt_enc;\r
+                                       uint32_t ar = prng_successor(nt1, 64);\r
+                                       uint32_t at = prng_successor(nt1, 96);\r
+                                       printf("key> nested auth uid: %08x nt: %08x nt_parity: %s ar: %08x at: %08x\n", uid, nt1, printBitsPar(&nt_enc_par, 4), ar, at);\r
+                                       uint32_t nr1 = crypto1_word(pcs, nr_enc, 1) ^ nr_enc;\r
+                                       uint32_t ar1 = crypto1_word(pcs, 0, 0) ^ ar_enc;\r
+                                       uint32_t at1 = crypto1_word(pcs, 0, 0) ^ at_enc;\r
+                                       crypto1_destroy(pcs);\r
+                                       printf("key> the same key test. nr1: %08x ar1: %08x at1: %08x \n", nr1, ar1, at1);\r
+\r
+                                       if (NTParityCheck(nt1))\r
+                                               printf("key> the same key test OK. key=%x%x\n", (unsigned int)((ui64Key & 0xFFFFFFFF00000000) >> 32), (unsigned int)(ui64Key & 0xFFFFFFFF));\r
+                                       else\r
+                                               printf("key> the same key test. check nt parity error.\n");\r
+                                       \r
+                                       uint32_t ntc = prng_successor(nt, 90);\r
+                                       uint32_t ntx = 0;\r
+                                       int ntcnt = 0;\r
+                                       for (int i = 0; i < 16383; i++) {\r
+                                               ntc = prng_successor(ntc, 1);\r
+                                               if (NTParityCheck(ntc)){\r
+                                                       if (!ntcnt)\r
+                                                               ntx = ntc;\r
+                                                       ntcnt++;\r
+                                               }                                               \r
+                                       }\r
+                                       if (ntcnt)\r
+                                               printf("key> nt candidate=%08x nonce distance=%d candidates count=%d\n", ntx, nonce_distance(nt, ntx), ntcnt);\r
+                                       else\r
+                                               printf("key> don't have any nt candidate( \n");\r
+\r
+                                       nt = ntx;\r
+                                       ks2 = ar_enc ^ prng_successor(ntx, 64);\r
+                                       ks3 = at_enc ^ prng_successor(ntx, 96);\r
+\r
+                                       // decode key\r
+                                       revstate = lfsr_recovery64(ks2, ks3);\r
+                                       lfsr_rollback_word(revstate, 0, 0);\r
+                                       lfsr_rollback_word(revstate, 0, 0);\r
+                                       lfsr_rollback_word(revstate, nr_enc, 1);\r
+                                       lfsr_rollback_word(revstate, uid ^ nt, 0);\r
+\r
+                                       crypto1_get_lfsr(revstate, &lfsr);\r
+                                       crypto1_destroy(revstate);\r
+                                       ui64Key = lfsr;\r
+                                       printf("key> probable key:%x%x  ks2:%08x ks3:%08x\n", \r
+                                               (unsigned int)((lfsr & 0xFFFFFFFF00000000) >> 32), (unsigned int)(lfsr & 0xFFFFFFFF),\r
+                                               ks2,\r
+                                               ks3);\r
+                                       AddLogUint64(logHexFileName, "key> ", lfsr);\r
+                               } else {                                \r
+                                       printf("key> hardnested not implemented!\n");\r
+                               \r
+                                       crypto1_destroy(traceCrypto1);\r
+\r
+                                       // not implemented\r
+                                       traceState = TRACE_ERROR;\r
+                               }\r
+                       }\r