Learning to Decapsulate Integrated Circuits Using Acid Deposition
jcjc-dev.com
jcjc-dev.com
Looking at dies under a microscope is fascinating, especially if there is anyone around who can help explain what you're looking at. Sort of like exploring an alien robot civilization. :-)
In this case it turned out someone had taken one of our competitor's dies (probably a test reject), packaged it, and labeled it as ours. I'm not sure why they bothered with a die at all since it wasn't like it was pin compatible or even functional.
More interesting to me was how we would package the same part differently and sell it at different price points depending on how much functionality was brought out. You might decap a $10 part with X amount of I/O, cores, memory, etc and a $20 part with Y and find the exact same die. If the testing process was really sophisticated the $10 part would have a defect in the unused portion that made it more economical to down rate it than throw it away, but more often, it was just cheaper to maintain a single set of masks and sell the same die in multiple packages.
There's a couple of options. For hardwired ROM, you can sometimes just decap/delid your target device and check it out under a microscope. Take very high quality pictures, difference 1s from 0s simply by looking at it, and reconstruct the binary data in your computer. That's been done to extract private keys from smartcards (such process was described in the book Murdoch's Pirates, where hackers would pull private keys off satellite TV cards, and use them to create and sell pirated cards).
Another option, more relevant to systems where the data is in regular EPROM/EEPROM/Flash/... is to attack the "read only" eFuse. The attack basically consists of decapping your target IC, finding the read-only efuse, covering the memory area with black tape, and shinning UV light on the eFuse. The photons will excite the electrons stuck in the cell, draining it, and enabling memory reads. At the end of the post I provided a link to Bunnie's blog where he does exactly that on a PIC target device, and manages to extract protected data.