Reverse-engineering the 8086 processor's address and data pin circuits
righto.com
righto.com
Unless I'm misunderstanding the terminology, there may be an error in the discussion of the shift/crossover circuit. And a minor typo...
> The [buses] can be connected in three ways: direct, crossed-over, or swapped.
> The "direct" mode connects the 16 bits of the C bus to the lower 16 bits of the address/data pins.
> The second mode performs the same connection but swaps the bytes.
> The final mode shifts the 20-bit AD bus value four positions to the right.
It sounds like those two modes got swapped? ;-)
For clarity, I think I would change the order in the introduction and use the mode names instead of "second" and "final":
> The buses can be connected in three ways: direct, swapped, or crossed-over.
> The "direct" mode connects the 16 bits of the C bus to the lower 16 bits of the address/data pins.
> The "swapped" mode performs the same connection but swaps the bytes.
> The "crossed-over" mode shifts the 20-bit AD bus value four positions to the right.
I'm curious about the circuitry that drives the difference between "minimum" and "maximum" modes from the processor - another Intel pin-saving strategy. Is there basically an 8288 sitting in a corner of the 8086 die, or are things more complicated than that?
Put another way, if you could, recursively, delete all the gates in the 8086 which only exist to drive minimum-mode pins, would any remnant of the minimum-mode signals remain for other internal uses?
My best guess is it for placing memory or state between the registers and the processing units. Or perhaps some subtlety of this as registers are already memory or state. I could not figure it out.
Modern patents are especially prone to this. They try to claim as much as possible while avoiding publishing any trade secrets. The result tends toward a unreadable mess.
Where they go and mention that the attackers went ahead and built their own simulator of a CPU as part of their attack vector. Do you know what they emulated and would you have more details on that specific hack ?
I think the authors promised to come back with a part 2 eventually but so far they haven't