Reading Silicon: How to Reverse Engineer Integrated Circuits

  Переглядів 387,423

HACKADAY

HACKADAY

День тому

Ken Shirriff has seen the insides of more integrated circuits than most people have seen bellybuttons. (This is an exaggeration.) But the point is, where we see a crazy jumble of circuitry, Ken sees a riddle to be solved, and he's got a method that guides him through the madness.
In his talk at the 2016 Hackaday SuperConference, Ken stepped the audience through a number of famous chips, showing how he approaches them and how you could do the same if you wanted to, or needed to. Reading an IC from a photo is not for the faint of heart, but with a little perseverance, it can give you the keys to the kingdom. We're stoked that Ken shared his methods with us, and gave us some deeper insight into a handful of classic silicon, from the Z80 processor to the 555 timer and LM7805 voltage regulator, and beyond.
Read the article:
hackaday.com/?p=237161
Learn more about Ken Shirriff:
www.righto.com/
Learn more about the Hackaday SuperConference:
hackaday.io/superconference/

КОМЕНТАРІ: 357
@franklydude
@franklydude 6 років тому
I'm a (retired) analogue IC designer and have many happy (?) memories studying other companies IC's using optical microscopes in our engineering laboratory, to reverse engineering them. It was a good way to learn tricks of the trade. I hope some engineers have studied some of my creations! We also used manual micro-manipulators to electrically probe connections when studying a powered up die. We sometimes used a laser to cut tracks in the lab. We also occasionally used an ion-beam milling machine to slice into the depth of an IC so we could modify the silicon experimentally. Oh what fun we had!
@willynebula6193
@willynebula6193 6 років тому
Ion beam milling machine what a unique bit of gear! Something like that would have cost millions. What companies would even manufacturer a machine like that
@franklydude
@franklydude 6 років тому
I forget the name of the company we used. It's not a big machine. Same principle as an electron beam microscope I think, although the polarity is obviously reversed! A tall evacuated chamber along which one accelerates charged particles. I think you have a very hot "anode" source creating a plasma (if that is the right terminology) so ions can be sucked away by the electric field. magnetic fields deflect the beam. The ions are much heavier than electrons and abrade the surface they hit... If I recall correctly, there was even technology to deposit material at a lower energy so that one could add a conducting track, very slowly......
@fakename3344
@fakename3344 4 роки тому
@@franklydude Would you happen to remember what it was? I'm really curious as to where I'd get the equipment to do this.
@franklydude
@franklydude 4 роки тому
@@fakename3344 I think it was companay in Cambridge or maybe even a university facility, I live in the UK... If you do a google for "focussed ion beam" milling etc, you should find some resources, certainly in the USA and in Europe, probably Japan and China too..
@gregorymalchuk272
@gregorymalchuk272 4 роки тому
@@franklydude Yeah, they also have ion implantation (basically ion doping) machines.
@HariWiguna
@HariWiguna 7 років тому
I've always been impressed with those who could read disassembled code. but at minute 11:43 , Ken is disassembling SILICON and THEN disassembling the code that is in that ROM in that silicon! Oh as if that is not enough, he also wrote a simulator of the calculator he reverse engineered BY LOOKING AT THE SILICON!? WOW...
@HxcTufty
@HxcTufty 6 років тому
Anyone that had being paying attention to EE classes (VLSI, Computer Archtecture, Microprocessors etc.) can do that. It is a lot of work though.
@dummypg6129
@dummypg6129 6 років тому
Actually there is a method on how to perform that... Decap, hotspot, curve tracing etc. its just depending on the ic function/s thats varying and talent is required.
@Daniel-ib5bx
@Daniel-ib5bx 6 років тому
I’m sayin right... what a bad ass lol
@zariumsheridan3488
@zariumsheridan3488 6 років тому
what a royal waste of time though ...
@satibel
@satibel 6 років тому
You are watching videos, what a waste of time! Jokes aside, any hobby may seem like a waste of time to others.
@johnnyprimavera2
@johnnyprimavera2 7 років тому
Simply put: Great overview of silicon features and excellent approach on chip decapping.
@edinfific2576
@edinfific2576 6 років тому
Very nice and interesting to see how those basic components and circuits are made. Great work!
@zlac
@zlac 6 років тому
FFS, somebody give this guy a glass of water!
@meepk633
@meepk633 6 років тому
Banana noises.
@Mx6D
@Mx6D 6 років тому
so true lmao. Michael you hit right on the head
@crackmaster88
@crackmaster88 6 років тому
hahah i thought i was the only one who noticed that :D :D
@Euquila
@Euquila 6 років тому
it's like he's chewing on the very circuitry from his lecture.
@huckanz
@huckanz 6 років тому
actually those dry-mouth sounds are so pleasant for me... weird...
@chiragsinghyadav
@chiragsinghyadav Рік тому
I studied automation engineering and almost everything here was a part of the curriculum. I wish it was taught like this! Had so much difficulties in understanding the implementation of gates on chip that I couldn’t visualize it so had to learn them and I hated ‘just learning’ part. There’s no fun without seeing it practically. Great video
@TangodownNZ
@TangodownNZ 4 роки тому
I need the laser pointer when you zoom in please! Because we have no idea where he is pointing to.
@davidmaiolo
@davidmaiolo 4 роки тому
Thanks, had fun getting a better look into the transistor designs that actually make their way into an ic.
@samykamkar
@samykamkar 6 років тому
Ken is awesome
@giuliaesposito3071
@giuliaesposito3071 5 років тому
u too
@Adam-yd8dw
@Adam-yd8dw 5 років тому
My hero ❤️
@rooster443
@rooster443 5 років тому
Reverse engineering, the ultimate hacker skillz
@TracyNorrell
@TracyNorrell 8 місяців тому
If this the guy from the curious Marc videos?
@LumocolorARTnr1319
@LumocolorARTnr1319 6 років тому
Good talk but what are they doing with the camera taking shots from the back of the room and switching to the talker when he is showing something on the screen. Whoever filmed and edited this, watch some defcon talks.
@michaelbuckers
@michaelbuckers 4 роки тому
Yeah the filming is abysmal. 95% of the time he's showing something with a laser pointer, you can't see what it is.
@josephmazzeo2713
@josephmazzeo2713 3 роки тому
I really wanted to see what he meant by the "oh that's bad..." slide.
@darrelldourte9455
@darrelldourte9455 2 роки тому
Couldn't watch...camera man destroyed all follow along to the educational value seeking to be given. Hand that man a broom.
@Zemael
@Zemael 6 років тому
Thank you! This is the kind of information I always tryed to find. Great links!
@dans.8198
@dans.8198 6 років тому
Laser pointer vs mouse pointer :-(
@leocurious9919
@leocurious9919 5 років тому
"this here..." "these ..." WHERE?!
@fixing_stuff
@fixing_stuff 8 місяців тому
man you have to give the name of the music played at the end... so good
@Stallnig
@Stallnig 6 років тому
crazy how much stuff is on these tiny pieces, and its getting even crazier by the day. I can't even imagine how much engineering hours and knowlege went into any of these things.
@jeremiefaucher-goulet3365
@jeremiefaucher-goulet3365 4 роки тому
If you guys like Ken Shirriff, I suggest watching the CuriousMarc channel. Ken is often there tagging along and working with the others in restoring and understanding these old computers.
@drdyna
@drdyna Місяць тому
That's where I knew the face from, haha. I was sitting here watching this dude like where have I seen him....watching Marc's space shuttle computer videos!
@iuliannitu5699
@iuliannitu5699 5 років тому
Very interesting what you do Ken. Thank You.
@NSAwatchesME
@NSAwatchesME 7 років тому
i actually learnt quite a lot
@richardhead8264
@richardhead8264 6 років тому
*_THAT_* was freaking cool!!! _So much better_ than textbook cartoons!
@EnglishTeacherBerlin
@EnglishTeacherBerlin 6 років тому
Absolutely fascinating! Thanks a lot!
@SerBallister
@SerBallister 2 роки тому
Fascinating talk, learned a few things new things it. Thank you so much.
@whiteburr
@whiteburr 5 років тому
Phenomenal presentation! I want to thank that guy (and get him a bottle of water!)
@kevinhevans
@kevinhevans 5 років тому
Currently in school for comp E and we're slowly going over the topics presented, so this talk is really fascinating (to see this stuff in practice!) Does anybody know how large were the teams that were designing these chips?
@AI6XG
@AI6XG 3 роки тому
Early Mostek calculator devices (1970s) had fake contacts that would mess with reverse engineering and swiping the circuit. The fake contacts were not able to be detected under optical microscopy unless you were good at noting the direction of focus
@PauloConstantino167
@PauloConstantino167 4 роки тому
Beautiful work.
@12volt15
@12volt15 2 роки тому
Thank for sharing this! Really appreciate it!
@mrroobarb
@mrroobarb 6 років тому
Fantastic - very informative.
@MadsonOnTheWeb
@MadsonOnTheWeb 4 роки тому
It could've been even longer presentation and I still would watch it.
@MorganEarlJones
@MorganEarlJones 6 років тому
I chuckled when I saw the instruction "waitno"
@jlg23us
@jlg23us 7 років тому
Great job! Thank you for sharing :D
@yoramstein
@yoramstein 7 років тому
Great lecture
@bkzzzzz
@bkzzzzz 6 років тому
very nice inside of very popular chips. I always wonder how do they work still so tinny.
@danielkrajnik3817
@danielkrajnik3817 3 роки тому
this is crazy, awesome, breathtaking
@nxxxxzn
@nxxxxzn 7 років тому
this channel is awesome
@DavidvanDeijk
@DavidvanDeijk 4 роки тому
2nd time i watch this, still wrecking my brain about that ALU trick.
@hereb4theend
@hereb4theend 3 роки тому
Absolutely brilliant. Thank you very much.
@willynebula6193
@willynebula6193 7 років тому
absolutely brilliant
@tmdrake
@tmdrake 5 років тому
Rawr, Love the chip die art!
@amrkoptan4041
@amrkoptan4041 6 років тому
im a big fan of yours since curious marc channel !!!!
@PilotPlater
@PilotPlater 6 років тому
MikesElectricStuff does videos deencapsulating chips which is cool, but havent seen or forgot ever seeing anyone show a transistor-level look! Cool
@harakatabdelmjid9449
@harakatabdelmjid9449 4 роки тому
Merci pour la vidéo j'aime beaucoup les recherches
@ismaillafria2757
@ismaillafria2757 4 роки тому
كتبغيو البحث ولا كيعجبكم غير تشوفو الأخرين كيقومو بأمور خارقة بحال هكا,,العربان أش عندكم ماديرو
@dkaye512
@dkaye512 6 років тому
If you have an archive of the raw footage from all of the cameras, it would greatly helpful to have the wide angle shot showing you pointing is really helpful. However, the slides are better resolution, but where he is pointing is lost. The lecture is very interesting, but when you don't see where he is pointing makes much more difficult to follow Thanks.
@edgeeffect
@edgeeffect 4 роки тому
Yeah you can't win with the slides... laser pointer OR better quality image but you can't have both.... ideally we need speakers to use some kind of "virtual laser pointer" on the presentation laptop.
@olegil2
@olegil2 2 роки тому
@@edgeeffect You can have both, it's called picture in picture. You can show slide, presenter and picture of where he's pointing at the same time. Then the virtual experience would in most cases actually be better than the real one. "Virtual laser pointer" as in mouse pointer? Yeah, would be nice if someone invented that.
@TSulemanW
@TSulemanW 2 роки тому
Nice explaination
@linuxguy1199
@linuxguy1199 6 років тому
28:30 Looks more like a factorio base than an IC XD
@PilotPlater
@PilotPlater 6 років тому
this made me chuckle
@DavidHenderson1
@DavidHenderson1 4 роки тому
I mean, in a way, they're essentially the same thing. With Factorio, you're taking resources and converting them into other resources. With processors you're taking inputs and converting them into outputs.
@Cyberfoxxy
@Cyberfoxxy 5 років тому
after a decades of innovation we still haven't figured out how to get a laser pointer on youtube
@jaymzkardell1841
@jaymzkardell1841 7 років тому
This is awesome.
@xenlase
@xenlase 7 років тому
Brilliant :)
@nagualdesign
@nagualdesign 6 років тому
My sentiments exactly.
@jamest.5001
@jamest.5001 6 років тому
I don't think I'd wanna buy a POSFET OR a POS transistor. this is a very interesting video.
@tibfulv
@tibfulv 5 років тому
How about an old SGI Tezro? SGI doesn't exist anymore, and to our knowledge these machines aren't repairable using standard services. Reengineering the ICs may be the only way to service them, and emulation requires the same thing.
@damianbutterworth2434
@damianbutterworth2434 Рік тому
I have a David and Mann x,y table from a microchip factory. Very accurate. It had a 110 volt motor on the x axis. So I wonder if it was for cutting the wafers up.
@NicksStuff
@NicksStuff 19 днів тому
This blew my mind
@HansBaier
@HansBaier 3 роки тому
Excellent!
@MrGunnaras
@MrGunnaras 5 років тому
You are amazing!
@hqqns
@hqqns 4 роки тому
Oh, it's Ken from Marc's channel!
@paulgill7222
@paulgill7222 Рік тому
Guys like him and the designers are out of this world, seriously extra terrestrial ufos.....wow.... way over my head..........
@sjb27182
@sjb27182 6 років тому
Silicon in an elevated enthalpy reaction(add heat) undergoes an elevation of the 3p orbitol, allowing for an enthalpy controlled reduction/oxidation reaction of the atom. So start there. Then make transistors...
@sardinefinder334
@sardinefinder334 4 роки тому
My digital logic professor brought me here. THANKS J DAWG
@SebastianGarcia-go4tx
@SebastianGarcia-go4tx 3 роки тому
This guy should definitely write a book about this topic. I'd love to learn more about it.
@tekvax01
@tekvax01 4 роки тому
where did the cool opening and closing music come from? anyone know who made it?
@PauloSantos-cv1bi
@PauloSantos-cv1bi 4 роки тому
Wow! Amazing!!
@metallitech
@metallitech 6 років тому
When I was 11 or 12 years old I did a science fair thing where I got the chips out and let people look at them with a microscope. The way I came up with for getting the silicon out was simply by heating the package until it crumbled.
@hydrochloricacid2146
@hydrochloricacid2146 6 років тому
metallitech hey that's what i do!
@deaustin4018
@deaustin4018 5 років тому
well, I started programming in the late 60s, but I can still understand like maybe up to 30 percent of this. I checked with a couple other people, sure enough, they couldn't understand a single word, so I'm happy enough.
@ramizyabac3256
@ramizyabac3256 Рік тому
:)
@abdokamal4133
@abdokamal4133 Рік тому
Thank you. I wanted to ask about the power of the microscope used
@neojb7417
@neojb7417 6 років тому
YES!
@aaronr.9644
@aaronr.9644 7 років тому
Great stuff! Is there a forum somewhere (something like reddit) where ppl take a stab at analysing these die pics?
@Donatellangelo
@Donatellangelo 7 років тому
This looks like it takes a lot of patience. But that's okay, well worth it in the end.
@gregorymccoy6797
@gregorymccoy6797 2 роки тому
It's Master Ken!!!
@generosonunezarias369
@generosonunezarias369 3 роки тому
This Guy is a Beast with Silicon! Wow!
@seankayll9017
@seankayll9017 6 років тому
You sounded really nervous. Relax, it was a fascinating talk and your presentation was excellent.
@nicknicolosi1
@nicknicolosi1 6 років тому
that's impressive!
@peterhindes56
@peterhindes56 6 років тому
shame I cant see the lazer pointer
@-LightningRod-
@-LightningRod- 5 років тому
bro, u r amazing, that is soo cool ,nd the earth is burning,
@limsheng4873
@limsheng4873 5 років тому
we should b extremely thankful 4da existence of XEROX ALTO cuz it was a precursor 2all modern Pc's.
@NorthWay_no
@NorthWay_no 3 роки тому
Fantastic stuff. Is there anything like a program that can be fed a die photo and more or less make sense of it?
@snooks5607
@snooks5607 3 роки тому
that's how you create Skynet
@dennihsaur
@dennihsaur 6 років тому
I watch these videos with no background in CS, i'm just like wtf how is this even possible?!?
@yaus0527
@yaus0527 6 років тому
No, it is possible. If you study semiconductor related knowledge, it will be piece of cake.
@BemBem-G
@BemBem-G 6 років тому
hay quá. cám ơn rất nhiều. rất hữu ích. tôi rất thích chúng.
@climbeverest
@climbeverest 3 роки тому
Incredible only in America such geniuses self develop
@josephmazzeo2713
@josephmazzeo2713 3 роки тому
I always wondered if a working chip with a metal lid will continue to work with the lid popped off and exposed to ambient air. The lid would have to be removed carefully so as not to damage the bonding wires or the chip. Would light have any effect? How about a low power laser such as from a pointer? EPROMs continue to work even though the window is exposed (although erasure might occur after some time), so I guess yes?
@KevinJohnson-fw8kv
@KevinJohnson-fw8kv Рік тому
it has to be exposed to UV light a strong UV light. Which is why some of these EEPROMs that are being pulled out of vintage computers from the 80's still have all of their EEPROM data intact.
@edgeeffect
@edgeeffect 5 років тому
Oh hello Ken! Seen you before hanging around with Curious Marc.
@hqqns
@hqqns 4 роки тому
It was a pleasant surprise to recognise someone. He definitely is a reverse engineering king.
@raynegames2636
@raynegames2636 6 років тому
This Guy is a master of the modern reverse Engineering, a God...
@choosetolivefree
@choosetolivefree 6 років тому
These chips are not modern, but in fact very old. This would be nearly impossible to do with modern chips, as one of the commenters above explained very well
@delysid111
@delysid111 2 роки тому
His good . the true beauty of transistors is the differance in opening, and closing . Some are Voltage controlled, some are Ampere controlled, some are Normally Open NO, others are NC, Normally Closed , before you apply voltage to them . NPN & PNP junctions .
@Bianchi77
@Bianchi77 4 місяці тому
Cool video, thanks :)
@n.aminr.7175
@n.aminr.7175 4 роки тому
For YT videos, I suggest you show the diagram next to the actual screen. I can't see that laser dot on my screen to sync with his explanation lol.
@StefanReich
@StefanReich 5 років тому
Love it
@WooShell
@WooShell 6 років тому
Who's the end theme song from? I need that track badly..
@abbyboing
@abbyboing 4 роки тому
Excellent amount of information. Respect. Just the Saliva sound was a bit bothersome. Sounded a bit kinky while under the impression of knowledge. You know.
@Sparkette
@Sparkette 4 роки тому
Am I the only one who saw "Instruction ROM" in the calculator chip and immediately thought, I'd love to experiment with that and see what changing values in it would do?
@ajikishaya463
@ajikishaya463 Рік тому
I've been wondering how the control logic schematic looks like and how it interacts with the interrupts in the instruction rom( schematic) at transistor leve of the z80 and it's burning my neural circuit. Someone plz save me!
@EllotusFreeholy
@EllotusFreeholy 6 років тому
"if you stare at it long enough it will start to make sense" ~ No, if YOU stare at it long enough it will start to make sense, if I stare at it long enough i'll get a headache. lol
@firmman4505
@firmman4505 4 роки тому
Ellotus Freeholy lol
@emmarobertson3933
@emmarobertson3933 4 роки тому
9:02 just for efficiency, would it not be better to use just 2 transistors to solve the NOR circuit the 3 transistor seems of no use theoretical it might be part of the drawment for the negation but why would you do that then
@jeffsheldon
@jeffsheldon 7 років тому
I've found that very flat ceramic chips (which can't be chiseled) can be heated and will crumble, though occasionally with case residue on the die. The fumes are not good for breathing.
@andreassjoberg3145
@andreassjoberg3145 5 років тому
I think that we soon will have access to high power laser beams that can chisel away AND scan a chip in 3D and remodel them, as a by-product of the nascent 3D-printing technology.
@deldrinov
@deldrinov 6 років тому
That last shot looked totally like screenshot from Factorio.
@spidermcgavenport8767
@spidermcgavenport8767 5 років тому
My favorite past time hobby is editing assembly code in original Nintendo games. Hex editor for DOS. Keeps me busy.
@arts9591
@arts9591 6 років тому
ALU the real brain of a chip by Ken.S
@haxxx0rz
@haxxx0rz 5 років тому
Nice outro music. Sounds very 303-ish :-)
@RequiemForABuckeye
@RequiemForABuckeye 2 місяці тому
It'd be nice if we could actually see what he's pointing at when he keeps saying which parts "run here"
@Kenbomp
@Kenbomp 3 роки тому
Not unusual cur mirror it saves allot of space. Beautiful design
@bluestar2253
@bluestar2253 3 роки тому
Anybody here still remember the early days of 1980s when the Soviets stole the blueprint for Zilog Z8000 microprocessor and tried to reverse engineer it.
@johnmarks714
@johnmarks714 2 роки тому
I dont. Got any info? Im interested
@terencem9962
@terencem9962 6 років тому
i got a few chips open but it just was white mush. don't know where they put the transistors and i have a feeling they had just stuffed it with potatoe
@AstAMoore
@AstAMoore 7 років тому
“Any Z80 fans out there?” Yes, me! Me! Me!
@desmondwilson3416
@desmondwilson3416 6 років тому
Right...the game boy advance..tho..
@KuraIthys
@KuraIthys 6 років тому
What about the GBA? It uses an ARM/Thumb core. Though obviously, yes, it contains a Z80 as well, for obvious reasons. (in fact, the Mega Drive/Genesis contains a z80 for basically the same reason; Technically it's the Audio co-processor, but I'm sure using it for that was an afterthought; The only reason they chose a z80 for that task is that they wanted it to play Master System games and thus needed one anyway. Might as well put it to work doing something else while it's there.) Still... Z80... Ehh. I'll stick with my 65xx family chips thanks. XD
@perseverance8
@perseverance8 6 років тому
Ditto!
@halonothing1
@halonothing1 5 років тому
I had to pet the Z80 I have in front of me when he said that.
@josephmazzeo2713
@josephmazzeo2713 3 роки тому
I love the vintage processor chips, especially Z80, 8085, 805x series. Yeah I know you won't build a Pi clone with one of those but they are fun to work with!
@nanoelectronicsdemystified
@nanoelectronicsdemystified 7 років тому
Awesome
@MarkSeve
@MarkSeve 6 років тому
PoW!! Mind blown! Additionally, watch Ben Eater for step 2
Fairchild Briefing on Integrated Circuits
29:52
Computer History Museum
Переглядів 283 тис.
Reverse engineering a simple CMOS chip
41:14
Robert Baruch
Переглядів 127 тис.
Артем Пивоваров х Klavdia Petrivna - Барабан
03:16
Artem Pivovarov
Переглядів 7 млн
How TRANSISTORS do MATH
14:22
In One Lesson
Переглядів 2,1 млн
Hack everything: re-purposing everyday devices - Matt Evans
50:39
Linux.conf.au 2012 -- Ballarat, Australia
Переглядів 795 тис.
Making your own die photos: how to take apart a CPU
11:38
Distributed Systems Course
Переглядів 15 тис.
Decapping ICs (removing epoxy packaging from chips to expose the dies)
4:44
27c3: Reverse Engineering the MOS 6502 CPU (en)
51:57
Christiaan008
Переглядів 429 тис.
Reverse Engineering a Cold War Military Telephone
30:02
Nick's Knacks
Переглядів 113 тис.
The Fabrication of Integrated Circuits
10:42
Roberto Mulargia
Переглядів 585 тис.
Reverse Engineering the Motorola MC14500 1-bit CPU
21:57
Usagi Electric
Переглядів 16 тис.
Processor under microscope. Nanometer journey
12:41
My Computer
Переглядів 1 млн
Вы поможете украсть ваш iPhone
0:56
Romancev768
Переглядів 202 тис.
The power button can never be pressed!!
0:57
Maker Y
Переглядів 29 млн
Эволюция телефонов!
0:30
ТРЕНДИ ШОРТС
Переглядів 5 млн
📱 SAMSUNG, ЧТО С ЛИЦОМ? 🤡
0:46
Яблочный Маньяк
Переглядів 294 тис.
🤯Самая КРУТАЯ Функция #shorts
0:58
YOLODROID
Переглядів 3 млн