Live data from Hacker News

Can you reverse engineer an ASIC?

blog.janestreet.com

71–80 of 89 posts

Re: Can you reverse engineer an ASIC?

#71

Earlier quoted context omitted.

Many laymen confuse logic analyzers with oscilloscopes. Don't take it personally - the person you responded to is clearly not a native English speaker. You absolutely can reverse chips with logic analysis. It is big business in some parts of the world.

> You absolutely can reverse chips with logic analysis. You are not going to reverse engineer a GPU with a logic analyzer and by applying currents to pins. You could replace oscilloscope with logic analyzer in the comment above and nothing changes. It’s a fantasy story. The GPU I/O is high speed PCIe and memory buses. If you want to explore the chip you connect it to a PCIe host and use the host. Connecting logic ana…

I use this type of equipment every day. I'm aware of the expense - nobody said it was cheap to do this kind of work.

You might be thinking that the hobby-level logic analyzers you're used to, are what folks who are serious about doing this kind of work would be using. Just, no.

>Connecting logic analyzers and applying current to pins does not make sense on any level.

Tell me you've never fuzzed a chip without telling me you never fuzzed a chip.

Nobody said it would be easy or cheap, or that fuzzing is the only way to do it. The OP may not have had all the details correct.

But, you certainly can reverse engineer high-density digital electronics this way.

Re: Can you reverse engineer an ASIC?

#72

Earlier quoted context omitted.

with very, very expensive logic analyzers... But yeah, nothing weird here. Plus OP was retelling a story of someone else doing it, while probably not being a specialist in this field. So I wouldn't take the "random inputs" part literally.

> with very, very expensive logic analyzers... But yeah, nothing weird here. You can’t simply get an expensive logic analyzer and probe PCIe or memory buses at these speeds. There are expensive custom fixtures that need to be made to even begin to be able to probe at these speeds without disturbing the circuit so much that it fails to work. This isn’t like probing the I2C bus on a raspberry pi. It would be like conne…

Your pessimism belies a distinct lack of experience, if not also a dearth of imagination.

Harnesses for such things are not cheap, nor are they something you can just order from Reichelt. But, I assure you, there are reverse engineering labs in the world that can do this. There are technicians who think nothing whatsoever of de-soldering a BGA and using microscopes to rig things up. They do it before lunch, even.

The OP may have some details wrong - they're clearly laymen describing an anecdote - but that doesn't mean for an instance that this "isn't possible".

There is always a higher-speed logic analyzer, capable of operating faster than the consumer device under test. That's how the consumer DUT's get tested at the ATE, in the first place ..

Re: Can you reverse engineer an ASIC?

#73
post #43

I've looked at Visual 6502 and it's way beyond me. I've even looked at the scans where it shows how they severed the connection to disable 6502 decimal mode on the NES.

To be fair, the 6502 is very dense, and very hand optimized. Modern systems tend to use "standard cells" for logic which is a lot more digestible.

The original NMOS 6502 also used a lot of rather weird dynamic logic which can't easily be represented as standard digital logic elements. Some details here:

http://www.aholme.co.uk/6502/Main.htm

Re: Can you reverse engineer an ASIC?

#74
post #4

Is there something like an Extract-SPICE tool that takes a circuit and gives you back a text rendering of it ?

Practically No, the stack-up of metal layers often hides the gate structures underneath, and the billions of process cells may not all be the same. Theoretically Yes, as an ion-beam-mill and electron-microscope combination machine can slice up semiconductors layer-by-layer. Given these machines can often also give precise x-ray analysis material data, the exact makeup of the chip can be extracted by competitors given…

> Theoretically Yes, as an ion-beam-mill and electron-microscope combination machine can slice up semiconductors layer-by-layer.

You may not even need anything as fancy as that - many microchips can be delayered by a skilled operator using mechanical polishing processes.

Re: Can you reverse engineer an ASIC?

#75

I reverse engineered the Game Boy from pictures of the die - https://github.com/aappleby/metroboy - so yes, it's totally doable. It is also incredibly tedious and frustrating. Not sure if that gives me an advantage in this challenge, but I have too many things to do already. :D

Earlier this year I watched a video from a conference where a researcher took a die shot (one of Ken's I think) and then did guided learning by identifying on the image which were the different layers, metals, and layout of the gates on the die. The machine learning algorithm could go off and identify other gates and provide a netlist(?).

I've tried searching REverse, and some of the hacker conferences from January, but haven't found it yet.

Re: Can you reverse engineer an ASIC?

#76

I reverse engineered the Game Boy from pictures of the die - https://github.com/aappleby/metroboy - so yes, it's totally doable. It is also incredibly tedious and frustrating. Not sure if that gives me an advantage in this challenge, but I have too many things to do already. :D

Earlier this year I watched a video from a conference where a researcher took a die shot (one of Ken's I think) and then did guided learning by identifying on the image which were the different layers, metals, and layout of the gates on the die. The machine learning algorithm could go off and identify other gates and provide a netlist(?). I've tried searching REverse, and some of the hacker conferences from January,…

and of course I find it...

giulioz: MMO-CHIP: From Microscope to Verilog in an hour[1]

source code is on github[2]

[1] https://www.youtube.com/watch?v=5211iYEqnzo [2] https://github.com/giulioz/mmo-chip

Re: Can you reverse engineer an ASIC?

#77

Earlier quoted context omitted.

> You absolutely can reverse chips with logic analysis. You are not going to reverse engineer a GPU with a logic analyzer and by applying currents to pins. You could replace oscilloscope with logic analyzer in the comment above and nothing changes. It’s a fantasy story. The GPU I/O is high speed PCIe and memory buses. If you want to explore the chip you connect it to a PCIe host and use the host. Connecting logic ana…

I use this type of equipment every day. I'm aware of the expense - nobody said it was cheap to do this kind of work. You might be thinking that the hobby-level logic analyzers you're used to, are what folks who are serious about doing this kind of work would be using. Just, no. >Connecting logic analyzers and applying current to pins does not make sense on any level. Tell me you've never fuzzed a chip without telling…

> You might be thinking that the hobby-level logic analyzers you're used to, are what folks who are serious about doing this kind of work would be using. Just, no.

No I'm not. I'm referring to the logic analyzers and probes, and fixturing that would be necessary to probe something like this.

It's not as simple as saying "wouldn't be cheap". I'm saying it's virtually impossible for a university student to do for fun with the resources available to them.

> Tell me you've never fuzzed a chip without telling me you never fuzzed a chip.

Please don't be snarky. Also please don't take my quotes out of context to try to attack a strawman.

I'm talking about the comment thread we're responding to about someone reverse engineering the opcodes by applying current to the pins.

Nobody is going to be fixturing up an nVidia GPU chip, acquiring enough probes and logic analyzer inputs to measure it, then applying currents to pins, just to reverse engineer the opcodes. You're off trying to argue something else to show off your knowledge on the internet, but you've missed the point of the thread.

If someone wants to reverse engineer a GPU, the first thing you do is plug it into a system and access it through software. Nobody is going to connect logic analyzers to a million pins and re-invent PCIe signaling just because it's technically possible to do.

Re: Can you reverse engineer an ASIC?

#78

Earlier quoted context omitted.

> with very, very expensive logic analyzers... But yeah, nothing weird here. You can’t simply get an expensive logic analyzer and probe PCIe or memory buses at these speeds. There are expensive custom fixtures that need to be made to even begin to be able to probe at these speeds without disturbing the circuit so much that it fails to work. This isn’t like probing the I2C bus on a raspberry pi. It would be like conne…

Your pessimism belies a distinct lack of experience, if not also a dearth of imagination. Harnesses for such things are not cheap, nor are they something you can just order from Reichelt. But, I assure you, there are reverse engineering labs in the world that can do this. There are technicians who think nothing whatsoever of de-soldering a BGA and using microscopes to rig things up. They do it before lunch, even. The…

> Your pessimism belies a distinct lack of experience, if not also a dearth of imagination.

You keep missing the point and trying to insult my experience in the process.

We're talking about a university student and CPU opcodes. The whole side story about probing the chip is completely irrelevant. This is a software task.

> But, I assure you, there are reverse engineering labs in the world that can do this.

We're talking about a university student.

> There are technicians who think nothing whatsoever of de-soldering a BGA and using microscopes to rig things up. They do it before lunch, even.

I'm talking about the fixturing required to actually probe those pins. Replacing the BGA is the easy part. You can't probe a large BGA by having a tech remove and replace it. The contrast between you trying to insult my experience while not understanding the task at hand is truly something.

You've chosen a weird hill to die on, given how much you're arguing things that have no relevance to the story.

Re: Can you reverse engineer an ASIC?

#79
post #6

At my uni, 15 years ago, one postdoc reverse engineered NVIDIA chip and wrote more performant compiler. He did that by connecting oscyloscops to all chip's outputs and started with applying random current on inputs. Using ML and his genius he rediscoverd all opcodes including a few hidden ones. Eventually he got hired by some company that was doing a lot of GPU on supercomputers.

Detailed write-up please, or it didn't happen. At least not as described.

Really simple ICs with a few counters etc in there might be possible to RE this way. Complex ICs with lots of internal state, memory blocks etc like a modern-ish GPU? Not a chance.

Some hybrid approach? Software fiddling with the chip's internals, with say. a big FPGA attached to physically probe outputs? Architecture docs, and maybe some IC die shots at hand? Perhaps (hence my ask for "detailed").

Sounds like requiring the kind of hardware setup that would not be available to uni students.

Re: Can you reverse engineer an ASIC?

#80

Earlier quoted context omitted.

I use this type of equipment every day. I'm aware of the expense - nobody said it was cheap to do this kind of work. You might be thinking that the hobby-level logic analyzers you're used to, are what folks who are serious about doing this kind of work would be using. Just, no. >Connecting logic analyzers and applying current to pins does not make sense on any level. Tell me you've never fuzzed a chip without telling…

> You might be thinking that the hobby-level logic analyzers you're used to, are what folks who are serious about doing this kind of work would be using. Just, no. No I'm not. I'm referring to the logic analyzers and probes, and fixturing that would be necessary to probe something like this. It's not as simple as saying "wouldn't be cheap". I'm saying it's virtually impossible for a university student to do for fun w…

Your extreme claims that "nobody is going to do that", while I have actually seen people doing exactly that in modern universities and other reverse engineering institutions, just renders your stubborn know-best boring.

Yes, people do this. Yes, it is a lot of tedious work. PCIe signaling is not a panacea - there are reasons to fuzz like this.

I've also seen folks break out a tunneling electron microscope to dig deeper on de-laminated cores.

>I'm saying it's virtually impossible for a university student to do for fun with the resources available to them.

Now who's inventing straw man claims? "For fun"? Yes, for fun. "For profit"? Yes, for profit too. At universities? Yes, at universities.

Just give it up. The world is big.

Post reply on HN