Decapping integrated circuits with sap

[James] is interested in reverse engineering some integrated circuits. One of the biggest hurdles in this process has always been just getting to the guts of the chip. He used acetone to dissolve the plastic case but had trouble getting through the epoxy blob. Commonly, the epoxy is soaked in nitric acid for a few minutes but [James] didn’t have access to that chemical. Instead he popped into the local music store and picked up some rosin (used to make violin bows sticky enough to grab the strings of the instrument). After boiling down the rock-hard rosin and the chip for 20 minutes, he got a clean and relatively undamaged semiconductor that he can easily peer into.

Comments

  1. cpmike says:

    To what end, curiousity? Can a chip really be analyzed visually like this, to make any determination as to its function? I would imagine that it can’t help much more than normal creative testing of the existing pins…

  2. catzburg says:

    Sure if you get good enough magnification you can see the individual transistors, though most of these chips are multi-layer so you have to dissolve through the layer one at a time.

  3. Erwin says:

    Check the latest hitb slides, there was one about thermo analysisng chips to find out their functions.
    You can do it when the device operates so I guess its how jack bauer steal military secrets from embedded devices and uploads them to CTU :D

  4. Jake says:

    @cpmike

    Absolutely. My company regularly decaps/X-Rays IC’s for various purposes. Usually it’s to explore the possibilities of patent infringement, lol.

  5. It can also be used to get an idea of what’s in a chip that may let you reprogram it. Do those pins lead to an internal eeprom directly? JTAG? Level shifter for a serial port?

  6. Jon says:

    Another hackish way of decapping is just to simply take a blowtorch to the chip. It’ll become very britte and fall apart, except for the die itself.

  7. LarrySDonald says:

    Doesn’t look that undamaged but hard to tell w/ low magnification. Nowhere near well equipped enough to start trying anything anyway though so I dunno. Nurdrage (no relation to them, but have used their demos at times) have pretty good instructions for making small amounts of Nitric Acid from OTC only, supposing it’s only unavailable rather then illegal. Needs heavier concentrating, but then it’s not like you need much if you’re just decapping with it.

  8. mungewell says:

    Interesting… I wonder if the ‘oil’ (really a sap-derivative) which they use for dust control on North American gravel roads would work the same way. It comes in 55gal drums at a reasonable price, and I’m sure the local MD could spare a litre or two.

  9. steeve says:

    I wonder whether the chip still works!

  10. Chuckt says:

    LOL. Our company paid to get rid of their nitric acid. We could have just given you some. Now we would have to order it.

  11. Brent says:

    You sure he’s not making Meth? ;-)

  12. Chuck Norris says:

    Nitric acid is used for explosives, not for meth

  13. Jonathan Wilson says:

    One use for decapping chips is when the chips contain internal ROM, decapping can be used to read it out. If it contains mask ROM, you can decap it and photograph the ROM. In some cases you can decap the chip, disable the protection circuitry and read out the data.

  14. hyte says:

    careful of rosin fume, it will give you asthma. we used to encase the chips in Bakelite then polish, it worked well. Nice to see different options.

  15. Vonskippy says:

    What rock does this guy live under?

    You can buy Nitric acid pretty much anywhere.

  16. James says:

    @Vonskippy, I live under the really big one called Africa…

  17. Tachikoma says:

    Fuming nitric acid? Really?

  18. Fallen says:

    Hmm didn’t realize flux could do that.(that sap is just rosin…it’s been used in solder forever)I wonder if rosin sap is more effective than just using a bottle of rosin flux. Hmm would no clean fluxes work as well?

  19. catzburg says:

    @Fallen
    I can’t tell if you are joking, so no, no clean wouldn’t do the same thing

  20. Drone says:

    Sparkfun has a very interesting series of identifying fake ATMEL processors they purchased via decapitation at the ATMEL laboratories. Start here and drill down

    http://www.sparkfun.com/commerce/news.php?id=395

    Yes Nitric Acid is involved. Good read

    Regards, Drone

  21. kabukicho2001 says:

    the rosin can be dangerous, boiling would produce toxic gases.

  22. Shocked says:

    Pretty sure that the chip doesn’t work (at least properly) after boiling it in rosin at +320 C for 20 minutes. With large geometries could be lucky enough though.

    I think that may be good for failure or topological analysis (like reading a rom) but not for an active attack. But if nothing is going to be lost trying… :)

  23. Jayson says:

    Wow!

    There’s a music shop still open?

  24. Terry says:

    If a hobbyist in the US wanted to do this with fuming nitric acid where could I find some? I understand the stuff needs to be handled very carefully, with proper safety and ventilation and not disposed of in an unsafe way.

  25. Anonymouse says:

    @Terry,

    Not sure if you will be able to get it, one of the uses of it are making explosives, and you live in the usa…

  26. M4CGYV3R says:

    @Jayson
    Where else do people buy pianos and guitars and such?

    Even in my relatively small home town, we had at least 6 or 7 dedicated music shops, not including the 3 Guitar Centers, which is like the sell-out version. Cheap MIDI controllers though.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

Follow

Get every new post delivered to your Inbox.

Join 92,317 other followers