MCU reverse engineering

Microcontroller Unlock - MikaTech

Our values and goals

About MikaTech

Time went fast, from the day we did our first 8051 MCU reverse engineering project in 1998, to the day we set up our million dollar reverse engineering lab in 2012, 14 years went by. Now we start our new business of embedded visual system development, hope we can serve another 10 years.

sign Peter Lee Co-Founder & CEO

Dallas MCU Crack

Dallas Semiconductor, now a subsidiary of Maxim Integrated Products, designs and manufactures analog, digital, and mixed-signal semiconductors (integrated circuits, or ICs). Its specialties include communications products (including T/E and Ethernet products), microcontrollers, battery management, thermal sensing and thermal management, non-volatile RAM, microprocessor supervisors, delay lines, silicon oscillators, digital potentiometers, real-time clocks, temperature-compensated crystal oscillators (TCXOs), iButton (commonly known as the Dallas Key), and 1-Wire products. The Dallas, Texas-based company was founded in 1984 and purchased by Maxim Integrated Products in 2001. Both the Maxim and Dallas Semiconductor brands were actively used until 2007. Since then the Maxim name has been used for all new products, though the Dallas Semiconductor brand has been retained for some older products.

  • Mikatech Dallas MCU reverse engineer list:
  • DS87CXX Series controller duplicate: DS87C520 DS87C530 DS87C550 ...
    DS89CXX Series controller duplicate: DS89C420 DS89C430 DS89C450 ...

 

1. 1-Wire Single-Wire IC Family (DS24xx / DS28xx / DS19xx iButton)

1.1 DS24xx 1-Wire Memory & Function ICs

DS2401 (64-bit unique ROM ID)

DS2405 (1-Wire single channel switch)

DS2406 (dual-channel switch + EEPROM)

DS2408 (8-channel I/O expander)

DS2430A (1Kb EEPROM)

DS2431 (1Kb EEPROM with write protection)

DS2432 (SHA-1 encrypted secure EEPROM)

DS2433 / DS24B33 (4Kb EEPROM)

DS2438 (temperature + battery monitor + ADC)

DS2450 (4-channel 1-Wire ADC)

1.2 DS28xx Secure & Specialized 1-Wire Chips

DS28E01 (SHA-256 authentication chip)

DS28E04 (secure 4Kb EEPROM)

DS28EC20 (20Kb EEPROM)

DS28EA00 (1-Wire multi-point digital thermometer)

DS28S60 (cryptographic security chip)

1.3 DS19xx iButton Standalone Data Loggers (Battery-powered)

DS1921 (Thermochron temperature logger)

DS1922 (high-capacity temperature logger)

DS1923 (temperature + humidity logger)

DS1961 (SHA secure memory iButton)

DS1963 (multi-page secure EEPROM iButton)

DS1990A (unique ID iButton key)

2. Digital Temperature Sensor & Thermostat Series (DS18xx / DS17xx / DS56)

2.1 DS18xx 1-Wire Temperature Sensors

DS1820 (9-bit digital thermometer)

DS18S20 (high-precision 9-bit sensor)

DS18B20 (9~12-bit programmable resolution, most mainstream)

DS1822 (low-cost 12-bit sensor)

DS1825 (multi-channel 1-Wire temperature sensor)

DS1821 (1-Wire thermostat with switch output)

2.2 DS17xx I2C/SMBus Temperature Sensors

DS1720 (2-wire digital thermometer)

DS1721 (dual temperature alarm sensor)

DS1722 (low-voltage SMBus temperature sensor)

DS1775 (remote diode temperature monitor)

2.3 Analog Thermostat IC

DS56 (dual-setpoint analog temperature switch)

3. Real-Time Clock (RTC) & Timekeeping ICs (DS12xx / DS13xx / DS15xx / DS16xx)

3.1 DS12xx Module RTC (Built-in battery + crystal, legacy PC clock)

DS1287 (industry standard PC motherboard RTC)

DS12CR887 (low-voltage upgrade version of DS1287)

DS1202 (serial SPI RTC)

DS1204 (RTC with watchdog timer)

DS1216 (smart socket RTC module)

3.2 DS13xx I2C Low-Power RTC (Most widely used)

DS1302 (3-wire serial RTC)

DS1307 (I2C 5V basic RTC)

DS1337 (I2C alarm RTC with square wave output)

DS1338 (low-voltage 3.3V I2C RTC)

DS1340 (ultra-low power RTC with trickle charger)

DS1374 (RTC with temperature compensation)

3.3 DS15xx High-Integration RTC (Watchdog / Power Control / NVSRAM)

DS1501 / DS1511 (Y2K-compliant RTC + watchdog + 256B NVSRAM)

DS1553 / DS1554 (data-logging RTC with large NVSRAM)

3.4 DS16xx Multi-Voltage RTC

DS1685 / DS1687 (3V/5V Y2K RTC, compatible with DS1287)

DS1602 (SPI RTC with battery monitor)

4. Non-Volatile SRAM (NVRAM / NVSRAM) Series (DS1220 / DS1225 / DS1230 / DS1245)

DS1220AB / DS1220Y (16K NVSRAM)

DS1225AB / DS1225Y (64K NVSRAM)

DS1230AB / DS1230Y (256K NVSRAM)

DS1245AB / DS1245Y (1024K 1MB NVSRAM)

DS1213 (smart socket NVRAM carrier)

5. Li-ion Battery Monitor & Fuel Gauge ICs (DS27xx)

DS2740 (low-power battery monitor)

DS2750 / DS2751 / DS2752 (single-cell fuel gauge)

DS2760 (high-precision Li-ion battery monitor with integrated sense resistor)

DS2770 / DS2771 (multi-cell battery protection IC)

DS2780 / DS2781 (standalone fuel gauge for battery packs)

6. High-Speed 8051 Compatible Flash Microcontrollers (DS80Cxx / DS89Cxx)

6.1 DS80C Series High-Speed 8051

DS80C310 / DS80C320 / DS80C323 (single-cycle high-speed 8051)

DS80C400 (networked 8051 with TCP/IP hardware)

6.2 DS89C Ultra-High-Speed Flash 8051

DS89C420, DS89C430, DS89C440, DS89C450 (16KB/32KB/64KB in-application programmable Flash)

7. Digital Potentiometer (Digitally Controlled Resistor) Series (DS180x / DS166x)

DS1802 (dual digital potentiometer)

DS1803 (8-channel digital potentiometer)

DS1804 (single-channel nonvolatile digital pot)

DS1669 (low-cost digital rheostat)

DS1689 (audio volume digital potentiometer)

8. Telecom T1/E1 Single Chip Transceivers (DS21xx Series)

DS2152, DS2154 (legacy T1/E1 transceivers)

DS21352, DS21354, DS21552, DS21554 (new generation 3.3V T1/E1 SCTs)

DS2188 (multi-port telecom line interface chip)

9. Watchdog Timer, Power Monitor & Reset ICs

DS1232 (microprocessor supervisor watchdog)

DS1830 (low-voltage power reset supervisor)

DS1705 (voltage detector with watchdog)

10. Miscellaneous Special Function ICs

DS21Q43 (line interface protection chip)

DS9097 / DS9097E (1-Wire USB adapter interface chip)

DS1420 (RS232 to 1-Wire bridge)

Supplementary Technical Notes

  1. Brand History
  2. Dallas Semiconductor was fully acquired by Maxim Integrated in 2001; Maxim was acquired by Analog Devices in 2021. All DS-series devices are still maintained by ADI/Maxim.
  3. Naming Suffix Rule
  4. Suffix letters indicate voltage (-3=3.3V, -5=5V), package (S=SOIC, Q=QFP, P=DIP), temperature grade (commercial / industrial), and built-in battery module (CR=integrated lithium battery).
  5. Scope Limitation
  6. This catalog only lists standard off-the-shelf commercial IC families. Custom mask ICs, evaluation boards, and adapter modules are excluded. Each base model has hundreds of complete ordering part numbers differentiated by memory size, pin count, package and temperature, which cannot be fully listed one by one.
  7. Core Technology Feature
  8. Dallas Semiconductor’s iconic proprietary technology is the 1-Wire® single-wire bus, which realizes power supply and bidirectional data communication through only one signal line plus ground.

General Questions About Microcontroller Firmware Extraction


  • Is it safe to send payment to MikaTech ?

    If MikaTech was a bad company, you could find tons of bad reputations about its service on the internet over the 28 years history

    So, the answer is YES! We are good people.

    Why choose Mikatech, please click here to find out


  • Can Mikatech break ics not listed on this site ?

    Different chip manufacturers have different part numbers, but the inner core of the chip can be make with same technology, it would be quite impossible to list all the part numbers where our technology can apply such as MYSON, STK, FEELING, ANALOG, FUJITSU, NOVATEK, LG/HYNDAI.

    Also by the advancing of the technology, everyday we gain more and more experience and develope new methods for reverse engineering for different Intergated Circuit parts. Full list of Integrated Circuit part numbers which is within our scope of capability is always getting bigger, please contact us to find out.

  • Will my privacy be protected ?

    Mikatech Innovative Limited understands the importance of its clients' privacy. At the moment you contact Mikatech, the personal information from you will be put under protection by our management regulations which was developed by our years of practice, Mikatech uses these information to customize its service to you, it will never disclose these information to third party out of any reason.
    Every project we did, we will delete all the data, materials, and codes 60days after deliverig the files, it iwll protect us and protect your privacy.

  • Is it legal to get service from Mikatech ?

    Yes, it is totally legal.
    Mikatech deliver its reverse engineering services for educational purposes only, it can be illegal to use above mentioned services in some coutries or regions, please check your local laws. Mikatech does not take any responsibility in relation to the use of above mentioned services that may be considered illegal.


  • Timing Attacks and the MCU Lockbit Lock

    Timing attacks exploit the variation in execution time of cryptographic or security-critical operations. The MCU lockbit lock often relies on password comparisons. If the comparison returns early upon a mismatch, the attacker can measure the time. This reveals the correct password byte by byte. The read-out of an EEPROM processor may be password-protected. The attacker can use timing to guess the password. Once guessed, they can dump flash and eeprom. Decapsulation and code recovery are not needed. Copy contents of crypto memory becomes possible. Microcontroller reverse engineering can then proceed. Firmware extraction is the final goal. The MCU lockbit lock is defeated by a simple timing side-channel. To prevent this, the comparison must be constant-time. It must take the same number of cycles regardless of the password. Many MCUs implement constant-time compare in hardware. The hardware compares all bytes simultaneously. This eliminates timing differences. However, other operations may have timing variations. For example, memory access times can depend on the address. If the attacker can cause cache misses, they can infer data. Some MCUs have instruction caches. The cache behavior leaks information. The MCU lockbit lock can be bypassed by exploiting cache timing. The attacker can monitor the execution time of a function. If the function accesses a secret table, the time reveals the index. This is a classic attack. The read-out of an EEPROM processor might be affected by cache. Dump flash and eeprom might have variable latency. The attacker can use that. To counter timing attacks, MCUs use deterministic memory access. They disable caches during security-sensitive operations. They also use random delays. The random delays add noise. But they do not eliminate the leak. The attacker can average out the noise. So constant-time is the only robust solution. The MCU lockbit lock should be implemented in hardware. Hardware does not have timing variations due to microarchitecture. It is deterministic. The lock decision should be a single combinatorial path. That path has fixed delay. The attacker cannot extract information. Additionally, the MCU can use blinding. Blinding randomizes the input. This makes timing attacks harder. For example, the password can be XORed with a random value. The comparison is done on the blinded values. The random value changes each attempt. The attacker cannot correlate time with password. The MCU lockbit lock also includes a maximum number of attempts. After a few failures, the lock permanently blocks. This prevents iterative timing attacks. The read-out of an EEPROM processor is then disabled. Dump flash and eeprom is disabled. Copy contents of crypto memory is disabled. Microcontroller reverse engineering is stopped. Firmware extraction is impossible. In conclusion, timing attacks are a subtle but effective method to break the MCU lockbit lock. Defenses include constant-time comparisons, cache management, random delays, blinding, and attempt limits. These ensure that read-out, dump, decapsulation, copy, reverse engineering, and extraction do not benefit from timing leakage.

    microcontroller_hack_time

    Years

    28 +
    microcontroller hack countries

    Countries

    110 +
    microcontroller attack clients

    Clients

    5000 +
    microcontroller projects unlocked

    Projects

    60000 +