MCU reverse engineering

Microcontroller Unlock - MikaTech

Our values and goals

About MikaTech

Time went fast, from the day we did our first 8051 MCU reverse engineering project in 1998, to the day we set up our million dollar reverse engineering lab in 2012, 14 years went by. Now we start our new business of embedded visual system development, hope we can serve another 10 years.

sign Peter Lee Co-Founder & CEO

National Semiconductor Microcontroller Unlock

National Semiconductor was an American semiconductor manufacturer, that specialized in analog devices and subsystems, formerly headquartered in Santa Clara, California, USA. The products of National Semiconductor included power management circuits, display drivers, audio & operational amplifiers, communication interface products and data conversion solutions. National's key markets included wireless handsets, displays and a variety of broad electronics markets, including medical, automotive, industrial and test & measurement applications. On September 23, 2011, the company formally became part of Texas Instruments as the "Silicon Valley" division.

 

  • Mikatech National Semiconductor MCU reverse engineer list:
  • 1. Fuse-Based TTL PAL OTP Series

    20-Pin Combinatorial PALs

    PAL10H8, PAL10L8, PAL10P8

    PAL12H6, PAL12L6, PAL12P6

    PAL14H4, PAL14L4, PAL14P4

    PAL16C1

    PAL16H2, PAL16L2, PAL16P2

    PAL16H4, PAL16L4, PAL16P4

    PAL16H6, PAL16L6, PAL16P6

    PAL16H8, PAL16L8, PAL16P8

    20-Pin Registered Synchronous PALs

    PAL16R4, PAL16R6, PAL16R8

    PAL16RP4, PAL16RP6, PAL16RP8

    20-Pin XOR Enhanced PALs

    PAL16X4, PAL16X6, PAL16X8

    24-Pin Combinatorial PALs

    PAL18H4, PAL18L4, PAL18P4

    PAL20C1

    PAL20H2, PAL20L2, PAL20P2

    PAL20L8, PAL20S10

    PAL22V10 (Fuse-type variable macrocell PAL)

    24-Pin Registered PALs

    PAL20R4, PAL20R6, PAL20R8

    24-Pin XOR PALs

    PAL20X4, PAL20X6, PAL20X8

    Wide-Bus High-Density PALs

    PAL32R16, PAL32X16

    2. NSC E²CMOS GAL Electrically Reprogrammable PLD Series

    GAL16V8 20-Pin 8-Macrocell Universal PLD

    GAL16V8, GAL16V8A, GAL16V8B, GAL16V8D, GAL16V8NB

    GAL20V8 24-Pin 8-Macrocell Universal PLD

    GAL20V8, GAL20V8A, GAL20V8B

    GAL22V10 24-Pin Flagship 10 Variable-Term Macrocell PLD

    GAL22V10, GAL22V10B

    GAL18V10 20-Pin 10-Macrocell PLD

    GAL18V10

    GAL20RA10 Asynchronous Register Dedicated GAL

    GAL20RA10

    GAL26CV12 Low-Voltage 28-Pin High-Density GAL

    GAL26CV12

    GAL6001 E²CMOS Full Programmable Logic Array (FPLA)

    GAL6001

 

Founding

National Semiconductor[2] was founded in Danbury, Connecticut by Dr. Bernard J Rothlein on May 27, 1959, when he and seven colleagues, Edward N. Clarke, Joseph J. Gruber, Milton Schneider, Robert L. Hopkins, Robert L. Hoch, Richard N. Rau and Arthur V. Siefert, left their employment at the semiconductor division of Sperry Rand Corporation.
The founding of the new company was followed by Sperry Rand filing a lawsuit against National Semiconductor for patent infringement.[3] By 1965, as it was reaching the courts, the preliminaries of the lawsuit had caused the stock value of National to be depressed. The depressed stock values allowed Peter J Sprague[4] to invest heavily in the company with Sprague's family funds. Sprague also relied on further financial backing from a pair of west coast investment firms and a New York underwriter to take control as the Chairman of National Semiconductor. At that time Sprague was 27 years old. Jeffrey S Young characterised the era as the beginning of venture capitalism.[5]
That same year National Semiconductor acquired Molectro. Molectro was founded in 1962, in Santa Clara, California by J. Nall and D. Spittlehouse, who were formerly employed at Fairchild Camera and Instrument Corporation. The acquisition also brought to National Semiconductor two experts in linear semiconductor technologies, Dave Talbert and Robert Widlar, who were also formerly employed at Fairchild. The acquisition of Molectro provided National with the technology to launch itself in the fabrication and manufacture of monolithic integrated circuits.

In 1967, Sprague hired five top executives away from Fairchild, among whom were Charles E Sporck and Pierre Lamond. At the time of Sporck's hiring, Robert Noyce was defacto head of semiconductor operations at Fairchild and Sporck was his operations manager.
Charles E Sporck was appointed President and CEO of National. To make the deal better for Sporck's hiring and appointment for half his former salary at Fairchild, Sporck was alloted a substantial share of National's stock. In essence, Sporck took four of his personnel from Fairchild with him as well as three others from TI, Perkin-Elmer and Hewlett Packard to form a new eight man team at National Semiconductor.[5] Incidentally, Sporck had been Widlar's superior at Fairchild before Widlar left Fairchild to join Molectro due to a compensation dispute with Sporck.

In 1968, National shifted its headquarters from Danbury, Connecticut to Santa Clara, California. However, not unlike many companies, for legal and financial expediency, National retained its registration as a Delaware corporation.
Over the years they acquired several companies like Fairchild Semiconductor (in 1987), and Cyrix (in 1997). However, over time National Semiconductor spun off these acquisitions. Fairchild Semiconductor became a separate company again in 1997, the Cyrix microprocessors division was sold to VIA Technologies of Taiwan in 1999.
From 1997 to 2002, National enjoyed a large amount of publicity and awards with the development of the Cyrix Media Center, Cyrix WebPad, WebPad Metro and National Origami PDA concept devices created by National's Conceptual Products Group. Based largely on the success of the WebPad National formed the Information Appliance division (highly integrated processors & "internet gadgets") in 1998. The Information Appliance Division was sold to AMD in 2003.
Other business like digital wireless chipsets, image sensors, PC I/O chipsets have also been recently closed down or sold off as National has reincarnated itself as a high performance analog semiconductor company.

The transformation of National Semiconductor

The National Semiconductor 8250 UART chip, one of the most prolific and most cloned UART chips due to its presence in the first IBM Personal Computer.
Peter Sprague, Pierre Lamond and the affectionately called Charlie Sporck worked hand-in-hand, with support of the board of directors to transform the company into a multinational and world-class semiconductor concern. Immediately after becoming CEO, Sporck started an historic price war among semiconductor companies, which then trimmed the number of competitors in the field. Among the casualties to exit the semiconductor business were General Electric and Westinghouse.

Cost control, overhead reduction and a focus on profits implemented by Sporck was the key element to National surviving the price war and subsequently in 1981 becoming the first semiconductor company to reach the US$1 billion annual sales mark. However, the foundation that made National successful was its expertise in analogue electronics, TTL (transistor–transistor logic) and MOSFET (metal-oxide-semiconductor field-effect transistor) integrated circuit technologies. As they had while employed in Fairchild - Sporck and Lamond directed National Semiconductor towards the growing industrial and commercial markets and to rely less on military and aerospace contracts. Those decisions coupled with inflationary growth in use of computers provided the market for the expansion of National. Meanwhile, sources of funds associated with Sprague coupled with creative structuring of cash flow buffering due to Sporck and Lamond provided the financing required for that expansion. Lamond and Sporck had also managed to attract and extract substantial funds to finance the expansion.[10]
Among Sporck's cost control efforts was his attraction towards low-cost labour and outsourcing of labour. National Semiconductor was among the pioneers in the semiconductor industry to invest in facilities to perform final manufacturing operations of integrated circuits in developing countries, especially in Southeast Asia.

National Semiconductor's manufacturing improvements under Sporck (in collaboration with Lamond) had not been enabled by emphasis on process innovation but on improving and standardizing processes already established by other companies like Fairchild and Texas Instruments. As well as, by frequent raiding to hire from Fairchild's pool of talents.

General Questions About Microcontroller Firmware Extraction


  • Is it safe to send payment to MikaTech ?

    If MikaTech was a bad company, you could find tons of bad reputations about its service on the internet over the 28 years history

    So, the answer is YES! We are good people.

    Why choose Mikatech, please click here to find out


  • Can Mikatech break ics not listed on this site ?

    Different chip manufacturers have different part numbers, but the inner core of the chip can be make with same technology, it would be quite impossible to list all the part numbers where our technology can apply such as MYSON, STK, FEELING, ANALOG, FUJITSU, NOVATEK, LG/HYNDAI.

    Also by the advancing of the technology, everyday we gain more and more experience and develope new methods for reverse engineering for different Intergated Circuit parts. Full list of Integrated Circuit part numbers which is within our scope of capability is always getting bigger, please contact us to find out.

  • Will my privacy be protected ?

    Mikatech Innovative Limited understands the importance of its clients' privacy. At the moment you contact Mikatech, the personal information from you will be put under protection by our management regulations which was developed by our years of practice, Mikatech uses these information to customize its service to you, it will never disclose these information to third party out of any reason.
    Every project we did, we will delete all the data, materials, and codes 60days after deliverig the files, it iwll protect us and protect your privacy.

  • Is it legal to get service from Mikatech ?

    Yes, it is totally legal.
    Mikatech deliver its reverse engineering services for educational purposes only, it can be illegal to use above mentioned services in some coutries or regions, please check your local laws. Mikatech does not take any responsibility in relation to the use of above mentioned services that may be considered illegal.


  • Understanding and Bypassing Fuses and Lock Bits

    Microcontroller fuses and lock bits represent one of the oldest and most fundamental mechanisms for protecting firmware from unauthorized read-out. These one-time programmable elements control various aspects of device operation, including whether debug interfaces are enabled, whether flash memory can be read externally, and whether code execution is permitted from specific memory regions. The configuration of these fuses is typically performed during production programming, after which they are intended to remain immutable throughout the device's lifetime. Despite their widespread adoption, fuse-based protection mechanisms have proven vulnerable to a variety of attacks. The physical nature of fuses—typically implemented as polysilicon links or floating-gate transistors—means that they can be manipulated through both electrical and optical techniques. Researchers have demonstrated that UV light can erase flash-based security fuses in some microcontrollers, effectively resetting protection mechanisms without impacting the main code array. Similarly, focused ion beam (FIB) techniques can be used to physically alter fuse states on decapsulated chips, enabling attackers to unlock debug access or disable read-out protection. The relationship between fuses and lock bits adds another layer of complexity. In many microcontroller architectures, fuse bits must be configured before lock bits can be programmed, and once lock bits are set, the state of fuse bits cannot be changed. This sequencing creates a window of vulnerability during production programming where an attacker with appropriate access might intercept or modify the configuration. Moreover, some microcontrollers allow lock bits to be modified through software, creating potential attack vectors if the software responsible for managing these bits contains vulnerabilities. Modern microcontrollers have evolved beyond simple fuse-based protection to incorporate more sophisticated mechanisms such as eFuses and physically unclonable functions. eFuses, which are electronically programmable one-time memory elements, are used to store cryptographic keys, secure boot configuration, and debug access control settings. These elements are often read-protected at the hardware level, preventing software from accessing their contents. However, fault injection attacks have been demonstrated to bypass read protection for eFuse-stored keys, with researchers showing that repeated attacks and analysis can recover full key values. As microcontroller security continues to evolve, the interplay between fuses, lock bits, and other protection mechanisms will remain a critical area of research and development.

    microcontroller_hack_time

    Years

    28 +
    microcontroller hack countries

    Countries

    110 +
    microcontroller attack clients

    Clients

    5000 +
    microcontroller projects unlocked

    Projects

    60000 +