MCU reverse engineering

Microcontroller Unlock - MikaTech

Our values and goals

About MikaTech

Time went fast, from the day we did our first 8051 MCU reverse engineering project in 1998, to the day we set up our million dollar reverse engineering lab in 2012, 14 years went by. Now we start our new business of embedded visual system development, hope we can serve another 10 years.

sign Peter Lee Co-Founder & CEO

Modern Microcontrollers Hack and Ways of Defenses

  • Modern microcontrollers are becoming increasingly powerful in processing speed, peripheral integration and energy efficiency. They now integrate more memory, communication interfaces and computing logic than the generations released a decade ago. Despite this rapid functional advancement, not enough attention is being paid to the hardware security against unauthorised access to the program and data stored in them. Most manufacturers prioritize performance and cost reduction over robust native security mechanisms in mainstream products. As a result, many embedded systems based on these microcontrollers could be compromised by both amateur hackers and professional security adversaries. Some commercial and industrial MCU-based devices have been already broken and publicly documented in security research reports. Once the internal firmware is leaked, product intellectual property faces irreversible loss. In this case, more and more embedded software developers have become interested in achieving a higher level of protection for their software and data against any unauthorised access. They aim to block reading, copying, tampering and reverse engineering of their proprietary code. In this respect, all microcontrollers intended to be used in valuable applications should be carefully selected and thoroughly tested before formal deployment. Security engineers must verify lock mechanisms, memory protection boundaries and authentication reliability during pre-production evaluation. This paper discusses common security protection schemes implemented in many mainstream microcontrollers. It identifies critical weaknesses found across various hardware security implementations from different chip vendors. It also analyzes why legacy protection methods fail against modern low-cost attack tools. Finally, the paper proposes practical ideas about possible defense technologies to mitigate existing security vulnerabilities effectively.

  • Microcontrollers are widely adopted in modern equipment and intelligent electronic devices across all industrial and consumer fields. They are everywhere around us — from household washing machines and smart TV sets to portable mobile phones and desktop computers. Each category of electronic products relies on MCUs to manage logic control and data interaction. Some microcontrollers are used by electronics amateurs to build small experimental devices purely for learning and entertainment purposes. These hobbyist projects usually involve simple sensors, LED indicators and motor control modules. Others are used by small companies in industrial control units, precision measurement instruments and automated testing equipment. These commercial MCUs require basic anti-copy protection to protect corporate algorithms. A large number of high-grade microcontrollers are deployed for serious confidential applications by security services, global banking institutions and professional medical services etc. These high-risk scenarios demand the highest level of on-chip data isolation and anti-tampering capability. Each microcontroller executes the specific algorithm or user program that is permanently uploaded into its internal non-volatile memory. The execution flow is strictly determined by the machine instructions stored in program flash memory. Programs for embedded systems are usually written in Assembly or C programming languages due to their high execution efficiency and low memory overhead. High-level languages such as Basic or Java are rarely used in traditional MCU firmware development. They only appear in a small number of high-performance embedded platforms with additional memory resources. Usually the program is stored inside the chip in binary machine codes after compilation and linking. Therefore, all source code must be fully compiled before uploading and flashing into the chip memory. There are many professional development software suites tailored for each family of microcontrollers on the market. These tools include integrated development environments, compilers, debuggers and firmware flashing utilities. Complete hardware development kits are also provided by both the original chip manufacturers and qualified third-party technology suppliers. These kits help engineers accelerate prototype verification and mass production development.

  • This paper will follow a clear logical structure to discuss MCU security issues in depth. I will start with a brief introduction to the classification and working principles of common attack technologies in embedded security. It will also provide a comprehensive overview of microcontrollers available on the current global market. This overview evaluates devices from the perspective of underlying semiconductor manufacturing technology and native hardware features of microcontrollers. After the foundational background, I will systematically explain different classes of hardware and software attack technologies targeting MCUs. I will further discuss how easily each type of attack can be practically applied to different chip architectures and vendor platforms. In the next core part of the paper, I will introduce many real-world examples of commercial microcontroller chips. Each case will include detailed explanations of its native hardware security implementation structure. I will also summarize the obvious advantages and inherent disadvantages of each integrated security scheme objectively. The last chapter will describe feasible and low-cost ways of increasing security protection levels for already existing microcontrollers currently in use. It will also provide targeted professional suggestions for future silicon hardware design purely from the security research point of view. The ultimate goal is to help the next generation of embedded devices achieve stronger resistance against invasive attacks.

General Questions About Microcontroller Firmware Extraction


  • Is it safe to send payment to MikaTech ?

    If MikaTech was a bad company, you could find tons of bad reputations about its service on the internet over the 28 years history

    So, the answer is YES! We are good people.

    Why choose Mikatech, please click here to find out


  • Can Mikatech break ics not listed on this site ?

    Different chip manufacturers have different part numbers, but the inner core of the chip can be make with same technology, it would be quite impossible to list all the part numbers where our technology can apply such as MYSON, STK, FEELING, ANALOG, FUJITSU, NOVATEK, LG/HYNDAI.

    Also by the advancing of the technology, everyday we gain more and more experience and develope new methods for reverse engineering for different Intergated Circuit parts. Full list of Integrated Circuit part numbers which is within our scope of capability is always getting bigger, please contact us to find out.

  • Will my privacy be protected ?

    Mikatech Innovative Limited understands the importance of its clients' privacy. At the moment you contact Mikatech, the personal information from you will be put under protection by our management regulations which was developed by our years of practice, Mikatech uses these information to customize its service to you, it will never disclose these information to third party out of any reason.
    Every project we did, we will delete all the data, materials, and codes 60days after deliverig the files, it iwll protect us and protect your privacy.

  • Is it legal to get service from Mikatech ?

    Yes, it is totally legal.
    Mikatech deliver its reverse engineering services for educational purposes only, it can be illegal to use above mentioned services in some coutries or regions, please check your local laws. Mikatech does not take any responsibility in relation to the use of above mentioned services that may be considered illegal.


  • I sent you an email, why there is no answer ?

    • A. Our mail server is temperally broke down, your message has not been delivered to our mailbox even the mail sent successfully message is showed on the screen, please contact us again.
    • B. Our email is recognised as junk mail email by your mail server, so our reply has been rejected by your mail server or it is diverted to your junk mailbox, please remove our account from junkmail list or check your junk mailbox, or use another email account to contact such as gmail.
    • C. Your email is recognised as junk mail email by our mail server, so your email was put to our junk mailbox, please use another email account to contact us again.

    microcontroller_hack_time

    Years

    28 +
    microcontroller hack countries

    Countries

    110 +
    microcontroller attack clients

    Clients

    5000 +
    microcontroller projects unlocked

    Projects

    60000 +