Can you reverse engineer an ASIC?

Posted by bschne 11 hours ago

Counter80Comment51OpenOriginal

Comments

Comment by supernetworks_ 18 minutes ago

I wrote a guide for newbies to learn

https://siliconzoo.org/tutorial.html

Comment by zoenolan 7 hours ago

I thought the article was going to be about how people scan chips

Rapid Chip Reverse Engineering Using Laser, Focused ion beams, and Scanning electron microscope https://academic.oup.com/mam/article/30/Supplement_1/ozae044...

FIBs are also used to test modifications before doing a respin. I'm still in awe that matter can be manipulated so precisely

Comment by zie1ony 8 hours ago

At my uni, 15 years ago, one postdoc reverse engineered NVIDIA chip and wrote more performant compiler. He did that by connecting oscyloscops to all chip's outputs and started with applying random current on inputs. Using ML and his genius he rediscoverd all opcodes including a few hidden ones. Eventually he got hired by some company that was doing a lot of GPU on supercomputers.

Comment by Aurornis 6 hours ago

> He did that by connecting oscyloscops to all chip's outputs and started with applying random current on inputs

This is absolutely not how reverse engineering a digital logic ASIC works.

Either the story got embellished through retellings, or this person was a fantasist.

There are people who hack on GPUs but it’s done at the software level.

I did get a kick out of imagining a scene where someone is trying to connect an oscilloscope to a circuit board to reverse engineer the CPU opcodes. That’s like the CSI: Miami version of what this would look like.

Comment by inigyou 8 hours ago

You can't do that by applying random inputs to any single-chip GPU - it has far too much state. I can see that perhaps it worked on some of the early multi-chip cards - where one chip was a texture sampler, and so on.

You'll have more luck reverse engineering the software driver first. They're not hidden, you can just open the driver files in Ghidra, the almost-universal tool for open-sourcing proprietary code. Hidden opcodes can be discovered first by just trying all the opcodes you couldn't discover any other way. You only need to go to the physical level if they're really hidden.

Comment by JSR_FDED 4 hours ago

Small pedantic nit: Open-sourcing is not the same as reverse-engineering.

Comment by sigbottle 8 hours ago

To be fair, Ghidra was released in 2019 and in general knowledge was still hard to find even back in 2010 I feel (well, compared to 2026 in the age of AI)

Comment by inigyou 7 hours ago

Before that there was, and still is, IDA Pro. Works largely the same but costs a lot, on the order of $1000/seat/year. Useless for hobbyists unless pirated, but reasonable if it's your job. Probably had academic discounts.

Comment by rzzzt 6 hours ago

Also a few free-but-cut-down versions like 5 (which still recognizes MS-DOS executables). I'm not going to recommend downloading it from any of the locations mentioned here but it's out there: https://reverseengineering.stackexchange.com/questions/19179...

Comment by tverbeure 7 hours ago

There is absolutely no way that happened. 15 years ago, we're talking Fermi class GPUs and chips with hundreds of millions of bits of on-chip state and much more if you include the DRAM.

You can't tease out the right information by applying random inputs. Which input would you even use? The PCIe interface? You'd first "randomly" need to get past its complex training sequences...

Your postdoc probably wrote micro-benchmarks of some sort. That is a common technique.

Comment by Taniwha 13 minutes ago

You might is they included DFT (design for test, stuff to make sure when you make a chip all of it actually works) - a scan chain thru all the internal flops will provide you with info about the internal flops and how they are connected - reverse engineering this into a model of reality would certainly be extremely hard, but maybe not impossible

Comment by kjs3 7 hours ago

And you don't use an o-scope in anycase, since you'd need...what...a thousand of them to watch all the signals. You'd use a logic analyzer. I think I read somewhere that those older nvidia chips had something like 2000 BGA balls, and Tektronix does make an LA that can scale to 2000-something channels (TLA7000), for a modest US$500k or so. Then you gotta figure how to mount the thing to attach the probes.

So...agreed...far more likely there was a software solution of some kind if this happened.

Comment by pixelatedindex 7 hours ago

“oscyloscops” is a way better spelling I gotta say.

Comment by Dwedit 5 hours ago

I've looked at Visual 6502 and it's way beyond me. I've even looked at the scans where it shows how they severed the connection to disable 6502 decimal mode on the NES.

Comment by monocasa 5 hours ago

To be fair, the 6502 is very dense, and very hand optimized.

Modern systems tend to use "standard cells" for logic which is a lot more digestible.

Comment by kayson 6 hours ago

Getting a logic-gate-level netlist from a GDS is trivial with industry standard chip design tools. Circuit designers do this every day. The hardest part will be reverse engineering the functionality.

I wish I had more time and I'd throw Calibre at it.

Comment by roadbuster 4 hours ago

Indeed, this is a problem for an energetic student who has free access to every tool in the Cadence, Synopsys, and Mentor portfolios: take the GDS-II layout, run it through extraction, generate a netlist, convert to higher-level blocks ("netlist-to-gate recovery"), translate to RTL HDL, then attempt to work out "what it does."

This is just a job posting in disguise for Jane Street: solve the puzzle, get a call from one of their recruiters.

Comment by Taniwha 5 hours ago

It's even easier in this case because they've included the original verilog source ....

Comment by mercurywells 5 hours ago

No, that's for the warmup. The real puzzle only has a .gds file available.

Comment by BobbyTables2 3 hours ago

Hasn’t Ken Shirriff been doing this for quite a while? (:->

Comment by kens 2 hours ago

I'm too busy trying to reverse-engineer the Intel 8087 floating-point chip, although it would be interesting to look at this puzzle chip.

Comment by marethyu 5 hours ago

What prerequisites I need to solve this puzzle? I don't have much knowledge in electrical engineering.

Comment by supernetworks_ 17 minutes ago

It’s hard without some basic knowledge maybe this can help https://siliconzoo.org/tutorial.html

Comment by whitten 9 hours ago

Is there something like an Extract-SPICE tool that takes a circuit and gives you back a text rendering of it ?

Comment by kayson 6 hours ago

Yes. There is exactly that, and we call it an "extraction" tool. It takes a GDS (text representation of shapes in the physical layout), and gives you back a "netlist" (text representation of components and connections in a circuit schematic).

Circuit designers use these tools basically daily for two reasons - the first is Layout Versus Schematic. We want to make sure that the physical layout matches the schematic, so the tool turns the layout GDS into a netlist and compares that to the netlist created from the schematic (basically a diff, but more complicated). The second is so we can run simulations that take into account the "parasitic" resistances and capacitances of the wires and metal shapes in the physical layout. It's basically the same procedure as LVS with an extra step that analyzes the metal shapes to determine said R's and C's.

Comment by Taniwha 5 hours ago

yes, but at the transistor level .... it has no idea at that level how those transistors are arranged into gates directly

Comment by kayson 4 hours ago

The tools can definitely recognize static logic gates purely from the topology (nothing special in the GDS needed). I don't know that I've tested it for anything more complicated, but as you've pointed out, if the hierarchy is in the GDS it's trivial to recover

Comment by Taniwha 5 hours ago

I take it back, it's a sky130 .gds the gates are explicitly in there

Comment by Taniwha 5 hours ago

In fact if you have the sky130 libraries installed (it's where I'm working) you can get a spice netlist out of it in about 10 seconds - really they should have flattened it

Comment by Joel_Mckay 8 hours ago

Practically No, the stack-up of metal layers often hides the gate structures underneath, and the billions of process cells may not all be the same.

Theoretically Yes, as an ion-beam-mill and electron-microscope combination machine can slice up semiconductors layer-by-layer. Given these machines can often also give precise x-ray analysis material data, the exact makeup of the chip can be extracted by competitors given enough time. =3

Comment by saltcured 8 hours ago

Now you're making me imagine some kind of 3D-scanning, confocal x-ray fluorescent spectroscope.

Or maybe some kind of hybrid of x-ray microtomography and spectroscopic analysis all in one.

But, maybe the energies involved would be about the same destructive power as some microtome slicing technique...

Comment by inigyou 7 hours ago

We already know that X-rays don't destroy chips.

Comment by saltcured 6 hours ago

I was thinking of the kind of high-energy photon sources that sprawl across a large laboratory campus behind rings of security fences.

These things can definitely erode the targets. Tomography experiments have to think carefully to optimize the set exposure angles used during a session, because the target degrades more with each shot.

Comment by bofadeez 7 hours ago

[flagged]

Comment by Joel_Mckay 6 hours ago

I’d recommend the Chenming-Hu books on solar cells and semis available as pdfs on his site.

https://www.chu.berkeley.edu/modern-semiconductor-devices-fo...

LLMs have already been shown to cause cognitive/skill performance losses in some users. =3

https://www.youtube.com/watch?v=axOcn--n_lM

Comment by inigyou 6 hours ago

You're replying to a probably now shadowbanned LLM bot that advertises Fable all day

Comment by bofadeez 4 hours ago

Are these "shadow bans" in the room with you right now? What a nut.

Fable needs no advertising. It was more important than the printing press. Code singularity.

But it's old news, Fable is no longer my favorite LLM. I mostly use Kimi k3 now. It's also more competent than you are in general.

The primary point you're avoiding is that programming is not a job for professional humans anymore. At least not humans with any dignity or self respect or economic value.

I'm sure you at least agree with this point, like every other reasonable person does now too.

Comment by perching_aix 5 hours ago

> LLMs have already been shown to cause cognitive/skill performance losses in some users. =3

Sorry to interrupt your smugness, but have you actually read that study? It's basically tautological: people remained mostly unfamiliar with code they did not write, and remained mostly unfamiliar with a library they did not use. That's kind of the whole point to begin with! https://homepages.inf.ed.ac.uk/rni/papers/realprg.html

Unless you want to argue that anyone who cannot code is brain damaged, I'd say it's a bit difficult to suggest that this would amount to any kind of clinically relevant cognitive impairment, much to the contrary of the masses desperately hoping and asserting so. Losing a skill you don't use / want / need is very normal cognitive function.

Comment by 4 hours ago

Comment by NooneAtAll3 9 hours ago

looks like they didn't post any blog post about 2nd NN challenge (https://huggingface.co/spaces/jane-street/droppedaneuralnet)

I was waiting for some writeup about permutation decyphering

Comment by mentat 7 hours ago

30 minutes with /goal for the solution from Sol w/ high.

Comment by arjie 2 hours ago

Man, these guys always have insane puzzles. What the heck.

Comment by q3k 8 hours ago

In a simplified scenario (not too far from this)? Yeah, we've done that in CTFs almost a decade ago.

https://blog.dragonsector.pl/2017/10/?m=1

Comment by inigyou 8 hours ago

From where do I know the name Dragon Sector and q3k? You aren't the ones who hacked the train DRM, are you? Or maybe active in the demo scene? Or maybe I'm just confusing you with TRSi?

Comment by q3k 8 hours ago

Maybe. :)

Comment by IshKebab 9 hours ago

That sounds like a fun challenge. Feels a lot more tractable than the neural net one.

Comment by ck2 9 hours ago

people who can do this stuff are super-smartypants

but reminds me how we're going to find out on an industrial level when the Saudis give China some nvidia chips they were grifted

they've cloned lots of chips before but nothing that advanced

Comment by Taniwha 5 hours ago

I'm a chip designer, back in the early 90s I visited a small silicon house who were doing some work for us, their boardroom table had been taken over by a giant sized photomicrograph of IBM's VGA chip and they had a bunch of summer hire grad students tracing wiring and matching standard cells (easier back then because we only worked in 2 layers of metal).

They weren't trying to steal IBM's design, they already had one of their own, what they wanted to know was "is there any as yet unannounced functionality in the IBM VGA chip?" they didn't want to be caught out when some unknown registers popped up. Of course it turned out there was as yet unannounced functionality - but not by IBM's design, more because of the orthogonality of the design - MODE-X was discovered and became the basis for DOOM's speed, anyone who didn't support it lost out

Comment by jsLavaGoat 5 hours ago

MODE-X launched 1,000 ships too with the demoscene.

Comment by JSR_FDED 4 hours ago

They did give the chips to China, but they didn’t work. Turns out they’d first taken them to the basement where someone cut them into pieces before sending them to China.

Comment by inigyou 7 hours ago

You can do this. If you commit the whole next month to it you'll make quite some progress. But you won't.

Comment by bofadeez 7 hours ago

[flagged]

Comment by inigyou 8 hours ago

China has no shortage of Nvidia chips. It costs nothing (relatively) for someone to just buy a 5090 off the shelf and send it there.

Comment by inigyou 8 hours ago

Is this the chip they used to steal money from the Indian stock market until they got banned from India?

Comment by 8 hours ago