Chip reverse engineering is the process of reconstructing what a device actually does — its circuit topology, memory contents or logic structure — from the physical part rather than from documentation. It is used to support products whose manufacturer has stopped supplying technical data, to investigate counterfeit or re-marked components, to resolve IP disputes with technical evidence, and to recover designs that exist only as an assembled board.
We work from the package inwards: decapsulation, delayering, imaging, feature extraction and netlist reconstruction, with each stage documented so that the result is traceable rather than a black box.
| Stage | What happens | Deliverable |
|---|---|---|
| 1. Package analysis | Markings, X-ray and XRF check for re-marking or counterfeiting before any destructive step | Screening note |
| 2. Decapsulation | Acid, laser or plasma opening planned around the analysis target | Opened sample plus die images |
| 3. Delayering | Successive metal and oxide layers removed with controlled etch back | Per-layer image set |
| 4. Imaging and stitching | Optical and SEM capture, mosaicked into a readable whole-die image | Full-die and ROI imagery |
| 5. Extraction | Routes traced, cells identified, connections recorded | Netlist and/or schematic |
| 6. Verification | Extracted structure cross-checked against observed behaviour or a reference sample | Verification report |
For FPGA and CPLD devices we combine bitstream analysis with structural inspection of the configuration fabric. Where a configuration bitstream is available, we map it to the fabric resources it occupies; where it is protected, we work from the programmed device itself to determine the implemented function. This is frequently the fastest route to reproducing the behaviour of a legacy programmable part that is no longer stocked.
How much of a large digital die can realistically be extracted?
Full extraction is practical for dies up to roughly 50,000 gates with a well-structured standard cell library, and for specific functional blocks of much larger dies. For a large SoC, the realistic approach is targeted: we extract the blocks you need — a bus controller, an analog front end, a custom peripheral — rather than attempting the entire device. We will tell you honestly which parts are achievable before starting.
Do you need a working reference device?
A functional reference makes verification far stronger and shortens the project. If you can supply two samples — one to destroy and one to keep working — we can compare extracted behaviour against observed behaviour. Where only a single sample exists, we plan the process to preserve as much of it as possible.
How long does a full chip reverse engineering project take?
A targeted block extraction on a small-to-medium die typically runs two to four weeks. A full-die netlist for a large device is a multi-month programme and is quoted per stage so you can stop at any point. We provide a written extraction plan with milestones before work begins.
Can you identify whether a chip is counterfeit without destroying it?
In many cases yes. Marking inspection, X-ray, XRF material analysis and electrical characterisation are all non-destructive and are enough to catch re-marking, re-packaging and die substitution. Destructive decapsulation is only needed when the non-destructive evidence is inconclusive or when you need die-level proof for a dispute.
Tell us the part, the package, what you already know about it, and what you need to end up with — a netlist, a schematic, a functional reproduction, or evidence for a dispute. We will come back with a staged plan, a clear statement of what is achievable, and a per-stage quotation. Work is accepted only where the requester can demonstrate ownership or written authorisation.