Chip Reverse Engineering Service

Chip reverse engineering is the process of reconstructing what a device actually does — its circuit topology, memory contents or logic structure — from the physical part rather than from documentation. It is used to support products whose manufacturer has stopped supplying technical data, to investigate counterfeit or re-marked components, to resolve IP disputes with technical evidence, and to recover designs that exist only as an assembled board.

We work from the package inwards: decapsulation, delayering, imaging, feature extraction and netlist reconstruction, with each stage documented so that the result is traceable rather than a black box.

What we extract

  • Die and layout imagery — whole-die mosaics plus region-of-interest captures at the resolution needed to read metal routing and identify standard cells
  • Gate-level netlist — logic structure extracted from delayered polysilicon and metal layers, delivered in a standard netlist format
  • Schematic reconstruction — block-level and transistor-level schematics for analog sections where a netlist alone is not meaningful
  • Memory contents — flash, EEPROM, ROM and fuse array read-out, where the array is accessible
  • Process and geometry data — feature size, metal stack, passivation and any anomalies that indicate a re-marked or cloned part

The stages, and why each one is documented

Stage What happens Deliverable
1. Package analysis Markings, X-ray and XRF check for re-marking or counterfeiting before any destructive step Screening note
2. Decapsulation Acid, laser or plasma opening planned around the analysis target Opened sample plus die images
3. Delayering Successive metal and oxide layers removed with controlled etch back Per-layer image set
4. Imaging and stitching Optical and SEM capture, mosaicked into a readable whole-die image Full-die and ROI imagery
5. Extraction Routes traced, cells identified, connections recorded Netlist and/or schematic
6. Verification Extracted structure cross-checked against observed behaviour or a reference sample Verification report

FPGA and programmable logic

For FPGA and CPLD devices we combine bitstream analysis with structural inspection of the configuration fabric. Where a configuration bitstream is available, we map it to the fabric resources it occupies; where it is protected, we work from the programmed device itself to determine the implemented function. This is frequently the fastest route to reproducing the behaviour of a legacy programmable part that is no longer stocked.

Typical engagements

  • Obsolete part replacement: reproduce a discontinued ASIC or custom IC so that an existing system can stay in service
  • Counterfeit investigation: determine whether a supplied component is the genuine die or a re-marked substitute
  • Design recovery: rebuild a schematic for a board or module whose original design data has been lost
  • Compatibility engineering: understand an interface device well enough to build a drop-in replacement

Frequently asked questions

How much of a large digital die can realistically be extracted?
Full extraction is practical for dies up to roughly 50,000 gates with a well-structured standard cell library, and for specific functional blocks of much larger dies. For a large SoC, the realistic approach is targeted: we extract the blocks you need — a bus controller, an analog front end, a custom peripheral — rather than attempting the entire device. We will tell you honestly which parts are achievable before starting.

Do you need a working reference device?
A functional reference makes verification far stronger and shortens the project. If you can supply two samples — one to destroy and one to keep working — we can compare extracted behaviour against observed behaviour. Where only a single sample exists, we plan the process to preserve as much of it as possible.

How long does a full chip reverse engineering project take?
A targeted block extraction on a small-to-medium die typically runs two to four weeks. A full-die netlist for a large device is a multi-month programme and is quoted per stage so you can stop at any point. We provide a written extraction plan with milestones before work begins.

Can you identify whether a chip is counterfeit without destroying it?
In many cases yes. Marking inspection, X-ray, XRF material analysis and electrical characterisation are all non-destructive and are enough to catch re-marking, re-packaging and die substitution. Destructive decapsulation is only needed when the non-destructive evidence is inconclusive or when you need die-level proof for a dispute.

Request an extraction plan

Tell us the part, the package, what you already know about it, and what you need to end up with — a netlist, a schematic, a functional reproduction, or evidence for a dispute. We will come back with a staged plan, a clear statement of what is achievable, and a per-stage quotation. Work is accepted only where the requester can demonstrate ownership or written authorisation.