S5L8701 analysis

From freemyipod.org
Jump to: navigation, search
View of the bonding via X-ray
View of the top layer
View of the bottom layer

Contents

Introduction

The samsung S5L8701 is the SOC of the IN2G. This chip is supposed to be close to the 8700 used on some concurrent MP3 players.

We currently know nearly nothing about the differences of both chips, and the further evolutions. There is probably a small unencrypted boot ROM inside, which would be very useful for integrating user SW. Probably containing crypto information. Knowing the location of some JTAG pins could be very helpful.

There is an OpenOffice Calc document describing possible pinouts here. There is also tof's mailing list post.

Structure of the packaging

The chip is a 226-pin TFBGA with a pitch of 0.5mm. This is the structure of a BGA package: BGA package

The chip is glued to a small double side PCB substrate. the electrical current passes through:

The known datasheet shows die pad numbers that need to be correlated to ball numbers (the specified package has a different ball layout). In order to do this, we make an analysis of the bonding and PCB.

Packaging analysis

Following steps were made:

Guessed pinout table

the pinout is currently under study. See here for the actual status. This is not an easy part of the work, each pad has to be tested for connections all over the board (most IC's removed). See Nano2G HW analysis for further PCB analysis.

Personal tools
Namespaces
Variants
Actions
Navigation
Info
Software
Basic skills
Reverse engineering Results
Exploiting
Hardware
Toolbox