ST series of ARM chips, there is a unique ID number encryption. Usually, we decrypt and soft encryption crack, is to remove the ID number encryption, but recently in the process of reverse development of the entire system for the guests, found a readable When the chip AT45DB041E was read and then burned, it found that it could not work usually. After careful investigation, it found that the chip and the main chip STM32F105 were bound to each other. After verification, AT45DB041E did have a globally unique ID number. This encryption method usually Used for boot detection; the main chip will not start when the check fails.

After understanding the whole encryption method, our engineers reverse-compiled the main control chip STM32F105, found the corresponding encryption code, skipped the FLASH verification directly, and finally wholly cloned.

