in the mean time i'll download the software and get a feel of the software and how it functions.vtl wrote: ↑16 Jun 2023, 14:32The ones with the board.oscilloscope wrote: ↑16 Jun 2023, 14:29 did you use any of the multi-com.pl break out boards & connectors or just the general wiring harness which i am assuming comes with the device?
Vida CEM swapping
-
oscilloscope
- Posts: 285
- Joined: 20 May 2022
- Year and Model: 2005
- Location: uk
- Has thanked: 27 times
- Been thanked: 11 times
Re: Vida CEM swapping
-
oscilloscope
- Posts: 285
- Joined: 20 May 2022
- Year and Model: 2005
- Location: uk
- Has thanked: 27 times
- Been thanked: 11 times
Did you analyse the CAN lines only. or did you go straight too the cem microcontroller via jtag or direct pin connection. And analyse the data coming in and out ?vtl wrote: ↑16 Jun 2023, 14:32The ones with the board.oscilloscope wrote: ↑16 Jun 2023, 14:29 did you use any of the multi-com.pl break out boards & connectors or just the general wiring harness which i am assuming comes with the device?
-
vtl
- Posts: 4724
- Joined: 16 August 2012
- Year and Model: 2005 XC70
- Location: Boston
- Has thanked: 114 times
- Been thanked: 604 times
I first didn't know what pin is it. I read in Renesas datasheet about flash pin protection, so the first attempt was to crack the chip over serial line by soldering wires to PCB and forcing the chip into boot mode. I looked at the response latency with logic analyzer to confirm the theory that it differs for good/bad bytes. That attempt fail, because in Volvo Renesas is unprotected. Then T5Luke contacted me, he knew lot more on that topic, and in about month or two of brain storming and hard working we got it rolling over CAN.oscilloscope wrote: ↑17 Jun 2023, 07:51 Did you analyse the CAN lines only. or did you go straight too the cem microcontroller via jtag or direct pin connection. And analyse the data coming in and out ?
DSLogic can see these latencies at a very high speed, because it captures the signals in FPGA. I'd say, it can peek at any signal in that car era electronics without problem. Cheap Saleae knock off has a lot of jitter and is not very fast to begin with.
-
oscilloscope
- Posts: 285
- Joined: 20 May 2022
- Year and Model: 2005
- Location: uk
- Has thanked: 27 times
- Been thanked: 11 times
That's good to info to know, I have a theory that if I where to probe the CAN lines and then perform a test synchronisation on a test ecu and cem and see what happens. I'll assume that i could analyse the CAN data packets to see what section is adjusted. , currently a theory in practice it may give me a load of data which will unintelligible.vtl wrote: ↑17 Jun 2023, 08:12I first didn't know what pin is it. I read in Renesas datasheet about flash pin protection, so the first attempt was to crack the chip over serial line by soldering wires to PCB and forcing the chip into boot mode. I looked at the response latency with logic analyzer to confirm the theory that it differs for good/bad bytes. That attempt fail, because in Volvo Renesas is unprotected. Then T5Luke contacted me, he knew lot more on that topic, and in about month or two of brain storming and hard working we got it rolling over CAN.oscilloscope wrote: ↑17 Jun 2023, 07:51 Did you analyse the CAN lines only. or did you go straight too the cem microcontroller via jtag or direct pin connection. And analyse the data coming in and out ?
DSLogic can see these latencies at a very high speed, because it captures the signals in FPGA. I'd say, it can peek at any signal in that car era electronics without problem. Cheap Saleae knock off has a lot of jitter and is not very fast to begin with.
-
oscilloscope
- Posts: 285
- Joined: 20 May 2022
- Year and Model: 2005
- Location: uk
- Has thanked: 27 times
- Been thanked: 11 times
I'm not too familiar with the dslogic analyser , I have most of the data sheets for pretty much all of the mcu versions , so 1k79X , 1M14E, 1k78k , OL01Y, the list continues , i have some help from a developer who is much more clued up on oreans obfuscating. Then me , and knows much better around reverse engineering tools such as m32 and ghidra , I have other the name escapes me currently.
I am curious to know what the code card developer did on the synchro software for the sid807evo with the p2 cem. , as from what I can tell the process changed after that application, SMOk provides synchro via can bus , to newer versions of the ecu and cem combinations. Which is interesting. I did read somewhere that the security changed on the later ones that smok can do , but that is of course not confirmed.
it does make me wonder whatever did happen to the original developer of the software , i had been informed by codecard the developer does not work there anymore.
-
oscilloscope
- Posts: 285
- Joined: 20 May 2022
- Year and Model: 2005
- Location: uk
- Has thanked: 27 times
- Been thanked: 11 times
if some of you are not aware this is an example of what the sync software does , sorry for the quality but here we go!
left hex dump is the damaged dump file , the left is the repaired dump file , i have highlighted the ABS ID showing where it is badly I might add , the information is then placed inside the ECU eeprom , as that is what's losses the info. , too keep track of the ecu versions and cem versions ,i label them the cem version , in this example this is from a sid803a and a cem which a 1L15Y MASK. ok its not the sid807evo but it could give an idea to folks.
left hex dump is the damaged dump file , the left is the repaired dump file , i have highlighted the ABS ID showing where it is badly I might add , the information is then placed inside the ECU eeprom , as that is what's losses the info. , too keep track of the ecu versions and cem versions ,i label them the cem version , in this example this is from a sid803a and a cem which a 1L15Y MASK. ok its not the sid807evo but it could give an idea to folks.
-
oscilloscope
- Posts: 285
- Joined: 20 May 2022
- Year and Model: 2005
- Location: uk
- Has thanked: 27 times
- Been thanked: 11 times
Analyser has arrived.
I have some test cem & ecu which I can plug into and see what i can do
I have some test cem & ecu which I can plug into and see what i can do
-
oscilloscope
- Posts: 285
- Joined: 20 May 2022
- Year and Model: 2005
- Location: uk
- Has thanked: 27 times
- Been thanked: 11 times
I'm going to concentrate my efforts on the sid807evo with the p3 white cem this ecu kit I already have , it's from a v40 , there in them from 2011 onwards, this one has push button start. I have purchased a body loom and will buying an engine loom. To make life simple , I'll be removing wiring so I can use the bare minimum to do the process , this is mainly the test mule for now
-
- Similar Topics
- Replies
- Views
- Last post
-
- 1 Replies
- 6431 Views
-
Last post by RickHaleParker
-
- 5 Replies
- 8699 Views
-
Last post by forumoto






