Vu Duo V3 security chip repair project.

Discussion in 'VuPlus Duo Hardware troubles and Repair support.' started by Johnny B., May 1, 2016.

  1. Johnny B.

    Johnny B. Technical Support Staff Member Moderator

    Messages:
    2,547
    Likes Received:
    1,316
    Trophy Points:
    113
    Gender:
    Male
    Location:
    Netherlands
    Home Page:
    I'm posting this information mainly for my own project.
    Trying to read out of the chip, and to write.

    The main objective is to repair faulty chips.
    Mainly the ones that are in a terminal program see the UPDF, and fails with UPDS which means that the security chip doesn't work, only the chip (UPDF) on-board works.

    This is because it is now difficult or no longer possible to buy these security chips, while the motherboard is still working.
    And so it is worth the effort to find a solution.

    Time being a starting project, maybe later hopefully followed by a good result.
    For now, these are my notes..

    security chip v3-duo.jpg

    --------------------------------------------------------------------------------------------
    Status..
    Not (yet) managed to get any data from the chip so I've bought another programmer and sockets for this chip.
    May takes weeks before it arrives, so this project is on hold.


    Some more experiments..
    Meanwhile did some testings to figure out what the security chip software needs to be able to upload it trough the rs232 port.
    If I only connect the Rx/Tx pins, and of-course the ground pin and vcc pin to the motherboard from the security chip.
    It works to upload the software trough the rs232 port with adapter.
    So, only trough these rx/tx ports it uploads the software, the Sda/Scl ports pins has another function.

    And so I came up with another idea, what if I connect two security chips to the motherboard, one that failed, and one that's good.
    Both with the Rx/Tx pins, and the ground/vcc on the motherboard.
    Normally the software refuses to upload with the faulty chip, now it uploads.
    However, although it uploads, and it goes slower than normal, it only upload it to the healthy chip.
    So, somehow it refuses to write also to the faulty chip, need to examine this further.


    Secure the chip for writing to it?.
    By this experiment I noticed that the motherboard only needs the Tx/Sda/Scl pins to get started.
    So basically the chip could be protected for writing to it, and so may never get corrupted after a image upload.
    At least, assuming that this happens trough the Rx pin, It could also happen trough the Sda/Scl pins.
    So it's not guarantee that it works, at least yet, but in any case I've tested it and the box works well without the Rx pin.
     

    Attached Files:

    Last edited: May 5, 2016
    toysoft likes this.
  2. Koevoet

    Koevoet New Member

    Messages:
    15
    Likes Received:
    5
    Trophy Points:
    3
    Gender:
    Male
    Location:
    England
    This is very interesting , I have one of these boxes that fails with UPDS and the rest of the board is functional , and as you say these security IC's are now hard to come by so a way of repairing them would be beneficial .

    I have only tested up to the point where i get the correct voltages at the base of the chip pins connecting to the board . I would be very interested to know how you would revive this chip and if ICP is possible.
    Could you tell me if you have ordered a specific board to connect to your mini pro programmer or are you using a different programmer all together ? I do have a TL866CS programmer so just need to know where and if a specific attachment board is available.

    Regards
     
    Johnny B. likes this.
  3. Johnny B.

    Johnny B. Technical Support Staff Member Moderator

    Messages:
    2,547
    Likes Received:
    1,316
    Trophy Points:
    113
    Gender:
    Male
    Location:
    Netherlands
    Home Page:
    Good questions..

    ICP, SCL/SDA reprogramming..
    To start with the TL866CS, the main problem is that it has no ICSP port on the back, and the TL866A has.
    However this can be added as you can read on the inet searching for, minipro tl866cs to tl866a
    You need to add the connector, and a update to the programmer.
    I've done it, and works, however because I had some doubts if it worked, I also bought the TL866A.
    But so far I have no reasons to think that rebuilding the TL866CS won't work correctly.

    But okay, this is to access the security chip with Scl/Sda and is only usable if we had the data file to reprogram it.
    Further I have a bit off doubts if these Vu box data is uploaded trough the Scl/Sda.
    Because it can also be done trough the Rx/Tx pins.
    In any case, these chips are locked for reading, and can only be reprogrammed.
    And to get the data from it will be hard to get, but there are guy's who claim that it can.

    Anyways as I told, without the data backup from a working chip it will be difficult to repair the chip, at least with Scl/Sda.

    With a LQFP48 Socket programming...
    This is for the V3 Syncmos chip, and need to be removed for programming.
    And I bought a LQFP48 TQFP48 QFP48 to DIP 7x7mm 0.5Pitch IC Socket Programming Adapter.

    This was another attempt to see if I could reach and read these chips, but it fails due the same reason.
    Reading the chip is locked, reprogramming is not a issue.
    Also, for the TL866 programmer I did not found a LQFP48 test socket, only one that is 48 pins, and this programmer has no 48p socket.
    So I bought a TOP3000 USB universal programmer which has these amount of pins, and support these chips.
    But despite the facts it works, I had the same problem... reading the chip is locked, reprogramming is not a issue.
    And I have also some doubts if this is the best solution to reprogram these chips.
    It's more work, than trough the Scl/Sda pins, or Rx/Tx.
    But okay, I only did it to see if I had the possibility to read these chips.

    Fixing trough the Rx/Tx pins...
    I did have some success with fixing it trough the Rx/Tx pins.
    For this, I have build a module to connect the security chip directly to the serial port.
    Basically, I have taken the Rs232 print from the Vubox, added some wires and a 5 to 3.3v fixed dc to dc ic.
    The main voltage input I use is the 5v, which is for the Rs232 module, the 3.3v is for the supply to the Security chip.
    So, +/- 5v to the Rs232 module, +/- 3.3v to the security chip.
    As for the Rx/tx pins to the security chip I've used on the rs232 board side the Receive/Transmit 1 output/input (R1 OUT/T1 IN),
    These goes to the security chip board the RXD0/TXD0.
    R1 OUT goes to TXD0 and T1 IN to RXD0
    This way I don't needed the adapter between the cable, or a vubox to program or test the chip.
    If you use the Bps 19200 you need to see in a terminal the UPDS output, then the chip works.

    For fixing the V3 chip, I've used the V3.2 upd_vu62k method.

    However, it's basically a same method as can be done on the normal way.
    But still, somehow it did not worked on the normal way, but did with this direct to the chip way.
    Not all chips succeeded, only a few, let say 3 out of 10.
    With the V2 chips I had more success, 6 out of 10.

    rs_sec_Snap1.jpg
    For a sort of schematic about this, see this picture.
    -------------------
    But I'm still waiting for some more tools to see if I can do more with it.
    Also from other security chips, as for the ST chips which are used in the Vu mini Solo/duo.
    As for the Syncmos chips, I still wait for some Syncmos tools, as the MSM9171 and MSM9066 ISP which works with the Syncmos smap software.

    But still, main problem is to get the data from these chips, so that it's possible to repair the one who failed.
    As for now, I only get 00 or FF which means that the chip is protected for reading.
     
    Koevoet likes this.
  4. Koevoet

    Koevoet New Member

    Messages:
    15
    Likes Received:
    5
    Trophy Points:
    3
    Gender:
    Male
    Location:
    England
    Ok lots to take in here ....

    So if with the converted TL866CS to TL866A you are saying it is possible to write to the chip ? would this be the vu_2ver_22m_130110_sec_isp file that gets written to the chip ? Using the normal rs232 coverter board and cable obviously does not allow me to load this specific file using TX/RX so if using the SCL/SDA lines with the TL programmer would this not in a way keep the chip functional or is Data on the chip already corrupted ?

    Excuse my ignorance but i am more used to programming different chips which seem to be a lot easier than this specific one.

    I see you have made significant progress on this particular project and hope you do manage to bypass the read protection which should be possible .

    Regards
     
  5. Johnny B.

    Johnny B. Technical Support Staff Member Moderator

    Messages:
    2,547
    Likes Received:
    1,316
    Trophy Points:
    113
    Gender:
    Male
    Location:
    Netherlands
    Home Page:
    No, unfortunately this bin file is not suitable for uploading via Scl / Sda.
    It does nothing good when you upload this.
    This is written for uploading via the Rx / Tx with the program renewaes.exe
    Maybe it can be rewritten to use it with sda/scl, but till now unknown.

    To upload with Scl / Sda you need a backup of a working chip, readed with sda/scl
    But, as mentioned earlier, this is not possible because the chip is protected against reading.
    If it's a secure chip, it will only give the 00 or FF.
    If you get data, then the chip is not protected to read, and ofcourse I would like to get the data file.

    But the chances are small because the basic settings to program the chip's, the security setting is on.
    But still, it's not imposable to have a security chip which is unprotected.
     
  6. Koevoet

    Koevoet New Member

    Messages:
    15
    Likes Received:
    5
    Trophy Points:
    3
    Gender:
    Male
    Location:
    England
    I have read the chip from a working box as well as the faulty one and i get the same as you all FF so they are definitely read protected :(( .

    I will keep on searching to see if there is a way apart from sending it to a specific place (break-ic) and hopefully you may also find something , i will keep on checking here to post any updates or to see if you have found a solution.

    Many thanks
     
  7. Koevoet

    Koevoet New Member

    Messages:
    15
    Likes Received:
    5
    Trophy Points:
    3
    Gender:
    Male
    Location:
    England
    Is it possible to get a working security board for the vu+ duo clone from somewhere as i now have one sitting here that wont work due to the security chip being faulty ?
     
  8. Johnny B.

    Johnny B. Technical Support Staff Member Moderator

    Messages:
    2,547
    Likes Received:
    1,316
    Trophy Points:
    113
    Gender:
    Male
    Location:
    Netherlands
    Home Page:
    Well, so I have several working motherboards as duo and solo that do not have a working chip, very frustrating.
    But no, unfortunately it is currently very difficult to get a v3 security chip.
    I did try to contact with China, possibly for the data file, but it is unfortunately not responded to.

    There was also a source (brandasat), which possibly still has a few in stock.
    But to date unclear whether they still have it.

    Therefore, I do many attempts to get the chip data.
    But to date, it is me not succeeded.
     
  9. Koevoet

    Koevoet New Member

    Messages:
    15
    Likes Received:
    5
    Trophy Points:
    3
    Gender:
    Male
    Location:
    England
    Thx for that , i have just contacted Syncmos as well and asked for some information , but i assume they too will not reply ...

    I had a look at that brandasat but seems on there they have nothing although i may try to eamil them just in case .
    If i hear anything i will let you know.

    regards
     
  10. Johnny B.

    Johnny B. Technical Support Staff Member Moderator

    Messages:
    2,547
    Likes Received:
    1,316
    Trophy Points:
    113
    Gender:
    Male
    Location:
    Netherlands
    Home Page:
    Status for this project..

    Although I have many devices to read/write/access the vubox syncmos (V3) SM59R16G6 or (V2) SM39R16A2 or Stm32 chip,
    still no luck to get the data from a good working security chip to fix the others. :(

    Without the help/information, I do not see it happen that this will succeed.
    In any case, the tricks which were given by email and or found on the internet have not helped.
    So till now, without proper input, no working output.

    But I also have my doubts whether it is possible, after all it is protected data.
    Not something a programmer might want to release.

    But just a pity for all owners who have a technically good working satellite receiver, which is useless if the security chip fails.
    In this case the satellite vu duo / solo (also mini) receivers of the (Chinese) market.

    One of my last attempt, in this case with the msm 9066 device...
    sm59r16g6-protected.jpg
     
  11. Koevoet

    Koevoet New Member

    Messages:
    15
    Likes Received:
    5
    Trophy Points:
    3
    Gender:
    Male
    Location:
    England
    Quick question , i removed the security chip and was messing about with the box and i uploaded an openpli image to the box and the box came back to life , everything seems to work apart from the tuner , now i assume it needs the security chip for this in order for the tuner drivers to work properly , but i cannot understand why this image loads and no other image will ... any ideas ??
     
  12. Johnny B.

    Johnny B. Technical Support Staff Member Moderator

    Messages:
    2,547
    Likes Received:
    1,316
    Trophy Points:
    113
    Gender:
    Male
    Location:
    Netherlands
    Home Page:
    Some image files as Openpli checks the security chip but skips it if it's not present or working, and so it booting up till it finished.
    However the tuners will not working, they always need the security chip code which probably has to do with the encoding/decoding or something.
    And other image files ends with the epc error when the security chip failed.

    Basically, I think that if they program the code into the image file, it doesn't need the security chip.
    But this is more a thought, actually more a dream. :)
     
  13. fingersd

    fingersd Member

    Messages:
    64
    Likes Received:
    9
    Trophy Points:
    8
    Gender:
    Male
    I´ve read and reread this topic several times and find it informative and interesting, in my case I have a pair of Mini VU Duo´s (I think using the ST chip mentioned above) that always fails to flash, although I have also found that some PLI images will load but always have "Tuner Fail" upon use.
    Would you know if there is a "V3.2 upd_vu62k" equivalent file for these boxes I could try?
    the boxes were supplied with a serial daughter board as with the V2 or V3 boxes so a serial flash may be possible.

    Thanks in advance, Dave.
     
  14. Johnny B.

    Johnny B. Technical Support Staff Member Moderator

    Messages:
    2,547
    Likes Received:
    1,316
    Trophy Points:
    113
    Gender:
    Male
    Location:
    Netherlands
    Home Page:
    Yeah openpli skips the security part if it's not working, which is handy for to test the receiver without a security chip or when it failed, but the tuners will not working due the missing decoding/encoding.

    And no, unfortunately I do not have a security chip update for the mini-duo and I doubt whether it is ever released.

    But it seems to me quite possible that the duo security chips updates may work on the mini box.
    This is because it works fine for me with a security chip from the duo / solo.
    But so also these security chips modules were sold with St and Syncmos chip.

    But it is possible with a cecurity chip update that it fails due the rs232 chip, these are often broken by static electricity when the RS232 plug is plugged while both devices has been turned on.
    These rs232 chip may work fine for reading, but can fail for writing.
    I always replace them if a security chip update failed, which often helps.

    But try one of the security chip updates from this zip file.
    it includes...

    VU DUO Update_Security_IC\Clean_Update_VuDuo_v2.x
    VU DUO Update_Security_IC\renewaes duo v2
    VU DUO Update_Security_IC\Security chip binary V3.0
    VU DUO Update_Security_IC\Security chip binary V3.0 beta
    VU DUO Update_Security_IC\Security chip binary V3.2
    VU DUO Update_Security_IC\V3.2 upd_vu62k
    VU DUO Update_Security_IC\VU DUO Update Fail solution
    VU DUO Update_Security_IC\VU+ Uno, Solo, Duo OEM V3.2 security IC update
     

    Attached Files:

  15. fingersd

    fingersd Member

    Messages:
    64
    Likes Received:
    9
    Trophy Points:
    8
    Gender:
    Male
    Thanks for this info, what you are saying does make sense, from memory one of the mini duo´s i have does output´s a lot of rubbish from the rs232 port along with some valid Data, which could well point to the serial chip.
    The mini duo unfortunately has the 232 ic on the mainboard not on a daughter board as in the full size duo.

    If i can identify the IC used I´ll pull out my hot air station and replace it (if available)

    Thanks again, Dave.
     
  16. Johnny B.

    Johnny B. Technical Support Staff Member Moderator

    Messages:
    2,547
    Likes Received:
    1,316
    Trophy Points:
    113
    Gender:
    Male
    Location:
    Netherlands
    Home Page:
    Hi,

    This rs232 ic is just a regular max3232 ic and is placed on the print side which can easily replace with a solder iron and desoldering wire.
    But can also easily replaced with hot air.

    And yes, they are often defective due the many attempt due the previous owner(s).
     
  17. fingersd

    fingersd Member

    Messages:
    64
    Likes Received:
    9
    Trophy Points:
    8
    Gender:
    Male
    P . S. I did try all of the update files on 4 boxes, 2 working but with no success, shame.

    I´ll definitely try swapping out the RS232 IC, thanks.

    Do you know if the DB9 pin assignment on the Mini Duo is the same as on the Ferrari as I´ve not got the genuine mini duo 232 daughter board but am using one from a V3 box

    Thanks
     
    Last edited: Aug 1, 2016
  18. Johnny B.

    Johnny B. Technical Support Staff Member Moderator

    Messages:
    2,547
    Likes Received:
    1,316
    Trophy Points:
    113
    Gender:
    Male
    Location:
    Netherlands
    Home Page:
    No they are not the same.
    As for the mini regular reading it is the same, but for the security chip it use the pin 1 and 6.
    The vu boxes use 4 and 6 on the rs232 connector box side
     
  19. fingersd

    fingersd Member

    Messages:
    64
    Likes Received:
    9
    Trophy Points:
    8
    Gender:
    Male
    Johnny B. Thanks for that info, I'll make a patch cable up and test again. Does this look correct or is transmit and receive reversed do you know Revised RS232 Security Chip Cable.jpg

    T I A.
     
  20. Johnny B.

    Johnny B. Technical Support Staff Member Moderator

    Messages:
    2,547
    Likes Received:
    1,316
    Trophy Points:
    113
    Gender:
    Male
    Location:
    Netherlands
    Home Page:
    Hi,

    This seems correct, as you show in your picture.