How to get your box keys with a JTAG readerNotes
Semi-Complicated BoxKey retreival GuideConnecting the IRD Normally:
To Get the keys:
To Save the Flash:
NOTE: most IRDs have flash starting address and length as shown which is why they are defaults. Connecting the IRD to Erase/Program Flash:
NOTE: after powered up, you can remove the BRM0 to GND connection. To Erase Flash:
NOTE: Version 1.2or higher of jKeys assumes that the flash being programmed starts at 7ff80000 and has a size of 80000 bytes. It further assumes that the flash has a device ID of 2223 which is a 29F400T, and will recognize AMD(01) and Hynix(AD) manufacturers. CAUTION: If the flash device is not recognized you can override this by proceeding through the warnings, but please only do so if you ARE CERTAIN ABOUT WHAT YOU ARE DOING. Again, I'm not responsible for any damages To Program Flash:
NOTE: expects a binary file, will write the image to 7ff80000 regardless of what the file is or how long the file is. NOTE: During/After flash erase/program operations the IRD will not be responsive because, well, you changed the program So after doing so, ensure you power down the IRD (remove the power) and re-apply the power (plug it in) before doing further testing. |