Skip to content

Memory Extraction

JTAG-Based Memory Extraction is a critical technique for analyzing embedded systems, enabling the retrieval of firmware, configuration data, and volatile memory contents. This process leverages the Joint Test Action Group (JTAG) interface to access internal memory regions, often bypassing traditional security mechanisms. Below are methods, tools, and workflows for performing JTAG-based memory extraction.


Tools and Toolchains

1. OpenOCD (Open On-Chip Debugger)

A versatile open-source toolchain for JTAG communication. It supports scripting and can interface with hardware debuggers like the J-Link, ST-Link, or Bus Pirate.

Example: Basic Memory Dump via OpenOCD

# Initialize OpenOCD with a configuration file (e.g., interface.cfg and target.cfg)
openocd -f interface/jlink.cfg -f target/your_device.cfg

# In a separate terminal, use telnet to interact with OpenOCD
telnet localhost 4444
Once connected, use commands like:
mdw 0x20000000 0x1000  # Dump 4KB from address 0x20000000 (RAM)
mrd 0x08000000 0x1000  # Read 4KB from flash memory

2. Custom Scripts and Hardware

For advanced use cases, scripts (Python, C) can automate memory dumping via JTAG. Tools like ChipWhisperer or Bus Pirate may be used for low-level access.


Techniques for Memory Extraction

1. Firmware Extraction from Flash

Flash memory (e.g., NOR/NAND) often contains the device's firmware. Use JTAG to read raw binary data and convert it to a usable format.

Example: Extracting Firmware

# Use OpenOCD to read flash memory
mrd 0x08000000 0x40000 > firmware.bin  # Dump 1MB from flash
Post-processing with tools like binwalk or firmware-analysis scripts can extract embedded files.

2. Volatile Memory (RAM) Capture

RAM dumps capture transient data, such as runtime variables or encryption keys. This requires stopping the device's execution and reading memory contents.

Example: RAM Dump with OpenOCD

# Halt the target
shutdown

# Read RAM contents
mdw 0x20000000 0x10000 > ram_dump.bin  # 64KB dump from SRAM

3. Bypassing JTAG Security

Some devices implement JTAG authentication or memory protection. Techniques include: - Brute-force JTAG-TAP authentication (e.g., using jtagkey tools). - Exploiting known vulnerabilities (e.g., JTAG over UART bypasses). - Physical tampering (e.g., desoldering JTAG pins to access the interface).


Post-Processing and Analysis

  1. Hex File Conversion Convert raw memory dumps to .hex files for analysis:

    objcopy --input-target binary firmware.bin firmware.hex
    

  2. Firmware Analysis Use tools like IDA Pro, Ghidra, or Binwalk to dissect firmware:

    binwalk firmware.bin
    

  3. Decryption and Obfuscation If firmware is encrypted, use cryptographic tools (e.g., pycryptodome) or reverse-engineer the encryption algorithm.


Challenges and Considerations

  • Device-Specific Memory Maps: Memory addresses vary by hardware. Use datasheets or JTAG scripts to identify regions.
  • Power and Timing Constraints: JTAG operations may require precise timing or stable power to avoid corruption.
  • Legal and Ethical Risks: Ensure compliance with laws and terms of service when extracting data from devices.

Key takeaways

  • Use OpenOCD for scripting JTAG memory reads and interacting with hardware debuggers.
  • Differentiate between flash and RAM dumps, as they require distinct approaches.
  • Post-processing is critical—tools like Binwalk and IDA Pro help analyze extracted data.
  • Bypassing JTAG security often requires device-specific knowledge and may involve physical tampering.
  • Always verify legal permissions before performing memory extraction on any device.