Hardware

From freemyipod.org
Revision as of 23:27, 27 March 2009 by A W (talk | contribs)
Jump to: navigation, search

Although iPods have many other components, here we are only listing the components that might be relavent to cracking firmware encryption. If you have any suggestions for any other components to add, just post on the talk page or IRC. Links to datasheets are important if they can be found. For a visual hardware reference, visit the Hardware annotation page.

For information about the S5L8700 datasheet, see the S5L8700 datasheet page.

1G Nano

Component Details
CPU Portal Player PP5021C-TDF. This is the last Nano that used a PortalPlayer processor before Apple started using Samsung. If anybody knows of a datasheet for this, please add a link to it.
RAM Samsung K4M56163PG - A datasheet for this Mobile SDRAM chip can be found here.
Utility Flash SST39WF400A. This chip is documented very well as is a similar chip on the 2G Nano.

2G Nano

Component Details
CPU Samsung S5L8701 System On Chip (SoC), includes ARM940T(SAM44X?) central processor, advanced DSP, 50kb boot ROM, 256kb SRAM, external RAM, flash and LCD controllers, USB(1.1-host; 2.0-function) and some other parts. Package: 232-pin FBGA 10x10mm or 224/226-pin 9x9mm. Similar chips: SA58700X07. Some documentation available for the S5L series can be found here. The processor itself is Apple-branded and marked 337S3291 8701.
RAM Samsung K4M56163PG - here is the datasheet. This is the same chip used in the iPod 1G Nano. Sometimes the Qimonda HYE18L256 chip is used instead.
Utility Flash SST SST39WF800A,stores Disk Mode, Diagnostic Mode and the code to flash this chip. Tof has managed to extract this data and the dump can be obtained by emailing Emmanuel Fleury. All of the contents in the utility flash chip are encrypted from now on.
DSP Combination of Samsung 16-bit CalmRisc16 and Samsung 24-bit CalmMAC2424. Performance - up to 40MIPS (24x24 operation per cycle). During boot performs data verification and decryption.

3G Nano

Component Details
CPU Samsung S5L8701 ARM940T processor. The package itself is Apple-branded and marked 337S3473 8702.
RAM Like the flash chip, the memory also varies. The most popular chip seems to be the K4X56163PI. Another similar one that is sometimes used is the Qimonda HYE18M169CX75.
Utility Flash SST25VF080B. Like the other SST chips, this one is also extremely well documented.

4G Nano

Component Details
CPU Samsung S5L8701 ARM940T processor. It is definitely worth knowing that this is the exact same processor used in the iTouch 2G. This could mean that some of the same exploits for that could possibly be used. Here is a very interesting page about the S5L8720 processor.
RAM Integrated into the processor, similar to the iPod Touch and iPhone lines.
Utility Flash Possibly the chip on the lower part of the 4G board? See Hardware annotation.

Helpful pages

http://theiphonewiki.com/wiki/index.php?title=S5L8720_(Hardware)

http://www.ipodlinux.org/wiki/Generations (Be careful! This is extremely inaccurate.)

http://www.rockbox.org/twiki/bin/view/Main/SamsungSA58#SA58700_codename_Blues

1G Nano

http://www2.electronicproducts.com/Apple_iPod_nano-whatsinside-2.aspx

http://arstechnica.com/apple/reviews/2005/09/nano.ars/4

Image of the 1G Nano board

[1] - The pictures listed

2G Nano

http://home.gna.org/linux4nano/download/hardware_synth-1.0.pdf

http://www.ifixit.com/Guide/First-Look/iPod-Nano-2nd-Generation/592/1

http://arstechnica.com/apple/reviews/2006/09/ipod-2g.ars/4

3G Nano

http://www2.electronicproducts.com/Applie_iPod_Nano_(4GB)_3rd_Generation-whatsinside-16.aspx#

http://content.techrepublic.com.com/2346-13636_11-170826-1.html

http://www.ifixit.com/Guide/First-Look/iPod-Nano-3rd-Generation/594/1

http://insidetronics.blogspot.com/2007/09/teardown-ipod-nano-3g.html

Image of 3G Nano board

4G Nano

http://www.ifixit.com/Guide/First-Look/iPod-Nano-4th-Generation/584/1

Other (for comparison)

http://www2.electronicproducts.com/Apple_iPod_Touch-whatsinside-57.aspx

http://www2.electronicproducts.com/Apple_iPhone-whatsinside-4.aspx