Skip to content

Chip-Off Acquisition

Definition

A physical extraction method in which the flash memory chip is desoldered from the device's circuit board and read directly with specialised hardware. Used when the device has no standard data interface and firmware-level access is blocked. Destructive to the device but preserves a raw image of the storage media.

Method type
Physical extraction
Process
Desolder flash memory chip, read directly with specialised hardware
When used
No standard data interface, or firmware-level access blocked
Effect on device
Destructive, but preserves a raw image of the storage media

Common questions

Why would an examiner choose chip-off over a logical or JTAG extraction?+

Chip-off is used as a last resort when the device is damaged, locked without a bypass, or lacks accessible test points for JTAG, since it bypasses the device's operating system entirely by reading the memory chip's raw contents directly.

What are the risks of chip-off acquisition for evidence integrity?+

The desoldering process can damage the chip through heat or static, potentially causing partial or total data loss, and the extracted raw data must still be correctly decoded and reassembled (accounting for wear-levelling and encryption) before it becomes readable evidence.

Can chip-off recover data from an encrypted device?+

The chip yields the raw stored bits, but if the device used full-disk or file-based encryption tied to a key stored elsewhere (such as a secure enclave), the extracted data remains unreadable without that key, so chip-off alone does not defeat strong encryption schemes.

Related terms

Bootloader
Firmware that runs immediately after power-on to verify, load, and hand control to the operating system. A locked bootloader refuses to execute...
Cloud Backend
The vendor-operated server infrastructure where IoT device data is stored, processed, and made accessible via companion apps. The cloud backend is often...
Companion App
The smartphone application that pairs with an IoT or wearable device, caches recent sensor data locally, and relays data to the cloud...
EDL Mode (Emergency Download Mode)
A Qualcomm diagnostic protocol embedded in the Primary Boot Loader (PBL) that activates before the main OS and accepts raw memory read...
eMMC (Embedded MultiMediaCard)
A flash storage standard that packages NAND memory chips and a controller into one soldered module using a parallel interface. Common in...
Faraday Enclosure
A shielded container or bag that blocks all radio-frequency signals including Wi-Fi, Bluetooth, cellular, and Z-Wave. Used at scene to prevent remote...
File-Based Encryption (FBE)
An Android encryption model introduced in Android 7.0 in which each file is encrypted with a separate key derived from the user...
Full-Disk Encryption (FDE)
A storage protection model in which the entire partition is encrypted with a key derived from the user's passcode and hardware-bound identifiers....
IoT (Internet of Things)
The category of networked physical objects embedded with sensors, processors, and communication modules that collect and transmit data without continuous human interaction....
ISP (In-System Programming)
A variant of direct chip access that connects to the eMMC command and data pins while the chip is still on the...
JTAG (Joint Test Action Group)
The industry group that produced IEEE standard 1149.1, which defines the test access port and boundary-scan architecture built into most modern integrated...
NAND Flash
The type of non-volatile memory used in all modern mobile device storage. Data is written to pages grouped into blocks; erasure operates...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.