Integrated circuit (IC) reverse engineering is the process of physically examining the circuit and its package to determine how it was built, without depending on a datasheet or the manufacturer's cooperation. The purpose is to answer questions such as which process node was actually used, how many metal layers the interconnect stack has, how the die area is partitioned among CPU, memory, and I/O, and – in the most detailed projects – what the underlying circuit netlist looks like.
The process can be used in competitive benchmarking to determine the exact process node, overall die size, and functional floorplan layout of a competitor's chip, or in intellectual property work to provide the physical manufacturing evidence needed to substantiate or defend against a patent infringement claim. Reverse engineering is also valuable in supply chain verification, where a suspicious sample can be checked against a genuine reference part, and in failure analysis to locate and characterize manufacturing defects directly at the die level.
Construction analysis vs. circuit analysis
Most IC reverse engineering projects start with construction analysis, which characterizes the physical structure of the package and die, including dimensions, materials, process geometry, and floorplan. If needed, circuit analysis can be performed as a follow-up to reconstruct the logic of the circuit by extracting a detailed schematic or netlist from delayered, layer-by-layer high-resolution imaging of the die. However, as this process is considerably more expensive and labor-intensive, the vast majority of competitive teardowns, patent litigations, and process-benchmarking studies use construction analysis only.
Analytical techniques for construction analysis
A typical construction analysis project moves from the outside in, using a defined sequence of techniques to study different levels of physical detail:
The process starts with a straightforward, non-destructive optical microscopy inspection of the package as received. The markings, dimensions, pin or ball count, and overall condition are visualized and recorded before the hardware is altered.
Non-destructive X-ray imaging is then used to examine the package without opening it, revealing the ball or lead array, internal wire bonds, die count and stacking, and gross defects such as voiding or misalignment. 2D X-ray provides an overall view, while 3D X-ray (computed tomography) resolves internal features at higher resolution and adds tilted views of substrate layers, bond-wire loop shape, and via structure.
Next, the package must be opened to physically access the die. This can be done by chemical decapsulation, which etches away the mold compound, or by mechanical decapsulation, which grinds or mills it away. Embedded cross-sectioning (ECS) is yet another alternative that mounts the whole package in resin and polishes it. This preserves the assembly stack, i.e., heatsink, thermal interface, solder balls, substrate, and die attach in a single cross-sectional view, yielding die thickness, substrate layer count, and bond-wire or bump dimensions.
Once the die is exposed, it is extracted and imaged from the front side using high-resolution optical microscopy, with individual fields of view stitched into a single composite image of the full die. This floorplan image is where die markings, die size, and the boundaries between major functional blocks first become visible, allowing the approximate silicon area allocated to each block (CPU, GPU, memory PHYs, and I/O) to be measured. It also forms the base layer that later cross-section and SEM work is registered against.
The silicon substrate is then thinned or removed from the backside to expose the transistor and shallow-trench-isolation (STI) level. The die is re-imaged with a scanning electron microscope (SEM) to study features below the resolution of visible light, including logic versus memory regions, individual memory array cells, and isolation structures. This forms the basis for capacity estimates on arrays such as embedded SRAM, where a measured unit-cell area is multiplied across the imaged array area.
Focused ion beam (FIB) milling is performed next to obtain a precise, site-specific cross-section through a chosen location on the die. This exposes the metal stack edge-on, layer by layer, and is the standard technique for measuring critical dimensions such as metal width, height and pitch, gate length, contact width, and fin pitch. The measurements are cross-referenced against known foundry design rules, allowing the process node to be determined even without vendor documentation.
In cases where FIB/SEM resolution is not sufficient to resolve the finest features in advanced-node interconnect and gate structures, a thin lamella is prepared and imaged by scanning transmission electron microscopy (STEM). STEM resolves individual fins, gate metal, source/drain contacts, and the lowest interconnect layers, and the most precise process-geometry figures in a report are typically derived from these images.
For compositional detail, energy-dispersive X-ray spectroscopy (EDX) is used to identify the elemental composition of a selected region, confirming materials such as mold compound filler, metallization alloys, interconnect barrier layers, and whether the top metal is copper or aluminum. Secondary ion mass spectrometry (SIMS) can also be used for depth-resolved dopant and junction profiling, showing how composition changes through the device rather than only at a single cross-section.
The final choice of techniques depends on the goals of the project; some steps can be left out if they are not necessary to obtain the required information.
Limitations of construction analysis
A construction analysis does not, on its own, tell you exact transistor counts, memory capacities, or per-block silicon areas, as these are extrapolated from measured unit cells and imaged areas rather than counted directly. Connectivity and logic function fall outside the scope entirely, as does behavior under load – these require circuit-level extraction or electrical characterization, which are different and generally more involved services.
It is also worth noting that processes like decapsulation, backside thinning, and cross-sectioning are destructive and consume the sample, which means that full construction analysis does not leave a working chip.
Reverse costing
Reverse costing takes the physical data produced by a construction analysis and converts it into an estimate of the component's manufacturing cost. The measured physical parameters, such as die size, process node, metal layer count, and package construction, are used to reconstruct the manufacturing process flow step by step. This information is combined with benchmarked cost data for each manufacturing step and fed into cost simulation tools to calculate the final cost for producing the IC. The resulting figure can be used as an anchor in sourcing negotiations, should-cost evaluations, and competitive cost benchmarking against the company's own production costs.
Reverse costing fees generally scale with process-node complexity. A component built on a leading-edge node below roughly 22 nm requires more detailed metrology to characterize than an older, larger-geometry process, and is quoted accordingly.
Our IC reverse engineering services
Measurlabs offers IC reverse engineering with flexible scoping, ranging from non-destructive package inspection to full construction analysis and reverse costing. Further electrical characterization techniques are also available for determining how the chip performs under load, and circuit analysis can be arranged in cases where the underlying operating logic of the circuit is of interest. Pricing is always itemized by technique, reflecting the actual scope of the project.
Suitable samples include:
Packaged integrated circuits (BGA, QFN, QFP, and similar)
Bare or desoldered die
Multi-die packages and system-in-package (SiP) modules
PCB assemblies, where the target IC is desoldered as part of the project
A full construction analysis typically takes around 30 days from the laboratory receiving the hardware, depending on package complexity and the techniques used. Sending two samples is recommended when both non-destructive and destructive analyses are needed, as decapsulation and cross-sectioning cannot be reversed.
For more information or a quote, contact our experts using the form below.

