Decrypting Intel 540s (SM2258G) SED - SA Modules Dumped
Posted: December 19th, 2025, 2:06
Hi everyone,
I am handling a data recovery case for an Intel 540s SSD with an SM2258G controller. The original controller was hardware-damaged, and I have moved the NAND to a donor board. The drive is currently in Technological Mode, but the data is encrypted due to the internal AES-256 SED locking.
I have used PC-3000 SSD to backup all critical SA Blocks/Modules. My dump includes the following key modules:
E7 (CP) - Control Program
E5 (SMI Index)
64, 66, 68 (L2P) - Translation Tables
Various Srv modules (6D, 7C, 7D, 74, 75, etc.)
My Questions:
1.Since the original controller's hardware KEK is inaccessible, is it possible to locate the MEK (Media Encryption Key) blob within these modules (specifically E7 or E5)?
2.Is there a known offset for Intel 540s firmware where the SED metadata or the encrypted MEK is stored?
3.In PC-3000 Data Extractor, is there a way to manually bypass or provide the MEK from these SA backups to build a sub-map with decryption?
4.I am willing to share specific module dumps (like E7 or E5) with experienced members for structural analysis.
Any guidance on how to proceed with the decryption of this Intel-specific SMI firmware would be greatly appreciated.
Thanks in advance!
SA Block dumps ----- https://dropmefiles.com/nzRQ8
I am handling a data recovery case for an Intel 540s SSD with an SM2258G controller. The original controller was hardware-damaged, and I have moved the NAND to a donor board. The drive is currently in Technological Mode, but the data is encrypted due to the internal AES-256 SED locking.
I have used PC-3000 SSD to backup all critical SA Blocks/Modules. My dump includes the following key modules:
E7 (CP) - Control Program
E5 (SMI Index)
64, 66, 68 (L2P) - Translation Tables
Various Srv modules (6D, 7C, 7D, 74, 75, etc.)
My Questions:
1.Since the original controller's hardware KEK is inaccessible, is it possible to locate the MEK (Media Encryption Key) blob within these modules (specifically E7 or E5)?
2.Is there a known offset for Intel 540s firmware where the SED metadata or the encrypted MEK is stored?
3.In PC-3000 Data Extractor, is there a way to manually bypass or provide the MEK from these SA backups to build a sub-map with decryption?
4.I am willing to share specific module dumps (like E7 or E5) with experienced members for structural analysis.
Any guidance on how to proceed with the decryption of this Intel-specific SMI firmware would be greatly appreciated.
Thanks in advance!
SA Block dumps ----- https://dropmefiles.com/nzRQ8