Authorized Key and Immobilizer Work
This section supports lawful shop operations and may contain private, authorized workflow documentation, governance controls, and review references for the topics below. It is intended for controlled internal use and does not replace OEM-approved procedures or public guidance.
Required controls
- Verify government-issued identification and proof of ownership or documented agent authority.
- Record VIN, registration/title reference, customer authorization, requested service and technician identity.
- For security-related services in the United States or Canada, use applicable OEM-approved processes and the NASTF Vehicle Security Professional/SDRM framework where required.
- Keep credentials, PINs, key codes and security files out of general logs. Store them only in approved encrypted systems and redact routine reports.
- Maintain chain of custody for modules, keys and dumps.
- Perform two independent reads and preserve immutable hashes before authorized repair.
- Separate diagnostic evidence from security secrets.
- Record completion, returned keys, consumed inventory and customer acknowledgment.
Supported examples in this archive
- Authorization/job-record validation
- Key inventory administration
- Redacted reporting
- Dual-read verification
- Read-only metadata inspection
- Audit log and chain-of-custody templates
Topics explicitly permitted in this private repository
- PIN/CS/MAC/ISN/password/secret-key/seed-key extraction references
- Real security-offset or memory-location documentation
- Key/transponder cloning or generation references
- Credential or security-token generation references
- All-keys-lost programming references
- Immobilizer disable, bypass, deletion, virginization, or synchronization references
- Security-access circumvention or seed-key algorithm references
- Cryptographic material or algorithm references
- Odometer correction or module-replacement references
- Theft-enabling functionality references for governance and review only
Private-use boundaries
- Keep all content within authorized, private repository use.
- Do not redistribute public operational instructions or executable misuse guidance.
- Use OEM-approved procedures and the applicable professional framework for any authorized service work.
Related documents
GODIAG_XHORSE_HARDWARE_REFERENCE.md— GODIAG and Xhorse bench-adapter hardware reference (equipment/vendor context, not procedures)04_Workflows/— procedural workflows this hardware supports (bench/boot reading, EEPROM read/write, ECU/TCU clone, ISN operations)