Home
Technics KN5000. Photo: Sound On Sound (March 1998)
Technics Keyboards — Reverse Engineering & Preservation
Welcome to the technical documentation for the reverse engineering and digital preservation of Technics musical keyboards. Our long-term goal is to preserve the history of these instruments — their internal architecture, firmware, and protocols — as the physical hardware becomes scarce.
A Digital Archaeology Project
This project preserves technical knowledge of Technics keyboards through detailed reverse engineering. As physical hardware becomes scarce, accurate documentation ensures these instruments remain accessible for emulation, repair, and homebrew development.
The Instruments
| Instrument | Year | Main CPU | Documentation |
|---|---|---|---|
| Technics SX-WSA1 | 1995 | Toshiba TLCS-900 (TMP95C061 ×2) | New — the 61-key synthesizer; the images are a redistributed set and running them in both variants rests on the uploader’s testimony. No service manual exists anywhere, so its panel rests on the ROM alone |
| Technics SX-WSA1R | 1995 | Toshiba TLCS-900 (TMP95C061 ×2) | New — a synthesizer module, not an arranger: rack-mount “acoustic modelling”. Firmware images are second-hand, not our dumps; all four EPROM images rebuild byte-identically from source with no verbatim blobs; MAME driver reaches a UI, no sound |
| Technics SX-KN1500 | 1996 | Toshiba TLCS-900 (TMP95C061) | New — the KN5000’s CPU lineage; program ROM unvalidated (BAD_DUMP, needs redump) but its LCD-panel SVG is preserved as a ROM asset; MAME skeleton |
| Technics SX-KN5000 | 1997 | Toshiba TLCS-900/H2 (TMP94C241F) | Extensive — nine ROM images rebuild byte-identically from source, MAME driver, homebrew SDK |
| Technics SX-KN2400 / KN2600 | 1998–2000 | Panasonic MN10300 | New — drivers built; the KN7000’s closest sibling (one firmware serves KN2400/KN2600/PR54) |
| Technics SX-KN6000 | 2000 | Panasonic MN10300 | New — firmware extracted, hardware mapped from the service manual; ~85% code shared with KN7000 |
| Technics SX-KN6500 | 2001 | Panasonic MN10300 (MN103002A) | New — firmware extracted, hardware mapped from the service manual |
| Technics SX-KN7000 | 2002 | Panasonic MN10300/AM33 | Early research — update-disk extraction and firmware analysis underway |
These instruments span two CPU architectures — the earlier TLCS-900 group
(SX-WSA1/WSA1R, KN1500, KN5000) and the MN10300 family (KN2400, KN2600, KN6000,
KN6500, KN7000) — yet all descend from a single evolving source codebase: the same
update-disk container format (.SLD/LZSS), the same MILK UI-framework symbol conventions,
resource tables and message text recur across the arrangers (the KN6000 shares ~85 % of its
strings with the KN7000).
The SX-WSA1 pair is the odd one out, and the most informative. It is a synthesizer, not an arranger — its specification page has no rhythm, style or auto-accompaniment row at all — and it predates the MILK framework entirely. What it shares with the KN5000 instead is its CPU family, its RTOS, its panel driver and 32,795 bytes of literal machine code (against a measured null of zero). See the Shared Codebase Map and the cross-version diff guidebook for the comparison across the family.
Project Goals
| Goal | Description |
|---|---|
| ROM Reconstruction | Create buildable source code that produces byte-identical ROMs |
| MAME Emulation | Full system emulation in the MAME framework |
| Homebrew Development | Enable custom software development for the hardware |
| Compiler Development | LLVM backend for TLCS-900/H2, enabling C/C++ development |
Technics KN7000
The Technics SX-KN7000 (2002) is the successor to the KN5000. Research here is at an early stage, focused so far on extracting and understanding its system-update disks and firmware images.
| Page | Description |
|---|---|
| KN7000 Overview | Hardware summary, MN10300 CPU, memory map, project status |
| KN7000 System Update Discs | .SLD container format, LZSS decompression, .INF checksums, extraction tool |
| KN7000 Firmware Images | Program & table flash layout, version numbers, string/hardware inventory, byte-exact disassembly project |
| KN7000 Image Gallery | 169 images extracted from the firmware (demo slideshows, product photos, digital-drawbar UI graphics) |
| Techni-chord (auto-harmony) | Proof that the auto-harmony feature is pure firmware, not a tone-generator capability |
| Effects DSP Algorithm Catalog | Every ADSP-21065L program identified — kernel, 72 effect algorithms, GUI names as ROM fact |
| Panel Design Language | The control panel as a kit of injection-moulded parts — the design system behind the layout artwork |
| Shared Codebase Map | Cross-model code/data reuse between KN5000 and KN7000 |
| Roadmap (vs KN5000) | What was done for the KN5000 and how each piece maps onto the KN7000 |
Technics KN5000
The Technics SX-KN5000 (1997) is the most thoroughly documented instrument on this site: a 1997-era professional arranger keyboard whose firmware, protocols and hardware have been reverse engineered in depth.
New to the KN5000? Begin with the System Overview to understand how all the components work together.
KN5000 Documentation by Topic
Hardware & Memory
| Page | Description |
|---|---|
| System Overview | Architecture diagram and subsystem guide |
| Hardware Architecture | Physical components from service manual |
| CPU Subsystem | TMP94C241F dual-CPU design |
| Memory Map | Complete address space layout |
Subsystems
| Page | Status | Description |
|---|---|---|
| Control Panel Protocol | Documented | Serial protocol for buttons, LEDs, encoders |
| Audio Subsystem | Documented | DSP effects, tone generation, voice management |
| Effects DSP (NEC uPD6383GF) | Documented | IC311 effects processor — chip, instruction word, decoded EQ/reverb, 50-effect parameter catalogue |
| Effects-DSP Flowcharts | Documented | Signal-flow Mermaid diagrams — the shared kernel + 38 effect microprograms, synced from the disassembly |
| µPD6383GF Unofficial Datasheet | Documented | Pinout, memories, host interface and instruction set of a chip NEC never documented |
| µPD6383GF Decode — State of Play | Documented | 80.8 % decoded: what is left, what has been ruled out, and the cost-ranked route to 100 % |
| Keybed Scanning | Documented | Hardware key scanning, note encoding, voice slots |
| Display Subsystem | Documented | Framebuffer layout, palette, VGA registers |
| Storage Subsystem | Documented | Floppy, flash, Table Data ROM, HDAE5000 |
| MIDI Subsystem | Documented | 26-channel voice routing, CC handlers, SysEx |
| UI Framework | Documented | 550+ widget handlers, event system, drawing API |
| Sequencer | Documented | 16-track engine, ring buffer, style system |
Protocols
| Page | Description |
|---|---|
| Control Panel Protocol | MCU serial communication |
| Inter-CPU Protocol | Main/Sub CPU latch protocol |
| HDAE5000 Disk Interface | IDE/ATA and PC parallel port |
| HDAE5000 Filesystem | Custom FSB/FGB/FEB filesystem |
Firmware Analysis
| Page | Description |
|---|---|
| Boot Sequence | Power-on to ready state |
| SubCPU Payload Loading | LZSS decompression, E1 bulk transfer, DMA investigation |
| Sub CPU Payload Transfer | 192KB firmware loading mechanism |
| ROM Reconstruction | Disassembly progress |
| Source Code Map | Guide to every source file in the disassembly |
| FDC Subsystem | Floppy disk handlers |
| Feature Demo & Presentation System | SSF XML scripting, demo assets, planned-but-unshipped floppy loading |
| Floppy Security Analysis | Code injection vectors via crafted update discs |
| HDAE5000 | Hard disk expansion firmware |
| Firmware v9 vs v10 | Detailed comparison of the last two firmware releases |
Homebrew
| Page | Description |
|---|---|
| Playing Games on MAME | Step-by-step guide to running homebrew games in the emulator |
| Another World VM | Full game port: bytecode VM, polygon rendering, input, frame timing |
Resources
| Page | Description |
|---|---|
| Image Gallery | 46+ extracted graphics (42 main CPU, 4 HDAE5000) |
| ROM Strings | Extracted text resources |
| Reverse Engineering | Methodology and strategies |
| Help Wanted | Contribution guide |
| Open Questions | Unsolved mysteries |
Learning Paths
Choose based on your goal:
MAME Emulation Development
- System Overview - Understand the architecture
- Hardware Architecture - Physical components
- Memory Map - Address space
- Control Panel Protocol - HLE for buttons/LEDs
Homebrew Development
- Playing Games on MAME - Get the emulator running first
- CPU Subsystem - TMP94C241F programming
- Memory Map - Available resources
- Display Subsystem - Graphics output
- Another World VM - Full game port example
- Help Wanted - Tool development needs
Reverse Engineering Research
- ROM Reconstruction - Current progress
- Reverse Engineering - Techniques
- Open Questions - Areas needing investigation
- Help Wanted - Specific tasks you can pick up
Project Status
ROM Reconstruction Progress
Thirteen ROM images rebuild byte-identically from source — nine KN5000 and four
SX-WSA1R, 12,386,304 bytes, gated together by
make gate-all after every commit. Built with a custom
LLVM TLCS-900 backend.
| Component | Size | Rebuild | Verbatim debt |
|---|---|---|---|
| Main CPU Program (v10, v9) | 2MB each | byte-identical | 0 |
| Main CPU Program (v7) | 2MB | byte-identical | 120,666 B |
| Sub CPU Payload | 192KB | byte-identical | 0 |
| Sub CPU Boot ROM | 128KB | byte-identical | 0 |
| Table Data | 2MB | byte-identical | 0 real (six genuine BMPs the tool counts) |
| Custom Data | 1MB | byte-identical | 0 |
| HDAE5000 ROM | 512KB | byte-identical | 0 |
SX-WSA1R prom_a–prom_d |
512KB each | byte-identical | 0 |
Byte-identical means identical to the dump files we hold. For the sub-CPU boot ROM that
file is a BAD_DUMP: 89% of IC30 was never read and is present in the file as assumed
0xFF. See Sub-CPU Boot ROM (IC30).
Rebuilding is not the same as understanding. Of the same bytes, about 93.8 % can be
explained — what the data represents, not merely that it reproduces — with a 95 %
confidence interval of 86.7 % – 96.6 %. That covers the twelve distinct images; the
thirteenth gated image is a compressed re-encoding of the sub-CPU payload. Measured by
scripts/analysis/data_range_census.py; see
how much of the data is actually explained.
Homebrew Development
A homebrew SDK is available for writing custom HDAE5000 extension ROMs. Features a Quick Start guide, C + assembly build pipeline, and a fully playable Minesweeper game as a working example.
MAME Emulation
| Component | Status |
|---|---|
| MAME Driver | upstream in mamedev/mame; further work staged as a queue of follow-up PRs — see MAME Branch Review |
| Display | 320x240 LCD working (VGA controller emulated) |
| Audio | DSP protocol decoded, tone generator HLE |
| Control Panel | Protocol documented, button state arrays emulated |
| HDAE5000 | Extension board detected, IDE/ATA wired, homebrew ROMs loadable |
| Floppy | UPD72067 FDC emulated, disk images available |
Quick Links
- Service Manual PDF (26MB, EMID971655 A5) - Schematics, board layouts, IC pinouts
- GitHub: ROM Disassembly - Source code
- GitHub: Homebrew - Custom software
- MAME Pull Requests - the upstreaming record
- Discussion Forum
- Firmware Archive - All versions (v5-v10, HD-AE5000 updates)
- Keysoftservice HDAE5000 Page - Original HDAE5000 information
About This Project
| Project Lead: Felipe Sanches | Arqueologia Digital |
This documentation is developed with AI assistance from Claude Code. All content is verified against actual hardware behavior and service documentation. Contributions and corrections are welcome via GitHub issues.
We believe preserving technical knowledge of instruments like the Technics KN5000 and KN7000 is essential for cultural heritage. Our long-term goal is to preserve the history of Technics musical keyboards as a whole. If you find errors or have additions, please contribute.