First off, HELLO!!!
Second, don't know if this goes here. ANYWAYS,
I was looking around for a way to decrypt the KV.bin with out the cpu key. Didn't find anything of course. So I start to look at my nand dump from my JTAG with "010 Editor" (a hex tool), didn't really find anything useful. Then I use "360 Flash Dump Tool .97" on it and extracted the key vault only. Of course it was encrypted but it hit me, I HAVE MY CPU KEY. 360 Flash Dump Tool can decrypt the key vault if you have your cpu key. So now I have an encrypted kv.bin and a decrypted kv.bin file. If you use 360 Flash Dump Tool to view the decrypted key vault, it will give you a list on the left with the addresses and names of the keys inside it and on the right side will be the hex and ASCII of the address. Here is what I found, mind you that I will not show the hex or ASCII for private reasons.
KEY 0x14 - XEKEY_CONSOLE_SERIAL_NUMER
KEY 0x1A - XEKEY_DVD_KEY
You can even get your "real console id" that you can generate with 360 Flash Dump Tool.
At the bottom of the box it will tell you the offset address (hex of course) of the highlighted key.
BINGO!!!!
Now I had an idea to make a program to decrypt the kv.bin without the cpu key. Since we know the serial number of the console is on the back of the 360, and we know the hex address to look for it (the first 12 of 16 bits) is 0x00B0, it would be just be decrypting the 0x00B0 address. The last 4 bits of the address on my kv.bin were "...." (00 00 00 00 in hex), I would think it would be the same for all kv.bin files. We could also use the "real console id". Basically, use any information that we know with out a decrypted kv.bin file (like the sn of you console) to actually decrypt it, given the know addresses in hex.
If I knew how code a decryption program I would. Mind you that if someone else makes the decryptor you will have to use a 32 character pass word (CPU KEY). Basically decrypt the cpu key out of the kv.bin with known information.
We all know that you can dump a nand regardless of the dash version so this will work for anybody. I though that this would come in handy for making a decryption program for decrypting the key vault. This would defiantly be useful for getting the dvd key for people with lost keys. I will look into this a little more. I will also try to post all the key names (XEKEY) that are listed the key vault and maybe some pics.
Though I might share this, who knows, it might help someone.