As someone pointed here (I think it was ExCyber) the CD subsystem is a black box. It's composed of 3 chips :
YGR019 (Seems to be the interface and ASIC and maybe also with a DSP inside for error correction)
HD6437097 (the code in it is called CDB105) (this for the 20 pin saturn)
and the H8 microcontroller on the CD drive mechanism :
HD6433712H (the code in it is called CDM103V)
As was also mentioned before, the modchip works by disturbing the communication of the SH1 with the H8 making the SH1 think it got the security code read from disc by the H8. It means the H8 can fully read the disc even if the security code was not authenticated yet (some mods make the system completely skip the security check and others have the laser to quicly move to the cheking point but then quickly come back.)
This makes me think the check is surely on the SH1. I also believe that there's a unlock command that can be issued to the SH1 to simply skip the check and get access to the disc. I think this is how the MPEG cartridge works. Since the connection of the MPEG cart to the Saturn is buffered throught the YGR019 chip, I think the command is issued directly to the SH1 by the asic inside the MPEG cartridge.
Maybe a person with all the hardware, a logic analyzer and some guts might unlock it .... Maybe even get a way into the SH1 ram and dump it's microcode ...
But this is just a idea and I'm not a cracking GOD like some people arround the world who cracked strong security schemes like the CPS2 encryption ...
It's just my two cents ....