DS2703 MAXIM | Alldatasheet
Document overview
- Manufacturer or author: Provided By ALLDATASHEET.COM(FREE DATASHEET DOWNLOAD SITE)
- PDF pages: 20
Technical content
1 of 20 REV: 061307 Note: Some revisions of this device may incorporate deviations from published specifications known as errata. Multiple revisions of any device may be simultaneously available through various sales channels. For information about device errata, click here: www.maxim-ic.com/errata. GENERAL DESCRIPTION The DS2703 provides a robust cryptographic solution to ensure the authenticity of Li-Ion battery packs for cell phone, PDA, and portable computing devices. The DS2703 employs the Secure Hash Algorithm (SHA-1) specified in the Federal Information publication 180-1 and 180-2, and ISO/IEC 10118-3. SHA-1 is designed for authentication ⎯just what is required for identifying battery packs manufactured by authorized sources. The device’s SHA-1 engine processes a host transmitted challenge using its stored 64-bit secret key and unique 64-bit ROM ID to produce a 160-bit response word for transmission back to the host. The secret key is securely stored on-chip and never transmitted between the battery and the host. A DS2703-based system produces a high degree of authentication security between a host system and its removable battery or other peripheral devices. The Thermistor Multiplexer feature allows a three contact battery pack configuration to support data and thermistor functions. When activated through 1-Wire command, the THM pin presents the thermistor impedance on the data contact and disconnects internal loading from the node. TYPICAL OPERATING CIRCUIT
FEATURES
Secure Challenge and Response Authentication Using the SHA-1 Algorithm Directly Powered by the Dallas 1-Wire® Interface with 16kbps Standard and 143kbps Overdrive Communication Modes Unique 64-Bit Serial Number Thermistor Multiplexer Operates with VPULLUP as Low as 2.7V Pb-Free 8-Pin μMAX® or 2mm x 3mm TDFN Package PIN CONFIGURATION
APPLICATIONS
2.5G/3G Wireless Handsets PDAs Handheld or Notebook Computers and Terminals Digital Still and Video Cameras
ORDERING INFORMATION
PART TEMP RANGE PIN-PACKAGE DS2703G+ -20°C to +70°C 2mm x 3mm TDFN DS2703G+T&R -20°C to +70°C DS2703G+ on Tape-and-Reel DS2703U+ -20°C to +70°C μMAX-8 DS2703U+T&R -20°C to +70°C DS2703U+ on Tape-and-Reel + Denotes lead-free package. DS2703 SHA-1 Battery Pack Authentication IC www.maxim-ic.com 1-Wire is a registered trademark of Dallas Semiconductor. µMAX is a registered trademark of Maxim Integrated Products.
DS2703 SHA-1 Battery Pack Authentication IC 2 of 20 ABSOLUTE MAXIMUM RATINGS Voltage Range on DQ, THM Pins Relative to Ground -0.3V to +18V Voltage Range on VB Pin Relative to Ground -0.3V to +6V Operating Temperature Range -40°C to +85°C Storage Temperature Range -55°C to +125°C Soldering Temperature See IPC/JEDEC J-STD-020A Specification Stresses beyond those listed under “Absolute Maximum Ratings” may cause permanent damage to the device. These are stress ratings only, and functional operation of the device at these or any other conditions beyond those indicated in the operational sections of the specifications is not implied. Exposure to the absolute maximum rating conditions for extended periods may affect device. RECOMMENDED DC OPERATING CONDITIONS (TA = -20°C to +70°C.) PARAMETER SYMBOL CONDITIONS MIN TYP MAX UNITS Communication Mode 0 5.5 DQ Pullup Voltage V PULLUP Computation Mode 2.7 5.5 V DQ, THM Relative Voltage V DQ-THM (Note 1) -0.3 15 V DQ to THM Resistor R DQ-THM (Note 2) 5 500 KΩ DC ELECTRICAL CHARACTERISTICS (VPULLUP = 2.7V to 5.5V, TA = -20°C to +70°C.) PARAMETER SYMBOL CONDITIONS MIN TYP MAX UNITS IDQ0 Standby Mode, V DQ > VIH 1 2.5 μA IDQ1 Communication Mode (Note 14) 75 μA IDQ2 Computation Mode, SHA-1 Computation Active 0.25 mA IDQ3 Thermistor Mux Active, (Note 3) 1 μA IPP 14.5 < VDQ < 15.0V 0 < t < 50 oC 10 mA DQ Load Current IPP-IDLE (Note 4) 60 μA DQ Programming Voltage V PP Program Pulse, (Note 5, 6) 14.5 15.0 V Input Logic High: DQ V IH (Note 6) 0.8 V PULLUP V Input Logic Low: DQ V IL (Note 6) 0.5 V Output Logic Low: DQ V OL-DQ I OL = 4mA, (Note 6, 7) 0.4 V Output Logic Low: THM V OL-THM I OL = 4mA, (Note 6, 7, 8) 0.4 V Hold-Up Current: VB pin I HU THM pin Active, V B = 2.70V 3.2 μA DQ Capacitance C DQ (Note 9) 50 pF EEPROM RELIABILITY SPECIFICATION (VPULLUP = 2.7V to 5.5V, TA = -20°C to +70°C.) PARAMETER SYMBOL CONDITIONS MIN TYP MAX UNITS EEPROM Write Endurance NEEC 0 < t < 50 oC (Note 10) 1000 Cycles
DS2703 SHA-1 Battery Pack Authentication IC 3 of 20 AC ELECTRICAL CHARACTERISTICS (VPULLUP = 2.7V to 5.5V, TA = -20°C to +70°C.) PARAMETER SYMBOL CONDITIONS MIN TYP MAX UNITS THM Low Delay t TD (Note 11) 15 μs Computation Delay Time tD (Note 12) 100 μs Computation Time tSHA (Note 12) 15 ms Programming Pulse Width tPPW (Note 5) 17 ms Programming Pulse Rise Time tPPR 0.5 5 μs Programming Pulse Fall Time tPPF 0.5 5 μs Start-up Delay Time tSTRT (Note 13) 100 ms AC ELECTRICAL CHARACTERISTICS: 1-Wire INTERFACE (VPULLUP = 2.7V to 5.5V, TA = -20°C to +70°C.) PARAMETER SYMBOL CONDITIONS MIN TYP MAX UNITS 1-Wire INTERFACE REGULAR TIMING Time Slot tSLOT 60 120 μs Recovery Time tREC 1 μs Write 0 Low Time tLOW0 60 120 μs Write 1 Low Time tLOW1 1 15 μs Read Data Valid Time tRDV 15 μs Reset Time High tRSTH 480 μs Reset Time Low tRSTL 480 960 μs Presence Detect High tPDH 15 60 μs Presence Detect Low tPDL 60 240 μs 1-Wire INTERFACE OVERDRIVE TIMING Time Slot tSLOT 6 16 μs Recovery Time tREC 1 μs Write 0 Low Time tLOW0 6 16 μs Write 1 Low Time tLOW1 1 2 μs Read Data Valid Time tRDV 2 μs Reset Time High tRSTH 48 μs Reset Time Low tRSTL 48 80 μs Presence Detect High tPDH 2 6 μs Presence Detect Low tPDL 8 24 μs Note 1: V DQ – VTHM. The THM pin must not be driven to a higher voltage than the DQ pin. Note 2: The application thermistor cannot exceed the R DQ-THM resistance range over operating temperature. If thermistor mode is not used in the application, it is recommended that a 50KΩ resistor be connected between DQ and THM pins instead. Note 3: Maximum leakage of DQ pin while in thermistor mode. Note 4: When performing a Lock Secret (0x6A), Set Overdrive (0x8B) or Clear Overdrive (0x8D) operation, there will be an increased operating current of IPGM- IDLE during and after the program pulse until the next 1-Wire bus reset. Note 5: See Figure 11 for definitionof tPPR, tPPW, and tPPF. Note 6: All voltages referenced to VSS. Note 7: V DQ must be at least 3.0V when the 1-Wire bus is idle. Note 8: Drive strength at time=0 after Activate Thermistor command is sent to the DS2703. Note 9: Does not include capacitance referred from VB pin on initial power up. Note 10: EEPROM data read retention is four years at +50°C Note 11: Time from msb of Activate Thermistor command until THM pin is driven low internally. Note 12: Time from msb of Compute Next Secret or Compute MAC command. Note 13: Time after initial power up before the DS2703 will respond to communication. T STRT specifications are valid only if the capacitor on VB (CVB) is 0.22µF. Worst case 100ms delay based on maximum thermistor value of 500kΩ. Note 14: The average current measured in Overdrive mode with minimum bus timings while the master issues: 1-Wire Reset, Skip ROM, Write Challenge, Write 0's repeatedly unil the end of measurement.
2 8 V SS Device Ground. Connect directly to the negative terminal of the battery cell. 5 3 N.C. No Connection. Pin not connected internally, float or connect to VSS. 6 4 N.C. No Connection. Pin not connected internally, float or connect to VSS. 7 5 N.C. No Connection. Pin not connected internally, float or connect to VSS. 8 6 N.C. No Connection. Pin not connected internally, float or connect to VSS. Figure 1. Block Diagram
DS2703 SHA-1 Battery Pack Authentication IC 5 of 20 DETAILED DESCRIPTION The DS2703 is comprised of a SHA-1 Authentication function and thermistor mux control that are accessed via a 1- Wire interface. The high voltage (HV) detection circuit r outes the externally supplied programming voltage to the EEPROM array and enables the internal regulator to isolate portions of the chip from the programming voltage. The 1-Wire interface controls access by a host system to the 64-bit Net Address (ROM ID) and SHA-1 Authentication. The DS2703 operates in one of four operating modes: communication, computation, programming and thermistor access. Most operations are performed in communicati on mode, with the host system addressing the DS2703 using Net Address commands and then setting up an authentication exchange and retrieving the results. In communication mode, the DQ load current is no more than IDQ0 maximum, and the DS2703 can be “parasite” powered via the DQ pin through a high impedance pullup resistor during a communication transaction. Power available while the 1-Wire bus is at a logic high is rectified by the on chip diode and stored in an off chip capacitor connected to the VB pin. In computation mode, when a SHA-1 verification is performed, the DQ load current increases up to IDQ2, necessitating a lower impedance pullup resistor. The computation mode load current occurs after the host supplies the required challenge data and requests the computation using the proper function commands in communication mode. In this mode, the pullup supply and low impedance pullup resistor must be capable of keeping the DQ pin above V PULLUP-MIN. The third operating mode is required when programming th e non-volatile memory portions of the DS2703. The programming mode is defined by the application of a high voltage programming pulse to the DQ pin at the appropriate point during a Compute Secret command, Load/ Lock Secret or Clear/Set Overdrive Timing command. The internal voltage regulator limits the internal voltage (V DD_INT) to isolate low voltage portions of the chip from the HV programming pulse. Typically, programming mode is us ed during module or pack manufacture to configure the DS2703 and program the 64-bit secret. Finally, thermistor mode allows the voltage on an exter nal thermistor to be measured from the DQ line. The command sequence causes the DS2703 to internally disconnect its DQ interface and drive the THM pin to VSS allowing the measurement to be made. The IC remains in this mode until the VB pin capacitor is drained causing the DS2703 to power cycle back to communication mode. AUTHENTICATION Authentication is performed using a FIPS-180 compli ant SHA-1 one way hash algorithm on a 512 bit message block. The message block consists of a 64-bit secret, a 64-bit challenge and 384 bits of constant data. Optionally, the 64-bit net address replaces 64 of t he 384 bits of constant data used in the hash operation. An authentication attempt is initiated by the host system providing a 64-bit random challenge then sending one of two compute command sequences. The host and the DS2703 both calculate the result based on the mutually known secret. The result data, known as the Message Authentication Code (MAC) or Message Digest, is returned by the DS2703 for comparison to the host’s result. Note that the secret is never transmitted on the bus and thus cannot be captured by observing bus traffic. SHA-1 based authentication is a cryptographically strong method in wide use for digitally signing encrypted files and secure transactions such as electronic cash and password exchange protocols. The FIPS 180 Compliant Input Block, the 512-bit message block is organized as sixteen 32-bit words, W0-W15. The message block is initialized when a command is receiv ed to compute the MAC. Upon initialization, the 64-bit secret is loaded, and it is important to note that the SH A-1 algorithm has access to this data, but not the serial interface. The challenge data is received with the command just prior to the compute MAC command. The challenge data is cleared during computation of the MAC, so the host must write new challenge data prior to issuing each Compute MAC or Compute Next Secret comma nd. Additionally, the A, B, C, D and E variables used in the hash computation are initialized per FIPS 180 as shown in Table 1. Variable Initiation. Please contact the factory for memory map details.
Table 1. Variable Initiation returned as a 160-bit serial stream, beginning with the least significant bit of variable A. Table 2. Message Authentication Code (MAC) Return Format
DS2703 SHA-1 Battery Pack Authentication IC 7 of 20 SHA Computation The variables A, B, C, D, E and constants H0, H1, H2, H3, and H4 are initialized as follows: A := 67452301h H0 := 67452301h B := EFCDAB89h H1 := EFCDAB89h C := 98BADCFEh H2 := 98BADCFEh D := 10325476h H3 := 10325476h E := C3D2E1F0h H4 := C3D2E1F0h The final values of variables A, B, C, D, and E are gener ated by looping through the following set of computations for t = 0 to 79 (discarding any carry-out). Finally, the H0 -H4 constants are added to the A-E variables respectively, which are then concatenated to form the 160-bit MAC, ABCDE. for ( t = 0 to 79 ) TMP := S 5(A) + Ft(B,C,D) + Wt + Kt + E E := D D := C C := S 30(B) B := A A := TMP 160-bit MAC := (A+H0) | (B+H1) | (C+H2) | (D+H3) | (E+H4) DS2703 AUTHENTICATION COMMANDS WRITE CHALLENGE [0Ch]. This command writes 64 bits in the message block. The LSB of the 64-bit data can begin immediately after the MSB of the command has been co mpleted. If more than 8 bytes are written, the final value in the challenge register will be indeterminate. T he Compute MAC and Compute Next Secret (with or without ROM ID) function commands clear the challenge value. Therefore the Write Challenge command must be issued prior to every Compute MAC or Compute Next Secret command for reliable results. NOTE: Immediately after power-up, a du mmy Compute MAC command is required to initialize the DS2703. If the dummy command is not issued, the first authentication atte mpt is computed using a challenge value of 0. When issuing the dummy Compute MAC command, the command sequence can be terminated immediately following the 8th bit of the Compute MAC command byte. Waiting for the SHA-1 computation and re ading the results back are not required. COMPUTE MAC WITHOUT ROM ID [36h]. This command initiates a SHA-1 computation on the 512 bit block comprised of words W0 - W15. The 64-bit secret and the 64-bit challenge are loaded in the message block and the space in the message reserved for the ROM ID is filled with logical 1's. The DS2703 pauses at least 100us after receiving this command before MAC computation begins. This gives the host ample time to connect the DQ pin to a low impedance node prior to the high current demand computation. The DQ pin must not fall below V PULLUP_MIN during the computation period, t COMP. The host must release the DQ pin for 1-Wire data communications (i.e. terminate the low source impedance mode). After the DQ pin has returned to normal impedance, the host must write eight write zero time slots and then issue 160 read time slots to get the MA C. The 32-bit registers A, B, C, D, and E are used during every cycle of the hash algorithm and their final values at calculation cycle t=79 are added to the values H0-H4 and stored in registers A-E. T he new word ABCDE is now the MAC. After issuing the command and waiting a minimum of t COMP, the host reads the 20-byte MAC . This command allows the use of a master secret and message digest response independent of the ROM ID. COMPUTE MAC WITH ROM ID [35h] This command is structured the same as the Compute MA C without ROM ID, except that the ROM ID is loaded to the message block. Including the ROM ID unique to each DS2703 in the MAC computation allows the use of a unique secret in each token and a master secret in the host device. See application note “White Paper 4”, available at http://www.maxim-ic.com, for more information.
Table 3. Authentication Function Commands host must apply a programming pulse afterwards to copy the new secret value to EEPROM. apply a programming pulse to write the new secret value to EEPROM. Compute Next Secret With ROM ID and Compute Next Secret Without ROM ID commands. pulse to write the secret lock bit to EEPROM. Table 4. Secret Loading Function Commands
Table 5. 1-Wire Speed Control Function Commands timing diagram in Figure 12. Figure 2. Thermistor Mode Duration when CVB is .22µF
DS2703 SHA-1 Battery Pack Authentication IC 12 of 20 TRANSACTION SEQUENCE The protocol for accessing the DS2703 through the 1-Wire port is as follows: Initialization Net Address Command Function Command(s) Data Transfer (not all commands have data transfer) All transactions of the 1-Wire bus begin with an initialization sequence consisting of a reset pulse transmitted by the bus master, followed by a presence pulse simultaneously transmitted by the DS2703 an d any other slaves on the bus. The presence pulse tells the bus master that one or more devices are on the bus and ready to operate. For more details, see the 1-Wire Signaling section below. NET ADDRESS COMMANDS Once the bus master has detected the presence of one or more slaves, it can issue one of the net address commands described in the following paragraphs. The name of each Net Address command (ROM command) is followed by the 8-bit opcode for that command in square br ackets. Figure 6 presents a transaction flowchart of the net address commands. Read Net Address [33h]. This command allows the bus master to r ead the DS2703’s 1-Wire net address. This command can only be used if there is a single slave on the bus. If more than one slave is present, a data collision occurs when all slaves try to transmit at the same time (open drain produces a wired-AND result). Match Net Address [55h]. This command allows the bus master to specifically address one DS2703 on the 1-Wire bus. Only the addressed DS2703 responds to any subsequent function command. All other slave devices ignore the function command and wait for a reset pulse. This command can be used with one or more slave devices on the bus. Skip Net Address [CCh]. This command saves time when there is only one DS2703 on the bus by allowing the bus master to issue a function command without specifying the address of the slave. If more than one slave device is present on the bus, a su bsequent function command can cause a data collision when a ll slaves transmit data at the same time. Search Net Address [F0h]. This command allows the bus master to use a process of elimination to identify the 1-Wire net addresses of all slave devic es on the bus. The search process invo lves the repetition of a simple three- step routine: read a bit, read the complement of the bit, t hen write the desired value of that bit. The bus master performs this simple three-step routine on each bit locati on of the net address. After one complete pass through all 64 bits, the bus master knows the address of one devic e. The remaining devices can then be identified on additional iterations of the process. See Chapter 5 of the Book of DS19xx i Button® Standards for a comprehensive discussion of a net address search, including an actual example (www.maxim-ic.com/iButtonBook).
Figure 6. Net Address Command Flow Chart
1 BYTE
6 BYTES
are as follows: the initialization sequence (reset pulse followed by presence pu lse), write 0, write 1, and read data. The bus master initiates all these types of signaling except the presence pulse. waits for tPDH and then transmits the presence pulse for tPDL. Figure 7. 1-Wire Initialization Sequence pulled low and held low for the duration of the write-time slot. allows Vdd_int to recharge sufficiently each time slot. A read-time slot is initiated when the bus master pulls the 1-Wire bus line from a logic-high level to a logic-low level. timing specifications in the Electrical Characteristics table for more information.
Figure 8. 1-Wire Write and Read Time Slots
Table 7. All Function Commands MAC and Compute Next Secret commands. 36 Computes hash of W0-W15 with logical 1’s in place of the ROM_ID. 35 Computes hash of W0-W15 with the ROM_ID. without ROM ID 30 Generates new global secret. Requires programming pulse. with ROM ID 33 Generates new unique secret. Requires programming pulse. Lock Secret 6A Sets lock bit to prevent ch anges to the Secret. Requires programming pulse. Set Overdrive 8B Sets 1-Wire interface ti mings to OVERDRIVE. Requires programming pulse. Clear Overdrive 8D Sets 1-Wire interface ti mings to STANDARD. Requires programming pulse. Reset BB Resets DS2703 (Software POR). Table 8. Guide to Function Command Requirements
one-wire interface. See Figure 9. Figure 9. Compute MAC Function Command
8 Write 0
damage during the transition between normal communication mode and programming mode. Figure 10. Lock Secret, Set/Clear Overdrive Function Commands
between normal communication mode and programming mode. Figure 11. Compute Next Secret Function Command