DS2704 MAXIM | Alldatasheet

Document overview

  • Manufacturer or author: Provided By ALLDATASHEET.COM(FREE DATASHEET DOWNLOAD SITE)
  • PDF pages: 18

Technical content

The DS2704 provides 1280 bits of EEPROM data storage and a Secure Hash Algorithm (SHA) engine. The Dallas 1-Wire interface enables serial communication on a single battery contact and the 64-bit unique serial number allows multidrop networking and identification of individual devices. The 1280-bit memory is organized as 5 pages of 32 bytes each and supports storage of battery cell characteristics, charging voltage, current, and temperature parameters, as well as battery pack manufacturing data. The EEPROM pages are in circuit rewritable and can be individually locked to write protect data. The DS2704 employs the Secure Hash Algorithm (SHA-1) specified in the Federal Information publication 180-1 and 180-2, and ISO/IEC 10118-3. SHA-1 provides a robust cryptographic solution to ensure battery packs or other peripherals have been manufactured by authorized sources. The DS2704 processes a host transmitted challenge and the 64- bit secret key stored on chip to produce a 160-bit response for transmission back to the host. The secret key is never transmitted between the battery and the host. APPLICATION EXAMPLE Li+ Safety Circuit DS2704 PACK+ THM DATA PACK- VDD DQ VSS 150 4.7V 0.01F 150 PIN CONFIGURATION DQ VSS NC NC NC VDD 3mm × 3mm TDFN (TOP VIEWPADS ON BOTTOM) A 1.98 mm 1.73 B C Top Side A1 Mark UCSP (FUTURE AVAILABILITY) (TOP VIEWBALLS ON BOTTOM)

FEATURES

Secure Challenge and Response Authentication Using the SHA-1 Algorithm Five Lockable 32-Byte Pages of EEPROM Dallas 1-Wire Interface with Standard and Overdrive Communications Speeds Unique 64-Bit Serial Number Compatible with DS2502 Memory Map and Read Function Command Operates with VDD as Low as 2.5V Tiny Chip-Scale UCSP and 3mm x 3mm TDFN Packaging (Pb-free)

ORDERING INFORMATION

-20C to +70C 6-TDFN DS2704G+T&R -20C to +70C DS2704G+ on Tape-and-Reel DS2704W -20C to +70C Bare Die DS2704 1280-Bit EEPROM with SHA-1 Authentication www.maxim-ic.com + Denotes lead-free package. 1-Wire is a registered trademark of Dallas Semiconductor.

DS2704: 1280-Bit EEPROM with SHA-1 Authentication 2 of 18 ABSOLUTE MAXIMUM RATINGS Voltage Range on All Pins, Relative to VSS -0.3V to +6V Operating Temperature Range -40°C to +85°C Storage Temperature Range -55°C to +125°C Soldering Temperature See IPC/JEDEC J-STD-020A Specification Stresses beyond those listed under “Absolute Maximum Ratings” may cause permanent damage to the device. These are stress ratings only, and functional operation of the device at these or any other conditions beyond those indicated in the operational sections of the specifications is not implied. Exposure to the absolute maximum rating conditions for extended periods may affect device. RECOMMENDED DC OPERATING CONDITIONS (2.5V VDD 5.5V, TA = -30°C to +85°C.) PARAMETER SYMBOL CONDITIONS MIN TYP MAX UNITS Supply Voltage VDD (Note 1) 2.5 5.5 V Data Pin DQ (Note 1) -0.3 +5.5 v DC ELECTRICAL CHARACTERISTICS (2.5V VDD 5.5V, TA = -30°C to +85°C, typical values at VDD = 3.7V and TA = 25°C.) PARAMETER SYMBOL CONDITIONS MIN TYP MAX UNITS IDD0 Standby mode (Note 4) A Communication mode using Standard Bus Timing (Note 5) A IDD1 Communication mode using Overdrive Bus Timing (Note 5) A IDD2 Computation mode 500 A Active Current IDDP Programming mode 400 750 A Input Logic High: DQ VIH (Note 1) 1.5 V Input Logic Low: DQ VIL (Note 1) 0.6 V Output Logic Low: DQ VOL IOL = 4mA (Note 1) 0.4 V Pull-down Current: DQ IPD A EEPROM RELIABILITY SPECIFICATION (2.5V VDD 5.5V, TA = -30C to +85C.) PARAMETER SYMBOL CONDITIONS MIN TYP MAX UNITS Write Endurance: EEPROM Data Field NEEC1 (Note 2) 50,000 Writes Write Endurance: Secret EEPROM NEEC2 (Note 2) 1,000 Writes Storage tEES (Note 2, 3) Years AC ELECTRICAL CHARACTERISTICS (2.5V VDD 5.5V, TA = -30°C to +85°C) PARAMETER SYMBOL CONDITIONS MIN TYP MAX UNITS Computation Time tSHA ms EEPROM Copy Time tEEC (Note 2) ms

DS2704: 1280-Bit EEPROM with SHA-1 Authentication 3 of 18 AC ELECTRICAL CHARACTERISTICS: 1-WIRE INTERFACE (2.5V VDD 5.5V, TA = -30C to +85C.) PARAMETER SYMBOL CONDITIONS MIN TYP MAX UNITS STANDARD BUS TIMING Time Slot tSLOT 120 s Recovery Time tREC s Write 0 Low Time tLOW0 120 s Write 1 Low Time tLOW1 s Read Data Valid tRDV s Reset Time High tRSTH 480 s Reset Time Low tRSTL 480 960 s Presence Detect High tPDH s Presence Detect Low tPDL 240 s OVERDRIVE BUS TIMING Time Slot tSLOT s Recovery Time tREC s Write 0 Low Time tLOW0 s Write 1 Low Time tLOW1 s Read Data Valid tRDV s Reset Time High tRSTH s Reset Time Low tRSTL s Presence Detect High tPDH s Presence Detect Low tPDL s DQ Capacitance CDQ pF Note 1: All voltages are referenced to VSS. Note 2: EEPROM programming temperature range limited to 0C to 50C. Note 3: Device written NEEC times then stored for tEES at 50C. Note 4: DQ = VDD. Note 5: Current measured with minimum bus timing while the master issues: 1-Wire Reset, Skip ROM, Write Challenge, Write Repeated 0’s until end of measurement.

Figure 1. Block Diagram SHA-1 Authentication, 1280-bit EEPROM memory and EEPROM Status. selection of Standard or Overdrive bus timing. current occurs after the last bit of one of the Compute MAC function commands is sent.

DS2704: 1280-Bit EEPROM with SHA-1 Authentication 5 of 18 Programming mode is entered when writing the nonvolatile memory portions of the DS2704. The supply current increases to IDDP for tEEC when a Copy Scratchpad, Write Status, Compute Secret, Clear/Lock Secret or Clear/Set Overdrive Timing command is executed. Functional compatibility has been maintained between the DS2502 and DS2704 at the Net Address/ROM Command and Function Command levels for reading the Memory and Status data fields. Since the DS2704 is based on EEPROM technology versus the EPROM technology used for the DS2502, writing of the Memory and Status data fields is not the same as the DS2502. The DS2704 includes an on-chip charge pump to facilitate in- circuit programming. The need to apply an external high voltage programming pulse during pack manufacture is therefore eliminated. Data can be written to a 0 or 1 value up to NEEC times in the DS2704. The ability to reprogram the data in the EEPROM pages makes the Page Address Redirection bytes in the Status data field unnecessary. Therefore, the DS2704 maintains them for DS2502 read compatibility but they cannot be modified from their factory default values of FFh. AUTHENTICATION Authentication is performed using a FIPS-180 compliant SHA-1 one way hash algorithm on a 512-bit message block. The message block consists of a 64-bit secret, a 64-bit challenge and 384 bits of constant data. Optionally, the 64-bit net address replaces 64 of the 384 bits of constant data used in the hash operation. Contact Dallas/Maxim for details of the message block organization. The host and the DS2704 both calculate the result based on the mutually known secret. The result data, known as the Message Authentication Code (MAC) or Message Digest, is returned by the DS2704 for comparison to the host’s result. Note that the secret is never transmitted on the bus and thus cannot be captured by observing bus traffic. Each authentication attempt is initiated by the host system by providing a 64-bit random challenge via the Write Challenge command. The host then issues the Compute MAC or Compute MAC with ROM ID command. The MAC is computed per FIPS 180, and then returned as a 160-bit serial stream, beginning with the least significant bit. DS2704 AUTHENTICATION COMMANDS WRITE CHALLENGE [0Ch]. This command writes the 64-bit challenge to the DS2704. The LSB of the 64-bit data argument can begin immediately after the MSB of the command has been completed. If more than 8 bytes are written, the final value in the challenge register will be indeterminate. The Write Challenge command must be issued prior to every Compute MAC or Compute Next Secret command for reliable results. COMPUTE MAC WITHOUT ROM ID [36h]. This command initiates a SHA-1 computation based on the Challenge value and internal Secret. Logical 1’s are loaded in place of the ROM ID. This command allows the use of a master secret and MAC response independent of the ROM ID. The DS2704 computes the MAC in tSHA after receiving the last bit of this command. After the MAC computation is complete, the host must write 8 write zero time slots and then issue 160 read time slots to receive the 20-byte MAC. See Figure 7 on page 16 for command timing. COMPUTE MAC WITH ROM ID [35h] This command is structured the same as the Compute MAC without ROM ID, except that the ROM ID is included in the message block. With the ROM ID unique to each DS2704 included in the MAC computation, use of a unique secret in each token and a master secret in the host device is allowed. See application note “White Paper 4”, available at http://www.maxim-ic.com, for more information. See Figure 7 on page 16 for command timing. NOTE: Immediately after power-up, a dummy Compute MAC command is required to initialize the DS2704. If the dummy command is not issued, the first authentication attempt is computed using a challenge value of 0. When issuing the dummy Compute MAC command, the command sequence can be terminated immediately following the 8th bit of the Compute MAC command byte. Waiting for the SHA-1 computation and reading the results back are not required. SHA-1 related commands used while authenticating a battery or peripheral device are summarized in Table 1 for convenience. Four additional commands for clearing, computing and locking of the Secret are described in detail in the following section.

Table 1. Authentication Function Commands issuing Compute MAC and Compute Next Secret commands. ROM ID. Returns the 160-bit MAC. Computes hash of the message block including the ROM ID. wait tEEC for the DS2704 to write the new secret value to EEPROM. See Figure 10 on page 18 for command timing. the DS2704 to write the new secret value to EEPROM. See Figure 8 on page 17 for command timing. to write the lock secret bit to EEPROM. See Figure 10 on page 18 for command timing. Table 2. Secret Loading Function Commands initial power up. The host must wait tEEC for the DS2704 to write the EEPROM. See Figure 10 for command timing. Standard 1-Wire timing is the factory default. initial power up. The host must wait tEEC for the DS2704 to write the EEPROM. See Figure 10 for command timing.

DS2704: 1280-Bit EEPROM with SHA-1 Authentication 7 of 18 Table 3. 1-Wire Speed Control Function Commands Sets 1-Wire interface timings to OVERDRIVE. Sets 1-Wire interface timings to STANDARD. EEPROM data field. Read access to the entire EEPROM data field is provided by the ReadAll function command. EEPROM data field. The EEPROM memory is organized as 5 pages of 32 bytes each as shown in Table 4. 1280-bit EEPROM data field appears as logical 1’s. Table 4. EEPROM Data Field

DESCRIPTION

0000 – 001F PAGE 0 (32 bytes) R/W* 0020 – 003F PAGE 1 (32 bytes) R/W* 0040 – 005F PAGE 2 (32 bytes) R/W* 0060 – 007F PAGE 3 (32 bytes) R/W* 0080 – 009F PAGE 4 (32 bytes) R/W* 00A0 – FFFF Reserved * Writing requires programming delay of tEEC READ MEMORY [F0h] The Read Memory command is used to read data from the lower 1024 bits (PAGE 0 to PAGE 3) of the 1280-bit EEPROM data field. The bus master follows the command byte with a 2-byte address (TA1=(T7:T0), TA2=(T15:T8)) that indicates a starting byte location within the data field. An 8-bit CRC of the command byte and address bytes is computed by the DS2704 and read back by the bus master to confirm that the correct command word and starting address were received. If the CRC is deemed to be incorrect by the bus master, a reset pulse should be issued and the entire sequence repeated. If the CRC is deemed to be correct by the bus master, read time slots can be issued to receive data from the EEPROM data field starting at the initial address. The bus master can issue a reset pulse at any point or continue to issue read time slots until the end of PAGE 3 of the data field is reached. If reading continues through the end of PAGE 3, the bus master can issue eight additional read time slots and the DS2704 will respond with a 8-bit CRC of all data bytes read from the initial starting byte through the last byte of PAGE 3. Terminating the command transaction with a reset pulse prior to reaching the end of PAGE 3 results in a loss of availability of the 8-bit CRC. READ DATA/GENERATE 8-BIT CRC [C3h] The Read Data/Generate 8-bit CRC command is used to read data from the lower 1024 bits (PAGE 0 to PAGE 3) of the 1280-bit EEPROM data field. The bus master follows the command byte with a 2-byte address (TA1=(T7:T0), TA2=(T15:T8)) that indicates a starting byte location within the data field. An 8-bit CRC of the command byte and address bytes is computed by the DS2704 and read back by the bus master to confirm that the correct command word and starting address were received. If the CRC is deemed to be incorrect by the bus master, a reset pulse should be issued and the entire sequence repeated. If the CRC is deemed to be correct by the bus master, read time slots can be issued to receive data from the EEPROM data field starting at the initial

DS2704: 1280-Bit EEPROM with SHA-1 Authentication 8 of 18 address. The bus master can issue a reset pulse at any point or continue to issue read time slots until the end of the 32-byte page is reached. If reading occurs through the end of the 32-byte page, the bus master can issue eight additional read time slots and the DS2704 will respond with a 8-bit CRC of all data bytes read from the initial starting byte through the last byte of the current page. After the CRC is received, additional read time slots return data starting with the first byte of the next page. This sequence will continue until the bus master reads PAGE 3 and its accompanying CRC. Thus each page of data can be considered to be 33 bytes long: the 32 bytes of user- programmed EEPROM data and an 8-bit CRC that gets generated automatically at the end of each page. The Read Data/Generate 8-Bit CRC command sequence can be exited at any point by issuing a reset pulse. READ ALL [65h] The Read All command is used to read data from all 1280 bits (PAGE 0 – PAGE 4) of the EEPROM data field. This includes PAGE 0 – PAGE 3 which are accessible via the DS2502 Read Memory and Read Data/Gen CRC legacy commands and PAGE 4 which is only accessible using the Read All command. The bus master follows the command byte with a 2-byte address (TA1=(T7:T0), TA2=(T15:T8)) that indicates a starting byte location within the data field. An 8-bit CRC of the command byte and address bytes is computed by the DS2704. The bus master must issue 8 read time slots to receive the CRC value, and then issue additional read time slots to receive data from the DS2704 starting at TA2:TA1. When reading begins within the EEPROM data field (0000h – 009Fh) and continues past 009Fh, an 8 bit CRC of all data returned is computed by the DS2704 and returned following the last byte of the data field. If reading begins in the reserved range or time slots are issued after receiving the 8 bit CRC, the DS2704 returns logical 1’s. WRITE SCRATCHPAD [6Ch] The Write Scratchpad command is used to write up to 8-bytes to the scratchpad buffer which is in turn used to program 1280-bit EEPROM data field via the Copy Scratchpad command. The bus master issues the Write Scratchpad function command followed by a 1-byte address argument that depicts the starting byte position in the scratchpad of the following byte stream to be written. The valid range for the address is 00h – 07h. The address is auto-incremented after each data byte is written. When the address is greater than 07h, no further bytes will be accepted. Incomplete bytes are not written to the scratchpad. The Write Scratchpad command fills the scratchpad LSByte first, so when fewer than 8 bytes are written, the upper bytes of the scratchpad buffer contain data from previous operations. Since the Copy Scratchpad command transfers the entire scratchpad to the EEPROM data field, incomplete writing of the scratchpad should be done with caution. If the master determines the scratchpad data is unsuitable to copy to the EEPROM, the entire write sequence (command and data) must be repeated after issuing a reset pulse. READ SCRATCHPAD [69h] The Read Scratchpad command is used to return scratchpad data if verification of the scratchpad data is required prior to programming the EEPROM data field. The bus master issues the Read Scratchpad function command followed by a 1-byte address argument that depicts the starting byte position in the scratchpad of the first byte to be read. The valid range for the address is 00h – 07h. The address is auto-incremented after each data byte is read. When the address is greater than 07h, any further reads will return bit values of 1. The DS2704 returns up to 64 bits from the scratchpad beginning with the least significant bit of the least significant byte. COPY SCRATCHPAD [48h] The Copy Scratchpad function command is used to transfer data from the 8-byte scratchpad buffer to the EEPROM data field memory. Transfers are aligned on 8 byte boundaries. The bus master issues the Copy Scratchpad function command followed by the 2-byte target address (TA1=(T7:T0), TA2=(T15:T8)). The DS2704 aligns target addresses to the least significant byte (LSByte) of each eight byte boundary by zeroing the three least significant bits of TA1. That is, TA1[T2:T0] are set internally to 000b. As an example, issuing the Copy Scratchpad command with TA2:TA1 = 0x0020 or TA2:TA1 = 0x0027 results in the same 8-byte block being copied to PAGE 1 beginning at address 0x0020. A delay of tEEC is required to program the scratchpad contents to the EEPROM array. See Figure 9 for command timing.

DS2704: 1280-Bit EEPROM with SHA-1 Authentication 9 of 18 EEPROM STATUS The DS2704 has a separate 8-byte linear address space for access to the EEPROM Status data field using the Read Status and Write Status Function Commands. READ STATUS [AAh] The Read Status command is used to read data from the EEPROM Status data field. The bus master follows the command byte with a 2-byte address (TA1=(T7:T0), TA2=(T15:T8)) that indicates a starting byte location within the data field. An 8-bit CRC of the command byte and address bytes is computed by the DS2704 and read back by the bus master to confirm that the correct command word and starting address were received. If the CRC is deemed to be incorrect by the bus master, a reset pulse should be issued and the entire sequence repeated. If the CRC is deemed to be correct by the bus master, read time slots can be issued to receive data starting at the initial address. The bus master can issue a reset pulse at any point or continue to issue read time slots until the end of the EEPROM Status data field is reached. If reading occurs through the end of the EEPROM Status data field, the bus master can issue eight additional read time slots and the DS2704 will respond with a 8-bit CRC of all data bytes read from the initial starting byte through the last byte. Additional read time slots return logical 1’s. The Read Status command sequence can be ended at any point by issuing a reset pulse. Table 5. EEPROM Status Field B0: Page 0 Write Protect B1: Page 1 Write Protect B2: Page 2 Write Protect B3: Page 3 Write Protect B4: Page 4 Write Protect B5: Reserved for TMEX B6: Reserved for TMEX B7: Reserved for TMEX R/W* 0001 Factory Programmed to FFh R 0002 Factory Programmed to FFh R 0003 Factory Programmed to FFh R 0004 Factory Programmed to FFh R 0005-0006 Reserved R 0007 Factory Programmed to 00h R * One time write to “0” WRITE STATUS [55h] The Write Status command is used to program the EEPROM Status data field. Only the Write Protect Page bits at address 0000h are writable. The other bytes are factory programmed to the values in Table 5. The Write Protect Page bits are set to logical 1’s when received from the factory. EEPROM page data can be programmed multiple times until its associated Write Protect Page bit is programmed to a logical 0. Once a Write Protect Page bit is programmed to a logical 0, it cannot be programmed back to a logical 1. Programming a Write Protect Page bit to a logical 0 prevents any future modification or overwriting of the data in the associated page. To protect page data from modification, the bus master writes the Write Status function command followed by one byte of status data containing the Write Protect Page bits (B7:B0). The status data must be written least significant bit to most significant bit, that is B0 to B7. Once the eighth bit of the status data is completed, the write operation cannot be undone. If the write operation is abandoned prior to completing the status data byte, the entire write sequence must be repeated after issuing a reset pulse.

appropriate Write Protect Page bits have been programmed. Table 6. EEPROM Memory and Status Function Commands Read data from lower 4 pages of the EEPROM Memory data field. continues to the end of page. considered correct only for TA2:TA1 = 0000h to 007Fh. unique serial number. The last eight bits are a cyclic redundancy check (CRC) of the first 56 bits (see Figure 2). the 1-Wire protocol detailed in this data sheet. Figure 2. 1-Wire Net Address Format

Figure 4. 1-Wire Bus Interface Circuitry more details, see the 1-Wire Signaling section below. followed by the 8-bit opcode for that command in square brackets. occurs when all slaves try to transmit at the same time (open drain produces a wired-AND result). discussion of a net address search, including an actual example (www.maxim-ic.com/iButtonBook). iButton is a registered trademark of Dallas Semiconductor.

are as follows: the initialization sequence (reset pulse followed by presence pulse), write 0, write 1, and read data. The bus master initiates all these types of signaling except the presence pulse. waits for tPDH and then transmits the presence pulse for tPDL. Figure 5. 1-Wire Initialization Sequence pulled low and held low for the duration of the write-time slot. A read-time slot is initiated when the bus master pulls the 1-Wire bus line from a logic-high level to a logic-low level. timing specifications in the Electrical Characteristics table for more information.

Figure 6. 1-Wire Write and Read Time Slots

Table 7. All Function Commands MAC and Compute Next Secret commands. Generates new global secret. Generates new unique secret. Write data to the EEPROM Status data field. Sets 1-Wire interface timings to STANDARD. Key: CCcomplete compatibility, NP:no programming pulse required on DS2704.

Table 8. Guide to Function Command Requirements

8 Write 0

DS2704: 1280-Bit EEPROM with SHA-1 Authentication 17 of 18 Figure 8: Compute Next Secret Function Command SKIP ROM Cmd Compute Next Secret Cmd 1-Wire Reset Presence Pulse tSHA Wait for MAC Computation Wait for EEPROM Programming tEEC Figure 9: Copy Scratchpad Function Command SKIP ROM Cmd Copy Scratchpad Cmd 1-Wire Reset Presence Pulse Wait for EEPROM Programming tEEC

16 Write

(TA1, TA2)

DS2704: 1280-Bit EEPROM with SHA-1 Authentication 18 of 18 Figure 10: Clear/Lock Secret, Set/Clear Overdrive Function Commands SKIP ROM Cmd Clear/Lock Secret Cmd or Set/Clear Overdrive Cmd 1-Wire Reset Presence Pulse Wait for EEPROM Copy Time tEEC

PACKAGE INFORMATION

(For the latest package outline information, go to www.maxim-ic.com/DallasPackInfo.)