DS28C36 MAXIM | Alldatasheet

Document overview

  • Manufacturer or author: Provided By ALLDATASHEET.COM(FREE DATASHEET DOWNLOAD SITE)
  • PDF pages: 5

Technical content

The DS28C36 is a secure authenticator that provides a core set of cryptographic tools derived from integrated asymmetric (ECC-P256) and symmetric (SHA-256) secu- rity functions. In addition to the security services provided by the hardware implemented crypto engines, the device integrates a FIPS/NIST true random number genera - tor (RNG), 8Kb of secured EEPROM, a decrement-only counter, two pins of configurable GPIO, and a unique 64-bit ROM identification number (ROM ID). The ECC public/private key capabilities operate from the NIST defined P-256 curve and include FIPS 186 compliant ECDSA signature generation and verification to support a bidirectional asymmetric key authentication model. The SHA-256 secret-key capabilities are compli - ant with FIPS 180 and are flexibly used either in conjunc - tion with ECDSA operations or independently for multiple HMAC functions. Two GPIO pins can be independently operated under command control and include configurability supporting authenticated and nonauthenticated operation including an ECDSA-based crypto-robust mode to support secure- boot of a host processor. DeepCover embedded security solutions cloak sensitive data under multiple layers of advanced security to provide the most secure key storage possible. To protect against device-level security attacks, invasive and noninvasive countermeasures are implemented including active die shield, encrypted storage of keys, and algorithmic methods.

Applications

  • IoT Node Crypto-Protection
  • Accessory and Peripheral Secure Authentication
  • Secure Storage of Cryptographic Keys for a Host Controller
  • Secure Boot or Download of Firmware and/or System Parameters Benefits and Features
  • ECC-256 Compute Engine
  • FIPS 186 ECDSA P256 Signature and Verification
  • ECDH Key Exchange with Authentication Prevents Man-in-the-Middle Attacks
  • ECDSA Authenticated R/W of Configurable Memory
  • FIPS 180 SHA-256 Compute Engine
  • HMAC
  • SHA-256 OTP (One-Time Pad) Encrypted R/W of Configurable Memory Through ECDH Established Key
  • Two GPIO Pins with Optional Authentication Control
  • Open-Drain, 4mA/0.4V
  • Optional SHA-256 or ECDSA Authenticated On/Off and State Read
  • Optional ECDSA Certificate to Set On/Off after Multiblock Hash for Secure Boot
  • RNG with NIST SP 800-90B Compliant Entropy Source with Function to Read Out
  • Optional Chip Generated Pr/Pu Key Pairs for ECC Operations
  • 17-Bit One-Time Settable, Nonvolatile Decrement- Only Counter with Authenticated Read
  • 8Kbits of EEPROM for User Data, Keys, and Certificates
  • Unique and Unalterable Factory Programmed 64-Bit Identification Number (ROM ID)
  • Optional Input Data Component to Crypto and Key Operations
  • I2C Communication, 100kHz and 400kHz
  • Operating Range: 3.3V ±10%, -40°C to +85°C
  • 6-Pin TDFN Package Ordering Information appears at end of data sheet. Typical Application Circuit appears at end of data sheet. 19-8546; Rev 0; 6/16 DS28C36 DeepCover Secure Authenticator EVALUATION KIT AVAILABLE ABRIDGED DATA SHEET

Electrical Characteristics

(TA = -40°C to +85°C.) (Note 1) PARAMETER SYMBOL CONDITIONS MIN TYP MAX UNITS Supply Voltage VCC 2.97 3.3 3.63 V Active Supply Current ICC (Note 2) 300 µA Standby Supply Current ICCS 250 µA Computation Current ICMP Refer to the full data sheet mA GPIO Output Low PIOVOL 0.4 V Input Low PIOVIL -0.3 VCC x 0.3V V Input High PIOVIH VCC + 0.7V VCC + 0.3V V Leakage current IL -10 10 µA ECC ENGINE Generate ECDSA Signature Time tGES Refer to the full data sheet ms Generate ECC Key Pair tGKP ms Verify ECDSA Signature or Compute ECDH Time tVES ms SHA-256 ENGINE Computation Time (HMAC or RNG) tCMP Refer to the full data sheet ms EEPROM W/E Endurance NCY TA = +25°C (Notes 4, 5) 100K — Read Memory Time tRM 1 ms Write Memory Time tWM Refer to the full data sheet ms Data Retention tDR TA = +85°C (Notes 6, 7) 10 years I2C SCL AND SDA PINS (Note 8) Low-Level Input Voltage VIL -0.3 0.15 × VCC V High-Level Input Voltage VIH 0.7 × VCC VCC + 0.3V V Hysteresis of Schmitt Trigger Inputs VHYS (Note 9) 0.05 × VCC V Low-Level Output Voltage at 4mA Sink Current VOL 0.4 V DS28C36 DeepCover Secure Authenticator www.maximintegrated.com Maxim Integrated │ 2 Absolute Maximum Ratings Stresses beyond those listed under “Absolute Maximum Ratings” may cause permanent damage to the device. These are stress ratings only, and functional operation of the device at these or any other conditions beyond those indicated in the operational sections of the specifications is not implied. Exposure to absolute maximum rating conditions for extended periods may affect device reliability. ABRIDGED DATA SHEET

(TA = -40°C to +85°C.) (Note 1) Note 1: Limits are 100% production tested at T A = +25°C and/or TA = +85°C. Limits over the operating temperature range and relevant supply voltage range are guaranteed by design and characterization. Typical values at +25 °C. Note 2: Operating current continuously reading memory at 400kHz with < 25ns rise and fall times on SDA and SCL. Note 3: Refer to the full data sheet. Note 4: Write-cycle endurance is tested in compliance with JESD47H. Note 5: Not 100% production tested; guaranteed by reliability qualification. Note 6: Data retention is rested in compliance with JESD47H. Note 7: Guaranteed by 100% production test at elevated temperature for a shorter time; equivalence of this production test to the data sheet limit at operating temperature range is established by reliability testing. Note 8: All I2C timing values are referred to V IH(MIN) and VIL(MAX) levels, except for tOF, which is measured from V IH(MIN) to 0.3 x VCC. Note 9: Guaranteed by design and/or characterization only. Not production tested. Note 10: System requirement. Note 11: The DS28C36 provides a hold time of at least 100ns for the SDA signal (referred to the V IH(MIN) of the SCL signal) to brigde the undefined regin of the falling edge of SCL. The master can provide a hold time of 0ns when writing to the device. Note 12: The maximum tHD:DAT has only to be met if the device does not stretch the low period (t LOW) of the SCL signal. If the clock stretches the SCL, the data must be valid by the setup time before it releases the clock (I 2C-bus specification Rev. 03, 19 June 2007). Note 13: A fast-mode I2C-bus device can be used in a standard-mode I 2C-bus system, but the requirement t SU:DAT ≥ 250ns must then be met. This is automatically the case if the device does not stretch the low period of the SCL signal. If such a device does stretch the low period of the SCL signal, it must output the next data bit to the SDA line tr max + t SU:DAT = 1000 + 250 = 1250ns (according to the standard-mode I 2C-bus specification) before the SCL line is released. Also, the acknowl - edge timing must meet this set-up time. (I 2C-bus specification Rev. 03, 19 June 2007) Note 14: CB = total capacitance of one bus line in pF. The maximum bus capacitance allowable can vary from this value depending on the actual operating voltage and frequency of the application (I 2C-bus specification Rev. 03, 19 June 2007). Note 15: I2C communication should not take place for max t OSCWUP time following a power-on reset. PARAMETER SYMBOL CONDITIONS MIN TYP MAX UNITS Output Fall Time from VIH(MIN) to VIL(MAX) with a Bus Capacitance from 10pF to 400pF tOF (Note 9) 30 ns Pulse Width of Spikes that are Suppressed by the Input Filter tSP (Note 9) 50 ns Input Current with an Input Voltage Between 0.1VCCmax and 0.9VCCmax II -10 +10 µA Input Capacitance CI (Note 9) 10 pF SCL Clock Frequency fSCL (Note 10) 0 400 kHz Hold Time (Repeated) START Condition tHD:STA After this period, the first clock pulse is generated 0.6 µs Low Period of the SCL Clock tLOW 1.3 µs High Period of the SCL Clock tHIGH 0.6 µs Setup Time for a Repeated START Condition tSU:STA 0.6 µs Data Hold Time tHD:DAT (Notes 9, 11, 12) 0.9 µs Data Setup Time tSU:DAT (Note 13) 100 ns Setup Time for STOP Condition tSU:STO 0.6 µs Bus Free Time Between a STOP and START Condition tBUF 1.3 µs Capacitive Load for Each Bus Line CB (Notes 10, 14) 400 pF Warm-Up Time tOSCWUP (Note 15) 250 µs DS28C36 DeepCover Secure Authenticator www.maximintegrated.com Maxim Integrated │ 3 Electrical Characteristics (continued) ABRIDGED DATA SHEET

1 SCL I2C CLK

2 SDA I2C Data

3 GND Ground

4 PIOB General-Purpose IO

5 PIOA General-Purpose IO

6 VCC Supply Voltage

6 VCC

5 PIOA

4 PIOB

(3mm x 3mm) TOP VIEW DS28C36 DS28C36 DeepCover Secure Authenticator www.maximintegrated.com Maxim Integrated │ 4 Pin Configuration Pin Description ABRIDGED DATA SHEET

+Denotes a lead(Pb)-free/RoHS-compliant package. T= Tape and reel. *EP = Exposed pad. PART TEMP RANGE PIN-PACKAGE DS28C36Q+T -40°C to +85°C 6 TDFN-EP* (2.5k pcs) PACKAGE TYPE PACKAGE CODE OUTLINE NO. LAND PATTERN NO.

6 TDFN-EP* T633+2 21-0137 90-0058

3.3V SCL PIOA PIOB SDA VCC GND µC IO IO RP I2C PORT DS28C36 Maxim Integrated cannot assume responsibility for use of any circuitry other than circuitry entirely embodied in a Maxim Integrated product. No circuit patent licenses are implied. Maxim Integrated reserves the right to change the circuitry and specifications without notice at any time. The parametric values (min and max limits) shown in the Electrical Characteristics table are guaranteed. Other parametric values quoted in this data sheet are provided for guidance. Maxim Integrated and the Maxim Integrated logo are trademarks of Maxim Integrated Products, Inc. DS28C36 DeepCover Secure Authenticator © 2016 Maxim Integrated Products, Inc. │ 5 Typical Application Circuit Ordering Information Package Information For the latest package outline information and land patterns (footprints), go to www.maximintegrated.com/packages. Note that a “+”, “#”, or “-” in the package code indicates RoHS status only. Package drawings may show a different suffix character, but the drawing pertains to the package regardless of RoHS status. For pricing, delivery, and ordering information, please contact Maxim Direct at 1-888-629-4642, or visit Maxim Integrated’s website at www.maximintegrated.com. ABRIDGED DATA SHEET