E5561 ATMEL | Alldatasheet
Document overview
- Manufacturer or author: Provided By ALLDATASHEET.COM(FREE DATASHEET DOWNLOAD SITE)
- PDF pages: 26
Technical content
Features
- Low-power, Low-voltage CMOS IDIC/g210 Contactless Power Supply, Data Transmission and Programming of EEPROM Radio Frequency (RF): 100 kHz to 150 kHz, Typically 125 kHz Automatic Programmable Adaptation of Resonance Frequency Easy Synchronization with Special Terminators High-security Method Unilink Challenge Response Authentication by AUT64 Crypto Algorithm Encryption Time < 10 ms, Optional < 30 ms Programmable at 125 kHz 320-bit EEPROM Memory in 10 Blocks of 32 Bits Each Programmable Read/Write Protection Extensive Protection Against Contactless Malprogramming of the EEPROM Programming Time for One Block of the EEPROM Typically 16 ms Main Options Set by EEPROM: – Bit Rate [Bit/s]: RF/32, RF/64 – Encoding: Manchester, Bi-phase
Description
The e5561 is a member of Atmel’s IDentification IC (IDIC) family for applications where information has to be transmitted cont actlessly. The IDIC is connected to a tuned LC circuit for power supply and bi-directional data communication (Read/Write) to a base station. Atmel offers an LC circuit and a chip assembled in the form of a tran- sponder or tag. These units are small, smart and rugged data storage units. The e5561 is a Read/Write crypto IC for applications which demand higher security levels than standard R/W transponder ICs can offer. For that purpose, the e5561 has an encryption algorithm block which enables a base station to authenticate the tran- sponder. The base station transmits a random number to the e5561. This challenge is encrypted by both IC and base station. The e5561 sends back the result to the base station for comparison. As both should possess the same secret key, the results of this encryption are expected to be equal. Any attempt to fake the base station with a wrong transponder will be recognized immediately. The on-chip 320-bit EEPROM (10 blocks of 32 bits each) can be read and written blockwise by a base station. Two or four blocks contain the ID code and six memory blocks are used to store the crypto key as well as the read/write options. The crypto key and the ID code can be protected individually against overwriting. Likewise, the crypto key cannot be read out. 125 kHz is the typical operational frequency of a system using the e5561. Two read data rates are programmable. Reading occurs through damping the incoming RF field with an on-chip load. This damping is detected by the field-generating base station. Data transmission starts after power-up with the transmission of the ID code and con- tinues as long as the e5561 is powered. Writ ing is carried out with Atmel's writing method. To transmit data to the e5561, the base station has to interrupt the RF for a short time to create a field gap. The information is encoded in the number of clock cycles between two subsequent gaps. Standard Read/Write Crypto Identification IC e5561 Rev. 4699A–RFID–04/03
Figure 1. Transponder System Example Using e5561 Internal Modes The e5561 can be operated in several internal modes, each providing a special function. description is given in the section "Operating the e5561". reading out the configuration data bits of the EEPROM. data transmission will be designated as ’read’. stream and the type of modulation depend on the configuration loaded during start-up.
4699A–RFID–04/03 Every section consists of one or more EEPROM blocks. Programming is carried out by sending the programming data sequence to the e5561. When the base station sends data to the transponder, this direction of data transmission will be designated as 'write'. When the base station has sent the data sequence and the specified block has been programmed, the e5561 transmits the content of the programmed EEPROM block. The content is always sent in loop with terminator 1. The beginning of the data stream is indi- cated by a preburst. During programming, the e5561 monitors several fault and protection mechanisms. If a fault or a protection violation is detected, the e5561 switches to ID mode. Direct-access Mode If the base station transmits a special data sequence to the e5561, it will enter the direct- access mode. The base station can activate two different functions: Read the content of a single block of the EEPROM In this case, the e5561 transmits the block's content in loop, starting with a preburst followed by the terminator which is also used to indicate the beginning of the trans- mission of the specified block data. Reset the e5561 in case of all modes During direct-access mode, the e5561 monitors several fault and protection mecha- nisms. If a fault or a protection violation is detected, the e5561 switches to ID mode. Crypto Mode In crypto mode, a non-linear high-security encryption algorithm called AUT64 is used to authenticate the e5561. After the base station has identified the e5561 (i.e., read the ID code), the base station may authenticate the transponder by transmitting a challenge. Receiving this data sequence causes the e5561 to switch to crypto mode. This initiates the following actions: While calculating the AUT64 result, the transponder transmits the checksum of the challenge The e5561 generates the response from the calculated result of the AUT64 As soon as the calculation is finished, the e5561 interrupts the transmission of the checksum by sending a terminator The e5561 transmits the response in loop with a terminator back to the base station The base station can read the response and authentify the transponder. It is possible to interrupt the calculation of the AUT64 result by sending another data sequence (e.g., if the checksum was found to be wrong). During crypto mode, the e5561 monitors several fault and protection mechanisms. If a fault or a protection violation is detected, the e5561 enters ID mode. Stop Mode If two or more transponders are used simultaneously (e.g., in a manufacturing step), it might be useful to be able to set the transponders to a passive state. To avoid a commu- nication conflict, the base station has to transmit a special data sequence to the active transponder(s) forcing them to switch to stop mode. In stop mode, the e5561 switches off the damping as long as the RF field is applied. After a power-on reset or after having received the software-reset command, the e5561 enters start-up and ID mode again. During the data sequence of the stop mode, the e5561 monitors fault mechanisms. If a fault is detected, the e5561 enters ID mode.
The stop command can be disabled. Note: For correct stop-mode operation it is necessary that the field be switched off instantly. fault or a protection violation is detected, the e5561 enters ID mode. only possible by sending an uncorrect data sequence to the transponder. Figure 2. State Diagram of the e5561 (Overview) Note: This diagram provides only an overview. In reality, more transitions are possible.
Figure 3. Block Diagram
4699A–RFID–04/03 Adapt The e5561 is able to minimize the tolerance of the resonance frequency between the base station and the transponder by switching on-chip capacitors in parallel to the LC circuit of the transponder. By using a coil of approximately 4 mH for a resonance fre- quency of 125 kHz it is possible to tune the resonance frequency in a range of about 5%. The active value of the adaptation func tion is carried out automatically every time the e5561 enters the RF field or when the EEPROM is read out. This depends on a con- trol bit. The automatic adaptation stops when the optimized adaptation has been reached. This is between 1.0 ms and 5.0 ms (125 kHz) depending on the capacitance value required. The voltage at Coil 1/Coil 2 after start-up is shown in Figure 8. Adapt Bits: Details In addition to the adapt mode, which is executed during the start-up phase by the IC itself, it is possible to set the adapt bits in the EEPROM manually. Before carrying out the manual setting of the adapt bits, bit A in block 0 must be set to 1 (see Figure 8). The content of these 3 bits, that need to be defined, determines the transponder’s response frequenzy in a limited range. Bits are set by programming block 0 in the microcontroller. Bit-rate Generator The bit-rate generator can deliver bit rates of RF/32 and RF/64 for data transmission from the e5561 to the base station. Bit Decoder The bit decoder forms the signals needed for write operations and decodes the received data bits in the write data stream. Modulator The modulator consists of two data encoders and the terminator generator. There are two kinds of modulation: Manchester – Mid-bit rising edge = data H – Mid-bit falling edge = data L Bi-phase – Every bit creates a change, a data 0 creates an additional mid-bit change By using Bi-phase modulation, data transmission always starts with damping on. HV Generator The HV generator is a voltage pump which generates about 18 V for programming the EEPROM. Memory The memory of the e5561 is a 320-bit EEPROM which is arranged in 10 blocks of 32 bits each. All 32 bits of a block are programmed simultaneously. The programming volt- age is generated on-chip. Block 0 is reserved for basic configuration data. Blocks 1 to 9 are freely programmable. Blocks 1 to 4 are used for the ID code, blocks 5 to 8 contain the crypto key. In password mode, bits 4 to 31 of block 9 contain the password; bits 0 to 3 of block 9 contain the cus- tomer-configuration data. If no password is required, the corresponding bits can be programmed freely. Note: Data from the memory is transmitted serially, starting with the least significant bit.
4699A–RFID–04/03 Protection Mechanisms Several protection mechanisms are implemented into the e5561. These are mainly: Error mechanisms to detect a fault. These mechanisms are always enabled. Programmable protection mechanisms. These mechanisms are optional. When used, they provide protection against attempts to break the security system. Password Protection If the password protection is enabled, the e5561 remains in ID mode even if it has received a correct write sequence. The only possible operation is to modify the content of block 9 by sending the correct password bits. In all other cases, an error handling pro- cedure is started and the e5561 enters ID mode. Lock-bit Protection A lock-bit is a physical part of the EEPROM's content and is under user control. The lock-bit protection mechanism has two different effects: Avoid programming (modifying data) of the EEPROM's blocks Avoid reading out the crypto key from the EEPROM using the direct-access mode If the base station tries to read out the crypto key and the corresponding lock-bit is set, the e5561 will enter ID mode immediately. Once the crypto key lock-bit is set, the crypto key can not be modified or read out any more. There are several lock-bits available, each affecting a special data region of the EEPROM. The main groups of lock-bits are: Lock-bits to inhibit programming of the specified blocks of the EEPROM Lock-bits to inhibit programming of the specified blocks of a specific address range In both cases, an attempt to modify a data region protected by a lock-bit will cause an error handling procedure (i.e., the e5561 enters ID mode) Stop Mode The stop mode can also be used as a protection mechanism, e.g., during configuration at manufacturing. The base station can configure the transponders one by one, forcing them into stop mode after programming. In this way, transponders can be programmed even if there are other transponders in the RF field at the same time. Operating the e5561 General The basic functions of the e5561 are: Supply the IC from the coil Read data from the EEPROM to the base station Authenticate the IC Receive commands from the base station and program the received data into the EEPROM. Several write errors can be detected to protect the memory from being overwritten with uncorrect data. A password function is implemented ensuring that only authorized peo- ple can operate the IC. Operating modes: ID mode: the e5561 sends the ID code to the base station Programming mode: the e5561 programs the EEPROM with data bits received from the base station Direct-access mode: the e5561 sends the content of single blocks of the EEPROM to the base station
Figure 16. OP Codes field clocks without any gap. Figure 17. Programming Mode Write Sequence Figure 18. Programming
10 Data bits 310 ADR 30 EOT
Figure 23. Coil Voltage in Direct-access Mode Reset command is also accepted during stop mode. Figure 24. Software Reset Figure 25. After the OPcode 01, the challenge is sent to the e5561 (LSB first). Figure 25. Crypto Mode Write Sequence been computed, the base station can read the response in loop with the terminator 1. crypto mode is shown in Figure 26. Figure 26. Crypto Mode Datastream sequence read FFh read blockTerm.
01 Challenge bits 630 EOT
Figure 27. Checksum Figure 28. Coil Voltage in Crypto Mode cuted 8 or 24 times. This feature can be set at block 0, bit 7. special data sequence to the active transponder(s) forcing them to enter the stop mode. applied. After a power-on reset, the e5561 enters the start-up and the ID mode again. An other possibility to exit the stop mode is to send the software reset (see Figure 30). This command results in a new initialization of the IC. Figure 29. Stop Mode Data Sequence Figure 30. Write Sequence to Disable Password Function without knowing the password. operations are posible, i.e., reading the ID code in ID mode or authentication.
11 EOT
10 Password 314 EOTXXXX 1 0 0 1
4699A–RFID–04/03 For programming or direct-access mode, the password function has to be disabled by receiving the password. If this function is enabled, the customer configuration can only be changed by an autho- rized person using the correct password of the e5561. During password mode, the e5561 monitors several fault and protection mechanism. If a fault or a protection violation is detected, the e5561 enters ID mode. Error Handling Several error conditions can be detected to ensure that only valid operations affect the e5561. Errors while Writing Data There are four detectable errors possible during writing data to the e5561: Field gap was not detected Wrong number of field clocks between two gaps, e.g., 37 FCs The OPcode is not valid (11) The number of bits received is incorrect; valid bit counts are: – programming mode: 38 bits – direct-access mode: 6 bits – crypto mode: 66 bits – stop mode: 2 bits If any of these four conditions is detected, the e5561 stops writing and enters ID mode. This can easily be analyzed using the damping which is usually on during writing. It changes according to the selected modulation scheme in ID mode. Errors During Programming Mode If the writing sequence has been transmitted successfully, there are three errors that may prevent the e5561 from programming the data to the EEPROM: The programming voltage V PP is too low, i.e., the field strength is not high enough The lock-bit of the adressed block is set The password function is enabled In these cases, the procedure stops immediately after the error has been detected and the IC reverts to ID mode. Errors During Direct-access Mode In addition to the possible errors mentioned before, two errors may occur in direct- access mode: The lock-bit of the addressed block 5 to 8 is set The password function is enabled In these cases, the IC enters ID mode after the end of the writing sequence. Errors During Crypto Mode In crypto mode, ONE error mechanism is active, that may prevent the e5561 from send- ing the correct response: Error during the crypto writing sequence The e5561 will enter ID mode immediately if an error in the writing sequence is detected. If the password function is enabled, the e5561 enters ID mode after having completed the writing sequence.
a certain number of combinations. Figure 31. Simplified Error Handling of the e5561
Figure 32. Authentication Procedure
4699A–RFID–04/03 Initialization Before using the e5561 in crypto mode, it has to be initialized. First, the crypto key to be used by the crypto algorithm has to be generated by the key- generating program. This program guarantees that each crypto key is unique, no other e5561 has the same key. This key has to be stored in the memory (block 5 - block 8) of the e5561 via the programming mode. Once the crypto key is locked, it can not be over- written or read out anymore with direct-access mode. For correct authentication it is necessary that base station and transponder both use the same key. Therefore, the base station needs to know which transponder is currently in the field. Only then, the base station can select the key corresponding to this particular transponder. For this identification the e5561 sends a string of data after it has been powered up. This ID code must also be stored in the e5561. Starting the Authentication After power-up the various modes (bit rate, encoding) are read out of block 0. Then, the e5561 transmits the ID code to identify itself. Thereby, the base station can identify the transponder and knows which crypto key to use. The base station forces the e5561 into crypto mode by sending the OPcode 01 followed by a 64-bit string, the challenge. Challenge The base station generates a 64-bit random number R. This number is the starting value of the actual encryption algorithm. To improve security, this random number is not sent directly to the transponder, but is encrypted by means of a part of the crypto key. The encoded result R' is then transmitted as challenge to the transponder. Once the tran- sponder has received the encoded random number R', it recovers the random number R originally generated by the base station. Both devices, the base station as well as the transponder, then start with the encryption of this number. If the number of received bits is incorrect, the e5561 leaves the crypto mode and enters read mode immediatly, trans- mitting the ID code. Checksum For verification of the received challenge, the e5561 sends a checksum (representing the number of 1 of the challenge) with a special pattern in loop until the encryption is fin- ished (less than 10 ms - optionally 30 ms). Encryption For encryption, the optimized high-security algorithm AUT64 is used. The elementary parts of this 64-bit block cipher are transposition and substitution (Figure 34). For more detailed information on this algorithm additi onal documentation is provided. The entire algorithm AUT64 is executed 24 times. At each of these 8/24 times, another key is gen- erated out of the crypto key. Therefore, the algorithm keeps changing and a high- security level is achieved. This is confirmed by statistical analysis. For more detailed information, the description 'The Encryption Process of the e5561' can be provided. Response The 64-bit result of the algorithm is reduced to 32 bits using logical operations. This 32- bit response is sent back to the base station for comparison. If the correct keys were used, the result generated inside the base station is identical to the result sent by the e5561. The response is transmitted in loop including the terminator until the IC is pow- ered by the RF field. This gives the base station enough time to check the validation of the response.
Figure 33. Atmels' Crypto Algorithm AUT64
Figure 34. Authentication Example
4699A–RFID–04/03 Stresses above those listed under "Absolute Maximum Ratings" may cause permanent damage to the device. Absolute Maximum Ratings All voltage are given corresponding to VSS. Parameters Symbol Value Unit Supply voltage V DD -0.3 to +7.0 V Input voltage V IN VSS -0.3 /g163 VIN /g163 VDD +0.3 V Current into Coil1/Coil2 I C1/C2 10 mA Power dissipation (dice)(1) Ptot 100 mW Operating temperature range T amb -40 to +85 /g176C Storage temperature range(2) Tstg -40 to +125 /g176C Assembly temperature (t /g163 5 min) T ass 170 /g176C Notes: 1. Free-air condition. Time of application: 1 s. 2. Data retention reduced. Operating Range Tamb = 25°C; reference terminal is VSS; DC operating voltage VDD - VSS = 2 V (unless otherwise noted). Parameters Test Conditions Symbol Min. Typ. Max. Unit RF frequency range f RF 100 125 150 kHz Supply current fRF = 125 kHz, read and write I DD 15 µA fRF = 125 kHz, programming I DD 100 µA No clock I DD 100 250 500 nA Clamp voltage Current into Coil1/Coil2 = 5 mA V cl 7.5 9.0 10.2 V Equivalent coil input capacitance (without self-adapt) C1,2 30 pF Programming voltage V PP 15 16 19 V Programming time f RF = 125 kHz t PP 16 ms Data retention t retention 10 Y ears Programming cycles n cycle 100,000 – Lowest operating voltage for programming Vmfs 1.8 V
4699A–RFID–04/03 Figure 35. Application Example Note: For normal (coil-driven) operation, the e5561 needs only Coil1 and Coil2.
Ordering Information
Extended Type Number Package Remarks e5561A-DOW DOW – Pads Name Pad Window Function Coil1 136 /g180/g32136 m2 1st coil pad Coil2 136 /g180/g32136 m2 2nd coil pad VDD 78 /g180 78 m2 Positive supply voltage VSS 82 /g180 82 m2 Negative supply voltage (GND) Coil1 Coil2 4930 /g109m 1600 /g109m VDD VSS Test pads e5561
Printed on recycled paper. © Atmel Corporation 2003. Atmel Corporation makes no warranty for the use of its products, other than those expressly contained in the Company’s standard warranty which is detailed in Atmel’s Terms and Conditions located on the Company’s web site. The Company assumes no responsibility for any errors which may appear in this document, reserves the right to change de vices or specifications detailed herein at any time without n otice, and does not make any commitment to update the information contained herein. No licenses to patents or other intellectual property of At mel are granted by the Company in connection with the sale of Atmel products, ex pressly or by implication. Atmel’s products are not authorized for use as critical components in life support devices or systems. Atmel Headquarters Atmel Operations Corporate Headquarters
2325 Orchard Parkway
San Jose, CA 95131 TEL 1(408) 441-0311 FAX 1(408) 487-2600 Europe Atmel Sarl Route des Arsenaux 41 Case Postale 80 CH-1705 Fribourg Switzerland TEL (41) 26-426-5555 FAX (41) 26-426-5500 Asia Room 1219 Chinachem Golden Plaza
77 Mody Road Tsimhatsui
TEL (852) 2721-9778 FAX (852) 2722-1369 Japan 9F, Tonetsu Shinkawa Bldg. 1-24-8 Shinkawa Chuo-ku, Tokyo 104-0033 Japan TEL (81) 3-3523-3551 FAX (81) 3-3523-7581 Memory San Jose, CA 95131 TEL 1(408) 441-0311 FAX 1(408) 436-4314 Microcontrollers San Jose, CA 95131 TEL 1(408) 441-0311 FAX 1(408) 436-4314 La Chantrerie BP 70602
44306 Nantes Cedex 3, France
13106 Rousset Cedex, France
1150 East Cheyenne Mtn. Blvd. Colorado Springs, CO 80906 TEL 1(719) 576-3300 FAX 1(719) 540-1759 Scottish Enterprise Technology Park Maxwell Building East Kilbride G75 0QR, Scotland TEL (44) 1355-803-000 FAX (44) 1355-242-743 RF/Automotive Theresienstrasse 2 Postfach 3535
74025 Heilbronn, Germany
FAX (49) 71-31-67-2340 1150 East Cheyenne Mtn. Blvd. Colorado Springs, CO 80906 TEL 1(719) 576-3300 FAX 1(719) 540-1759 Biometrics/Imaging/Hi-Rel MPU/ High Speed Converters/RF Datacom Avenue de Rochepleine BP 123
38521 Saint-Egreve Cedex, France
literature@atmel.com Web Site http://www.atmel.com 4699A–RFID–04/03 xM Atmel ® is the registered trademark of Atmel. IDIC/g210 stands for IDentification Integrated Circuit and is a registered trademark of Atmel Germany GmbH. Other terms and product names may be the trademarks of others.