DATASHEET SEARCH SITE | WWW.ALLDATASHEET.COM
Document overview
- Manufacturer or author: Provided By ALLDATASHEET.COM(FREE DATASHEET DOWNLOAD SITE)
- PDF pages: 28
Technical content
2001 Microchip Technology Inc. DS21137F-page 1 HCS300
FEATURES
- Programmable 28-bit serial number
- Programmable 64-bit encryption key
- Each transmission is unique
- 66-bit transmission code length
- 32-bit hopping code
- 28-bit serial number, 4-bit button code, 2-bit status
- Crypt keys are read protected Operating
- 2.0V - 6.3V operation
- Four button inputs
- No additional circuitry required
- 15 functions available
- Selectable baud rate
- Automatic code word completion
- Low battery signal transmitted to receiver
- Non-volatile synchronization data Other
- Easy-to-use programming interface
- On-chip EEPROM
- On-chip oscillator and timing components
- Button inputs have internal pull-down resistors
- Current limiting on LED output
- Low external component cost Typical Applications The HCS300 is ideal for Remote Keyless Entry (RKE) applications. These applications include:
- Automotive RKE systems
- Automotive alarm systems
- Automotive immobilizers
- Gate and garage door openers
- Identity tokens
- Burglar alarm systems
DESCRIPTION
The HCS300 from Microchip Technology Inc. is a code hopping encoder designed for secure Remote Keyless Entry (RKE) systems. The HCS300 utilizes the KEE LOQ code hopping technology, incorporating high security, a small package outline and low cost. The HCS300 is a perfect solution for unidirectional remote keyless entry systems and access control systems. PACKAGE TYPES HCS300 BLOCK DIAGRAM The HCS300 combines a 32-bit hopping code, generated by a nonlinear encryption algorithm, with a 28-bit serial number and 6 information bits to create a 66-bit code word. The code word length eliminates the threat of code scanning and the code hopping mecha- nism makes each transmission unique, thus rendering code capture and resend schemes useless. VDD LED PWM VSS PDIP, SOIC HCS300 VSS VDD Oscillator RESET circuit LED driver Controller Power latching and switching Button input port 32-bit shift register EncoderEEPROM PWM LED S3 S2 S1 S0 K EE L OQ ® Code Hopping Encoder
DS21137F-page 2 2001 Microchip Technology Inc. The crypt key, serial number and configuration data are stored in an EEPROM array which is not accessible via any external connection. The EEPROM data is pro- grammable but read-protected. The data can be veri- fied only after an automatic erase and programming operation. This protects against attempts to gain access to keys or manipulate synchronization values. The HCS300 provides an easy-to-use serial interface for programming the necessary keys, system parame- ters and configuration data.
1.0 SYSTEM OVERVIEW
The following is a list of key terms used throughout this data sheet. For additional information on KEE LOQ and Code Hopping, refer to Technical Brief 3 (TB003).
- RKE - Remote Keyless Entry
- Button Status - Indicates what button input(s) activated the transmission. Encompasses the 4 button status bits S3, S2, S1 and S0 (Figure 4-2).
- Code Hopping - A method by which a code, viewed externally to the system, appears to change unpredictably each time it is transmitted.
- Code word - A block of data that is repeatedly transmitted upon button activation (Figure 4-1).
- Transmission - A data stream consisting of repeating code words (Figure 8-1).
- Crypt key - A unique and secret 64-bit number used to encrypt and decrypt data. In a symmetri- cal block cipher such as the K EE LOQ algorithm, the encryption and decryption keys are equal and will therefore be referred to generally as the crypt key.
- Encoder - A device that generates and encodes data.
- Encryption Algorithm - A recipe whereby data is scrambled using a crypt key. The data can only be interpreted by the respective decryption algorithm using the same crypt key.
- Decoder - A device that decodes data received from an encoder.
- Decryption algorithm - A recipe whereby data scrambled by an encryption algorithm can be unscrambled using the same crypt key.
- Learn – Learning involves the receiver calculating the transmitter’s appropriate crypt key, decrypting the received hopping code and storing the serial number, synchronization counter value and crypt key in EEPROM. The K EE LOQ product family facil- itates several learning strategies to be imple- mented on the decoder. The following are examples of what can be done. - Simple Learning The receiver uses a fixed crypt key, common to all components of all systems by the same manufacturer, to decrypt the received code word’s encrypted portion. - Normal Learning The receiver uses information transmitted during normal operation to derive the crypt key and decrypt the received code word’s encrypted portion. - Secure Learn The transmitter is activated through a special button combination to transmit a stored 60-bit seed value used to generate the transmitter’s crypt key. The receiver uses this seed value to derive the same crypt key and decrypt the received code word’s encrypted portion.
- Manufacturer’s code – A unique and secret 64- bit number used to generate unique encoder crypt keys. Each encoder is programmed with a crypt key that is a function of the manufacturer’s code. Each decoder is programmed with the manufac- turer code itself. The HCS300 code hopping encoder is designed specif- ically for keyless entry systems; primarily vehicles and home garage door openers. The encoder portion of a keyless entry system is integrated into a transmitter, carried by the user and operated to gain access to a vehicle or restricted area. The HCS300 is meant to be a cost-effective yet secure solution to such systems, requiring very few external components (Figure 2-1). Most low-end keyless entry transmitters are given a fixed identification code that is transmitted every time a button is pushed. The number of unique identification codes in a low-end system is usually a relatively small number. These shortcomings provide an opportunity for a sophisticated thief to create a device that ‘grabs’ a transmission and retransmits it later, or a device that quickly ‘scans’ all possible identification codes until the correct one is found. The HCS300 on the other hand, employs the K EE LOQ code hopping technology coupled with a transmission length of 66 bits to virtually eliminate the use of code ‘grabbing’ or code ‘scanning’. The high security level of the HCS300 is based on the patented K EE LOQ technol- ogy. A block cipher based on a block length of 32 bits and a key length of 64 bits is used. The algorithm obscures the information in such a way that even if the transmission information (before coding) differs by only one bit from that of the previous transmission, the next
DS21137F-page 4 2001 Microchip Technology Inc. FIGURE 1-2: BUILDING THE TRANSMITTED CODE WORD (ENCODER) FIGURE 1-3: BASIC OPERATION OF RECEIVER (DECODER) NOTE: Circled numbers indicate the order of execution. Button Press Information EEPROM Array
32 Bits
Encrypted DataSerial Number Transmitted Information Crypt Key Sync Counter Serial Number KEE LOQ Encryption Algorithm Button Press Information EEPROM Array Manufacturer Code 32 Bits of Encrypted DataSerial Number Received Information Decrypted Synchronization Counter Check for Match Sync Counter Serial Number KEE LOQ Decryption Algorithm Check for Match2 Perform Function Indicated by button press 5 Crypt Key
2001 Microchip Technology Inc. DS21137F-page 5 HCS300
2.0 ENCODER OPERATION
As shown in the typical application circuits (Figure 2-1), the HCS300 is a simple device to use. It requires only the addition of buttons and RF circuitry for use as the transmitter in your security application. A description of each pin is given in Table 2-1. FIGURE 2-1: TYPICAL CIRCUITS TABLE 2-1: PIN DESCRIPTIONS The HCS300 will wake-up upon detecting a button press and delay approximately 10 ms for button debounce (Figure 2-2). The synchronization counter, discrimination value and button information will be encrypted to form the hopping code. The hopping code portion will change every transmission, even if the same button is pushed again. A code word that has been transmitted will not repeat for more than 64K transmissions. This provides more than 18 years of use before a code is repeated; based on 10 operations per day. Overflow information sent from the encoder can be used to extend the number of unique transmissions to more than 192K. If in the transmit process it is detected that a new but- ton(s) has been pressed, a RESET will immediately occur and the current code word will not be completed. Please note that buttons removed will not have any effect on the code word unless no buttons remain pressed; in which case the code word will be completed and the power-down will occur. FIGURE 2-2: ENCODER OPERATION Name Pin Number Description S0 1 Switch input 0 S1 2 Switch input 1 S2 3 Switch input 2 / Clock pin when in Programming mode S3 4 Switch input 3 V SS 5 Ground reference PWM 6 Pulse Width Modulation (PWM) output pin / Data pin for Programming mode LED
7 Cathode connection for LED
VDD 8 Positive supply voltage VDD Tx out LED VDD PWM Vss 2 button remote control VDD Tx out LED VDD PWM Vss 5 button remote control (Note) B4 B3 B2 B1 B0 Note: Up to 15 functions can be implemented by pressing more than one button simultaneously or by using a suitable diode array. Power-Up RESET and Debounce Delay (10 ms) Sample Inputs Update Sync Info Encrypt With Load Transmit Register Buttons Added All Buttons Released (A button has been pressed) Transmit Stop No Yes No Yes Crypt Key Complete Code Word Transmission
DS21137F-page 6 2001 Microchip Technology Inc.
3.0 EEPROM MEMORY
The HCS300 contains 192 bits (12 x 16-bit words) of EEPROM memory (Table 3-1). This EEPROM array is used to store the encryption key information, synchronization value, etc. Further descriptions of the memory array is given in the following sections. TABLE 3-1: EEPROM MEMORY MAP
3.1 KEY_0 - KEY_3 (64-Bit Crypt Key)
The 64-bit crypt key is used to create the encrypted message transmitted to the receiver. This key is calcu- lated and programmed during production using a key generation algorithm. The key generation algorithm may be different from the K EE LOQ algorithm. Inputs to the key generation algorithm are typically the transmit- ter’s serial number and the 64-bit manufacturer’s code. While the key generation algorithm supplied from Microchip is the typical method used, a user may elect to create their own method of key generation. This may be done providing that the decoder is programmed with the same means of creating the key for decryption purposes.
3.2 SYNC (Synchronization Counter)
This is the 16-bit synchronization value that is used to create the hopping code for transmission. This value will increment after every transmission.
3.3 Reserved
Must be initialized to 0000H.
3.4 SER_0, SER_1
(Encoder Serial Number) SER_0 and SER_1 are the lower and upper words of the device serial number, respectively. Although there are 32 bits allocated for the serial number, only the lower order 28 bits are transmitted. The serial number is meant to be unique for every transmitter.
3.5 SEED_0, SEED_1 (Seed Word)
The 2-word (32-bit) seed code will be transmitted when all three buttons are pressed at the same time (see Figure 4-2). This allows the system designer to imple- ment the secure learn feature or use this fixed code word as part of a different key generation/tracking pro- cess.
3.5.1 AUTO-SHUTOFF TIMER ENABLE
The Most Significant bit of the serial number (Bit 31) is used to turn the Auto-shutoff timer on or off. This timer prevents the transmitter from draining the battery should a button get stuck in the on position for a long period of time. The time period is approximately 25 seconds, after which the device will go to the Time- out mode. When in the Time-out mode, the device will stop transmitting, although since some circuits within the device are still active, the current draw within the Shutoff mode will be higher than Standby mode. If the Most Significant bit in the serial number is a one, then the Auto-shutoff timer is enabled, and a zero in the Most Significant bit will disable the timer. The length of the timer is not selectable. WORD ADDRESS MNEMONIC DESCRIPTION
0 KEY_0 64-bit encryption key
(word 0) LSb’s
1 KEY_1 64-bit encryption key
(word 1)
2 KEY_2 64-bit encryption key
(word 2)
3 KEY_3 64-bit encryption key
(word 3) MSb’s
4 SYNC 16-bit synchronization
5 RESERVED Set to 0000H
6 SER_0 Device Serial Number
(word 0) LSb’s
7 SER_1
(Note) Device Serial Number (word 1) MSb’s
8 SEED_0 Seed Value (word 0)
9 SEED_1 Seed Value (word 1)
10 RESERVED Set to 0000H
11 CONFIG Config Word
Note: The MSB of the serial number contains a bit used to select the Auto-shutoff timer.
2001 Microchip Technology Inc. DS21137F-page 7 HCS300
3.6 CONFIG (Configuration Word)
The Configuration Word is a 16-bit word stored in EEPROM array that is used by the device to store information used during the encryption process, as well as the status of option configurations. The following sections further explain these bits. TABLE 3-2: CONFIGURATION WORD
3.6.1 DISCRIMINATION VALUE
(DISC0 TO DISC9) The discrimination value aids the post-decryption check on the decoder end. It may be any value, but in a typical system it will be programmed as the 12 Least Significant bits of the serial number. Values other than this must be separately stored by the receiver when a transmitter is learned. The discrimination bits are part of the information that form the encrypted portion of the transmission (Figure 4-2). After the receiver has decrypted a transmission, the discrimination bits are checked against the receiver’s stored value to verify that the decryption process was valid. If the discrimi- nation value was programmed as the 12 LSb’s of the serial number then it may merely be compared to the respective bits of the received serial number; saving EEPROM space.
3.6.2 OVERFLOW BITS
(OVR0, OVR1) The overflow bits are used to extend the number of possible synchronization values. The synchronization counter is 16 bits in length, yielding 65,536 values before the cycle repeats. Under typical use of 10 operations a day, this will provide nearly 18 years of use before a repeated value will be used. Should the system designer conclude that is not adequate, then the overflow bits can be utilized to extend the number of unique values. This can be done by programming OVR0 and OVR1 to 1s at the time of production. The encoder will automatically clear OVR0 the first time that the synchronization value wraps from 0xFFFF to 0x0000 and clear OVR1 the second time the counter wraps. Once cleared, OVR0 and OVR1 cannot be set again, thereby creating a permanent record of the counter overflow. This prevents fast cycling of 64K counter. If the decoder system is programmed to track the overflow bits, then the effective number of unique synchronization values can be extended to 196,608.
3.6.3 BAUD RATE SELECT BITS
(BSL0, BSL1) BSL0 and BSL1 select the speed of transmission and the code word blanking. Table 3-3 shows how the bits are used to select the different baud rates and Section 5.7 provides detailed explanation in code word blanking. TABLE 3-3: BAUD RATE SELECT
3.6.4 LOW VOLTAGE TRIP POINT
SELECT (V LOW SEL ) The low voltage trip point select bit is used to tell the HCS300 what VDD level is being used. This information will be used by the device to determine when to send the voltage low signal to the receiver. When this bit is set to a one, the VDD level is assumed to be operating from a 5V or 6V VDD level. If the bit is set low, then the VDD level is assumed to be 3.0 volts. FIGURE 3-1: V LOW CHARACTERISTICS Bit Number Bit Description
0 Discrimination Bit 0
1 Discrimination Bit 1
2 Discrimination Bit 2
3 Discrimination Bit 3
4 Discrimination Bit 4
5 Discrimination Bit 5
6 Discrimination Bit 6
7 Discrimination Bit 7
8 Discrimination Bit 8
9 Discrimination Bit 9
10 Overflow Bit 0 (OVR0)
11 Overflow Bit 1 (OVR1)
12 Low Voltage Trip Point Select (V
SEL )
13 Baud rate Select Bit 0 (BSL0)
14 Baud rate Select Bit 1 (BSL1)
15 Reserved, set to 0
0 0 400 µsA l l 0 1 200 µs 1 out of 2 1 0 100 µs 1 out of 2 1 1 100 µs 1 out of 4 -40 05 0 8 5 2.0 1.6 1.8 1.4 2.2 2.4 2.6 3.6 3.8 4.0 4.2 VLOW Temp (C) Volts (V) VLOW sel = 0 VLOW sel = 1
DS21137F-page 8 2001 Microchip Technology Inc.
4.0 TRANSMITTED WORD
4.1 Code Word Format
The HCS300 code word is made up of several parts (Figure 4-1). Each code word contains a 50% duty cycle preamble, a header, 32 bits of encrypted data and 34 bits of fixed data followed by a guard period before another code word can begin. Refer to Table 8-4 for code word timing.
4.2 Code Word Organization
The HCS300 transmits a 66-bit code word when a button is pressed. The 66-bit word is constructed from a Fixed Code portion and an Encrypted Code portion (Figure 4-2). The 32 bits of Encrypted Data are generated from 4 button bits, 12 discrimination bits and the 16-bit sync value. The encrypted portion alone provides up to four billion changing code combinations. The 34 bits of Fixed Code Data are made up of 2 sta- tus bits, 4 button bits and the 28-bit serial number. The fixed and encrypted sections combined increase the number of code combinations to 7.38 x 10 19. FIGURE 4-1: CODE WORD FORMAT FIGURE 4-2: CODE WORD ORGANIZATION LOGIC ‘0’ LOGIC ‘1’ Bit Period Preamble Header Encrypted Portion of Transmission Fixed Portion of Transmission Guard Time TP TH THOP TFIX TG TETETE 50% Duty Cycle Repeat (1 bit) VLOW (1 bit) Button Status S2 S1 S0 S3 Serial Number (28 bits) Button Status S2 S1 S0 S3 OVR (2 bits) DISC (10 bits) Sync Counter (16 bits) Repeat (1 bit) VLOW (1 bit) Button Status 1 1 1 1 Serial Number (28 bits) SEED (32 bits) 34 bits of Fixed Portion 32 bits of Encrypted Portion
66 Data bits
LSb first. LSbMSb MSb LSb Note: SEED replaces Encrypted Portion when all button inputs are activated at the same time.
2001 Microchip Technology Inc. DS21137F-page 9 HCS300
4.3 Synchronous Transmission Mode
Synchronous Transmission mode can be used to clock the code word out using an external clock. To enter Synchronous Transmission mode, the Pro- gramming mode start-up sequence must be executed as shown in Figure 4-3. If either S1 or S0 is set on the falling edge of S2 (or S3), the device enters Synchro- nous Transmission mode. In this mode, it functions as a normal transmitter, with the exception that the timing of the PWM data string is controlled externally and 16 extra bits are transmitted at the end with the code word. The button code will be the S0, S1 value at the falling edge of S2 or S3. The timing of the PWM data string is controlled by supplying a clock on S2 or S3 and should not exceed 20 kHz. The code word is the same as in PWM mode with 16 reserved bits at the end of the word. The reserved bits can be ignored. When in Syn- chronous Transmission mode S2 or S3 should not be toggled until all internal processing has been com- pleted as shown in Figure 4-4. FIGURE 4-3: SYNCHRONOUS TRANSMISSION MODE FIGURE 4-4: CODE WORD ORGANIZATION (SYNCHRONOUS TRANSMISSION MODE) “01,10,11” PWM S[1:0] TPS TPH 1 TPH 2 t = 50ms Preamble Header Data Reserved (16 bits) Padding (2 bits) Button Status S2 S1 S0 S3 Serial Number (28 bits) Button Status S2 S1 S0 S3 DISC+ OVR (12 bits) Sync Counter (16 bits)
82 Data bits
LSb first. LSbMSb Fixed Portion Encrypted Portion
DS21137F-page 10 2001 Microchip Technology Inc.
5.0 SPECIAL FEATURES
5.1 Code Word Completion
The code word completion feature ensures that entire code words are transmitted, even if the button is released before the code word is complete. If the but- ton is held down beyond the time for one code word, multiple code words will result. If another button is acti- vated during a transmission, the active transmission will be aborted and a new transmission will begin using the new button information.
5.2 LED Output Operation
During normal transmission the LED output is LOW. If the supply voltage drops below the low voltage trip point, the LED output will be toggled at approximately 5Hz during the transmission (Section 3.6.4).
5.3 RPT: Repeat Indicator
This bit will be low for the first transmitted word. If a button is held down for more than one transmitted code word, this bit will be set to indicate a repeated code word and remain set until the button is released.
5.4 V LOW : Voltage LOW Indicator
The VLOW signal is transmitted so the receiver can give an indication to the user that the transmitter bat- tery is low. The VLOW bit is included in every transmis- sion (Figure 4-2 and Figure 8-4) and will be transmitted as a zero if the operating voltage is above the low voltage trip point. Refer to Figure 4-2. The trip point is selectable based on the battery voltage being used. See Section 3.6.3 for a description of how the low voltage trip point is configured.
5.5 Auto-shutoff
The Auto-shutoff function automatically stops the device from transmitting if a button inadvertently gets pressed for a long period of time. This will prevent the device from draining the battery if a button gets pressed while the transmitter is in a pocket or purse. This function can be enabled or disabled and is selected by setting or clearing the Auto-shutoff bit (see Section 3.5.1). Setting this bit high will enable the func- tion (turn Auto-shutoff function on) and setting the bit low will disable the function. Time-out period is approx- imately 25 seconds.
5.6 Seed Transmission
In order to increase the level of security in a system, it is possible for the receiver to implement what is known as a secure learn function. This can be done by utilizing the seed value stored in EEPROM, transmitted only when all four button inputs are pressed at the same time (Table 5-1). Instead of the normal key generation inputs being used to create the crypt key, this seed value is used. TABLE 5-1: PIN ACTIVATION TABLE Function S3 S2 S1 S0 Standby 0 000 0 Hopping Code 1 000 1 2 001 0 - --- - 13 110 1 14 111 0 Seed Code 15 111 1
2001 Microchip Technology Inc. DS21137F-page 11 HCS300
5.7 Blank Alternate Code Word
Federal Communications Commission (FCC) part 15 rules specify the limits on worst case average funda- mental power and harmonics that can be transmitted in a 100 ms window. For FCC approval purposes, it may therefore be advantageous to minimize the transmis- sion duty cycle. This can be achieved by minimizing the duty cycle of the individual bits as well as by blanking out consecutive code words. Blank Alternate Code Word (BACW) may be used to reduce the average power of a transmission by transmitting only every sec- ond code word (Figure 5-1). This is a selectable feature that is determined in conjunction with the baud rate selection bit BSL0. Enabling the BACW option may likewise allow the user to transmit a higher amplitude transmission as the time averaged power is reduced. BACW effectively halves the RF on time for a given transmission so the RF out- put power could theoretically be doubled while main- taining the same time averaged output power. FIGURE 5-1: BLANK ALTERNATE CODE WORD (BACW) Code WordBACW Disabled (All words transmitted) BACW Enabled (1 out of 2 transmitted) BACW Enabled (1 out of 4 transmitted) A Amplitude Time Code Word Code Word Code Word
DS21137F-page 12 2001 Microchip Technology Inc.
6.0 PROGRAMMING THE HCS300
When using the HCS300 in a system, the user will have to program some parameters into the device including the serial number and the secret key before it can be used. The programming cycle allows the user to input all 192 bits in a serial data stream, which are then stored internally in EEPROM. Programming will be initiated by forcing the PWM line high, after the S2 (or S3) line has been held high for the appropriate length of time line (Table 6-1 and Figure 6-1). After the Pro- gram mode is entered, a delay must be provided to the device for the automatic bulk write cycle to complete. This will set all locations in the EEPROM to zeros. The device can then be programmed by clocking in 16 bits at a time, using S2 (or S3) as the clock line and PWM as the data in line. After each 16-bit word is loaded, a programming delay is required for the internal program cycle to complete. This delay can take up to T WC . At the end of the programming cycle, the device can be veri- fied (Figure 6-2) by reading back the EEPROM. Read- ing is done by clocking the S2 (or S3) line and reading the data bits on PWM. For security reasons, it is not possible to execute a verify function without first pro- gramming the EEPROM. A Verify operation can only be done once, immediately following the Program cycle. FIGURE 6-1: PROGRAMMING WAVEFORMS FIGURE 6-2: VERIFY WAVEFORMS Note: To ensure that the device does not acci- dentally enter Programming mode, PWM should never be pulled high by the circuit connected to it. Special care should be taken when driving PNP RF transistors. PWM Enter Program Mode (Data) (Clock) Note 1: Unused button inputs to be held to ground during the entire programming sequence. Bit 0 Bit 1 Bit 2 Bit 3 Bit 14 Bit 15 Bit 16 Bit 17 TPH 1 TPBW TPS Repeat for each word (12 times) TPH 2 TCLKH TCLKL TWCTDS S2 (S3) Data for Word 0 (KEY_0) Data for Word 1 TDH 2: The VDD pin must be taken to ground after a Program/Verify cycle. PWM (Clock) (Data) Note: If a Verify operation is to be done, then it must immediately follow the Program cycle. End of Programming Cycle Beginning of Verify Cycle Bit 1 Bit 2 Bit 3 Bit 15 Bit 14 Bit 16 Bit 17 Bit190 Bit191 TWC Data from Word 0 TDV S2 (S3) Bit 0Bit191Bit190
2001 Microchip Technology Inc. DS21137F-page 13 HCS300 TABLE 6-1: PROGRAMMING/VERIFY TIMING REQUIREMENTS Note 1: Typical values - not tested in production. Parameter Symbol Min. Max. Units Program mode setup time TPS 3.5 4.5 ms Hold time 1 TPH 1 3.5 —m s Hold time 2 TPH 2 50 — µs Bulk Write time TPBW 4.0 — ms Program delay time TPROG 4.0 — ms Program cycle time TWC 50 — ms Clock low time TCLKL 50 — µs Clock high time TCLKH 50 — µs Data setup time TDS 0— µs(1) Data hold time TDH 30 — µs(1) Data out valid time TDV —3 0 µs(1)
DS21137F-page 14 2001 Microchip Technology Inc.
7.0 INTEGRATING THE HCS300
Use of the HCS300 in a system requires a compatible decoder. This decoder is typically a microcontroller with compatible firmware. Microchip will provide (via a license agreement) firmware routines that accept transmissions from the HCS300 and decrypt the hopping code portion of the data stream. These routines provide system designers the means to develop their own decoding system.
7.1 Learning a Transmitter to a
A transmitter must first be 'learned' by a decoder before its use is allowed in the system. Several learning strat- egies are possible, Figure 7-1 details a typical learn sequence. Core to each, the decoder must minimally store each learned transmitter's serial number and cur- rent synchronization counter value in EEPROM. Addi- tionally, the decoder typically stores each transmitter's unique crypt key. The maximum number of learned transmitters will therefore be relative to the available EEPROM. A transmitter's serial number is transmitted in the clear but the synchronization counter only exists in the code word's encrypted portion. The decoder obtains the counter value by decrypting using the same key used to encrypt the information. The K EE LOQ algorithm is a symmetrical block cipher so the encryption and decryp- tion keys are identical and referred to generally as the crypt key. The encoder receives its crypt key during manufacturing. The decoder is programmed with the ability to generate a crypt key as well as all but one required input to the key generation routine; typically the transmitter's serial number. Figure 7-1 summarizes a typical learn sequence. The decoder receives and authenticates a first transmis- sion; first button press. Authentication involves gener- ating the appropriate crypt key, decrypting, validating the correct key usage via the discrimination bits and buffering the counter value. A second transmission is received and authenticated. A final check verifies the counter values were sequential; consecutive button presses. If the learn sequence is successfully com- plete, the decoder stores the learned transmitter's serial number, current synchronization counter value and appropriate crypt key. From now on the crypt key will be retrieved from EEPROM during normal opera- tion instead of recalculating it for each transmission received. Certain learning strategies have been patented and care must be taken not to infringe. FIGURE 7-1: TYPICAL LEARN SEQUENCE Enter Learn Mode Wait for Reception of a Valid Code Generate Key from Serial Number Use Generated Key to Decrypt Compare Discrimination Value with Fixed Value Equal Wait for Reception of Second Valid Code Compare Discrimination Value with Fixed Value Use Generated Key to Decrypt Equal Counters Encryption key Serial number Synchronization counter Sequential Exit Learn successful Store: Learn Unsuccessful No No No Yes Yes Yes
2001 Microchip Technology Inc. DS21137F-page 15 HCS300
7.2 Decoder Operation
Figure 7-2 summarizes normal decoder operation. The decoder waits until a transmission is received. The received serial number is compared to the EEPROM table of learned transmitters to first determine if this transmitter's use is allowed in the system. If from a learned transmitter, the transmission is decrypted using the stored crypt key and authenticated via the discrimination bits for appropriate crypt key usage. If the decryption was valid the synchronization value is evaluated. FIGURE 7-2: TYPICAL DECODER OPERATION
7.3 Synchronization with Decoder
(Evaluating the Counter) The K EE LOQ technology patent scope includes a sophisticated synchronization technique that does not require the calculation and storage of future codes. The technique securely blocks invalid transmissions while providing transparent resynchronization to transmitters inadvertently activated away from the receiver. Figure 7-3 shows a 3-partition, rotating synchronization window. The size of each window is optional but the technique is fundamental. Each time a transmission is authenticated, the intended function is executed and the transmission's synchronization counter value is stored in EEPROM. From the currently stored counter value there is an initial "Single Operation" forward win- dow of 16 codes. If the difference between a received synchronization counter and the last stored counter is within 16, the intended function will be executed on the single button press and the new synchronization counter will be stored. Storing the new synchronization counter value effectively rotates the entire synchroniza- tion window. A "Double Operation" (resynchronization) window fur- ther exists from the Single Operation window up to 32K codes forward of the currently stored counter value. It is referred to as "Double Operation" because a trans- mission with synchronization counter value in this win- dow will require an additional, sequential counter transmission prior to executing the intended function. Upon receiving the sequential transmission the decoder executes the intended function and stores the synchronization counter value. This resynchronization occurs transparently to the user as it is human nature to press the button a second time if the first was unsuc- cessful. The third window is a "Blocked Window" ranging from the double operation window to the currently stored synchronization counter value. Any transmission with synchronization counter value within this window will be ignored. This window excludes previously used, perhaps code-grabbed transmissions from accessing the system. Transmission Received Does Serial Number Match Decrypt Transmission Is Decryption Valid Is Counter Within 16 Is Counter Within 32K Update Counter Execute Command Save Counter in Temp Location Start No No No No Yes Yes Yes Yes Yes No andNo Note: The synchronization method described in this section is only a typical implementation and because it is usually implemented in firmware, it can be altered to fit the needs of a particular system.
DS21137F-page 16 2001 Microchip Technology Inc. FIGURE 7-3: SYNCHRONIZATION WINDOW Blocked Entire Window rotates to eliminate use of previously used codes Single Operation Window Window (32K Codes) (16 Codes) Double Operation (resynchronization) Window (32K Codes) Stored Synchronization Counter Value
2001 Microchip Technology Inc. DS21137F-page 17 HCS300
8.0 ELECTRICAL CHARACTERISTICS
TABLE 8-1: ABSOLUTE MAXIMUM RATINGS TABLE 8-2: DC CHARACTERISTICS Symbol Item Rating Units VDD Supply voltage -0.3 to 6.6 V VIN Input voltage -0.3 to V DD + 0.3 V VOUT Output voltage -0.3 to V DD + 0.3 V IOUT Max output current 50 mA TSTG Storage temperature -55 to +125 °C (Note) TLSOL Lead soldering temp 300 °C (Note) VESD ESD rating 4000 V Note: Stresses above those listed under “ABSOLUTE MAXIMUM RATINGS” may cause permanent damage to the device. Commercial (C): Tamb = 0 °C to +70 °C Industrial (I): Tamb = -40 °C to +85 °C 2.0V < VDD < 3.0 3.0 < V DD < 6.3 Operating cur- rent (avg)2 ICC 0.2 1 1.0 2.5 mA VDD = 3.0V VDD = 6.3V Standby current ICCS 0.1 1.0 0.1 1.0 µA Auto-shutoff current3,4 ICCS 40 75 160 650 µA High level Input voltage VIH 0.55VDD VDD + 0.3 0.55VDD VDD + 0.3 V Low level input voltage VIL -0.3 0.15V DD -0.3 0.15V DD V High level output voltage VOH 0.6VDD 0.6VDD V IOH = -1.0 mA VDD = 2.0V IOH = -2.0 mA VDD = 6.3V Low level out- put voltage VOL 0.08V DD 0.08V DD V IOL = 1.0 mA VDD = 2.0V IOL = 2.0 mA VDD = 6.3V LED sink current5 VLED 6 = 1.5V VDD = 6.3V Pull-down Resistance; S0-S3 R S0 - 3 4 06 08 0 4 06 08 0 k Ω VDD = 4.0V Pull-down Resistance; PWM R PWM 80 120 160 80 120 160 k Ω VDD = 4.0V Note 1:Typical values are at 25 °C. 2: No load. 3: Auto-shutoff current specification does not include the current through the input pull-down resistors. 4: These values are characterized but not tested. 6: VLED is the voltage drop across the terminals of the LED.
2001 Microchip Technology Inc. DS21137F-page 19 HCS300 FIGURE 8-3: CODE WORD FORMAT: PREAMBLE/HEADER PORTION FIGURE 8-4: CODE WORD FORMAT: DATA PORTION TABLE 8-4: CODE WORD TRANSMISSION TIMING REQUIREMENTS VDD = +2.0 to 6.0V Commercial(C):Tamb = 0 °C to +70 °C Industrial(I):Tamb = -40 °C to +85 °C Code Words Transmitted All 1 out of 2 1 out of 4 Symbol Characteristic Number TE Basic pulse element 1 260 400 660 130 200 330 65 100 165 µs TBP PWM bit pulse width 3 780 1200 1980 390 600 990 195 300 495 µs — PWM data rate — 1282 833 505 2564 1667 1010 5128 3333 2020 bps Note: The timing parameters are not tested but derived from the oscillator clock. 50% Duty Cycle Preamble Header P1 P12
23 TE 10 TE Data Bits
Bit 30Bit 31Bit 32 Bit 33Bit 58 Bit 59 Fixed PortionEncrypted Portion Guard LSBLSB MSB MSB S3 S0 S1 S2 VLOW RPT Time Serial Number Button Code Status Bit 60Bit 61Bit 62 Bit 63 Bit 64 Bit 65
DS21137F-page 20 2001 Microchip Technology Inc. FIGURE 8-5: HCS300 TE VS. TEMP 0.8 1.7 1.6 1.5 1.4 1.3 1.2 1.1 1.0 0.9 0.7 -50 -40 -30 -20 -10 0 10 20 30 40 50 60 70 80 90 0.6 TE Min. TE Max. Typical LEGEND = 2.0 = 3.0 = 6.0
2001 Microchip Technology Inc. DS21137F-page 21 HCS300
9.0 PACKAGING INFORMATION
9.1 Package Marking Information
8-Lead PDIP (300 mil) Example 8-Lead SOIC (150 mil) Example XXXXXXXX XXXXXNNN YYWW HCS300 XXXXXNNN 0025 XXXXXXX XXXYYWW NNN HC300 XXX0025 NNN Legend: XX...X Customer specific information* Y Year code (last digit of calendar year) YY Year code (last 2 digits of calendar year) WW Week code (week of January 1 is week ‘01’) NNN Alphanumeric traceability code Note: In the event the full Microchip part number cannot be marked on one line, it will be carried over to the next line thus limiting the number of available characters for customer specific information. * Standard PICmicro device marking consists of Microchip part number, year code, week code, and traceability code. For PICmicro device marking beyond this, certain price adders apply. Please check with your Microchip Sales Office. For QTP devices, any special marking adders are included in QTP price.
DS21137F-page 22 2001 Microchip Technology Inc.
9.2 Package Details
8-Lead Plastic Dual In-line (P) - 300 mil (PDIP) B A L p α E eB β c n D Units INCHES* MILLIMETERS Dimension Limits MIN NOM MAX MIN NOM MAX Number of Pins n 88 Pitch p .100 2.54 Base to Seating Plane A1 .015 0.38 Mold Draft Angle Top α 51 01 5 51 01 5 Mold Draft Angle Bottom β 51 01 5 51 01 5 * Controlling Parameter Notes: Dimensions D and E1 do not include mold flash or protrusions. Mold flash or protrusions shall not exceed JEDEC Equivalent: MS-001 Drawing No. C04-018 .010” (0.254mm) per side. § Significant Characteristic
2001 Microchip Technology Inc. DS21137F-page 23 HCS300 8-Lead Plastic Small Outline (SN) - Narrow, 150 mil (SOIC) Foot Angle φ 048048 1512015120βMold Draft Angle Bottom 1512015120αMold Draft Angle Top 1.27.050pPitch 88nNumber of Pins MAXNOMMINMAXNOMMINDimension Limits MILLIMETERSINCHES*Units D n p B E h Lβ c 45° φ α A * Controlling Parameter Notes: Dimensions D and E1 do not include mold flash or protrusions. Mold flash or protrusions shall not exceed .010” (0.254mm) per side. JEDEC Equivalent: MS-012 Drawing No. C04-057 § Significant Characteristic
DS21137F-page 24 2001 Microchip Technology Inc. ON-LINE SUPPORT Microchip provides on-line support on the Microchip World Wide Web (WWW) site. The web site is used by Microchip as a means to make files and information easily available to customers. To view the site, the user must have access to the Internet and a web browser, such as Netscape or Microsoft Explorer. Files are also available for FTP download from our FTP site. Connecting to the Microchip Internet Web Site The Microchip web site is available by using your favorite Internet browser to attach to: www.microchip.com The file transfer site is available by using an FTP ser- vice to connect to: ftp://ftp.microchip.com The web site and file transfer site provide a variety of services. Users may download files for the latest Development Tools, Data Sheets, Application Notes, User's Guides, Articles and Sample Programs. A vari- ety of Microchip specific business information is also available, including listings of Microchip sales offices, distributors and factory representatives. Other data available for consideration is:
- Latest Microchip Press Releases
- Technical Support Section with Frequently Asked Questions
- Design Tips
- Device Errata
- Job Postings
- Microchip Consultant Program Member Listing
- Links to other useful web sites related to Microchip Products
- Conferences for products, Development Systems, technical information and more
- Listing of seminars and events Systems Information and Upgrade Hot Line The Systems Information and Upgrade Line provides system users a listing of the latest versions of all of Microchip's development systems software products. Plus, this line provides information on how customers can receive any currently available upgrade kits.The Hot Line Numbers are: 1-800-755-2345 for U.S. and most of Canada, and 1-480-792-7302 for the rest of the world.
2001 Microchip Technology Inc. DS21137F-page 25 HCS300 READER RESPONSE It is our intention to provide you with the best documentation possible to ensure successful use of your Microchip prod- uct. If you wish to provide your comments on organization, clarity, subject matter, and ways in which our documentation can better serve you, please FAX your comments to the Technical Publications Manager at (480) 792-4150. Please list the following information, and use this outline to provide us with your comments about this Data Sheet. To: Technical Publications Manager RE: Reader Response Total Pages Sent From: Name Company Address City / State / ZIP / Country Application (optional): Would you like a reply? Y N Device: Literature Number: Questions: DS21137FHCS300 1. What are the best features of this document? 2. How does this document meet your hardware and software development needs? 3. Do you find the organization of this data sheet easy to follow? If not, why? 4. What additions to the data sheet do you think would enhance the structure and subject? 5. What deletions from the data sheet could be made without affecting the overall usefulness? 6. Is there any incorrect or misleading information (what and where)? 7. How would you improve this document? 8. How would you improve our software, systems, and silicon products?
DS21137F-page 26 2001 Microchip Technology Inc. HCS300 PRODUCT IDENTIFICATION SYSTEM To order or obtain information, e.g., on pricing or delivery, refer to the factory or the listed sales office. Sales and Support Package: P = Plastic DIP (300 mil Body), 8-lead SN = Plastic SOIC (150 mil Body), 8-lead Temperature Blank = 0°C to +70°C Range: I = –40°C to +85°C Device: HCS300 = Code Hopping Encoder HCS300T = Code Hopping Encoder (Tape and Reel) HCS 300 - /P Data Sheets Products supported by a preliminary Data Sheet may have an errata sheet describing minor operational differences and recommended workarounds. To determine if an errata sheet exists for a particular device, please contact one of the following: 1. Your local Microchip sales office 2. The Microchip Corporate Literature Center U.S. FAX: (480) 792-7277 3. The Microchip Worldwide Site (www.microchip.com) Please specify which device, revision of silicon and Data Sheet (include Literature #) you are using. New Customer Notification System Register on our web site (www.microchip.com/cn) to receive the most current information on our products.
2001 Microchip Technology Inc. DS21137F - page 27 Information contained in this publication regarding device applications and the like is intended through suggestion only and may be superseded by updates. It is your responsibility to ensure that your application meets with your specifications. No representation or warranty is given and no liability is assumed by Microchip Technology Incorporated with respect to the accuracy or use of such information, or infringement of patents or other intellectual property rights arising from such use or otherwise. Use of Microchip’s products as critical com- ponents in life support systems is not authorized except with express written approval by Microchip. No licenses are con- veyed, implicitly or otherwise, under any intellectual property rights. Trademarks The Microchip name and logo, the Microchip logo, FilterLab, KEE LOQ , MPLAB, PIC, PICmicro, PICMASTER, PICSTART, PRO MATE, SEEVAL and The Embedded Control Solutions Company are registered trademarks of Microchip Technology Incorporated in the U.S.A. and other countries. dsPIC, ECONOMONITOR, FanSense, FlexROM, fuzzyLAB, In-Circuit Serial Programming, ICSP, ICEPIC, microID, microPort, Migratable Memory, MPASM, MPLIB, MPLINK, MPSIM, MXDEV, PICC, PICDEM, PICDEM.net, rfPIC, Select Mode and Total Endurance are trademarks of Microchip Technology Incorporated in the U.S.A. Serialized Quick Turn Programming (SQTP) is a service mark of Microchip Technology Incorporated in the U.S.A. All other trademarks mentioned herein are property of their respective companies. © 2001, Microchip Technology Incorporated, Printed in the U.S.A., All Rights Reserved. Printed on recycled paper. Microchip received QS-9000 quality system certification for its worldwide headquarters, design and wafer fabrication facilities in Chandler and Tempe, Arizona in July 1999. The Company’s quality system processes and procedures are QS-9000 compliant for its PICmicro® 8-bit MCUs, KEE LOQ ® code hopping devices, Serial EEPROMs and microperipheral products. In addition, Microchip’s quality system for the design and manufacture of development systems is ISO 9001 certified. Microchip’s Secure Data Products are covered by some or all of the following patents:
DS21137F-page 28 2001 Microchip Technology Inc. AMERICAS Corporate Office 2355 West Chandler Blvd. Chandler, AZ 85224-6199 Tel: 480-792-7200 Fax: 480-792-7277 Technical Support: 480-792-7627 Web Address: http://www.microchip.com Rocky Mountain 2355 West Chandler Blvd. Chandler, AZ 85224-6199 Tel: 480-792-7966 Fax: 480-792-7456 Atlanta
500 Sugar Mill Road, Suite 200B
Atlanta, GA 30350 Tel: 770-640-0034 Fax: 770-640-0307 Boston
2 Lan Drive, Suite 120
Westford, MA 01886 Tel: 978-692-3848 Fax: 978-692-3821 Chicago
333 Pierce Road, Suite 180
Itasca, IL 60143 Tel: 630-285-0071 Fax: 630-285-0075 Dallas
4570 Westgrove Drive, Suite 160
Addison, TX 75001 Tel: 972-818-7423 Fax: 972-818-2924 Dayton Two Prestige Place, Suite 130 Miamisburg, OH 45342 Tel: 937-291-1654 Fax: 937-291-9175 Detroit Tri-Atria Office Building
32255 Northwestern Highway, Suite 190
Farmington Hills, MI 48334 Tel: 248-538-2250 Fax: 248-538-2260 Kokomo 2767 S. Albright Road Kokomo, Indiana 46902 Tel: 765-864-8360 Fax: 765-864-8387 Los Angeles
18201 Von Karman, Suite 1090
Irvine, CA 92612 Tel: 949-263-1888 Fax: 949-263-1338 New York
150 Motor Parkway, Suite 202
Hauppauge, NY 11788 Tel: 631-273-5305 Fax: 631-273-5335 San Jose Microchip Technology Inc.
2107 North First Street, Suite 590
San Jose, CA 95131 Tel: 408-436-7950 Fax: 408-436-7955 Toronto
6285 Northam Drive, Suite 108
Mississauga, Ontario L4V 1X5, Canada Tel: 905-673-0699 Fax: 905-673-6509 ASIA/PACIFIC Australia Microchip Technology Australia Pty Ltd Suite 22, 41 Rawson Street Epping 2121, NSW Australia Tel: 61-2-9868-6733 Fax: 61-2-9868-6755 China - Beijing Microchip Technology Consulting (Shanghai) Co., Ltd., Beijing Liaison Office Unit 915 Bei Hai Wan Tai Bldg. No. 6 Chaoyangmen Beidajie Beijing, 100027, No. China Tel: 86-10-85282100 Fax: 86-10-85282104 China - Chengdu Microchip Technology Consulting (Shanghai) Co., Ltd., Chengdu Liaison Office Rm. 2401, 24th Floor, Ming Xing Financial Tower No. 88 TIDU Street Chengdu 610016, China Tel: 86-28-6766200 Fax: 86-28-6766599 China - Fuzhou Microchip Technology Consulting (Shanghai) Co., Ltd., Fuzhou Liaison Office Rm. 531, North Building Fujian Foreign Trade Center Hotel
73 Wusi Road
Fuzhou 350001, China Tel: 86-591-7557563 Fax: 86-591-7557572 China - Shanghai Microchip Technology Consulting (Shanghai) Co., Ltd. Room 701, Bldg. B Far East International Plaza No. 317 Xian Xia Road Shanghai, 200051 Tel: 86-21-6275-5700 Fax: 86-21-6275-5060 China - Shenzhen Microchip Technology Consulting (Shanghai) Co., Ltd., Shenzhen Liaison Office Rm. 1315, 13/F, Shenzhen Kerry Centre, Renminnan Lu Shenzhen 518001, China Tel: 86-755-2350361 Fax: 86-755-2366086 Hong Kong Microchip Technology Hongkong Ltd. Unit 901-6, Tower 2, Metroplaza
223 Hing Fong Road
Kwai Fong, N.T., Hong Kong Tel: 852-2401-1200 Fax: 852-2401-3431 India Microchip Technology Inc. India Liaison Office Divyasree Chambers
1 Floor, Wing A (A3/A4)
No. 11, O’Shaugnessey Road Bangalore, 560 025, India Tel: 91-80-2290061 Fax: 91-80-2290062 Japan Microchip Technology Japan K.K. Benex S-1 6F 3-18-20, Shinyokohama Kohoku-Ku, Yokohama-shi Kanagawa, 222-0033, Japan Tel: 81-45-471- 6166 Fax: 81-45-471-6122 Korea Microchip Technology Korea 168-1, Youngbo Bldg. 3 Floor Samsung-Dong, Kangnam-Ku Seoul, Korea 135-882 Tel: 82-2-554-7200 Fax: 82-2-558-5934 Singapore Microchip Technology Singapore Pte Ltd.
200 Middle Road
#07-02 Prime Centre Singapore, 188980 Tel: 65-334-8870 Fax: 65-334-8850 Taiwan Microchip Technology Taiwan 11F-3, No. 207 Tung Hua North Road Taipei, 105, Taiwan Tel: 886-2-2717-7175 Fax: 886-2-2545-0139 EUROPE Denmark Microchip Technology Nordic ApS Regus Business Centre Lautrup hoj 1-3 Ballerup DK-2750 Denmark Tel: 45 4420 9895 Fax: 45 4420 9910 France Microchip Technology SARL Parc d’Activite du Moulin de Massy
43 Rue du Saule Trapu
91300 Massy, France
D-81739 Munich, Germany Tel: 49-89-627-144 0 Fax: 49-89-627-144-44 Italy Microchip Technology SRL Centro Direzionale Colleoni Palazzo Taurus 1 V. Le Colleoni 1
20041 Agrate Brianza
Milan, Italy Tel: 39-039-65791-1 Fax: 39-039-6899883 United Kingdom Arizona Microchip Technology Ltd.
505 Eskdale Road
Berkshire, England RG41 5TU Tel: 44 118 921 5869 Fax: 44-118 921-5820 10/01/01 W ORLDWIDE SALES AND SERVICE