L9680 STMICROELECTRONICS | Alldatasheet

Document overview

  • Manufacturer or author: Provided By ALLDATASHEET.COM(FREE DATASHEET DOWNLOAD SITE)
  • PDF pages: 277

Technical content

Datasheet sections

  • 1 Description
  • 2 Absolute maximum ratings
  • 3 Operative maximum ratings
  • 4 Pin out
  • 5 Overview and block diagram
  • 5.1 Power supply
  • 5.2 Deployment drivers
  • 5.3 Remote sensor interfaces (4)
  • 5.4 DC sensor interfaces (9)
  • 5.5 General purpose outputs (3)
  • 5.6 Arming logic
  • 5.7 Other features
  • 6 Start-up and power control
  • 6.1 Power supply overview
  • 6.2 Power mode control
  • 6.2.1 POWER OFF mode
  • 6.2.2 SLEEP mode
  • 6.2.3 ACTIVE mode
  • 6.2.4 PASSIVE mode
  • 6.2.5 Power-up and power-down sequences
  • 6.2.6 IC operating states
  • 6.3 ERBOOST switching regulator
  • 6.4 Energy reserve capacitor charging and discharging circuits
  • 6.5 ER CAP diagnostic
  • 6.5.1 ER CAP measurement
  • 6.5.2 ER CAP ESR measurement
  • 6.6 ER switch and COVRACT pin
  • 6.7 SYNCBOOST boost regulator

Datasheet sections

  • 7.3.25 WD2 seed read command register (WD2_SEED)
  • 7.3.26 WD2 key write command register (WD2_KEY)
  • 7.3.27 WD test command register (WD_TEST)
  • 7.3.28 System diagnostic register (SYSDIAGREQ)
  • 7.3.29 Diagnostic result register for deployment loops (LPDIAGSTAT)
  • 7.3.30 Loops diagnostic configuration command register for low leve
  • 7.3.31 Loops diagnostic configuration command register for high level
  • 7.3.32 DC sensor diagnostic configuration command register (SWCTRL)
  • 7.3.33 ADC request and data registers (DIAGCTRL_x)
  • 7.3.35 Global configuration register for GPO driver function (GPOCR)
  • 7.3.36 GPOx control register (GPOCTRLx)
  • 7.3.37 GPO fault status register (GPOFLTSR)
  • 7.3.38 Wheel speed sensor test request register (WSS_TEST)
  • 7.3.39 PSI5/WSS configuration register for channel x (RSCRx)
  • 7.3.40 Remote sensor control register (RSCTRL)
  • 7.3.41 WSS Threshold configuration register 1 (RS_AUX_CONF1)
  • 7.3.42 WSS Threshold configuration register 2 (RS_AUX_CONF2)
  • 7.3.43 Safing algorithm configuration register (SAF_ALGO_CONF)
  • 7.3.44 Arming signals register (ARM_STATE)
  • 7.3.46 ARMx enable pulse stretch timer status (AEPSTS_ARMx)
  • 7.3.48 Passenger inhibit lower threshold for DC sensor 0 (PADTHRESH_LO)
  • 7.3.49 Assignment of PSINH signal to specific Loop(s) (LOOP_MATRIX_PSINH)
  • 7.3.50 Safing records enable register (SAF_ENABLE)
  • 7.3.51 Safing records request mask registers (SAF_REQ_MASK_x)
  • 7.3.52 Safing records request target registers (SAF_REQ_TARGET_x)
  • 7.3.53 Safing records response mask registers (SAF_RESP_MASK_x)
  • 7.3.55 Safing records data mask registers (SAF_DATA_MASK_x)
  • 7.3.56 Safing record threshold registers (SAF_THRESHOLD_x)
  • 7.3.57 Safing control x registers (SAF_CONTROL_x)
  • 7.3.58 Safing record compare complete register (SAF_CC)
  • 7.4 Remote sensor SPI register map

Datasheet sections

  • 9.3 Remote sensor interface fault protection
  • 9.3.1 Short to ground, current limit
  • 9.3.2 Short to battery
  • 9.3.3 Cross link
  • 9.3.4 Leakage to battery, sensor open
  • 9.3.5 Leakage to ground
  • 9.3.6 Thermal shutdown
  • 10 Watchdog timers
  • 10.1 Temporal watchdog (WD1)
  • 10.1.1 Watchdog timer configuration
  • 10.1.2 Watchdog timer operation
  • 10.2 Algorithmic watchdog (WD2)
  • 10.3 Watchdog reset assertion timer
  • 10.4 Watchdog timer disable input (WDT/TM)
  • 11 DC sensor interface
  • 11.1 Passenger inhibit interface
  • 12 Safing logic
  • 12.1 Safing logic overview
  • 12.2 SPI sensor data decoding
  • 12.3 In-frame and out-of-frame responses
  • 12.4 Safing state machine operation
  • 12.4.1 Simple threshold comparison operation
  • 12.5 Safing engine output logic (ARMxINT)
  • 12.5.1 Arming pulse stretch
  • 12.6 Additional communication line
  • 13 General purpose output (GPO) drivers
  • 14 System voltage diagnostics
  • 14.1 Analog to digital algorithmic converter
  • 15 Temperature sensor

Datasheet sections

  • 18 Errata sheet
  • 19 Package information
  • 20 Revision history

Features

 AEC-Q100 qualified  Boost regulator for energy reserve – 1.882 MHz operation, I load = 70 mA max – Output voltage user selectable, 23 V/ 33 V ±5% – Capacitor value & ESR diagnostics  Boost regulator for PSI-5 SYNC pulse – 1.882 MHz operation, – Output voltage, 12 V/14.75 V, user configurable  Buck regulator for remote sensor – 1.882 MHz operation – Output voltage, 7.2 V/9 V ±4%, user configurable  Buck regulator for micro controller unit – 1.882 MHz operation – Output voltage user selectable, 3.3 V or

5.0 V ±3%

 Integrated energy reserve crossover switch –3 Ω - 912 mA max – Switch active output indicator  Battery voltage monitor & shutdown control with Wake-up control  System voltage diagnostics with integrated ADC  Squib deployment drivers – 12 channel HSD/LSD –2 5 V max deployment voltage – Various deployment profiles – Current monitoring measure, STB, STG & Leakage diagnostics – High & low side driver FET tests  High side safing switch regulator and enable control  Four channel remote sensor interface – PSI-5 satellite sensors – Active wheel speed sensors  Three channel GPO, HSD or LSD configurable, with PWM 0-100% control  Nine channel hall-effect, resistive or switch sensor interface  User customizable safing logic  Specific disarm signal for passenger airbag  Temporal and algorithmic Watchdog timers  End of life disposal interface  Temperature sensor  32 bit SPI communications  5.5 V minimum operating voltage at device battery pin  Operating temperature, -40 to 95 °C  Packaging - 100 pin *$3*36 TQFP100 exposed pad down (14x14x1.0mm) Table 1. Device summary

1 Description

The L9680 is an advanced airbag system chip solution targeted for mature airbag market and integrated safety markets. This device is family compatible with the L9678 and L9679 devices. Safety system integration is enabled through higher power supply currents and integrated active wheel speed sensor interface. The active wheel speed interface is shared with the PSI-5 satellite interface to create a generic remote safety sensor interface compliant to both systems. High frequency power supply design allows further cost reduction by using smaller and less expensive external components. All switching regulators operate at 1.882 MHz while buck converters have integrated synchronous rectifiers. Additional attention is given to system integrity and diagnostics. The reserve capacitor is electrically isolated from the boost regulator by a 65 mA nominal fixed current source, controlling in-rush an additional capacitor discharge fixed current source is integrated to diagnose the reserve capacitor value and ESR. The same current sources can be used to discharge the capacitor at shutdown. Thanks to low quiescent current, the device can be directly connected to battery. In this way, the device start-up and shutdown are controlled through the wake-up input function. The power supply and crossover function are controlled automatically through the internal state machine. The user can select both ECU logic voltage (VCC at 3.3 V or 5.0 V) and energy reserve output voltage (at either 23 V or 33 V). Deployment voltage is set to a maximum of 25 V for all profiles and can be controlled through external safing switch circuit using the high side safing switch reference enabled through the system SPI interface or the arming logic.

2 Absolute maximum ratings

functionality to a subset of it in order to respect to the power dissipation capability. Table 2. Absolute maximum ratings

26 DCS8 DC Sensor interface channel 8 -2 40 V

27 DCS7 DC Sensor interface channel 7 -2 40 V

28 DCS6 DC Sensor interface channel 6 -2 40 V

29 DCS5 DC Sensor interface channel 5 -2 40 V

30 DCS4 DC Sensor interface channel 4 -2 40 V

31 DCS3 DC Sensor interface channel 3 -2 40 V

32 DCS2 DC Sensor interface channel 2 -2 40 V

33 DCS1 DC Sensor interface channel 1 -2 40 V

34 DCS0 DC Sensor interface channel 0 -2 40 V

39 GPOD0 GPO driver 0 drain output pin -1 40 V

40 GPOS0 GPO driver 0 source output pin -1 40 V

41 GPOS1 GPO driver 1 source output pin -1 40 V

42 GPOD1 GPO driver 1 drain output pin -1 40 V

43 GPOD2 GPO driver 2 drain output pin -1 40 V

44 GPOS2 GPO driver 2 source output pin -1 40 V

Table 2. Absolute maximum ratings (continued)

79 VBATMON Battery line voltage monitor -18

  1. VBATMON negative AMR is -18 V or -20 mA.

3 Operative maximum ratings

recover with no damage or degradation. of each specification table. Table 3. Operative maximum ratings

26 DCS8 DC sensor interface channel 8 -1 18 V

27 DCS7 DC sensor interface channel 7 -1 18 V

28 DCS6 DC sensor interface channel 6 -1 18 V

29 DCS5 DC sensor interface channel 5 -1 18 V

30 DCS4 DC sensor interface channel 4 -1 18 V

31 DCS3 DC sensor interface channel 3 -1 18 V

32 DCS2 DC sensor interface channel 2 -1 18 V

33 DCS1 DC sensor interface channel 1 -1 18 V

34 DCS0 DC Sensor interface channel 0 -1 18 V

Table 3. Operative maximum ratings (continued)

79 VBATMON Battery line voltage monitor -1 18 V

4 Pin out

1.0mm) with a 7.6 x 7.6 mm exposed pad down. Figure 1. Pin connection diagram (top view) The exposed pad is electrically shorted to the substrate pins GNDSUB1 and GNDSUB2. These three connection nodes are to be kept shorted on the application.

5 Overview and block diagram

Figure 2. Device function block diagram

Overview and block diagram L9680

5.1 Power supply

 Integrated 1.882 MHz boost regulator, 33 V ± 5% or 23 V ± 5% nominal output  Integrated 1.882 MHz boost regulator,12 V/14.75 V nominal output, user selectable via SPI command  Integrated 1.882 MHz synchronous buck regulator, 7.2 V/9 V ± 4% nominal output, user selectable via SPI command  Integrated 1.882 MHz synchronous buck regulator, 5 V ± 3% or 3.3 V ± 3% nominal output, user selectable via VCCSEL pin  Over and under voltage detection and shutdown for all regulators  Under-voltage lockout to guarantee buck regulator outputs disabled and discharged  Integrated energy reserve capacitor fixed constant current source (65 mA, nominal) switch for controlled inrush and charge characteristics  Integrated energy reserve diagnostics, capacitor value and ESR  Integrated energy reserve crossover switch with current limit and battery input voltage monitoring  Crossover switch ‘active’ output signal  Integrated 25 V/20 V SPI selectable linear regulator for high side safing FET gate supply enabled via SPI or arming logic  Reset output

5.2 Deployment drivers

 12 high side deployment drivers, 12 low side deployment drivers  User programmable deployment options – 1.20 A or 1.75 A minimum – programmable time in 0.1ms increments  Capability to deploy a squib with a minimum current of 1.2 / 1.75 A and the low side FET shorted to ground up to 25 V on SSxy  Independently-controlled high-side and low-side FETs  Squib resistance measurement  Firing current monitor feature  High and low side FET tests  Open & shorts diagnostics, including between loop drivers  Independent fire enable logic, SPI and discrete digital input

L9680 Overview and block diagram 276

5.3 Remote sensor interfaces (4)

 Quad channel receiver, user selectable – standard PSI-5 v1.3 compatible with sync pulse or – active wheel speed sensors  High side drivers for active wheel speed sensor mode (with driver protection)  Current limit with short circuit protection diagnostics  PSI-5 satellite sensor mode – Auto-adjusting current trip points for each satellite channel – Even parity, 8 or 10 bit messages, 125k or 189kbps – Satellite message error detection  Active wheel speed sensor mode – Standard active dual level sensors, 7ma/14ma – Three level sensors with direction and air gap data, 7ma/14ma/28ma – PWM encoded two level sensor, 2 edges/tooth – PWM encoded two level sensor, 1 edge/tooth – Standard active two and three level sensor data decoding available through SPI

5.4 DC sensor interfaces (9)

 Nine integrated switch interfaces with current sense capability  Compatible with Hall-effect, resistive and switch sensors  Current limit protected  System dedicated path to disable the passenger airbag with input from DC sensor interface

5.5 General purpose outputs (3)

 Three configurable high-side or low-side drivers  ON-OFF mode and PWM 0-100% fine control  Diagnostics for short circuit protection and open load detection  Current limit and reverse battery protected

5.6 Arming logic

 User configurable safing algorithms with 16 safing records  Four digital sensor interfaces through SPI  Independent user programmable thresholds  Independent user programmable latch timers  Four discrete and independent arming logic outputs  Four discrete and independent internal arming signals  End-of-life interface

Overview and block diagram L9680

5.7 Other features

 One dedicated 32-bit SPI bus for global configuration and control  One dedicated 32-bit SPI bus for remote sensor configuration and control  Microcontroller ‘state of health’ input and control function  Integrated watchdog control with 2 independent structures: windowed WD and algorithmic WD  Temperature sensor  Independent thermal shutdown protection on the ER boost switch, the SYNC boost switch, the energy reserve crossover switch, the energy reserve charge paths, the remote sensor interfaces and the general purpose outputs  All diagnostics are digital and are available through SPI communications  Configurable logic operation, 5 V or 3.3 V

6 Start-up and power control

6.1 Power supply overview

Figure 3. The power supply block contains the following features: voltage levels resulting in an output voltage above the set regulation point. external optional cross-over switch. to either 5 V or 3.3 V nominal voltage. primary control signals for the power supply control state machine.

Figure 3. Power supply block diagram

6.2 Power mode control

sleep, active and passive mode. Figure 4. The descriptions include references to conditions and sometimes nominal values. The absolute values for each condition are listed in the electrical specifications section. Figure 4. Power control state flow diagram

Start-up and power control L9680

6.2.1 POWER OFF mode

During the POWER-OFF Mode all supplies are disabled keeping the system in a quiescent state with very low current draw from battery. As soon as WAKEUP>WU_mon the IC will move to SLEEP Mode.

6.2.2 SLEEP mode

During the Sleep mode the VINT3V3 and CVDD internal regulators are turned on and the IC is ready for full activation of all the other supplies. As soon as VIN voltage is over a minimum threshold, all the other supplies are turned on and the IC enters the ACTIVE mode.

6.2.3 ACTIVE mode

This is the normal operating mode for the system. All power supplies are enabled and the energy reserve boost converter starts to increase the voltage at ERBOOST. Likewise, the SYNCBOOST boost converter continues to charge and regulate to a nominal 12 V (default level at startup). Once the SYNCBOOST has reached a good value, the SATBUCK regulator starts up. In turn, when SATBUCK has ramped up, VCC regulator is enabled. Once the VCC buck regulator is in regulation, RESET is released allowing the system microcontroller and other components to begin their power- on sequence. Among these, also the ER charge current generator can be enabled by the microcontroller via a dedicated SPI command. The active mode can be left when either WAKEUP pin or VIN voltage drop down. For the very first 9ms after having entered the active mode, the WAKEUP pin low would immediately cause the IC to switch back to sleep mode. After that time, WAKEUP pin low must be first confirmed by a μC SPI_SLEEP command prior to cause the system to switch to passive mode. Passive mode is also entered in case of VIN voltage low.

6.2.4 PASSIVE mode

In this state, the reserve capacitor charge current and the ERBOOST boost converter are disabled. When in passive mode the device activates both the COVRACT output pin and the integrated ER switch to allow VIN to be connected to the ER capacitor. In this time, VIN is supposed to be increased up to almost VER level and the system operation relies on energy from the ER capacitor. Two scenarios are possible: high or low battery. If VIN < VINGOOD, the device moved from RUN state in ACTIVE mode to the ER state. Here, the ER capacitor is depleted while supplying all the regulators until the POR on internal regulator occurs. The threshold to decide the ER switch activation is based on VIN, because VIN is the supply voltage rail for ERBOOST regulator. If the device has still a good battery level, it entered the POWERMODE SHUTDOWN thanks to a microcontroller command to switch off. In this case, the VER node will be discharged down to approximately VIN level, which then will be supplied out of the battery line. System will continue to run up to a dedicated SPI command to disable the SATBUCK regulator, which will lead the device to enter the POWEROFF state. The wake-up pin is filtered to suppress undesired state changes resulting from transients or glitches. Typical conditions are shown in the chart below and summarized by state.

Figure 5. Wake-up input signal behaviour

  1. No change of sleep mode state but current consumption may exceed specification for
  2. The sleep mode current returns to within specified limits.
  3. Power supply exits sleep mode. Switchers start operating if applicable voltages exceed

instantaneously sends the system back to sleep.

  1. Sleep reset is released and the entire system starts operating. An SPI command to

enter sleep state would not be executed.

  1. No change in system status, an SPI command to turn off switchers would be ignored.
  2. No change in system status, but an SPI command to turn off switchers would be

accepted and turn the system off. states. When one function is flagged, the related circuitry cannot be activated on that state. Table 4. Functions disabling by state

Table 4. Functions disabling by state (continued)

6.2.5 Power-up and power-down sequences

Figure 9. The following sequences represent just a subset of all possible power-up and Figure 6. Normal power-up sequence

Figure 7. Normal power down sequence through POWERMODE SHUTDOWN state -

Figure 8. Normal power down sequence through Powermode Shutdown state - ER

Figure 9. Normal power down sequence through ER state

L9680 Start-up and power control 276

6.2.6 IC operating states

Different states can be identified while operating the device. These states allow safe and predictable initialization, test, operation and final disposal of the part (scrapping). As soon as the RESET signal is de-asserted at the beginning of the ACTIVE mode, the microcontroller powers up. At this stage, L9680 is in the Init state: during this state the device must be initialized by the controller. In particular, the watchdog timer window can be programmed during this state. When the watchdog service begins (upon the first successful watchdog feed), the device switches to Diag state for diagnostics purposes. The remaining configuration of the device is allowed in this state, in particular for safing records and deployment masks. Several tests are also enabled while in this state and all these tests are mutually exclusive to one another. HS and LS switch tests of the squib drivers can only be processed during this Diag state. Also high side safing FET can only be run during this state. When not in Diag state, any commands for squib driver switch tests will be ignored. Other checks are also performed: on the arming outputs to check for non-stuck-at conditions on the pins and on the configured firing time configuration through one of the ARMx pin. The SSM remains in this state until commanded to transition into the Safing state or Scrap state via the dedicated SPI commands. Upon reception of the SAFING_STATE command while in Diag state, the device enters Safing state. This is the primary run-time state for normal operation, and the logic performs the safing function, including monitoring of sensor data and setting of the ARMx signals. The only means of exiting Safing state is by the assertion of the SSM_Reset signal. The Scrap state is entered upon reception of the SCRAP_STATE command while in Diag state. While in Scrap state, the part allows the main microcontroller to initiate a transition to Arming state, and monitoring of the Remote Sensor SPI interface and the safing logic is disabled. From Scrap state, the device can transition to Arming state only, and the only means of moving back to Init state is through an SSM_Reset. In order to protect from inadvertent entry into Arming state, and to prevent undesired activation of the safing signals, a handshake mechanism is used to control entry into, and exit from Arming state. This handshake is described further in Section 11.6. While in Arming state, the arming outputs are asserted. Exit from Arming state occurs when the periodic SCRAP_KEY commands cease (timeout), the key value is incorrect, or when SSM_Reset is asserted. Upon exit, the device re-enters Scrap state, except for the case of SSM_Reset, which results in entry into Init state. The device operating states are shown in Figure 10.

Figure 10. IC operating state diagram

6.3 ERBOOST switching regulator

disabled so that system power can be taken from the energy reserve capacitor. SYS_CFG(KEEP_ER_BOOST_ON) bit.

Figure 12. ERBOOST regulator state diagram

6.4 Energy reserve capacitor charging and discharging circuits

Figure 13. ER charge state diagram generator. This discharge can be controlled via SPI command while not in SLEEP mode. avoid inefficient way of controlling the charge on the VER energy reserve capacitor.

Figure 14. ER discharge state diagram

6.5 ER CAP diagnostic

6.5.1 ER CAP measurement

capacitor connected on ER pin. The simplified block diagram is shown in the figure below. Figure 15. ER CAP measurement block diagram avoid ESR error contribution.

application, in order to maximize the differential voltage and then improve the accuracy. issue, so the discharge time cannot be longer than 350 ms. Figure 16. ER CAP measurement timing diagram

6.5.2 ER CAP ESR measurement

Figure 17. ER ESR measurement block diagram Figure 18. The test lasts for TESR_DIAG. After this time has without interruption even if the device enters in ER State because of a battery loss event.

Figure 18. ER ESR measurement timing diagram

6.6 ER switch and COVRACT pin

the VIN node, supply input for the SYNCBOOST regulator and for internal power supplies. above mentioned overvoltage detection. the COVRACT is deactivated).

Figure 19. ER switch state diagram

6.7 SYNCBOOST boost regulator

regulator also provides the power for the SATBUCK regulator. SYNCBOOST_OFF state to the SYNCBOOST_ON state. should an extended voltage range be needed. and latched in this state until the related fault flag ERBST_OT in the FLTSR register is read.

6.8 SATBUCK regulator

integrates the external recirculation diode. Figure 22. SATBUCK regulator state diagram

6.9 VCC buck regulator

VCCSEL state, the VCC buck regulator cannot be changed by the user. Detection Low to prevent any MCU damage.

Figure 23. VCC regulator state diagram

6.10 VCOREMON external core voltage monitor

VCC = 3.3 V and to disable the VCORE monitor. and to disable the VCORE monitor. and then the VCORE monitor will be enabled function.

6.11 VSF regulator and control

Figure 24. The VSF regulator supply input is ERBOOST. Figure 24. VSF control logic function are shown in the electrical performance tables.

6.12 Oscillators

selectable via the CLK_CNF register. clocks for the switching regulators (1.882 MHz typ). latched into the CLKFRERR flag in the FLTSR register and a POR is issued.

6.13 Reset control

Figure 25 the voltage monitoring diagram is shown. Figure 25. Internal voltage monitors devices such as the microcontroller, sensors, and other ICs within the ECU.

supplies or bandgap circuits. When active, all other resets are asserted. when a failure is detected in the VCC or VCORE supply. machine, or again when the MCUFAULTB pin is active. FLTSR and cleared upon SPI reading. Figure 26. Reset control logic

7 SPI interfaces

SPI provides dedicated access to Remote Sensor Data and Status Registers.

7.1 SPI protocol

input shift register or out from the output one while CS_X is the active low chip select input. 32 bit transmission for the SPI interface is shown in Table 5. frames, respectively. Odd parity type is used. The communications is controlled through CS_X, enabling and disabling communication. When CS_X is at logic high, all SPI communication I/O is tri-stated and no data is accepted. for MISO_X, data is read MSB first, LSB last. Table 5. SPI MOSI and MISO frames layout

7.2 Global SPI register map

Table 6. Global ID bit (GID) is used to extend available register addresses, but it is shared The L9680 checks the validity of the received WID and RID fields in the MOSI_G frame.

Table 6. Global SPI register map

Table 6. Global SPI register map (continued)

  1. A check mark indicates in which operating state a WRITE-command is valid.
  2. KEEP_ERBOOST_ON, LOW_POWER_MODE, VSF_V and VINGOOD_FILT_SEL bits are writable in all states, the other bits of SYS_CFG are on ly writable in INIT state.

7.3 Global SPI tables

indicate that the register is not affected by the relevant reset signal'). Global Status Word (GSW) of the Global SPI is the most significant 11 bits of MISO_G data. Table 7. Global SPI Global Status Word

0 No fault

1 Fault

0 All the DSRx-CHDS bits are 0

1 At least one of the DSRx-CHDS bits is 1

0 WDT/TM=0

1 WDT/TM=1

0 Powermode state machine is not in ER state

1 Powermode state machine is in ER state

0 All the bits from 18 to 9 in the POWER_STATE Registers

1 At least one of the bits from 18 to 9 in the

0 All the bits in the Fault Status Register (FLTSR) are 0s

1 At least one of the bits in the Fault Status Register

0 No new data available

1 New data available

0 No Error

1 Error

Table 7. Global SPI Global Status Word (continued)

Global SPI read/write register

7.3.1 Fault status register (FLTSR)

ID: 00 Type: R Read: 0000 Write: - 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - XXXXXXXXXXXXXXXX MISO ERCHARGE_OT MCUFL T_TEST ERBST_OT CLKFRERR WD2 retry cnt OTPCRC_ERR WD2_LO WD2_TM WD2_WDR WD1_LO WD1_TM WD1_WDR MCURST WSMRST SSMRST VCORE_ERR POR POR WSM SSM ERCHARGE_OT 0 - - ER charge over temperature bit Set when over-temp condition detected, cleared on SPI read or POR=1 MCUFLT_TEST 1 1 1 MCU FAULT test mode - reflects MCU_FLT_TM signal state

0 MCU FLT TM=0

1 MCU FLT TM=1

ERBST_OT 0 - - ER Boost over-temperature bit Set when over-temp condition detected, cleared on SPI read or POR=1 CLKFRERR 0 - - Internal oscillator cross-check error bit Set when osc. error detected, cleared on SPI read or SUPPLY_POR=1 WD2_retry_cnt[3:0] $0 $0 $0 Value of WD2 retry counter OTPCRC_ERR 0 - - OTP CRC error bit Set when OTP error detected (tested at release of POR), cleared by POR=1 WD2_LO 0 0 - WD2 lockout - reflects WD2 lockout state

0 WD2 Lockout inactive

1 WD2 Lockout active

WD2_TM 0 0 0 WD2 test mode - reflects WD2TM signal state

0 WD2TM=0

1 WD2TM=1

WD2_WDR 00- WD2 reset latch - set when WD2RESET or STOPPING states are entered, cleared upon read

0 WD2RST signal = 0

1 WD2RST signal = 1

WD1_LO 00- WD1 lockout - reflects WD1 lockout state Set and cleared per Watchdog Timer Flow Diagram

0 WD1 Lockout inactive

1 WD1 Lockout active

WD1_TM 0 0 0 WD1 test mode - reflects WD1TM signal state Set and cleared per Watchdog Timer Flow Diagram

0 WD1TM=0

1 WD1TM=1

WD1_WDR 0 0 - WD1 reset latch Set and cleared per Watchdog Timer Flow Diagram

0 WD1_WDR signal = 0

1 WD1_WDR signal = 1

MCURST 0 0 - MCU reset latch - set when MCUFLT pin goes low, cleared upon read

0 MCURST signal = 0

1 MCURST signal = 1

WSMRST 1 1 - Watchdog state machine reset Set when WSM reset goes to '1', cleared upon SPI read

0 WSM reset has not occurred

1 WSM reset has occurred

SSMRST 1 1 1 Safing state machine reset Set when SSM reset goes to '1', cleared upon SPI read

0 SSM reset has not occurred

1 SSM Reset has occurred

VCORE_ERR 0-- VCOREMON pin status - set when VCOREMON pin goes out of range, reset upon read

0 VCORMON in range (VCORE_UV<VCOREMON<VCORE_OV)

1 VCOREMON out of range (VCOREMON<VCORE_UV, or VCOREMON>VCORE_OV)

Set when POR goes to '1', cleared upon SPI read

0 POR reset has not occurred

1 POR Reset has occurred

7.3.2 System configuration register (SYS_CFG)

ID: 01 Type: RW Read: 0100 Write: 0002 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - EN_AUTO_SWITCH_OFF X LOW_POWER_MODE KEEP_ERBST_ON PSINHSEL HI_LEV_DIAG_TIME RSU_SYNCPULSE_SHIFT_CONF SQMEAS VMEAS DCS_PAD_V SAFESEL VSF_V VINGOOD_FILT_SEL WD1_TO_DIS MISO 0000 EN_AUTO_SWITCH_OFF LOW_POWER_MODE KEEP_ERBST_ON PSINHSEL HI_LEV_DIAG_TIME RSU_SYNCPULSE_SHIFT_CONF SQMEAS VMEAS DCS_PAD_V SAFESEL VSF_V VINGOOD_FILT_SEL WD1_TO_DIS POR WSM SSM EN_AUTO_SWITCH_OFF 000 Enable auto switch off ISRC current source and DCS regulator after measurement completion

0 Auto switch off disabled

1 Auto switch off enabled

LOW_POWER_MODE 0-- Selection of over current detection for SYNCBOOST, SATBUCK and VCCBUCK

0 High current level

1 Low current level

KEEP_ERBST_ON 0 0 0 ER Boost behaviour during ER state

0 ER Boost is disabled

1 ER Boost stay enabled

PSINHSEL 111 PSINH engine mode select Updated by SSM_RESET or SPI write

0 Internal

1 External

HI_LEV_DIAG_TIME 0 0 0 Selection of duration of high level squib diagnostics

0 Short time (see high level diag diagram)

1 Long time (see high level diag diagram)

RSU_SYNCPULSE_ SHIFT_CONF 0 0 0 Selection of sync pulses shift duration

0 Long time

1 Short time

SQMEAS 00 00 00 Sample number in DC sensor, squib measurement and temperature conversions Updated by SSM_RESET or SPI write 00 8 samples 01 16 samples 10 4 samples 11 2 sample VMEAS 00 00 00 Sample number in any other voltage measurement conversions Updated by SSM_RESET or SPI write 00 4 samples 01 16 samples 10 8 samples 11 1 sample DCS_P AD_V 0 0 0 Passenger inhibit measurement mode

0 Current

1 Voltage

SAFESEL 1 1 1 Safing engine mode select Updated by SSM_RESET or SPI write

0 Internal safing engine

VSF_V 0 0 0 VSF voltage select Updated by SSM_RESET or SPI write 0 20V 1 25V VINGOOD_FIL T_SEL 0 - - Selector of filter time for VINGOOD going low (time is fixed to 3.5 μs for VINGOOD going high) 0 1 μs 1 3.5 μs WD1_TO_DIS 0 0 - Disable of initial 500ms timeout function of WD1 state machine Updated by WSM_RESET or SPI write 0 timeout function is enabled 1 timeout function is disabled

7.3.3 System control register (SYS_CTL)

ID: 02 Type: RW Read: 0200 Write: 0004 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - RESTART_SYBST_SEL PD&VRCM_SEL KEEP_SYNCBST_ON VIN_TH_SEL VBATMON_TH_SEL ER_BST_V ER_CUR_EN ER_BST_EN SYNCBST_EN SPI_OFF x ERSWITCH_LIM_SEL SYBST_V SAT_V MISO 0000 RESTART_SYBST_SEL PD&VRCM_SEL KEEP_SYNCBST_ON VIN_TH_SEL VBATMON_TH_SEL ER_BST_V ER_CUR_EN ER_BST_EN VSUP_EN SPI_OFF ERSWITCH_LIM_SEL SYBST_V SAT_V POR WSM SSM RESTART_SYBST_SEL 0-- Selection of comparator used to restart sync boost in erstate (don't care in case SYS_CTL(KEEP_SYNCBST_ON) bit is high)

0 VIN comparator is used; syncboost is switched off entering erstate and

switched on once VIN goes above VIN_fastslope threshold.

1 SYNCBST comparator is used; syncboost is switched off entering

erstate and switched on when SYNCBST voltage falls down VSYNCBST_RESTART_TH threshold (this condition requires that SYNCBST voltage has been pulled up above the same threshold previously). PD&VRCM_SEL 0 0 0 Squib pull down current level and VRCM leakage to GND threshold selection 0 1 mA pull down current and 450 μA VRCM leakage to GND threshold 1 5 mA pull down current and 2 mA VRCM leakage to GND threshold KEEP_SYNCBST_ON 1 - - SYNC Boost behaviour during ER state

0 SYNC Boost is disabled entering in ER state

1 SYNC Boost stay enabled in ER state. If boost is OFF in ER state and this command is received during that state the boost is switched on. VIN_TH_SEL 0 0 0 VIN comparators threshold selector

0 VINGOOD= VINgood0

1 VINGOOD= VINgood1

VBATMON_TH_SEL 00 00 00 VBATMON comparators threshold selector

00 VINGOOD= VINgood0

01 VINGOOD= VINgood1

10 VINGOOD= VINgood2

11 VINGOOD= VINgood3

ER_BST_V 0 0 0 ER Boost voltage select Updated by SSM_RESET or SPI write 0 set 23V boost 1 set 33V boost ER_CUR_EN 00 00 00 ER charge / discharge control

00 Current sources off

01 ER charge enabled

10 ER discharge enabled

11 Current sources off

ER_BST_EN 1 1 1 Boost enable Updated by SSM_RESET or SPI write

0 ER_BOOST OFF request

1 ER_BOOST ON request

SYNCBST_EN 1 1 1 Syncboost enable Updated by SSM_RESET or SPI write

0 SYNC_BOOST OFF request

1 SYNC_BOOST ON request

SPI_OFF 0 0 0 Go to POWER OFF state from POWERMODE SHUTDOWN state Updated by SSM_RESET or SPI write while in POWERMODE SHUTDOWN state 0 no effect 1 transition to POWER OFF state ERSWITCH_LIM_SEL 0 - - ERswitch current limitation select Updated by POR or SPI write

0 Low current limit

1 High current limit is no more available

SYBST_V 0 0 0 Sync Boost voltage select Updated by SSM_RESET or SPI write

0 Low - syncboost=12V

1 High - syncboost=14.75V

7.3.4 SPI Sleep command register (SPI_SLEEP)

ID: 03 Type: W Read: - Write: 0006

7.3.5 System status register (SYS_STATE)

ID: 04 Type: R Read: 0400 Write: - SAT_V 0 0 0 SatBuck and Satellite Interface voltage select Updated by SSM_RESET or SPI write 0 Low - satbuck=7.2V

1 High - satbuck=9V

19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - $3C95X MISO 0000-000000000000000 POR WSM SSM SLEEP_MODE N/A N/A N/A Non-latched command that allows transition into POWERMODE_SHUTDOWN state according to the Power Control State Flow Diagram 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI -X X X X X X X X X X X X X X X X MISO 00000 00 0 0 OPER_CTL_STATE 00 0 0 0 POWER_CTL_STATE POR WSM SSM OPER_CTL_STATE[2:0] 000 000 000 Reports Operating Control State Updated per Power Up Phases diagram 000 = INIT

001 = DIAG 010 = SAFING 011 = SCRAP 100 = ARMING 101 unused 110 unused 111 unused POWER_CTL_STATE[2:0] 000 - - Reports Power Control State Updated per Power Control State Flow Diagram 000 = AWAKE 001 = STARTUP 010 = RUN 011 = ER 100 = POWER MODE SHUTDOWN 101 unused 110 unused 111 unused

7.3.6 Power state register (POWER_STATE)

ID: 05 Type: R Read: 0500 Write: - 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI -X X X X X X X X X X X X X X X X MISO WAKEUP VBBAD NOT_VBGOOD VINBAD NOT_VINGOOD S_BST_NOK SATBUCK_NOK ER_BST_NOK VCC_UV VCC_OV ER_BST_ON ER_CHRG_ON ER_LCDIS_ON ER_HCDIS_ON ER_SW_ON S_BST_ACT SATBUCK_ACT VCC_ACT VSF_ACT POR WSM SSM WAKEUP - - - WAKEUP pin status Set and cleared based on voltage

0 WAKEUP pin < WU_off

1 WAKEUP pin > WU_on

VBBAD - - - VBATMON bad pin status Set and cleared based on voltage

1 VBATMON < VBBAD

0 VBATMON > VBBAD

NOT_VBGOOD - - - VBATMON good pin status Set and cleared based on voltage

1 VBATMON < VBGOOD

0 VBATMON > VBGOOD

VINBAD - - - VIN bad pin status Set and cleared based on voltage

0 VIN > VINBAD

1 VIN < VINBAD

NOT_VINGOOD - - - VIN good pin status Set and cleared based on voltage

0 VIN > VINGOOD

1 VIN < VINGOOD

S_BST_NOK - - - SYNCBOOST bad pin status

Set based on voltage, cleared on SPI read

1 V_SYNCBOOST < SYNCBOOST_OK

0 V_SYNCBOOST > SYNCBOOST_OK

SATBUCK_NOK - - - SATBUCK bad pin status Set based on voltage, cleared on SPI read

1 V_SATBUCK < SATBUCK_OK

0 V_SATBUCK > SATBUCK_OK

ER_BST_NOK - - - ERBOOST pin status Set and cleared based on voltage

1 V_ERBOOST < ERBOOST_OK

0 V_ERBOOST > ERBOOST_OK

VCC_UV - - - VCC_UV status Set based on voltage, cleared on SPI read

0 VCC > VCC_UV

1 VCC < VCC_UV

VCC_OV - - - VCC_OV status Set based on voltage, cleared on SPI read

0 VCC < VCC_OV

1 VCC > VCC_OV

ER_BST_ON 0 - - ERBOOST_ON state Updated according to ER_BOOST Control Behavior diagram

0 RBOOST_OFF or ERBOOST_OT state or ER_BST_STBY state (boost

not running)

1 ERBOOST_ON state (boost running)

ER_CHRG_ON 0 0 0 ERCHARGE_ON state Updated according to ER_CHARGE Power Mode Control diagram

0 ERCHARGE_ON = 0

1 ERCHARGE_ON = 1

ER_LCDIS_ON 0 - - ER Low Current Discharge State Updated according to ER Low current discharge state diagram

0 ER_LCDIS_OFF

1 ER_LCDIS_ON

ER_HCDIS_ON 0 - - ER High Current Discharge State Updated according to ER High Current discharge state diagram

0 ER_HCDIS_OFF

1 ER_HCDIS_ON

ER_SW_ON 0 - - ER_SWITCH State Updated according to ER Switch state diagram

0 ER_SWITCH_OFF

1 ER_SWITCH_ON

S_BST_ACT 0 - - SYNCBOOST Active state Updated according to SYNCBOOST Power Mode Control state diagram

0 SYNCBOOST supply in SYNCBOOST_OFF state

1 SYNCBOOST supply in SYNCBOOST_ON state

SATBUCK_ACT 0 0 0 SATBUCK Active state Updated according to SATBUCK Power Mode Control state diagram

0 SATBUCK supply in SATBUCK_OFF state

1 SATBUCK supply in SATBUCK_ON state

VCC_ACT 0 - - Buck Active state Updated according to VCC Power Mode Control state diagram

0 VCC supply in VCC_OFF or VCC_SHUTDOWN states

1 VCC supply in VCC_RAMPUP or VCC_ON states

VSF_ACT 0 0 0 VSF Active state Updated according to VSF Control Logic diagram

0 VSF_EN = 0

1 VSF_EN = 1

7.3.7 Deployment configuration registers (DCR_x)

Deployment Configuration Channel 0 (DCR_0) Deployment Configuration Channel 1 (DCR_1) Deployment Configuration Channel 2 (DCR_2) Deployment Configuration Channel 3 (DCR_3) Deployment Configuration Channel 5 (DCR_5) Deployment Configuration Channel 6 (DCR_6) Deployment Configuration Channel 7 (DCR_7) Deployment Configuration Channel 8 (DCR_8) Deployment Configuration Channel 9 (DCR_9) Deployment Configuration Channel A (DCR_A) Deployment Configuration Channel B (DCR_B) ID: 06 (DCR_0) 07 (DCR_1) 08 (DCR_2) 09 (DCR_3) 0A (DCR_4) 0B (DCR_5) 0C (DCR_6) 0D (DCR_7) 0E (DCR_8) 0F (DCR_9) 10 (DCR_A) 11 (DCR_B) Type: RW Read: 0600 (DCR_0) 0700 (DCR_1) 0800 (DCR_2) 0900 (DCR_3) 0A00 (DCR_4) 0B00 (DCR_5) 0C00 (DCR_6) 0D00 (DCR_7) 0E00 (DCR_8) 0F00 (DCR_9) 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - X X X X Deploy_Time Dep_Current Dep_expire_time X PD_CURR_CSR MISO 0 0 0 0 0 0 0 0 Deploy_Time Dep_Current Dep_expire_time PD_CURR_CSR

1000 (DCR_A) 1100 (DCR_B) Write: 000C (DCR_0) 000E (DCR_1) 0010 (DCR_2) 0012 (DCR_3) 0014 (DCR_4) 0016 (DCR_5) 0018 (DCR_6) 001A (DCR_7) 001C (DCR_8) 001E (DCR_9) 0020 (DCR_A) 0022 (DCR_B) POR WSM SSM Deploy_Time[5:0] 0000 0000 0000 Default deployment time = 0 us (no deployment, 8 us pulse output on ARM1 pin during PULSE TEST) Deployment time: actual deployment time (ms) = Deploy_Time*0.064ms (0.064ms/count up to 4.032ms max) Dep_Current[1:0] 00 00 00 Deployment Current limit select Updated by SSM_RESET or SPI write while in DIAG state

00 Unused (no deploy)

01 1.75A min 10 1.2A min

11 Unused (no deploy)

Dep_expire_time[1:0] 00 00 00 Deploy command expiration timer select Updated by SSM_RESET or SPI write while in DIAG state 00 500ms 01 250ms 10 125ms 11 0ms PD_CURR_CSR 000 Pull down current control for Commmon SR connection Updated by SSM_RESET or SPI write

0 PD Current OFF only for channel selected for diagnostic measurement,

1 PD Current OFF for both channels of the channel pair selected for

diagnostic measurement, ON for all other channel

7.3.8 Deployment command (DEPCOM)

ID: 12 Type: RW Read: 1200 Write: 0024 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI -X X X X CHBDEPREQ CHADEPREQ CH9DEPREQ CH8DEPREQ CH7DEPREQ CH6DEPREQ CH5DEPREQ CH4DEPREQ CH3DEPREQ CH2DEPREQ CH1DEPREQ CH0DEPREQ MISO 00000000 CHBDEP CHADEP CH9DEP CH8DEP CH7DEP CH6DEP CH5DEP CH4DEP CH3DEP CH2DEP CH1DEP CH0DEP POR WSM SSM CHxDEPREQ N/A N/A N/A Channel x Deploy Request - non-latched channel-specific deploy request

0 No change to deployment control for channel x

1 Clear and start Expiration timer if in ARMING or SAFING state and in

DEPLOY_ENABLED state CHxDEP 0 0 0 Channel x deployment expiration timer enable Set when SPI_DEPCOM(CHxDEPREQ=1) AND in ARMING or SAFING state AND in DEP_ENABLED state Cleared on SSM_RESET OR when in DEP_DISABLED state OR when Deploy Expiration Timer x reaches timeout threshold

1 Expiration timer enabled - Deploy command still valid

0 Expiration Timer disabled - Deploy command no more valid

7.3.9 Deployment status registers (DSR_x)

Deployment Status Channel 0 (DSR_0) Deployment Status Channel 1 (DSR_1) Deployment Status Channel 2 (DSR_2) Deployment Status Channel 3 (DSR_3) Deployment Status Channel 5 (DSR_5) Deployment Status Channel 6 (DSR_6) Deployment Status Channel 7 (DSR_7) Deployment Status Channel 8 (DSR_8) Deployment Status Channel 9 (DSR_9) Deployment Status Channel A (DSR_A) Deployment Status Channel B (DSR_B) ID: 13 (DSR_0) 14 (DSR_1) 15 (DSR_2) 16 (DSR_3) 17 (DSR_4) 18 (DSR_5) 19 (DSR_6) 1A (DSR_7) 1B (DSR_8) 1C (DSR_9) 1D (DSR_A) 1E (DSR_B) Type: R Read: 1300 (DSR_0) 1400 (DSR_1) 1500 (DSR_2) 1600 (DSR_3) 1700 (DSR_4) 1800 (DSR_5) 1900 (DSR_6) 1A00 (DSR_7) 1B00 (DSR_8) 1C00 (DSR_9) 1D00 (DSR_A) 1E00 (DSR_B) Write: - 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI -X X X X X X X X X X X X X X X X MISO 0000 CHxDS CHxSTAT DCRxERR DEP_CHx_ExpTimer

CHxDS 0 0 0 Channel x deployment successful Updated according to Deployment Driver Control Logic (set when deployment terminates on ch x due to deploy timer timeout, cleared on SSM_RESET OR when deployment starts on ch x)

0 Deployment not successful

1 Deployment successful

CHxSTAT 0 0 0 Channel x deployment status Updated according to Deployment Driver Control Logic (set when deployment starts on ch x, cleared on SSM_RESET OR when deployment terminates due to deploy timer timeout, LS Over current OR GND Loss)

0 Deployment not in progress

1 Deployment in progress

DCRxERR 0 0 0 Deployment configuration register error

0 Deploy configuration change accepted and stored in memory

1 Deploy configuration change rejected because deploy is in progress

(or DEP_EXPIRE_TIME changed when in DEP_ENABLED state) DEP_CHx_ExpTimer[5:0] 0000 0000 0000 Channel x Deployment Expiration Timer value 8ms/count Updated according to Deployment Driver Control Logic (Cleared on SSM_RESET OR when Exp Timer times out OR when SPI_DEPREQx is received while in DEP_ENABLED state AND in ARMING or SAFING states)

7.3.10 Deployment current monitor registers (DCMTSxy)

Deployment Current Monitor Status Channel 0,1 (DDCMTS01) Deployment Current Monitor Status Channel 2,3 (DDCMTS23) Deployment Current Monitor Status Channel 4,5 (DDCMTS45) Deployment Current Monitor Status Channel 6,7 (DDCMTS67) Deployment Current Monitor Status Channel 8,9 (DDCMTS89) Deployment Current Monitor Status Channel A,B (DDCMTSAB) ID: 1F (DDCMTS01) 20 (DDCMTS23) 21 (DDCMTS45) 22 (DDCMTS67) 23 (DDCMTS89) 24 (DDCMTSAB) Type: R Read: 1F00 (DDCMTS01) 2000 (DDCMTS23) 2100 (DDCMTS45) 2202 (DDCMTS67) 2300 (DDCMTS89) 2400 (DDCMTSAB) Write: - 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - XXXXXXXXXXXXXXXX MISO 0 0 0 0 Current_Mon_Timer_y[7:0] Current_Mon_Timer_x[7:0] POR WSM SSM Current_Mon_Timer_y[7:0] $00 $00 $00 Channel y current monitor timer value corresponding to SPI command DCMTSxy. Set to default (cleared) on SSM_RESET or when a new deployment starts on channel y. Increments each 16μs while deployment current exceeds monitor threshold on channel y Current_Mon_Timer_x[7:0] $00 $00 $00 Channel x current monitor timer value corresponding to SPI command DCMTSxy. Set to default (cleared) on SSM_RESET or when a new deployment starts on channel x. Increments each 16μs while deployment current exceeds monitor threshold on channel y

7.3.11 Deploy enable register (SPIDEPEN)

ID: 25 Type: RW Read: 2500 Write: 004A

7.3.12 Deployment ground loss register (LP_GNDLOSS)

ID: 26 Type: R Read: 2600 Write: - 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - DEPEN_WR[15:0] MISO 0 0 0 0 DEPEN_STATE[15:0] POR WSM SSM DEPEN_WR[15:0] N/A N/A N/A Non-latched encoded value for LOCK / UNLOCK command $0FF0 LOCK - enter DEP_DISABLED state $F00F UNLOCK - enter DEP_ENABLED state. DEPEN_STATE[15:0] $0FF0 $0FF0 $0FF0Deploy Enabled State Updated according to Global SPI Deployment Enable State Diagram $0FF0 In DEP_DISABLED state $F00F In DEP_ENABLED state 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - XXXXXXXXXXXXXXXX MISO 00000000 GNDLOSSB GNDLOSSA GNDLOSS9 GNDLOSS8 GNDLOSS7 GNDLOSS6 GNDLOSS5 GNDLOSS4 GNDLOSS3 GNDLOSS2 GNDLOSS1 GNDLOSS0 POR WSM SSM GNDLOSSx 0 0 0 Loop x Squib Ground loss Cleared upon SSM_RESET or SPI read. Set when GND loss is detected during deployment or loop diag's (HS sw test, LS sw test, squib resistance)

0 Loss of ground not detected

1 Loss of ground detected

7.3.13 Device version register (VERSION_ID)

ID: 27 Type: R Read: 2700 Write: - 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI -X X X X X X X X X X X X X X X X MISO 0 0 0 0 0 0 0 0 0 DEVICE ID 0 0 VERSN POR WSM SSM DEVICE ID - - - Identification of the device Static value - never updated

001 Low end

010 Medium end

011 High end

VERSN - - - Identification of the silicon version Static value - never updated

000000 AA version

000001 AB version

001000 BA version

001001 BB version

010000 CA version

010001 CB version

010010 CC version

7.3.14 Watchdog retry configuration register (WD_RETRY_CONF)

ID: 28 Type: RW Read: 2800 Write: 0050

7.3.15 Microcontroller fault test register (MCU_FLT_TEST)

ID: 29 Type: W Read: - Write: 0052 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - WD2_ERR_TH WD2_RETRY_TH X X X X X WD1_RETRY_TH MISO 0 0 0 0 0 0 WD2_ERR_TH WD2_RETRY_TH 0 0 0 0 0 WD1_RETRY_TH POR WSM SSM WD2_ERR_TH 4 4 - WD2 error counter threshold (number of W2 reset permitted before going to WD2_STOP state) WD2_RETRY_TH 4 4 - WD2 retry counter threshold (number of W2 errors permitted before asserting WD2_Lockout and increment WD2_ERRcnt) WD1_RETRY_TH 7 7 - WD1 retry counter threshold (number of WD errors permitted before latching WD1_LOCKOUT=1) 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - MCU_FLT_TEST Mode MISO 0 0 0 0 00 0000 0 000 0 0 0000 POR WSM SSM MCU_FLT_TEST $0FF0 $0FF0 $0FF0 MCU Fault Test Mode - Allows the masking of the MCUFLT_ERR and prevents reset $0FF0 Mask MCUFLT_ERR $F00F Do not mask MCUFLT_ERR

7.3.16 Watchdog timer configuration register (WDTCR)

ID: 2A Type: RW Read: 2A00 Write: 0054 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI -X WD1_MODE WDTMIN[6:0] WDTDELTA[6:0] MISO 00000 WD1_MODE WDTMIN[6:0] WDTDELTA[6:0] POR WSM SSM WD1_MODE 0 0 - WD1 Mode Updated by WSM_RESET or SPI write while in WD1_INIT state

0 Fast WD1 mode - nominal 8 μs timer resolution (2ms max value)

1 Slow WD1 mode - nominal 64 μs timer resolution (16.3ms max value) WDTMIN[6:0] $32 $32 - WD1 window minimum value - resolution according to WD1_MODE bit ($32 = 400μs in WD1 fast mode) Updated by WSM_RESET or SPI write while in WD1_INIT state WDTMIN[6:0] $19 $19 - WD1 window delta value - WDTMAX=WDTMIN+WDTDELTA - resolution according to WD1_MODE bit ($19 = 200μs in WD1 fast mode) Updated by WSM_RESET or SPI write while in WD1_INIT state

7.3.17 WD1 timer control register (WD1T)

ID: 2B Type: RW Read: 2B01 Write: 0056 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - X X X X X X X X X X X X X X WD1CTL[1:0] MISO 0 0 0 0 WD1_TIMER 0 0 0 0 0 0 WD1CTL[1:0] POR WSM SSM WD1CTL[1:0] 00 00 00 WD1 Control command Updated by SSM_RESET or SPI write

00 NOP

01 Code 'A'

10 Code 'B'

11 NOP

WD1_TIMER $00 $00 $00 WD1 Window timer value Cleared by SSM_RESET or by WD1 refresh, incremented every 8μs or 64μs while in WD1_RUN or WD1_TEST states

7.3.18 WD state register (WDSTATE)

ID: 2C Type: R Read: 2C00 Write: - 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI -X X X X X X X X X X X X X X X X MISO 0 0 0 0 0 WD1_ERR_CNT[3:0] WD_STATE[2:0] WD2_ERR_CNT[3:0] WD2_STATE[2:0] POR WSM SSM WD1_ERR_CNT[3:0] 0000 0000 - Watchdog 1 error counter Updated according to Watchdog State Diagram WD1_STATE[2:0] 000 000 - Watchdog state Updated according to Watchdog State Diagram

000 INITIAL

001 RUN

010 TEST

011 RESET

100 OVERRIDE

WD2_ERR_CNT[3:0] 0000 0000 - Watchdog 2 error counter Updated according to Watchdog State Diagram WD2_STATE[3:0] 0000 0000 - Watchdog state Updated according to Watchdog State Diagram

0000 INITIAL

0001 OVERRIDE

0010 INITSEED

0011 RUN

0100 TEST

0101 QUAL

0110 LOCK

0111 STOPPING

1000 STOP

1001 RESET

7.3.19 Clock configuration register (CLK_CONF)

ID: 2D Type: RW Read: 2D00 Write: 005A 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI -X X X X X X VCCBCK_F_SEL[1:0] SATBCK_F_SEL[1:0] SYBST_F_SEL[1:0] AUX_SS_DIS MAIN_SS_DIS ERBST_F_SEL[1:0] MISO 00000 00 0 0 0 VCCBCK_F_SEL SATBCK_F_SEL SYBST_F_SEL AUX_SS_DIS MAIN_SS_DIS ERBST_F_SEL POR WSM SSM VCCBCK_F_SEL[1:0] 00 - - VCCBuck switching frequency select Updated by POR or SPI write 00 1.88 MHz 01 2.13 MHz 10 2.00 MHz 11 2.00 MHz SATBCK_F_SEL[1:0] 00 - - SatBuck switching frequency select Updated by POR or SPI write 00 1.88 MHz 01 2.13 MHz 10 2.00 MHz 11 2.00 MHz SYBST_F_SEL[1:0] 00 - - Sync Boost switching frequency select Updated by POR or SPI write 00 1.88 MHz 01 2.13 MHz 10 2.00 MHz 11 2.00 MHz AUX_SS_DIS 1 - - Auxiliary oscillator Spread Spectrum disable Updated by POR or SPI write

0 Spread Spectrum enabled

1 Spread Spectrum disabled

7.3.20 Scrap seed read command register (SCRAP_SEED)

ID: 2E Type: R Read: - Write: 2E00 MAIN_SS_DIS 0 - - Main oscillator Spread Spectrum disable Updated by POR or SPI write ERBST_F_SEL[1:0] 00 - - ER Boost switching frequency select Updated by POR or SPI write 00 1.88 MHz 01 2.13 MHz 10 2.00 MHz 11 2.00 MHz 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI -X X X X X X X X X X X X X X X X MISO 0 0 0 0 0 0 0 0 0 0 0 0 SEED[7:0] POR WSM SSM N/A N/A N/A SEED[7:0] $00 $00 $00 Random scrap seed value - generated from a free-running 8-bit counter

7.3.21 Scrap key write command register (SCRAP_KEY)

ID: 2F Type: W Read: - Write: 005E

7.3.22 Scrap state entry command register (SCRAP_STATE)

ID: 30 Type: W Read: - Write: 0060 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - X X X X X X X X KEY[7:0] MISO 0 0 0 0 00 0000 0 000 0 0 0000 POR WSM SSM N/A N/A N/A KEY[7:0] $00 $00 $00 KEY value submitted to the SCRAP state machine (correct value is derived from the seed value using a simple logical inversion on the even-numbered bits (0, 2, 4, 6)) 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - $3535 MISO 0 0 0 0 00 0000 0 000 0 0 0000 POR WSM SSM N/A N/A N/A Non-latched Scrap State entry command Enter Scrap state from DIAG state

7.3.23 Safing state entry command register (SAFING_STATE)

ID: 31 Type: W Read: - Write: 0062

7.3.24 WD2 recover write command register (WD2_RECOVER)

ID: 32 Type: W Read: - Write: 0064 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - $ACAC MISO 0 0 0 0 00 0000 0 000 0 0 0000 POR WSM SSM N/A N/A N/A Non-latched Safing State entry command Enter safing state from DIAG state and clear arming pulse stretch counter (if received in DIAG or SAFING state) 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI -X X X X X X X X $AA MISO 0 0 0 0 00 0000 0 000 0 0 0000 POR WSM SSM N/A N/A N/A Non-latched command to clear WD2_retry counter during WD2 LOCK state

7.3.25 WD2 seed read command register (WD2_SEED)

ID: 33 Type: R Read: - Write: 3300

7.3.26 WD2 key write command register (WD2_KEY)

ID: 34 Type: W Read: - Write: 0068 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI -X X X X X X X X X X X X X X X X MISO 0 0 0 0 WD2_PREV_KEY[7:0] WD2_SEED[7:0] POR WSM SSM N/A N/A N/A WD2_PREV_KEY[7:0] $0D $0D $0D Previous WD2 key value - stored key from previous comparison WD2_SEED[7:0] $F0 $F0 $F0 Random WD2 seed value - generated from a free-running 8-bit counter 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - X X X X X X X X KEY[7:0] MISO 0 0 0 0 00 0000 0 000 0 0 0000 POR WSM SSM N/A N/A N/A KEY[7:0] $0D $0D $0D Previous WD2 key value - stored key from previous comparison (correct value is derived from WD2_KEY = WD2_SEED ‡ WD2_PREV_KEY + $01 where ‡ denotes a bit-wise XOR)

7.3.27 WD test command register (WD_TEST)

ID: 35 Type: W Read: - Write: 006A 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - WD1_TEST = $3C WD2_TEST = $3C MISO 0 0 0 0 00 0000 0 000 0 0 0000 POR WSM SSM N/A N/A N/A $0D $0D $0D Non-latched WD1 and WD2 Test Commands WD1_TEST and WD2_TEST SPI command as described in Watchdog State Diagram

7.3.28 System diagnostic register (SYSDIAGREQ)

ID: 36 Type: RW Read: 3600 Write: 006C 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - X X X X X X X X X X X X DSTEST[3:0] MISO 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 DSTEST[3:0] POR WSM SSM DSTEST[3:0] 0000 0000 0000 Diagnostic State Test selection Updated by SSM_RESET or SPI write while in DIAG state 0000 = all outputs inactive 0001 = ARM 1 pin active 0010 = ARM 2 pin active 0011 = ARM 3 pin active 0100 = ARM 4 pin active 0101 = PSINHB pin inactive (high) 0110 = VSF regulator active 0111 = HS squib driver FET active 1000 = LS squib driver FET active 1001 = Output deployment timing pulses on ARM1 (separated by 8 ms) 1010 = HS squib driver FET active to test full path (FET switched off by the comparator used in the deployment current timer monitor) 1011 - 1111 = all outputs inactive

7.3.29 Diagnostic result register for deployment loops (LPDIAGSTAT)

ID: 37 Type: R Read: 3700 Write: - 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI -X X X X X X X X X X X X X X X X MISO DIAG_LEVEL TIP 0F P FETON HS_DRV_OK HSR_HI HSR_LO RES_MEAS_CHSEL/HIGH_LEV_DIAG_SELECTED SBL STG STB SQP LEAK_CHSEL POR WSM SSM DIAG_LEVEL 0 0 0 Diagnostic mode selector Not present for low level diagnostic Updated by SSM_RESET or SPI write to LPDIAGREQ 0 low level mode 1 high level mode TIP 0 0 0 High level diagnostic test is running Updated by SSM_RESET or Loops diagnostic state machine

0 High level diagnostic test is not running

1 High level diagnostic test is running

FP 0 0 0 Fault present before requested diagnostic Updated by SSM_RESET or Loops diagnostic state machine

0 Fault not present before requested diagnostic

1 Fault present before requested diagnostic

FETON 0 0 0 FET activation during diagnostic Updated by SSM_RESET or Loops diagnostic state machine or when HS or LS FET is activated during DIAG state

0 FET is off during diagnostic

1 FET is on during diagnostic

HS_DRV_OK 0 0 0 FET Test Status Updated by SSM_RESET or Loops diagnostic state machine or when driver full path test is run test is run

0 HS squib driver full path test did not complete successfully

1 HS squib driver full path test complete successfully

HSR_HI 0 0 0 HSR Diagnostic - HIGH Range Updated by SSM_RESET or Loops diagnostic state machine or when squib resistance test is run

0 HSR measurement < HSR HIGH value

1 HSR measurement > HSR HIGH value

HSR_LO 0 0 0 HSR Diagnostic - Low Range Updated by SSM_RESET or Loops diagnostic state machine or when squib resistance test is run

1 HSR measurement< HSR LOW value

0 HSR measurement > HSR LOW value

RES_MEAS_CHSEL[3:0] 0000 0000 0000 Channel selected for resistance measurement HIGH_LEV_DIAG_SELECTED[3:0] Updated by SSM_RESET or Loops diagnostic state machine or as determined by squib resistance channel selected 0000 = Ch 0 0000 No diagnostic selected 0001 = Ch 1 0001 VRCM CHECK 0010 = Ch 2 0010 Leakage CHECK 0011 = Ch 3 0011 Short Between Loops CHECK 0100 = Ch 4 0100 Unused 0101 = Ch 5 0101Squib resistance range CHECK 0110 = Ch 6 0110 Squib resistance measurement 0111 = Ch 7 0111 FET test 1000 = Ch 8 1000 - 1111 Unused 1001 = Ch 9 1010 = Ch A 1011 = Ch B 0100 - 1111 None Selected

SBL 0 0 0 Short between loop state Updated by SSM_RESET or Loops diagnostic state machine

0 Short between squib loops is not present

1 Short between squib loops is present

STG 0 0 0 Short to Ground Test Status Updated by SSM_RESET or Loops diagnostic state machine or as determined by squib leakage diagnostic

0 STG not detected

1 STG detected

STB 0 0 0 Short to Battery Test Status Updated by SSM_RESET or Loops diagnostic state machine or as determined by squib leakage diagnostic

0 STB not detected

1 STB detected

SQP 0 0 0 Squib PIN where leakage test has been performed Updated by SSM_RESET or Loops diagnostic state machine or as determined by squib leakage diagnostic

0 SRx

1 SFx

LEAK_CHSEL[3:0] 0000 0000 0000 Channel selected for leakage measurement Updated by SSM_RESET or Loops diagnostic state machine or as determined by squib leakage diagnostic 0000 = Ch 0 0001 = Ch 1 0010 = Ch 2 0011 = Ch 3 0100 = Ch 4 0101 = Ch 5 0110 = Ch 6 0111 = Ch 7 1000 = Ch 8 1001 = Ch 9 1010 = Ch A 1011 = Ch B 1100 - 1111 None Selected

7.3.30 Loops diagnostic configuration command register for low level

diagnostic (LPDIAGREQ) ID: 38 Type: RW Read: 3800 Write: 0070 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - DIAG_LEVEL ISRC_CURR_SEL PD_CURR ISRC [1:0] ISINK VRCM[1:0] RES_MEAS_CHSEL[3:0] LEAK_CHSEL[3:0] MISO 0000 DIAG_LEVEL ISRC_CURR_SEL PD_CURR ISRC [1:0] ISINK VRCM[1:0] RES_MEAS_CHSEL[3:0] LEAK_CHSEL[3:0] POR WSM SSM DIAG_LEVEL 0 0 0 Diagnostic mode selector Updated by SSM_RESET or SPI write 0 low level mode

1 N/A - see description below

ISRC_CURR_SEL 0 0 0 Selection of ISRC current value 0 40mA 1 8mA PD_CURR 0 0 0 Pull down current control Updated by SSM_RESET or SPI write

0 Request OFF only for channels connected to VRCM or ISINK or ISRC,

1 Request OFF for all channels

ISRC [1:0] 00 00 00 High side current source for channel selected in RES_MEAS_CHSEL[3:0] Updated by SSM_RESET or SPI write 00 = OFF

01 = ON 40 mA/ 8 mA current for channel selected in RES_MEAS_CHSEL, OFF on all other channels 10 = ON bypass current for channel selected in RES_MEAS_CHSEL, OFF ON all other channels 11 = ON ISRC 40mA or 8mA current for channel selected in RES_MEAS_CHSEL and connect the SRM Differential Amplifier to the other squib channel of the selected channel pair ISINK 0 0 0 Low Side current sink control (max 50mA) Updated by SSM_RESET or SPI write

0 All channels OFF

1 ON for channel selected by RES_MEAS_CHSEL[3:0], OFF on all other

VRCM[1:0] 00 00 00 Voltage Regulator Current Monitor control Updated by SSM_RESET or SPI write

00 VRCM not connected

01 VRCM connected to SFx of channel selected by LEAK_CHSEL[3:0]

10 VRCM connected to SRx of channel selected by LEAK_CHSEL[3:0]

and pull down current of the same channel disabled

11 VRCM connected to SRx of channel selected by LEAK_CHSEL[3:0]

and pull down current of the same channel enabled (ISINK and ISRC must be switched off) RES_MEAS_CHSEL[3:0] 0000 0000 0000 Squib Resistance Measurement Channel select - selects the channel and muxes for the resistance test, and the channel for HS driver test (full path fet test) activation Updated by SSM_RESET or SPI write

0000 Channel 0

0001 Channel 1

0010 Channel 2

0011 Channel 3

0100 Channel 4

0101 Channel 5

0110 Channel 6

0111 Channel 7

1000 Channel 8

1001 Channel 9

1010 Channel A

1011 Channel B

LEAK_CHSEL[3:0] 0000 0000 0000 Squib Leakage Measurement Channel select - selects the channel and muxes for the leakage test, and the channel for HS/LS FET test activation. Updated by SSM_RESET or SPI write

7.3.31 Loops diagnostic configuration command register for high level

diagnostic (LPDIAGREQ) ID: 38 Type: RW Read: 3800 Write: 0070 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - DIAG_LEVEL XXX XX XX HIGH_LEVEL_DIAG_SEL SQP LOOP_DIAG_CHSEL[3:0] MISO 0000 DIAG_LEVEL 000 00 00 HIGH_LEVEL_DIAG_SEL SQP LOOP_DIAG_CHSEL[3:0] POR WSM SSM DIAG_LEVEL 0 0 0 Diagnostic mode selector

00 N/A - see description above

HIGH_LEVEL_DIAG_SEL 000 000 000 Selection of high level squib diagnostic Updated by SSM_RESET or SPI write

000 No diagnostic selected

001 VRCM CHECK

010 Leakage CHECK

011 Short Between Loops CHECK

100 Unused

101 Squib resistance range CHECK

110 Squib resistance measurement

111 FET test

SQP 0 0 0 Squib pin select for all leakage diagnostic Updated by SSM_RESET or SPI write

7.3.32 DC sensor diagnostic configuration command register (SWCTRL)

ID: 39 Type: RW Read: 3900 Write: 0072 LOOP_DIAG_CHSEL[3:0] 0000 0000 0000 Channel select - selects the channel and muxes for all squib diagnostic. Updated by SSM_RESET or SPI write 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI -X X X X X X X PSINHPOL DCS_PDCURR SWOEN X X CHID[3:0] MISO 00000 00 0 0 00 PSINHPOL DCS_PDCURR SWOEN 0 0 CHID[3:0] POR WSM SSM PSINHPOL 0 0 0 Selector of in range/ out of range for passenger inhibit function 0 if result is inside thresholds the counter is initialized to start value 1 if result is outside thresholds the counter is initialized to start value DCS_PDCURR 0 0 0 Disable of all pull down current for DC sensor Updated by SSM_RESET or SPI write

0 OFF for channel under voltage or current measurement, ON for all other

1 OFF for all channels

SWOEN 0 0 0 Switch Output Enable Updated by SSM_RESET or SPI write

0 OFF

CHID[3:0] 0000 0000 0000 Channel ID - selects DC sensor channel for output activation Updated by SSM_RESET or SPI write

7.3.33 ADC request and data registers (DIAGCTRL_x)

ADC A control command (DIAGCTRL_A) ID: 3A Type: RW Read: 3A00 Write: 0074 ADC B control command (DIAGCTRL_B) ID: 3B Type: RW Read: 3B00 Write: 0076 ADC C control command (DIAGCTRL_C) ID: 3C Type: RW Read: 3C00 Write: 0078 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - X X X X X X X X X ADCREQ_A[6:0] MISO NEWDATA_A 0 0 ADCREQ_A[6:0] ADCRES_A[9:0] 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - X X X X X X X X X ADCREQ_B[6:0] MISO NEWDATA_B 0 0 ADCREQ_B[6:0] ADCRES_B[9:0] 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - X X X X X X X X X ADCREQ_C[6:0] MISO NEWDATA_C 0 0 ADCREQ_C[6:0] ADCRES_C[9:0]

ADC D control command (DIAGCTRL_D) ID: 3D Type: RW Read: 3D00 Write: 007A 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - X X X X X X X X X ADCREQ_D[6:0] MISO NEWDATA_D 0 0 ADCREQ_D[6:0] ADCRES_D[9:0] POR WSM SSM NEWDATA_x 0 0 0 New data available from convertion Updated by SSM_RESET or ADC state machine 0 cleared on read 1 convertion finished ADCREQ_x[6:0] $00 $00 $00 ADC Request select command Updated by SSM_RESET or SPI write to DIAGCTRL_x Measurement $00 Unused $01 Ground Ref $02 Full scale Ref $03 DCSx voltage $04 DCSx current $05 DCSx resistance $06 Squib x resistance $07 Internal BG reference voltage (BGR) $08 Internal BG monitor voltage (BGM) $09 Vcore $0A Temperature $0B DCS 0 voltage $0C DCS 1 voltage $0D DCS 2 voltage $0E DCS 3 voltage $0F DCS 4 voltage $10 DCS 5 voltage $11 DCS 6 voltage $12 DCS 7 voltage $13 DCS 8 voltage

$14 Vb voltage of ER ESR measure (valid only for ADCREQ_x field of MISO response when ESR measure results are available) $15 Va voltage of ER ESR measure (valid only for ADCREQ_x field of MISO response when ESR measure results are available) $16 Vc voltage of ER ESR measure (valid only for ADCREQ_x field of MISO response when ESR measure results are available) $20 VBATMON pin voltage $21 VIN pin voltage $22 Internal analog supply voltage (VINT) $23 Internal digital supply voltage (VDD) $24 ERBOOST pin voltage $25 SYNCBOOST pin voltage $26 VER pin voltage $27 SATBUCK voltage $28 VCC voltage $29 WAKEUP pin voltage $2A VSF pin voltage $2B WDTDIS pin voltage $2C GPOD0 pin voltage $2D GPOS0 pin voltage $2E GPOD1 pin voltage $2F GPOS1 pin voltage $30 GPOD2 pin voltage $31 GPOS2 pin voltage $32 RSU0 pin Voltage $33 RSU1 pin Voltage $34 RSU2 pin Voltage $35 RSU3 pin Voltage $36 SS0 pin voltage $37 SS1 pin voltage $38 SS2 pin voltage $39 SS3 pin voltage $3A SS4 pin voltage $3B SS5 pin voltage $3C SS6 pin voltage $3D SS7 pin voltage $3E SS8 pin voltage $3F SS9 pin voltage $40 SSA pin voltage $41 SSB pin voltage $46 SF0 $47 SF1 $48 SF2 $49 SF3 $4A SF4 $4B SF5 $4C SF6 $4D SF7

7.3.34 Configuration register for switching regulators (SW_REGS_CONF)

ID: 3F Type: RW Read: 3F00 Write: 007E $4E SF8 $4F SF9 $50 SFA $51 SFB ADCRES_x[9:0] $000 $000 $000 10-bit ADC result value corresponding to ADCREQ_x request Updated by SSM_RESET or ADC state machine 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - LOW_ERBST_ILIM_ERON EN_VCC_GNDLOSS_DET EN_SAT_GNDLOSS_DET SATBCK_LS_ON_DELAY VCCBCK_LS_ON_DELAY SATBCK_FORCE_F_SLOPE SYBST_FORCE_F_SLOPE ERBST_FORCE_F_SLOPE VCCBCK_PH_SEL[1:0] SATBCK_PH_SEL[1:0] SYBST_PH_SEL[1:0] ERBST_PH_SEL[1:0] MISO 0000 LOW_ERBST_ILIM_ERON EN_VCC_GNDLOSS_DET EN_SAT_GNDLOSS_DET SATBCK_LS_ON_DELAY VCCBCK_LS_ON_DELAY SATBCK_FORCE_F_SLOPE SYBST_FORCE_F_SLOPE ERBST_FORCE_F_SLOPE VCCBCK_PH_SEL SATBCK_PH_SEL SYBST_PH_SEL ERBST_PH_SEL POR WSM SSM LOW_ERBST_ILIM_ERON 0 - - ERBoost current limitation behavior selection Updated by POR or SPI write

0 ERBoost current limitation is NOT reduced if ER Switch is activated

1 ERBoost current limitation is reduced if ER Switch is activated

EN_VCC_GNDLOSS_DET 0 - - New VCC ground loss detection enable Updated by POR or SPI write 0 run time ground loss detection disabled 1 run time ground loss detection enabled EN_SAT_GNDLOSS_DET 0 - - New SAT ground loss detection enable Updated by POR or SPI write 0 run time ground loss detection disabled

1 run time ground loss detection enabled SATBCK_LS_ON_DELAY 0 - - SATBuck low side activation delay Updated by POR or SPI write

0 No delay is applied

1 Delay is applied

VCCBCK_LS_ON_DELAY 0 - - SVCCBuck low side activation delay Updated by POR or SPI write SATBCK_FORCE_F_SLOPE 0 - - SatBuck fast slope selection Updated by POR or SPI write

0 Fast slope activation depends on VIN voltage

1 Fast slope is forced ON

SYBST_FORCE_F_SLOPE 0 - - SyncBoost fast slope selection Updated by POR or SPI write ERBST_FORCE_F_SLOPE 0 - - ER Boost fast slope selection Updated by POR or SPI write VCCBCK_PH_SEL[1:0] 11 - - VCCBuck phase shifting selection (if switching frequency is different respect to another regulator, the phase shift between them is not guaranteed) Updated by POR or SPI write 00 0 ns switching ON shift respect to t0 01 125 ns switching ON shift respect to t0 10 250 ns switching ON shift respect to t0 11 375 ns switching ON shift respect to t0 SATBCK_PH_SEL[1:0] 10 - - SatBuck phase shifting selection (if switching frequency is different respect to another regulator, the phase shift between them is not guaranteed) Updated by POR or SPI write 00 0 ns switching ON shift respect to t0 01 125 ns switching ON shift respect to t0 10 250 ns switching ON shift respect to t0 11 375 ns switching ON shift respect to t0

7.3.35 Global configuration register for GPO driver function (GPOCR)

ID: 42 Type: RW Read: 4200 Write: 0084 SYBST_PH_SEL[1:0] 01 - - SyncBoost phase shifting selection (if switching frequency is different respect to another regulator, the phase shift between them is not guaranteed) Updated by POR or SPI write 00 0 ns switching ON shift respect to t0 01 125 ns switching ON shift respect to t0 10 250 ns switching ON shift respect to t0 11 375 ns switching ON shift respect to t0 ERBST_PH_SEL[1:0] 00 - - ER Boost phase shifting selection (if switching frequency is different respect to another regulator, the phase shift between them is not guaranteed) Updated by POR or SPI write 00 0 ns switching ON shift respect to t0 01 125 ns switching ON shift respect to t0 10 250 ns switching ON shift respect to t0 11 375 ns switching ON shift respect to t0 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI -X X X X X X X X X X X X X GPO2LS GPO1LS GPO0LS MISO 0 0 0 0 00 0000 0 000 0 0 0 GPO2LS GPO1LS GPO0LS POR WSM SSM GPOxLS 0 0 0 GPO driver configuration bit Updated by SSM_RESET or SPI write

0 High-side Driver configuration for GPOx (ER_BOOST_OK is required to

enable GPO as HS)

1 Low-side Driver configuration for GPOx (ER_BOOST_OK is not required

to enable GPO as LS)

7.3.36 GPOx control register (GPOCTRLx)

Channel 0 (GPOCTRL0) Channel 1 (GPOCTRL1) Channel 2 (GPOCTRL2) ID: 43 (GPOCTRL0) 44 (GPOCTRL1) 45 (GPOCTRL2) Type: RW Read: 4300 (GPOCTRL0) 4400 (GPOCTRL1) 4500 (GPOCTRL2) Write: 0086 (GPOCTRL0) 0088 (GPOCTRL1) 008A (GPOCTRL2) 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - X X X X X X X X X X GPOxPWM[5:0] MISO 0 0 0 0 0 0 0 0 0 0 0 0 0 0 GPOxPWM[5:0] POR WSM SSM GPOxPWM 000000 000000 000000 6 bit value for PWM% with scaling of 1.6% per count Updated by SSM_RESET or SPI write

7.3.37 GPO fault status register (GPOFLTSR)

ID: 46 Type: R Read: 4600 Write: - 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI -X X X X X X X X X X X X X X X X MISO GPO2DISABLE GPO1DISABLE GPO0DISABLE GPOS_NOT_CONF GPO2TEMP GPO2LIM GPO2ONOPN GPO2OFFOPN GPO2SHORT GPO1TEMP GPO1LIM GPO1ONOPN GPO1OFFOPN GPO1SHORT GPO0TEMP GPO0LIM GPO0ONOPN GPO0OFFOPN GPO0SHORT POR WSM SSM GPO2DISABLE 1 1 1 GPO 2 disable state

0 GPO enable to work

1 GPO disabled due to thermal fault or configuration not received or

ERBOOST not OK (only HS mode) GPO1DISABLE 1 1 1 GPO 1 disable state ERBOOST not OK (only HS mode) GPO0DISABLE 1 1 1 GPO 0 disable state ERBOOST not OK (only HS mode) GPOS_NOT_CONF 1 1 1 GPOs configuration status

0 GPOs configured (activation is permitted)

1 GPOs not yet configured (activation is denied)

GPO2TEMP 0 0 0 GPO 2Thermal Fault Cleared as reported in GPO-Over Temp diagram, set by detection circuit

0 Fault not detected

1 Fault detected

GPO2LIM 0 0 0 GPO 2 Current Limit Flag Cleared by SSM_RESET or SPI read, set by detection circuit while ON GPO2ONOPN 0 0 0 GPO 2 Open Detection Cleared by SSM_RESET or SPI read, set by detection circuit while ON GPO2OFFOPN 0 0 0 GPO 2 Open detection in OFF condition Cleared by SSM_RESET or SPI read, set by detection circuit while OFF GPO2SHORT 0 0 0 GPO 2 Short Detection in OFF condition (short to battery in HS mode, short to ground in LS mode) Cleared by SSM_RESET or SPI read, set by detection circuit while OFF GPO1TEMP 0 0 0 GPO 1 Thermal Fault Cleared as reported in GPO-Over Temp diagram, set by detection circuit GPO1LIM 0 0 0 GPO 1 Current Limit Flag Cleared by SSM_RESET or SPI read, set by detection circuit while ON GPO1ONOPN 0 0 0 GPO 1 Open Detection Cleared by SSM_RESET or SPI read, set by detection circuit while ON GPO1OFFOPN 0 0 0 GPO 1 Open detection in OFF condition Cleared by SSM_RESET or SPI read, set by detection circuit while OFF

GPO1SHORT 0 0 0 GPO 1 Short Detection in OFF condition (short to battery in HS mode, short to ground in LS mode) Cleared by SSM_RESET or SPI read, set by detection circuit while OFF GPO0TEMP 0 0 0 GPO 0 Thermal Fault Cleared as reported in GPO-Over Temp diagram, set by detection circuit GPO0LIM 0 0 0 GPO 0 Current Limit Flag Cleared by SSM_RESET or SPI read, set by detection circuit while ON GPO0ONOPN 0 0 0 GPO 0 Open Detection OK Cleared by SSM_RESET or SPI read, set by detection circuit while ON GPO0OFFOPN 0 0 0 GPO 0 Open detection in OFF condition Cleared by SSM_RESET or SPI read, set by detection circuit while OFF GPO0SHORT 0 0 0 GPO 0 Short Detection in OFF condition (short to battery in HS mode, short to ground in LS mode) Cleared by SSM_RESET or SPI read, set by detection circuit while OFF

7.3.38 Wheel speed sensor test request register (WSS_TEST)

ID: 48 Type: RW Read: 4800 Write: 0090 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - X X X X X X X WSSSEL [6:0] X WSSTP MISO 0 0 0 0 0 0 0 0 0 0 0 WSSSEL [6:0] X WSSTP POR WSM SSM WSSSEL [6:0] 000000 000000 000000 Wheel Speed Sensor Selection - code below uniquely selects one of the four WSx outputs to place a static output level on

1010011 WSS Test Mode for WS3 Output

1010101 WSS Test Mode for WS2 Output

1011001 WSS Test Mode for WS1 Output

1010110 WSS Test Mode for WS0 Output

all other WSS Test Mode disabled WSSTP 0 0 0 WSx Output Test Value

1 Output for selected WSx set 'high'

0 Output for selected WSx set 'low'

7.3.39 PSI5/WSS configuration register for channel x (RSCRx)

PSI5/WSS configuration register for channel 0 (RSCR0) PSI5/WSS configuration register for channel 1 (RSCR1 PSI5/WSS configuration register for channel 2 (RSCR2) PSI5/WSS configuration register for channel 3 (RSCR3 ID: 4A (RSCR0) 4B (RSCR1) 4C (RSCR2) 4D (RSCR3) Type: RW Read: 4A00 (RSCR0) 4B00 (RSCR1) 4C00 (RSCR2) 4D00 (RSCR3) Write: 0094 (RSCR0) 0096 (RSCR1) 0098 (RSCR2) 009B (RSCR3) 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - REDUCED_RANGE BLOCK_CURR_IN_MSG PERIOD_MEAS_DISABLE FIX_THRESH TSxDIS BLKTxSEL WSFILT[3:0] RSPTEN AVG/SSDIS STS[3:0] MISO 0000 REDUCED_RANGE BLOCK_CURR_IN_MSG PERIOD_MEAS_DISABLE FIX_THRESH TSxDIS BLKTxSEL WSFILT[3:0] RSPTEN AVG/SSDIS STS[3:0] POR WSM SSM PSI5 configured channel REDUCED_RANGE 0 0 0 Tracking speed of base and delta current 0 Fast tracking of Ibase if rx_sat_pre_filt is low; Slow tracking otherwise. Fast tracking of Idelta if rx_sat_pre_filt is high; Blocked otherwise.

1 Fast tracking of Ibase if current is less than (Ibase+(Idelta/4));

Slow tracking otherwise. Fast tracking of Idelta if current is higher than (top current -(Idelta/4)); Slow otherwise.

BLOCK_CURR_IN_MSG 0 0 0 Tracking enable of base and delta current during message transmission 0 Ibase tracking is enabled during blanking and after start bits recognition. Idelta tracking is disabled during blanking and enabled after start bits recognition.

1 Ibase tracking is enabled during blanking and disabled after start bits

recognition. Idelta tracking is disabled during blanking and enabled after start bits recognition PERIOD_MEAS_DISABLE 0 0 0 Disabling of start bits period measure to decode following bits

0 Period is measured

1 Period is not measured (default is used)

FIX_THRESH 0 0 0 PSI5 selection of fixed or auto adaptive thresholds 0 auto adaptive threshold 1 fixed threshold (threshold is latched when this bit is set to high, we recommend to set this bit before enabling of the interface) TSxDIS 0 0 0 Time Slot Control Disable

0 Slot control enabled

1 Slot control disabled

BLKTxSEL 0 0 0 Blanking Time Selection

0 Blanking time = 5ms

1 Blanking time = 10ms

WSFILT[3:0] 0010 0010 0010 Wheel speed filter time selection 189k: 125k: (16+x)*Tosc (24+x)*Tosc Tosc=1/16MHz RSPTEN 0 0 0 Pass Through mode Enable AVG/SSDIS 0 0 0 Current average enable during message transmission

0 Off (base and delta work as configured with bits 12, 14, 15)

On: base is freezed during data message and during blanking time and delta is averaged during message (fcut of the filter=2500 Hz) while is freezed during blanking time.

STSx[3:0] 0000 0000 0000 Sensor Type Selection

0000 Synchronous PSI5, parity, 8-bit, 125k (P8P-500/3L)

0001 Synchronous PSI5, parity, 8-bit, 189k (P8P-500/3H)

0010 Synchronous PSI5, parity, 10-bit, 125k (P10P-500/3L)

0011 Synchronous PSI5, parity, 10-bit, 189k (P10P-500/3H)

0100 unused (default automatically selected) 0101 unused (default automatically selected) 0110 unused (default automatically selected) 0111 unused (default automatically selected) 1000 NA 1001 NA 1010 NA 1011 NA 1100 unused (default automatically selected) 1101 unused (default automatically selected) 1110 unused (default automatically selected) 1111 unused (default automatically selected) Wheel speed configured channel REDUCED_RANGE 0 0 0 Tracking speed of base and delta current XN A BLOCK_CURR_IN_MSG 0 0 0 Tracking enable of base and delta current during message transmission XN A PERIOD_MEAS_DISABLE 0 0 0 Disabling of start bits period measure to decode following bits XN A FIX_THRESH 0 0 0 PSI5 selection of fixed or auto adaptive thresholds 0 auto adaptive threshold 1 fixed thresholds (configured through SPI registers) TSxDIS 0 0 0 Time Slot Control Disable XN A BLKTxSEL 0 0 0 Blanking Time Selection XN A WSFILT[3:0] 0010 0010 0010 Wheel speed filter time selection (500ns per bit) 0000 8 us - - - - 500ns/bit 1111 15.5μs:

RSPTEN 0 0 0 Pass Through mode Enable (only for PWM 2-edges sensors) AVG/SSDIS 000 WSx output pulses disabled in case of Standstill condition (valid only for PWM Encoded 2 edges sensors)

0 WSx enabled during Standstill

1 WSx disabled during Standstill

STSx[3:0] 0000 0000 0000 Sensor Type Selection 0000 NA 0001 NA 0010 NA 0011 NA 0100 unused (default automatically selected) 0101 unused (default automatically selected) 0110 unused (default automatically selected) 0111 unused (default automatically selected)

1000 Two-Level, Standard

1001 Three-Level, VDA

1010 PWM Encoded, 2-Level, 2 edges/tooth

1011 PWM Encoded, 2-Level, 1 edge/tooth

1100 unused (default automatically selected) 1101 unused (default automatically selected) 1110 unused (default automatically selected) 1111 unused (default automatically selected)

7.3.40 Remote sensor control register (RSCTRL)

ID: 4E Type: R/W Read: 4E00 Write: 009C 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI -X X X X X X X X CH3EN SYNC3E CH2EN SYNC2E CH1EN SYNC1E CH0EN SYNC0E MISO 00000 00 0 0 000 CH3EN SYNC3E CH2EN SYNC2E CH1EN SYNC1E CH0EN SYNC0E POR WSM SSM CHxEN 0 0 0 Channel x Output enable Updated by SSM_RESET or SPI write SYNCxEN 0 0 0 Channel x Sync Pulse Enable

7.3.41 WSS Threshold configuration register 1 (RS_AUX_CONF1)

ID: 64 Type: R/W Read: 6400 Write: 00C8

7.3.42 WSS Threshold configuration register 2 (RS_AUX_CONF2)

ID: 65 Type: R/W Read: 6500 Write: 00CB 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - X X X X X X X X WSS_LOW_THRESH [7:0] MISO 0 0 0 0 0 0 0 0 0 0 0 0 WSS_LOW_THRESH [7:0] POR WSM SSM WSS_LOW_THRESH [7:0] $33 $33 $33 Low threshold setting in case of fixed threshold is selected (93,75 μA +/-9% each LSB). Low threshold = ($36+WSS_LOW_THRESH)*93,75 μA) 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - X X X X X X X X WSS_LOW_THRESH [7:0] MISO 0 0 0 0 0 0 0 0 0 0 0 0 WSS_LOW_THRESH [7:0] POR WSM SSM WSS_LOW_THRESH [7:0] $34 $34 $34 Delta threshold setting in case of fixed threshold is selected (93,75 μA +/-9% each LSB). High threshold = ($6C+WSS_LOW_THRESH+WSS_OFFSET_THRESH)*93,75 μA)

7.3.43 Safing algorithm configuration register (SAF_ALGO_CONF)

ID: 66 Type: R/W Read: 6600 Write: 00CC 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - NO_DATA X ARMN_TH ARMP_TH SUB_VAL ADD_VAL MISO 0000 NO_DATA ARMN_TH ARMP_TH SUB_VAL ADD_VAL POR WSM SSM NO_DATA 0 0 0 Event counter no data select Updated by SSM_RESET or SPI write while in DIAG state

0 Event counter reset to 0 if CC=0 or (ABS value of response > limit

determined by LIM_SELx) and LIM_ENx=1 when SPI read of SAF_CC bit is performed (end of sample cycle)

1 Event counter decremented by SUB_VAL if CC=0 or (ABS value of

response > limit determined by LIM_SELx) and LIM_ENx=1 when SPI read of SAF_CC bit is performed (end of sample cycle) ARMN_TH 0011 0011 0011 Negative event counter threshold to assert arming Updated by SSM_RESET or SPI write while in DIAG state

0000 Negative event counter disabled

ARMP_TH 0011 0011 0011 Positive event counter threshold to assert arming Updated by SSM_RESET or SPI write while in DIAG state

0000 Positive event counter disabled

SUB_VAL 011 011 011 Decremental step size of the event counter Updated by SSM_RESET or SPI write while in DIAG state ADD_VAL 001 001 001 Incremental step size of the event counter Updated by SSM_RESET or SPI write while in DIAG state

7.3.44 Arming signals register (ARM_STATE)

ID: 6A Type: R Read: 6A00 Write: - 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI -X X X X X X X X X X X X X X X X MISO 00000 00 0 0 0 PSINHINT PSINH_EXP_TIME ACL_PIN_STATE ACL_VALID ARMINT_4 ARMINT_3 ARMINT2 ARMINT_1 POR WSM SSM ARMINT_x - - - State of armint signals Updated per Safing Engine output logic diagram in case of internal safing engine otherwise is the echo of ARMx pins ACL_VALID 0 0 0 Valid ACL detection

0 Cleared when ACL_BAD=2

1 Set when ACL_GOOD=3

ACL_PIN_STATE - - - Echo of ACL pin PSINH_EXP_TIME 0 0 0 State of PSINH expiration timer

0 If timer is 0

1 If timer is counting

PSINHINT - - - State of PSINHINT signal Updated per PSINH output logic diagram in case of internal engine otherwise is the echo of PSINH pin inverted

7.3.45 ARMx assignment registers to specific Loops (LOOP_MATRIX_ARMx)

Assignment of ARM1 to specific loops (LOOP_MATRIX_ARM1) Assignment of ARM2 to specific loops (LOOP_MATRIX_ARM2) Assignment of ARM3 to specific loops (LOOP_MATRIX_ARM3) Assignment of ARM4 to specific loops (LOOP_MATRIX_ARM4) ID: 6E (LOOP_MATRIX_ARM1) 6F (LOOP_MATRIX_ARM2) 70 (LOOP_MATRIX_ARM3) 71 (LOOP_MATRIX_ARM4) Type: RW Read: 6E00 (LOOP_MATRIX_ARM1) 6F00 (LOOP_MATRIX_ARM2) 7000 (LOOP_MATRIX_ARM3) 7100 (LOOP_MATRIX_ARM4) Write: 00DC (LOOP_MATRIX_ARM1) 00DE (LOOP_MATRIX_ARM2) 00E0 (LOOP_MATRIX_ARM3) 00E2 (LOOP_MATRIX_ARM4) 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI -X X X X ARMx_LB ARMx_LA ARMx_L9 ARMx_L8 ARMx_L7 ARMx_L6 ARMx_L5 ARMx_L4 ARMx_L3 ARMx_L2 ARMx_L1 ARMx_L0 MISO 00000 00 0 ARMx_LB ARMx_LA ARMx_L9 ARMx_L8 ARMx_L7 ARMx_L6 ARMx_L5 ARMx_L4 ARMx_L3 ARMx_L2 ARMx_L1 ARMx_L0 POR WSM SSM ARMx_Ly 0 0 0 Configures ARMx for Loop_y Updated by SSM_RESET or SPI write while in DIAG state

0 ARMx signal is not associated with Loopy

1 ARMx signal is associated with Loopy

7.3.46 ARMx enable pulse stretch timer status (AEPSTS_ARMx)

ARM1 enable pulse stretch timer status (AEPSTS_ARM1) ARM2 enable pulse stretch timer status (AEPSTS_ARM2) ARM3 enable pulse stretch timer status (AEPSTS_ARM3) ARM4 enable pulse stretch timer status (AEPSTS_ARM4) ID: 73 (AEPSTS_ARM1) 74 (AEPSTS_ARM2) 75 (AEPSTS_ARM3) 76 (AEPSTS_ARM4) Type: R Read: 7300 (AEPSTS_ARM1) 7400 (AEPSTS_ARM2) 7500 (AEPSTS_ARM3) 7600 (AEPSTS_ARM4) Write: - 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI -X X X X X X X X X X X X X X X X MISO 0 0 0 0 0 0 0 0 0 0 Timer Count[9:0] POR WSM SSM Timer Count $000 $000 $000 10-bit ARMing Enable Pulse Stretcher timer value Cleared by SSM_RESET Loaded with initial value based on ARMx bit and DWELL[1:0] of SAF_CONTROL_y while safing is met for record y provided current value is < DWELL[1:0] value Decremented every 2ms while > 0 Contains remaining pulse stretcher timer value

7.3.47 Passenger inhibit upper threshold for DC sensor 0 (PADTHRESH_HI)

ID: 78 Type: RW Read: 7800 Write: 00F0

7.3.48 Passenger inhibit lower threshold for DC sensor 0 (PADTHRESH_LO)

ID: 79 Type: RW Read: 7900 Write: 00F2 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - X X X X X X PADTHRESH_HI MISO 0 0 0 0 0 0 0 0 0 0 PADTHRESH_HI POR WSM SSM PADTHRESH_HI $000 $000 $000 Upper threshold - measurements above this upper value will assert the PSINH signal and deactivate loops identified in the PSINH mask 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - X X X X X X PADTHRESH_LO MISO 0 0 0 0 0 0 0 0 0 0 PADTHRESH_LO POR WSM SSM PADTHRESH_LO $3FF $3FF $3FFLower threshold - measurements below this lower value will assert the PSINH signal and deactivate loops identified in the PSINH mask

7.3.49 Assignment of PSINH signal to specific Loop(s)

(LOOP_MATRIX_PSINH) ID: 7A Type: RW Read: 7A00 Write: 00F4

7.3.50 Safing records enable register (SAF_ENABLE)

ID: 7F Type: RW Read: 7F00 Write: 00FE 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI -X X X X PSINH_LB PSINH_LA PSINH_L9 PSINH_L8 PSINH_L7 PSINH_L6 PSINH_L5 PSINH_L4 PSINH_L3 PSINH_L2 PSINH_L1 PSINH_L0 MISO 00000 00 0 PSINH_LB PSINH_LA PSINH_L9 PSINH_L8 PSINH_L7 PSINH_L6 PSINH_L5 PSINH_L4 PSINH_L3 PSINH_L2 PSINH_L1 PSINH_L0 POR WSM SSM PSINH_Ly 0 0 0 Configures PSINH for Loop_y

0 PSINH signal is not associated with Loopy

1 PSINH signal is associated with Loopy

19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - EN_SAF16 EN_SAF15 EN_SAF14 EN_SAF13 EN_SAF12 EN_SAF11 EN_SAF10 EN_SAF9 EN_SAF8 EN_SAF7 EN_SAF6 EN_SAF5 EN_SAF4 EN_SAF3 EN_SAF2 EN_SAF1 MISO 0000 EN_SAF16 EN_SAF15 EN_SAF14 EN_SAF13 EN_SAF12 EN_SAF11 EN_SAF10 EN_SAF9 EN_SAF8 EN_SAF7 EN_SAF6 EN_SAF5 EN_SAF4 EN_SAF3 EN_SAF2 EN_SAF1 POR WSM SSM EN_SAFx 000 Safing Record enable Updated by SSM_RESET or SPI write

0 Disable

1 Enable

7.3.51 Safing records request mask registers (SAF_REQ_MASK_x)

Safing record request mask for record 1 (SAF_REQ_MASK_1) Safing record request mask for record 2 (SAF_REQ_MASK_2) Safing record request mask for record 3 (SAF_REQ_MASK_3) Safing record request mask for record 4 (SAF_REQ_MASK_4) Safing record request mask for record 5 (SAF_REQ_MASK_5) Safing record request mask for record 6 (SAF_REQ_MASK_6) Safing record request mask for record 7 (SAF_REQ_MASK_7) Safing record request mask for record 8 (SAF_REQ_MASK_8) Safing record request mask for record 9 (SAF_REQ_MASK_9) Safing record request mask for record 10 (SAF_REQ_MASK_10) Safing record request mask for record 11 (SAF_REQ_MASK_11) Safing record request mask for record 12 (SAF_REQ_MASK_12) Safing record request mask for record 13 (SAF_REQ_MASK_13) Safing record request mask for record 14_pt1 (SAF_REQ_MASK_14)_pt1 Safing record request mask for record 14_pt2 (SAF_REQ_MASK_14)_pt2 Safing record request mask for record 15_pt1 (SAF_REQ_MASK_15)_pt1 Safing record request mask for record 15_pt2 (SAF_REQ_MASK_15)_pt2 Safing record request mask for record 16_pt1 (SAF_REQ_MASK_16)_pt1 Safing record request mask for record 16_pt2 (SAF_REQ_MASK_16)_pt2 ID: 80 (SAF_REQ_MASK_1) 81 (SAF_REQ_MASK_2) 82 (SAF_REQ_MASK_3) 83 (SAF_REQ_MASK_4) 84 (SAF_REQ_MASK_5) 85 (SAF_REQ_MASK_6) 86 (SAF_REQ_MASK_7) 87 (SAF_REQ_MASK_8) 88 (SAF_REQ_MASK_9) 89 (SAF_REQ_MASK_10) 8A (SAF_REQ_MASK_11) 8B (SAF_REQ_MASK_12) 8C (SAF_REQ_MASK_13) 8D (SAF_REQ_MASK_14_pt1 8E (SAF_REQ_MASK_14_pt2) 8F (SAF_REQ_MASK_15_pt1) 90 (SAF_REQ_MASK_15_pt2) 91 (SAF_REQ_MASK_16_pt1) 92 (SAF_REQ_MASK_16_pt2) Type: RW Read: 8000 (SAF_REQ_MASK_1) 8100 (SAF_REQ_MASK_2) 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - SAF_REQ_MASKx[15:0] MISO 0 0 0 0 SAF_REQ_MASKx[15:0]

8200 (SAF_REQ_MASK_3) 8300 (SAF_REQ_MASK_4) 8400 (SAF_REQ_MASK_5) 8500 (SAF_REQ_MASK_6) 8600 (SAF_REQ_MASK_7) 8700 (SAF_REQ_MASK_8) 8800 (SAF_REQ_MASK_9) 8900 (SAF_REQ_MASK_10) 8A00 (SAF_REQ_MASK_11) 8B00 (SAF_REQ_MASK_12) 8C00 (SAF_REQ_MASK_13) 8D00 (SAF_REQ_MASK_14_pt1 8E00 (SAF_REQ_MASK_14_pt2) 8F00 (SAF_REQ_MASK_15_pt1) 9000 (SAF_REQ_MASK_15_pt2) 9100 (SAF_REQ_MASK_16_pt1) 9200 (SAF_REQ_MASK_16_pt2) Write: 8000 (SAF_REQ_MASK_1) 8002 (SAF_REQ_MASK_2) 8004 (SAF_REQ_MASK_3) 8006 (SAF_REQ_MASK_4) 8008 (SAF_REQ_MASK_5) 800A (SAF_REQ_MASK_6) 800C (SAF_REQ_MASK_7) 800E (SAF_REQ_MASK_8) 8010 (SAF_REQ_MASK_9) 8012 (SAF_REQ_MASK_10) 8014 (SAF_REQ_MASK_11) 8016 (SAF_REQ_MASK_12) 8018 (SAF_REQ_MASK_13) 801A (SAF_REQ_MASK_14_pt1 801C (SAF_REQ_MASK_14_pt2) 801E (SAF_REQ_MASK_15_pt1) 8020 (SAF_REQ_MASK_15_pt2) 8022 (SAF_REQ_MASK_16_pt1) 8424 (SAF_REQ_MASK_16_pt2) POR WSM SSM SAF_REQ_MASKx[15:0] $0000$0000$0000 Safing Request Mask for safing record x - 16-bit request mask that is bit- wise ANDed with MOSI data from SPI monitor Updated by SSM_RESET or SPI write while in DIAG state

7.3.52 Safing records request target registers (SAF_REQ_TARGET_x)

Safing record request mask for record 1 (SAF_REQ_TARGET_1) Safing record request mask for record 2 (SAF_REQ_TARGET_2) Safing record request mask for record 3 (SAF_REQ_TARGET_3) Safing record request mask for record 4 (SAF_REQ_TARGET_4) Safing record request mask for record 5 (SAF_REQ_TARGET_5) Safing record request mask for record 6 (SAF_REQ_TARGET_6) Safing record request mask for record 7 (SAF_REQ_TARGET_7) Safing record request mask for record 8 (SAF_REQ_TARGET_8) Safing record request mask for record 9 (SAF_REQ_TARGET_9) Safing record request mask for record 10 (SAF_REQ_TARGET_10) Safing record request mask for record 11 (SAF_REQ_TARGET_11) Safing record request mask for record 12 (SAF_REQ_TARGET_12) Safing record request mask for record 13 (SAF_REQ_TARGET_13) Safing record request mask for record 14_pt1 (SAF_REQ_TARGET_14)_pt1 Safing record request mask for record 14_pt2 (SAF_REQ_TARGET_14)_pt2 Safing record request mask for record 15_pt1 (SAF_REQ_TARGET_15)_pt1 Safing record request mask for record 15_pt2 (SAF_REQ_TARGET_15)_pt2 Safing record request mask for record 16_pt1 (SAF_REQ_TARGET_16)_pt1 Safing record request mask for record 16_pt2 (SAF_REQ_TARGET_16)_pt2 ID: 93 (SAF_REQ_TARGET_1) 94 (SAF_REQ_TARGET_2) 95 (SAF_REQ_TARGET_3) 96 (SAF_REQ_TARGET_4) 97 (SAF_REQ_TARGET_5) 98 (SAF_REQ_TARGET_6) 99 (SAF_REQ_TARGET_7) 9A (SAF_REQ_TARGET_8) 9B (SAF_REQ_TARGET_9) 9C (SAF_REQ_TARGET_10) 9D (SAF_REQ_TARGET_11) 9E (SAF_REQ_TARGET_12) 9F (SAF_REQ_TARGET_13) A0 (SAF_REQ_TARGET_14_pt1 A1 (SAF_REQ_TARGET_14_pt2) A2 (SAF_REQ_TARGET_15_pt1) A3 (SAF_REQ_TARGET_15_pt2) A4 (SAF_REQ_TARGET_16_pt1) A5 (SAF_REQ_TARGET_16_pt2) Type: RW Read: 9300 (SAF_REQ_TARGET_1) 9400 (SAF_REQ_TARGET_2) 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - SAF_REQ_TARGET[15:0] MISO 0 0 0 0 SAF_REQ_TARGET[15:0]

9500 (SAF_REQ_TARGET_3) 9600 (SAF_REQ_TARGET_4) 9700 (SAF_REQ_TARGET_5) 9800 (SAF_REQ_TARGET_6) 9900 (SAF_REQ_TARGET_7) 9A00 (SAF_REQ_TARGET_8) 9B00 (SAF_REQ_TARGET_9) 9C00 (SAF_REQ_TARGET_10) 9D00 (SAF_REQ_TARGET_11) 9E00 (SAF_REQ_TARGET_12) 9F00 (SAF_REQ_TARGET_13) A000 (SAF_REQ_TARGET_14_pt1 A100 (SAF_REQ_TARGET_14_pt2) A200 (SAF_REQ_TARGET_15_pt1) A300 (SAF_REQ_TARGET_15_pt2) A400 (SAF_REQ_TARGET_16_pt1) A500 (SAF_REQ_TARGET_16_pt2) Write: 8026 (SAF_REQ_TARGET_1) 8028 (SAF_REQ_TARGET_2) 802A (SAF_REQ_TARGET_3) 802C (SAF_REQ_TARGET_4) 802E (SAF_REQ_TARGET_5) 8030 (SAF_REQ_TARGET_6) 8032 (SAF_REQ_TARGET_7) 8034 (SAF_REQ_TARGET_8) 8036 (SAF_REQ_TARGET_9) 8038 (SAF_REQ_TARGET_10) 803A (SAF_REQ_TARGET_11) 803C (SAF_REQ_TARGET_12) 803E (SAF_REQ_TARGET_13) 8040 (SAF_REQ_TARGET_14_pt1 8042 (SAF_REQ_TARGET_14_pt2) 8044 (SAF_REQ_TARGET_15_pt1) 8246 (SAF_REQ_TARGET_15_pt2) 8048 (SAF_REQ_TARGET_16_pt1) 804A (SAF_REQ_TARGET_16_pt2) POR WSM SSM SAF_REQ_TARGET[15:0 $0000$0000$0000 Safing Request target for safing record x - 16-bit request target that is compared to the bit-wise AND result of the SAF_REQ_MASKx and MOSI data from SPI monitor Updated by SSM_RESET or SPI write while in DIAG state

7.3.53 Safing records response mask registers (SAF_RESP_MASK_x)

Safing record response mask for record 1 (SAF_RESP_MASK_1) Safing record response mask for record 2 (SAF_RESP_MASK_2) Safing record response mask for record 3 (SAF_RESP_MASK_3) Safing record response mask for record 4 (SAF_RESP_MASK_4) Safing record response mask for record 5 (SAF_RESP_MASK_5) Safing record response mask for record 6 (SAF_RESP_MASK_6 Safing record response mask for record 7 (SAF_RESP_MASK_7)) Safing record response mask for record 8 (SAF_RESP_MASK_8) Safing record response mask for record 9 (SAF_RESP_MASK_9) Safing record response mask for record 10 (SAF_RESP_MASK_10) Safing record response mask for record 11 (SAF_RESP_MASK_11) Safing record response mask for record 12 (SAF_RESP_MASK_12) Safing record response mask for record 13 (SAF_RESP_MASK_13) Safing record response mask for record 14_pt1 (SAF_RESP_MASK_14_pt1) Safing record response mask for record 14_pt2 (SAF_RESP_MASK_14_pt2) Safing record response mask for record 15_pt1 (SAF_RESP_MASK_15_pt1) Safing record response mask for record 15_pt2 (SAF_RESP_MASK_14_pt2) Safing record response mask for record 16_pt1 (SAF_RESP_MASK_16_pt1) Safing record response mask for record 16_pt2 (SAF_RESP_MASK_16_pt2) ID: A6 (SAF_RESP_MASK_1) A7 (SAF_RESP_MASK_2 A8 (SAF_RESP_MASK_3 A9 (SAF_RESP_MASK_4 AA (SAF_RESP_MASK_5 AB (SAF_RESP_MASK_6 AC (SAF_RESP_MASK_7 AD (SAF_RESP_MASK_8 AE (SAF_RESP_MASK_9 AF (SAF_RESP_MASK_10 B0 (SAF_RESP_MASK_11 B1 (SAF_RESP_MASK_12 B2 (SAF_RESP_MASK_13) B3 (SAF_RESP_MASK_14_pt1) B4 (SAF_RESP_MASK_14_pt2) B5 (SAF_RESP_MASK_15_pt1) B6 (SAF_RESP_MASK_15_pt2) 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - SAF_RESP_MASKx[15:0] MISO 0 0 0 0 SAF_RESP_MASKx[15:0]

B7 (SAF_RESP_MASK_16_pt1 B8 (SAF_RESP_MASK_16_pt2 Type: RW Read: Read: A600 (SAF_RESP_MASK_1) A700 (SAF_RESP_MASK_2 A800 (SAF_RESP_MASK_3 A900 (SAF_RESP_MASK_4 AA00 (SAF_RESP_MASK_5 AB00 (SAF_RESP_MASK_6 AC00 (SAF_RESP_MASK_7 AD00 (SAF_RESP_MASK_8 AE00 (SAF_RESP_MASK_9 AF00 (SAF_RESP_MASK_10 B000 (SAF_RESP_MASK_11 B100 (SAF_RESP_MASK_12 B200 (SAF_RESP_MASK_13) B300 (SAF_RESP_MASK_14_pt1) B400 (SAF_RESP_MASK_14_pt2) B500 (SAF_RESP_MASK_15_pt1) B600 (SAF_RESP_MASK_15_pt2) B700 (SAF_RESP_MASK_16_pt1 B801 (SAF_RESP_MASK_16_pt1 Write: 804C (SAF_RESP_MASK_1) 804E (SAF_RESP_MASK_2 8050 (SAF_RESP_MASK_3 8052 (SAF_RESP_MASK_4 8054 (SAF_RESP_MASK_5 8056 (SAF_RESP_MASK_6 8058 (SAF_RESP_MASK_7 805A (SAF_RESP_MASK_8 805C (SAF_RESP_MASK_9 805E (SAF_RESP_MASK_10 8060 (SAF_RESP_MASK_11 8062 (SAF_RESP_MASK_12 8064 (SAF_RESP_MASK_13) 8066 (SAF_RESP_MASK_14_pt1) 8068 (SAF_RESP_MASK_14_pt2) 806A (SAF_RESP_MASK_15_pt1) 806C (SAF_RESP_MASK_15_pt2) 806E (SAF_RESP_MASK_16_pt1 8070 (SAF_RESP_MASK_16_pt2 POR WSM SSM SAF_RESP_MASKx[15:0] 0000 0000 0000 Safing Response Mask for safing record x - 16-bit response mask that is bit- wise ANDed with MISO data from SPI monitor 16-bit request target that is compared to the bit-wise AND result of the SAF_REQ_MASKx and MOSI data from SPI Updated by SSM_RESET or SPI write while in DIAG state

7.3.54 Safing records response mask registers (SAF_RESP_TARGET_x)

Safing record response target for record 1 (SAF_RESP_TARGET_1) Safing record response target for record 2 (SAF_RESP_TARGET_2) Safing record response target for record 3 (SAF_RESP_TARGET_3) Safing record response target for record 4 (SAF_RESP_TARGET_4) Safing record response target for record 5 (SAF_RESP_TARGET_5) Safing record response target for record 6 (SAF_RESP_TARGET_6) Safing record response target for record 7 (SAF_RESP_TARGET_7) Safing record response target for record 8 (SAF_RESP_TARGET_8) Safing record response target for record 9 (SAF_RESP_TARGET_9) Safing record response target for record 10 (SAF_RESP_TARGET_10) Safing record response target for record 11 (SAF_RESP_TARGET_11) Safing record response target for record 11 (SAF_RESP_TARGET_12) Safing record response target for record 13 (SAF_RESP_TARGET_13) Safing record response target for record 14_pt1 (SAF_RESP_TARGET_14)_pt1 Safing record response target for record 14_pt2 (SAF_RESP_TARGET_14)_pt2 Safing record response target for record 15_pt1 (SAF_RESP_TARGET_15)_pt1 Safing record response target for record 15_pt2 (SAF_RESP_TARGET_15)_pt2 Safing record response target for record 16_pt1 (SAF_RESP_TARGET_16)_pt1 Safing record response target for record 16_pt2 (SAF_RESP_TARGET_16)_pt2 ID: B9 (SAF_RESP_TARGET_1) BA (SAF_RESP_TARGET_2 BB (SAF_RESP_TARGET_3 BC (SAF_RESP_TARGET_4 BD (SAF_RESP_TARGET_5 BE (SAF_RESP_TARGET_6 BF (SAF_RESP_TARGET_7 C0 (SAF_RESP_TARGET_8 C1 (SAF_RESP_TARGET_9 C2 (SAF_RESP_TARGET_10 C3 (SAF_RESP_TARGET_11 C4 (SAF_RESP_TARGET_12 C5 (SAF_RESP_TARGET_13 C6 (SAF_RESP_TARGET_14_pt1 C7 (SAF_RESP_TARGET_14_pt2 C8 (SAF_RESP_TARGET_15_pt1 C9 (SAF_RESP_TARGET_15_pt2 CA (SAF_RESP_TARGET_16_pt1 CB (SAF_RESP_TARGET_16_pt2 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - SAF_RESP_TARGETx[15:0] MISO 0 0 0 0 SAF_RESP_TARGETx[15:0]

Type: RW Read: B900 (SAF_RESP_TARGET_1) BA00 (SAF_RESP_TARGET_2 BB00 (SAF_RESP_TARGET_3 BC00 (SAF_RESP_TARGET_4 BD00 (SAF_RESP_TARGET_5 BE00 (SAF_RESP_TARGET_6 BF00 (SAF_RESP_TARGET_7 C000 (SAF_RESP_TARGET_8 C100 (SAF_RESP_TARGET_9 C200 (SAF_RESP_TARGET_10 C300 (SAF_RESP_TARGET_11 C400 (SAF_RESP_TARGET_12 C500 (SAF_RESP_TARGET_13 C600 (SAF_RESP_TARGET_14_pt1 C700 (SAF_RESP_TARGET_14_pt2 C800 (SAF_RESP_TARGET_15_pt1 C900 (SAF_RESP_TARGET_15_pt2 CA00 (SAF_RESP_TARGET_16_pt1 CB00 (SAF_RESP_TARGET_16_pt2) Write: 8072 (SAF_RESP_TARGET_1) 8074 (SAF_RESP_TARGET_2 8076 (SAF_RESP_TARGET_3 8078 (SAF_RESP_TARGET_4 807A (SAF_RESP_TARGET_5 807C (SAF_RESP_TARGET_6 807E (SAF_RESP_TARGET_7 8080 (SAF_RESP_TARGET_8 8082 (SAF_RESP_TARGET_9 8084 (SAF_RESP_TARGET_10 8086 (SAF_RESP_TARGET_11 8088 (SAF_RESP_TARGET_12 808A (SAF_RESP_TARGET_13 808C (SAF_RESP_TARGET_14_pt1 808E (SAF_RESP_TARGET_14_pt2 8090 (SAF_RESP_TARGET_15_pt1 8092 (SAF_RESP_TARGET_15_pt2 8094 (SAF_RESP_TARGET_16_pt1 CB00 (SAF_RESP_TARGET_16_pt2) POR WSM SSM SAF_RESP_TARGETx[15:0] 0000 0000 0000 Safing Response target for safing record x - 16-bit response target that is compared to the bit-wise AND result of the SAF_RESP_MASKx and MISO data from SPI monitor Updated by SSM_RESET or SPI write while in DIAG state

7.3.55 Safing records data mask registers (SAF_DATA_MASK_x)

Safing record data mask for record 1 (SAF_DATA_MASK_1) Safing record data mask for record 2 (SAF_DATA_MASK_2) Safing record data mask for record 3 (SAF_DATA_MASK_3) Safing record data mask for record 4 (SAF_DATA_MASK_4) Safing record data mask for record 5 (SAF_DATA_MASK_5) Safing record data mask for record 6 (SAF_DATA_MASK_6) Safing record data mask for record 7 (SAF_DATA_MASK_7) Safing record data mask for record 8 (SAF_DATA_MASK_8) Safing record data mask for record 9 (SAF_DATA_MASK_9) Safing record data mask for record 10 (SAF_DATA_MASK_10) Safing record data mask for record 11 (SAF_DATA_MASK_11) Safing record data mask for record 12 (SAF_DATA_MASK_12) Safing record data mask for record 13 (SAF_DATA_MASK_13) Safing record data mask for record 14 (SAF_DATA_MASK_14_pt1) Safing record data mask for record 14 (SAF_DATA_MASK_14_pt2) Safing record data mask for record 15 (SAF_DATA_MASK_15_pt1) Safing record data mask for record 15 (SAF_DATA_MASK_15_pt2) Safing record data mask for record 16 (SAF_DATA_MASK_16_pt1) Safing record data mask for record 16 (SAF_DATA_MASK_16_pt2) ID: CC (SAF_DATA_MASK_1) CD (SAF_DATA_MASK_2) CE (SAF_DATA_MASK_3) CF (SAF_DATA_MASK_4) D0 (SAF_DATA_MASK_5) D1 (SAF_DATA_MASK_6) D2 (SAF_DATA_MASK_7) D3 (SAF_DATA_MASK_8) D4 (SAF_DATA_MASK_9) D5 (SAF_DATA_MASK_10) D6 (SAF_DATA_MASK_11) D7 (SAF_DATA_MASK_12) D8 (SAF_DATA_MASK_13) D9 (SAF_DATA_MASK_14_pt1) DA (SAF_DATA_MASK_14_pt2) DB (SAF_DATA_MASK_15_pt1) DC (SAF_DATA_MASK_15_pt2) 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - SAF_DATA_MASKx[15:0] MISO 0 0 0 0 SAF_DATA_MASKx[15:0]

DD (SAF_DATA_MASK_16_pt1) DE (SAF_DATA_MASK_16_pt2) Type: RW Read: CC00 (SAF_DATA_MASK_1) CD00 (SAF_DATA_MASK_2) CE00 (SAF_DATA_MASK_3) CF00 (SAF_DATA_MASK_4) D000 (SAF_DATA_MASK_5) D100 (SAF_DATA_MASK_6) D200 (SAF_DATA_MASK_7) D300 (SAF_DATA_MASK_8) D400 (SAF_DATA_MASK_9) D500 (SAF_DATA_MASK_10) D600 (SAF_DATA_MASK_11) D700 (SAF_DATA_MASK_12) D800 (SAF_DATA_MASK_13) D900 (SAF_DATA_MASK_14_pt1) DA00 (SAF_DATA_MASK_14_pt2) DB00 (SAF_DATA_MASK_15_pt1) DC00 (SAF_DATA_MASK_15_pt2) DD00 (SAF_DATA_MASK_16_pt1) DE00 (SAF_DATA_MASK_16_pt2) Write: 8099 (SAF_DATA_MASK_1) 809A (SAF_DATA_MASK_2) 809C (SAF_DATA_MASK_3) 809E (SAF_DATA_MASK_4) 80A0 (SAF_DATA_MASK_5) 80A2 (SAF_DATA_MASK_6) 80A4 (SAF_DATA_MASK_7) 80A6 (SAF_DATA_MASK_8) 80A8 (SAF_DATA_MASK_9) 80AA (SAF_DATA_MASK_10) 80AC (SAF_DATA_MASK_11) 80AE (SAF_DATA_MASK_12) 80B0 (SAF_DATA_MASK_13) 80B2 (SAF_DATA_MASK_14_pt1) 80B4 (SAF_DATA_MASK_14_pt2) 80B6 (SAF_DATA_MASK_15_pt1) 80B8 (SAF_DATA_MASK_15_pt2) 80BA (SAF_DATA_MASK_16_pt1) 80BC (SAF_DATA_MASK_16_pt2) POR WSM SSM SAF_DATA_MASKx[15:0] 0000 0000 0000 Safing Data Mask for safing record x - 16-bit data mask that is bit-wise ANDed with MISO data from SPI monitor Updated by SSM_RESET or SPI write while in DIAG state

7.3.56 Safing record threshold registers (SAF_THRESHOLD_x)

Safing record threshold for record 1 (SAF_THRESHOLD_1) Safing record threshold for record 2 (SAF_THRESHOLD_2) Safing record threshold for record 3 (SAF_THRESHOLD_3) Safing record threshold for record 4 (SAF_THRESHOLD_4) Safing record threshold for record 5 (SAF_THRESHOLD_5) Safing record threshold for record 6 (SAF_THRESHOLD_6) Safing record threshold for record 7 (SAF_THRESHOLD_7) Safing record threshold for record 8 (SAF_THRESHOLD_8) Safing record threshold for record 9 (SAF_THRESHOLD_9) Safing record threshold for record 10 (SAF_THRESHOLD_11) Safing record threshold for record 12 (SAF_THRESHOLD_12) Safing record threshold for record 13 (SAF_THRESHOLD_13) Safing record threshold for record 14 (SAF_THRESHOLD_14) Safing record threshold for record 15 (SAF_THRESHOLD_15) Safing record threshold for record 16 (SAF_THRESHOLD_16) ID: DF (SAF_THRESHOLD_1) E0 (SAF_THRESHOLD_2) E1 (SAF_THRESHOLD_3) E2 (SAF_THRESHOLD_4) E3 (SAF_THRESHOLD_5) E4 (SAF_THRESHOLD_6) E5 (SAF_THRESHOLD_7) E6 (SAF_THRESHOLD_8) E7 (SAF_THRESHOLD_9) E8 (SAF_THRESHOLD_10) E9 (SAF_THRESHOLD_11) EA (SAF_THRESHOLD_12) EB (SAF_THRESHOLD_13) EC (SAF_THRESHOLD_14) ED (SAF_THRESHOLD_15) EE (SAF_THRESHOLD_16) Type: RW Read: DF00 (SAF_THRESHOLD_1) E000 (SAF_THRESHOLD_2) E100 (SAF_THRESHOLD_3) E200 (SAF_THRESHOLD_4) E300 (SAF_THRESHOLD_5) E400 (SAF_THRESHOLD_6) E500 (SAF_THRESHOLD_7) E600 (SAF_THRESHOLD_8) 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - SAF_THRESHOLDx[15:0] MISO 0 0 0 0 SAF_THRESHOLDx[15:0]

E700 (SAF_THRESHOLD_9) E800 (SAF_THRESHOLD_10) E900 (SAF_THRESHOLD_11) EA00 (SAF_THRESHOLD_12) EB00 (SAF_THRESHOLD_13) EC00 (SAF_THRESHOLD_14) ED00 (SAF_THRESHOLD_15) EE00 (SAF_THRESHOLD_16) Write: 80BE (SAF_THRESHOLD_1) 80C0 (SAF_THRESHOLD_2) 80C2 (SAF_THRESHOLD_3) 80C4 (SAF_THRESHOLD_4) 80C6 (SAF_THRESHOLD_5) 80C8 (SAF_THRESHOLD_6) 80CA (SAF_THRESHOLD_7) 80CC (SAF_THRESHOLD_8) 80CE (SAF_THRESHOLD_9) 80D0 (SAF_THRESHOLD_10) 80D2 (SAF_THRESHOLD_11) 80D4 (SAF_THRESHOLD_12) 80D6 (SAF_THRESHOLD_13) 80D8 (SAF_THRESHOLD_14) 80DA (SAF_THRESHOLD_15) 80DB (SAF_THRESHOLD_16) POR WSM SSM SAF_THRESHOLD_x $FFFF $FFFF $FFFF Safing threshold for safing record x - 16-bit threshold used for safing data comparison Updated by SSM_RESET or SPI write while in DIAG state

7.3.57 Safing control x registers (SAF_CONTROL_x)

Safing control registers for record 1 (SAF_CONTROL_1) Safing control registers for record 2 (SAF_CONTROL_2) Safing control registers for record 3 (SAF_CONTROL_3) Safing control registers for record 4 (SAF_CONTROL_4) Safing control registers for record 5 (SAF_CONTROL_5) Safing control registers for record 6 (SAF_CONTROL_6) Safing control registers for record 7 (SAF_CONTROL_7) Safing control registers for record 8 (SAF_CONTROL_8) Safing control registers for record 9 (SAF_CONTROL_9) Safing control registers for record 10 (SAF_CONTROL_10) Safing control registers for record 11 (SAF_CONTROL_11) Safing control registers for record 12 (SAF_CONTROL_12) Safing control registers for record 13 (SAF_CONTROL_13) Safing control registers for record 14 (SAF_CONTROL_14) Safing control registers for record 15 (SAF_CONTROL_15) Safing control registers for record 16 (SAF_CONTROL_16) ID: EF (SAF_CONTROL_1) F0 (SAF_CONTROL_2) F1 (SAF_CONTROL_3) F2 (SAF_CONTROL_4) F3 (SAF_CONTROL_5) F4 (SAF_CONTROL_6) F5 (SAF_CONTROL_7 F6 (SAF_CONTROL_8) F7 (SAF_CONTROL_9) F8 (SAF_CONTROL_10) F9 (SAF_CONTROL_11) FA (SAF_CONTROL_12) FB (SAF_CONTROL_13) FC (SAF_CONTROL_14) FD (SAF_CONTROL_15) FE (SAF_CONTROL_16) Type: RW Read: EF00 (SAF_CONTROL_1) F000 (SAF_CONTROL_2) F100 (SAF_CONTROL_3) 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI - ARMSELx SPIFLDSELx LIM SELx LIM Enx COMBx DWELLx[1:0] ARM4x ARM3x ARM2x ARM1x CSx[2:0] IFx MISO 0 0 0 0 ARMSELx SPIFLDSELx LIM SELx LIM Enx COMBx DWELLx[1:0] ARM4x ARM3x ARM2x ARM1x CSx[2:0] IFx

F200 (SAF_CONTROL_4) F300 (SAF_CONTROL_5) F400 (SAF_CONTROL_6) F500 (SAF_CONTROL_7 F600 (SAF_CONTROL_8) F700 (SAF_CONTROL_9) F800 (SAF_CONTROL_10) F900 (SAF_CONTROL_11) FA00 (SAF_CONTROL_12) FB00 (SAF_CONTROL_13) FC00 (SAF_CONTROL_14) FD00 (SAF_CONTROL_15) FE00 (SAF_CONTROL_16) Write: 80DE (SAF_CONTROL_1) 80E0 (SAF_CONTROL_2) 80E2 (SAF_CONTROL_3) 80E4 (SAF_CONTROL_4) 80E6 (SAF_CONTROL_5) 80E8 (SAF_CONTROL_6) 80EA (SAF_CONTROL_7 80EC (SAF_CONTROL_8) 80EE (SAF_CONTROL_9) 80F0 (SAF_CONTROL_10) 80F2 (SAF_CONTROL_11) 80F4 (SAF_CONTROL_12) 80F6 (SAF_CONTROL_13) 80F8 (SAF_CONTROL_14) 80FA (SAF_CONTROL_15) 80FC (SAF_CONTROL_16) POR WSM SSM ARMSELx 00 00 00 ARMINT select for safing recode x - correlates A Updated by SSM_RESET or SPI write while in DIAG state

00 ARMP OR ARMN

01 ARMP

10 ARMN

11 ARMP OR ARMN

SPIFLDSELx 0 0 0 SPI field select for safing record x - determines which 16-bit field in long SPI messages (>31 bit) to use for response on MISO of SPI monitor. In case of messages less than 32 bits this bit is don't care. Updated by SSM_RESET or SPI write while in DIAG state. Updated by SSM_RESET or SPI write while in DIAG state

0 First 16 bits of SPI MISO frame used for Response Mask and Data

1 Last 16 bits of SPI MISO frame used for Response Mask and Data

LIM SELx 0 0 0 Data range limit select for safing record x - When enabled, determines the range limit used for incoming sensor data Updated by SSM_RESET or SPI write while in DIAG state 0 8-bit data range limit - incoming |data| >120d is not recognized as valid data 1 10-bit data range limit - incoming |data| > 480d is not recognized as valid data LIM Enx 0 0 0 Data range limit enable for safing record x Updated by SSM_RESET or SPI write while in DIAG state

0 Data range limit disabled

1 Data range limit enabled

COMBx 000 Combine function enable for safing record x Updated by SSM_RESET or SPI write while in DIAG state

0 Combine function disabled

1 Combine function enabled

For record pairs = x,x+1, the comparison for record x uses |data(x) + data(x+1)| and the comparison for record x+1 uses |data(x) - data(x+1)| Record pairs are 1,2; 3,4; 5,6; 7,8; 9,10; 11,12 DWELLx[1:0] 00 00 00 Safing dwell extension time select for safing record x Updated by SSM_RESET or SPI write while in DIAG state 00 2048 ms 01 256 ms 10 32 ms 11 0 ms ARM4x 000 ARM4INT select for safing record x - correlates safing result to ARM4INT Updated by SSM_RESET or SPI write while in DIAG state

0 Safing record x not assigned to ARM4INT

1 Safing record x assigned to ARM4INT

ARM3x 000 ARM3INT select for safing record x - correlates safing result to ARM3INT Updated by SSM_RESET or SPI write while in DIAG state

0 Safing record x not assigned to ARM3INT

1 Safing record x assigned to ARM3INT

ARM2x 000 ARM2INT select for safing record x - correlates safing result to ARM2INT Updated by SSM_RESET or SPI write while in DIAG state

0 Safing record x not assigned to ARM2INT

1 Safing record x assigned to ARM2INT

ARM1x 000 ARM1INT select for safing record x - correlates safing result to ARM1INT Updated by SSM_RESET or SPI write while in DIAG state

7.3.58 Safing record compare complete register (SAF_CC)

ID: FF Type: R Read: FF00 Write: -

0 Safing record x not assigned to ARM1INT

1 Safing record x assigned to ARM1INT

CSx[2:0] 000 000 000 SPI Monitor CS select for safing record x Updated by SSM_RESET or SPI write while in DIAG state

000 None selected for record x

001 SAF_CS0 selected for record x

010 SAF_CS1 selected for record x

011 SAF_CS2 selected for record x

100 SAF_CS3 selected for record x

101 CS_RS selected for record x

110 None selected for record x

111 None selected for record x

IFx 0 0 0 SPI format select for safing record x - selects response protocol for SPI monitor Updated by SSM_RESET or SPI write while in DIAG state

0 Out of frame response for record x

1 In Frame response for record x

19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI -X X X X X X X X X X X X X X X X MISO 0000 0CC_16 0CC_15 0CC_14 0CC_13 0CC_12 0CC_11 0CC_10 0CC_9 0CC_8 0CC_7 0CC_6 0CC_5 CC_4 CC_3 CC_2 CC_1 POR WSM SSM CC_xx 0 0 0 Indicates compare complete status of each of the 16 safing records, and defines the end of the sample cycle for safing Cleared by SSM_RESET or upon SPI read, set by safing engine when request, response mask and target registers match the incoming SPI frame

0 Compare not completed for record x

1 Compare completed for record x

7.4 Remote sensor SPI register map

are addressed by the read register ID and the Global ID bit. discarded and the ERR_RID bit will be flagged in the current GSW. Table 8. Remote sensor SPI register map

7.5 Remote sensor SPI tables

used to indicate that the register is not affected by the relevant reset signal’).

7.5.1 Remote sensor SPI global status word

significant 11 bits of MISO_RS data. Table 9. GSW - Remote sensor SPI global status word

0 All the RSDRx-FLTBIT bits are 0

1 At least one of the RSDRx-FLTBIT bits is 1 and the

7.6 Remote sensor SPI read/write registers

7.6.1 Remote sensor data/fault registers (RSDRx @FLT = 0)

PSI5/WSS Remote Sensor 0 Data and Fault Flag Register ch 0, slot 1 / ch 0 (RSDR0) PSI5/WSS Remote Sensor 1 Data and Fault Flag Register ch 1, slot 1 / ch 1 (RSDR1) PSI5/WSS Remote Sensor 2 Data and Fault Flag Register ch 2, slot 1 / ch 2 (RSDR2) PSI5/WSS Remote Sensor 3 Data and Fault Flag Register ch 3, slot 1 / ch 3 (RSDR3) PSI5 configuration register for channel 0, slot 2 (RSDR4) PSI5 configuration register for channel 1, slot 2 (RSDR5) PSI5 configuration register for channel 2, slot 2 (RSDR6) PSI5 configuration register for channel 3, slot 2 (RSDR7) PSI5 configuration register for channel 0, slot 2 (RSDR8) PSI5 configuration register for channel 1, slot 2 (RSDR9) PSI5 configuration register for channel 2, slot 2 (RSDR10) PSI5 configuration register for channel 3, slot 2 (RSDR11) Bit 15 = 0 NO FAULT Condition ID: 50 (RSDR0) 51 (RSDR1) 52 (RSDR2) 53 (RSDR3) 54 (RSDR4) 55 (RSDR5) 56 (RSDR6) 57 (RSDR7) 58 (RSDR8) 59 (RSDR9) 5A (RSDR10) 5B (RSDR11) Type: R Read: 5000 (RSDR0) 5100 (RSDR1) 5200 (RSDR2) 5300 (RSDR3) 5400 (RSDR4) 5500 (RSDR5) 5600 (RSDR6) 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI_RS xx xxxx x xxx x x xxxx MISO_RS CRC 0 FLT=0 On/Off LCID [3:0] DATA [9:0] MISO_RS CRC STDSTL FLT=0 Latch_D0 LCID [1:0] DATA [11:0]

5700 (RSDR7) 5800 (RSDR8) 5900 (RSDR9) 5A00 (RSDR10) 5B00 (RSDR11) Write: - POR WSM SSM PSI5 configured channel CRC[2:0] - - - CRC based on bits [16:0] Updated based on bits [16:0] FLT 1 1 1 Fault Status - Depending on Fault Status, the DATA bits are defined differently Cleared when all of the following bits are '0': STG, STB, CURRENT_HI, OPENDET, RSTEMP, INVALID, SLOT_ERROR, NODATA Set when any of the following bits are '1': STG, STB, CURRENT_HI, OPENDET, RSTEMP, INVALID, SLOT_ERROR, NODATA On/Off 0 0 0 Channel On/Off Status Cleared by SSM_RESET or when channel is commanded OFF via SPI RSCTRL or when the STG bit is set or the RSTEMP bit is set Set when channel is commanded ON by SPI RSCTRL LCID[3:0] - - - Logical Channel ID Updated based on SPI read request

0000 RSU0 SLOT1

0001 RSU0 SLOT2

0010 RSU0 SLOT3

0100 RSU1 SLOT1

0101 RSU1 SLOT2

0110 RSU1 SLOT3

1000 RSU2 SLOT1

1001 RSU2 SLOT2

1010 RSU2 SLOT3

1100 RSU3 SLOT1

1010 RSU3 SLOT2

1110 RSU3 SLOT3

DATA[9:0] $000 $000 $000 10-bit data from Manchester decoder

Cleared by SSM_RESET or SPI read or when channel is commanded OFF via SPI RSCTRL updated when a valid PSI5 frame is received Wheel speed configured channel (RSDR0, RSDR1, RSDR2, RSDR3) CRC[2:0] - - - CRC based on bits [16:0] Updated based on bits [16:0] STDSTL 0 0 0 Standstill indication (valid only for VDA sensor or PWM 2 edges)

1 Standstill

0 Valid Sensor Signal

FLT 1 1 1 Fault Status - Depending on Fault Status, the DATA bits are defined differently Cleared when all of the following bits are '0': STG, STB, CURRENT_HI, OPENDET, RSTEMP, INVALID, PULSE OVERFLOW ERROR, NODATA Set when any of the following bits are '1': STG, STB, CURRENT_HI, OPENDET, RSTEMP, INVALID, PULSE OVERFLOW ERROR, NODATA Latch_D0 0 0 0 Logical Channel ID 0 no prior bit0 faults 1 prior message(s) contained bit0 fault LCID[1:0] Logical Channel ID

00 RSU0

01 RSU1

10 RSU2

11 RSU3

DATA[11:0] $000 $000 $000 12-bit data from wheel speed decoder VDA Data Format DATA [7:0] Counter bits DATA [11:8] Counter bits PWM Data Format DATA [8:0] Pulse Data bits

7.6.2 Remote sensor data/fault registers w/o fault (RSDRx @ FLT=1)

PSI5/WSS Remote Sensor 0 Data and Fault Flag Register ch 0, slot 1 / ch 0 (RSDR0) PSI5/WSS Remote Sensor 1 Data and Fault Flag Register ch 1, slot 1 / ch 1 (RSDR1) PSI5/WSS Remote Sensor 2 Data and Fault Flag Register ch 2, slot 1 / ch 2 (RSDR2) PSI5/WSS Remote Sensor 3 Data and Fault Flag Register ch 3, slot 1 / ch 3 (RSDR3) PSI5 configuration register for channel 0, slot 2 (RSDR4) PSI5 configuration register for channel 1, slot 2 (RSDR5) PSI5 configuration register for channel 2, slot 2 (RSDR6) PSI5 configuration register for channel 3, slot 2 (RSDR7) PSI5 configuration register for channel 0, slot 2 (RSDR8) PSI5 configuration register for channel 1, slot 2 (RSDR9) PSI5 configuration register for channel 2, slot 2 (RSDR10) PSI5 configuration register for channel 3, slot 2 (RSDR11) Bit 15 = 1 FAULTED condition ID: 50 (RSDR0) 51 (RSDR1) 52 (RSDR2) 53 (RSDR3) 54 (RSDR4) 55 (RSDR5) 56 (RSDR6) 57 (RSDR7) 58 (RSDR8) 59 (RSDR9) 5A (RSDR10) 5B (RSDR11) Type: R Read: 5000 (RSDR0) 5100 (RSDR1) 5200 (RSDR2) 5300 (RSDR3) 5400 (RSDR4) 5500 (RSDR5) 5600 (RSDR6) 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOS_RSI -X X X X X X X X X X X X X X X MISO_RS (PSI5) CRC X FLT=1 On/Off LCID [3:0] STG STB CURRENT_HI OPENDET RSTEMP INVALID NODATA SLOT_ERROR XX MISO_RS (WSS) CRC X FLT=1 On/Off LCID [1:0] STG STB CURRENT_HI OPENDET RSTEMP INVALID NODATA SLOT_ERROR XX

5700 (RSDR7) 5800 (RSDR8) 5900 (RSDR9) 5A00 (RSDR10) 5B00 (RSDR11) Write: - POR WSM SSM CRC[2:0] - - - CRC based on bits [16:0] Updated based on bits [16:0] FLT 0 0 0 Fault Status Cleared when all of the following bits are '0': STG, STB, CURRENT_HI, OPENDET, RSTEMP, NODATA, INVALID, SLOT ERROR, PULSE OVERFLOW ERROR Set when any of the following bits are '1': STG, STB, CURRENT_HI, OPENDET, RSTEMP, NODATA, INVALID, SLOT ERROR, PULSE OVERFLOW ERROR On/Off 0 0 0 Channel On/Off Status Cleared by SSM_RESET or when channel is commanded OFF via SPI RSCTRL or when the STG bit is set or the RSTEMP bit is set Set when channel is commanded ON by SPI RSCTRL LCID[0:3] 0000 0000 0000 Logical Channel ID Updated based on SPI read request

0101 RSU1 SLOT2 1

1101 RSU3 SLOT2

STG 0 0 0 Short to Ground (in current limit condition) Cleared by SSM_RESET or when channel is commanded OFF via SPI RSCTRL STB 0 0 0 Short to Battery Cleared by SSM_RESET or SPI read or when channel is commanded OFF via SPI RSCTRL - not cleared by channel OFF caused by STG or RSTEMP Set when channel voltage exceeds VSUP for a time greater than TSTBTH CURRENT_HI 0 0 0 Current High Cleared by SSM_RESET or SPI read or when channel is commanded OFF via SPI RSCTRL Set when channel current exceeds ILKGG for a time determined by an up/down counter OPENDET 0 0 0 Open Sensor Detected Cleared by SSM_RESET or SPI read or when channel is commanded OFF via SPI RSCTRL Set when channel current exceeds ILKGB for a time determined by an up/down counter RSTEMP 0 0 0 Over temperature detected Cleared by SSM_RESET or when channel is commanded OFF via SPI RSCTRL Set when over-temp condition is detected INVALID 0 0 0 Invalid Data

Cleared by SSM_RESET or SPI read or when channel is commanded OFF via SPI RSCTRL or if one of the following is set: STG, STB, CURRENT_HI, OPEN_DET, RSTEMP, SLOT ERROR (PSI5), PULSE OVERFLOW ERROR (WSS) or if a new valid data is received Set in PSI5 configuration when two valid start bits are received and a Manchester error (# of bits, bit timing) or parity error is detected Set in WSS configuration when parity error is detected (when this check is feasible). Valid only for VDA sensor. NODATA 1 1 1 No Data in buffer Cleared when a valid PSI5/WSS frame is received or if one of the following is set: STG, STB, CURRENT_HI, OPEN_DET, RSTEMP, SLOT ERROR, PULSE OVERFLOW ERROR, INVALID Set upon SPI read of RSDRx and none of the following bits are set: STG, STB, CURRENT_HI, OPEN_DET, RSTEMP, SLOT ERROR, PULSE OVERFLOW ERROR, INVALID 0 0 0 Pulse duration counter overflow (valid only for PWM 2 edges sensors) Cleared by SSM_RESET or SPI read or when channel is commanded OFF via SPI RSCTRL SLOT ERROR 0 0 0 Slot error fault (valid only for PSI5 sensors Cleared by SSM_RESET or SPI read or when channel is commanded OFF via SPI RSCTRL or if one of the following is set: STG, STB, CURRENT_HI, OPEN_DET, RSTEMP or if a new valid data is received Set in case of slot control enabled and frame not completely inside slot or more than one frame inside the slot

7.6.3 Remote sensor x current registers y (RSTHRx_y)

Remote sensor 0, base current and delta to calculate 1st top current (RSTHR0_L) Remote sensor 1, base current and delta to calculate 1st top current (RSTHR1_L Remote sensor 2, base current and delta to calculate 1st top current (RSTHR2_L Remote sensor 3, base current and delta to calculate 1st top current (RSTHR3_L Remote sensor 0 (only for WSS), delta to calculate 2nd top current (RSTHR0_H Remote sensor 1 (only for WSS), delta to calculate 2nd top current (RSTHR1_H Remote sensor 2 (only for WSS), delta to calculate 2nd top current (RSTHR2_H Remote sensor 3 (only for WSS), delta to calculate 2nd top current (RSTHR3_H ID: 5C (RSTHR0_L) 5D (RSTHR1_L) 5E (RSTHR2_L) 5F (RSTHR3_L) 60 (RSTHR0_H) 61 (RSTHR1_H) 62 (RSTHR2_H) 63 (RSTHR3_H Type: R Read: 5C00 (RSTHR0_L) 5D00 (RSTHR1_L) 5E00 (RSTHR2_L) 5F00 (RSTHR3_L) 6000 (RSTHR0_H) 6100 (RSTHR1_H) 6200 (RSTHR2_H) 6300 (RSTHR3_H Write: - 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI -X X X X X X X X X X X X X X X X MISO_RS DELTA 1ST TOP [9:0] BASE CURRENT [9:0] MISO_RS 0 0 0 0 0 0 0 0 0 0 DELTA 2ND TOP [9:0] POR WSM SSM BASE CURRENT [9:0] $A1 $A1 $A1 PSI5/WSS base current measured by internal converter (93.75 μA ±9% each LSB). DELTA 1ST TOP [19:10] $103 $103 $103 PSI5/WSS delta measured by internal converter respect to base current (93.75 μA ±9% each LSB) to get top current. Low threshold = base current+(DELTA_1ST_TOP/2) in case of WSS or PSI5 without current averaged algorithm (bit 4 of RSRCx register equal to 0). Low threshold = base current+(DELTA_1ST_TOP) in case of PSI5 with current averaged algorithm (bit 4 of RSRCx register equal to 1).

7.6.4 Arming signals register (ARM_STATE)

ID: 6A Type: R Read: 6A00 Write: - DELTA 2ND TOP [9:0] $7 $103 $103 WSS delta measured by internal converter respect to base current (93.75 μA ±9% each LSB) to get second top current. High threshold = ((base current+DELTA_1ST_TOP)+(base current+DELTA_2ND_TOP))/2. 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI -X X X X X X X X X X X X X X X X MISO 00000 00 0 0 0 PSINHINT PSINH_EXP_TIME ACL_PIN_STATE ACL_VALID ARMINT_4 ARMINT_3 ARMINT_2 ARMINT_1 POR WSM SSM ARMINT_x - - - State of ARMINT signals Updated per Safing Engine output logic diagram in case of internal safing engine otherwise is the echo of ARMx pins ACL_VALID 0 0 0 Valid ACL detection ACL_PIN_STATE - - - Echo of ACL pin PSINH_EXP_TIME 0 0 0 State of PSINH expiration timer PSINHINT - - - State of PSINHINT signal Updated per PSINH output logic diagram in case of internal engine otherwise is the echo of PSINH pin inverted

7.6.5 Safing record compare complete register (SAF_CC)

ID: FF Type: R Read: $FF01 Write: $80FE 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 MOSI/ MOSI_RS -X X X X X X X X X X X X X X X X MISO/ MISO_RS 0000 CC_16 CC_15 CC_14 CC_13 CC_12 CC_11 CC_10 CC_9 CC_8 CC_7 CC_6 CC_5 CC_4 CC_3 CC_2 CC_1 POR WSM SSM CC_xx 0 0 0 Indicates compare complete status of each of the 16 safing records, and defines the end of the sample cycle for safing Cleared by SSM_RESET or upon SPI read, set by safing engine when request, response mask and target registers match the incoming SPI frame

8 Deployment drivers

deployment is initiated, it can only be terminated by an SSM_RESET event. under all normal operating conditions and with a deployment repetition time higher than 10s. during power-up/down transients.

8.1 Control logic

Figure 27. Deployment driver control blocks

Figure 30. Deployment driver block

8.1.1 Deployment current selection

(DCRx) shown in Section 7.3.7.

8.1.2 Deploy command expiration timer

is selectable via 2 bits and the maximum programmable time is 500 ms nominal.

8.1.3 Deployment control flow

 a global deployment state has to be active, as described in the following figure. Figure 31. Global SPI deployment enable state diagram command on the same channel has to be sent.  All squib, DC sensor and ADC diagnostic MUX settings, state machine, etc. because ARM4 pin is used to arm the low side of all loops without association matrix. Deploy commands in the Deploy Command Register (DEPCOM) are channel specific.

Arming Enable Pulse Stretch Timers is available in the AEPSTS register.

8.1.4 Deployment current monitoring

Monitor Timer Register XY (DCMTSxy). There is a unique timer register for each channel. absence of current in the deployment channel. Figure 32. Current monitor counter behavior performed and a new DEPCOM command on the same channel is received.

8.1.5 Deployment success

(DEPOK) is also set once any of the 12 deployment channels sets a deploy success flag.

8.2 Energy reserve - deployment voltage

and 3). These pins are directly connected to the high side drivers for each channel.

8.3 Deployment ground return

simultaneously, even in case of only one out of the three possible connections being available.

8.4 Deployment driver protections

8.4.1 Delayed low-side deactivation

To control voltage spikes at the squib pins during drivers deactivation at the end of a deployment, the low side driver is switched off after tdepl_ls-dly delay time with respect to the high side deactivation.

8.4.2 Low-side voltage clamp

The Low side driver is protected against overvoltage at the SRx pins by means of a clamping structure as shown in Figure 30. When the Low side driver is turned off, voltage transients at the SRx pin may be caused by squib inductance. In this case a low side FET drain to gate clamp will reactivate the low side FET allowing for residual inductance current recirculation, thus preventing potential low side FET damage by overvoltage.

8.4.3 Short to battery

The Low side driver is equipped with current limitation and overcurrent protection circuitry. In case of short to battery at the squib pins, the short circuit current is limited by the Low side driver to I LIMSRx. If this condition lasts for longer than tLIM deglitch filter time then the low and high-side drivers will be switched off and latched in this state until a new deployment is commanded after SPI_DEPEN is re-triggered.

8.4.4 Short to ground

The squib driver is designed to stand a short to ground at the squib pins during deployment. In particular, the current flowing through the short circuit is limited by the high side driver (deployment current) and the high-side FET is sized to handle the related energy. In case the short to ground during deployment occurs after an open circuit, a protection against damage is also available. The high side current regulator would have normally reacted to the open circuit by increasing the Vgs of the high side FET. Thanks to a dedicated fast comparator detecting the open condition, the driver is able to discharge the FET gate quickly in order to reduce current overshoot and prevent potential driver damage when the short to ground occurs.

8.4.5 Intermittent open squib

A dedicated protection is also available in case of intermittent open load during deployment. In this case, if load is restored after an open circuit, due to slow reaction of the high-side current regulation loop, the current through the squib is limited only to I LIMSRx by the low side driver. If this condition lasts for longer than tLIMOS then the high side is turned off for tHSOFFOS and then reactivated. By this feature, intermittent open squib and short to battery faults may be distinguished and handled properly by the drivers.

8.5 Diagnostics

The L9680 provides the following diagnostic feedback for all deployment channels:  High voltage leakage test for oxide isolation check on SFx and SRx  Leakage to battery and ground on both SFx and SRx pins with or without a squib  Short between loops diagnostics  Squib resistance measurement with leakage cancellation and selectable range (10/50 Ω)  High squib resistance with range from 500 Ω to 2000 Ω  SSxy, SFx and VER voltage status  High and Low side FET diagnostics  High side driver diagnostics  Loss of ground return diagnostics  High Side Safing FET diagnostics The above diagnostic results are processed through a 10 bit Analog to digital algorithmic converter. These tests can be addressed in two different ways, with a high level approach or a low-level one. The main difference between the two approaches is that with the low level approach the user is allowed to precisely control the diagnostic circuitry, also deciding the proper timings involved in the different tests. On the other hand, the high level approach is an automatic way of getting diagnostic results for which an internal state machine is taking care of instructions and timings. The following is block diagram of the Squib Diagnostics.

Figure 33. Deployment loop diagnostics The leakage diagnostic includes short to battery, short to ground and shorts between loops. resistance between the squib pins.

8.5.1 Low level diagnostic approach

intervention by issuing the proper SPI command. test on SFx and SRx pins can be issued to double check possible leakages.

battery flag would be asserted. the VRCM block works properly, the short to ground flag would be asserted. Figure 34. SRx pull-down enable logic will detect the abnormal current flow and the relative flags will be given in the LPDIAGSTAT. SRx) under test, respectively with LEAK_CHSEL and SQP bit fields. test or on a short between loops.

the channel under test has a short to another squib loop. SFx pins is open, the fault will be indicated on the open channel. Table 10. Short between loops diagnostics decoding

measurement reported in the electrical parameters table. Section 7.3.33: ADC request and data registers (DIAGCTRL_x). ISRC current generator to mitigate emissions. Figure 10. Tests are performed individually for HS driver or LS driver, with two dedicated appropriate HS or LS squib driver during FET test. immediately and automatically. and automatically, and the corresponding VRCM flag, STG or STB, is set. driver is anyway turned off within TFETTIMEOUT.

and will be cleared as soon as the FET is switched back off. connection for that channel. Table 11. HS FET TEST

10 FET test disabled

Table 12. LS FET TEST

01 FET test disabled

allowed to disable the appropriate HS or LS squib driver anymore. external squib connection and other internal circuitries. This diagnostics is available during a squib measurement or a high side driver diagnostics. FLT_SGOPEN and cleared upon read. This test has to be issued during the Diag state of the power-up sequence (Figure 10). on, the voltage on SSxy will be regulated. results will be reported through ADCRESx bit fields. Figure 35. The μC

Figure 35. Deployment timer diagnostic sequence on both channels of the loop pair selected. to 0, otherwise it will be half the real squib resistance. Status Register (LPDIAGSTAT).

8.5.2 High level diagnostic approach

state machine that helps reducing the user intervention to a minimum. The concept is depicted in the following figures. Figure 36. High level loop diagnostic flow1

Figure 37. High level loop diagnostic flow2

9 Remote sensor interface

(synchronous mode, increased voltage, extended range) and active wheel speed sensors. global SPI data buffer in the Remote Sensor Data Registers (RSDRx). Figure 38. Remote sensor interface logic blocks detection each time a channel is activated. on and Off and for Sync Pulse control via SPI. sensor functions or active wheel speeds. conditions could be lost. This bit is cleared-upon-read. are explained in the following sections.

  1. Faults other than Short to Ground and Over-temperature will only clear after read, not by

Data are cleared upon reading the RSDRx register.

9.1 PSI5 mode

An example of the data format for one possible PSI-5 protocol configuration is shown below. Gap time is consistent regardless. Figure 39. PSI-5 remote sensor protocol (10-bit, 1-bit parity

9.1.1 Functional description

adapt the signal level to the sensors quiescent current. pulse voltage modulation as described in the PSI5 v1.3 specification.

L9680 Remote sensor interface 276 The remote sensor interface is also able to detect faults occurring on the sensor interface. The Remote Sensor Data Register (RSDRx) will report multiple fault flags. When the number of bits decoded is incorrect (either too many or too few), a bit error is indicated. When any bit error is detected (bit time, too many bits, too few bits), the decoder will revert to the minimum bit time of the selected range and the message is discarded. Error bit INVALID is an OR-ed combination of the following errors:  Start bit error outside of selected operating range  Data length error or stop bit error  Parity Error of received Remote sensor Message  Bit time error (a data bit edge is not received inside the expected time window)

9.1.2 Sensor data integrity: LCID and CRC

Each RSDRx data register contains a Logical Channel ID which is a 4/2-bit field for remote sensors used to link the received data to the corresponding logical channel number. Each RSDRx register contains also a CRC bit field computed on the data packet for data integrity check. To satisfy functional safety requirements LCID, DATA and CRC bit fields propagate through the same data path as a single item to the SPI output. The polynomial calculation implemented for PSI5 data is described as in PSI5 specification g(x)=1+x+x^3 with initialization value equal to ‘111’. Below are the equations to calculate the CRC in combinatorial way. CRC[2] = CRCext[0]+D[0]+D[1]+D[3]+D[6]+D[7]+D[8]+D[10]+D[13]+D[14]+D[15] CRC[1] = CRCext[2]+D[0]+D[1]+D[2]+D[4]+D[7]+D[8]+D[9]+D[11]+D[14]+D[15]+D[16] CRC[0] = CRCext[1]+CRCext[0]+D[0]+D[2]+D[5]+D[6]+D[7]+D[9]+D[12]+D[13]+D[14]+D[16] Where D[16:0]= RSDR[16:0] and CRCext[n] are the starting seed values (all '1').

9.1.3 Detailed description

The Manchester decoder will support remote sensor communication as per PSI specification rev 1.3 for the modes configurable via the STS bits in the RSCRx registers. The Manchester Decoder checks the duty-cycle and period of the start bits to determine their validity, depending on the configuration of the PERIOD_MEAS_DISABLE bit in the RSCRx registers. The expected time windows for the mid bit transitions of each subsequent bit within the received frame are determined by means of the internal oscillator time base. Glitches shorter than 25% of the minimum bit time duration are rejected.

Figure 43. Manchester decoder state diagram

L9680 Remote sensor interface 276 A Manchester Decoder Error occurs if one or more of the following are true:  Two valid start bits are detected, and at least one of the expected 13 mid-bit transitions are not detected  Two valid start bits are detected, and more than 13 mid-bit transitions are detected  When the number of bits decoded is incorrect (either too many or too few), a bit error is indicated. When any bit error is detected (bit time, too many bits, too few bits), the decoder will revert to the minimum bit time of the selected range and the message is discarded. The Manchester decoder re-initializes at the start of each timeslot, such that remote sensor frames violating timeslot boundaries will result in the setting of a Manchester Error. All errors are readable through the Sensor Fault Status Register and the RSFLT bit in the Global Status Word Register. When a valid message is correctly decoded, the 10/8 data bits are stored into the appropriate RSDRx register together with the related LCID. The RSDRx register contains the 10/8 bits data as they are received from the sensor (no data range check/mask is done at this stage). The 8-bit data word is right-justified inside the 10-bit data field in the RSDRx registers. Current sensor w/ auto-adjust trip current The current sensor is responsible for translating the current drawn by the sensor into a digital state. Each remote sensor channel has a dedicated current sensor. The current flowing through the RSU power stage is internally downscaled by a factor 100, sent to a 10 bits A/D converter and digitally processed to extract both the sensor quiescent and delta currents. The delta current threshold for signal detection can either be fixed or auto-adjusted to the actual calculated sensor delta current, depending on the FIX_THRESH bit setting in the RSCRx registers. The current trip point is dynamically determined by adding the delta current threshold (fixed/auto-adjusted) to the quiescent current (auto-adjusted). The RSU current is compared against the current trip point to determine the current demodulator digital output. A logic '1' represents the sensor current above the current trip point. The current demodulator output is fed into the Manchester decoder and optionally to the WSx discrete output pins, depending on the configuration of the RSPTEN bit in the RSCRx registers. Thanks to the quiescent and delta current tracking features the receiver is capable to automatically adapt to different nominal sensor currents and/or to be tolerant to sensor current drifts over lifetime. Both the sensor quiescent and delta current tracking algorithms can be configured by setting appropriately the REDUCED_RANGE, BLOCK_CURR_IN_MSG and AVG/SSDIS bits in the RSCRx registers.

Remote sensor interface L9680

9.2 Active wheel speed sensor

The remote sensor interface circuit conditions and decodes active wheel speed sensor signals with various pulse widths and output currents. The following sensor types are supported and selected through the Remote Sensor Configuration Register (RSCR)  Standard active 2-level wheel speed sensors (7/14 mA)  Three level (7/14/28 mA) VDA compliant sensor with direction and air gap information (‘Requirement Specification for Standardized Interface for Wheel Speed Sensor with Additional Information’, Version 2.0)  PWM encoded 2-level sensors with 2 edges per tooth (see data sheet Infineon® IC TLE4942/BOSCH DF11)  PWM encoded 2-level sensors with 1 edge per tooth (see data sheet Allegro® ATS651LSH/BOSCH DF11) Received wheel speed frames from all the above sensors are decoded into signals suitable for the microcontroller through the four WSx output pins (WS0-WS3). Specific information is shown in Figure 44. For all sensors, other than the standard active 2- level sensor, additional sensor data (diagnostics, etc…) are decoded and available within the Remote Sensor Data Registers (RSDR0, RSDR1, RSDR3, RSDR4). If standard active 2- level sensor is selected the content of the Remote Sensor Data Registers will be NO DATA fault. Only for 2-level sensors (STD or PWM encoded) the user may choose to have all sensor data processed through the microcontroller by selecting pass through mode, WSPTEN, within the Remote Sensor Configuration Register (RSCR). In pass through mode, the remote sensor interface simply transforms the incoming sensor current pulses to digital voltage pulses on the WSx pins, no decoding is performed. The sensor input filter time, deglitch filter (delay until a threshold crossing is detected) can be configured in 15 steps. Filters can be selected individually for each channel, through the Remote Sensor Configuration Register, WSFILT bits. For PWM encoded sensors with 2 edges per tooth not in pass through mode, the standstill signal can be processed directly to the WSx output pins. This is done in the Remote Sensor Configuration Register, SSEN bit. Since the decoder has to measure the pulses in order to determine, whether they are stand- still pulses or not, the first standstill pulse will always be seen on the WSx output pins and the first not stand-still pulse after a stand-still period will be suppressed. For 3-levels VDA sensors the device performs parity check on the received data frame. In case a parity error is detected, the INVALID fault bit of the RSDRx register will be set. Data from the sensor are not latched: last incoming frame overwrites the previous one once validated. Faults coming from diagnostic (i.e. over current, short to ground or battery) are latched until the microcontroller reads them. Sensor signal decoding is done according to two possible algorithms:  Auto-adjusting current trip points. With this option, the IC is able to find sensor DC current value (named IB0) in the range from 2.5 mA to 21 mA (default is 7 mA). The IC is also able to detect the current value of the data pulse and compute the first threshold (named Ith1): Ith1 = IB0 + Ith1/2 where Ith1 is in the range from 5 mA to 9.3 mA (default is 7 mA).

Figure 44. Wheel speed sensor protocols

Remote sensor interface L9680

9.2.1 Wheel speed data register formats

When programmed as a wheel speed sensor interface, only four data registers are used (Remote Sensor Data Register RSDR0-RSDR3). Independent data registers are defined for each wheel speed channel and their contents are determined by sensor type. Three level VDA sensors have eight data bits and. At fast wheel speed not all bits may be transmitted by the sensor: the IC is able both to process normal or either truncated frames by providing together with data, a 4 bit counter to inform the microcontroller about the number of received valid bits. For PWM encoded sensors, each pulse length is written to the sensor data register with a typical resolution of 5 μs per bit. In case of pulse width duration equal or higher than T STANDSTILL_TH_L and less or equal than TSTANDSTILL_TH_H2, the standstill condition will be recognized and bit 15 in the corresponding register will be set. The register is updated when a PWM falling edge is detected; in case of stuck-at 1 of the PWM signal the register is updated when the counter reaches the overflow value (0x1FF): in this case the standstill bit not set and the counter in overflow will signal a fault to the microcontroller.

9.2.2 Test mode

In order test the input structures of the connected microcontroller, the L9680 features a wheel speed test mode that allows test patterns to be applied on the four wheel speed outputs WS0-WS3. The test mode can be entered via SPI and the test patterns can also be controlled via SPI commands. Test patterns can be composed only of static high or low signals, which can be selected via SPI. For failsafe reasons only one channel at a time can be switched into test mode.

9.3 Remote sensor interface fault protection

9.3.1 Short to ground, current limit

Each output is short circuit protected by an independent current limit. Should the output current level reach or exceed the ILIMTH for a time period greater than TILIMTH or the remote sensor interface the output stage is disabled. An internal up-down counter will count in 25 μs increment up to TILIMTH. The filter time is chosen in order to avoid false current limit detection for in-rush current that may happen at interface switch-on. When the output is turned off due to current limit, the appropriate fault code STG is set in the Remote Sensor Data Register (RSDR). The fault timer latch is cleared when the sensor channel is first disabled and then re-enabled through the Remote Sensor Control Register (RSCTRL). This fault condition does not interfere neither with the normal operation of the IC, nor with the operation of the other channels. When a sensor fault is detected, the RSFLT bit of the GSW is set indicating a fault occurred and can be decoded by addressing the RSDR register. In order to fulfill the blanking time requirement at channel activation as per PSI-5 specification, a dedicated masking time is applied to the current limitation fault detection each time a channel is activated.

L9680 Remote sensor interface 276

9.3.2 Short to battery

All outputs are independently protected against a short to battery condition. Short to battery protection disconnects the channel from its supply rail to guarantee that no adverse condition occurs within the IC. The short-to-battery detection circuit has input offset voltage (10mV, minimum) to prevent disconnecting of the output under an open circuit condition. A short to battery is detected when the output RSUx pin voltage increases above SATBUCK or SYNCBOOST (depending on operation) supply pin voltage for a T STBTH time. An internal up-counter will count in 1.5 μs increment up to TSTBTH. The counter will be cleared if the short condition is not present for at least 1.5 μs. The channel in short to battery is not shut down by this condition. Other channels are not affected in case of short of one output pin. As in the case previously described, the STB fault code can be read from RSDR bits and any fault will set the RSFLT bit of the global status word register (GSW). The STB bit is cleared upon read or upon channel disabled via SPI RSCTRL register.

9.3.3 Cross link

The device provides also the capability of a cross link check between outputs, in order to reveal conditions where two output channels are in short. This functionality is allowed by enabling one output channel, while asking for voltage measurement on any of the other ones.

9.3.4 Leakage to battery, sensor open

The sensor interface offers also open sensor detection. The auto-adjusting counter for remote sensor current sensing will drop to 0 in case the current flowing through RSUx pin is lower than 2.5 mA typ. The OPENDET fault flag is asserted when the fault condition lasts for longer than TRSUOP_FILT deglitch filter time. This fault flag can be read from RSDR bits and any fault will set the RSFLT bit of the global status word register (GSW). The channel in this condition is not shutdown. This fault bit is cleared upon read or upon channel disabled via SPI RSCTRL register.

9.3.5 Leakage to ground

The sensor interface offers as well the detection of a leakage to ground condition, that will possibly raise the sensor current higher than 42 mA/12 mA typ in PSI5/WSS modes respectively. The CURRENT_HI fault flag is asserted when the fault condition lasts for longer than T RSUCH_FILT deglitch filter time. This fault flag can be read from RSDR bits and any fault will set the RSFLT bit of the global status word register (GSW). The channel in this condition is not shutdown. This fault bit is cleared upon read or upon channel disabled via SPI RSCTRL register.

9.3.6 Thermal shutdown

Each output is protected by an independent over-temperature detection circuit should the remote sensor interface thermal protection be triggered the output stage is disabled and a corresponding thermal fault is latched and reported through the RSTEMP flag in the Remote Sensor Data Register (RSDRx). The thermal fault flag is cleared when the sensor channel is first disabled and then re-enabled through the Remote Sensor Configuration Register (RSCRx).

10 Watchdog timers

control. The second control level is featured by an algorithmic seed/key watchdog (WD2). and WD2 watchdog functionalities can be tested trough the WD_TEST SPI command.

10.1 Temporal watchdog (WD1)

error state reported via the FLTSR register (WD1_WDR bit). The overall WD1 functionality is described in the state diagram reported in Figure 45. Figure 45. WD1 Temporal watchdog state diagram

10.1.1 Watchdog timer configuration

 Slow watchdog with maximum range of 16.3ms and a resolution of 64 μs. Figure 10. As soon as the device and cannot be changed anymore. Table 13. Watchdog timer status description arming signals are disabled during this state to prevent deployment. WD1 RUN Normal run time state where WD1 service is required. automatically exited after 1ms. A special state used to disable watchdog functionality for development purposes. without the need to service WD1. qualified. For WD1, this occurs when WD1 service is required, but not received. This signal is SPI-readable. are disabled, preventing deployment. This signal is SPI-readable. the threshold. This command has no effect in other states.

10.1.2 Watchdog timer operation

set, the device can stay in the WD1_INITIAL state indefinitely without watchdog service. reset the watchdog timer to create a new window. be read via the WD1T register. Figure 46. Watchdog timer refresh diagram

10.2 Algorithmic watchdog (WD2)

watchdog, where refresh is accepted at any time before the timer expires. Figure 47. Algorithmic watchdog timer flow diagram

Table 14. WD2 states and signals WD2 OVERRIDE Special state used to disable WD2 watchdog functionality. the timer starts to count waiting for the real first key. WD2 RUN Normal run-time state where WD2 service is required. to 1, in this way μC is able to verify the functionality of the watchdog. account for software jitter. where action is taken due to WD2 service failure. WD2_KEY key mechanism to restart watchdog service. WD2. This is a timed-duration state that is automatically exited after 1ms. time the logic detects a WD2 error while qualifying the error. after all retry attempts have previously failed. This signal is SPI-readable. WD2_LOCKOUT output pin. This signal is SPI-readable.

To refresh WD2, the logic must receive a WD2_KEY command containing the expected key value before the WD2 timer expires. If it is received too late the refresh criteria have not been met. The WD2 error is asserted if the refresh does not occur before the end of the timeout. The WD2 error is not asserted if it receives continuously a WD2_KEY command with the correct key. This allows the system software to repeatedly transmit the correct key value at any rate faster than the required timeout. Upon reception of the correct key, the logic will generate a new seed value, then calculate a new key using the new seed and reset the watchdog timer to create a new timeout. When in WD2 INITSEED state, the three steps above are executed anyway. The seed is latched from a free-running counter that starts when WSM is released. The WD2_KEY command is used for transmission of the watchdog key, while WD2_SEED command is used to read the new seed and the previous key. The SEED is generated by latching the value from a free-running counter. The free-running seed counter runs at a rate of fWD2_SEED as specified in Table 29. The key value and seed value are 8-bits in length. The key shall be calculated as follows: (KEY = SEED ‡ PrevKEY + $01) where ‡ denotes a bit-wise XOR operation

10.3 Watchdog reset assertion timer

Upon either a WD1 or a WD2 watchdog reset, the watchdog logic will momentarily assert the RESET pin for time duration T WDT1_RST / TWDT2_RST. When the RESET pin has been asserted through the watchdog reset assertion timer, stored faults are maintained and can be read by the microcontroller via SPI following the RESET period.

10.4 Watchdog timer disable input (WDT/TM)

This input pin has a passive and active pull-down and is used to disable the watchdog timer. The state of this pin can be read by SPI through the WDT/TM_S bit in the GSW register. When WDT/TM pin is asserted, the watchdog timer is disabled, the timer is reset to its starting value and no faults are generated. The WDT/TM input pin must not be biased HIGH (WDT/TM > VWDTDIS_TH) prior to POR in order to have a proper start-up.

11 DC sensor interface

sensors that can be connected to the device are Hall-effect, resistive or simple switches.  Hall-effect sensor: 1 mA to 2 0 mA. range 1 mA to 2 mA. Hall sensor and switch interface block diagram is shown below. Figure 48. DC sensor interface block diagram

The voltage and current for the selected channel are made available to the main ADC by selecting the proper channel and enabling the measurement process by dedicated DIAGCTRLx commands. The device offers the capability to actively keep all the DCSx lines discharged by means of a weak pull down. The pull down is active by default on all channels and it is deactivated in either of the following cases: 1. when the voltage source is active on the relevant channel 2. when a voltage measurement is requested on the relevant channel 3. if SPI bit SWCTRL(DCS_PD_CURR) is set (global pull-down disable for all channels) In case of Hall-effect sensors, a single current measurement is processed. The current load needed for regulating the pin is internally reflected to a reference resistance, whose voltage drop is then measured through the internal ADC converter. When resistive or switch sensors are used, a more complex measurement is performed. In a first step the current information as above described is provided. Then, also the information on the voltage level achieved on the output pin is provided via ADC. By processing these two values, the micro-controller can understand the resistive value. The DCSx voltage is internally rescaled by a voltage divider into the ADC converter voltage range as shown in Figure 48. Additionally a positive voltage offset is internally applied to the scaled voltage in order to allow voltage measurement capability for DCSx down to -1V. In order to get accurate resistive information even in case of an external ground voltage shift on the sensor of up to +/-1V , the voltage measurement step actually needs two DCSx voltage measurements. A first voltage measurement has to be done with selection of 6.25V on the output channel and a second one with the regulator switched off. The difference between the two measurements will cancel out the offsets (both external ground shift and internal offset). The DCSx current and voltage can be retrieved from ADC readings according to the following formulas and related parameters specified in the Electrical Characteristics section. I DCSx 100 IREF_DCS ADC RES VDCSx RATIO VDCSx ADC REF_hi ADC RES = – – VOFF_DCSx · (RATIOVDCSx –1) @DIAGCTRLn(ADCREQn) = $03 The DCSx sensor resistance can be calculated according to the following formula: Rsensor x VDCSx IDCSx VDCSx @(SWCTRL(SWOEN)=1 V DCSx @(SWCTRL(SWOEN)=0– IDCSx @SWCTRL(CHID) = x The device provides also the capability of a cross link check between outputs, in order to reveal conditions where two output channels are in short. This functionality is allowed by enabling one output channel, while asking for voltage measurement on any of the other ones.

 Ground offset between the ECU and the loads of up to ±1 V.

11.1 Passenger inhibit interface

PSINHB pin of the IC to activate externally controlled squib loops. Figure 49. Passenger inhibit logic diagram values into the PADTHRESH_HI and PADTHRESH_LO registers during the Diag state. mask. The PSINH mask is also preprogrammed during the Diag state.

Another control (DCS_PAD_V bit in SYS_CFG register) is preprogrammed to select either a voltage measurement or a current measurement on DCS0 for this purpose. The automated control of the PSINHINT signal occurs when the microcontroller runs diagnostic testing of the DCS0 interface. A 1 second timer is included to ensure the diagnostic test is run periodically. When the timer expires (down-counts to 0), the PSINHINT signal is asserted. When the measurement of the DCS0 voltage or DCS current (as selected by the DCS_PAD_V bit) is taken, and the value falls within the preprogrammed window, the timer will be reloaded. If the measurement is outside the window, the timer will not be reloaded, and it will continue to count down until it expires, resulting in activation of PSINHINT. For testing purposes, the PSINHINT can be controlled directly via SPI while in DIAG state using the Diag State Test Selection (DSTEST) register.

12 Safing logic

12.1 Safing logic overview

to any of the integrated squib drivers. Figure 50. Top level safing engine flow chart

12.2 SPI sensor data decoding

and the ensuing comparisons of valid sensor data to the programmed thresholds. Figure 51. Safing engine – 32-bit message decoding flow chart

Figure 52. Safing engine – 16-bit Message decoding flow chart

Figure 53. Safing engine - Validate data flow chart

Figure 54. Safing engine - Combine function flow chart

Figure 55. Safing engine threshold comparison

Figure 56. Safing engine - Compare complete

Each safing record has SPI accessible registers defined in the SPI command tables and summarized below:  Request Mask and Request Target - to understand what sensor the microcontroller is addressing  Response Mask and Response Target - to identify the sensor response  Data Mask - to extract relevant sensor data from the response. – Sensor data is extracted as a bit-wise AND result of the SAF_DATA_MASKx and monitored RS_MISO data. The configuration of the set bits of the DATAMASK must be contiguous for both 16-bit and 32-bit records. The 32-bit records are comprised of Part1 as MSW and Part2 as LSW. – The extracted data is then right justified into a 16/32 bit register for 16/32 bit safing records, respectively, prior to further processing steps which assume data is signed should be "using two's complement representation".  Safing Threshold - specific value that sets the comparator limit for successful arming  Control: – IF, In Frame - to indicate serial data response is ‘in frame’. There are two types of potential serial data responses, ‘in frame’ and ‘out of frame’. – CS - to align safing record with a specific SPI CS. The device contains 5 SPI CS inputs for the safing function (CS_RS, SAF_CSx) – ARM - there are four internal arming signals, each active record is assigned or mapped to any arming signal. Several safing records can be mapped to a single arming output. ARMx outputs can be enabled also simultaneously. – Dwell - Once an arming condition is detected, the safing record remains armed for the specified dwell time. – Comb (Combined Data) - specific solution for dual axis high-g sensors specifically oriented off-axis. – LimEn (Limit Enable) - to enable PSI5 out-of-range control. – LimSel (Limit Select) - to select PSI5 out-of-range thresholds between 8-bit and 10-bit protocol. – SPIFLDSEL (SPI Field Select) - to determine which 16-bit field in long SPI messages (>31 bit) to use for response on MISO of SPI monitor. Don't care for messages less than 32 bits. If input packet matches multiple safing records, the safing engine should process all of them and treat them independently. Safing record can only be evaluated on the first matching input packet. Any further data packet matches are ignored (i.e. once CC is set, record can't be processed until CC is cleared) The En (Record Enable) bit for any record is programmable as on or off at any time and will enable/disable the record itself upon the following SATSYNC. All CC bits are available in one register (SAF_CC) for access in one single SPI read. After ARMing is achieved and CC is set, no further messages are considered until CC is cleared via read. Safing Engine must not process sensor data in any state but Safing state (refer to Figure 10). All safing records are cleared on SSM RESET.

 The sum of the two matching inputs will be compared to the threshold of record(n).  The difference of the two records will be compared to the threshold of record(n+1). engine is set in Init state.

12.3 In-frame and out-of-frame responses

the basic communication differences of in and out of frame responses. Table 15. Example of combine function operation

Figure 57. In-frame example Figure 58. Out-of-frame example Synchronization between clock domains relies upon inter-frame gap.

12.4 Safing state machine operation

12.4.1 Simple threshold comparison operation

be activated immediately entering in safing state.

POS_COUNT and NEG_COUNT are not updated if microcontroller stops reading SAF_CC bits (this must be avoided otherwise ARMING set and reset will not be possible). By way of the assignment of the ADD_VAL, SUB_VAL, ARMP_TH and ARMN_TH settings, the safing engine can be configured to assert arming for either a simple accumulation of COUNTs in a non-consecutive manner, or it could be set to require some number of consecutive samples.

12.5 Safing engine output logic (ARMxINT)

SPI messages are monitored and mapped to specific safing records. Each safing record is configured with its own threshold, dwell time and the appropriate ARMxINT signal to activate if safing criteria are met. Any enabled safing record can be programmed to an arming signal. All safing records arming status is logically ‘OR'd’ to its programmed arming signal. For example, if safing records 1, 2, 4 are programmed to ARMINT1 and the records are enabled, any of the records can set the ARMINT1 signal. Configuration of safing record mapping to ARMxINT signals is specified in the in the SAF_CONTROL_x register (refer to Table 67). While in Diag state, L9680 allows diagnostics of the squib driver HS and LS FETs, ARM pins, VSF output and firing timers. The ARM and VSF output tests are mutually exclusive. For safety purposes, the safing logic circuitry is physically separated from the circuitry that contains the deployment logic.

Figure 59. Safing engine arming flow diagram

Figure 60. Safing engine diagnostic logic High Side Safing FET activation still requires microcontroller signal.

Figure 61. ARMx input/output control logic

12.5.1 Arming pulse stretch

deployment sequence to avoid undesired behaviour. setting, the new setting will be loaded into the dwell counter. Dwell times are user programmable. The behaviour of the pulse stretch timer is shown below.

Figure 62. Pulse stretch timer example The Arming Enable Pulse Stretch Timer status is available in the AEPSTS register.

12.6 Additional communication line

standpoint, this is equivalent to a bit-wise XOR of the seed value with 0x55.

13 General purpose output (GPO) drivers

connected to load's high side. Figure 66. GPO driver and diagnostic block diagram ERBST_OK threshold to be enabled. while activating the interface. When all bits are set to '0', the GPOx output will be disabled.

mode, in order to control the drivers with 64 total levels from a 0% to a full 100% duty cycle. synchronized to provide parallel configuration capability. terminals and a +1V reverse voltage across source and drain. output driver contains diagnostics available in the GPO Fault Status Register (GPOFLTSR). All faults except for thermal overload will be latched until the GPOFLTSR register is read. driver will operate in a linear mode (ILIM) until a thermal fault condition is detected. Figure 67. GPO Over temperature logic the output current be lower than the threshold, the open detection flag is asserted. Table 16. Short to ground fault in LS mode

Table 17. Short to battery fault in HS mode

14 System voltage diagnostics

avoid saturation of high voltage internal signals, an internal voltage divider is used. Figure 68. ADC MUX

DIAGCTRL_B, DIAGCTRL_C and DIAGCTRL_D), in no particular order. bit in GSW corresponds to (NEWDATA_C or NEWDATA_D). read out. However result is cleared only when new result for that register is available. Table 18. All diagnostics results are available on the ADCRESx registers, when

Table 18. Diagnostics control register (DIAGCTRLx)

Table 18. Diagnostics control register (DIAGCTRLx) (continued)

measurement and are summarized by function in the table below.

  1. The DC sensor resistance measurement can only be addressed through DIAGCRTL_A command. Results are available

through DIAGCTRL_A and DIAGCTRL_B, where ADCRES_A will contain DCSI and ADCRES_B will contain DCSV.

  1. Valid only for ADCREQ_x field of MISO response when ESR measure results are available.

Table 19. Diagnostics divider ratios

specified in the electrical parameters section of the relevant block.

14.1 Analog to digital algorithmic converter

 Conversion from 12 to 10 bits. voltage of the ADC is set to 2.5 V. Figure 69. The timings reported in Figure 69 are nominal ones, min/max values Table 19. Diagnostics divider ratios (continued)

Figure 69. ADC conversion time

6 RI6DPSOHV

15 Temperature sensor

The L9680 provides an internal analog temperature sensor. The sensor is aimed to have a reference for the average junction temperature on silicon surface. The sensor is placed far away from power dissipating stages and squib deployment drivers. The output of the temperature sensor is available via SPI through ADC conversion, as shown in Table 18. The formula to calculate temperature from ADC reading is the following one: T C 180 220  ADC REF ADC RES  0.739– – = @ DIAGCTRLn(ADCREQn) = 0A hex All parametric requirements for this block can be found in specification tables.

Every parameter in this chapter is fulfilled down to VINGOOD(max). No device damage is granted to occur down to VINBAD(min). device, unless otherwise stated.

16.1 Configuration and control

All electrical characteristics are valid for the following conditions unless otherwise noted. Table 20. Configuration and control DC specifications

4 WU_mon WAKEUP Monitor

5 WU_off WAKEUP Off threshold GNDSUBx as ground reference

6 WU_on WAKEUP On threshold GNDSUBx as ground reference

14 I LKG_VBATMON_OFF

15 I LKG_VBATMON_ON

16 R PD_VBATMON

18 VIN GOOD0

22 VIN FASTSLOPE_H

23 VIN

25 VIN SYNC_DIS_L

27 VIN SYNC_DIS_LYS

28 I LKG_VIN_OFF

29 I LKG_VIN_ON

30 C VIN External VIN capacitor Design Info 1 - 13 (1) μF

Table 20. Configuration and control DC specifications (continued)

31 I LKG_VER_OFF

32 I LKG_VER_ON_L

36 I PD_WDTDIS

37 V TH1_H_VCCSEL_

40 V TH2_H_VCCSEL_

43 I PD_VCCSEL

44 I TOTLKG_BAT

  1. Bigger capacitor can be used in case an external switch is used in parallel to the ER-Switch.

Table 21. Configuration and control AC specifications

3 TFLT_VINGOOD_DO

4 TFLT_VINGOOD_DO

9 TFLT_VINSYNCDIS_D

10 TFLT_ VINSYNCDIS

11 T FLT_WAKEUP

13 T PWRUP

Table 21. Configuration and control AC specifications (continued)

16.2 Internal analog reference

Table 22. Open ground detection DC specifications

1 GNDA OPEN GNDA open threshold GNDSUBx=0 100 200 300 mV

2 GNDD OPEN GNDD open threshold GNDSUBx=0 100 200 300 mV

3 BSTGND OPEN BSTGND open threshold GNDSUBx=0 100 200 300 mV

5 SATGND OPEN SATGND open threshold GNDSUBx=0 100 200 300 mV

7 VCCGND OPEN VCCGND open threshold GNDSUBx=0 100 200 300 mV

Table 23. GND_OPEN_AC - Open ground detection DC specifications Table 24. Internal analog reference

16.3 Internal regulators

All electrical characteristics are valid for the following conditions unless otherwise noted. Table 25. Internal regulator DC specifications Table 26. Internal regulators AC specifications

16.4 Watchdog

Table 27. Temporal watchdog timer AC specifications (WD1) Table 28. Algorithmic watchdog timer DC specifications (WD2) Table 29. Algorithmic watchdog timer AC specifications (WD2)

16.5 Oscillators

Table 30. Oscillators specifications

16.6 Reset

Table 31. Reset DC specifications

4 VCORE UV

5 VCORE OV

Table 32. Reset AC specifications

16.7 SPI interface

Table 33. Global and remote sensor SPI DC specifications

1 VIH_CS_G

2 VIL_CS_G

3 IPU_CS_G

4 VIH_MOSI_G

5 VIL_MOSI_G

6 IPD_MOSI_G

8 VIH_SCLK_G

9 VIL_SCLK_G

10 IPD_SCLK_G

12 VOH_MISO_G

13 VOL_MISO_G

14 ILKG_MISO_G

15 V IH_MISO_RS

16 V IL_MISO_RS

Note: All timing is shown with respect to 10% and 90% of the actual delivered VCC voltage. Figure 70. SPI timing diagram Table 34. SPI AC specifications

10 T DIS_MISO MISO_x disable time - - 100 ns

11 T VALID_MISO MISO_x output valid time - - 30 ns

12 T HOLD_MISO MISO_x Output Hold Time 80 pF load; Design Info 0 - - ns

13 T NODATA SCLK_x hold time - 20 - - ns

14 T FLT_CS CS_x noise glitch rejection time - 50 - 300 ns

15 T NODATA SPI interframe time - 400 - - ns

16 TSETUP_MISO_RS MISO_RS Input Setup Time - 20 - - ns

17 THOLD_MISO_RS MISO_RS Input Hold Time - 20 - - ns

16.8 ERBoost regulator

Table 35. ERBoost regulator DC specifications

10 I LKG_ERBST_ON

13 BST33V = 1 26 28 30 V

16 V ERBST_DIS_TH

18 T JSD_ERBST

19 T HYS_TSDERBST - 5 10 15 °C

Table 35. ERBoost regulator DC specifications (continued) Table 36. ERBoost regulator AC specifications

2 TRISE_ERBSTSW_SLOW

3 TRISE_ERBSTSW_FAST

Table 36. ERBoost regulator AC specifications (continued) Table 37. ERBOOST Converter external components design info

4 ESR CBLK_ERBST Bulk capacitor ESR - - 50 m Ω

16.9 ER CAP current generators and diagnostic

Table 38. ER CAP current generators and diagnostic DC specifications

5 VER RANGE

6 VER ACC

7 ERCAP RANGE

8 ERCAP ACC

9 ERCAP_ESR RANGE

10 ERCAP_ESR ACC

11 G ER_ESR

12 OFF ER_ESR

13 T JSD_ERBST ER charge thermal

14 T HYS_TSDERBST - 5 10 15 °C

15 V VER_VBATMON_TH

16.10 ER switch

Table 39. ER CAP current generators and diagnostic AC specifications Table 40. ER Switch DC specifications Table 41. ER Switch AC specifications

16.11 COVRACT

16.12 SYNCBOOST converter

Table 42. COVRACT DC specifications

1 VOH_COVRACT

Table 43. COVRACT AC specifications Table 44. SYNCBOOST converter DC specifications

10 I OC_SYNCBST_HIGH

11 I OC_SYNCBST_LOW

12 I LKG_SYNCBOOST SYNCBOOST leakage SYNCBOOST=40V Device off - - 10 μA

13 I LKG_SYNCBSTSW SYNCBSTSW leakage SYNCBSTSW=40V Device off - - 20 μA

14 V SYNCBST_OK

15 V SYNCBST_OV

16 V SYNCBST_DIS_TH

18 VVIN_SYNCBST_RESTART_TH

20 T JSDERSYNCBST Thermal shutdown - 150 175 190 C

21 T HYS_TSDSYNCBST

Table 44. SYNCBOOST converter DC specifications (continued)

Table 45. SYNCBOOST converter AC specifications

2 TRISE_SYNCBSTSW_SLOW

3 TRISE_SYNCBSTSW_FAST

Table 46. SYNCBOOST converter external components design info

4 ESR CBLK_SYNCBST Bulk capacitor ESR - - - 50 m Ω

16.13 SATBUCK converter

Table 47. SATBUCK converter DC specifications

2 Across all line and load,

10 R DSON_SATBCK_LS

11 I OC_HS_SATBCK_HI High side over

13 I OCP_LS_SATBCK_LO Low side positive

14 I OCP_LS_SATBCK_HI

15 I OCN_LS_SATBCK_HI Low side negative

16 I OCN_LS_SATBCK_LO

17 V SATBCK_OK_LOW SATBUCK voltage

16.14 VCC regulator

Table 48. SATBUCK converter AC specifications Table 49. SATBUCK converter external components design info

4 ESR CBLK_SATBCK Bulk Capacitor ESR - - - 50 m Ω

Table 50. VCC converter DC specifications

10 I OC_HS_VCCBCK_HI

11 I OC_HS_VCCBCK_LO

12 I OCP_LS_VCCBCK

13 I OCN_LS_VCCBCK_HI

14 I OCN_LS_VCCBCK_LO

15 I OF_VCC

16 VCC OV3V VCC over voltage

18 VCC UV3V VCC under voltage

20 VCC UVL

Table 50. VCC converter DC specifications (continued)

16.15 VSF regulator

Table 51. VCC converter AC specifications

2 TRISE_VCCBCKSW

5 TFLT_VCCOV_RAMPUP

Table 52. VCC converter external components design info

4 ESR CBLK_VCCBCK Bulk capacitor ESR - - - 50 m Ω

Table 53. VSF regulator DC specifications

16.16 Deployment drivers

6 ILKG_VSF_OFF VSF input leakage Device OFF -5 - 5 μA

Table 53. VSF regulator DC specifications (continued) Table 54. VSF regulator AC specifications Table 55. Deployment drivers – DC specifications

10 ILKG_SS_ON_

Table 55. Deployment drivers – DC specifications (continued)

14 ILKG_SF_ON_

22 L DEPL Load Inductance Maximum load inductance

23 C SFx

24 C SRx 13 - 455 nF

25 C SSxy SSxy Capacitance

27 Wire Length

30 R CSx Clock Spring Resistance

  1. In case of an unsupplied device and shorted deployment pins (e.g. to battery voltage), the dynamic reverse current through

the high side power stage depends on CSSxy.

  1. L DEPL could be calculated in the following way:

Figure 71. Deployment drivers diagram Table 56. Deployment drivers – AC specifications

16.17 Deployment driver diagnostic

16.17.1 Squib resistance measurement

10 TFLT_ILIM_LS

Table 57. Deployment drivers diagnostics - Squib resistance measurement

5 ISRC_HI_SF

14 R LKG_SF SFx leakage resistance Design info 1 - - k Ω

15 V LKG_SF SFx leakage voltage source Design info -1 - 18 V

16 R SQ_ACC

Table 57. Deployment drivers diagnostics - Squib resistance measurement (continued)

16.17.2 Squib leakage test (VRCM)

Table 58. Squib Leakage Test (VRCM)

6 TFLT_LKG

10 I LIM_VRCM_SRC

11 I LIM_VRCM_SINK - 10 - 20 mA

12 V SHIFT

16.17.3 High/low side FET test

13 R SQ_LOW_TH

15 T FLT_RLOW

16 R SQ_HIGH Detection Threshold for

17 I RSQ_HIGH Equivalent to resistance range -17% 700 +17% μA

18 T FLT_RHIGH

19 Tdelay_STG_sele

Table 59. High/low side FET test

6 TTOT_FETTEST_A

16.17.4 Deployment timer test

16.18 Remote sensor interface

16.18.1 PSI-5 interface

10 SGxy OPEN

11 T FLT_SGOPEN

Table 59. High/low side FET test (continued) Table 60. Deployment timer test - AC specifications Table 61. PSI-5 satellite transceiver - DC specifications

1 IRSU Interface quiescent current - -35 - -4 mA

10 I BO Base current Default value -15% -15 +15% mA

11 I LKGG Trigger point for fault

13 I OL

14 DAC RES DAC resolution - - 10 - Bit

16 V t2 Sync pulse amplitude

17 V SYNCDROP Sync drop-out voltage V SYNCBOOST - VRSUx 1-- V

18 I LIM_SYNC_LS

19 I LIM_SYNC

20 C 1

22 C 2 ECU pin capacitance 5 nF nominal

Table 61. PSI-5 satellite transceiver - DC specifications (continued)

Table 62. PSI-5 satellite transceiver - AC specifications

10 SR RISE_RSU

11 SR FALL_RSU

14 T BLANK

16 T FLT_PSI5_HF

17 T FLT_PSI5_LF

Table 62. PSI-5 satellite transceiver - AC specifications (continued)

65 Related to t0, Sensor Side, P10P-500-4H 273 - 311 μs

72 T SYNC_DLY_SHORT

75 TFLT_LKG_RSU

76 TWRITE_EN_DELAY_LF

16.18.2 WSS interface

Table 63. WSS sensor - DC specifications

10 I LIMTH_WSS Output Current Limit - -65 - -40 mA

12 V RSU_STB

13 I STBTH

14 V OH_WS

16 I LKG_WS WSx Output Leakage Tri-state leakage -10 - 10 μA

Table 64. WSS sensor - AC specifications

4 TFLT_OCTH_WS

5 TFLT_OPEN_RS

7 TSTANDSTILL_T

8 TSTANDSTILL_T

16.19 DC sensor interface

Table 65. DC Sensor interface specifications

10 I DCS_ACC2

11 I DCS_RANGE3

12 I DCS_ACC3

13 R DCS_RANGE

14 R DCS_ACC

16 R PD_DCS

16.20 Safing engine

17 I PD_DCS_TOT

18 C DCS Output capacitance Design Info 10 - - nF

19 I REF_DCS

20 Ratio_VDCS Divider ratio for DCSx

21 V OFF_DCS

Table 66. Arming Interface – DC specifications

10 R PD_ARMx, x=1,2,3

11 I PU_ARM4 ARM4 pull up current ARM4 = 0V

12 V OH_PSINHB

13 V OL_PSINHB

14 R PD_PSINHB

15 V IH_PSINHB

16 V IL_PSINHB

17 V IH_SAF_CSx

18 V IL_SAF_CSx

19 I PU_SAF_CSx SAF_CSx pull up current SAF_CSx = 0 V to

Table 66. Arming Interface – DC specifications (continued) Table 67. Arming interface – AC specifications

16.21 General purpose output drivers

40 °C  Ta  +95 °C, VINGOOD0  VIN  35V, VGPODx + 5V  VERBOOST. Table 68. GPO interface DC specifications

15 I DIAG_GPO Diagnostic current on load

16 I LKG_GPOD_OFF

17 I LKG_GPOD_ON

18 I LKG_GPOS_OFF

19 I LKG_GPOS_ON

20 I REV_GPO Reverse current VGPOS = VGPOD + 1 V

21 T JSD_GPO

22 T HYS_TSD_GPO - 5 10 15 °C

23 C GPO Load capacitor Design Info 6 - - nF

Table 68. GPO interface DC specifications (continued) Table 69. GPO driver interface – AC specifications

16.22 Analog to digital converter

Table 69. GPO driver interface – AC specifications (continued) Table 70. Analog to digital converter

3 ADC_RES ADC resolution (1) Design Info - 10 - bit

4 DNL Differential non linearity

actual and an ideal output step.

5 INL Integral non linearity error

7 TotErr Total error

16.23 Voltage diagnostics (Analog MUX)

10 R LSB_1

12 R LSB_8

Table 70. Analog to digital converter (continued) Table 71. Voltage diagnostics (Analog MUX

1 Ratio_1

2 Ratio_4 V INPUT_RANGE_4 = 1 V to 10 V -3% 4 +3% V/V

4 Ratio_10 V INPUT_RANGE_10 = 2 V to 25 V -3% 10 +3% V/V

5 Ratio_15 V INPUT_RANGE_15 = 3 V to 35 V -3% 15 +3% V/V

6 Offset Divider Offset High impedance -10 - 10 mV

16.24 Temperature sensor

10 R RATIO_15 Multiplexer input to GNDA 200 - - k Ω

11 I LEAK_MUX_ON

Table 71. Voltage diagnostics (Analog MUX (continued) Table 72. Temperature sensor specifications

17 Quality information

17.1 OTP memory

The device contains a 128-bits One-Time Programmable memory. This OTP memory is used for the following purposes: 1. 86 bits data + 3 bits CRC for critical parameters trimming: bandgaps, oscillators, reference currents, firing currents, DC sensor and RSU interface parameters. 2. 18 bits data for other blocks trimming: ADC, ER Cap Measurement 3. 20 bits data for die and wafer traceability 4. 1 bit for debug purpose User read/write access to the OTP memory via SPI is only possible during production testing and require activation of a special test mode. During mission mode, the trimming bits are automatically read from OTP and transferred to the related circuits at each POR cycle. During this operation, actual CRC of the protected trimming data is calculated and checked against the expected CRC stored in the OTP . In case of CRC check failure the OTPCRC_ERR flag is set in the FLTSR register.

18 Errata sheet

Table 73. Errata sheet

1 L9680CC Deployment

is not tested in production.

2 L9680CC

specifications, grade definitions and product status are available at: www.st.com. ECOPACK® is an ST trademark. Figure 72. TQFP100 (14x14x1.4 mm exp. pad down) package outline

Table 74. TQFP100 (14x14x1.4 mm exp. pad down) package mechanical data

  1. Values in inches are converted from mm and rounded to 4 decimal digits.
  2. The size of exposed pad is variable depending of lead frame design pad size. End user should verify “D2”

and “E2” dimensions for each device application.

Table 75. Document revision history 03-May-2016 1 Initial release.