M41ST87Y_10 STMICROELECTRONICS | Alldatasheet
Document overview
- Manufacturer or author: Provided By ALLDATASHEET.COM(FREE DATASHEET DOWNLOAD SITE)
- PDF pages: 52
Technical content
Datasheet sections
- 1 Description
- 1.1 Security features
- 2 Operating modes
- 2.1.1 Bus not busy
- 2.1.2 Start data transfer
- 2.1.3 Stop data transfer
- 2.1.4 Data valid
- 2.1.5 Acknowledge
- 2.2 READ mode
- 2.3 WRITE mode
- 2.4 Data retention mode
- 2.5 Tamper detection circuit
- 2.6 Tamper register bits (tamper 1 and tamper 2)
- 2.6.1 Tamper enable bits (TEB1 and TEB2)
- 2.6.2 Tamper bits (TB1 and TB2)
- 2.6.3 Tamper interrupt enable bits (TIE1 and TIE2)
- 2.6.4 Tamper connect mode bit (TCM1 and TCM2)
- 2.6.5 Tamper polarity mode bits (TPM1 and TPM2)
- 2.6.6 Tamper detect sampling (TDS1 and TDS2)
- 2.6.7 Tamper current high/tamper current low (TCHI/TCLO1
- 2.6.8 RAM clear (CLR1 and CLR2)
- 2.6.9 RAM clear external (CLR1 EXT and CLR2EXT) - available in SOX28
- 2.7 Tamper detection operation
- 2.8 Sampling
- 2.9 Internal tamper pull-up/down current
- 2.10 Avoiding inadvertent tampers (normally closed configuration)
- 2.11 Tamper event time-stamp
- 3 Clock operation
- 3.0.1 Power-down time-stamp
Features
■ 5.0, 3.3, or 3.0 V operation ■ 400 kHz I2C bus ■ NVRAM supervisor to non-volatize external LPSRAM ■ 2.5 to 5.5 V oscillator operating voltage ■ Automatic switchover and deselect circuitry ■ Choice of power-fail deselect voltages – M41ST87Y: THS = 1: VPFD≈ 4.63 V; VCC = 4.75 to 5.5 V THS = 0: VPFD≈ 4.37 V; VCC = 4.5 to 5.5 V – M41ST87W: THS = 1: VPFD ≈ 2.9 V; VCC = 3.0 to 3.6 V THS = 0: VPFD ≈ 2.63 V; VCC = 2.7 to 3.6 V ■ Two independent power-fail comparators (1.25 V reference) ■ Counters for tenths/hundredths of seconds, seconds, minutes, hours, day, date, month, year, and century ■ 128 bytes of clearable, general purpose NVRAM ■ Programmable alarm and interrupt function (valid even during battery backup mode) ■ Programmable watchdog timer ■ Unique electronic serial number (8-byte) ■ 32 kHz frequency output available upon power- on ■ Microprocessor power-on reset output ■ Battery low flag ■ Ultra-low battery supply current of 500 nA (typ) Security features ■ Tamper indication circuits with timestamp and RAM clear ■ LPSRAM clear function (TPCLR) ■ Packaging includes a 28-lead, embedded crystal SOIC and a 20-lead SSOP ■ Oscillator stop detection 28-pin, (300 mil) SOX28 (MX) Embedded crystal SSOP20 (SS)
M41ST87Y, M41ST87W Contents Doc ID 9497 Rev 8 3/52
3.8 Reset inputs (RSTIN1
3.14 t
Description M41ST87Y, M41ST87W 6/52 Doc ID 9497 Rev 8
1 Description
The M41ST87Y/W secure serial RTC and NVRAM supervisor is a low power 1280-bit, static CMOS SRAM organized as 160 bytes by 8 bits. A built-in 32.768 kHz oscillator (internal crystal-controlled) and 8 bytes of the SRAM (see Table 7 ) are used for the clock/calendar function and are configured in binary coded decimal (BCD) format. An additional 11 bytes of RAM provide calibration, status/control of alarm, watchdog, tamper, and square wave functions. 8 bytes of ROM and finally 128 bytes of user RAM are also provided. Addresses and data are transferred serially via a two line, bidirectional I interface. The built-in address register is incremented automatically after each WRITE or READ data byte. The M41ST87Y/W has a built-in power sense circuit which detects power failures and automatically switches to the battery supply when a power failure occurs. The energy needed to sustain the SRAM and clock operations can be supplied by a small lithium button-cell supply when a power failure occurs. Functions available to the user include a non-volatile, time-of-day clock/calendar, alarm interrupts, tamper detection, watchdog timer, and programmable square wave output. Other features include a power-on reset as well as two additional debounced inputs (RSTIN1 and RSTIN2) which can also generate an output reset (RST). The eight clock address locations contain the century, year, month, date, day, hour, minute, second and tenths/hundredths of a second in 24-hour BCD format. Corrections for 28, 29 (leap year), 30 and 31 day months are made automatically.
1.1 Security features
Two fully independent tamper detection Inputs allow monitoring of multiple locations within the system. User programmable bits provide both normally open and normally closed switch monitoring. Time stamping of the tamper event is automatically provided. There is also an option allowing data stored in either internal memory (128 bytes), and/or external memory to be cleared, protecting sensitive information in the event tampering occurs. By embedding the 32 kHz crystal in the SOX28 package, the clock is completely isolated from external tampering. An oscillator fail bit (OF) is also provided to ensure correct operation of the oscillator. The M41ST87Y/W is supplied in a 28-pin, 300 mil SOIC package (MX) which includes an embedded 32 kHz crystal and a 20-pin SSOP package (SS) for use with an external crystal. The SOIC and SSOP packages are shipped in plastic anti-static tubes or in tape & reel form. The 300 mil, embedded crystal SOIC requires only a user-supplied battery to provide non- volatile operation.
Figure 1. Logic diagram
- Programmable output (open drain or full-CMO S). Defaults to open drain on first power-up.
- Available in SOX28 (MX) package only.
- Available in SSOP (SS) package only.
Table 1. Signal names
- Available in SSOP (SS) package only.
- Available in SOX28 (MX) package only.
- Programmable output (open drain or full-CMOS).
- Should be connected to V SS.
Figure 4. Block diagram
- Programmable output (open drain or full -CMOS); if open drain option is selected and if pulled-up to supply other than VCC,
this supply must be equal to, or less than VBAT when VCC = 0 V (during battery backup mode).
- Available in SOX28 (MX) package only.
- Crystal is external on SSOP (SS) pack age and internal for the SOX28 (MX) package.
128 BYTES
8 BYTES ROM
Figure 5. Hardware hookup
- Available in SOX28 (MX) package only.
Operating modes M41ST87Y, M41ST87W 12/52 Doc ID 9497 Rev 8
2 Operating modes
The M41ST87Y/W clock operates as a slave device on the serial bus. Access is obtained by implementing a start condition followed by the correct slave address (D0h). The 160 bytes contained in the device can then be accessed sequentially in the following order: 00h. Tenths/hundredths of a second register 01h. Seconds register 02h. Minutes register 03h. Century/hours register 04h. Day register 05h. Date register 06h. Month register 07h. Y ear register 08h. Control register 09h. Watchdog register 0Ah-0Eh. Alarm registers 0Fh. Flag register 10h-12h. Reserved 13h. Square wave 14h. Tamper register 1 15h. Tamper register 2 16h-1Dh. Serial number (8 bytes) 1Eh-1Fh. Reserved (2 bytes) 20h-9Fh. User RAM (128 bytes) The M41ST87Y/W clock continually monitors V CC for an out-of-tolerance condition. Should VCC fall below VPFD, the device terminates an access in progress and resets the device address counter. Inputs to the device will not be recognized at this time to prevent erroneous data from being written to the device from a an out-of-tolerance system. When VCC falls below VSO, the device automatically switches over to the battery and powers down into an ultra low current mode of operation to conserve battery life. As system power returns and VCC rises above VSO, the battery is disconnected, and the device is switched to external VCC. Write protection continues until trec (min) elapses after VCC reaches VPFD (min). For more information on battery storage life refer to application note AN1012.
M41ST87Y, M41ST87W Operating modes Doc ID 9497 Rev 8 13/52 2.1 2-wire bus characteristics The bus is intended for communication between different ICs. It consists of two lines: a clock signal (SCL) and a bidirectional data signal (SDA). The SDA line must be connected to a positive supply voltage via a pull-up resistor. The following protocol has been defined:
- Data transfer may be initiated only when the bus is not busy.
- During data transfer, the data line must remain stable whenever the clock line is high.
- Changes in the data line, while the clock line is high, will be interpreted as control signals. Accordingly, the following bus conditions have been defined:
2.1.1 Bus not busy
Both data and clock lines remain high.
2.1.2 Start data transfer
A change in the state of the data line, from high to low, while the clock is high, defines the START condition.
2.1.3 Stop data transfer
A change in the state of the data line, from low to high, while the clock is high, defines the STOP condition.
2.1.4 Data valid
The state of the data line represents valid data when, after a start condition, the data line is stable for the duration of the high period of the clock signal. The data on the line may be changed during the low period of the clock signal. There is one clock pulse per bit of data. Each data transfer is initiated with a start condition and terminated with a stop condition. The number of data bytes transferred between the start and stop conditions is not limited. The information is transmitted byte-wide and each receiver acknowledges with a ninth bit. By definition a device that gives out a message is called “transmitter,” the receiving device that gets the message is called “receiver.” The device that controls the message is called “master.” The devices that are controlled by the master are called “slaves.”
2.1.5 Acknowledge
Each byte of eight bits is followed by one acknowledge bit. This acknowledge bit is a low level put on the bus by the receiver whereas the master generates an extra acknowledge related clock pulse. A slave receiver which is addressed is obliged to generate an acknowledge after the reception of each byte that has been clocked out of the transmitter. The device that acknowledges has to pull down the SDA line during the acknowledge clock pulse in such a way that the SDA line is a stable low during the high period of the acknowledge related clock pulse. Of course, setup and hold times must be taken into account. A master receiver must signal an end of data to the slave transmitter by not generating an acknowledge on the last byte that has been clocked out of the slave. In this
Table 2. AC characteristics
2.2 READ mode
At this point the master transmitter becomes the master receiver. byte and the address pointer is incremented to An+2. STOP condition to the slave transmitter (see Figure 10 on page 16). the pointer increments to a non-clock or RAM address. Note: This is true both in READ mode and WRITE mode. that is read is the last one stored in the pointer (see Figure 11 on page 16).
- Available in SOX28 (MX) package only.
- Transmitter must internally provide a hold time to bridge the undefined region (300 ns max) of the falling edge of SCL.
Figure 9. Slave address location Figure 10. READ mode sequence Figure 11. Alternate READ mode sequence
0100011 MSB
2.3 WRITE mode
the word address and each data byte. Figure 12. WRITE mode sequence Figure 13. WRITE cycle timing: RTC & external SRAM control signals
- Available in SOX28 (MX) package only.
2.4 Data retention mode
Operating modes M41ST87Y, M41ST87W 18/52 Doc ID 9497 Rev 8 power input is switched from the VCC pin to the battery, and the clock registers and external SRAM are maintained from the attached battery supply. All signal outputs become high impedance. The VOUT pin is capable of supplying 100µA of current to the attached memory with less than 0.3 volts drop under this condition. On power up, when V CC returns to a nominal value, write protection continues for trec by inhibiting ECON. The RST signal also remains active during this time (see Figure 28 on page 46). Note: Most low power SRAMs on the market today can be used with the M41ST87Y/W RTC SUPERVISOR. There are, however some criteria which should be used in making the final choice of an SRAM to use. The SRAM must be designed in a way where the chip enable input disables all other inputs to the SRAM. This allows inputs to the M41ST87Y/W and SRAMs to be “Don’t Care” once V CC falls below VPFD(min). The SRAM should also guarantee data retention down to VCC = 2.0 volts. The chip enable access time must be sufficient to meet the system needs with the chip enable output propagation delays included. If the SRAM includes a second chip enable pin (E2), this pin should be tied to V OUT. If data retention lifetime is a critical parameter for the system, it is important to review the data retention current specifications for the particular SRAMs being evaluated. Most SRAMs specify a data retention current at 3.0 volts. Manufacturers generally specify a typical condition for room temperature along with a worst case condition (generally at elevated temperatures). The system level requirements will determine the choice of which value to use. The data retention current value of the SRAMs can then be added to the I BAT value of the M41ST87Y/W to determine the total current requirements for data retention. The available battery capacity for the battery of your choice can then be divided by this current to determine the amount of data retention available. For a further more detailed review of lifetime calculations, please see application note AN1012.
2.5 Tamper detection circuit
The M41ST87Y/W provides two independent input pins, the tamper pin 1 input (TP1IN) and tamper pin 2 input (TP2IN), which can be used to monitor two separate signals which can result in the associated setting of the tamper bits (TB1 and/or TB2, in flag register 0Fh) if the tamper enable bits (TEB1 and/or TEB2) are enabled, for the respective tamper 1 or tamper 2 channels. The TP1 IN pin or TP2IN pin may be set to indicate a tamper event has occurred by either 1) closing a switch to ground or VOUT (normally open), or by 2) opening a switch that was previously closed to ground or VOUT (normally closed), depending on the state of the TCMX bits and the TPMX bits in the tamper register (14h and/or 15h).
2.6 Tamper register bits (tamper 1 and tamper 2)
2.6.1 Tamper enable bits (TEB1 and TEB2)
When set to a logic '1,' this bit will enable the tamper detection circuit. This bit must be set to '0' in order to clear the associated tamper bits (TBX, in 0Fh). Note: 1 TEB X should be cleared then set again whenever the tamper detect condition is modified.
2 When servicing a tamper interrupt, the TEB x bits must be cleared to clear the TBx bits, then
set to 1 to again enable the tamper detect circuits.
M41ST87Y, M41ST87W Operating modes Doc ID 9497 Rev 8 19/52
2.6.2 Tamper bits (TB1 and TB2)
If the TEBX bit is set, and a tamper condition occurs, the TBX bit will be set to '1.' This bit is “Read-only” and is reset only by setting the TEBX bit to '0.' These bits are located in the flags register 0Fh.
2.6.3 Tamper interrupt enable bits (TIE1 and TIE2)
If this bit is set to a logic '1,' the IRQ/OUT pin will be activated when a tamper event occurs. This function is also valid in battery backup if the ABE bit (alarm in battery backup) is also set to '1' (see Figure 15 on page 21). Note: In order to avoid an inad vertent activation of the IRQ/OUT pin due to a prior tamper event, the flag register (0Fh) should be read prior to clearing and again setting the TEBX bit.
2.6.4 Tamper connect m ode bit (TCM1 and TCM2)
This bit indicates whether the position of the external switch selected by the user is in the normally open (TCMX = '1') or normally closed (TCMX = '0') position (see Figure 14 on page 20 and Figure 16 on page 21).
2.6.5 Tamper polarity mode bits (TPM1 and TPM2)
The state of this bit indicates whether the tamper pin input will be taken high (to VOUT if TPMX = '1') or low (to VSS if TPMX = '0') to trigger a tamper event (see Figure 14 on page 20 and Figure 16 on page 21).
Figure 14. Tamper detect connection options Note: These options are summarized in Table 3.
- If the CLRX EXT bit is set, a second tamper to VOUT (TPM2 = '1') during tCLR will not be detected.
- If the CLRX EXT bit is set, a second tamper to VOUT (TPM2 = '1') will trigger automatically.
- Optional external resistor to VCC allows the user to bypass sampling when power is “on.”
Table 3. Tamper detection truth table
- No battery current drawn during battery backup.
Operating modes M41ST87Y, M41ST87W 22/52 Doc ID 9497 Rev 8
2.6.6 Tamper detect sampling (TDS1 and TDS2)
This bit selects between a 1Hz sampling rate or constant monitoring of the tamper input pin(s) to detect a tamper event when the normally closed switch mode is selected. This allows the user to reduce the current drain when the TEB X bit is enabled while the device is in battery backup (see Table 4 on page 23 and Figure 17 on page 23). Sampling is disabled if the TCMX bit is set to logic '1' (Normally Open). In this case the state of the TDSX bit is a “Don’t care.” Note: The crystal oscillator must be “on” for sampling to function. If the oscillator is stopped, the tamper detect circuit will revert to continuous monitoring.
2.6.7 Tamper current high/t amper current low (TCHI/TCLO1 and
TCHI/TCLO2) This bit selects the strength of the internal pull-up or pull-down used during the sampling of the normally closed condition. The state of the TCHI/TCLOX bit is a “Don’t care” for normally open (TCMX = '1') mode (see Figure 18 on page 24).
2.6.8 RAM clear (CLR1 and CLR2)
When either CLR1 or CLR2 and the TEBX bit are set to a logic '1,' the internal 128 bytes of user RAM (see Figure 15 on page 21) will be cleared to all zeros in the event of a tamper condition. Furthermore, the 128 bytes of user RAM will be deselected (inaccessible) until the corresponding TEBX bit is reset to '0.' Any data read during this time will be invalid. (ie. the cleared RAM values cannot be accessed.)
2.6.9 RAM clear external (CLR1 EXT and CLR2EXT) - available in SOX28
When either CLR1EXT or CLR2EXT is set to a logic '1' and the TEBX bit is also set to logic '1,' the TPCLR signal will be asserted for clearing external RAM, and the RST output asserted upon detection of a tamper event (see Figure 15 on page 21 and Figure 20 on page 25). Note: The reset output resulting from a tamper ev ent will be the same as a reset resulting from a power-down condition, a watchdog time-out, or a manual reset (RSTIN1 or RSTIN2); the RST output will be asserted for trec seconds. This is accomplished by forcing TPCLR high, which if used to control the inhibit pin of the DC regulator (see Figure 20 on page 25) will also switch off VOUT, depriving the external SRAM of power to the VCC pin. VOUT will automatically be disconnected from the battery if the tamper occurs during battery back-up (see Figure 19 on page 24). By inhibiting the DC regulator, the user will also prevent other inputs from sourcing current to the external SRAM, which would allow it to retain data otherwise. The user may optionally connect an inverting charge pump to the VCC pin of the external SRAM (see Figure 20 on page 25). Depending on the process technology used for the manufacturing of the external SRAM, clearing the memory may require varying durations of negative potential on the VCC pin. This device configuration will allow the user to program the time needed for their particular application. Control Bits CLRPW0 and CLRPW1 determine the duration TP CLR will be enabled (see Figure 19 on page 24 and Table 5 on page 25). Note: When using the inverting charge pump, the user must also provide isolation in the form of two additional small-signal power MOSFETs. These will isolate the VOUT pin from both the
Table 5. Tamper detect timing Figure 20. RAM clear hardware hookup (SOX28 MX package only)
- Most inverting charge pumps drive OUT to ground when device shut down is enabled (SHDN = logic low). Therefore, an n-
channel enhancement mode MOSFET should be used to isolate the OUT pin from the VOUT of the M41ST87.
- In order to avoid turning on an on- chip parasitic diode when driving VOUT negative, a p-channel enhancement mode
MOSFET should be used to isolate the VOUT pin from the negative voltage generated by the inverting charge pump.
0 Min Typ Max Unit
- With input capacitance = 70 pF and resistance = 50 Ω.
- If the OF bit is set, t CLRD(min) = 0.5 ms.
Operating modes M41ST87Y, M41ST87W 26/52 Doc ID 9497 Rev 8
2.7 Tamper detection operation
The tamper pins are triggered based on the state of an external switch. Two switch mode options are available, normally open or normally closed, based on the setting of the tamper connect mode bit (TCM X). If the selected switch mode is normally open (TCMX = '1'), the tamper pin will be triggered by being connected to VSS (if the TPMX bit is set to '0') or to VCC (if the TPMX bit is set to '1'), through the closing of the external switch. When the external switch is closed, the tamper bit (TBx) will be immediately set, allowing the user to determine if the device has been physically tampered with. If the selected switch mode is normally closed (TCM X = '0'), the tamper pin will be triggered by being pulled to VSS or to VOUT (depending on the state of the TPMX bit), through an internal pull-up/pull-down resistor as a result of opening the external switch. When a tamper event occurs, the tamper bits (TB1 and/or TB2) will be immediately set if TEBX = '1.' If the tamper interrupt enable bit (TIEX) is set to a '1,' the IRQ/OUT pin will also be activated. The IRQ/OUT output is cleared by a READ of the flags register (as seen in Figure 24 on page 34), a reset of the TIE bit to '0,' or the RST output is asserted. Note: In order to avoid an inad vertent activation of the IRQ/OUT pin due to a prior tamper event, the flag register (0Fh) should be read prior to resetting the TEBX bit. The tamper bits are “read only” bits and are reset only by writing the tamper enable bit (TEBX) to '0.' Thus, when servicing a tamper interrupt, the user should read the flags register to clear the IRQ pin, then clear the TEBx bit to clear the TBx flag, followed by setting TEBx to again enable the tamper circuit. The tamper detect function operates both under normal power, and in battery backup. Even if the trigger event occurs during a power-down condition, the tamper flag bit(s) will be set correctly.
2.8 Sampling
As the switch mode normally closed (TCMX = '0') requires a greater amount of current to maintain constant monitoring, the M41ST87Y/W offers a programmable tamper detect sampling bit (TDS X) to reduce the current drawn on VCC or VBAT (see Figure 17 on page 23). When enabled, the sampling frequency is once per second (1Hz), for a duration of approximately 1 ms. When TEBX is disabled, no current will be drawn by the tamper detection circuit. After a tamper event has been detected, no additional current will be drawn. Note: The oscillator mu st be running for tamper detection to operate in the sampling mode. If the oscillator is stopped, the tamper detection circuit will revert to constant monitoring. Note: Sampling in the tamper high mode (TPM X = '1') may be bypassed while on VCC by connecting the TPxIN pin to VCC through an external resistor. This will allow constant monitoring when VCC is “on” and revert to sampling when in battery backup (see Figure 14 on page 20).
2.9 Internal tamper pull-up/down current
1 MΩ pull-up/-down resistor, while TCHI/TCLOX = '0' uses a 10 MΩ pull-up/-down resistor
2.10 Avoiding inadvertent tampers (normally closed
a capacitor (C) on the tamper input pin. Figure 21. Low-pass filter implementation for noise immunity Table 6. Calculated cut-off frequency for typical capacitance and resistance
Operating modes M41ST87Y, M41ST87W 28/52 Doc ID 9497 Rev 8
2.11 Tamper event time-stamp
Regardless of which tamper occurs first, not only will the appropriate tamper bit be set, but the event will also be automatically time-stamped. This is accomplished by freezing the normal update of the clock registers (00h through 07h) immediately following a tamper event. Thus, when tampering occurs, the user may first read the time registers to determine exactly when the tamper event occurred, then re-enable the clock update to the current time (and reset the tamper bit, TB X) by resetting the tamper enable bit (TEBX). The time update will then resume and the clock can be read to determine the current time. Both tamper enable bits (TEBX) must always be set to '0' in order to read the current time. In the event of multiple tampers, the time-stamp will reflect the initial tamper event. Note: If the TEB X bit is set, the tamper event time-stamp will take precedence over the power down time-stamp (see Section 3.0.1: Power-down time-stamp on page 29) and the HT bit (halt update) will not be set during the power-down event. If both are needed, the power down time-stamp may be accomplished by writing the time into the general purpose RAM memory space when PFO is asserted.
M41ST87Y, M41ST87W Clock operation Doc ID 9497 Rev 8 29/52
3 Clock operation
The eight byte clock register (see Table 7 on page 30) is used to both set the clock and to read the date and time from the clock, in a binary coded decimal format. Tenths/hundredths of seconds, seconds, minutes, and hours are contained within the first four registers. Note: A WRITE to any clock register (addresses 0 to 7h) will result in the tenths/hundredths of seconds being reset to “00.” Furthermore, the tenths/hundredths of seconds cannot be written to any value other than “00.” Bits D6 and D7 of clock register 03h (century/hours register) contain the CENTURY bit 0 (CB0) and CENTURY bit 1 (CB1). Bits D0 through D2 of register 04h contain the day (day of week). Registers 05h, 06h, and 07h contain the date (day of month), month, and years. The ninth clock register is the control register (this is described in the clock calibration section). Bit D7 of register 01h contains the STOP bit (ST). Setting this bit to a '1' will cause the oscillator to stop. If the device is expected to spend a significant amount of time on the shelf, the oscillator may be stopped to reduce current drain. When reset to a '0' the oscillator restarts within one second (typical). Note: A WRITE to ANY location within the first eight bytes of the clock register (00h-07h), including the OFIE bit, CLRPW0 bit, CLRPW1 bit, THS bit, and so forth, will result in an update of the system clock and a reset of the divider chain. This could result in a significant corruption of the current time, especially if the HT bit (see Section 3.0.1: Power-down time- stamp) has not been previously reset. These non-clock related bits should be written prior to setting the clock, and remain unchanged until such time as a new clock time is also written. The eight clock registers may be read one byte at a time, or in a sequential block. The control register (address location 08h) may be accessed independently. The M41ST87 will periodically copy the time/date counters to the user registers thus updating them. This process is suspended when any of these 8 registers is being accessed. It is also suspended during backup mode. Suspending the updates ensures that the clock data being read does not change during the READ.
3.0.1 Power-down time-stamp
Upon power-down following a power failure, the halt update bit (HT) will automatically be set to a '1.' This will prevent the clock from updating the user registers, and will allow the user to read the time of the power-down event. Note: When the HT bit is set or a tamper event occurs, the tenths/hundredths of a second register (00h) will automatically be reset to a value of “00.” All other date and time registers (01h - 07h) will retain the value last updated prior to the power-down or tamper event. The internal clock remains accurate and no time is lost as a result of the zeroing of the tenth/hundredths of a second register. When updates are resumed (due to resetting the HT bit or TEB bit), the correct time will be displayed. Resetting the HT bit to a '0' will allow the clock to update the user registers with the current time. Note: If the TEB bit is set, the power down time-s tamp will be disabled, and the tamper event time- stamp will take precedence (see Section 2.7: Tamper detection operation on page 26).
3.1 TIMEKEEPER ® registers
WRITE to any clock address (00h to 07h). condition or when the pointer increments to a non-clock or RAM address. wave registers store data in binary format. Table 7. TIMEKEEPER
1 CLR1EXT CLR1 Tamper1
M41ST87Y, M41ST87W Clock operation Doc ID 9497 Rev 8 31/52
3.2 Calibrating the clock
The M41ST87Y/W is driven by a quartz controlled oscillator with a nominal frequency of 32,768 Hz. The devices are tested to not exceed ±35 ppm (parts per million) oscillator frequency error at 25 °C, with ±20 ppm crystals, which translates to about ±1.53 minutes per month. Even better accuracy can be achieved with higher accuracy crystals. When the calibration circuit is properly employed, accuracy can be improved to better than ±2 ppm at 25 °C. The oscillation rate of crystals changes with temperature (see Figure 22 on page 33). Therefore, the M41ST87Y/W design employs periodic counter correction. The calibration circuit adds or subtracts counts from the oscillator divider circuit at the divide by 256 stage, as shown in Figure 23: Calibration waveform on page 33. The number of times pulses which are blanked (subtracted, negative calibration) or split (added, positive calibration) depends upon the value loaded into the five calibration bits found in the control register. Adding counts speeds the clock up, subtracting counts slows the clock down. The calibration bits occupy the five lower order bits (D4-D0) in the control register (08h). These bits can be set to represent any value between 0 and 31 in binary form. Bit D5 is a sign bit; '1' indicates positive calibration, '0' indicates negative calibration. Calibration occurs within a 64 minute cycle. The first 62 minutes in the cycle may, once per minute, have one second either shortened by 128 or lengthened by 256 oscillator cycles. If a binary '1' is loaded into the register, only the first 2 minutes in the 64 minute cycle will be modified; if a binary 6 is loaded, the first 12 will be affected, and so on. Keys: 0 = Must be set to zero RB0-RB1 = Watchdog resolution bits 32kE = 32 kHz output enable bit RPT1-RPT5 = Alarm repeat mode bits ABE = Alarm in battery backup mode enable bit RS0-RS3 = SQW frequency AF = Alarm flag (read only) S = Sign bit AFE = Alarm flag enable bit SQWE = Square wave enable BL = Battery low flag (read only) SQWOD = Square wave open drain bit BMB0-BMB4 = Watchdog multiplier bits ST = Stop bit CB0-CB1 = Century bits TB (1 and 2) = Tamper bits (read only) CLR (1 and 2) = RAM clear bits TCHI/TCLO (1 and 2) = Tamper current hi/tamper current low bits CLR (1 and 2)EXT = RAM clear external bits TCM (1 and 2) = Tamper connect mode bits CLRPW0 = RAM clear pulse width 0 bit TDS (1 and 2) = Tamper detect sampling bits CLRPW1 = RAM clear pulse width 1 bit TEB (1 and 2) = Tamper enable bits FT = Frequency test bit THS = Threshold bit HT = Halt update bit TIE (1 and 2) = Tamper interrupt enable bits OF = Oscillator fail bit TPM (1 and 2) = Tamper polarity mode bits OFIE = Oscillator fail interrupt enable bit TR = t rec bit OUT = Output level WDS = Watchdog steering bit PFOD = Power-fail output open drain bit WDF = Watchdog flag (read only)
Clock operation M41ST87Y, M41ST87W 32/52 Doc ID 9497 Rev 8 Therefore, each calibration step has the effect of adding 512 or subtracting 256 oscillator cycles for every 125,829,120 actual oscillator cycles, that is +4.068 or –2.034 ppm of adjustment per calibration step in the calibration register. Assuming that the oscillator is running at exactly 32,768 Hz, each of the 31 increments in the calibration byte would represent +10.7 or –5.35 seconds per month which corresponds to a total range of +5.5 or –2.75 minutes per month. Two methods are available for ascertaining how much calibration a given M41ST87Y/W may require. The first involves setting the clock, letting it run for a month and comparing it to a known accurate reference and recording deviation over a fixed period of time. Calibration values, including the number of seconds lost or gained in a given period, can be found in application note AN934, “TIMEKEEPER ® calibration.” This allows the designer to give the end user the ability to calibrate the clock as the environment requires, even if the final product is packaged in a non-user serviceable enclosure. The designer could provide a simple utility that accesses the calibration byte. The second approach is better suited to a manufacturing environment, and involves the use of the SQW/FT pin. The pin will toggle at 512 Hz, when the stop bit (ST) is '0,' the frequency test bit (FT) is '1,' and SQWE is '0.' Any deviation from 512 Hz indicates the degree and direction of oscillator frequency shift at the test temperature. For example, a reading of 512.010124 Hz would indicate a +20 ppm oscillator frequency error, requiring a –10 (XX001010) to be loaded into the calibration byte for correction. Note that setting or changing the calibration byte does not affect the frequency test output frequency. If the SQWOD bit = '1,' the SQW/FT pin is an open drain output which requires a pull-up resistor to V CC for proper operation. A 500 to 10 kΩ resistor is recommended in order to control the rise time. The FT bit is cleared on power-down.
Figure 22. Crystal accuracy across temperature Figure 23. Calibration waveform
3.3 Setting alarm clock registers
M41ST87Y/W is in the battery back-up to serve as a system wake-up call. mode to quickly alert the user of an incorrect alarm setting.
the alarm, write '0' to the alarm date register and to RPT5–RPT1. easily handled by simply reading past the flags registers before teminating a read sequence. during power-up. Figure 25 on page 35 illustrates the backup mode alarm timing. Figure 24. Alarm interrupt reset waveform Table 8. Alarm repeat modes
11111 O n c e p e r s e c o n d
11110 O n c e p e r m i n u t e
11100 O n c e p e r h o u r
11000 O n c e p e r d a y
10000 O n c e p e r m o n t h
00000 O n c e p e r y e a r
Figure 25. Backup mode alarm waveform
3.4 Watchdog timer
register = 3*1 or 3 seconds). Note: The accuracy of the timer is within ± the selected resolution. WRITE of the watchdog register. The time-out period then starts over. be written into the watchdog register, effectively restarting the count-down cycle.
(bit D7; register 0Fh) but does not clear the IRQ/OUT pin.
3.5 Square wave output
the SQW/FT pin. RS3-RS0 bits located in 13h establish the square wave output frequency. wave enable bit (SQWE) located in Register 0Ah. specified in Table 17 on page 44). Table 9. Square wave output frequency
0000 N o n e –
11008 H z
11014 H z
11102 H z
11111 H z
3.6 Full-time 32 kHz square wave output
disconnected and allowed to float. Note: The F 32k pin is an open drain which requires an external pull-up resistor.
3.7 Power-on reset
be chosen to control rise time. SQWE, FT, WDS, BMB0-BMB4, RB0, RB1, TIE1, and TIE2 (see Table 13 on page 41).
3.8 Reset inputs (RSTIN1 & RSTIN2)
The M41ST87Y/W provides two independent inputs which can generate an output reset. triggers on the rising edge. Note: RSTIN2 is available only in the SOX28 (MX) package. Figure 26. RSTIN1 & RSTIN2 timing waveforms
Table 10. Reset AC characteristics
3.9 Power-fail comparators (1 and 2)
Two power-fail inputs (PFI1 and PFI2) are compared to an internal reference voltage (1.25V). operating voltage, thus providing an early warning of power failure.
3.10 Power-fail outputs
specified in Table 17 on page 23).
- Pulse widths of less than 100 ns will result in no RESET (for noise immunity).
- Programmable (see Table 12 on page 40). Same function as power-on reset.
3.11 Century bits
the appropriate turn-of-century years. Table 11. Century bits examples
3.12 Output driver pin
Note: The IRQ /OUT pin is an open drain which requires an external pull-up resistor.
3.13 Battery low warning
next scheduled 24-hour interval. below approximately 2.5 volts and may not be able to maintain data integrity in the SRAM. CC is applied to the device.
- Leap year occurs every four years (f or years evenly divisible by four), except for years evenly divisible by
- The only exceptions are those years evenly divisible by 400 (the year 2000 was a leap year, year
The M41ST87Y/W only monitors the battery when a nominal VCC is applied to the device. power-up via a checksum or other technique. allow the user to set the length of this deselect time as defined by Table 12. Table 12. t rec definitions
3.15 Electronic serial number
is “read only” and is generated such that no two devices will contain an identical number.
3.16 Oscillator stop detection
- The first time power is applied (defaults to a '1' on power-up).
- The voltage present on VCC or battery is insufficient to support oscillation.
- The ST bit is set to '1.' If the oscillator fail interrupt enable bit (OFIE) is set to a '1,' the IRQ/OUT pin will also be asserted. The IRQ/OUT output is cleared by resetting the OF bit to '0,' resetting the OFIE bit to '0,' or if the RST output is asserted (but is NOT cleared by reading the flag register). The OF bit will remain set to '1' until written to logic '0.' The oscillator must start and have run for at least 4 seconds before attempting to reset the OF bit to '0.' This function operates both under normal power and in battery backup. If the trigger event occurs during a power- down condition, this bit will be set correctly. Note: The ABE bit must be set to '1' for the IRQ /OUT pin to be activated in battery backup. trec bit (TR) STOP bit (ST) trec time Units Min Max 0 0 96 98 (1) 1. Default setting. ms 01 4 0 2 0 0 m s
1 X 50 2000 µs
3.17 Initial power-on defaults
Note: All other control bits are undetermined. Table 13. Default values
- When TEB X is set to '1,' the HT bit will not be set on power-down (tamper time-stamp will have precedence).
- ⇑ = VCC rising; ⇓ = VCC falling.
- WDS, BMB0-BMB4, RB0, RB1.
- 32 kHz output valid only on V
4 Maximum ratings
Program and other relevant quality documents. Table 14. Absolute maximum ratings
- Reflow at peak temperature of 260 °C. The time above 255 °C must not exceed 30 seconds.
- Reflow at peak temperature of 240 °C. The time above 235°C must not exceed 20 seconds.
5 DC and AC parameters
the measurement conditions when using the quoted parameters. Table 15. DC and AC measurement conditions Note: Output high Z is defined as the point where data is no longer driven. Figure 27. AC testing input/output waveforms Table 16. Capacitance
- Effective capacitance measured with power supply at 5 V. Sampled only, not 100% tested.
Table 17. DC characteristics
- Measured with V OUT and ECON open. Not including tamper detection current (see Table 4 on page 23).
- RSTIN1 and RSTIN2 internally pulled-up to VCC through 100 kΩ resistor. WDI internally pulled-down to VSS through
- External SRAM must match RTC supervisor chip V
- For PFO 1 and PFO2 (if PFOD = '0'), SQW/FT (if SQWOD = '0'), and TPCLR pins (CMOS).
- Conditioned output (E CON) can only sustain CMOS leakage current in the battery backup mode. Higher leakage currents
- TP CLR output can source –300 µA (typ) for VBAT = 2.9 V.
- For IRQ /OUT, SQW/FT (if SQWOD = '1'), PFO1 and PFO2 (if PFOD = '1'), RST, SDA, and F32k pins (open drain).
Table 17. DC characteristics (continued) Table 18. Crystal (1) electrical characteristics
- User supplied for the 20-lead SSOP package. STMicroelectronics recommends the KDS DT-38 (3 x 8 mm) for thru-hole, or
- Load capacitors are integrated within the M41ST87. Circuit board layout considerations for the 32.768 kHz crystal of
minimum trace lengths and isolation from RF generating signals should be taken into account.
- T A = –40 to 85 °C (guaranteed by design).
Figure 28. Power down/up mode AC waveforms
- E CON available in the SOX28 (MX) package only.
Table 19. Power down/up AC characteristics
- V PFD(max) to VPFD(min) fall time of less than tF may result in deselection/write protection not occurring until
200 µs after VCC passes VPFD(min).
- V PFD(min) to VSS fall time of less than tFB may cause corruption of RAM data.
- Programmable (see Table 12 on page 40)
6 Package mechanical data
specifications, grade definitions and product status are available at: www.st.com. ECOPACK® is an ST trademark. Figure 29. SOX28 – 28-lead plastic small outline, 300 mils, embedded crystal outline Note: Drawing is not to scale. Table 20. SOX28 – 28-lead plastic small outline, 300 mils, embedded crystal
Figure 30. SSOP20 – 20-lead, shrink, small outline package outline Table 21. SSOP20 – 20-lead, shrink, small outline package mechanical data
7 Part numbering
Table 22. Ordering information scheme ST sales office nearest you.
- The SOX28 package includes an embedded 32,768 Hz crystal.
- Lead-free second level interconnect and RoHS compliant (by exemption).
- Available in 3.3 V (W) version only.
- SSOP20 (SS) package only.
References M41ST87Y, M41ST87W 50/52 Doc ID 9497 Rev 8
8 References
KDS, the crystal component supplier mentioned in this document, can be contacted at
9 Revision history
Table 23. Document revision history 23-Apr-2003 2 Document promoted to preliminary data. 7-Sep-2004 4 Update maximum ratings ( Table 14). 28-Mar-2006 6 Update to “Avoiding inadvertent tamper paragraph“ paragraph. 15, 20, Section 6: Package mechanical data.