MF0ICU2 NXP | Alldatasheet
Document overview
- Manufacturer or author: Provided By www.digicamel.com(FREE DATASHEET DOWNLOAD SITE)
- PDF pages: 15
Technical content
- General description NXP Semiconductors has developed MIFARE MF0ICU2 - MIFARE Ultralight C - to be used with Proximity Coupling Devices (PCD) according to ISO/IEC 14443A (seeRef. 1 “ISO/IEC”). The communication layer (MIFARE RF Interface) complies to parts 2 and 3 of the ISO/IEC 14443A standard. The MF0ICU2 is primarily designed for limited use applications such as public transportation, event ticketing and NFC Forum Tag Type 2 applications.
1.1 Contactless energy and data transfer
In the MIFARE system, the MF0ICU2 is connected to a coil with a few turns. The MF0ICU2 fits for the TFC.0 (Edmonson) and TFC.1 ticket formats as defined in EN 753-2. TFC.1 ticket formats are supported by the MF0xxU20 chip featuring an on-chip resonance capacitor of 16.9 pF . The smaller TFC.0 tickets are supported by the MFxxU21 chip holding an on-chip resonance capacitor of 50 pF . When the ticket is positioned in the proximity of the coupling device (PCD) antenna, the high speed RF communication interface allows the transmission of the data with a baud rate of 106 kbit/s.
1.2 Anticollision
An intelligent anticollision function according to ISO/IEC 14443 allows to operate more than one card in the field simultaneously. The anticollision algorithm selects each card individually and ensures that the execution of a transaction with a selected card is performed correctly without data corruption resulting from other cards in the field. MF0ICU2 MIFARE Ultralight C Rev. 3.2 — 19 May 2009 171432 Product short data sheet PUBLIC Fig 1. MIFARE card reader 001aah998 coil: 20 mm coil: 56 mm TFC.0 energy directly mounted IC data MIFARE CARD PCD
MF0ICU2_SDS_32 © NXP B.V. 2009. All rights reserved. Product short data sheet PUBLIC Rev. 3 — 19 May 2009 171432 2 of 15 NXP Semiconductors MF0ICU2 MIFARE Ultralight C
1.2.1 Cascaded UID
The anticollision function is based on an IC individual serial number called Unique IDentification. The UID of the MF0ICU2 is 7 bytes long and supports cascade level 2 according to ISO/IEC 14443-3.
1.3 Security
- 3DES Authentication
- Anti-cloning support by unique 7-byte serial number for each device
- 32-bit user programmable OTP area
- Field programmable read-only locking function per page for first 512-bit
- Read-only locking per block for rest of memory 2. Features
2.1 MIFARE‚ RF interface (ISO/IEC 14443 A)
n Contactless transmission of data and supply energy (no battery needed) n Operating distance: up to 100 mm (depending on field strength and antenna geometry) n Operating frequency: 13.56 MHz n Fast data transfer: 106 kbit/s n High data integrity: 16-bit CRC, parity, bit coding, bit counting n True anticollision n 7-byte serial number (cascade level 2 according to ISO/IEC 14443-3) n Typical ticketing transaction: < 35 ms n Fast counter transaction: < 10 ms
2.2 EEPROM
n 512-bit compatible to MF0ICU1 n Field programmable read-only locking function per page for first 512-bit n Field programmable read-only locking function per block n 32-bit user definable One-Time Programmable (OTP) area n 16-bit counter n Data retention of 5 years n Write endurance 10000 cycles
MF0ICU2_SDS_32 © NXP B.V. 2009. All rights reserved. [1] Stresses above one or more of the limiting values may cause permanent damage to the device. of the specification is not implied. [3] Exposure to limiting values for extended periods may affect device reliability. Table 1. Quick reference data[1][2][3] Table 2. Ordering information
MF0ICU2_SDS_32 © NXP B.V. 2009. All rights reserved. Product short data sheet PUBLIC Rev. 3 — 19 May 2009 171432 4 of 15 NXP Semiconductors MF0ICU2 MIFARE Ultralight C 6. Block diagram 7. Functional description
7.1 Block description
The MF0ICU2 chip consists of the 1536-bit EEPROM, the RF-Interface and the Digital Control Unit. Energy and data are transferred via an antenna, which consists of a coil with a few turns directly connected to the MF0ICU2. No further external components are necessary. (For details on antenna design please refer to the document Ref. 6 “MIFARE (Card) Coil Design Guide”.)
- RF-Interface: – Modulator/Demodulator – Rectifier – Clock Regenerator – Power On Reset – Voltage Regulator
- Crypto coprocessor: Triple Data Encryption Standard (3DES) coprocessor
- Crypto control unit: controls Crypto coprocessor operations
- Command Interpreter: Handles the commands supported by the MF0ICU2 in order to access the memory
- EEPROM-Interface
- EEPROM: The 1536 bits are organized in 48 pages with 32 bits each. 80 bits are reserved for manufacturer data. 32 bits are used for the read-only locking mechanism. 32 bits are available as an OTP area. 1152 bits are user programmable read/write memory. Fig 2. Block diagram 001aah999 antenna RF-INTERFACE DIGITAL CONTROL UNIT EEPROM CRYPTO CO PROCESSOR CRYPTO CONTROL UNIT COMMAND INTERPRETER EEPROM INTERFACE
MF0ICU2_SDS_32 © NXP B.V. 2009. All rights reserved. Product short data sheet PUBLIC Rev. 3 — 19 May 2009 171432 5 of 15 NXP Semiconductors MF0ICU2 MIFARE Ultralight C
7.2 State diagram and logical states description
The commands are initiated by the PCD and controlled by the Command Interpreter of the MF0ICU2. It handles the internal states (as shown inFigure 3 “State diagram”) and generates the appropriate response. For a correct implementation of an anticollision procedure please refer to the documents inSection 10 “References”. Remark: Not shown in this diagram: In each state the command interpreter returns to the Idle state if an unexpected command is received. If the IC has already been in the Halt state before it returns to the Halt state in such a case. Fig 3. State diagram 001aai000 AUTHENTICATED ACTIVE READY 1 HALTIDLE POR SELECT of cascade level 1 READ from address 0 READ from address 0 WRITE of 4 byte WRITE of 4 byte READ of 16 byte READ of 16 byte ANTICOLLISION ANTICOLLISION AUTHENTICATE REQA WUPA WUPA HALT HALT SELECT of cascade level 2 READY 2 identification and selection procedure memory operations
MF0ICU2_SDS_32 © NXP B.V. 2009. All rights reserved.
7.3 Memory organization
state the EEPROM cells are read as a logical “0”, in the written state as a logical “1”.
7.3.1 UID/serial number
According to ISO/IEC14443-3 BCC0 is defined as CT⊕ SN0 ⊕ SN1⊕ SN2. Table 3. Memory organization
MF0ICU2_SDS_32 © NXP B.V. 2009. All rights reserved. Product short data sheet PUBLIC Rev. 3 — 19 May 2009 171432 7 of 15 NXP Semiconductors MF0ICU2 MIFARE Ultralight C
7.3.2 Lock bytes
Lock bytes enable the user to lock parts of the complete memory area for writing. A Read from user memory area cannot be restricted via lock bytes functionality. For this, please refer to the authentication functionality, (see Section 7.3.4 “3DES Authentication”).
7.3.3 OTP bytes
OPT bytes are pre-set to all “0” after production. These bytes may be bit-wise modified by a WRITE command. 7.3.4 3DES Authentication 3DES Authentication proves that two entities have the same secret and each entity can be seen as a reliable partner for the coming communication. The applied encryption algorithm ek() is 2 key 3DES encryption (see Ref. 9 “NIST SP800-67: Recommendation fortheTripleData EncryptionAlgorithm(TDEA) Block Cipher,Version1.1Ma y 19,2008”) in Cipher-Block Chaining (CBC) mode as described in ISO/IEC 10116 (seeRef. 10 “ISO/IEC10116:Informationtechnology-Securitytechniques-Modes ofoperationforan n-bit block cipher, February 1, 2006”).
7.3.5 Data pages
MF0ICU2 features 144 bytes of data memory. The address range from page 04h to 27h constitutes the read/write area. A write access to data memory is achieved with WRITE (seeSection 7.5.7 “WRITE”) or COMPATIBILITY WRITE (seeSection7.5.8“COMP ATIBILITYWRITE” ) command. In both cases, 4 bytes of memory - (one page) - will be overwritten. Write access to data memory can be permanently restricted via lock bytes (see Section 7.3.2 “Lock bytes”) and/or permanently or temporary restricted using an authentication (seeSection 7.3.4 “3DES Authentication”). NFC Forum Type 2 Tag compliancy MF0ICU2 has been designed to be compliant with NFC Forum Type 2 Tag specification (see Ref. 5 “MIFARE Ultralight as Type 2 Tag”). With its 144 bytes of data memory, it can easily support use cases like Smart Poster, Hand over, SMS, URL or Call Request.
7.4 Counter
MF0ICU2 features 16-bit one way counter. In its delivery state, counter value is set to 0000h.
MF0ICU2_SDS_32 © NXP B.V. 2009. All rights reserved. Product short data sheet PUBLIC Rev. 3 — 19 May 2009 171432 8 of 15 NXP Semiconductors MF0ICU2 MIFARE Ultralight C
7.5 Command set
The ATQA and SAK are identical as for MF0ICU1 (seeRef. 7 “MF0ICU1 Functional specification MIFARE Ultralight”). For information on ISO 14443 card activation, seeRef. 3 “MIFARE ISO/IEC 14443 PICC Selection”. The MF0ICU2 comprises the following command set:
7.5.1 REQA
The MF0ICU2 accepts the REQA command in Idle state only. The response is the 2-byte ATQA. REQA and ATQA are implemented fully according to ISO/IEC14443-3.
7.5.2 WUPA
The MF0ICU2 accepts the WUPA command in the Idle and Halt state only. The response is the 2-byte ATQA. WUPA is implemented fully according to ISO/IEC14443-3.
7.5.3 ANTICOLLISION and SELECT of cascade level 1
The ANTICOLLISION and SELECT commands are based on the same command code. They differ only in the Parameter byte. This byte is per definition 70h in case of SELECT. The MF0ICU2 accepts these commands in the Ready1 state only. The response is part 1 of the UID.
7.5.4 ANTICOLLISION and SELECT of cascade level 2
The ANTICOLLISION and SELECT commands are based on the same command code. They differ only in the parameter byte. This byte is per definition 70h in case of SELECT. The MF0ICU2 accepts these commands in the Ready2 state only. The response is part 2 of the UID.
7.5.5 READ
The READ command needs the page address as a parameter. Only addresses 00h to 2Bh are decoded. For higher addresses the MF0ICU2 returns a NAK. The MF0ICU2 responds to the READ command by sending 16 bytes starting from the page address defined in the command (e.g. if ADR is ‘03h‘ pages 03h, 04h, 05h, 06h are returned). If ADR is ‘2Bh’, the contents of pages 2Bh, 00h, 01h and 02h is returned). This is also applied by configuring the authentication address.
7.5.6 HALT
The HALT command is used to set already processed MF0ICU2 devices into a different waiting state (Halt instead of Idle), which allows a simple separation between devices whose UIDs are already known (as they have already passed the anticollision procedure) and devices that have not yet been identified by their UIDs.
7.5.7 WRITE
The WRITE command is used to program the lock bytes in page 02h, the OTP bytes in page 03h or the data bytes in pages 04h to 05h. A WRITE command is performed page-wise, programming 4 bytes in a page.
MF0ICU2_SDS_32 © NXP B.V. 2009. All rights reserved.
7.5.8 COMPATIBILITY WRITE
address. It is recommended to set the remaining bytes 4 to 15 to all ‘0’.
7.5.9 AUTHENTICATE
[1] Stresses above one or more of the limiting values may cause permanent damage to the device. [2] Exposure to limiting values for extended periods may affect device reliability. [3] MIL Standard 883-C method 3015; Human body model: C = 100 pF , R = 1.5 kΩ . Table 4. Limiting values[1][2] In accordance with the Absolute Maximum Rating System (IEC 60134).
MF0ICU2_SDS_32 © NXP B.V. 2009. All rights reserved. Table 5. Abbreviations
MF0ICU2_SDS_32 © NXP B.V. 2009. All rights reserved. Table 6. Revision history
MF0ICU2_SDS_32 © NXP B.V. 2009. All rights reserved. Product short data sheet PUBLIC Rev. 3 — 19 May 2009 171432 12 of 15 NXP Semiconductors MF0ICU2 MIFARE Ultralight C 12. Legal information
12.1 Data sheet status
[1] Please consult the most recently issued document before initiating or completing a design. [2] The term ‘short data sheet’ is explained in section “Definitions”. [3] The product status of device(s) described in this document may have changed since this document was published and may differ in case of multiple devices. The latest product status information is available on the Internet at URL http://www.nxp.com.
12.2 Definitions
Draft —The document is a draft version only. The content is still under internal review and subject to formal approval, which may result in modifications or additions. NXP Semiconductors does not give any representations or warranties as to the accuracy or completeness of information included herein and shall have no liability for the consequences of use of such information. Short data sheet —A short data sheet is an extract from a full data sheet with the same product type number(s) and title. A short data sheet is intended for quick reference only and should not be relied upon to contain detailed and full information. For detailed and full information see the relevant full data sheet, which is available on request via the local NXP Semiconductors sales office. In case of any inconsistency or conflict with the short data sheet, the full data sheet shall prevail.
12.3 Disclaimers
General — Information in this document is believed to be accurate and reliable. However, NXP Semiconductors does not give any representations or warranties, expressed or implied, as to the accuracy or completeness of such information and shall have no liability for the consequences of use of such information. Right to make changes —NXP Semiconductors reserves the right to make changes to information published in this document, including without limitation specifications and product descriptions, at any time and without notice. This document supersedes and replaces all information supplied prior to the publication hereof. Suitability for use —NXP Semiconductors products are not designed, authorized or warranted to be suitable for use in medical, military, aircraft, space or life support equipment, nor in applications where failure or malfunction of an NXP Semiconductors product can reasonably be expected to result in personal injury, death or severe property or environmental damage. NXP Semiconductors accepts no liability for inclusion and/or use of NXP Semiconductors products in such equipment or applications and therefore such inclusion and/or use is at the customer’s own risk. Applications —Applications that are described herein for any of these products are for illustrative purposes only. NXP Semiconductors makes no representation or warranty that such applications will be suitable for the specified use without further testing or modification. Limiting values —Stress above one or more limiting values (as defined in the Absolute Maximum Ratings System of IEC 60134) may cause permanent damage to the device. Limiting values are stress ratings only and operation of the device at these or any other conditions above those given in the Characteristics sections of this document is not implied. Exposure to limiting values for extended periods may affect device reliability. Terms and conditions of sale —NXP Semiconductors products are sold subject to the general terms and conditions of commercial sale, as published at http://www.nxp.com/profile/terms , including those pertaining to warranty, intellectual property rights infringement and limitation of liability, unless explicitly otherwise agreed to in writing by NXP Semiconductors. In case of any inconsistency or conflict between information in this document and such terms and conditions, the latter will prevail. No offer to sell or license —Nothing in this document may be interpreted or construed as an offer to sell products that is open for acceptance or the grant, conveyance or implication of any license under any copyrights, patents or other industrial or intellectual property rights. Export control —This document as well as the item(s) described herein may be subject to export control regulations. Export might require a prior authorization from national authorities. Quick reference data —The Quick reference data is an extract of the product data given in the Limiting values and Characteristics sections of this document, and as such is not complete, exhaustive or legally binding.
12.4 Licenses
12.5 Trademarks
Notice: All referenced brands, product names, service names and trademarks are the property of their respective owners. MIFARE — is a trademark of NXP B.V. MIFARE Ultralight —is a trademark of NXP B.V. Document status[1][2] Product status[3] Definition Objective [short] data sheet Development This document contains data from the objective specification for product development. Preliminary [short] data sheet Qualification This document contains data from the preliminary specification. Product [short] data sheet Production This document contains the product specification. ICs with DPA Countermeasures functionality NXP ICs containing functionality implementing countermeasures to Differential Power Analysis and Simple Power Analysis are produced and sold under applicable license from Cryptography Research, Inc.
MF0ICU2_SDS_32 © NXP B.V. 2009. All rights reserved. Product short data sheet PUBLIC Rev. 3 — 19 May 2009 171432 13 of 15 NXP Semiconductors MF0ICU2 MIFARE Ultralight C 13. Contact information For more information, please visit:http://www.nxp.com For sales office addresses, please send an email to:salesaddresses@nxp.com
MF0ICU2_SDS_32 © NXP B.V. 2009. All rights reserved. Table 4. Limiting values
NXP Semiconductors MF0ICU2 MIFARE Ultralight C © NXP B.V. 2009. All rights reserved. For more information, please visit: http://www.nxp.com For sales office addresses, please send an email to: salesaddresses@nxp.com Date of release: 19 May 2009 171432 Please be aware that important notices concerning this document and the product(s) described herein, have been included in section ‘Legal information’. 16. Contents 7.2 State diagram and logical states description . . 5