DATASHEET SEARCH SITE | WWW.ALLDATASHEET.COM

Document overview

  • Manufacturer or author: Provided By ALLDATASHEET.COM(FREE DATASHEET DOWNLOAD SITE)
  • PDF pages: 117

Technical content

  1. Introduction This data sheet describes the functionality of the MFRC531 Integrated Circuit (IC). It includes the functional and electrical specifications and from a system and hardware viewpoint gives detailed information on how to design-in the device. Remark: The MFRC531 supports all variants of the MIFARE Mini, MIFARE 1K, MIFARE 4K, MIFARE Ultralight, MIFARE DESFire EV1 and MIFARE Plus RF identification protocols. To aid readability throughout this data sheet, the MIFARE Mini, MIFARE 1K, MIFARE 4K, MIFARE Ultralight, MIFARE DESFire EV1 and MIFARE Plus products and protocols have the generic name MIFARE. 2. General description The MFRC531 is a highly integrated reader IC for contactless communication at 13.56 MHz. The MFRC531 reader IC provides:
  • outstanding modulation and demodulation for passive contactless communication
  • a wide range of methods and protocols
  • a small, fully integrated package
  • pin compatibility with the MFRC500, MFRC530 and SLRC400 All protocol layers of the ISO/IEC 14443 A and ISO/IEC 14443 B communication standards are supported provided:
  • additional components, such as the oscillator, power supply, coil etc. are correctly applied.
  • standardized protocols, such as ISO/IEC 14443-4 and/or ISO/IEC 14443 B anticollision are correctly implemented The MFRC531 supports contactless communication using MIFARE higher baud rates (see Section 9.12 on page 38). The receiver module provides a robust and efficient demodulation/decoding circuitry implementation for compatible transponder signals (see Section 9.10 on page 32 The digital module, manages the complete ISO/IEC 14443 standard framing and error detection (parity and CRC). In addition, it supports the fast MIFARE security algorithm for authenticating the MIFARE products (see Section 9.14 on page 40). The internal transmitter module (Section 9.9 on page 29) can directly drive an antenna designed for a proximity operating distance up to 100 mm without any additional active circuitry. MFRC531 Standard ISO/IEC 14443 A/B reader solution Rev. 3.7 — 30 June 2015 056637 Product data sheet COMPANY PUBLIC

Rev. 3.7 — 30 June 2015 056637 2 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution A parallel interface can be directly connected to any 8-bit microprocessor to ensure reader/terminal design flexibility. In addition, Serial Peripheral Interface (SPI) compatibility is supported (see Section 9.1.4 on page 9). 3. Features and benefits

3.1 General

 Highly integrated analog circuitry for demodulating and decoding card/label response  Buffered output drivers enable antenna connection using the minimum of external components  Proximity operating distance up to 100 mm  Supports both ISO/IEC 14443 A and ISO/IEC 14443 B standards  Supports the MIFARE Mini, MIFARE 1K, MIFARE 4K protocols  Contactless communication at MIFARE higher baud rates (up to 424 kBd)  Crypto1 and secure non-volatile internal key memory  Pin-compatible with the MFRC500, MFRC530 and the SLRC400  Parallel microprocessor interface with internal address latch and IRQ line  SPI compatibility  Flexible interrupt handling  Automatic detection of parallel microprocessor interface type  64-byte send and receive FIFO buffer  Hard reset with low power function  Software controlled Power-down mode  Programmable timer  Unique serial number  User programmable start-up configuration  Bit-oriented and byte oriented framing  Independent power supply pins for analog, digital and transmitter modules  Internal oscillator buffer optimized for low phase jitter enables 13.56 MHz quartz connection  Clock frequency filtering  3.3 V to 5 V operation for transmitter in short range and proximity applications  3.3 V or 5 V operation for the digital module

Table 1. Quick reference data Table 2. Ordering information

Rev. 3.7 — 30 June 2015 056637 4 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution 7. Block diagram Fig 1. MFRC531 block diagram 001aal218 FIFO CONTROL 64-BYTE FIFO MASTER KEY BUFFER CYRPTO1 UNIT CONTROL REGISTER BANK NWR NRD NCS ALE A0 A1 A2 10 11 9 21 22 23 24 13 14 15 16 17 18 19 20 AD0 to AD7/D0 to D7 STATE MACHINE MFRC531 COMMAND REGISTER PROGRAMMABLE TIMER INTERRUPT CONTROL CRC16/CRC8 GENERATION AND CHECK PARALLEL/SERIAL CONVERTER BIT COUNTER PARITY GENERATION AND CHECK FRAME GENERATION AND CHECK SERIAL DATA SWITCH BIT DECODING BIT ENCODING 32 × 16-BYTE EEPROM EEPROM ACCESS CONTROL 32-BIT PSEUDO RANDOM GENERATOR AMPLITUDE RATING CLOCK GENERATION, FILTERING AND DISTRIBUTION OSCILLATOR LEVEL SHIFTERS CORRELATION AND BIT DECODINGREFERENCE VOLTAGE Q-CHANNEL AMPLIFIER Q-CHANNEL DEMODULATOR I-CHANNEL AMPLIFIERANALOG TEST MULTIPLEXER I-CHANNEL DEMODULATOR PARALLEL INTERFACE CONTROL (INCLUDING AUTOMATIC INTERFACE DETECTION AND SYNCHRONISATION) VOLTAGE MONITOR AND POWER ON DETECT DVDD RSTPD Q-CLOCK GENERATION TRANSMITTER CONTROL GND GND TX1 TX2TVSSRXAUXVMID TVDD 578292730 6 V V POWER ON DETECT OSCIN AVDD AVSS OSCOUT IRQ MFIN MFOUT DVSS RESET CONTROL POWER DOWN CONTROL

8.1 Pin description

Table 3. Pin description

1 OSCIN I oscillator/clock inputs:

2 IRQ O interrupt request generates an output signaling an interrupt event

3 MFIN I ISO/IEC 14443 A MIFARE serial data interface input

6 TVDD P transmitter power supply for the TX1 and TX2 output stages

8 TVSS G transmitter ground for the TX1 and TX2 output stages

9 NCS I not chip select input: selects and activates the microprocessor interface

12 DVSS G digital ground

[1] Pin types: I = Input, O = Output, I/O = Input/Output, P = Power and G = Ground.

13 D0 O SPI master in, slave out output

23 A1 I address line 1 is the address register bit 1 input

25 DVDD P digital power supply

26 AVDD P analog power supply for pins OSCIN, OSCOUT, RX, VMID and AUX

28 AVSS G analog ground

13.56 MHz, drawn from the antenna circuit

30 VMID P internal reference voltag e pin provides the internal reference voltage as a supply

31 RSTPD I reset and power-down input:

32 OSCOUT O crystal oscillator output for the oscillator’s inverting amplifier

9.1 Digital interface

9.1.1 Overview of supported microprocessor interfaces

the parallel interface signals supported by the MFRC531.

9.1.2 Automatic microprocessor interface detection

mode and detects the microprocessor interface type. Initialization routine (see Section 9.7.4 on page 28). Table 4. Supported microproces sor and EPP interface signals

9.1.3 Connection to different microprocessor types

The connection to various microprocessor types is shown in Table 5.

9.1.3.1 Separate read and write strobe

Refer to Section 13.4.1 on page 93 for timing specification. Table 5. Connection scheme for detecting the parallel interface type

Rev. 3.7 — 30 June 2015 056637 9 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution

9.1.3.2 Common read and write strobe

Refer to Section 13.4.2 on page 94 for timing specification.

9.1.3.3 Common read and writ e strobe: EPP with handshake

Refer to Section 13.4.3 on page 95 for timing specification. Remark: In the EPP standard, a chip select signal is not defined. To cover this situation, the status of the NCS pin can be used to inhibit the nDStrb signal. If this inhibitor is not used, it is mandatory that pin NCS is connected to pin DVSS. Remark: After each Power-On or Hard reset, the nWait signal on pin A0 is high-impedance. nWait is defined as the first negative edge applied to the nAStrb pin after the reset phase. The MFRC531 does not support the Read Address Cycle.

9.1.4 Serial Peripheral Interface

The MFRC531 provides compatibility with the 5-wire Serial Peripheral Interface (SPI) standard and acts as a slave during SPI communication. The SPI clock signal SCK must be generated by the master. Data communication from the master to the slave uses the MOSI line. The MISO line sends data from the MFRC531 to the master. Fig 4. Connection to microprocessor: common read and write strobes 001aal221 address bus (A3 to An) NCS A0 to A2 address bus (A0 to A2) D0 to D7 ALE data bus (D0 to D7) HIGH NRDData strobe (NDS) NWRRead/Write (R/NW) MFRC531 ADDRESS DECODER non-multiplexed address NCS AD0 to AD7 ALE multiplexed address/data (AD0 to AD7) Address strobe (AS) NRDData strobe (NDS) NWRRead/Write (R/NW) A2LOW A1HIGH A0LOW MFRC531 ADDRESS DECODER Fig 5. Connection to micropro cessor: EPP common read/write strobes and handshake 001aal222 LOW NCS AD0 to AD7 ALE multiplexed address/data (AD1 to AD8) Address strobe (nAStrb) NRDData strobe (nDStrb) NWRRead/Write (nWrite) A2HIGH A1HIGH A0nWait MFRC531

Figure 6 shows the microprocessor connection to the MFRC531 using SPI. ensures that the MFRC531 can only be addressed as a slave.

9.1.4.1 SPI read data

up to n-data bytes. The first byte sent defines both, the mode and the address.

  • the Most Significant Bit (MSB) of the first byte sets the mode. To read data from the MFRC531 the MSB is set to logic 1
  • bits [6:1] define the address
  • the Least Significant Bit (LSB) should be set to logic 0. As shown in Table 8, all the bits of the last byte sent are set to logic 0.

Table 6. SPI compatibility Table 7. SPI read data

[1] All reserved bits must be set to logic 0.

9.1.4.2 SPI write data

up to n-data bytes. The first byte sent defines both the mode and the address.

  • the MSB of the first byte sets the mode. To write data to the MFRC531, the MSB is set to logic 0
  • bits [6:1] define the address
  • the LSB should be set to logic 0. SPI write mode writes all data to the address defined in byte 0 enabling effective write cycles to the FIFO buffer. [1] All reserved bits must be set to logic 0. Remark: The data bus pins D7 to D1 must be disconnected. Refer to Section 13.4.4 on page 97 for the timing specification.

Table 8. SPI read address Table 9. SPI write data Table 10. SPI write address

9.2 Memory organiza tion of the EEPROM

Table 11. EEPROM memory organization diagram

10 A A0h to AFh W

11 B B0h to BFh W

12 C C0h to CFh W

13 D D0h to DFh W

14 E E0h to EFh W

15 F F0h to FFh W

9.2.1 Product information field (read only)

[1] Byte 4 contains the current version number.

9.2.2 Register initialization files (read/write)

Table 12. Product in formation field

15 CRC R - the content of the product information field

14 RsMaxP R - maximum source resistance for the

register’s GsCfgCW[5:0] bits to 01h. Table 13. Product type identification definition

  • the Page register (addressed using 10h, 18h, 20h, 28h) is skipped and not initialized.
  • make sure that all PreSetxx registers are not changed.
  • make sure that all register bits that are reserved are set to logic 0.

9.2.2.1 StartUp register initialization file (read/write)

register initialization file”. The byte assignment is shown in Table 14.

9.2.2.2 Factory default StartU p register initialization file

values are written to the MFRC531’s registers. Table 14. Byte assignment for register initialization at start-up

Table 15. Shipment content of StartUp configuration file

9.2.2.3 Register initializa tion file (read/write)

argument for the initialization procedure. The byte assignment is shown in Table 16. up to one block (16-byte) of user data. be used to store other user data.

9.2.3 Crypto1 keys (write only)

communication on the contactless interface. These keys are called Crypto1 keys.

9.2.3.1 Key format

into lower four bits k0 to k3 (lower nibble) and the higher four bits k4 to k7 (higher nibble). page 88) and LoadKey commands (see Section 11.6.2 on page 88). Example: The value for the key must be written to the EEPROM.

  • If the key was: A0h A1h A2h A3h A4h A5h then:
  • 5Ah F0h 5Ah E1h 5Ah D2h 5Ah C3h 5Ah B4h 5Ah A5h would be written.

Table 16. Byte assignment for register initialization at startup

cause the LoadKeyE2 command (see Section 11.6.1 on page 88) to fail.

9.2.3.2 Storage of keys in the EEPROM

byte of the dedicated memory area can be the start of a key. block, for example, key byte 1 is stored at 130h, byte 2 at 131h up to byte 11 at 13Ah. different keys can be stored in the EEPROM. Remark: It is not possible to load a key exceeding the EEPROM byte location 1FFh.

9.3 FIFO buffer

An 8  64 bit FIFO buffer is used in the MFRC531 to act as a parallel-to-parallel converter. 64 bytes long without needing to take timing constraints into account.

9.3.1 Accessing the FIFO buffer

9.3.1.1 Access rules

write and read pointer can be obtained by reading the FIFOLength register. Table 17. FIFO buffer access

9.3.2 Controlling the FIFO buffer

buffer to be written with another 64 bytes of data.

9.3.3 FIFO buffer status information

  • the number of bytes stored in the FIFO buffer: bits FIFOLength[6:0]
  • the FIFO buffer full warning: bit HiAlert
  • the FIFO buffer empty warning: bit LoAlert
  • the FIFO buffer overflow warning: bit FIFOOvfl. Remark: Setting the FlushFIFO bit clears the FIFOOvfl bit. The MFRC531 can generate an interrupt signal when:
  • bit LoAlertIRq is set to logic 1 and bit LoAlert = logic 1, pin IRQ is activated.
  • bit HiAlertIRq is set to logic 1 and bit HiAlert = logic 1, pin IRQ activated. The HiAlert flag bit is set to logic 1 only when the WaterLevel[5:0] bits or less can be stored in the FIFO buffer. The trigger is generated by Equation 1: (1) The LoAlert flag bit is set to logic 1 when the FIFOLevel register’s WaterLevel[5:0] bits or less are stored in the FIFO buffer. The trigger is generated by Equation 2: (2) ReadE2 yes yes the microprocessor has to prepare the arguments, afterwards only reading is allowed LoadKeyE2 yes - LoadKey yes - Authent1 yes - Authent2 - - LoadConfig yes - CalcCRC yes -

9.3.4 FIFO buffer registers and flags

Table 17 shows the related FIFO buffer flags in alphabetic order.

9.4 Interrupt request system

capabilities ensuring efficient microprocessor software.

9.4.1 Interrupt sources overview

to the TReLoadValue[7:0] with bit TAutoRestart enabled.

  • the transmitter automatically sets the bit TxIRq interrupt when it is active and its state changes from sending data to transmitting the end of frame pattern
  • the CRC coprocessor sets the bit TxIRq after all data from the FIFO buffer has been processed indicated by bit CRCReady = logic 1
  • when EEPROM programming is finished, the bit TxIRq is set and is indicated by bit E2Ready = logic 1 The RxIRq flag bit indicates an interrupt when the end of the received data is detected. The IdleIRq flag bit is set when a command finishes and the content of the Command register changes to Idle. When the FIFO buffer reaches the HIGH-level indicated by the WaterLevel[5:0] value (see Section 9.3.3 on page 18 ) and bit HiAlert = logic 1, then the HiAlertIRq flag bit is set to logic 1. When the FIFO buffer reaches the LOW-level indicated by the WaterLevel[5:0] value (see Section 9.3.3 on page 18) and bit LoAlert = logic 1, then LoAlertIRq flag bit is set to logic 1.

Table 18. Associated FIFO buffer registers and flags

9.4.2 Interrupt request handling

9.4.2.1 Controlling interrupts and getting their status

source for an interrupt can be masked by the InterruptEn register interrupt enable bits. request bits are OR’ed, coupled to the IRq flag and then forwarded to pin IRQ.

9.4.2.2 Accessing the interrupt registers

register address must be set to logic 1 at the same time. to logic 1 and leaves all other bits unchanged. Table 19. Interrupt sources Table 20. Interrupt control registers

9.4.3 Configuration of pin IRQ

controlled using the following IRQPinConfig register bits.

  • bit IRQInv: the signal on pin IRQ is equal to the logic level of bit IRq when this bit is set to logic 0. When set to logic 1, the signal on pin IRQ is inverted with respect to bit IRq.
  • bit IRQPushPull: when set to logic 1, pin IRQ has CMOS output characteristics. When it is set to logic 0, it is an open-drain output which requires an external resistor to achieve a HIGH-level at pin IRQ. Remark: During the reset phase (see Section 9.7.2 on page 28) bit IRQInv is set to logic 1 and bit IRQPushPull is set to logic 0. This results in a high-impedance on pin IRQ.

9.4.4 Register overview interrupt request system

Table 21 shows the related interrupt request system flags in alphabetical order. Table 21. Associated Interrupt request system registers and flags

Rev. 3.7 — 30 June 2015 056637 22 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution

9.5 Timer unit

The timer derives its clock signal from the 13.56 MHz on-board chip clock. The microprocessor can use this timer to manage timing-relevant tasks. The timer unit can be used in one of the following configurations:

  • Timeout counter
  • WatchDog counter
  • Stopwatch
  • Programmable one shot
  • Periodical trigger The timer unit can be used to measure the time interval between two events or to indicate that a specific timed event occurred. The timer is triggered by events but does not influence any event (e.g. a time-out during data receiving does not automatically influence the receiving process). Several timer related flags can be set and these flags can be used to generate an interrupt.

Rev. 3.7 — 30 June 2015 056637 23 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution

9.5.1 Timer unit implementation

9.5.1.1 Timer unit block diagram

Figure 8 shows the block diagram of the timer module. The timer unit is designed, so that events when combined with enabling flags start or stop the counter. For example, setting bit TStartTxBegin = logic 1 enables control of received data with the timer unit. In addition, the first received bit is indicated by the TxBegin event. This combination starts the counter at the defined TReloadValue[7:0]. The timer stops automatically when the counter value is equal to zero or if a defined stop event happens.

9.5.1.2 Controlling the timer unit

The main part of the timer unit is a down-counter. As long as the down-counter value is not zero, it decrements its value with each timer clock cycle. If the TAutoRestart flag is enabled, the timer does not decrement down to zero. On reaching value 1, the timer reloads the next clock function with the TReloadValue[7:0]. Fig 8. Timer module block diagram 001aak611 TxEnd Event TAutoRestart TRunning TStartTxEnd TStartNow S R Q START COUNTER/ PARALLEL LOAD STOP COUNTER TPreScaler[4:0] TimerValue[7:0] Counter = 0 ? to interrupt logic: TimerIRq PARALLEL OUT PARALLEL IN TReloadValue[7:0] CLOCK DIVIDER COUNTER MODULE (x ≤ x − 1) TStopNow TxBegin Event TStartTxBegin TStopRxEnd RxEnd Event TStopRxBegin

13.56 MHz

Q

Rev. 3.7 — 30 June 2015 056637 24 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution The timer is started immediately by loading a value from the TimerReload register into the counter module. This is activated by one of the following events:

  • transmission of the first bit to the card (TxBegin event) with bit TStartTxBegin = logic 1
  • transmission of the last bit to the card (TxEnd event) with bit TStartTxEnd = logic 1
  • bit TStartNow is set to logic 1 by the microprocessor Remark: Every start event reloads the timer from the TimerReload register. Thus, the timer unit is re-triggered. The timer can be configured to stop on one of the following events:
  • receipt of the first valid bit from the card (RxBegin event) with bit TStopRxBegin = logic 1
  • receipt of the last bit from the card (RxEnd event) with bit TStopRxEnd = logic 1
  • the counter module has decremented down to zero and bit TAutoRestart = logic 0
  • bit TStopNow is set to logic 1 by the microprocessor. Loading a new value, e.g. zero, into the TimerReload register or changing the timer unit while it is counting will not immediately influence the counter. This is because this register only affects the counter content after a start event. If the counter is stopped when bit TStopNow is set, no TimerIRq is flagged.

9.5.1.3 Timer unit clock and period

The timer unit clock is derived from the 13.56 MHz on-board chip clock using the programmable divider. Clock selection is made using the TimerClock register TPreScaler[4:0] bits based on Equation 3 (3) The values for the TPreScaler[4:0] bits are between 0 and 21 which results in a minimum periodic time (T TimerClock) of between 74 ns and 150 ms. The time period elapsed since the last start event is calculated using Equation 4: (4) This results in a minimum time period (tTimer) of between 74 ns and 40 s.

9.5.1.4 Timer unit status

The SecondaryStatus register’s TRunning bit shows the timer’s status. Configured start events start the timer at the TReloadValue[7:0] and changes the status flag TRunning to logic 1. Conversely, configured stop events stop the timer and set the TRunning status flag to logic 0. As long as status flag TRunning is set to logic 1, the TimerValue register changes on the next timer unit clock cycle. The TimerValue[7:0] bits can be read directly from the TimerValue register. fTimerClock TTimerClock tTimer TReLoadValue TimerValue– fTimerClock

9.5.2 Using the timer unit functions

9.5.2.1 Time-out and WatchDog counters

being received from the card, the timer unit stops without generating an interrupt.

9.5.2.2 Stopwatch

9.5.2.3 Programmable one shot timer and periodic trigger

the timer interrupt. The interrupt occurs after the time specified by tTimer. request after every tTimer cycle.

9.5.3 Timer unit registers

Table 22 shows the related flags of the timer unit in alphabetical order. Table 22. Associated timer unit registers and flags

9.6 Power reduction modes

9.6.1 Hard power-down

defined internally (except pin RSTPD itself). The output pins are frozen at a given value. The status of all pins during a hard power-down is shown in Table 23.

9.6.2 Soft power-down mode

Soft power-down mode is entered immediately using the Control register bit PowerDown. digital output pins do not change their state. PowerDown bit is automatically cleared when the Soft power-down mode is exited. cycles will not be detected by the internal logic until VDDA is stable. Table 23. Signal on pins during Hard power-down

Rev. 3.7 — 30 June 2015 056637 27 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution

9.6.3 Standby mode

The Standby mode is immediately entered when the Control register StandBy bit is set. All internal current sinks, including the internal digital clock buffer are switched off. However, the oscillator buffer is not switched off. The digital input buffers are not separated by the input pads, keeping their functionality and the digital output pins do not change their state. In addition, the oscillator does not need time to wake-up. After resetting the Control register StandBy bit, it takes four clock cycles on pin OSCIN for Standby mode to exit. Resetting bit StandBy does not immediately clear it. It is automatically cleared when the Standby mode is exited.

9.6.4 Automatic receiver power-down

It is a power saving feature to switch off the receiver circuit when it is not needed. Setting bit RxAutoPD = logic 1, automatically powers down the receiver when it is not in use. Setting bit RxAutoPD = logic 0, keeps the receiver continuously powered up.

9.7 StartUp phase

The events executed during the StartUp phase are shown in Figure 9.

9.7.1 Hard power-down phase

The hard power-down phase is active during the following cases:

  • a Power-On Reset (POR) caused by power-up on pins DVDD or AVDD activated when VDDD or VDDA is below the digital reset threshold.
  • a HIGH-level on pin RSTPD which is active while pin RSTPD is HIGH. The HIGH level period on pin RSTPD must be at least 100 s (tPD  100 s). Shorter phases will not necessarily result in the reset phase (treset). The rising or falling edge slew rate on pin RSTPD is not critical because pin RSTPD is a Schmitt trigger input. Remark: In case two, HIGH level on pin RSTPD, has to be at least 100 s long (tPD  100 s). Shorter phases will not necessarily result in the reset phase treset. The slew rate of rising/falling edge on pin RSTPD is not critical because pin RSTPD is a Schmitt trigger input. Fig 9. The StartUp procedure 001aak613 StartUp phase states tRSTPD treset tinit Hard power- down phase Reset phase Initialising phase ready

Rev. 3.7 — 30 June 2015 056637 28 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution

9.7.2 Reset phase

The reset phase automatically follows the Hard power-down. Once the oscillator is running stably, the reset phase takes 512 clock cycles. During the reset phase, some register bits are preset by hardware. The respective reset values are given in the description of each register (see Section 10.5 on page 48). Remark: When the internal oscillator is used, time (tosc) is required for the oscillator to become stable. This is because the internal oscillator is supplied by VDDA and any clock cycles will not be detected by the internal logic until VDDA is stable.

9.7.3 Initialization phase

The initialization phase automatically follows the reset phase and takes 128 clock cycles. During the initializing phase the content of the EEPROM blocks 1 and 2 is copied into the register subaddresses 10h to 2Fh (see Section 9.2.2 on page 13). Remark: During the production test, the MFRC531 is initialized with default configuration values. This reduces the microprocessor’s configuration time to a minimum.

9.7.4 Initializing the parallel interface type

A different initialization sequence is used for each microprocessor. This enables detection of the correct microprocessor interface type and synchronization of the microprocessor’s and the MFRC531’s start-up. See Section 9.1.3 on page 8 for detailed information on the different connections for each microprocessor interface type. During StartUp phase, the command value is set to 3Fh once the oscillator attains clock frequency stability at an amplitude of > 90 % of the nominal 13.56 MHz clock frequency. At the end of the initialization phase, the MFRC531 automatically switches to idle and the command value changes to 00h. To ensure correct detection of the microprocessor interface, the following sequence is executed:

  • the Command register is read until the 6-bit register value is 00h. On reading the 00h value, the internal initialization phase is complete and the MFRC531 is ready to be controlled
  • write 80h to the Page register to initialize the microprocessor interface
  • read the Command register. If it returns a value of 00h, the microprocessor interface was successfully initialized
  • write 00h to the Page registers to activate linear addressing mode.

9.8 Oscillator circuit

best achieved by using the internal oscillator buffer with the recommended circuitry. Remark: We do not recommend using an external clock source.

9.9 Transmitter pins TX1 and TX2

register is used to control the TX1 and TX2 signals.

9.9.1 Configuring pins TX1 and TX2

TX1 pin configurations are described in Table 24. TX2 pin configurations are described in Table 25. Table 24. Pin TX1 configurations

0 X X LOW (GND)

9.9.2 Antenna operating distance versus power consumption

9.9.3 Antenna driver output source resistance

100  using the CwConductance register GsCfgCW[5:0] bits. adjusted between 1  and 100  using the ModConductance register GsCfgMod[5:0] bits. in Section 13.3.3 on page 92. Table 25. Pin TX2 configurations

9.9.3.1 Source resistance table

Table 26. TX1 and TX2 source resistance of n-chan nel driver transistor against GsCfgCW or GsCfgMod MANT = Mantissa; EXP = Exponent.

Rev. 3.7 — 30 June 2015 056637 32 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution

9.9.3.2 Calculating the relative source resistance

The reference source resistance RS(ref) can be calculated using Equation 6. (6) The reference source resistance (RS(ref)) during the modulation phase can be calculated using ModConductance register’s GsCfgMod[5:0].

9.9.3.3 Calculating the effective source resistance

Wiring resistance (RS(wire)): Wiring and bonding add a constant offset to the driver resistance that is relevant when pins TX1 and TX2 are switched to low-impedance. The additional resistance for pin TX1 (RS(wire)TX1) can be set approximately as shown in Equation 7. (7) Effective resistance (RSx): The source resistances of the driver transistors (RsMaxP byte) read from the Product Information Field (see Section 9.2.1 on page 13) are measured during the production test with CwConductance register’s GsCfgCW[5:0] = 01h. To calculate the driver resistance for a specific value set in GsCfgMod[5:0], use Equation 8. (8)

9.9.4 Pulse width

The envelope carries the data signal information that is transmitted to the card. It is an encoded data signal based on the Miller code. In addition, each pause of the Miller encoded signal is again encoded as a pulse of a fixed width. The width of the pulse is adjusted using the ModWidth register. The pulse width (tw) is calculated using Equation 9 where the frequency constant (fclk) = 13.56 MHz. (9)

9.10 Receiver circuitry

The MFRC531 uses an integrated quadrature demodulation circuit enabling it to detect an ISO/IEC 14443 A or ISO/IEC 14443 B compliant subcarrier signal on pin RX.

  • ISO/IEC 14443 A subcarrier signal: defined as a Manchester coded ASK modulated signal
  • ISO/IEC 14443 B subcarrier signal: defined as an NRZ-L coded BPSK modulated ISO/IEC 14443 B subcarrier signal RSr e f MANT GsCfgCW EXP GsCfgCW RSw i r e TX1 500 m  RSx RSr e f maxP RSw i r e TX1– RSr e l RSw i r e TX1+= tw 2ModWidth 1+ fc

Rev. 3.7 — 30 June 2015 056637 33 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution The quadrature demodulator uses two different clocks (Q-clock and I-clock) with a phase-shift of 90 between them. Both resulting subcarrier signals are amplified, filtered and forwarded to the correlation circuitry. The correlation results are evaluated, digitized and then passed to the digital circuitry. Various adjustments can be made to obtain optimum performance for all processing units.

9.10.1 Receiver circuit block diagram

Figure 11 shows the block diagram of the receiver circuit. The receiving process can be broken down in to several steps. Quadrature demodulation of the 13.56 MHz carrier signal is performed. To achieve the optimum performance, automatic Q-clock calibration is recommended (see Section 9.10.2.1 on page 33). The demodulated signal is amplified by an adjustable amplifier. A correlation circuit calculates the degree of similarity between the expected and the received signal. The BitPhase register enables correlation interval position alignment with the received signal’s bit grid. In the evaluation and digitizer circuitry, the valid bits are detected and the digital results are sent to the FIFO buffer. Several tuning steps are possible for this circuit. The signal can be observed on its way through the receiver as shown in Figure 11. One signal at a time can be routed to pin AUX using the TestAnaSelect register as described in Section 15.2.2 on page 103.

9.10.2 Receiver operation

In general, the default settings programmed in the StartUp initialization file are suitable for device to MIFARE card data communication. However, in some environments specific user settings will achieve better performance.

9.10.2.1 Automatic Q-clock calibration

The quadrature demodulation concept of the receiver generates a phase signal (I-clock) and a 90 phase-shifted quadrature signal (Q-clock). To achieve the optimum demodulator performance, the Q-clock and the I-clock must be phase-shifted by 90. After the reset phase, a calibration procedure is automatically performed. Fig 11. Receiver circuit block diagram 001aak615 ClkQDelay[4:0] ClkQCalib ClkQ180Deg BitPhase[7:0] CORRELATION CIRCUITRY EVALUATION AND DIGITIZER CIRCUITRY MinLevel[3:0] CollLevel[3:0] RxWait[7:0] RcvClkSell s_valid s_data s_coll s_clock Gain[1:0] to TestAnaOutSel clock I TO Q CONVERSION I-clock Q-clock

software when bit ClkQCalib has a logic 0 to logic 1 transition. phase-shift between the Q-clock and the I-clock is greater than 180.

  • The StartUp configuration file enables automatic Q-clock calibration after a reset
  • If bit ClkQCalib = logic 1, automatic calibration is not performed. Leaving this bit set to logic 1 can be used to permanently disable automatic calibration.
  • It is possible to write data to the ClkQDelay[4:0] bits using the microprocessor. The aim could be to disable automatic calibration and set the delay using the software. Configuring the delay value using the software requires bit ClkQCalib to have been previously set to logic 1 and a time interval of at least 4.8 s has elapsed. Each delay value must be written with bit ClkQCalib set to logic 1. If bit ClkQCalib is logic 0, the configured delay value is overwritten by the next automatic calibration interval.

9.10.2.2 Amplifier

Table 27. Gain factors for the internal amplifier See Table 83 “RxControl1 register bit descriptions” on page 61 for additional information.

Rev. 3.7 — 30 June 2015 056637 35 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution

9.10.2.3 Correlation circuitry

The correlation circuitry calculates the degree of matching between the received and an expected signal. The output is a measure of the amplitude of the expected signal in the received signal. This is done for both, the Q and I-channels. The correlator provides two outputs for each of the two input channels, resulting in a total of four output signals. The correlation circuitry needs the phase information for the incoming card signal for optimum performance. This information is defined for the microprocessor using the BitPhase register. This value defines the phase relationship between the transmitter and receiver clock in multiples of the BitPhase time (tBitPhase)=1/1 3 . 5 6M H z .

9.10.2.4 Evaluation a nd digitizer circuitry

The correlation results are evaluated for each bit-half of the Manchester coded signal. The evaluation and digitizer circuit decides from the signal strengths of both bit-halves, if the current bit is valid

  • If the bit is valid, its value is identified
  • If the bit is not valid, it is checked to identify if it contains a bit-collision Select the following levels for optimal using RxThreshold register bits:
  • MinLevel[3:0]: defines the minimum signal strength of the stronger bit-halve’s signal which is considered valid.
  • CollLevel[3:0]: defines the minimum signal strength relative to the amplitude of the stronger half-bit that has to be exceeded by the weaker half-bit of the Manchester coded signal to generate a bit-collision. If the signal’s strength is below this value, logic 1 and logic 0 can be determined unequivocally. After data transmission, the card is not allowed to send its response before a preset time period which is called the frame guard time in the ISO/IEC 14443 standard. The length of this time period is set using the RxWait register’s RxWait[7:0] bits. The RxWait register defines when the receiver is switched on after data transmission to the card in multiples of one bit duration. If bit RcvClkSelI is set to logic 1, the I-clock is used to clock the correlator and evaluation circuits. If bit RcvClkSelI is set to logic 0, the Q-clock is used. Remark: It is recommended to use the Q-clock.

9.11 Serial signal switch

The MFRC531 comprises two main blocks:

  • digital circuitry: comprising the state machines, encoder and decoder logic etc.
  • analog circuitry: comprising the modulator, antenna drivers, receiver and amplification circuitry The interface between these two blocks can be configured so that the interface signals are routed to pins MFIN and MFOUT. This makes it possible to connect the analog part of one MFRC531 to the digital part of another device. The serial signal switch can be used to measure MIFARE and ISO/IEC 14443 A.

Rev. 3.7 — 30 June 2015 056637 36 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution Remark: Pin MFIN can only be accessed at 106 kBd based on ISO/IEC 14443 A. The Manchester signal and the Manchester signal with subcarrier can only be accessed on pin MFOUT at 106 kBd based on ISO/IEC 14443 A.

9.11.1 Serial signal switch block diagram

Figure 13 shows the serial signal switches. Three different switches are implemented in the serial signal switch enabling the MFRC531 to be used in different configurations. The serial signal switch can also be used to check the transmitted and received data during the design-in phase or for test purposes. Section 15.2.1 on page 101 describes the analog test signals and measurements at the serial signal switch. Remark: The SLR400 uses pin name SIGOUT for pin MFOUT. The MFRC531 functionality includes the test modes for the SLRC400 using pin MFOUT. settings used to configure and control the serial signal switch.

9.11.2 Serial signal switch registers

The RxControl2 register DecoderSource[1:0] bits define the input signal for the internal Manchester decoder and are described in Table 28. Fig 13. Serial signal switch block diagram 001aak617MFIN MFOUT MODULATOR DRIVER (part of) analog circuitry SUBCARRIER DEMODULATOR TX1 TX2 RXCARRIER DEMODULATOR MILLER CODER

1 OUT OF 256

1 OUT OF 4

(part of) serial data processing Decoder Source[1:0] Modulator Source[1:0] SUBCARRIER DEMODULATOR serial data out 1 internal

2 Manchester with subcarrier

Manchester with subcarrier Manchester reserved reserved MFOUTSelect[2:0] digital test signal signal to MFOUT

transmitted 13.56 MHz energy carrier. The modulated signal drives pins TX1 and TX2.

9.11.2.1 Active antenna concept

The MFRC531 analog and digital circuitry is accessed using pins MFIN and MFOUT. Table 31 lists the required settings. Table 28. DecoderSource[1:0] values See Table 93 on page 64 for additional information. Table 29. ModulatorSource[1:0] values Table 30. MFOUTSelect[2:0] values

[1] The number column refers to the value in the number column of Table 28, Table 29 and Table 30. other using pins MFOUT and MFIN.

9.11.2.2 Driving both RF parts

configuration, two RF parts can be driven, one after another, by one microprocessor.

9.12 MIFARE higher baud rates

Proximity Coupling Devices (PCD). combination with a microcontroller IC such as the MIFARE ProX. of the MIFARE higher baud rates communication concept in current applications. Table 31. Register settings to enable use of the analog circuitry Table 32. MIFARE higher baud rates

9.13 ISO/IEC 14443 B communication scheme

Table 33. ISO/IEC 14443 B registers and flags

Rev. 3.7 — 30 June 2015 056637 40 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution

9.14 MIFARE authentication and Crypto1

The security algorithm used in the MIFARE products is called Crypto1. It is based on a proprietary stream cipher with a 48-bit key length. To access data on MIFARE cards, knowledge of the key format is needed. The correct key must be available in the MFRC531 to enable successful card authentication and access to the card’s data stored in the EEPROM. After a card is selected as defined in ISO/IEC 14443 A standard, the user can continue with the MIFARE protocol. It is mandatory that card authentication is performed. Crypto1 authentication is a 3-pass authentication which is automatically performed when the Authent1 and Authent2 commands are executed (see Section 11.6.3 on page 89 and Section 11.6.4 on page 89). During the card authentication procedure, the security algorithm is initialized. After a successful authentication, communication with the MIFARE card is encrypted.

9.14.1 Crypto1 key handling

On execution of the authentication command, the MFRC531 reads the key from the key buffer. The key is always read from the key buffer and ensures Crypto1 authentication commands do not require addressing of a key. The user must ensure the correct key is prepared in the key buffer before triggering card authentication. The key buffer can be loaded from:

  • the EEPROM using the LoadKeyE2 command (see Section 11.6.1 on page 88)
  • the microprocessor’s FIFO buffer using the LoadKey command (see Section 11.6.2 on page 88). This is shown in Figure 14. Fig 14. Crypto1 key handling block diagram 001aak624 FIFO BUFFER from the microcontroller WriteE2 LoadKey EEPROM KEYS KEY BUFFER LoadKeyE2 during Authent1 CRYPTO1 MODULE serial data stream outserial data stream in (plain) (encrypted)

9.14.2 Authentication procedure

  1. Load the internal key buffer by using the LoadKeyE2 (see Section 11.6.1 on page 88)

or the LoadKey (see Section 11.6.2 on page 88) commands.

  1. Start the Authent1 command (see Section 11.6.3 on page 89). When finished, check

the error flags to obtain the command execution status.

  1. Start the Authent2 command (see Section 11.6.4 on page 89). When finished, check

the error flags and bit Crypto1On to obtain the command execution status.

10.1 Register addressing modes

  • initiating functions and controlling data by executing commands
  • configuring the functional operation using a set of configuration bits
  • monitoring the state of the MFRC531 by reading status flags The commands, configuration bits and flags are accessed using the microprocessor interface. The MFRC531 can internally address 64 registers using six address lines.

10.1.1 Page registers

Page register can always be addressed, irrespective of which page is currently selected.

10.1.2 Dedicated address bus

shows how the register address is assembled.

10.1.3 Multiplexed address bus

Table 35 shows how the register address is assembled. Table 34. Dedicated address bus: assembling the register address

1 PageSelect2 PageSelect1 PageSelect0 A2 A1 A0

10.2 Register bit behavior

the function of the Access column in the register tables. Table 35. Multiplexed address bus: assembling the register address Table 36. Behavior and designation of register bits R/W read and write These bits can be read and written by the microprocessor. influenced by internal state machines. machines but never changed by them. D dynamic These bits can be read a nd written by the microprocessor. automatically after the execution of the command. registers returns an undefined value.

10.3 Register overview

Table 37. MFRC531 register overview

18 Page selects the page register Table 39 on page 48

19 RxControl1 controls receiver behavior Table 82 on page 61

Table 37. MFRC531 register overview …continued

10.4 MFRC531 register flags overview

Table 38. MFRC531 register flags overview

Table 38. MFRC531 register flags overview …continued

10.5 Register descriptions

10.5.1 Page 0: Command and status

10.5.1.1 Page register

10.5.1.2 Command register

Starts and stops the command execution. Table 39. Page register (address: 00h, 08h, 10h, 18h, 20h, 28h, 30h, 38h) Table 40. Page register bit descriptions

7 UsePageSelect 1 the value of PageSelect[2: 0] is used as the register address

Table 41. Command register (address: 01h) r eset value: x000 0000b, x0h bit allocation Table 42. Command register bit descriptions

7 IFDetectBusy - shows the status of interface detection logic

5 to 0 Command[5:0] - activates a command based on the Command code.

10.5.1.3 FIFOData register

Input and output of the 64 byte FIFO buffer.

10.5.1.4 PrimaryStatus register

Bits relating to receiver, transmitter and FIFO buffer status flags. Table 43. FIFOData register (address: 02h) reset value: xxxx xxxxb, 05h bit allocation Table 44. FIFOData register bit descriptions buffer acts as a parallel in to parallel out converter for all data streams. Table 45. PrimaryStatus register (address: 03 h) reset value: 0000 0101b, 05h bit allocation Table 46. PrimaryStatus register bit descriptions

000 Idle neither the transmitter or receiver are operating;

001 TxSOF transmit start of frame pattern

010 TxData transmit data from the FIFO buffer (or

011 TxEOF transmit End Of Frame (EOF) pattern

100 GoToRx1 intermediate state 1; receiver starts

101 PrepareRx waiting until the Rx Wait register time period

110 AwaitingRx receiver activated; waiting for an input signal on

111 Receiving receiving data

3 IRq - shows any interrupt source requesting attention

10.5.1.5 FIFOLength register

Number of bytes in the FIFO buffer.

2 Err 1 any error flag in the ErrorFlag register is set

1 HiAlert 1 the alert level for the number of bytes in the FIFO

0 LoAlert 1 the alert level for number of bytes in the FIFO

Table 47. FIFOLength register (address: 04h) reset value: 0000 0000b, 00h bit allocation Table 48. FIFOLength bit descriptions

10.5.1.6 SecondaryStatus register

Various secondary status flags.

10.5.1.7 InterruptEn register

Control bits to enable and disable passing of interrupt requests. [1] This bit can only be set or cleared using bit SetIEn. Table 49. SecondaryStatus register (address: 05h) reset value: 01100 000b, 60h bit Table 50. SecondaryStatus register bit descriptions

7 TRunning 1 the timer unit is running and the counter decrements the

6 E2Ready 1 EEPROM programming is finished

0 EEPROM programming is ongoing

5 CRCReady 1 CRC calculation is finished

0 CRC calculation is ongoing

Table 51. InterruptEn register (address: 06h) reset value: 0000 0000b, 00h bit allocation Table 52. InterruptEn register bit descriptions

7 SetIEn 1 indicates that the marked bits in the InterruptEn register are set

5 TimerIEn - sends the TimerIRq timer interrupt request to pin IRQ

4 TxIEn - sends the TxIRq transmitter interrupt request to pin IRQ [1]

3 RxIEn - sends the RxIRq receiver interrupt request to pin IRQ [1]

2 IdleIEn - sends the IdleIRq idle interrupt request to pin IRQ [1]

1 HiAlertIEn - sends the HiAlertIRq high alert interrupt request to pin IRQ [1]

0 LoAlertIEn - sends the LoAlertIRq low alert interrupt request to pin IRQ[1]

10.5.1.8 InterruptRq register

[1] PrimaryStatus register Bit HiAlertIRq stores this event and it can only be reset using bit SetIRq. Table 53. InterruptRq register (address: 07h) reset value: 0000 0000b, 00h bit allocation Table 54. InterruptRq register bit descriptions

7 SetIRq 1 sets the marked bits in the InterruptRq register

5 TimerIRq 1 timer decrements the TimerValue register to zero

4 TxIRq 1 TxIRq is set to logic 1 if one of the following events occurs:

3 RxIRq 1 the receiver terminates

register changes its value from any command to the Idle command. If an unknown command is started the IdleIRq bit is set.

0 IdleIRq = logic 0 in all other instances

1 HiAlertIRq 1 PrimaryStatus register HiAlert bit is set

0 PrimaryStatus register HiAlert bit is not set

0 LoAlertIRq 1 PrimaryStatus re gister LoAlert bit is set[1]

0 PrimaryStatus register LoAlert bit is not set

10.5.2 Page 1: Control and status

10.5.2.1 Page register

Selects the page register; see Section 10.5.1.1 “Page register” on page 48.

10.5.2.2 Control register

Various control flags, for timer, power saving, etc.

10.5.2.3 ErrorF lag register

Error flags show the error status of the last executed command. Table 55. Control register (address: 09h) reset value: 0000 0000b, 00h bit allocation Table 56. Control register bit descriptions

3 Crypto1On 1 Crypto1 unit is switched on and all data communication with

0 FlushFIFO 1 immediately clears the internal FIFO buffer’s read and write

Table 57. ErrorFlag register (address: 0Ah) reset value: 0100 0000b, 40h bit allocation Table 58. ErrorFlag register bit descriptions

6 KeyErr 1 set when the LoadKeyE2 or Loa dKey command recognize that the

[1] Only valid for communication using ISO/IEC 14443 A.

10.5.2.4 CollPos register

Bit position of the first bit-collision detected on the RF interface. ISO/IEC 14443 B protocol standard.

5 AccessErr 1 set when the access rights to the EEPROM are violated

4 FIFOOvfl 1 set when the microprocessor or MFRC531 internal state machine

3 CRCErr 1 set when RxCRCEn is set and the CRC fails

2 FramingErr 1 set when the SOF is incorrect

1 ParityErr 1 set when the parity check fails

0 CollErr 1 set when a bit-collision is detected [1]

Table 58. ErrorFlag register bit descriptions …continued Table 59. CollPos register (address: 0Bh) reset value: 0000 0000b, 00h bit allocation Table 60. CollPos register bit descriptions

10.5.2.5 TimerValue register

10.5.2.6 CRCResultLSB register

LSB of the CRC coprocessor register.

10.5.2.7 CRCResultMSB register

MSB of the CRC coprocessor register. Table 61. TimerValue register (address: 0Ch) reset value: xxxx xxxxb, xxh bit allocation Table 62. TimerValue register bit descriptions Table 63. CRCResultLSB register (address: 0Dh) reset value: xxxx xxxxb, xxh bit Table 64. CRCResultLSB regi ster bit descriptions Table 65. CRCResultMSB register (address: 0Eh) reset value: xxxx xxxxb, xxh bit Table 66. CRCResultMSB register bit descriptions The register’s value is undefined for 8-bit CRC calculation.

10.5.2.8 BitFraming register

Adjustments for bit oriented frames. Table 67. BitFraming register (address: 0Fh) reset value: 0000 0000b, 00h bit allocation Table 68. BitFraming register bit descriptions

10.5.3 Page 2: Transmitter and control

10.5.3.1 Page register

Selects the page register; see Section 10.5.1.1 “Page register” on page 48.

10.5.3.2 TxControl register

Controls the logical behavior of the antenna pin TX1 and TX2. Table 69. TxControl register (address: 11h) reset value: 0101 1000b, 58h bit allocation Table 70. TxControl register bit descriptions

4 Force100ASK - forces a 100 % ASK modulation independent

0 TX2 is driven at a constant output level

0 TX1 is driven at a constant output level

10.5.3.3 CwConductance register

Selects the conductance of the antenna driver pins TX1 and TX2. See Section 9.9.3 on page 30 for detailed information about GsCfgCW[5:0].

10.5.3.4 ModConductance register

Defines the driver output conductance. Remark: When Force100ASK = logic 1, the GsCfgMod[5:0] value has no effect. See Section 9.9.3 on page 30 for detailed information about GsCfgMod[5:0]. Table 71. CwConductance register (address: 12h) reset value: 0011 1111b, 3Fh bit Table 72. CwConductance register bit descriptions Table 73. ModConductance register (address: 13h) reset value: 0011 1111b, 3Fh bit Table 74. ModConductance register bit descriptions

10.5.3.5 CoderControl register

Sets the clock rate and the coding mode.

10.5.3.6 ModWidth register

Selects the pulse modulation width.

10.5.3.7 PreSet16 register

Remark: These values must not be changed. Table 75. CoderControl register (address: 14h) reset value: 0001 1001b, 19h bit allocation Table 76. CoderControl register bit descriptions

000 MIFARE 848 kBd

001 MIFARE 424 kBd

010 MIFARE 212 kBd

011 MIFARE 106 kBd; ISO/IEC 14443 A

100 ISO/IEC 14443 B

000 NRZ according to ISO/IEC 14443 B

001 MIFARE, ISO/IEC 14443 A, (Miller coded)

Table 77. ModWidth register (address: 15h) reset value: 0001 0011b, 13h bit allocation Table 78. ModWidth register bit descriptions Table 79. PreSet16 register (address: 16h) reset value: 0000 0000b, 00h bit allocation

10.5.3.8 TypeBFraming

Defines the framing for ISO/IEC 14443 B communication. Table 80. TypeBFraming register (address: 17h) reset value: 0011 1011b, 3Bh bit allocation Table 81. TypeBFraming register bit descriptions

7 NoTxSOF 1 TxCoder suppresses the SOF

0 TxCoder does not suppress SOF

6 NoTxEOF 1 TxCoder suppresses the EOF

0 TxCoder does not suppress the EOF

5 EOFWidth 1 set the EOF to a length to 11 ETU

10.5.4 Page 3: Receiver and decoder control

10.5.4.1 Page register

Selects the page register; see Section 10.5.1.1 “Page register” on page 48.

10.5.4.2 RxControl1 register

Controls receiver operation. Table 82. RxControl1 register (address: 19h) reset value: 0111 0011b, 73h bit allocation Table 83. RxControl1 register bit descriptions

10 ISO/IEC 14443 A and ISO/IEC 14443 B

2 LPOff switches off a low-pass filter at the internal amplifier

10.5.4.3 DecoderControl register

10.5.4.4 BitPhase register

Selects the bit-phase between transmitter and receiver clock. Table 84. DecoderControl register (addre ss: 1Ah) reset value: 0000 1000b, 08h bit Table 85. DecoderControl register bit descriptions

6 RxMultiple 0 after receiving one fram e, the receiver is deactivated

0 RxCoding 0 Manchester encoding

1 BPSK encoding

Table 86. BitPhase register (address: 1Bh) reset value: 1010 1101b, ADh bit allocation Table 87. BitPhase register bit descriptions

10.5.4.5 RxThreshold register

Selects thresholds for the bit decoder.

10.5.4.6 BPSKDemControl

Table 88. RxThreshold register (address: 1Ch) reset value: 1111 1111b, FFh bit allocation Table 89. RxThreshold register bit descriptions strength is below this level, it is not evaluated. Table 90. BPSKDemControl register (address: 1Dh) reset value: 0001 1110b, 1Eh bit Table 91. BPSKDemControl register bit descriptions

7 NoRxSOF 1 a missing SOF in the received data stream is ignored and no

6 NoRxEGT 1 an EGT which is too short or too long in the received data stream

5 NoRxEOF 1 a missing EOF in the received data stream is ignored and no

4 FilterAmpDet - switches on a high-pass filter for am plitude detection

10.5.4.7 RxControl2 register

Controls decoder behavior and defines the input source for the receiver. [1] I-clock and Q-clock are 90  phase-shifted from each other.

10.5.4.8 ClockQControl register

Controls clock generation for the 90 phase-shifted Q-clock. Table 92. RxControl2 register (address: 1Eh) reset value: 0100 0001b, 41h bit allocation Table 93. RxControl2 register bit descriptions

7 RcvClkSelI 1 I-clock is used as the receiver clock [1]

0 Q-clock is used as the receiver clock [1]

6 RxAutoPD 1 receiver circuit is automatically switched on before

00 LOW

Table 94. ClockQControl register (address: 1F h) reset value: 000x xxxxb, xxh bit allocation Table 95. ClockQControl register bit descriptions

7 ClkQ180Deg 1 Q-clock is phase-shifted more than 180  compared to the

0 Q-clock is phase-sh ifted less than 180 compared to the

6 ClkQCalib 0 Q-clock is automatically calibrated after the reset phase and

by the automatic calibration cycle.

10.5.5 Page 4: RF Timing and channel redundancy

10.5.5.1 Page register

Selects the page register; see Section 10.5.1.1 “Page register” on page 48.

10.5.5.2 RxWait register

Selects the time interval after transmission, before the receiver starts.

10.5.5.3 ChannelRedundancy register

Selects kind and mode of checking the data integrity on the RF channel. Table 96. RxWait register (address: 21h) reset value: 0000 0101b, 06h bit allocation Table 97. RxWait register bit descriptions signal on pin RX is ignored. Table 98. ChannelRedundancy register (addre ss: 22h) reset value: 0000 0011b, 03h bit Table 99. ChannelRedundancy bit descriptions

5 CRC3309 1 CRC calculation is performed using ISO/IEC 3309

0 CRC calculation is performed using ISO/IEC 14443 A

4 CRC8 1 an 8-bit CRC is calculated

the CRC bytes are incorrect, the CRCErr flag is set.

2 TxCRCEn 1 a CRC is calculated over the transmitted data and the CRC bytes

[1] When used with ISO/IEC 14443 A, this bit must be set to logic 1.

10.5.5.4 CRCPresetLSB register

LSB of the preset value for the CRC register.

10.5.5.5 CRCPresetMSB register

MSB of the preset value for the CRC register.

10.5.5.6 PreSet25 register

Remark: These values must not be changed.

1 ParityOdd 1 odd parity is generated or expected [1]

0 ParityEn 1 a parity bit is inserted in the transmitted data stream after each byte

Table 99. ChannelRedundancy bit descriptions …continued Table 100. CRCPresetLSB register (address: 23h) reset value: 0101 0011b, 63h bit allocation Table 101. CRCPresetLSB register bit descriptions the CalcCRC command (if CRC calculation is enabled). Table 102. CRCPresetMSB register (address: 24h) reset value: 0101 0011b, 63h bit Table 103. CRCPresetMSB bit descriptions Remark: This register is not relevant if CRC8 is set to logic 1. Table 104. PreSet25 register (address: 25h) reset value: 0000 0000b, 00h bit allocation

10.5.5.7 MFOUTSelect register

Selects the internal signal applied to pin MFOUT. [1] Only valid for MIFARE and ISO/IEC 14443 A communication at 106 kBd.

10.5.5.8 PreSet27 register

Table 105. MFOUTSelect register (address: 26 h) reset value: 0000 0000b, 00h bit allocation Table 106. MFOUTSelect register bit descriptions Table 107. PreSet27 (address: 27h) reset value: xxxx xxxxb, xxh bit allocation

10.5.6 Page 5: FIFO, timer and IRQ pin configuration

10.5.6.1 Page register

Selects the page register; see Section 10.5.1.1 “Page register” on page 48.

10.5.6.2 FIFOLevel register

Defines the levels for FIFO underflow and overflow warning.

10.5.6.3 TimerClock register

Selects the divider for the timer clock. Table 108. FIFOLevel register (address: 29h) r eset value: 0000 1000b, 08h bit allocation Table 109. FIFOLevel register bit descriptions or less than the WaterLevel[5:0] bits in the FIFO buffer. Table 110. TimerClock register (address: 2Ah) reset value: 0000 0111b, 07h bit allocation Table 111. TimerClock register bit descriptions

5 TAutoRestart 1 the timer automatically restarts its countdown from the

10.5.6.4 TimerControl register

Selects start and stop conditions for the timer.

10.5.6.5 TimerReload register

Defines the preset value for the timer. Table 112. TimerControl register (address: 2Bh) reset value: 0000 0110b, 06h bit allocation Table 113. TimerControl register bit descriptions

3 TStopRxEnd 1 the timer automatically stops when data reception ends

2 TStopRxBegin 1 the timer autom atically stops when the first valid bit is received

TReloadValue[7:0] into the timer. TReloadValue[7:0] into the timer. Table 114. TimerReload register (address: 2Ch) reset value: 0000 1010b, 0Ah bit allocation Table 115. TimerReload register bit descriptions 7 to 0 TReloadValue[7:0] on a start event, th e timer loads the TReloadValue[7:0] value. TReloadValue[7:0] is set to logic 0 the timer cannot start.

10.5.6.6 IRQPinConfig register

Configures the output stage for pin IRQ.

10.5.6.7 PreSet2E register

10.5.6.8 PreSet2F register

10.5.7 Page 6: reserved

10.5.7.1 Page register

Selects the page register; see Section 10.5.1.1 “Page register” on page 48.

10.5.7.2 Reserved registers 31h, 32h, 33h, 34h, 35h, 36h and 37h

Remark: These registers are reserved for future use. Table 116. IRQPinConfig register (address: 2Dh) reset value: 0000 0010b, 02h bit allocation Table 117. IRQPinConfig register bit descriptions

1 IRQInv 1 inverts the signal on pin IRQ with respect to bit IRq

0 IRQPushPull 1 pin IRQ functions as a standard CMOS output pad

Table 118. PreSet2E register (address: 2Eh) reset value: xxxx xxxxb, xxh bit allocation Table 119. PreSet2F register (address: 2Fh) reset value: xxxx xxxxb, xxh bit allocation Table 120. Reserved registers (address: 31h, 32h, 33h, 34h, 35h, 36h, 37h)

10.5.8 Page 7: Test control

10.5.8.1 Page register

Selects the page register; see Section 10.5.1.1 “Page register” on page 48.

10.5.8.2 Reserved register 39h

Remark: This register is reserved for future use.

10.5.8.3 TestAnaSelect register

Selects analog test signals. Table 121. Reserved register (address: 39h) reset value: xxxx xxxxb, xxh bit allocation Table 122. TestAnaSelect register (address: 3Ah) reset value: 0000 0000b, 00h bit allocation Table 123. TestAnaSelect bit descriptions

1 Vbandgap

2 VRxFollI

3 VRxFollQ

6 VCorrNI

7 VCorrNQ

8 VCorrDI

9 VCorrDQ

10.5.8.4 Reserved register 3Bh

Remark: This register is reserved for future use.

10.5.8.5 Reserved register 3Ch

Remark: This register is reserved for future use.

10.5.8.6 TestDigiSelect register

Table 124. Reserved register (address: 3Bh) reset value: xxxx xxxxb, xxh bit allocation Table 125. Reserved register (address: 3Ch) reset value: xxxx xxxxb, xxh bit allocation Table 126. TestDigiSelect register (address: 3Dh) reset value: xxxx xxxxb, xxh bit allocation Table 127. TestDigiSelect register bit descriptions

7 SignalToMFOUT 1 overrules the MFOUTS elect[2:0] setting and routes the

0 MFOUTSelect[2:0] defines the signal on pin MFOUT

6 to 0 TestDigiSignalSel[6:0] - selects the digita l test signal to be routed to pin MFOUT.

10.5.8.7 Reserved registers 3Eh, 3Fh

Remark: This register is reserved for future use. exchanged using the FIFO buffer.

  • Each command needing a data stream (or data byte stream) as an input immediately processes the data in the FIFO buffer
  • Each command that requires arguments only starts processing when it has received the correct number of arguments from the FIFO buffer
  • The FIFO buffer is not automatically cleared at the start of a command. It is, therefore, possible to write command arguments and/or the data bytes into the FIFO buffer before starting a command.
  • Each command (except the StartUp command) can be interrupted by the microprocessor writing a new command code to the Command register e.g. the Idle command.

11.1 MFRC531 command overview

Table 128. Reserved register (address: 3Eh, 3Fh) reset value: xxxx xxxxb, xxh bit allocation Table 129. MFRC531 commands overview Idle 00h no action; cancels exec ution of the current command.

[1] This command is the combination of the Transmit and Receive commands. [2] Relates to MIFARE Mini/MIFARE 1K/MIFARE 4K security. in the RxWait register has elapsed before starting. See Section 11.2.3 on page 82. EEPROM. See Section 11.3.1 on page 84. See Section 11.6.1 on page 88. [2]. See Section 11.6.2 on page 88. [2]. See Section 11.6.3 on page 89. MFRC531 registers. See Section 11.4.1 on page 86. Table 129. MFRC531 commands overview …continued

11.1.1 Basic states

11.1.2 StartUp command 3Fh

Remark: This command can only be activated by a Power-On or Hard reset.

  • Power-On Reset (POR) caused by power-up on pin DVDD
  • POR caused by power-up on pin AVDD
  • Negative edge on pin RSTPD The reset phase comprises an asynchronous reset and configuration of certain register bits. The initialization phase configures several registers with values stored in the EEPROM. When the StartUp command finishes, the Idle command is automatically executed. Remark:
  • The microprocessor must not write to the MFRC531 while it is still executing the StartUp command. To avoid this, the microprocessor polls for the Idle command to determine when the initialization phase has finished; see Section 9.7.4 on page 28.
  • When the StartUp command is active, it is only possible to read from the Page 0 register.
  • The StartUp command cannot be interrupted by the microprocessor.

11.1.3 Idle command 00h

command. It does not need or return, any data. Table 130. StartUp command 3Fh Table 131. Idle command 00h

11.2 Commands for ISO/IEC 14443 A card communication

set for ISO/IEC 14443 A card communication and related communication protocols.

11.2.1 Transmit command 1Ah

11.2.1.1 Using the Transmit command

  1. All data to be transmitted to the card is written to the FIFO buffer while the Idle

Remark: This is possible for transmission of a data stream up to 64 bytes.

  1. The command code for the Transmit command is stored in the Command register.

the microprocessor must write the subsequent data bytes into the FIFO buffer in time. written to the FIFO buffer in time.

  1. Part of the data transmitted to the card is written to the FIFO buffer while the Idle

the transmitted data stream. written to the FIFO buffer in time. to indicate to the microprocessor transmission is complete. produce output signals that are not in accordance with ISO/IEC 14443 A. Table 132. Transmit command 1Ah

Rev. 3.7 — 30 June 2015 056637 77 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution

11.2.1.2 RF channel redundancy and framing

Each ISO/IEC 14443 A transmitted frame consists of a Start Of Frame (SOF) pattern, followed by the data stream and is closed by an End Of Frame (EOF) pattern. These different phases of the transmission sequence can be monitored using the PrimaryStatus register ModemState[2:0] bit; see Section 11.2.4 on page 82. Depending on the setting of the ChannelRedundancy register bit TxCRCEn, the CRC is calculated and appended to the data stream. The CRC is calculated according to the settings in the ChannelRedundancy register. Parity generation is handled according to the ChannelRedundancy register ParityEn and ParityOdd bits settings.

11.2.1.3 Transmission of bit oriented frames

The transmitter can be configured to send an incomplete last byte. To achieve this the BitFraming register’s TxLastBits[2:0] bits must be set at above zero (for example, 1). This is shown in Figure 15. Figure 15 shows the data stream if bit ParityEn is set in the ChannelRedundancy register. All fully transmitted bytes are followed by a parity check bit but the incomplete byte is not followed by a parity check bit. After transmission, the TxLastBits[2:0] bits are automatically cleared. Remark: If the TxLastBits[2:0] bits are not equal to zero, CRC generation must be disabled. This is done by clearing the ChannelRedundancy register TxCRCEn bit.

11.2.1.4 Transmission of frames with more than 64 bytes

To generate frames of more than 64 bytes, the microprocessor must write data to the FIFO buffer while the Transmit command is active. The state machine checks the FIFO buffer status when it starts transmitting the last bit of the data stream; the check time is marked in Figure 16 with arrows. Fig 15. Transmitting bit oriented frames 001aak618 TxLastBits = 0 TxLastBits = 7 TxLastBits = 1

7 P 0 7 PSOF

Rev. 3.7 — 30 June 2015 056637 78 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution As long as the internal accept further data signal is logic 1, further data can be written to the FIFO buffer. The MFRC531 appends this data to the data stream transmitted using the RF interface. If the internal accept further data signal is logic 0, the transmission terminates. All data written to the FIFO buffer after accept further data signal was set to logic 0 is not transmitted, however, it remains in the FIFO buffer. Remark: If parity generation is enabled (ParityEn = logic 1), the parity bit is the last bit transmitted. This delays the accept further data signal by a duration of one bit. If the TxLastBits[2:0] bits are not zero, the last byte is not transmitted completely. Only the number of bits set by TxLastBits[2:0], starting with the least significant bit are transmitted. This means that the internal state machine has to check the FIFO buffer status at an earlier point in time; see Figure 17 Since in this example TxLastBits[2:0] = 4, transmission stops after bit 3 is transmitted and the frame is completed with an EOF, if configured. Fig 16. Timing for transmitting byte oriented frames Fig 17. Timing for transmi tting bit oriented frames 001aak619 accept further data check FIFO empty TxData FIFO empty FIFOLength[6:0] 01h 00h TxLastBits[2:0] TxLastBits = 0 7 0 770 001aak620 accept further data check FIFO empty TxData FIFO empty FIFOLength[6:0] 01h 00h 01h 00h TxLastBits[2:0] TxLastBits = 4 NWR (FIFO data) 7 0 3 4 7 0 34

verifies FIFO empty for one bit duration before the last expected bit transmission.

11.2.2 Receive command 16h

the microprocessor or automatically during execution of the Transceive command. relationship to the Transmit command.

11.2.2.1 Using the Receive command

circuitry, the minimum value for RxWait[7:0] is 3.

11.2.2.2 RF channel redundancy and framing

bits. Every completed byte is forwarded to the FIFO buffer. Table 133. Transmission of frames of more than 64 bytes Table 134. Receive command 16h

Rev. 3.7 — 30 June 2015 056637 80 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution If an EOF pattern is detected or the signal strength falls below the RxThreshold register MinLevel[3:0] bits setting, both the receiver and the decoder stop. Then the Idle command is entered and an appropriate response for the microprocessor is generated (interrupt request activated, status flags set). When the ChannelRedundancy register bit RxCRCEn is set, a CRC block is expected. The CRC block can be one byte or two bytes depending on the ChannelRedundancy register CRC8 bit setting. Remark: If the CRC block received is correct, it is not sent to the FIFO buffer. This is realized by shifting the incoming data bytes through an internal buffer of either one or two bytes (depending on the defined CRC). The CRC block remains in this internal buffer. Consequently, all data bytes in the FIFO buffer are delayed by one or two bytes. If the CRC fails, all received bytes are sent to the FIFO buffer including the faulty CRC. If ParityEn is set in the ChannelRedundancy register, a parity bit is expected after each byte. If ParityOdd = logic 1, the expected parity is odd, otherwise even parity is expected.

11.2.2.3 Collision detection

If more than one card is within the RF field during the card selection phase, they both respond simultaneously. The MFRC531 supports the algorithm defined in ISO/IEC 14443 A to resolve card serial number data collisions by performing the anti-collision procedure. The basis for this procedure is the ability to detect bit-collisions. Bit-collision detection is supported by the Manchester coding bit encoding scheme used in the MFRC531. If in the first and second half-bit of a subcarrier, modulation is detected, instead of forwarding a 1-bit or 0-bit, a bit-collision is indicated. The MFRC531 uses the RxThreshold register CollLevel[3:0] bits setting to distinguish between a 1-bit or 0-bit and a bit-collision. If the amplitude of the half-bit with smaller amplitude is larger than that defined by the CollLevel[3:0] bits, the MFRC531 flags a bit-collision using the error flag CollErr. If a bit-collision is detected in a parity bit, the ParityErr flag is set. On a detected collision, the receiver continues receiving the incoming data stream. In the case of a bit-collision, the decoder sends logic 1 at the collision position. Remark: As an exception, if bit ZeroAfterColl is set, all bits received after the first bit-collision are forced to zero, regardless whether a bit-collision or an unequivocal state has been detected. This feature makes it easier for the control software to perform the anti-collision procedure as defined in ISO/IEC 14443 A. When the first bit collision in a frame is detected, the bit-collision position is stored in the CollPos register. Table 135 shows the collision positions.

determine when it is next allowed to send data to the card.

11.2.2.4 Receiving bit oriented frames

  • BitFraming register’s RxAlign[2:0] bits select a bit offset for the first incoming byte. For example, if RxAlign[2:0] = 3, the first 5 bits received are forwarded to the FIFO buffer. Further bits are packed into bytes and forwarded. After reception, RxAlign[2:0] is automatically cleared. If RxAlign[2:0] = logic 0, all incoming bits are packed into one byte.
  • RxLastBits[2:0] returns the number of bits valid in the last received byte. For example, if RxLastBits[2:0] evaluates to 5 bits at the end of the received command, the 5 least significant bits are valid. If the last byte is complete, RxLastBits[2:0] evaluates to zero. RxLastBits[2:0] is only valid if a frame error is not indicated by the FramingErr flag. If RxAlign[2:0] is not zero and ParityEn is active, the first parity bit is ignored and not checked.

11.2.2.5 Communi cation errors

Table 135. Return values for bit-collision positions Table 136. Communication error table

11.2.3 Transceive command 1Eh

transmitted is sent using the FIFO buffer and all data received is written to the FIFO buffer. The Transceive command can only be started by the microprocessor. phase-shift between the transmitter and receiver clock.

11.2.4 States of the card communication

ModemState[2:0] in the PrimaryStatus register. Table 137. Transceive command 1Eh Table 138. Meaning of ModemState

000 Idle transmitter and/or receiver are not operating

001 TxSOF transmitting the SOF pattern

010 TxData transmitting data from the FIFO buffer (or redundancy CRC check

011 TxEOF transmitting the EOF pattern

100 GoToRx1 intermediate state passed, when receiver starts

101 PrepareRx waiting until the RxWa it register time period expires

110 AwaitingRx receiver activated; wa iting for an input signal on pin RX

Rev. 3.7 — 30 June 2015 056637 83 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution

11.2.5 Card communication state diagram

Fig 18. Card communication state diagram 001aak621 end of receive frame and RxMultiple = 0 RxMultiple = 1 EOF transmitted and command = Transceive FIFO not empty and command = Transmit or Transceive command = Receive COMMAND = TRANSMIT, RECEIVE OR TRANSCEIVE SET COMMAND REGISTER = IDLE (000) Awaiting Rx (110) RECEIVING (111) GoToRx2 (100) Prepare Rx (101) GoToRx1 (100) TxEOF (011) TxData (010) TxSOF (001) IDLE (000) SOF transmitted next bit clock data transmitted RxWaitC[7:0] = 0 EOF transmitted and command = Transmit signal strength > MinLevel[3:0] frame received

11.3 EEPROM commands

11.3.1 WriteE2 command 01h

11.3.1.1 Programming process

Up to 16 bytes can be programmed into the EEPROM during a single programming cycle. The time needed is approximately 5.8 ms. EEPROM input buffer is written or if the last byte of the FIFO buffer has been read. be used to generate an interrupt when programming of all data is finished. command cannot be stopped using any other command. Table 139. WriteE2 command 01h

Rev. 3.7 — 30 June 2015 056637 85 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution

11.3.1.2 Timing diagram

Figure 19 shows programming five bytes into the EEPROM. Assuming that the MFRC531 finds and reads byte 0 before the microprocessor is able to write byte 1 (tprog,del = 300 ns). This causes the MFRC531 to start the programming cycle (tprog), which takes approximately 5.8 ms to complete. In the meantime, the microprocessor stores byte 1 to byte 4 in the FIFO buffer. If the EEPROM start byte address is 16Ch then byte 0 is stored at that address. The MFRC531 copies the subsequent data bytes into the EEPROM input buffer. Whilst copying byte 3, it detects that this data byte has to be programmed at the EEPROM byte address 16Fh. As this is the end of the memory block, the MFRC531 automatically starts a programming cycle. Next, byte 4 is programmed at the EEPROM byte address 170h. As this is the last data byte, the E2Ready and TxIRq flags are set indicating the end of the EEPROM programming activity. Although all data has been programmed into the E2PROM, the MFRC531 stays in the WriteE2 command. Writing more data to the FIFO buffer would lead to another EEPROM programming cycle continuing from EEPROM byte address 171h. The command is stopped using the Idle command.

11.3.1.3 WriteE2 command error flags

Programming is restricted for EEPROM block 0 (EEPROM byte address 00h to 0Fh). If you program these addresses, the AccessErr flag is set and a programming cycle is not started. Addresses above 1FFh are taken modulo 200h; see Section 9.2 on page 12 for the EEPROM memory organization. Fig 19. EEPROM programm ing timing diagram 001aak623 NWR data WriteE2 command active EEPROM programming E2Ready TxIRq write addr LSB addr MSB byte 0 byte 1 tprog,del byte 2 byte 3 byte 4 programming byte 0 tprog programming byte 1, byte 2 and byte 3 tprog programming byte 4 tprog Idle command

11.3.2 ReadE2 command 03h

EEPROM starting byte address. stops when all data has been copied.

11.3.2.1 ReadE2 command error flags

these addresses sets the flag AccessErr = logic 1.

11.4 Diverse commands

11.4.1 LoadConfig command 07h

11.4.1.1 Register assignment

2Fh; see Section 9.2 on page 12 for the EEPROM memory organization. chosen with the LoadConfig command. Table 140. ReadE2 command 03h Table 141. LoadConfig command 07h

11.4.1.2 Relevant LoadConfig command error flags

Valid EEPROM starting byte addresses are between 10h and 60h.

11.4.2 CalcCRC command 12h

be read using the CRCResultLSB and CRCResultMSB registers. automatically stop. It must be stopped by the microprocessor sending the Idle command.

11.4.2.1 CRC coprocessor settings

shows the parameters that can be configured for the CRC coprocessor. The CRC polynomial for the 8-bit CRC is fixed to x8 + x4 + x3 + x2 + 1. The CRC polynomial for the 16-bit CRC is fixed to x16 + x12 + x5 + 1.

11.4.2.2 CRC coprocessor status flags

validity for the processed data. Table 142. CalcCRC command 12h Table 143. CRC coprocessor parameters

11.5 Error handling during command execution

information about the cause of the error.

11.6 MIFARE security commands

11.6.1 LoadKeyE2 command 0Bh

FIFO buffer, the command executes. stops after copying the key from the EEPROM to the key buffer.

11.6.1.1 Relevant LoadKeyE2 command error flags

value is copied into the key buffer and the KeyErr flag is set.

11.6.2 LoadKey command 19h

Table 144. ErrorFlag register error flags overview Table 145. LoadKeyE2 command 0Bh Table 146. LoadKey command 19h

checked and, if valid, are copied into the key buffer. stops after copying the key from the FIFO buffer to the key buffer.

11.6.2.1 Relevant LoadKey command error flags

into the key buffer and the KeyErr flag is set.

11.6.3 Authent1 command 0Ch

authenticate the card to the MFRC531 and vice versa.

11.6.4 Authent2 command 14h

byte, however all the data needed to be sent to the card is assembled by the MFRC531. to the MFRC531 and vice versa. Table 147. Authent1 command 0Ch Table 148. Authent2 command 14h

11.6.4.1 Authent2 command effects

Authent2 command fails, bit Crypto1On is cleared (Crypto1On = logic 0). continue with unencrypted (plain) card communication. stored in the key buffer and those on the card must match.

13.1 Operating condition range

Table 149. Limiting values In accordance with the Absolute Maximum Rating System (IEC 60134). Table 150. Operating condition range

13.2 Current consumption

13.3 Pin characteristics

13.3.1 Input pin characteristics

characteristics, and behave as defined in Table 153. Table 151. Current consumption Table 152. Standard input pin characteristics Table 153. Schmitt trigger input pin characteristics

a RC low-pass filter which causes a propagation delay on the reset signal.

13.3.2 Digital output pin characteristics

13.3.3 Antenna driver output pin characteristics

while their source conductance for driving the LOW-level is constant. The antenna driver default configuration output characteristics are specified in Table 157. Table 154. RSTPD input pin characteristics Table 155. RX input capacitance and input voltage range Table 156. Digital output pin characteristics

13.4 AC electrical characteristics

13.4.1 Separate read/write strobe bus timing

Table 157. Antenna driver output pin characteristics Table 158. Timing specification for separate read/write strobe

address lines (A0 to A2) must be connected as described in Section 9.1.3 on page 8.

13.4.2 Common read/write strobe bus timing

Table 159. Common read/write strobe timing specification

13.4.3 EPP bus timing

Table 159. Common read/write strobe timing specification …continued Table 160. Common read/write stro be timing specification for EPP

the address lines (A0 to A2) must be connected as described in Section 9.1.3 on page 8.

13.4.4 SPI timing

13.4.5 Clock frequency

The clock input is pin OSCIN. Table 161. SPI timing specification Table 162. Clock frequency

15.1 Typical application

15.1.1 Circuit diagram

Table 163. EEPROM characteristics

Rev. 3.7 — 30 June 2015 056637 99 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution

15.1.2 Circuit description

The matching circuit consists of an EMC low-pass filter (L0 and C0), matching circuitry (C1 and C2n), a receiver circuit (R1, R2, C3 and C4) and the antenna itself. Refer to the following application notes for more detailed information about designing and tuning an antenna.

  • MICORE reader IC family; Directly Matched Antenna Design Ref. 1
  • MIFARE (14443 A) 13.56 MHz RFID Proximity Antennas Ref. 2.

15.1.2.1 EMC low-pass filter

The MIFARE system operates at a frequency of 13.56 MHz. This frequency is generated by a quartz oscillator to clock the MFRC531. It is also the basis for driving the antenna using the 13.56 MHz energy carrier. This not only causes power emissions at 13.56 MHz, it also emits power at higher harmonics. International EMC regulations define the amplitude of the emitted power over a broad frequency range. To meet these regulations, appropriate filtering of the output signal is required. A multilayer board is recommended to implement a low-pass filter as shown in Figure 24 The low-pass filter consists of the components L0 and C0. The recommended values are given in Application notes MICORE reader IC family; Directly Matched Antenna Design Ref. 1 and MIFARE (14443 A) 13.56 MHz RFID Proximity Antennas Ref. 2. Remark: To achieve best performance, all components must be at least equal in quality to those recommended. Remark: The layout has a major influence on the overall performance of the filter.

15.1.2.2 Antenna matching

Due to the impedance transformation of the low-pass filter, the antenna coil has to be matched to a given impedance. The matching elements C1 and C2n can be estimated and have to be fine tuned depending on the design of the antenna coil. The correct impedance matching is important to ensure optimum performance. The overall quality factor has to be considered to guarantee a proper ISO/IEC 14443 A and ISO/IEC 14443 B communication schemes. Environmental influences have to considered and common EMC design rules. Refer to Application notes MICORE reader IC family; Directly Matched Antenna Design Ref. 1 and MIFARE (14443 A) 13.56 MHz RFID Proximity Antennas Ref. 2 for details. Remark: Do not exceed the current limits (IDD(TVDD)), otherwise the chip might be destroyed. Remark: The overall 13.56 MHz RFID proximity antenna design in combination with the MFRC531 IC does not require any specialist RF knowledge. However, all relevant parameters have to be considered to guarantee optimum performance and international EMC compliance.

Rev. 3.7 — 30 June 2015 056637 100 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution

15.1.2.3 Receiver circuit

The internal receiver of the MFRC531 makes use of both subcarrier load modulation side-bands. No external filtering is required. It is recommended to use the internally generated VMID potential as the input potential for pin RX. This VMID DC voltage level has to be coupled to pin RX using resistor (R2). To provide a stable DC reference voltage, capacitor (C4) must be connected between VMID and ground. The AC voltage divider of R1 + C3 and R2 has to be designed taking in to account the AC voltage limits on pin RX. Depending on the antenna coil design and the impedance, matching the voltage at the antenna coil will differ. Therefore the recommended way to design the receiver circuit is to use the given values for R1, R2, and C3; refer to Application note; MIFARE (14443 A) 13.56 MHz RFID Proximity Antennas Ref. 2 . The voltage on pin RX can be altered by varying R1 within the given limits. Remark: R2 is AC connected to ground using C4.

15.1.2.4 Antenna coil

The precise calculation of the antenna coil’s inductance is not practicable but the inductance can be estimated using Equation 10. We recommend designing an antenna that is either circular or rectangular. (10)

  • l1 = length of one turn of the conductor loop
  • D1 = diameter of the wire or width of the PCB conductor, respectively
  • K = antenna shape factor (K = 1.07 for circular antennas and K = 1.47 for square antennas)
  • N1 = number of turns
  • ln = natural logarithm function The values of the antenna inductance, resistance, and capacitance at 13.56 MHz depend on various parameters such as:
  • antenna construction (type of PCB)
  • thickness of conductor
  • distance between the windings
  • shielding layer
  • metal or ferrite nearby in the environment Therefore, a measurement of these parameters under real life conditions or at least a rough measurement and a tuning procedure is highly recommended to guarantee a reasonable performance. Refer to Application notes MICORE reader IC family; Directly Matched Antenna Design Ref. 1 and MIFARE (14443 A) 13.56 MHz RFID Proximity Antennas Ref. 2 for details. L1 nH 2= I1 cm  N1 1.8

15.2 Test signals

switch as described in Section 9.11 on page 35.

  • internal analog signals for measurement on pin AUX
  • internal digital signals for observation on pin MFOUT (based on register selections) These measurements can be helpful during the design-in phase to optimize the receiver’s behavior or for test purposes.

15.2.1 Measurements using the serial signal switch

received from the card. Table 164 gives an overview of the different signals available. MFOUT is only possible at 106 kBd based on ISO/IEC 14443 A.

15.2.1.1 TX control

Figure 25 shows as an example of an ISO/IEC 14443 A communication. coded as NRZ. Setting MFOUTSelect[2:0] = 001 shows the data as a Miller coded signal. detail information on the RF signal pulse. Table 164. Signal routed to pin MFOUT

1 X digital test signal

Rev. 3.7 — 30 June 2015 056637 102 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution

15.2.1.2 RX control

Figure 26 shows an example of ISO/IEC 14443 A communication which represents the beginning of a card’s answer to a request signal. The RF signal shows the RF voltage measured directly on the antenna so that the card’s load modulation is visible. Setting MFOUTSelect[2:0] = 011 shows the Manchester decoded signal with subcarrier. Setting MFOUTSelect[2:0] = 100 shows the Manchester decoded signal. (1) MFOUTSelect[2:0] = 001; serial data stream; 2 V per division. (2) MFOUTSelect[2:0] = 010; serial data stream; 2 V per division. (3) RFOut; 1 V per division. Fig 25. TX control signals 001aak626 (1) (2) (3) 10 μs per division

15.2.2 Analog test signals

TestAnaSelect register TestAnaOutSel[4:0] bits. (1) RFOut; 1 V per division. (2) MFOUTSelect[2:0] = 011; Manchester with subcarrier; 2 V per division. (3) MFOUTSelect[2:0] = 100; Manchester; 2 V per division. Table 165. Analog test signal selection

0 VMID voltage at internal node VMID

1 Vbandgap internal reference voltage generated by the bandgap

2 VRxFollI output signal from the demodulator using the I-clock

3 VRxFollQ output signal from the demodulator using the Q-clock

4 VRxAmpI I-channel subcarrier signal amplified and filtered

5 VRxAmpQ Q-channel subcarrier signal amplified and filtered

6 VCorrNI output signal of N-channel correlator fed by the I-channel subcarrier

7 VCorrNQ output signal of N-channel correlator fed by the Q-channel subcarrier

8 VCorrDI output signal of D-channel correlator fed by the I-channel subcarrier

9 VCorrDQ output signal of D-channel correlator fed by the Q-channel subcarrier

15.2.3 Digital test signals

digital test signal is selected using the TestDigiSelect register TestDigiSignalSel[6:0] bits. The signals selected by the TestDigiSignalSel[6:0] bits are shown in Table 166. If test signals are not used, the TestDigiSelect register address value must be 00h. Remark: All other values for TestDigiSignalSel[6:0] are for production test purposes only.

15.2.4 Examples of ISO/IEC 14443 A analog and digital test signals

evaluation and digitizer circuitry. Table 166. Digital test signal selection

Rev. 3.7 — 30 June 2015 056637 105 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution Signals VEvalR and VEvalL show the evaluation of the signal’s right and left half-bit. Finally, the digital test signal s_data shows the received data. This is then sent to the internal digital circuit and s_valid which indicates the received data stream is valid. Fig 27. ISO/IEC 14443 A receiving path Q-clock 001aak628 RX reference VRxAmpQ VCorrDQ VCorrNQ VEvalR VEvalL s_data s_valid 50 μs per division

Rev. 3.7 — 30 June 2015 056637 106 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution 16. Package outline Fig 28. Package outline SOT287-1 UNIT A max. A1 A2 A3 bp cD (1) E(1) eH E LL p QZ y w v θ REFERENCESOUTLINE VERSION EUROPEAN PROJECTION ISSUE DATE IEC JEDEC JEITA mm inches 2.65 0.1 0.25 0.01 1.4 0.055 0.3 0.1 2.45 2.25 0.49 0.36 0.27 0.18 20.7 20.3 7.6 7.4 1.27 10.65 10.00 1.2 1.0 0.95 0.55 8 o o 0.25 0.1 0.004 0.25 DIMENSIONS (inch dimensions are derived from the original mm dimensions) Note 1. Plastic or metal protrusions of 0.15 mm (0.006 inch) maximum per side are not included. 1.1 0.4 SOT287-1 MO-119 (1) 0.012 0.004 0.096 0.089 0.02 0.01 0.05 0.047 0.039 0.419 0.394 0.30 0.29 0.81 0.80 0.011 0.007 0.037 0.0220.010.010.043 0.016 w M bp D HE Z e c v M A X A y 32 17 161 θ A Lp Q detail X L (A )3 E pin 1 index 0 5 10 mm scale SO32: plastic small outline package; 32 leads; body width 7.5 mm SOT287-1 00-08-17 03-02-19

[1] Application note — MICORE reader IC family; Directly Matched Antenna Design. [2] Application note — MIFARE (14443 A) 13.56 MHz RFID Proximity Antennas. [3] Application note — Directly matched Antenna - Excel calculation. circuit(s) cards - Proximity cards, part 1-4. [5] Application note — MIFARE Implementation of Higher Baud rates. Table 167. Abbreviations and acronyms

Table 168. Revision history

  • Section 2 “General description”: updated
  • Change of descriptive title MFRC531_34 20100126 Product data sheet - 056633 Modifications:
  • The format of this data sheet has been redesigned to comply with the new identity guidelines of NXP Semiconductors
  • Legal texts have been adapted to the new company name where appropriate
  • The symbols for electrical characteristics and their parameters have been updated to meet the NXP Semiconductors’ guidelines
  • A number of inconsistencies in pin, register and bit names have been eliminated from the data sheet
  • All drawings have been updated
  • Several symbol changes made to drawings in Figure 23 on page 97 to Figure 26 “RX control signals” on page 103
  • Section 5 “Quick reference data” on page 3: section added
  • Section 6 “Ordering information” on page 3: updated
  • Section 15.1.2.4 “Antenna coil” on page 100: added missing formula and updated the last clause
  • Section 16 “Package outline” on page 106: updated
  • Data sheet security status changed from COMPANY CONFIDENTIAL to COMPANY PUBLIC
  • RATP/Innovatron Technologies license statement added to the legal page

056633 December 2005 Product data sheet 056632

056632 April 2005 Product data sheet 056631

056631 May 2004 Product data sheet 056630

056630 November 2002 Product data sheet 056620

056620 January 2002 Preliminary data sheet 056610

056610 July 2001 Objective data sheet -

Rev. 3.7 — 30 June 2015 056637 109 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution 20. Legal information

20.1 Data sheet status

[1] Please consult the most recently issued document before initiating or completing a design. [2] The term ‘short data sheet’ is explained in section “Definitions”. [3] The product status of device(s) described in this document may have changed since this document was published and may differ in case of multiple devices. The latest product status information is available on the Internet at URL http://www.nxp.com.

20.2 Definitions

Draft — The document is a draft version only. The content is still under internal review and subject to formal approval, which may result in modifications or additions. NXP Semiconductors does not give any representations or warranties as to the accuracy or completeness of information included herein and shall have no liability for the consequences of use of such information. Short data sheet — A short data sheet is an extract from a full data sheet with the same product type number(s) and title. A short data sheet is intended for quick reference only and should not be relied upon to contain detailed and full information. For detailed and full information see the relevant full data sheet, which is available on request via the local NXP Semiconductors sales office. In case of any inconsistency or conflict with the short data sheet, the full data sheet shall prevail. Product specification — The information and data provided in a Product data sheet shall define the specification of the product as agreed between NXP Semiconductors and its customer, unless NXP Semiconductors and customer have explicitly agreed otherwise in writing. In no event however, shall an agreement be valid in which the NXP Semiconductors product is deemed to offer functions and qualities beyond those described in the Product data sheet.

20.3 Disclaimers

Limited warranty and liability — Information in this document is believed to be accurate and reliable. However, NXP Semiconductors does not give any representations or warranties, expressed or implied, as to the accuracy or completeness of such information and shall have no liability for the consequences of use of such information. NXP Semiconductors takes no responsibility for the content in this document if provided by an information source outside of NXP Semiconductors. In no event shall NXP Semiconductors be liable for any indirect, incidental, punitive, special or consequential damages (including - without limitation - lost profits, lost savings, business interruption, costs related to the removal or replacement of any products or rework charges) whether or not such damages are based on tort (including negligence), warranty, breach of contract or any other legal theory. Notwithstanding any damages that customer might incur for any reason whatsoever, NXP Semiconductors’ aggregate and cumulative liability towards customer for the products described herein shall be limited in accordance with the Terms and conditions of commercial sale of NXP Semiconductors. Right to make changes — NXP Semiconductors reserves the right to make changes to information published in this document, including without limitation specifications and product descriptions, at any time and without notice. This document supersedes and replaces all information supplied prior to the publication hereof. Suitability for use — NXP Semiconductors products are not designed, authorized or warranted to be suitable for use in life support, life-critical or safety-critical systems or equipment, nor in applications where failure or malfunction of an NXP Semiconductors product can reasonably be expected to result in personal injury, death or severe property or environmental damage. NXP Semiconductors and its suppliers accept no liability for inclusion and/or use of NXP Semiconductors products in such equipment or applications and therefore such inclusion and/or use is at the customer’s own risk. Applications — Applications that are described herein for any of these products are for illustrative purposes only. NXP Semiconductors makes no representation or warranty that such applications will be suitable for the specified use without further testing or modification. Customers are responsible for the design and operation of their applications and products using NXP Semiconductors products, and NXP Semiconductors accepts no liability for any assistance with applications or customer product design. It is customer’s sole responsibility to determine whether the NXP Semiconductors product is suitable and fit for the customer’s applications and products planned, as well as for the planned application and use of customer’s third party customer(s). Customers should provide appropriate design and operating safeguards to minimize the risks associated with their applications and products. NXP Semiconductors does not accept any liability related to any default, damage, costs or problem which is based on any weakness or default in the customer’s applications or products, or the application or use by customer’s third party customer(s). Customer is responsible for doing all necessary testing for the customer’s applications and products using NXP Semiconductors products in order to avoid a default of the applications and the products or of the application or use by customer’s third party customer(s). NXP does not accept any liability in this respect. Limiting values — Stress above one or more limiting values (as defined in the Absolute Maximum Ratings System of IEC 60134) will cause permanent damage to the device. Limiting values are stress ratings only and (proper) operation of the device at these or any other conditions above those given in the Recommended operating conditions section (if present) or the Characteristics sections of this document is not warranted. Constant or repeated exposure to limiting values will permanently and irreversibly affect the quality and reliability of the device. Terms and conditions of commercial sale — NXP Semiconductors products are sold subject to the general terms and conditions of commercial sale, as published at http://www.nxp.com/profile/terms , unless otherwise agreed in a valid written individual agreement. In case an individual agreement is concluded only the terms and conditions of the respective agreement shall apply. NXP Semiconductors hereby expressly objects to applying the customer’s general terms and conditions with regard to the purchase of NXP Semiconductors products by customer. No offer to sell or license — Nothing in this document may be interpreted or construed as an offer to sell products that is open for acceptance or the grant, conveyance or implication of any license under any copyrights, patents or other industrial or intellectual property rights. Document status[1][2] Product status[3] Definition Objective [short] data sheet Development This document contains data from the objective specification for product development. Preliminary [short] data sheet Qualification This document contains data from the preliminary specification. Product [short] data sheet Production This document contains the product specification.

Rev. 3.7 — 30 June 2015 056637 110 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution Export control — This document as well as the item(s) described herein may be subject to export control regulations. Export might require a prior authorization from competent authorities. Quick reference data — The Quick reference data is an extract of the product data given in the Limiting values and Characteristics sections of this document, and as such is not complete, exhaustive or legally binding. Non-automotive qualified products — Unless this data sheet expressly states that this specific NXP Semiconductors product is automotive qualified, the product is not suitable for automotive use. It is neither qualified nor tested in accordance with automotive testing or application requirements. NXP Semiconductors accepts no liability for inclusion and/or use of non-automotive qualified products in automotive equipment or applications. In the event that customer uses the product for design-in and use in automotive applications to automotive specifications and standards, customer (a) shall use the product without NXP Semiconductors’ warranty of the product for such automotive applications, use and specifications, and (b) whenever customer uses the product for automotive applications beyond NXP Semiconductors’ specifications such use shall be solely at customer’s own risk, and (c) customer fully indemnifies NXP Semiconductors for any liability, damages or failed product claims resulting from customer design and use of the product for automotive applications beyond NXP Semiconductors’ standard warranty and NXP Semiconductors’ product specifications. Translations — A non-English (translated) version of a document is for reference only. The English version shall prevail in case of any discrepancy between the translated and English versions.

20.4 Licenses

20.5 Trademarks

Notice: All referenced brands, product names, service names and trademarks are the property of their respective owners. MIFARE — is a trademark of NXP Semiconductors N.V. MIFARE Ultralight — is a trademark of NXP Semiconductors N.V. MIFARE Plus — is a trademark of NXP Semiconductors N.V. DESFire — is a trademark of NXP Semiconductors N.V. 21. Contact information For more information, please visit: http://www.nxp.com For sales office addresses, please send an email to: salesaddresses@nxp.com Purchase of NXP ICs with ISO/IEC 14443 type B functionality This NXP Semiconductors IC is ISO/IEC 14443 Type B software enabled and is licensed under Innovatron’s Contactless Card patents license for ISO/IEC 14443 B. The license includes the right to use the IC in systems and/or end-user equipment. RATP/Innovatron Technology

Table 4. Supported micropr ocessor and EPP interface Table 5. Connection scheme for detecting the parallel Table 14. Byte assignment for register initialization at Table 15. Shipment content of StartUp configuration file .15 Table 16. Byte assignment for register initialization at Table 18. Associated FIFO buffer registers and flags . . .19 Table 21. Associated Interru pt request system registers Table 26. TX1 and TX2 source resistance of n-channel Table 31. Register settings to enable use of the analog Table 34. Dedicated address bus: assembling the register Table 35. Multiplexed address bus: assembling the register Table 39. Page register (address: 00h, 08h, 10h, 18h, 20h, Table 41. Command register (address: 01h) reset value: Table 43. FIFOData register (address: 02h) reset value: Table 45. PrimaryStatus register (address: 03h) reset value: Table 47. FIFOLength register (address: 04h) reset value: Table 49. SecondaryStatus regi ster (address: 05h) reset Table 51. InterruptEn register (address: 06h) reset value: Table 53. InterruptRq register (address: 07h) reset value: Table 55. Control register (address: 09h) reset value: 0000 Table 57. ErrorFlag register (address: 0Ah) reset value: Table 59. CollPos register (address: 0Bh) reset value: 0000 Table 61. TimerValue register (address: 0Ch) reset value: Table 63. CRCResultLSB register (address: 0Dh) reset Table 65. CRCResultMSB register (address: 0Eh) reset Table 67. BitFraming register (address: 0Fh) reset value: Table 69. TxControl register (address: 11h) reset value:

Table 71. CwConductance register (address: 12h) reset Table 73. ModConductance regi ster (address: 13h) reset Table 75. CoderControl register (address: 14h) reset value: Table 77. ModWidth register (address: 15h) reset value: Table 79. PreSet16 register (address: 16h) reset value: Table 80. TypeBFraming register (address: 17h) reset Table 82. RxControl1 register (address: 19h) reset value: Table 84. DecoderControl regi ster (address: 1Ah) reset Table 86. BitPhase register (a ddress: 1Bh) reset value: Table 88. RxThreshold register (address: 1Ch) reset value: Table 90. BPSKDemControl regist er (address: 1Dh) reset Table 91. BPSKDemControl regist er bit descriptions . . .63 Table 92. RxControl2 register (address: 1Eh) reset value: Table 94. ClockQControl regi ster (address: 1Fh) reset Table 96. RxWait register (address: 21h) reset value: 0000 Table 98. ChannelRedundancy register (address: 22h) Table 100. CRCPresetLSB register (address: 23h) reset Table 102. CRCPresetMSB register (address: 24h) reset Table 104. PreSet25 register (address: 25h) reset value: Table 105. MFOUTSelect register (address: 26h) reset Table 107. PreSet27 (address: 27h) reset value: xxxx xxxxb, Table 108. FIFOLevel register (address: 29h) reset value: Table 110. TimerClock register (address: 2Ah) reset value: Table 112. TimerControl register (address: 2Bh) reset value: Table 114. TimerReload register (address: 2Ch) reset value: Table 116. IRQPinConfig register (address: 2Dh) reset value: Table 118. PreSet2E register (address: 2Eh) reset value: Table 119. PreSet2F register (address: 2Fh) reset value: Table 120. Reserved registers (address: 31h, 32h, 33h, 34h, Table 121. Reserved register (address: 39h) reset value: Table 122. TestAnaSelect register (address: 3Ah) reset Table 124. Reserved register (address: 3Bh) reset value: Table 125. Reserved register (address: 3Ch) reset value: Table 126. TestDigiSelect register (address: 3Dh) reset Table 128. Reserved register (address: 3Eh, 3Fh) reset Table 133. Transmission of frames of more than

Table 155. RX input capacitance and input voltage range 92 Table 158. Timing specification for separate read/write Table 159. Common read/write strobe timing Table 160. Common read/write strobe timing

Rev. 3.7 — 30 June 2015 056637 114 of 117 NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution 23. Figures Fig 3. Connection to microprocessor: separate read Fig 4. Connection to microprocessor: common read Fig 5. Connection to microprocessor: EPP common Fig 22. Timing diagram for common read/write strobe; Fig 24. Application example circuit diagram: directly

Rev. 3.7 — 30 June 2015 056637 115 of 117 continued >> NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution 24. Contents

9.1.1 Overview of supported microprocessor

9.1.2 Automatic microprocessor interface detection . 7 9.1.3 Connection to different microprocessor types . 8

9.1.3.3 Common read and write strobe: EPP with

9.2.2.1 StartUp register initiali zation file (read/write) . 14

9.2.2.2 Factory defaul t StartUp register

9.4.2.1 Controlling interrupts and getting their status . 20 9.4.4 Register over view interrupt request system . . 21

9.5.2.3 Programmable one shot timer and

9.9.2 Antenna operating distance versus power

9.13 ISO/IEC 14443 B communication scheme. . . 39

Rev. 3.7 — 30 June 2015 056637 116 of 117 continued >> NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution 10.5.5 Page 4: RF Timing and channel redundancy . 65

10.5.6 Page 5: FIFO, timer and IRQ

10.5.7.2 Reserved registers 31h, 32h, 33h, 34h,

11.2 Commands for ISO/IEC 14443 A card

11.2.1.4 Transmission of frames with more than

NXP Semiconductors MFRC531 Standard ISO/IEC 14443 A/B reader solution © NXP Semiconductors N.V. 2015. All rights reserved. For more information, please visit: http://www.nxp.com For sales office addresses, please send an email to: salesaddresses@nxp.com Date of release: 30 June 2015 056637 Please be aware that important notices concerning this document and the product(s) described herein, have been included in section ‘Legal information’. 11.5 Error handling during command execution. . . 88

15.2.1 Measurements using the serial signal switch 101

15.2.4 Examples of ISO/IEC 14443 A analog