FXTH87E NXP | Alldatasheet

Document overview

  • Manufacturer or author: Provided By www.digicamel.com(FREE DATASHEET DOWNLOAD SITE)
  • PDF pages: 183

Technical content

Datasheet sections

  • 1 About this document
  • 1.1 Purpose
  • 1.2 Audience
  • 1.3 Related documentation
  • 2 Product profile
  • 2.1 General description
  • 2.2 Features and benefits
  • 2.3 Configuration options
  • 2.4 Part number definition
  • 2.5 Part marking definition
  • 3 General Information
  • 3.1 Overall block diagram
  • 3.2 Multi-chip interface
  • 3.3 System clock distribution
  • 3.4 Reference documents
  • 4 Pinning information
  • 4.1 Pinning
  • 4.2 Pin description
  • 4.3 Recommended application
  • 4.4 Signal properties
  • 4.4.1 VDD and VSS pins
  • 4.4.2 AVDD and AVSS pins
  • 4.4.3 VREG pin
  • 4.4.4 RVSS pin
  • 4.4.5 RF pin
  • 4.4.6 XO, XI pins
  • 4.4.7 LF[A:B] pins
  • 4.4.8 PTA[1:0] pins
  • 4.4.9 PTA[3:2] pins
  • 4.4.10 BKGD/PTA4 pin
  • 4.4.11 RESET pin
  • 4.4.12 PTB[1:0] pins
  • 5 Modes of operation
  • 5.1 Features
  • 5.2 RUN mode
  • 5.3 WAIT mode
  • 5.4 ACTIVE BACKGROUND mode
  • 5.5 STOP Modes
  • 5.5.1 STOP1 Mode
  • 5.5.2 STOP4 LVD enabled in STOP mode
  • 5.5.3 Active BDM enabled in STOP mode
  • 5.5.4 MCU on-chip peripheral modules in STOP
  • 5.5.4.1 I/O pins
  • 5.5.4.2 Memory
  • 5.5.4.3 Parameter registers
  • 5.5.4.4 LFO
  • 5.5.4.5 FRC
  • 5.5.4.6 MFO
  • 5.5.4.7 HFO
  • 5.5.4.8 PWU
  • 5.5.4.9 ADC10
  • 5.5.4.10 LFR
  • 5.5.4.11 Band gap reference
  • 5.5.4.12 TPM1
  • 5.5.4.13 Voltage regulator
  • 5.5.4.14 Temperature sensor
  • 5.5.4.15 Temperature restart
  • 5.5.5 RFM module in STOP modes
  • 5.5.5.1 RF output
  • 5.5.6 P-cell in STOP modes
  • 5.5.7 Optional g-cell in STOP modes
  • 6 Memory
  • 6.1 MCU memory map
  • 6.2 Reset and interrupt vectors
  • 6.3 MCU register addresses and bit
  • 6.4 High address registers
  • 6.5 MCU parameter registers
  • 6.6 MCU RAM
  • 6.7 FLASH
  • 6.7.1 Features
  • 6.7.2 Program and erase times
  • 6.7.3 Program and erase command execution
  • 6.7.4 Burst program execution
  • 6.7.5 Access errors
  • 6.7.6 FLASH block protection
  • 6.7.7 Vector redirection
  • 6.8 Security
  • 6.9 FLASH registers and control bits
  • 6.9.1 FLASH clock divider register (FCDIV)
  • 6.9.2 FLASH options register (FOPT and NVOPT)
  • 6.9.3 FLASH configuration register (FCNFG)
  • 6.9.4 FLASH protection register (FPROT and
  • 6.9.5 FLASH status register (FSTAT)
  • 6.9.6 FLASH command register (FCMD)
  • 7 Reset, interrupts and system configuration
  • 7.1 Features
  • 7.2 MCU reset
  • 7.3 Computer Operating Properly (COP)
  • 7.4 SIM test register (SIMTST)
  • 7.5 Interrupts
  • 7.5.1 Interrupt stack frame
  • 7.5.2 Vector summary
  • 7.6 Low-Voltage Detect (LVD) System
  • 7.6.1 Power-on reset operation
  • 7.6.2 LVD reset operation
  • 7.6.3 LVD interrupt operation
  • 7.6.4 Low-Voltage Warning (LVW)
  • 7.7 System clock control
  • 7.8 Keyboard interrupts
  • 7.9 Real-time interrupt
  • 7.10 Temperature sensor and restart system
  • 7.11 Reset, interrupt and system control registers
  • 7.11.1 System Reset Status Register (SRS)
  • 7.11.2 System Options Register 1 (SIMOPT1)
  • 7.11.3 System Operation Register 2 (SIMOPT2)
  • 7.11.4 System Power Management Status and

FXTH87E, Family of Tire Pressure Monitor Sensors Rev. 5.0 — 4 February 2019 Reference manual

1 About this document

1.1 Purpose

This reference manual describes the features, architecture, and programming model of the FXTH87E family of devices.

1.2 Audience

This document is primarily for system architects and software application developers who are using or considering use of the FXTH87E in a system.

1.3 Related documentation

The FXTH87E device features and operations are described in a variety of reference manuals, user guides, and application notes. To find the most-current versions of these documents: 1. Go to the FXTH87E page on NXP.com at: http://www.nxp.com/FXTH87E 2. Select the documentation tab and review the related documentation. Contact NXP sales representatives for performance attributes such as electrical, mechanical, and time-based characteristics.

2 Product profile

2.1 General description

The FXTH87E is a small (7 x 7 mm), fully integrated tire pressure monitoring sensor (TPMS). It also provides low transmitting power consumption, large customer memory size and dual-axis accelerometer architecture. The FXTH87E TPMS solution integrates an 8-bit microcontroller (MCU), pressure sensor, XZ-axis or Z-axis accelerometer and RF transmitter.

2.2 Features and benefits

  • Long battery service life
  • Provided software for power optimization
  • Pin for pin electrical connections compatible with FXTH87-based customer applications
  • Included firmware subroutines compatible with FXTH87-based customer software
  • Pressure sensor with one of three calibrated pressure ranges
  • Temperature sensor
  • Optional XZ- or Z-axis accelerometer with adjustable offset option
  • Voltage reference measured by ADC10
  • Six-channel, 10-bit analog-to-digital converter (ADC10) with two external I/O inputs
  • 8-bit MCU – S08 Core with SIM and interrupt – 512 RAM – 16 KB FLASH – 64-byte, low-power, parameter registers
  • Dedicated state machines to sequence routine measurement and transmission processes for reduced power consumption
  • Internal 315-/434-MHz RF transmitter – External crystal oscillator – PLL-based output with fractional-n divider – OOK and FSK modulation capability – Programmable data rate generator – Manchester, Bi-Phase or NRZ data encoding – 256-bit RF data buffer variable length interrupt – Direct access to RF transmitter from MCU for unique formats – Low-power consumption
  • Differential input LF detector/decoder on independent signal pins
  • Seven multipurpose GPIO pins – Four pins can be connected to optional internal pullups/pulldowns and STOP4 wakeup interrupt – Two of seven pins can be connected to a channel on the ADC10 – Two of seven pins can be connected to a channel on the TPM1
  • Real-time Interrupt driven by LFO with interrupt intervals of 2, 4, 8, 16, 32, 64, or 128 ms
  • Free-running counter, low-power, wakeup timer and periodic reset driven by LFO
  • Watchdog timeout with selectable times and clock sources
  • Two-channel general purpose timer/PWM module (TPM1)
  • Internal oscillators – MCU bus clock of 0.5, 1, 2, and 4 MHz (1, 2, 4, and 8 MHz HFO) – Low frequency, low power time clock (LFO) with 1 ms period – Medium frequency, controller clock (MFO) of 8 μs period
  • Low-voltage detection
  • Normal temperature restart in hardware (over- or under-temperature detected by software)

2.3 Configuration options

Table 1. Configuration options

2.4 Part number definition

Table 2. Part number breakdown

2.5 Part marking definition

Table 3. Part marking breakdown

3 General Information

3.1 Overall block diagram

controls and bus control signals are not shown in this block diagram for clarity. Figure 1. FXTH87E overall block diagram

3.2 Multi-chip interface

The FXTH87E contains two to three devices using the best process technology for each.

  • Microcontroller with accelerometer and pressure sensor interfaces, and RF transmitter (MCU)
  • Optional ranges on pressure transducers
  • Optional XZ- or Z-axis acceleration transducer As shown in Figure 1, the MCU interfaces to the RF transmitter using a standard memory mapped registers. The transducers connect to the MCU using custom analog interfaces and inter-chip bonding wires.

3.3 System clock distribution

26 MHz

Figure 2. Clock distribution

3.4 Reference documents

full capabilities of this core, refer to the HCS08 Family Reference Manual (HCS08RMV1).

4 Pinning information

This section describes the pin layout and general function of each pin.

4.1 Pinning

N/C = No Connect: Do not connect PCB pads to signal traces, power/ground or multi-layer via. Figure 3. FXTH87E QFN package pinout Figure 4. FXTH87E QFN optional Z-axis accelerometer orientation

4.2 Pin description

Table 4. Pin description power/ground or multi-layer via.

4.3 Recommended application

Figure 5. FXTH87E example application external radiated signals from corrupting the power input circuits. cases, the bubble may bend the bond wires and result in a permanent shift.

4.4 Signal properties

The following sections describe the general function of each pin.

4.4.1 VDD and VSS pins

decoupled as shown in Figure 6. share any load currents with other external devices as shown in Figure 6.

4.4.2 AVDD and AVSS pins

through the AVDD and AVSS pins. AVDD is the positive supply and AVSS is the ground. locally decoupled as shown in Figure 6. share any load currents with other external devices as shown in Figure 6. application tuning may be required. Figure 6. Recommended power supply connections

4.4.3 VREG pin

4.4.4 RVSS pin

4.4.5 RF pin

The RF pin is the RF energy data supplied by the FXTH87E to an external antenna.

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019

4.4.6 XO, XI pins

The XO and XI pins are for an external crystal to be used by the internal PLL for creating the carrier frequencies and data rates for the RF pin.

4.4.7 LF[A:B] pins

The LF[A:B] pins can be used by the LF receiver (LFR) as one differential input channel for sensing low level signals from an external low frequency (LF) coil. The external LF coil should be connected between the LFA and the LFB pins. Signaling into the LFR pins can place the FXTH87E into various diagnostic or operational modes. The LFR is comprised of the detector and the decoder. Each LF[A:B] pin will always have an impedance of approximately 500 kΩ to VSS due to the LFR input circuitry. The LFA/LFB pins are used by the LFR when the LFEN control bit is set and are not functional when the LFEN control bit is clear.

4.4.8 PTA[1:0] pins

The PTA[1:0] pins are general purpose I/O pins. These two pins can be configured as normal bidirectional I/O pins with programmable pullup or pulldown devices and/or wakeup interrupt capability; or one or both can be connected to the two input channels of the A/D converter module. The pulldown devices can only be activated if the wakeup interrupt capability is enabled. User software must configure the general purpose I/O pins so that they do not result in "floating" inputs as described in Section 8.1 "Unused pin configuration" PTA[1:02] map to keyboard Interrupt function bits [1:0].

4.4.9 PTA[3:2] pins

The PTA[3:2] pins are general purpose I/O pin. These two pins can be configured as normal bidirectional I/O pin with programmable pullup or pulldown devices and/or wakeup interrupt capability; or one or both can be connected to the two input channels of the Timer Pulse Width (TPM1) module. The pulldown devices can only be activated if the wakeup interrupt capability is enabled. User software must configure the general purpose I/O pins so that they do not result in "floating" inputs as described in Section 8.1 "Unused pin configuration". PTA[3:2] map to keyboard Interrupt function bits [3:2].

4.4.10 BKGD/PTA4 pin

The BKGD/PTA4 pin is used to place the FXTH87E in the BACKGROUND DEBUG mode (BDM) to evaluate MCU code and to also transfer data to/from the internal memories. If the BKGD/PTA4 pin is held low when the FXTH87E comes out of a power- on reset the device will go into the ACTIVE BACKGROUND DEBUG mode (BDM). The BKGD/PTA4 pin has an internal pullup device and can connected to VDD in the application unless there is a need to enter BDM operation after the device as been soldered into the PWB. If in-circuit BDM is desired the BKGD/PTA4 pin can be left unconnected, but should be connected to VDD through a low impedance resistor (< 10 kΩ) which can be over-driven by an external signal. This low impedance resistor reduces the possibility of getting into the debug mode in the application due to an EMC event. When the BDM is disabled, PTA4 can be used as an output-only GPIO.

4.4.11 RESET pin

direct to the MCU to the reset vector as described in Section 7.2 "MCU reset". the debug mode in the application due to an EMC event. below 0.3 x VDD for at least 100 ns before rising above 0.7 x VDD as shown in Figure 7.

0.7 VDD

0.3 VDD

Figure 7. RESET pin timing

4.4.12 PTB[1:0] pins

interrupts and system configuration" for details regarding pin multiplexing priorities.

5 Modes of operation

mode, exit from each mode, and functionality while in each of the modes are described.

5.1 Features

  • ACTIVE BACKGROUND DEBUG mode for code development
  • STOP modes: – System clocks stopped – STOP1: Power down of most internal circuits, including RAM, for maximum power savings; voltage regulator in standby – STOP4: All internal circuits powered and full voltage regulation maintained for fastest recovery

5.2 RUN mode

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 from internal memory following a reset with execution beginning at address specified by the reset pseudo-vector ($DFFE and $DFFF).

5.3 WAIT mode

The WAIT mode is also present like other members of the NXP S08 family members; but is not normally used by the FXTH87E firmware or typical TPMS applications.

5.4 ACTIVE BACKGROUND mode

The ACTIVE BACKGROUND mode functions are managed through the BACKGROUND DEBUG controller (BDC) in the HCS08 core. The BDC provides the means for analyzing MCU operation during software development. ACTIVE BACKGROUND mode is entered in any of four ways:

  • When the BKGD/PTA4 pin is low at the rising edge of a power up reset
  • When a BACKGROUND command is received through the BKGD/PTA4 pin
  • When a BGND instruction is executed by the CPU
  • When encountering a BDC breakpoint Once in ACTIVE BACKGROUND mode, the CPU is held in a suspended state waiting for serial BACKGROUND commands rather than executing instructions from the user’s application program. Background commands are of two types:
  • Non-intrusive commands, defined as commands that can be issued while the user program is running. Non-intrusive commands can be issued through the BKGD/PTA4 pin while the MCU is in RUN mode; non-intrusive commands can also be executed when the MCU is in the ACTIVE BACKGROUND mode. Non-intrusive commands include: – Memory access commands – Memory-access-with-status commands – BDC register access commands – The BACKGROUND command
  • ACTIVE BACKGROUND commands, which can only be executed while the MCU is in ACTIVE BACKGROUND mode. ACTIVE BACKGROUND commands include commands to: – Read or write CPU registers – Trace one user program instruction at a time – Leave ACTIVE BACKGROUND mode to return to the user’s application program (GO) The ACTIVE BACKGROUND mode is used to program a boot loader or user application program into the FLASH program memory before the MCU is operated in RUN mode for the first time. When the FXTH87E is shipped from the NXP factory, the FLASH program memory is erased by default (unless specifically requested otherwise) so there is no program that could be executed in RUN mode until the FLASH memory is initially programmed. The ACTIVE BACKGROUND mode can also be used to erase and reprogram the FLASH memory after it has been previously programmed.

5.5 STOP Modes

5.5.1 STOP1 Mode

the internal circuitry of the MCU to be powered down. exited by asserting either a reset or an interrupt function to the MCU. is greater than VLVDH or VLV/DL rising (VDD must rise above the LVI re-arm voltage).

5.5.2 STOP4 LVD enabled in STOP mode

with the LVD enabled in STOP (LVDSE = 1), the MCU will enter STOP4 instead. Table 5. STOP mode behavior

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 Mode STOP1 STOP4 Sensor Measurement Interface (SMI) Off Optionally On Pressure P-cell Off Optionally On Optional Acceleration g-cell Off Optionally On Temperature Sensor (in ADC10) Off Optionally On [3] Normal Temperature Restart Optionally On Optionally On Voltage Reference (in ADC10) Off Optionally On(3) LFR Detector [4] Periodically On Periodically On LFR Decoder Optionally On Optionally On RF Controller, Data Buffer, Encoder Optionally On Optionally On RF Transmitter [5] Optionally On Optionally On ADC10 Off Optionally On(3) Regulator Off On I/O Pins Hi-Z States Held Wakeup Methods Interrupts, resets Interrupts, resets Computer Operating Properly (COP) watchdog Off Off [1] The interrupt from RTI operates from all power modes, however the RTIF flag will not be set and the interrupt service routine will not execute if the RTI is configured and STOP1 mode entered. RTIF flag and the interrupt service routine will execute if in Run mode or if STOP4 is entered. [2] MFO oscillator started if the LFR detectors are periodically sampled, the LFR detectors detect an input signal; a pressure or acceleration reading is in progress or the RF state machine is sending data. [3] Requires internal ADC10 clock to be enabled. [4] Period of sampling set by MCU. [5] RF data buffer may be set up to run while the CPU is in the STOP modes. Specific to the tire pressure monitoring application the parameter registers and the LFO with wakeup timer are powered up at all times whenever voltage is applied to the supply pins. The LFR detector and MFO may be periodically powered up by the LFR decoder.

5.5.3 Active BDM enabled in STOP mode

Entry into the ACTIVE BACKGROUND DEBUG mode from RUN mode is enabled if the ENBDM bit in BDCSCR is set. The BDCSCR register is not memory mapped so it can only be accessed through the BDM interface by use of the BDM commands READ_STATUS and WRITE_CONTROL. If ENBDM is set when the CPU executes a STOP instruction, the system clocks to the BACKGROUND DEBUG logic remain active when the MCU enters STOP mode so BACKGROUND DEBUG communication is still possible. In addition, the voltage regulator does not enter its low-power standby state but maintains full internal regulation. If the user attempts to enter the STOP1 with ENDBM set, the MCU will instead enter this mode which is STOP4 with system clocks running. Most BACKGROUND commands are not available in STOP mode. The memory-access- with-status commands do not allow memory access, but they report an error indicating that the MCU is in STOP mode. The BACKGROUND command can be used to wake the MCU from stop and enter ACTIVE BACKGROUND mode if the ENDBM bit is set. Once in BACKGROUND DEBUG mode, all BACKGROUND commands are available.

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019

5.5.4 MCU on-chip peripheral modules in STOP modes

When the MCU enters any STOP mode, system clocks to the internal peripheral modules except the wakeup timer and LFR detectors/decoder are stopped. Even in the exception case (ENDBM = 1), where clocks are kept alive to the BACKGROUND debug logic, clocks to the peripheral systems are halted to reduce power consumption.

5.5.4.1 I/O pins

If the MCU is configured to go into STOP1 mode, the I/O pins are forced to their default reset state (Hi-Z) upon entry into stop. This means that the I/O input and output buffers are turned off and the pullup is disconnected.

5.5.4.2 Memory

All module interface registers will be reset upon wakeup from STOP1 and the contents of RAM are not preserved. The MCU must be initialized as upon reset. The contents of the FLASH memory are non-volatile and are preserved in any of the STOP modes.

5.5.4.3 Parameter registers

The 64 bytes of parameter registers are kept active in all modes of operation as long as power is applied to the supply pins. The contents of the parameter registers behave like RAM and are unaffected by any reset.

5.5.4.4 LFO

The LFO remains active regardless of any mode of operation.

5.5.4.5 FRC

The Free-Running Counter can be enabled or halted. Once enabled and not halted, the FRC remains active regardless of any mode of operation.

5.5.4.6 MFO

The medium frequency oscillator (MFO) will remain powered up when the MCU enters the STOP mode only when the SMI has been initiated to make a pressure or acceleration measurement; or when the RF transmitter’s state machine is processing data.

5.5.4.7 HFO

The HFO is halted in all STOP modes.

5.5.4.8 PWU

The PWU remains active regardless of any mode of operation.

5.5.4.9 ADC10

The internal asynchronous ADC10 clock is always used as the conversion clock. The ADC10 can continue operation during STOP4 mode. Conversions can be initiated while the MCU is the STOP4 mode. All ADC10 module registers contain their reset values following exit from STOP1 mode Section 14 "LF Receiver".

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019

5.5.4.10 LFR

When the LFR is enabled and the MCU enters STOP mode, the detectors in the LFR will remain powered up depending on the states of the bits selecting the periodic sampling. Refer to Section 14 "LF Receiver" for more details.

5.5.4.11 Band gap reference

The band gap reference should be enabled whenever the sensor measurement interface requires sensor or voltage measurements.

5.5.4.12 TPM1

When the MCU enters STOP mode, the clock to the TPM1 module stops and the module halts operation. If the MCU is configured to go into STOP1 mode, the TPM1 module will be reset upon wakeup from STOP and must be re-initialized.

5.5.4.13 Voltage regulator

The voltage regulator enters a low-power standby state when the MCU enters any of the STOP modes except STOP4 (LVDSE = 1 or ENBDM = 1).

5.5.4.14 Temperature sensor

The temperature sensor is powered up on command from the MCU.

5.5.4.15 Temperature restart

When the MCU enters a STOP mode, the temperature restart will remain powered up if the TRE bit is set. If the temperature restart level is reached, the MCU will restart from the reset vector.

5.5.5 RFM module in STOP modes

The RFM’s external crystal oscillator (XCO), bit rate generator, PLL, VCO, RF data buffer, data encoder, and RF output stage will remain powered up in STOP modes during a transmission, or if the SEND bit has been set and DIRECT mode has been enabled.

5.5.5.1 RF output

When the RFM finishes a transmission sequence the external crystal oscillator (XCO), bit rate generator, PLL, VCO, RF data buffer, data encoder, and RF output stage will remain powered up if the SEND bit is set.

5.5.6 P-cell in STOP modes

The P-cell is powered up only during a measurement if scheduled by the sensor measurement interface. Otherwise it is powered down.

5.5.7 Optional g-cell in STOP modes

The g-cell is powered up only during a measurement if scheduled by the sensor measurement interface. Otherwise it is powered down.

6 Memory

The overall memory map of the FXTH87E resides on the MCU.

6.1 MCU memory map

  • Direct-page registers ($0000 through $004F)
  • Parameter registers ($0050 through $008F)
  • RAM ($0090 through $028F)
  • High-page registers ($1800 through $182B) $0000 $004F $0050 $008F $1800 $17FF $182B $182C $FDFF $FE00 $FFAF $FFB0 $FFFF $0090 $C000 $BFFF Direct page registers RAM 512 bytes Unimplemented 5488 bytes High page registers 41964 bytes $028F $0290 Parameter registers $DFE0 $DFDF User flash 8160 bytes User vectors Firmware flash 7008 bytes $E000 $DFFF $E0A0 $E09F Firmware jump table $FBFF $FC00Protected coefficients 512 bytes Firmware flash 432 bytes Flash control and HW vectors 80 bytes aaa-027997

Figure 8. FXTH87E MCU memory map

6.2 Reset and interrupt vectors

in the CodeWarrior project file. Table 6. Vector summary

6.3 MCU register addresses and bit assignments

  • Direct-page registers are located in the first 80 locations in the memory map; these are accessible with efficient direct addressing mode instructions.
  • The parameter registers begin at address $0050; these are also accessible with efficient direct addressing mode instructions.
  • High-page registers are used less often, so they are located above $1800 in the memory map. This leaves more room in the direct page for more frequently used registers and variables.
  • The nonvolatile register area consists of a block of 16 locations in FLASH memory at $FFB0:FFBF. Nonvolatile register locations include: – Three values that are loaded into working registers at reset – An 8-byte back door comparison key that optionally allows the user to gain controlled access to secure memory. Because the nonvolatile register locations are FLASH memory, they must be erased and programmed like other FLASH memory locations.

described in detail in this specification. Table 7. MCU direct page register summary

  • Shaded cell with a 0 indicate an unused bit that always reads as 0
  • Shaded cells not containing a value indicate unused or reserved bit locations that could read as 1s or 0s Address Register Name Bit 7 6 5 4 3 2 1 Bit 0 $0000 PTAD PTAD[4:0] $0001 PTAPE PTAPE[3:0] $0002 Reserved $0003 PTADD PTADD[3:0] $0004 PTBD PTBD[1:0] $0005 PTBPE PTBPE[1:0] $0006 Reserved $0007 PTBDD PTBDD[1:0] $0008 Reserved $0009 Reserved $000A Reserved $000B Reserved $000C KBISC 0 0 0 0 KBF KBACK KBIE KBIMOD $000D KBIPE KBIPE[3:0] $000E KBIES KBEDG[3:0] $000F Reserved $0010 TPM1SC TOF TOIE CPWMS CLKSB CLKSA PS2 PS1 PS0 $0011 TPM1CNTH Bit [15:8] $0012 TPM1CNTL Bit [7:0] $0013 TPM1MODH Bit [15:8] $0014 TPM1MODL Bit [7:0] $0015 TPM1C0SC CH0F CH0IE MS0B MS0A ELS0B ELS0A 0 0 $0016 TPM1C0VH Bit [15:8] $0017 TPM1C0VL Bit [7:0] $0018 TPM1C1SC CH1F CH1IE MS1B MS1A ELS1B ELS1A 0 0 $0019 TPM1C1VH Bit [15:8] $001A TPM1C1VL Bit [7:0] $001B Reserved $001C PWUDIV WDIV[5:0] $001D PWUCS0 WUF WUFAK WUT[5:0] $001E PWUCS1 PRF PRFAK PRST[5:0] $001F PWUS PSEL 0 CSTAT[5:0]

Note: Shaded bits are recommended to only be controlled by firmware or factory test. Table 8. LFR register summary - LPAGE = 0 Table 9. LFR register summary - LPAGE = 1 Note: Shaded bits are recommended to only be controlled by firmware or factory test.

Table 10. RFM register summary - RPAGE = 0 Note: Shaded bits are recommended to only be controlled by firmware or factory test. Table 11. RFM register summary - RPAGE = 1

Note: Shaded bits are recommended to only be controlled by firmware or factory test.

6.4 High address registers

registers and variables. The registers control system level features as given in Table 12. Table 12. MCU high address register summary

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 Address Register Name Bit 7 6 5 4 3 2 1 Bit 0 $1803 SIMOPT2 COPT[2:0] LFOSEL TCLKDIV BUSCLKS[1:0] $1804 Reserved $1805 Reserved $1806 SDIDH REV[3:0] ID[11:8] $1807 SDIDL ID[7:0] $1808 SRTISC RTIF RTIACK RTICLKS RTIE 0 RTIS{2:0] $1809 SPMSC1 LVDF LVDACK LVDIE LVDRE LVDSE LVDE 0 BGBE $180A SPMSC2 0 0 0 PDF 0 PPDACK PDC 0 $180B FRC FRCLR FRCEN FPAGE $180C SPMSC3 LVWF LVWACK LVDV LVWV 0 0 0 0 $180D SIMSES KBF IRQF TRF PWUF LFF RFF $180E SOTRM SOTRM[7:0] $180F SIMTST TRH[2:0] TRO $1810-1F Reserved $1820 FCDIV DIVLD PRDIV8 DIV[5:0] $1821 FOPT KEYEN FNORED 0 0 0 0 SEC0[1:0]} $1822 Reserved $1823 FCNFG 0 0 KEYACC 0 0 0 0 0 $1824 FPROT FPS[7:1] FPDIS $1825 FSTAT FCBEF FCCF FPVIOL FACCERR 0 FBLANK 0 0 $1826 FCMD FERASE FCMD[6:0] $1827-3F Reserved Note: Reserved bits shown as 0 must always be written to 0. Note: Reserved bits shown as 1 must always be written to 1. Note: Shaded bits are recommended to only be controlled by firmware or factory test.

6.5 MCU parameter registers

The 64 bytes of parameter registers are located at addresses $0050 through $008F. These registers are powered up at all times and may be used to store temporary or history data during the times that the MCU is in any of the STOP modes. The parameter register at $008F is used by the firmware for interrupt flags.

6.6 MCU RAM

The FXTH87E includes static RAM. The locations in RAM below $0100 can be accessed using the more efficient direct addressing mode, and any single bit in this area can be accessed with the bit-manipulation instructions (BCLR, BSET, BRCLR, and BRSET). Locating the most frequently accessed program variables in this area of RAM is preferred. The RAM retains data when the MCU is in low-power WAIT, or STOP4 modes. At power- on or after wakeup from STOP1, the contents of RAM are not initialized. RAM data is unaffected by any reset provided that the supply voltage does not drop below the minimum value for RAM retention (VRAM).

Section 6.8 "Security" for a detailed description of the security feature.

6.7 FLASH

Family Reference Manual, Volume I, NXP document number HCS08RMV1/D.

6.7.1 Features

  • User Program FLASH Size — 8192 bytes (16 pages of 512 bytes each)
  • Single power supply program and erase
  • Command interface for fast program and erase operation
  • Up to 100,000 program/erase cycles at typical voltage and temperature
  • Flexible FLASH protection
  • Security feature for FLASH and RAM
  • Auto power-down for low-frequency read accesses

6.7.2 Program and erase times

command state machine and enabling and disabling of program and erase voltages. Table 13. Program and erase times

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 Parameter Cycles of FCLK Time if FCLK = 200 kHz Page erase 4000 20 ms Mass erase 20,000 100 ms [1] Excluding start/end overhead

6.7.3 Program and erase command execution

The steps for executing any of the commands are listed below. The FCDIV register must be initialized and any error flags cleared before beginning command execution. The command execution steps are: 1. Write a data value to an address in the FLASH array. The address and data information from this write is latched into the FLASH interface. This write is a required first step in any command sequence. For erase and blank check commands, the value of the data is not important. For page erase commands, the address may be any address in the 512-byte page of FLASH to be erased. For mass erase and blank check commands, the address can be any address in the FLASH memory. Whole pages of 512 bytes are the smallest block of FLASH that may be erased. Do not program any byte in the FLASH more than once after a successful erase operation. Reprogramming bits to a byte which is already programmed is not allowed without first erasing the page in which the byte resides or mass erasing the entire FLASH memory. Programming without first erasing may disturb data stored in the FLASH. 2. Write the command code for the desired command to FCMD. The five valid commands are blank check (0x05), byte program (0x20), burst program (0x25), page erase (0x40), and mass erase (0x41). The command code is latched into the command buffer. 3. Write a 1 to the FCBEF bit in FSTAT to clear FCBEF and launch the command (including its address and data information). A partial command sequence can be aborted manually by writing a 0 to FCBEF any time after the write to the memory array and before writing the 1 that clears FCBEF and launches the complete command. Aborting a command in this way sets the FACCERR access error flag which must be cleared before starting a new command. A strictly monitored procedure must be obeyed or the command will not be accepted. This minimizes the possibility of any unintended changes to the FLASH memory contents. The command complete flag (FCCF) indicates when a command is complete. The command sequence must be completed by clearing FCBEF to launch the command. Figure 9 is a flowchart for executing all of the commands except for burst programming. The FCDIV register must be initialized before using any FLASH commands. This must be done only once following a reset.

6.7.4 Burst program execution

The burst program command is used to program sequential bytes of data in less time than would be required using the standard program command. This is possible because the high voltage to the FLASH array does not need to be disabled between program operations. Ordinarily, when a program or erase command is issued, an internal charge pump associated with the FLASH memory must be enabled to supply high voltage to the array. Upon completion of the command, the charge pump is turned off. When a burst program command is issued, the charge pump is enabled and then remains enabled after completion of the burst program operation if these two conditions are met:

  • The next burst program command has been queued before the current program operation has completed.
  • The next sequential address selects a byte on the same physical row as the current byte being programmed. A row of FLASH memory consists of 64 bytes. A byte within a row is selected by addresses A5 through A0. A new row begins when addresses A5 through A0 are all zero. The first byte of a series of sequential bytes being programmed in burst mode will take the same amount of time to program as a byte programmed in standard mode. Subsequent bytes will program in the burst program time provided that the conditions above are met. In the case the next sequential address is the beginning of a new row, the program time for that byte will be the standard time instead of the burst time. This is because the high voltage to the array must be disabled and then enabled again. If a new burst command has not been queued before the current command completes, then the charge pump will be disabled and high voltage removed from the array. Start Write to FLASH, to buffer address, and data Write command to FCMD No YesFPVIOL or FACCERR? Write 1 to FCBEF to launch command and clear FCBEF (2) 0 FCCF? ERROR exit Done Note 2: Wait at least four bus cycles before checking FCBEF or FCCF. 0FACCERR? Clear error Write to FCDIV (1) Note 1: Required only once after reset. aaa-027998 FLASH PROGRAM AND ERASE FLOW

Figure 9. FLASH program and erase flowchart

Write to FCDIV (1) Note 1: Required only once after reset. Figure 10. FLASH burst program flowchart

6.7.5 Access errors

An access error occurs whenever the command execution protocol is violated. before any command can be processed.

  • Writing to a FLASH address before the internal FLASH clock frequency has been set by writing to the FCDIV register
  • Writing to a FLASH address while FCBEF is not set (A new command cannot be started until the command buffer is empty.)
  • Writing a second time to a FLASH address before launching the previous command (There is only one write to FLASH for every command.)
  • Writing a second time to FCMD before launching the previous command (There is only one write to FCMD for every command.)
  • Writing to any FLASH control register other than FCMD after writing to a FLASH address
  • Writing any command code other than the five allowed codes (0x05, 0x20, 0x25, 0x40, or 0x41) to FCMD
  • Accessing (read or write) any FLASH control register other than the write to FSTAT (to clear FCBEF and launch the command) after writing the command to FCMD.
  • The MCU enters STOP mode while a program or erase command is in progress (The command is aborted.)
  • Writing the byte program, burst program, or page erase command code (0x20, 0x25, or 0x40) with a BACKGROUND DEBUG command while the MCU is secured (the BACKGROUND DEBUG controller can only do blank check and mass erase commands when the MCU is secure.)
  • Writing 0 to FCBEF to cancel a partial command.

6.7.6 FLASH block protection

last address of FLASH, 0xFFFF. (see Section 6.9.4). must be programmed into NVPROT to protect addresses 0xE000 through 0xFFFF. Figure 11. Block Protection Mechanism even if MCU power is lost in the middle of an erase and reprogram operation.

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019

6.7.7 Vector redirection

Note: Not recommended for TPMS applications where NXP firmware has been included in the final image. Whenever any block protection is enabled, the reset and interrupt vectors will be protected. Vector redirection allows users to modify interrupt vector information without unprotecting boot loader and reset vector space. Vector redirection is enabled by programming the FNORED bit in the NVOPT register located at address 0xFFBF to zero. For redirection to occur, at least some portion but not all of the FLASH memory must be block protected by programming the NVPROT register located at address 0xFFBD. All of the interrupt vectors (memory locations 0xFFC0–0xFFFD) are redirected, though the reset vector (0xFFFE:FFFF) is not. For example, if 512 bytes of FLASH are protected, the protected address region is from 0xFE00 through 0xFFFF. The interrupt vectors (0xFFC0–0xFFFD) are redirected to the locations 0xFDC0–0xFDFD. Now, if an SPI interrupt is taken for instance, the values in the locations 0xFDE0:FDE1 are used for the vector instead of the values in the locations 0xFFE0:FFE1. This allows the user to reprogram the unprotected portion of the FLASH with new program code including new interrupt vector values while leaving the protected area, which includes the default vector locations, unchanged.

6.8 Security

The FXTH87E includes circuitry to prevent unauthorized access to the contents of FLASH and RAM memory. When security is engaged, FLASH and RAM are considered secure resources. Direct-page registers, high-page registers, and the BACKGROUND DEBUG controller are considered unsecured resources. Programs executing within secure memory have normal access to any MCU memory locations and resources. Attempts to access a secure memory location with a program executing from an unsecured memory space or through the BACKGROUND DEBUG interface are blocked (writes are ignored and reads return all 0s). Security is engaged or disengaged based on the state of nonvolatile register bits SEC[1:0] in the FOPT register. During reset, the contents of the nonvolatile location NVOPT are copied from FLASH into the working FOPT register in high-page register space. A user engages security by programming the NVOPT location, which can be done at the same time the FLASH memory is programmed. The SEC[1:0] = 1 0 state disengages security and the 0 0, 0 1 and 1 1 states engage security. At production, NXP programs the NVOPT SEC[1:0] = 1 0, which keeps the device unsecured. In this case, note that SEC[0] is programmed to 0 and it is not possible to reprogram it to 1 without first erasing the entire memory page. Notice the erased state of SEC[1:0] = 1 1 secures the device. During development, whenever the FLASH is erased, it is good practice to immediately program the NVOPT SEC[0] = 0, such that SEC[1:0] = 1 0. This would allow the MCU to remain unsecured after a subsequent reset. The on-chip debug module cannot be enabled while the MCU is secure. The separate BACKGROUND DEBUG controller can still be used for background memory access commands, but the MCU cannot enter ACTIVE BACKGROUND mode except by holding BKGD/MS low at the rising edge of reset. A user can choose to allow or disallow a security unlocking mechanism through an 8-byte backdoor security key. If the nonvolatile KEYEN bit in NVOPT/FOPT is 0, the backdoor key is disabled and there is no way to disengage security without completely erasing all FLASH locations. If KEYEN is 1, a secure user program can temporarily disengage security by:

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 1. Writing 1 to KEYACC in the FCNFG register. This makes the FLASH module interpret writes to the backdoor comparison key locations (NVBACKKEY through NVBACKKEY +7) as values to be compared against the key rather than as the first step in a FLASH program or erase command. 2. Writing the user-entered key values to the NVBACKKEY through NVBACKKEY+7 locations. These writes must be done in order starting with the value for NVBACKKEY and ending with NVBACKKEY+7. STHX must not be used for these writes because these writes cannot be done on adjacent bus cycles. User software normally would get the key codes from outside the MCU system through a communication interface such as a serial I/O. 3. Writing 0 to KEYACC in the FCNFG register. If the 8-byte key that was just written matches the key stored in the FLASH locations, SEC[1:0] are automatically changed to 1 0 and security will be disengaged until the next reset. The security key can be written only from secure memory (either RAM or FLASH), so it cannot be entered through BACKGROUND commands without the cooperation of a secure user program. The backdoor comparison key (NVBACKKEY through NVBACKKEY+7) is located in FLASH memory locations in the nonvolatile register space so users can program these locations exactly as they would program any other FLASH memory location. The nonvolatile registers are in the same 512-byte block of FLASH as the reset and interrupt vectors, so block protecting that space also block protects the backdoor comparison key. Block protects cannot be changed from user application programs, so if the vector space is block protected, the backdoor security key mechanism cannot permanently change the block protect, security settings, or the backdoor key. Security can always be disengaged through the BACKGROUND DEBUG interface by taking these steps: 1. Disable any block protections by writing FPROT. FPROT can be written only with BACKGROUND DEBUG commands, not from application software. 2. Mass erase FLASH if necessary. 3. Blank check FLASH. Provided FLASH is completely erased, security is disengaged until the next reset. To avoid returning to secure mode after the next reset, program NVOPT so SEC[1:0] = 1 0. Note: Enabling the security feature disables NXP ability to perform failure analysis without first completely erasing all flash memory contents. If the security feature is implemented, customer shall be responsible for providing to NXP unsecured parts for any failure analysis to begin or supplying the entire contents of the device flash memory data as part of the return process, to allow NXP to erase and subsequently restore the device to its original condition.

6.9 FLASH registers and control bits

The FLASH module has nine 8-bit registers in the high-page register space, three locations in the nonvolatile register space in FLASH memory which are copied into three corresponding high-page control registers at reset. There is also an 8-byte comparison key in FLASH memory. Refer to Table 12 and Table 13 for the absolute address assignments for all FLASH registers. This section refers to registers and control bits only by their names. A NXP Semiconductor-provided equate or header file normally is used to translate these names into the appropriate absolute addresses.

6.9.1 FLASH clock divider register (FCDIV)

Table 14. FLASH clock divider register (FCDIV) (address $1820) Table 15. FCDIV register field descriptions set regardless of the data written.

0 FCDIV has not been written since reset; erase and program operations disabled for FLASH

1 FCDIV has been written since reset; erase and program operations enabled for FLASH

0 Clock input to the FLASH clock divider is the bus rate clock

1 Clock input to the FLASH clock divider is the bus rate clock divided by 8

complete an erase or program operation.

  • if PRDIV8 = 0 — fFCLK = fBUS ÷ ([DIV5:DIV0] + 1)
  • if PRDIV8 = 1 — fFCLK = fBUS ÷ (8 × ([DIV5:DIV0] + 1)) Table 16 shows the appropriate values for PRDIV8 and DIV5:DIV0 for selected bus frequencies.

Table 16. FLASH clock divider settings

10 MHz 0 49 200 kHz 5 μs

8 MHz 0 39 200 kHz 5 μs

4 MHz 0 19 200 kHz 5 μs

2 MHz 0 9 200 kHz 5 μs

1 MHz 0 4 200 kHz 5 μs

6.9.2 FLASH options register (FOPT and NVOPT)

Table 17. FLASH options register (FOPT) (address $1821) Reset This register is loaded from nonvolatile location NVOPT during reset. Table 18. FOPT register field descriptions about the backdoor key mechanism, refer to Section 6.8 "Security".

0 No backdoor key access allowed

1 If user firmware writes an 8-byte value that matches the nonvolatile backdoor key (NVBACKKEY through

Vector Redirection Disable — When this bit is 1, then vector redirection is disabled.

0 Vector redirection enabled

1 Vector redirection disabled

Security State Code — This 2-bit field determines the security state of the MCU as shown in Table 19. or a successful blank check of FLASH. Table 19. Security states

6.9.3 FLASH configuration register (FCNFG)

Table 20. FLASH configuration register (FCNFG) (address $1823) Table 21. FCNFG register field descriptions information about the backdoor key mechanism, refer to Section 6.8 "Security".

0 Writes to 0xFFB0–0xFFB7 are interpreted as the start of a FLASH programming or erase command

1 Writes to NVBACKKEY (0xFFB0–0xFFB7) are interpreted as comparison key writes

6.9.4 FLASH protection register (FPROT and NVPROT)

commands can write to FPROT. Table 22. FLASH protection register (FPROT) (address $1824) Reset This register is loaded from nonvolatile location NVPROT during reset. [1] Background commands can be used to change the contents of these bits in FPROT. Table 23. FPROT register field descriptions

0 FLASH block specified by FPS[7:1] is block protected (program and erase not allowed)

1 No FLASH block is protected

6.9.5 FLASH status register (FSTAT)

meanings that are discussed in the bit descriptions. Table 24. FLASH status register (FSTAT) (address $1825) Table 25. FSTAT register field descriptions to the array for programming. Only burst program commands can be buffered.

0 Command buffer is full (not ready for additional commands)

1 A new burst program command can be written to the command buffer

to FCBEF to register a command). Writing to FCCF has no meaning or effect.

0 Command in progress

1 All commands complete

is cleared by writing a 1 to FPVIOL.

0 No protection violation

1 An attempt was made to erase or program a protected location

0 No access error

1 An access error has occurred

to write a new valid command. Writing to FBLANK has no meaning or effect.

0 After a blank check command is completed and FCCF = 1, FBLANK = 0 indicates the FLASH array is not

1 After a blank check command is completed and FCCF = 1, FBLANK = 1 indicates the FLASH array is

6.9.6 FLASH command register (FCMD)

Only five command codes are recognized in normal user modes as shown in Table 27. programming and erase operations. Table 26. FLASH command register (FCMD) (address $1826) Table 27. FLASH commands All other command codes are illegal and generate an access error. It is not necessary to perform a blank check command after a mass erase operation. Only blank check is required as part of the security unlocking mechanism.

7 Reset, interrupts and system configuration

systems, but are part of the system control logic.

7.1 Features

  • Multiple sources of reset for flexible system configuration and reliable operation
  • Reset status register (SRS) to indicate source of most recent reset
  • Separate interrupt vectors for each module (reduces polling overhead)

7.2 MCU reset

  • Power-on reset (POR)
  • Low-voltage detect (LVD)
  • Computer operating properly (COP) timer
  • Periodic hardware reset (PRST)
  • Illegal opcode detect
  • Illegal address detect
  • BACKGROUND DEBUG forced reset Each of these sources has an associated bit in the system reset status register with the exception of the BACKGROUND DEBUG forced reset and the periodic hardware reset, PRST, that is indicated by the PRF bit in the PWUCS1 register.

7.3 Computer Operating Properly (COP) Watchdog

value to the address of SRS. This write does not affect the data in the read-only SRS. Table 28. COP watchdog timeout period

may be used as a substitute.

7.4 SIM test register (SIMTST)

Table 29. SIM test register (SIMTST) (address $180F)

Table 30. SIMTST register field descriptions reserved Reserved Bit — These bits are reserved for factory trim and should not be altered by the user. to 0x06 at each wakeup cycle. reserved Reserved Bit — These bits are reserved for factory trim and should not be altered by the user.

1 TR module is outside the TREARM temperature range and will restart the MCU if the TRE bit is set and

temperature falls back within the TRESET temperature range.

0 TR module is within the TRESET temperature range and the MCU cannot be armed to restart when

temperature falls back to the TRESET range. The TRE bit cannot be set.

7.5 Interrupts

also generate an SWI under certain circumstances. logic 1 to enable the interrupt. The I bit in the CCR must be a logic 0 to allow interrupts.

  • Saving the CPU registers on the stack
  • Setting the I bit in the CCR to mask further interrupts
  • Fetching the interrupt vector for the highest-priority interrupt that is currently pending
  • Filling the instruction queue with the first three bytes of program information starting from the address fetched from the interrupt vector locations While the CPU is responding to the interrupt, the I bit is automatically set to avoid the possibility of another interrupt interrupting the ISR itself (this is called nesting of interrupts). Normally, the I bit is restored to 0 when the CCR is restored from the value stacked on entry to the ISR. In rare cases, the I bit may be cleared inside an ISR (after clearing the status flag that generated the interrupt) so that other interrupts can be serviced without waiting for the first service routine to finish. This practice is not recommended for anyone other than the most experienced programmers because it can lead to subtle program errors that are difficult to debug. The interrupt service routine ends with a return-from-interrupt (RTI) instruction which restores the CCR, A, X, and PC registers to their pre interrupt values by reading the previously saved information off the stack. When two or more interrupts are pending when the I bit is cleared, the highest priority source is serviced first.

7.5.1 Interrupt stack frame

in the main program that would have executed next if the interrupt had not occurred. serviced after completion of the current ISR.

  • High byte (H) of index register is not automatically stacked.

Figure 12. Interrupt stack frame

7.5.2 Vector summary

process latency for each interrupt will be described in Section 16 "Firmware".

regarding firmware and disabled interrupts. Table 31. Vector summary valid wake ID has been received. a carrier present for the required time. decode mode when an error is detected. has been successfully received. buffer has been completely sent. transmission error detected. selected event for channel 1 occurs. selected event for channel 0 occurs. wakeup time interval has elapsed.

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 Vector Priority Vector No. Jump Table Vector Addr (High/Low) Vector Name Module Source Flags Enables Description 2 $DFFA - $DFFB Reserved 1 $DFFC - $DFFD Vswi SWI opcode — — Interrupt from the CPU when an SWI instruction has been executed. Sys Ctrl - POR — — Reset from power on sequence. Sys Ctrl - PRF PRF PRST[5:0] Reset from PWU when the reset interval elapsed. Sys Ctrl - COP — COPE Reset when COP watchdog times out. Sys Ctrl - LVD — LVDRE Reset from the LVD when the supply voltage has dropped below the LVD threshold. Temp Restart — TRE Reset when the temperature falls below the temperature restart threshold Illegal opcode — — Reset from the CPU when trying to execute an illegal opcode. 0 $DFFE -$DFFF Vreset Illegal address — — Reset from the CPU when trying to access an illegal address.

7.6 Low-Voltage Detect (LVD) System

The FXTH87E includes a system to detect low voltage conditions in order to protect memory contents and control MCU system states during supply voltage variations. The system is comprised of a power-on reset (POR) circuit and an LVD circuit with a user selectable trip voltage, either high (VLVDH) or low (VLVDL). The LVD circuit is enabled when LVDE in SPMSC1 is high and the trip voltage is selected by LVDV in SPMSC3. The LVD is disabled upon entering any of the STOP modes unless the LVDSE bit is set. If LVDSE and LVDE are both set, then the MCU cannot enter STOP1.

7.6.1 Power-on reset operation

When power is initially applied to the FXTH87E, or when the supply voltage drops below the VPOR level, the POR circuit will cause a reset condition. As the supply voltage rises, the LVD circuit will hold the chip in reset until the supply has risen above the level determined by LVDV bit. Both the POR bit and the LVD bit in SRS are set following a POR.

7.6.2 LVD reset operation

The LVD can be configured to generate a reset upon detection of a low voltage condition has occurred by setting LVDRE to 1 when the supply voltage has fallen below the level determined by LVDV bit. After an LVD reset has occurred, the LVD system will hold the FXTH87E in reset until the supply voltage has risen above the level determined by LVDV bit. The threshold for falling and rising differ by a small amount of hysteresis. The LVD bit in the SRS register is set following either an LVD reset or POR.

7.6.3 LVD interrupt operation

7.6.4 Low-Voltage Warning (LVW)

threshold for falling and rising differ by a small amount of hysteresis.

7.7 System clock control

bits are cleared by any MCU reset. Table 32. HFO frequency selections

7.8 Keyboard interrupts

general I/O pins as given in Table 33. Table 33. Keyboard interrupt assignments

0 PTA0 General I/O

1 PTA1 General I/O

2 PTA2 General I/O

3 PTA3 General I/O

7.9 Real-time interrupt

software control. The control bits for the RTI are shown in Table 34. Table 34. RTI Status/Control register (SRTISC) (address $1808) Table 35. SRTISC register field descriptions 0 Wakeup interrupt not generated or was previously acknowledged. 1 Wakeup interrupt generated. 0 Real-time interrupt request clock source is the LFO. 1 Real-time interrupt request clock source is the HFO (MCU must be in the RUN mode). RTIF Interrupt Enable — The RTIE bit enables RTI interrupts if written with a one. Reset clears this bit. RTI Interrupt Delay Selects — The RTIS[2:0] bits select the timing of the RTI interrupts as given in Table 36. Table 36. Real-time interrupt period

7.10 Temperature sensor and restart system

  1. The temperature restart wakeup is enabled by software following detection of an over

temperature condition using the temperature sensor connected to the ADC10.

  1. User software enables the temperature restart detector and then instructs the MCU to

enter STOP1 mode to halt execution during the out-of-range temperature condition.

  1. When the temperature crosses the temperature restart threshold back into the normal

the TRH bit in the SIMOPT1 register.

7.11 Reset, interrupt and system control registers and bits

page register space are related to reset and interrupt systems.

7.11.1 System Reset Status Register (SRS)

register. The reset state of these bits depends on what caused the MCU to reset. Table 37. System reset status register (SRS) (address $1800)

active at the time of reset will be cleared. Table 38. SRS register field descriptions indicate that the reset occurred while the internal supply was below the LVR threshold.

0 Reset not caused by POR

1 POR caused reset

when the device is in the STOP1 mode.

0 Reset not caused by external reset pin

1 Reset came from external reset pin

watchdog timer timing out. This reset source may be blocked by COPE = 0.

0 Reset not caused by COP timeout

1 Reset caused by COP timeout

opcode. The STOP instruction is considered illegal if STOP is disabled by STOPE = 0 in the SOPT register.

0 Reset not caused by an illegal opcode

1 Reset caused by an illegal opcode

at an unimplemented memory address.

0 Reset not caused by an illegal address

1 Reset caused by an illegal address

Programmable Wakeup — This bit indicates reset was caused by a PWU reset in RUN, WAIT, and STOP4. After STOP1 exit, PRF in PWUCSI indicates PWU was the source of a wakeup. voltage, an LVD reset will occur. This bit is also set by POR. 0 Reset not caused by LVD trip or POR. 1 Reset caused by LVD trip or POR. Unused Unused Bit — This bit always reads as a logical zero.

7.11.2 System Options Register 1 (SIMOPT1)

option register 1 as shown in Table 39. Table 39. System option register 1 (SIMOPT1) (address $1802) Table 40. SIMOPT1 register field descriptions write after reset is honored. Reset sets the COPE bit. write-once bit so that only the first write after reset is honored. This bit is cleared by an MCU reset. 0 Select the LFO oscillator output. bit is cleared by an MCU reset. power on after STOP exit. It is only initialized at the first power up. This bit can be written anytime. after being shutdown at either a very high or very low temperature. This bit is cleared by an MCU reset. 0 Temperature restart disabled. 1 Temperature restart enabled. 0 Temperature restart interrupts MCU on return from a very low temperature. 1 Temperature restart interrupts MCU on return from a very high temperature. 0 BKGD function disabled, PTA4 output-only enabled. 1 BKGD function enabled, PTA4 disabled.

7.11.3 System Operation Register 2 (SIMOPT2)

option register 2 as shown in Table 41. Table 41. System option register 2 (SIMOPT2) (address $1803) Table 42. SIMOPT2 register field descriptions period. These bits are write-once after power up. 0, see Section 11 "Timer Pulse-Width Module". 0 Select clock input driven by PTA2. 1 Select clock input driven by the LFO. Section 11 "Timer Pulse-Width Module". 0 Select RFM Dx clock source divided by 1. 1 Select RFM Dx clock source divided by 8. Bus Clock Select — Bus clock frequency selection by changing HFO FLL ratio as shown in Figure 2. reset and can be written at any time.

00 Bus Frequency = 4 MHz (HFO = 8 MHz)

01 Bus Frequency = 2 MHz (HFO = 4 MHz)

10 Bus Frequency = 1 MHz (HFO = 2 MHz)

7.11.4 System Power Management Status and Control 1 Register (SPMSC1)

Table 43. System power management status and control 1 register (SPMSC1) (address $1809) [1] Bit 1 is a reserved bit that must always be written to 0.

[2] This bit can be written only one time after reset. Additional writes are ignored. Table 44. SPMSC1 register field descriptions (write 1 to clear LVDF). Reads always return logic 0. Low-Voltage Detect Interrupt Enable — This read/write bit enables hardware interrupt requests for LVDF.

0 Hardware interrupt disabled (use polling)

1 Request a hardware interrupt when LVDF = 1

0 LVDF does not generate hardware resets

1 Force an MCU reset when LVDF = 1

voltage detect function operates when the MCU is in STOP mode.

0 Low-voltage detect disabled during STOP mode

1 Low-voltage detect enabled during STOP mode

operation of other bits in this register.

0 LVD logic disabled

1 LVD logic enabled

write should be a logical zero. reference for use by the ADC module on one of its internal channels.

0 Band gap buffer disabled

1 Band gap buffer enabled

7.11.5 System Power Management Status and Control 2 Register (SPMSC2)

This register is used to configure the STOP mode behavior of the MCU. Table 45. System power management status and control 2 register (SPMSC2) (address $180A) [1] This bit can be written only one time after reset. Additional writes are ignored.

Table 46. SPMSC2 register field descriptions Reserved Reserved Bits — These bits are reserved should not be altered by the user. Any read returns a logical zero. Power Down Flag — This read-only status bit indicates the MCU has recovered from STOP1 mode.

0 MCU has not recovered from STOP1 mode

1 MCU recovered from STOP1 mode

Reserved Reserved Bit — This bit is reserved should not be altered by the user. Any read returns a logical zero. PPDACK Partial Power Down Acknowledge — Writing a logic 1 to PPDACK clears the PDF bit.

0 Power down mode are disabled

1 Power down mode are enabled

write should be a logical zero.

7.11.6 System Power Management Status and Control 3 Register (SPMSC3)

Table 47. System power management status and control 3 register (SPMSC3) (address $180C) [1] LVWF will be set in the case when VSupply transitions below the trip point or after reset and VSupply is already below VLVW. Table 48. SPMSC3 register field descriptions Low-Voltage Warning Flag — The LVWF bit indicates the low voltage warning status.

0 Low-voltage warning not present

1 Low-voltage warning is present or was present

Low-Voltage Warning Acknowledge — The LVWF bit indicates the low voltage warning status. Writing a logic 1 to LVWACK clears LVWF to a logic 0 if a low voltage warning is not present. Low-Voltage Detect Voltage Select — The LVDV bit selects the LVD trip point voltage (VLVD).

0 Low-trip point selected (VLVD = VLVDL)

1 High-trip point selected (VLVD = VLVDH)

Low-Voltage Warning Voltage Select — The LVWV bit selects the LVW trip point voltage (VLVW).

0 Low-trip point selected (VLVW = VLVDL)

1 High-trip point selected (VLVW = VLVDH)

Reserved Reserved Bits — These bits are reserved should not be altered by the user. Any read returns a logical zero.

7.11.7 Free-Running Counter (FRC)

For additional information on the FRC, see Section 12.8 "Free-Running Counter (FRC)". STOP4, STOP3, and STOP1 modes, unless halted as defined below. Table 49. PMCT register (address $180B) Table 50. PMCT register field descriptions

1 Clears the counter value, for example, resets to 0x0000 (may also start at 0x0001 due to the inbound

0 Free-running-counter is halted in place. 1 Free-running-counter is released and begins/continues to increment.

0 Addresses $1808 and $1809 revert to the PMCRSC and PMCSC1 registers and the FRC remains

functioning as last controlled while FPAGE had been 1.

1 PMCT bits 7 and 5 functions as described above, and addresses $1808 and $1809 become the FRC_

TIMER[15:0] result registers holding the 16-bit free-running-counter value. Table 51. FRC_TIMER register, MSbyte and LSbyte (address $1808 and $1809)

7.11.7.1 Software handler requirements

  1. Disable all interrupt sources
  2. Control PMCT and/or read FRC_TIMER as needed
  3. Enable all interrupt sources.

7.11.7.2 Initialization recommendations

  1. Disable all interrupt sources
  2. Re-enable appropriate interrupt sources.

7.12 System STOP exit status register (SIMSES)

Table 52. SIM STOP exit status (SIMSES) (address $180D)

Table 53. SIMSES register field descriptions this bit is never overwritten. Keyboard Flag — This bit indicates that any keyboard pin caused the last exit from STOP mode.

0 Keyboard pin did not cause the last exit from STOP mode

1 Keyboard pin caused the last exit from STOP mode

IRQ Flag — This bit indicates that IRQ pin caused the last exit from STOP mode.

0 IRQ pin did not cause the last exit from STOP mode

1 IRQ pin caused the last exit from STOP mode

0 TR module did not cause the last exit from STOP mode

1 TR module caused the last exit from STOP mode

PWU Flag — This bit indicates that the PWU module caused the last exit from STOP mode.

0 PWU module did not cause the last exit from STOP mode

1 PWU module caused the last exit from STOP mode

LFR Flag — This bit indicates that the LFR module caused the last exit from STOP mode.

0 LFR module did not cause the last exit from STOP mode

1 LFR module caused the last exit from STOP mode

RFM Flag — This bit indicates that the RFM module caused the last exit from STOP mode.

0 RFM module did not cause the last exit from STOP mode

1 RFM module caused the last exit from STOP mode

8 General Purpose I/O

general use 5-bit port A and a 2-bit port B. devices disabled (PTxPEn = 0). Reading and writing of general purpose I/O is performed through the port data registers. The direction, either input or output, is controlled through the port data direction registers.

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 PTBPE[1:0] (pull enable) PTBDD[1:0] (data direction) KBIPE[3:0] (KBI pin enable) KBEDG[3:0] (KBI Edge Select) Pullup Pulldown 0 0 x x disabled x 1 0 x x enabled x x 1 x x disabled x The data direction control bit (PTxDDn) determines whether the output buffer for the associated pin is enabled, and also controls the source for port data register reads. The input buffer for the associated pin is always enabled unless the pin is enabled as an analog function. When a shared digital function is enabled for a pin, the output buffer is controlled by the shared function. However, the data direction register bit still controls the source for reads of the port data register. When a shared analog function is enabled for a pin, both the input and output buffers are disabled. A value of 0 is read for any port data bit where the bit is an input (PTxDDn = 0) and the input buffer is disabled. In general, whenever a pin is shared with both an alternate digital function and an analog function, the analog function has priority such that if both the digital and analog functions are enabled, the analog function controls the pin. It is a good programming practice to write to the port data register before changing the direction of a port pin to become an output. This ensures that the pin will not be driven momentarily with an old data value that happened to be in the port data register. An internal pullup device can be enabled for each port pin by setting the corresponding bit in one of the pullup enable registers (PTxPEn). The pullup device is disabled if the pin is configured as an output by the general purpose I/O control logic or any shared peripheral function regardless of the state of the corresponding pullup enable register bit. The pullup device is also disabled if the pin is controlled by an analog function.

8.1 Unused pin configuration

Any general purpose I/O pins which are not used in the application must be properly configured to avoid a floating input that could cause excessive supply current, IDD. When the device comes out of the reset state the NXP supplied firmware will not configure any of the general purpose I/O pins. Recommended configuration methods are: 1. Configure the general purpose I/O pin as an input (PTxDDn = 0) with the pin connected to the VDD source; use a pullup resistor of 10-51 kΩ to assure sufficient noise immunity. 2. Configure the general purpose I/O pin as an input (PTxDDn = 0) with the internal pullup activated (PTxPEn = 1) and leave the pin disconnected. 3. Configure the general purpose I/O pin as an output (PTxDDn = 1) and drive the pin low (PTxDn = 0) and leave the pin disconnected. In cases where GPIOs are directly connected to AVDD, VDD, AVSS, VSS or RVSS, user application should configure the GPIO as an input with the internal pull-up disabled, in order to prevent software code faults from causing excessive supply current states should these pins become outputs.

8.2 Pin behavior in STOP modes

  • In STOP1 mode, all internal registers including general purpose I/O control and data registers are powered off. Each of the pins assumes its default reset state (input buffer, output buffer and internal pullup disabled). Upon exit from STOP1, all pins must be reconfigured the same as if the MCU had been reset.
  • In STOP4 mode, all pin states are maintained because internal logic stays powered up. Upon recovery, all pin functions are the same as before entering STOP4.

8.3 General purpose I/O registers

8.4 Port A registers

Table 55. Port A data register (PTAD) (address $0000) Table 56. Port A data register field descriptions pins that are configured as outputs, reads return the last value written to this register. is driven out the corresponding MCU pin. configures all port pins as high-impedance inputs with pullups disabled. Note: PTA4 can be used as output-only. Table 57. Internal pullup enable for port A register (PTAPE) (address $0001)

Table 58. Port A register pullup enable field descriptions and the internal pullup devices are disabled. 0 Internal pullup device disabled for port A bit n. 1 Internal pullup device enabled for port A bit n. Table 59. Data direction for port A register (PTADD) (address $0003) Table 60. Port A data direction field descriptions 0 Input (output driver disabled) and reads return the pin value. only; therefore, bit 4 will always be 0.

8.5 Port B registers

block is disabled, port B pins operate as described here. Table 61. Port B data register (PTBD) (address $0004)

Table 62. Port B data register field descriptions B pins that are configured as outputs, reads return the last value written to this register. is driven out the corresponding MCU pin. configures all port pins as high-impedance inputs with pullups disabled. Table 63. Internal pullup enable for port B register (PTBPE) (address $0005) Table 64. Port B register pullup enable field descriptions and the internal pullup devices are disabled. 0 Internal pullup device disabled for port B bit n. 1 Internal pullup device enabled for port B bit n. Table 65. Data direction for port B register (PTBDD) (address $0007) Table 66. Port B data direction field descriptions 0 Input (output driver disabled) and reads return the pin value. 1 Output driver enabled for port B bit n and PTBDD reads return the contents of PTBDDn.

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019

9 Keyboard Interrupt

The FXTH87E has a KBI module with general purpose I/O pins.

9.1 Features

The KBI features include:

  • Up to four keyboard interrupt pins with individual pin enable bits.
  • Each keyboard interrupt pin is programmable as falling edge (or rising edge) only, or both falling edge and low level (or both rising edge and high level) interrupt sensitivity.
  • One software enabled keyboard interrupt.
  • Exit from low-power modes.

9.2 Modes of operation

This section defines the KBI operation in WAIT, STOP, and BACKGROUND DEBUG modes.

9.2.1 KBI in STOP modes

The KBI operates asynchronously in STOP4 mode if enabled before executing the STOP instruction. Therefore, an enabled KBI pin (KBPE[3:0]) can be used to bring the MCU out of STOP4 mode if the KBI interrupt is enabled (KBIE = 1). During STOP1 mode, the KBI is disabled. In some systems, the pins associated with the KBI may be sources of wakeup from STOP1, see the STOP modes section in the Section 5 "Modes of operation". Upon wakeup from STOP1 mode, the reset vector is taken but no interrupt is generated (even if interrupt enabled). The wake up is triggered when the pin is low (even with no edge), whatever the settings are (raising edge or falling edge). So in STOP1 as long as the pin is low the reset vector will be taken.

9.2.2 KBI in ACTIVE BACKGROUND mode

When the microcontroller is in ACTIVE BACKGROUND mode, the KBI will continue to operate normally.

9.3 Block diagram

The block diagram for the keyboard interrupt module is shown in Figure 15.

Figure 15. KBI block diagram

9.4 External signal description

The signal properties of KBI are shown in Table 67. Table 67. Signal properties

9.5 Register definitions

  • An 4-bit pin status and control register.
  • An 4-bit pin enable register.
  • An 4-bit edge select register.

9.5.1 KBI status and control register (KBISC)

KBISC contains the status flag and control bits, which are used to configure the KBI. Table 68. KBI status and control register (address $000C)

Table 69. KBISC register field descriptions 7:4 Unused register bits, always read 0. 0 No keyboard interrupt detected. 1 Keyboard interrupt detected. Keyboard Interrupt Enable — KBIE determines whether a keyboard interrupt is requested. 0 Keyboard interrupt request not enabled. 1 Keyboard interrupt request enabled. 0 Keyboard detects edges only. 1 Keyboard detects both edges and levels.

9.5.2 KBI pin enable register (KBIPE)

KBIPE contains the pin enable control bits. Table 70. KBI pin enable register (address $000D) Table 71. KBIPE register field descriptions Keyboard Pin Enables — Each of the KBIPEn bits enable the corresponding keyboard interrupt pin. 0 Pin not enabled as keyboard interrupt. 1 Pin enabled as keyboard interrupt.

9.5.3 KBI edge select register (KBIES)

KBIES contains the edge select control bits. Table 72. KBI edge select register (address $000E)

Table 73. KBIES register field descriptions level function of the corresponding pin).

9.6 Functional description

9.6.1 Edge only sensitivity

writing a 1 to KBACK in KBISC.

9.6.2 Edge and level sensitivity

9.6.3 KBI pullup/pulldown resistors

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 register is used to select whether the resistor is a pullup (KBEDG[3:0] = 0) or a pulldown (KBEDG[3:0] = 1).

9.6.4 KBI initialization

When a keyboard interrupt pin is first enabled it is possible to get a false keyboard interrupt flag. To prevent a false interrupt request during keyboard initialization, the user should do the following: 1. Mask keyboard interrupts by clearing KBIE in KBISC. 2. Enable the KBI polarity by setting the appropriate KBEDGn bits in KBIES. 3. If using internal pullup/pulldown device, configure the associated pullup enable bits in PTAPE[3:0]. 4. Enable the KBI pins by setting the appropriate KBIPE[3:0] bits in KBIPE. 5. Write to KBACK in KBISC to clear any false interrupts. 6. Set KBIE in KBISC to enable interrupts.

10 Central processing unit

10.1 Introduction

This section provides summary information about the registers, addressing modes, and instruction set of the CPU of the HCS08 Family. For a more detailed discussion, refer to the HCS08 Family Reference Manual, volume 1, NXP Semiconductor document order number HCS08RMV1/D. The HCS08 CPU is fully source- and object-code-compatible with the M68HC08 CPU. Several instructions and enhanced addressing modes were added to improve C compiler efficiency and to support a new BACKGROUND DEBUG system which replaces the monitor mode of earlier M68HC08 microcontrollers (MCU).

10.2 Features

Features of the HCS08 CPU include:

  • Object code fully upward-compatible with M68HC05 and M68HC08 Families
  • All registers and memory are mapped to a single 64-Kbyte address space
  • 16-bit stack pointer (any size stack anywhere in 64-Kbyte address space)
  • 16-bit index register (H:X) with powerful indexed addressing modes
  • 8-bit accumulator (A)
  • Many instructions treat X as a second general-purpose 8-bit register
  • Seven addressing modes: – Inherent — Operands in internal registers – Relative — 8-bit signed offset to branch destination – Immediate — Operand in next object code byte(s) – Direct — Operand in memory at 0x0000–0x00FF – Extended — Operand anywhere in 64-Kbyte address space – Indexed relative to H:X — Five submodes including auto-increment – Indexed relative to SP — Improves C efficiency dramatically
  • Memory-to-memory data move instructions with four address mode combinations
  • Overflow, half-carry, negative, zero, and carry condition codes support conditional branching on the results of signed, unsigned, and binary-coded decimal (BCD) operations
  • Efficient bit manipulation instructions
  • Fast 8-bit by 8-bit multiply and 16-bit by 8-bit divide instructions
  • STOP and WAIT instructions to invoke low-power operating modes

10.3 Programmer’s model and CPU registers

Figure 16 shows the five CPU registers. CPU registers are not part of the memory map. Figure 16. CPU registers

10.3.1 Accumulator (A)

various addressing modes to specify the address where data from A will be stored. Reset has no effect on the contents of the A accumulator.

10.3.2 Index register (H:X)

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 full 16-bit value in H:X as an index reference pointer; however, for compatibility with the earlier M68HC05 Family, some instructions operate only on the low-order 8-bit half (X). Many instructions treat X as a second general-purpose 8-bit register that can be used to hold 8-bit data values. X can be cleared, incremented, decremented, complemented, negated, shifted, or rotated. Transfer instructions allow data to be transferred from A or transferred to A where arithmetic and logical operations can then be performed. For compatibility with the earlier M68HC05 Family, H is forced to 0x00 during reset. Reset has no effect on the contents of X.

10.3.3 Stack pointer (SP)

This 16-bit address pointer register points at the next available location on the automatic last-in-first-out (LIFO) stack. The stack may be located anywhere in the 64-Kbyte address space that has RAM and can be any size up to the amount of available RAM. The stack is used to automatically save the return address for subroutine calls, the return address and CPU registers during interrupts, and for local variables. The AIS (add immediate to stack pointer) instruction adds an 8-bit signed immediate value to SP. This is most often used to allocate or deallocate space for local variables on the stack. SP is forced to 0x00FF at reset for compatibility with the earlier M68HC05 Family. HCS08 programs normally change the value in SP to the address of the last location (highest address) in on-chip RAM during reset initialization to free up direct page RAM (from the end of the on-chip registers to 0x00FF). The RSP (reset stack pointer) instruction was included for compatibility with the M68HC05 Family and is seldom used in new HCS08 programs because it only affects the low-order half of the stack pointer.

10.3.4 Program counter (PC)

The program counter is a 16-bit register that contains the address of the next instruction or operand to be fetched. During normal program execution, the program counter automatically increments to the next sequential memory location every time an instruction or operand is fetched. Jump, branch, interrupt, and return operations load the program counter with an address other than that of the next sequential location. This is called a change-of-flow. During reset, the program counter is loaded with the reset vector that is located at 0xFFFE and 0xFFFF. The vector stored there is the address of the first instruction that will be executed after exiting the reset state.

10.3.5 Condition code register (CCR)

The 8-bit condition code register contains the interrupt mask (I) and five flags that indicate the results of the instruction just executed. Bits 6 and 5 are set permanently to 1. The following paragraphs describe the functions of the condition code bits in general terms. For a more detailed explanation of how each instruction sets the CCR bits, refer to the HCS08 Family Reference Manual, volume 1, NXP Semiconductors document order number HCS08RMv1.

Figure 17. Condition code register Table 74. CCR register field descriptions

0 No overflow

1 Overflow

previous ADD or ADC on BCD operands to correct the result to a valid BCD value.

0 No carry between bits 3 and 4

1 Carry between bits 3 and 4

are disabled. CPU interrupts are enabled when the interrupt mask is cleared. service routine is executed.

0 Interrupts enabled

1 Interrupts disabled

most significant bit of the loaded or stored value was 1.

0 Non-negative result

1 Negative result

0 Non-zero result

1 Zero result

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 Field Description C Carry/Borrow Flag — The CPU sets the carry/borrow flag when an addition operation produces a carry out of bit 7 of the accumulator or when a subtraction operation requires a borrow. Some instructions — such as bit test and branch, shift, and rotate — also clear or set the carry/borrow flag.

0 No carry out of bit 7

1 Carry out of bit 7

10.4 Addressing modes

Addressing modes define the way the CPU accesses operands and data. In the HCS08, all memory, status and control registers, and input/output (I/O) ports share a single 64- Kbyte linear address space so a 16-bit binary address can uniquely identify any memory location. This arrangement means that the same instructions that access variables in RAM can also be used to access I/O and control registers or nonvolatile program space. Some instructions use more than one addressing mode. For instance, move instructions use one addressing mode to specify the source operand and a second addressing mode to specify the destination address. Instructions such as BRCLR, BRSET, CBEQ, and DBNZ use one addressing mode to specify the location of an operand for a test and then use relative addressing mode to specify the branch destination address when the tested condition is true. For BRCLR, BRSET, CBEQ, and DBNZ, the addressing mode listed in the instruction set tables is the addressing mode needed to access the operand to be tested, and relative addressing mode is implied for the branch destination.

10.4.1 Inherent addressing mode (INH)

In this addressing mode, operands needed to complete the instruction (if any) are located within CPU registers so the CPU does not need to access memory to get any operands.

10.4.2 Relative addressing mode (REL)

Relative addressing mode is used to specify the destination location for branch instructions. A signed 8-bit offset value is located in the memory location immediately following the opcode. During execution, if the branch condition is true, the signed offset is sign-extended to a 16-bit value and is added to the current contents of the program counter, which causes program execution to continue at the branch destination address.

10.4.3 Immediate addressing mode (IMM)

In immediate addressing mode, the operand needed to complete the instruction is included in the object code immediately following the instruction opcode in memory. In the case of a 16-bit immediate operand, the high-order byte is located in the next memory location after the opcode, and the low-order byte is located in the next memory location after that.

10.4.4 Direct addressing mode (DIR)

In direct addressing mode, the instruction includes the low-order eight bits of an address in the direct page (0x0000–0x00FF). During execution a 16-bit address is formed by concatenating an implied 0x00 for the high-order half of the address and the direct address from the instruction to get the 16-bit address where the desired operand is

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 located. This is faster and more memory efficient than specifying a complete 16-bit address for the operand.

10.4.5 Extended addressing mode (EXT)

In extended addressing mode, the full 16-bit address of the operand is located in the next two bytes of program memory after the opcode (high byte first).

10.4.6 Indexed addressing mode

Indexed addressing mode has seven variations including five that use the 16-bit H:X index register pair and two that use the stack pointer as the base reference.

10.4.6.1 Indexed, No Offset (IX)

This variation of indexed addressing uses the 16-bit value in the H:X index register pair as the address of the operand needed to complete the instruction.

10.4.6.2 Indexed, No Offset with Post Increment (IX+)

This variation of indexed addressing uses the 16-bit value in the H:X index register pair as the address of the operand needed to complete the instruction. The index register pair is then incremented (H:X = H:X + 0x0001) after the operand has been fetched. This addressing mode is only used for MOV and CBEQ instructions.

10.4.6.3 Indexed, 8-Bit Offset (IX1)

This variation of indexed addressing uses the 16-bit value in the H:X index register pair plus an unsigned 8-bit offset included in the instruction as the address of the operand needed to complete the instruction.

10.4.6.4 Indexed, 8-Bit Offset with Post Increment (IX1+)

This variation of indexed addressing uses the 16-bit value in the H:X index register pair plus an unsigned 8-bit offset included in the instruction as the address of the operand needed to complete the instruction. The index register pair is then incremented (H:X = H:X + 0x0001) after the operand has been fetched. This addressing mode is used only for the CBEQ instruction.

10.4.6.5 Indexed, 16-Bit Offset (IX2)

This variation of indexed addressing uses the 16-bit value in the H:X index register pair plus a 16-bit offset included in the instruction as the address of the operand needed to complete the instruction.

10.4.6.6 SP-Relative, 8-Bit Offset (SP1)

This variation of indexed addressing uses the 16-bit value in the stack pointer (SP) plus an unsigned 8-bit offset included in the instruction as the address of the operand needed to complete the instruction.

10.4.6.7 SP-Relative, 16-Bit Offset (SP2)

This variation of indexed addressing uses the 16-bit value in the stack pointer (SP) plus a 16-bit offset included in the instruction as the address of the operand needed to complete the instruction.

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019

10.5 Special operations

The CPU performs a few special operations that are similar to instructions but do not have opcodes like other CPU instructions. In addition, a few instructions such as STOP and WAIT directly affect other MCU circuitry. This section provides additional information about these operations.

10.5.1 Reset sequence

Reset can be caused by a power-on-reset (POR) event, internal conditions such as the COP (computer operating properly) watchdog, or by assertion of an external active-low reset pin. When a reset event occurs, the CPU immediately stops whatever it is doing (the MCU does not wait for an instruction boundary before responding to a reset event). For a more detailed discussion about how the MCU recognizes resets and determines the source, refer to Section 7 "Reset, interrupts and system configuration". The reset event is considered concluded when the sequence to determine whether the reset came from an internal source is done and when the reset pin is no longer asserted. At the conclusion of a reset event, the CPU performs a 6-cycle sequence to fetch the reset vector from 0xFFFE and 0xFFFF and to fill the instruction queue in preparation for execution of the first program instruction.

10.5.2 Interrupt sequence

When an interrupt is requested, the CPU completes the current instruction before responding to the interrupt. At this point, the program counter is pointing at the start of the next instruction, which is where the CPU should return after servicing the interrupt. The CPU responds to an interrupt by performing the same sequence of operations as for a software interrupt (SWI) instruction, except the address used for the vector fetch is determined by the highest priority interrupt that is pending when the interrupt sequence started. The CPU sequence for an interrupt is: 1. Store the contents of PCL, PCH, X, A, and CCR on the stack, in that order. 2. Set the I bit in the CCR. 3. Fetch the high-order half of the interrupt vector. 4. Fetch the low-order half of the interrupt vector. 5. Delay for one free bus cycle. 6. Fetch three bytes of program information starting at the address indicated by the interrupt vector to fill the instruction queue in preparation for execution of the first instruction in the interrupt service routine. After the CCR contents are pushed onto the stack, the I bit in the CCR is set to prevent other interrupts while in the interrupt service routine. Although it is possible to clear the I bit with an instruction in the interrupt service routine, this would allow nesting of interrupts (which is not recommended because it leads to programs that are difficult to debug and maintain). For compatibility with the earlier M68HC05 MCUs, the high-order half of the H:X index register pair (H) is not saved on the stack as part of the interrupt sequence. The user must use a PSHH instruction at the beginning of the service routine to save H and then use a PULH instruction just before the RTI that ends the interrupt service routine. It is not necessary to save H if you are certain that the interrupt service routine does not use any instructions or auto-increment addressing modes that might change the value of H.

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 The software interrupt (SWI) instruction is like a hardware interrupt except that it is not masked by the global I bit in the CCR and it is associated with an instruction opcode within the program so it is not asynchronous to program execution.

10.5.3 WAIT mode operation

The WAIT instruction enables interrupts by clearing the I bit in the CCR. It then halts the clocks to the CPU to reduce overall power consumption while the CPU is waiting for the interrupt or reset event that will wake the CPU from WAIT mode. When an interrupt or reset event occurs, the CPU clocks will resume and the interrupt or reset event will be processed normally. If a serial BACKGROUND command is issued to the MCU through the BACKGROUND DEBUG interface while the CPU is in WAIT mode, CPU clocks will resume and the CPU will enter ACTIVE BACKGROUND mode where other serial BACKGROUND commands can be processed. This ensures that a host development system can still gain access to a target MCU even if it is in WAIT mode.

10.5.4 STOP mode operation

Usually, all system clocks, including the crystal oscillator (when used), are halted during STOP mode to minimize power consumption. In such systems, external circuitry is needed to control the time spent in STOP mode and to issue a signal to wakeup the target MCU when it is time to resume processing. Unlike the earlier M68HC05 and M68HC08 MCUs, the HCS08 can be configured to keep a minimum set of clocks running in STOP mode. This optionally allows an internal periodic signal to wake the target MCU from STOP mode. When a host debug system is connected to the BACKGROUND DEBUG pin (BKGD) and the ENBDM control bit has been set by a serial command through the BACKGROUND interface (or because the MCU was reset into ACTIVE BACKGROUND mode), the oscillator is forced to remain active when the MCU enters STOP mode. In this case, if a serial BACKGROUND command is issued to the MCU through the BACKGROUND DEBUG interface while the CPU is in STOP mode, CPU clocks will resume and the CPU will enter ACTIVE BACKGROUND mode where other serial BACKGROUND commands can be processed. This ensures that a host development system can still gain access to a target MCU even if it is in STOP mode. Recovery from STOP mode depends on the particular HCS08 and whether the oscillator was stopped in STOP mode. Refer to the Section 5 "Modes of operation" for more details.

10.5.5 BGND instruction

The BGND instruction is new to the HCS08 compared to the M68HC08. BGND would not be used in normal user programs because it forces the CPU to stop processing user instructions and enter the ACTIVE BACKGROUND mode. The only way to resume execution of the user program is through reset or by a host debug system issuing a GO, TRACE1, or TAGGO serial command through the BACKGROUND DEBUG interface. Software-based breakpoints can be set by replacing an opcode at the desired breakpoint address with the BGND opcode. When the program reaches this breakpoint address, the CPU is forced to ACTIVE BACKGROUND mode rather than continuing the user program.

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019

10.6 HCS08 instruction set summary

10.6.1 Instruction set summary nomenclature

The nomenclature listed here is used in the instruction descriptions in Table 75.

10.6.2 Operators

( ) = Contents of register or memory location shown inside parentheses ← = Is loaded with (read: "gets") & = Boolean AND | = Boolean OR ⊕ = Boolean exclusive-OR × = Multiply ÷ = Divide : = Concatenate + = Add – = Negate (two’s complement)

10.6.3 CPU registers

A = Accumulator CCR = Condition code register H = Index register, higher order (most significant) 8 bits X = Index register, lower order (least significant) 8 bits PC = Program counter PCH = Program counter, higher order (most significant) 8 bits PCL = Program counter, lower order (least significant) 8 bits SP = Stack pointer

10.6.4 Memory and addressing

M = A memory location or absolute data, depending on addressing mode M:M + 0x0001 = A 16-bit value in two consecutive memory locations. The higher-order (most significant) 8 bits are located at the address of M, and the lower-order (least significant) 8 bits are located at the next higher sequential address.

10.6.5 Condition code register (CCR) bits

V = Two’s complement overflow indicator, bit 7 H = Half carry, bit 4 I = Interrupt mask, bit 3 N = Negative indicator, bit 2

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 Z = Zero indicator, bit 1 C = Carry/borrow, bit 0 (carry out of bit 7)

10.6.6 CCR activity notation

– = Bit not affected 0 = Bit forced to 0 1 = Bit forced to 1 Þ = Bit set or cleared according to results of operation U = Undefined after the operation

10.6.7 Machine coding notation

dd = Low-order 8 bits of a direct address 0x0000–0x00FF (high byte assumed to be 0x00) ee = Upper 8 bits of 16-bit offset ff = Lower 8 bits of 16-bit offset or 8-bit offset ii = One byte of immediate data jj = High-order byte of a 16-bit immediate data value kk = Low-order byte of a 16-bit immediate data value hh = High-order byte of 16-bit extended address ll = Low-order byte of 16-bit extended address rr = Relative offset

10.6.8 Source form

Everything in the source forms columns, except expressions in italic characters, is literal information that must appear in the assembly source file exactly as shown. The initial 3- to 5-letter mnemonic is always a literal expression. All commas, pound signs (#), parentheses, and plus signs (+) are literal characters. n — Any label or expression that evaluates to a single integer in the range 0–7 opr8i — Any label or expression that evaluates to an 8-bit immediate value opr16i — Any label or expression that evaluates to a 16-bit immediate value opr8a — Any label or expression that evaluates to an 8-bit value. The instruction treats this 8-bit value as the low order 8 bits of an address in the direct page of the 64-Kbyte address space (0x00xx). opr16a — Any label or expression that evaluates to a 16-bit value. The instruction treats this value as an address in the 64-Kbyte address space. oprx8 — Any label or expression that evaluates to an unsigned 8-bit value, used for indexed addressing oprx16 — Any label or expression that evaluates to a 16-bit value. Because the HCS08 has a 16-bit address bus, this can be either a signed or an unsigned value. rel — Any label or expression that refers to an address that is within –128 to +127 locations from the next address after the last byte of object code for the current

10.6.9 Address modes

Table 75. HCS08 instruction set summary

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 Effect on CCRSource Form Operation Description V H I N Z C Address Mode Opcode Operand Bus Cycles [1] AIX #opr8i Add Immediate Value (Signed) to Index Register (H:X) H:X ← (H:X) + (M) M is sign extended to a 16-bit value AND #opr8i AND opr8a AND opr16a AND oprx16,X AND oprx8,X AND ,X AND oprx16,SP AND oprx8,SP Logical AND A ← (A) & (M) 0 – – Þ Þ – IMM DIR EXT IX2 IX1 IX SP2 SP1 9ED4 9EE4 ii dd hh ll ee ff ff ee ff ff ASL opr8a ASLA ASLX ASL oprx8,X ASL ,X ASL oprx8,SP Arithmetic Shift Left (Same as LSL) b0b7 C 0 aaa-028006 Þ – – Þ Þ Þ DIR INH INH IX1 IX SP1 9E68 dd ff ff ASR opr8a ASRA ASRX ASR oprx8,X ASR ,X ASR oprx8,SP Arithmetic Shift Right b0b7 C aaa-028007 Þ – – Þ Þ Þ DIR INH INH IX1 IX SP1 9E67 dd ff ff BCC rel Branch if Carry Bit Clear Branch if (C) = 0 – – – – – – rel 24 rr 3 BCLR n,opr8a Clear Bit n in DIR (b0) DIR (b1) DIR (b2) DIR (b3) DIR (b4) DIR (b5) DIR (b6) DIR (b7) dd dd dd dd dd dd dd dd BCS rel Branch if Carry Bit Set (Same as BLO) Branch if (C) = 1 – – – – – – rel 25 rr 3 BEQ rel Branch if Equal Branch if (Z) = 1 – – – – – – rel 27 rr 3 BGE rel Branch if Greater Than or Equal To (Signed Operands) Branch if (N ⊕ V) = 90 rr 3

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 Effect on CCRSource Form Operation Description V H I N Z C Address Mode Opcode Operand Bus Cycles [1] BGND Enter ACTIVE BACK-GROUND if ENBDM = 1 Waits For and Processes BDM Commands Until GO, TRACE1, or TAGGO 82 5+ BGT rel Branch if Greater Than (Signed Operands) Branch if (Z) | (N ⊕ 92 rr 3 BHCC rel Branch if Half Carry Bit Clear Branch if (H) = 0 – – – – – – rel 28 rr 3 BHCS rel Branch if Half Carry Bit Set Branch if (H) = 1 – – – – – – rel 29 rr 3 BHI rel Branch if Higher Branch if (C) | (Z) = BHS rel Branch if Higher or Same (Same as BCC) Branch if (C) = 0 – – – – – – rel 24 rr 3 BIH rel Branch if IRQ Pin High Branch if IRQ pin = BIL rel Branch if IRQ Pin Low Branch if IRQ pin = BIT #opr8i BIT opr8a BIT opr16a BIT oprx16,X BIT oprx8,X BIT ,X BIT oprx16,SP BIT oprx8,SP Bit Test (A) & (M) (CCR Updated but Operands Not Changed) 0 – – Þ Þ – IMM DIR EXT IX2 IX1 IX SP2 SP1 9ED5 9EE5 ii dd hh ll ee ff ff ee ff ff BLE rel Branch if Less Than or Equal To (Signed Operands) Branch if (Z) | (N ⊕ 93 rr 3 BLO rel Branch if Lower (Same as BCS) Branch if (C) = 1 – – – – – – rel 25 rr 3 BLS rel Branch if Lower or Same Branch if (C) | (Z) = BLT rel Branch if Less Than (Signed Operands) Branch if (N ⊕ V ) = 91 rr 3 BMC rel Branch if Interrupt Mask Clear Branch if (I) = 0 – – – – – – rel 2C rr 3 BMI rel Branch if Minus Branch if (N) = 1 – – – – – – rel 2B rr 3 BMS rel Branch if Interrupt Mask Set Branch if (I) = 1 – – – – – – rel 2D rr 3

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 Effect on CCRSource Form Operation Description V H I N Z C Address Mode Opcode Operand Bus Cycles [1] BNE rel Branch if Not Equal Branch if (Z) = 0 – – – – – – rel 26 rr 3 BPL rel Branch if Plus Branch if (N) = 0 – – – – – – rel 2A rr 3 BRA rel Branch Always No Test – – – – – – rel 20 rr 3 BRCLR n,opr8a,rel Branch if Bit n in Memory Clear Branch if (Mn) = 0 – – – – – Þ DIR (b0) DIR (b1) DIR (b2) DIR (b3) DIR (b4) DIR (b5) DIR (b6) DIR (b7) dd rr dd rr dd rr dd rr dd rr dd rr dd rr dd rr BRN rel Branch Never Uses 3 Bus Cycles – – – – – – rel 21 rr 3 BRSET n,opr8a, rel Branch if Bit n in Memory Set Branch if (Mn) = 1 – – – – – Þ DIR (b0) DIR (b1) DIR (b2) DIR (b3) DIR (b4) DIR (b5) DIR (b6) DIR (b7) dd rr dd rr dd rr dd rr dd rr dd rr dd rr dd rr BSET n,opr8a Set Bit n in DIR (b0) DIR (b1) DIR (b2) DIR (b3) DIR (b4) DIR (b5) DIR (b6) DIR (b7) dd dd dd dd dd dd dd dd BSR rel Branch to Subroutine PC ← (PC) + 0x0002 push (PCL); SP ← (SP) – 0x0001 push (PCH); SP ← (SP) – 0x0001 PC ← (PC) + rel AD rr 5 CBEQ opr8a,rel CBEQA #opr8i,rel CBEQX #opr8i,rel CBEQ oprx8,X+, rel CBEQ ,X+,rel CBEQ oprx8,SP, rel Compare and Branch if Equal Branch if (A) = (M) Branch if (A) = (M) Branch if (X) = (M) Branch if (A) = (M) Branch if (A) = (M) Branch if (A) = (M) DIR IMM IMM IX1+ IX+ SP1 9E61 dd rr ii rr ii rr ff rr rr ff rr

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 Effect on CCRSource Form Operation Description V H I N Z C Address Mode Opcode Operand Bus Cycles [1] CLC Clear Carry Bit C ← 0 – – – – – 0 INH 98 1 CLI Clear Interrupt Mask Bit I ← 0 – – 0 – – – INH 9A 1 CLR opr8a CLRA CLRX CLRH CLR oprx8,X CLR ,X CLR oprx8,SP Clear M ← 0x00 A ← 0x00 X ← 0x00 H ← 0x00 M ← 0x00 M ← 0x00 M ← 0x00 0 – – 0 1 – DIR INH INH INH IX1 IX SP1 9E6F dd ff ff CMP #opr8i CMP opr8a CMP opr16a CMP oprx16,X CMP oprx8,X CMP ,X CMP oprx16,SP CMP oprx8,SP Compare Accumulator with Memory (A) – (M) (CCR Updated But Operands Not Changed) Þ – – Þ Þ Þ IMM DIR EXT IX2 IX1 IX SP2 SP1 9ED1 9EE1 ii dd hh ll ee ff ff ee ff ff COM opr8a COMA COMX COM oprx8,X COM ,X COM oprx8,SP Complement (One’s Complement) M ← (M)= 0xFF – (M) A ← (A) = 0xFF – (A) X ← (X) = 0xFF – (X) M ← (M) = 0xFF – (M) M ← (M) = 0xFF – (M) M ← (M) = 0xFF – (M) 0 – – Þ Þ 1 DIR INH INH IX1 IX SP1 9E63 dd ff ff CPHX opr16a CPHX #opr16i CPHX opr8a CPHX oprx8,SP Compare Index Register (H:X) with Memory (H:X) – (M:M + 0x0001) (CCR Updated But Operands Not Changed) Þ – – Þ Þ Þ EXT IMM DIR SP1 9EF3 hh ll jj kk dd ff CPX #opr8i CPX opr8a CPX opr16a CPX oprx16,X CPX oprx8,X CPX ,X CPX oprx16,SP CPX oprx8,SP Compare X (Index Register Low) with Memory (X) – (M) (CCR Updated But Operands Not Changed) Þ – – Þ Þ Þ IMM DIR EXT IX2 IX1 IX SP2 SP1 9ED3 9EE3 ii dd hh ll ee ff ff ee ff ff

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 Effect on CCRSource Form Operation Description V H I N Z C Address Mode Opcode Operand Bus Cycles [1] DAA Decimal Adjust Accumulator After ADD or ADC of BCD Values (A)10 U – – Þ Þ Þ INH 72 1 DBNZ opr8a,rel DBNZA rel DBNZX rel DBNZ oprx8,X,rel DBNZ ,X,rel DBNZ oprx8,SP, rel Decrement and Branch if Not Zero Decrement A, X, or M Branch if (result) ≠ 0 DBNZX Affects X Not H DIR INH INH IX1 IX SP1 9E6B dd rr rr rr ff rr rr ff rr DEC opr8a DECA DECX DEC oprx8,X DEC ,X DEC oprx8,SP Decrement M ← (M) – 0x01 A ← (A) – 0x01 X ← (X) – 0x01 M ← (M) – 0x01 M ← (M) – 0x01 M ← (M) – 0x01 Þ – – Þ Þ – DIR INH INH IX1 IX SP1 9E6A dd ff ff DIV Divide A ← (H:A) ÷ (X) H ← Remainder – – – – Þ Þ INH 52 6 EOR #opr8i EOR opr8a EOR opr16a EOR oprx16,X EOR oprx8,X EOR ,X EOR oprx16,SP EOR oprx8,SP Exclusive OR Memory with Accumulator IMM DIR EXT IX2 IX1 IX SP2 SP1 9ED8 9EE8 ii dd hh ll ee ff ff ee ff ff INC opr8a INCA INCX INC oprx8,X INC ,X INC oprx8,SP Increment M ← (M) + 0x01 A ← (A) + 0x01 X ← (X) + 0x01 M ← (M) + 0x01 M ← (M) + 0x01 M ← (M) + 0x01 Þ – – Þ Þ – DIR INH INH IX1 IX SP1 9E6C dd ff ff JMP opr8a JMP opr16a JMP oprx16,X JMP oprx8,X JMP ,X Jump PC ← Jump DIR EXT IX2 IX1 IX BC CC DC EC FC dd hh ll ee ff ff

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 Effect on CCRSource Form Operation Description V H I N Z C Address Mode Opcode Operand Bus Cycles [1] JSR opr8a JSR opr16a JSR oprx16,X JSR oprx8,X JSR ,X Jump to Subroutine PC ← (PC) + n (n = 1, 2, or 3) Push (PCL); SP ← (SP) – 0x0001 Push (PCH); SP ← (SP) – 0x0001 PC ← Unconditional Address DIR EXT IX2 IX1 IX BD CD DD ED FD dd hh ll ee ff ff LDA #opr8i LDA opr8a LDA opr16a LDA oprx16,X LDA oprx8,X LDA ,X LDA oprx16,SP LDA oprx8,SP Load Accumulator from Memory IMM DIR EXT IX2 IX1 IX SP2 SP1 9ED6 9EE6 ii dd hh ll ee ff ff ee ff ff LDHX #opr16i LDHX opr8a LDHX opr16a LDHX ,X LDHX oprx16,X LDHX oprx8,X LDHX oprx8,SP Load Index Register (H:X) from Memory H:X ← (M:M + 0x0001) 0 – – Þ Þ – IMM DIR EXT IX IX2 IX1 SP1 9EAE 9EBE 9ECE 9EFE jj kk dd hh ll ee ff ff ff LDX #opr8i LDX opr8a LDX opr16a LDX oprx16,X LDX oprx8,X LDX ,X LDX oprx16,SP LDX oprx8,SP Load X (Index Register Low) from Memory IMM DIR EXT IX2 IX1 IX SP2 SP1 AE BE CE DE EE FE 9EDE 9EEE ii dd hh ll ee ff ff ee ff ff LSL opr8a LSLA LSLX LSL oprx8,X LSL ,X LSL oprx8,SP Logical Shift Left (Same as ASL) C aaa-028008 Þ – – Þ Þ Þ DIR INH INH IX1 IX SP1 9E68 dd ff ff LSR opr8a LSRA LSRX LSR oprx8,X LSR ,X LSR oprx8,SP Logical Shift Right C aaa-028009 Þ – – 0 Þ Þ DIR INH INH IX1 IX SP1 9E64 dd ff ff

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 Effect on CCRSource Form Operation Description V H I N Z C Address Mode Opcode Operand Bus Cycles [1] MOV opr8a,opr8a MOV opr8a,X+ MOV #opr8i,opr8 a MOV ,X+,opr8a Move (M)destination ← (M)source H:X ← (H:X) + 0x0001 in IX+/DIR and DIR/IX + Modes 0 – – Þ Þ – DIR/DIR DIR/IX+ IMM/DIR IX+/DIR dd dd dd ii dd dd MUL Unsigned multiply X:A ← (X) × (A) – 0 – – – 0 INH 42 5 NEG opr8a NEGA NEGX NEG oprx8,X NEG ,X NEG oprx8,SP Negate (Two’s Complement) M ← – (M) = 0x00 – (M) A ← – (A) = 0x00 – (A) X ← – (X) = 0x00 – (X) M ← – (M) = 0x00 – (M) M ← – (M) = 0x00 – (M) M ← – (M) = 0x00 – (M) Þ – – Þ Þ Þ DIR INH INH IX1 IX SP1 9E60 dd ff ff NOP No Operation Uses 1 Bus Cycle – – – – – – INH 9D 1 NSA Nibble Swap Accumulator A ← (A[3:0]:A[7:4]) – – – – – – INH 62 1 ORA #opr8i ORA opr8a ORA opr16a ORA oprx16,X ORA oprx8,X ORA ,X ORA oprx16,SP ORA oprx8,SP Inclusive OR Accumulator and Memory IMM DIR EXT IX2 IX1 IX SP2 SP1 AA BA CA DA EA FA 9EDA 9EEA ii dd hh ll ee ff ff ee ff ff PSHA Push Accumulator onto Stack Push (A); SP ← 87 2 PSHH Push H (Index Register High) onto Stack Push (H); SP ← 8B 2 PSHX Push X (Index Register Low) onto Stack Push (X); SP ← 89 2 PULA Pull Accumulator from Stack SP ← (SP + PULH Pull H (Index Register High) from Stack SP ← (SP + 0x0001); Pull (H) – – – – – – INH 8A 3

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 Effect on CCRSource Form Operation Description V H I N Z C Address Mode Opcode Operand Bus Cycles [1] PULX Pull X (Index Register Low) from Stack SP ← (SP + 0x0001); Pull (X) – – – – – – INH 88 3 ROL opr8a ROLA ROLX ROL oprx8,X ROL ,X ROL oprx8,SP Rotate Left through Carry aaa-028011 b0b7 C Þ – – Þ Þ Þ DIR INH INH IX1 IX SP1 9E69 dd ff ff ROR opr8a RORA RORX ROR oprx8,X ROR ,X ROR oprx8,SP Rotate Right through Carry aaa-028010 b0b7 C Þ – – Þ Þ Þ DIR INH INH IX1 IX SP1 9E66 dd ff ff RSP Reset Stack Pointer SP ← 0xFF (High Byte Not Affected) 9C 1 RTI Return from Interrupt SP ← (SP) + 0x0001; Pull (CCR) SP ← (SP) + 0x0001; Pull (A) SP ← (SP) + 0x0001; Pull (X) SP ← (SP) + 0x0001; Pull (PCH) SP ← (SP) + 0x0001; Pull (PCL) Þ Þ Þ Þ Þ Þ INH 80 9 RTS Return from Subroutine SP ← SP + 0x0001; Pull (PCH) SP ← SP + 0x0001; Pull (PCL) 81 6 SBC #opr8i SBC opr8a SBC opr16a SBC oprx16,X SBC oprx8,X SBC ,X SBC oprx16,SP SBC oprx8,SP Subtract with Carry A ← (A) – (M) – (C) Þ – – Þ Þ Þ IMM DIR EXT IX2 IX1 IX SP2 SP1 9ED2 9EE2 ii dd hh ll ee ff ff ee ff ff SEC Set Carry Bit C ← 1 – – – – – 1 INH 99 1 SEI Set Interrupt Mask Bit I ← 1 – – 1 – – – INH 9B 1

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 Effect on CCRSource Form Operation Description V H I N Z C Address Mode Opcode Operand Bus Cycles [1] STA opr8a STA opr16a STA oprx16,X STA oprx8,X STA ,X STA oprx16,SP STA oprx8,SP Store Accumulator in Memory DIR EXT IX2 IX1 IX SP2 SP1 9ED7 9EE7 dd hh ll ee ff ff ee ff ff STHX opr8a STHX opr16a STHX oprx8,SP Store H:X (Index Reg.) (M:M + 0x0001) ← (H:X) 0 – – Þ Þ – DIR EXT SP1 9EFF dd hh ll ff STOP Enable Interrupts: Stop Processing Refer to MCU Documentation I bit ← 0; Stop Processing – – 0 – – – INH 8E 2+ STX opr8a STX opr16a STX oprx16,X STX oprx8,X STX ,X STX oprx16,SP STX oprx8,SP Store X (Low

8 Bits of Index

Register) in Memory DIR EXT IX2 IX1 IX SP2 SP1 BF CF DF EF FF 9EDF 9EEF dd hh ll ee ff ff ee ff ff SUB #opr8i SUB opr8a SUB opr16a SUB oprx16,X SUB oprx8,X SUB ,X SUB oprx16,SP SUB oprx8,SP Subtract A ← (A) – (M) Þ – – Þ Þ Þ IMM DIR EXT IX2 IX1 IX SP2 SP1 9ED0 9EE0 ii dd hh ll ee ff ff ee ff ff SWI Software Interrupt PC ← (PC) + 0x0001 Push (PCL); SP ← (SP) – 0x0001 Push (PCH); SP ← (SP) – 0x0001 Push (X); SP ← (SP) – 0x0001 Push (A); SP ← (SP) – 0x0001 Push (CCR); SP ← (SP) – 0x0001 I ← 1; PCH ← Interrupt Vector High Byte PCL ← Interrupt Vector Low Byte 83 11

[1] Bus clock frequency is one-half of the CPU clock frequency. Table 76. Opcode map (Sheet 1 of 2)

2 IX1

3 IX2

3 IX1+

2 IX+

3 EXT

3 IX1

Table 77. Opcode map (Sheet 2 of 2)

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 Bit-Manipulation Branch Read-Modify-Write Control Register/Memory 9E61 6 CBEQ

4 SP1

4 SP2

3 SP1

4 IX2

INH Inherent REL relative SP1 Stack Pointer, 8-Bit Offset IMM Immediate IX Indexed, no offset SP2 Stack Pointer, 16-Bit offset DIR Direct IX1 Indexed, 8-Bit offset IX+ Indexed, No offset with post increment EXT Extended IX2 Indexed, 16-Bit offset IX1+ Indexed, 1-Byte offset with post increment DD DIR to DIR IMD IMM to DIR IX+D IX+ to DIR DIX+ DIR to IX+ Note: All Sheet 2 Opcodes are Preceded by the Page 2 Prebyte (9E) Prebyte (9E) and Opcode in Hexadecimal Number of Bytes 9E60 6 SUB

11 Timer Pulse-Width Module

The timer pulse-width module (TPM1) is a two channel timer system that supports traditional input capture, output compare, or edge-aligned PWM on each channel. All

system option register 2 as shown in Table 41 and Table 42.

11.1 Features

  • May be configured for buffered, center-aligned pulse-width modulation (CPWM) on all channels
  • Clock sources independently selectable
  • Selectable clock sources (device dependent): bus clock, fixed system clock
  • Clock prescaler taps for divide by 1, 2, 4, 8, 16, 32, 64, or 128
  • 16-bit free-running or up/down (CPWM) count operation
  • 16-bit modulus register to control counter range
  • Timer system enable
  • One interrupt per channel plus a terminal count interrupt
  • Channel features: – Each channel may be input capture, output compare, or buffered edge-aligned PWM – Rising-edge, falling-edge, or any-edge input capture trigger – Set, clear, or toggle output compare action – Selectable polarity on PWM outputs

11.2 TPM1 configuration information

The device provides one two-channel timer/pulse-width modulator (TPM1). connected to PTAZ or the LFO. TPM1 clock source selection for the TPM1 is shown in the following table. Table 78. TPM1 clock source selection

11.2.1 Block diagram

Figure 18 shows the structure of a TPM1.

Figure 18. TPM1 block diagram TPMCNT counter resets the counter regardless of the data value written. or buffered edge-aligned PWM channels.

11.3 External signal description

general-purpose inputs with the passive pullups disabled.

11.4 Register definition

  • An 8-bit status and control register (TPMSC)
  • A 16-bit counter (TPMCNTH:TPMCNTL)
  • A 16-bit modulo register (TPMMODH:TPMMODL) Each timer channel has:
  • An 8-bit status and control register (TPMCnSC)
  • A 16-bit channel value register (TPMCnVH:TPMCnVL)

11.4.1 Timer status and control register (TPM1SC)

relate to all channels within this timer module. Table 79. Timer status and control register (TPM1SC) (address $0010) Table 80. TPM1SC register field descriptions so TOF would remain set after the clear sequence was completed for the earlier TOF. Reset clears TOF. Writing a 1 to TOF has no effect.

0 TPM1 counter has not reached modulo value or overflow

1 TPM1 counter has overflowed

interrupt is generated when TOF equals 1. Reset clears TOIE.

0 TOF interrupts inhibited (use software polling)

1 TOF interrupts enabled

functions. Reset clears CPWMS.

0 All TPM channels operate as input capture, output compare, or edge-aligned PWM mode as selected by

1 All TPM channels operate in center-aligned PWM mode

clock by an on-chip synchronization circuit. affects whatever clock source is selected to drive the TPM1 system. Table 81. Prescale divisor selection

11.4.2 Timer counter registers (TPM1CNTH:TPM1CNTL)

write to the timer status/control register (TPM1SC). Reset clears the TPM1 counter registers. Table 82. Timer counter register high (TPM1CNTH) (address $0011) W Any write to TPMCNTH clears the 16-bit counter. Table 83. Timer counter register low (TPM1CNTL) (address $0012) W Any write to TPMCNTL clears the 16-bit counter.

while BACKGROUND mode is active.

11.4.3 Timer counter modulo registers (TPM1MODH:TPM1MODL)

The read/write TPM1 modulo registers contain the modulo value for the TPM1 counter. Table 84. Timer counter modulo register high (TPM1MODH) (address $0013) Table 85. Timer counter modulo register low (TPM1MODL) (address $0014) first counter overflow will occur.

11.4.4 Timer channel 0 status and control register (TPM1C0SC)

configure the interrupt enable, channel configuration, and pin function. Table 86. Timer channel 0 status and control register (TPM1C0SC) (address $0015)

Table 87. TPM1C0SC register field descriptions set when the value in the TPM1 counter registers matches the value in the TPM1 channel 0 value registers. channel value register, which correspond to both edges of the active duty cycle period. lost by clearing a previous CH0F. Reset clears CH0F. Writing a 1 to CH0F has no effect.

0 No input capture or output compare event occurred on channel 0

1 Input capture or output compare event occurred on channel 0

Channel 0 Interrupt Enable — This read/write bit enables interrupts from channel 0. Reset clears CH0IE.

0 Channel 0 interrupt requests disabled (use software polling)

1 Channel 0 interrupt requests enabled

aligned PWM mode. For a summary of channel mode and setup controls, refer to Table 88. associated timer channel is set up as a software timer that does not require the use of a pin. Table 88. Mode, edge, and level selection

01 Capture on rising edge only

10 Capture on falling edge only00

00 Software compare only

01 Toggle output on compare

10 Clear output on compare

10 High-true pulses (clear output on compare)

10 High-true pulses (clear output on compare-up)

to input capture mode, it is possible to get an unexpected indication of an edge trigger.

11.4.5 Timer channel value registers (TPM1C0VH:TPM1C0VL)

channel value registers are cleared by reset. Table 89. Timer channel 0 value register high (TPM1C0VH) (address $0016) Table 90. Timer channel 0 value register low (TPM1C0VL) (address $0017) contents of both bytes into a buffer where they remain latched until the other byte is read. mechanism may be manually reset by writing to the TPM1C0SC register. various compiler implementations.

11.4.6 Timer channel 1 status and control register (TPM1C1SC)

configure the interrupt enable, channel configuration, and pin function. Table 91. Timer channel 1 status and control register (TPM1C1SC) (address $0018)

Table 92. TPM1C1SC register field descriptions set when the value in the TPM1 counter registers matches the value in the TPM1 channel 1 value registers. channel value register, which correspond to both edges of the active duty cycle period. lost by clearing a previous CH1F. Reset clears CH1F. Writing a 1 to CH1F has no effect.

0 No input capture or output compare event occurred on channel 1

1 Input capture or output compare event occurred on channel 1

Channel 1 Interrupt Enable — This read/write bit enables interrupts from channel 1. Reset clears CH1IE.

0 Channel 1 interrupt requests disabled (use software polling)

1 Channel 1 interrupt requests enabled

aligned PWM mode. For a summary of channel mode and setup controls, refer to Table 88. the polarity of the PWM output. software timer that does not require the use of a pin. Table 93. Mode, edge, and level selection

to input capture mode, it is possible to get an unexpected indication of an edge trigger.

11.4.7 Timer channel value registers (TPM1C1VH:TPM1C1VL)

channel value registers are cleared by reset. Table 94. Timer channel 1 value register high (TPM1C1VH) (address $0019) Table 95. Timer channel 1 value register low (TPM1C1VL) (address $001A) contents of both bytes into a buffer where they remain latched until the other byte is read. mechanism may be manually reset by writing to the TPM1C1SC register. various compiler implementations.

11.5 Functional description

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 the main 16-bit counter in the TPM1. Each TPM1 channel is optionally associated with an MCU pin and a maskable interrupt function. The TPM1 has center-aligned PWM capabilities controlled by the CPWMS control bit in TPM1SC. When CPWMS is set to 1, timer counter TPM1CNT changes to an up-/down- counter and all channels in the associated TPM1 act as center-aligned PWM channels. When CPWMS = 0, each channel can independently be configured to operate in input capture, output compare, or buffered edge-aligned PWM mode. The following sections describe the main 16-bit counter and each of the timer operating modes (input capture, output compare, edge-aligned PWM, and center-aligned PWM). Because details of pin operation and interrupt activity depend on the operating mode, these topics are covered in the associated mode sections.

11.5.1 Counter

All timer functions are based on the main 16-bit counter (TPM1CNTH:TPM1CNTL). This section discusses selection of the clock source, up-counting vs. up-/down-counting, end- of-count overflow, and manual counter reset. After any MCU reset, CLKSB:CLKSA = 0:0 so no clock source is selected and the TPM1 is inactive. Normally, CLKSB:CLKSA would be set to 0:1 so the bus clock drives the timer counter. The clock source for the TPM1 can be selected to be off, the bus clock (BUSCLK), the fixed system clock (XCLK), or an external input. The maximum frequency allowed for the external clock option is one-fourth the bus rate. Refer to Section 11.4.1 "Timer status and control register (TPM1SC)" and Table 87 for more information about clock source selection. When the microcontroller is in ACTIVE BACKGROUND mode, the TPM1 temporarily suspends all counting until the microcontroller returns to normal user operating mode. During STOP mode, all TPM1 clocks are stopped; therefore, the TPM1 is effectively disabled until clocks resume. During WAIT mode, the TPM1 continues to operate normally. The main 16-bit counter has two counting modes. When center-aligned PWM is selected (CPWMS = 1), the counter operates in up-/down-counting mode. Otherwise, the counter operates as a simple up-counter. As an up-counter, the main 16-bit counter counts from 0x0000 through its terminal count and then continues with 0x0000. The terminal count is 0xFFFF or a modulus value in TPM1MODH:TPM1MODL. When center-aligned PWM operation is specified, the counter counts upward from 0x0000 through its terminal count and then counts downward to 0x0000 where it returns to up-counting. Both 0x0000 and the terminal count value (value in TPM1MODH:TPM1MODL) are normal length counts (one timer clock period long). An interrupt flag and enable are associated with the main 16-bit counter. The timer overflow flag (TOF) is a software-accessible indication that the timer counter has overflowed. The enable signal selects between software polling (TOIE = 0) where no hardware interrupt is generated, or interrupt-driven operation (TOIE = 1) where a static hardware interrupt is automatically generated whenever the TOF flag is 1. The conditions that cause TOF to become set depend on the counting mode (up or up/down). In up-counting mode, the main 16- bit counter counts from 0x0000 through 0xFFFF and overflows to 0x0000 on the next counting clock. TOF becomes set at the transition from 0xFFFF to 0x0000. When a modulus limit is set, TOF becomes set at the transition from the value set in the modulus register to 0x0000. When the main 16-bit counter is operating in up-/down-counting mode, the TOF flag gets set as the counter

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 changes direction at the transition from the value set in the modulus register and the next lower count value. This corresponds to the end of a PWM period. (The 0x0000 count value corresponds to the center of a period.) Because the HCS08 MCU is an 8-bit architecture, a coherency mechanism is built into the timer counter for read operations. Whenever either byte of the counter is read (TPM1CNTH or TPM1CNTL), both bytes are captured into a buffer so when the other byte is read, the value will represent the other byte of the count at the time the first byte was read. The counter continues to count normally, but no new value can be read from either byte until both bytes of the old count have been read. The main timer counter can be reset manually at any time by writing any value to either byte of the timer count TPM1CNTH or TPM1CNTL. Resetting the counter in this manner also resets the coherency mechanism in case only one byte of the counter was read before resetting the count.

11.5.2 Channel mode selection

Provided CPWMS = 0 (center-aligned PWM operation is not specified), the MSnB and MSnA control bits in the channel n status and control registers determine the basic mode of operation for the corresponding channel. Choices include input capture, output compare, and buffered edge-aligned PWM.

11.5.2.1 Input capture mode

With the input capture function, the TPM1 can capture the time at which an external event occurs. When an active edge occurs on the pin of an input capture channel, the TPM1 latches the contents of the TPM1 counter into the channel value registers (TPM1CnVH:TPM1CnVL). Rising edges, falling edges, or any edge may be chosen as the active edge that triggers an input capture. When either byte of the 16-bit capture register is read, both bytes are latched into a buffer to support coherent 16-bit accesses regardless of order. The coherency sequence can be manually reset by writing to the channel status/control register (TPM1CnSC). An input capture event sets a flag bit (CHnF) that can optionally generate a CPU interrupt request.

11.5.2.2 Output compare mode

With the output compare function, the TPM1 can generate timed pulses with programmable position, polarity, duration, and frequency. When the counter reaches the value in the channel value registers of an output compare channel, the TPM1 can set, clear, or toggle the channel pin. In output compare mode, values are transferred to the corresponding timer channel value registers only after both 8-bit bytes of a 16-bit register have been written. This coherency sequence can be manually reset by writing to the channel status/control register (TPM1CnSC). An output compare event sets a flag bit (CHnF) that can optionally generate a CPU interrupt request.

11.5.2.3 Edge-aligned PWM mode

This type of PWM output uses the normal up-counting mode of the timer counter (CPWMS = 0) and can be used when other channels in the same TPM1 are configured

determined by the setting in the modulus register (TPM1MODH:TPM1MODL). the ELSnA control bit. Duty cycle cases of 0 percent and 100 percent are possible. Figure 19. PWM period and pulse width (ELSnA = 0) must be less than 0xFFFF to get 100% duty cycle.

11.5.3 Center-aligned PWM mode

0x0001 to 0x7FFF because values outside this range can produce ambiguous results. ELS0A will determine the polarity of the CPWM output.

longer than required for normal applications. directions from up-counting to down-counting. the modulo setting in TPM1MODH:TPM1MODL, then counts down until it reaches zero. This sets the period equal to two times TPM1MODH:TPM1MODL. Figure 20. CPWM period and pulse width (ELSnA = 0) of PWM is also required for some types of motor drives. requirement only applies to PWM channels, not output compares.

11.6 TPM1 interrupts

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 output compare or PWM modes, the interrupt flag is set each time the main timer counter matches the value in the 16-bit channel value register. See Section 7 "Reset, interrupts and system configuration" for absolute interrupt vector addresses, priority, and local interrupt mask control bits. For each interrupt source in the TPM1, a flag bit is set on recognition of the interrupt condition such as timer overflow, channel input capture, or output compare events. This flag may be read (polled) by software to verify that the action has occurred, or an associated enable bit (TOIE or CHnIE) can be set to enable hardware interrupt generation. While the interrupt enable bit is set, a static interrupt will be generated whenever the associated interrupt flag equals 1. It is the responsibility of user software to perform a sequence of steps to clear the interrupt flag before returning from the interrupt service routine.

11.6.1 Clearing timer interrupt flags

TPM1 interrupt flags are cleared by a two-step process that includes a read of the flag bit while it is set (1) followed by a write of 0 to the bit. If a new event is detected between these two steps, the sequence is reset and the interrupt flag remains set after the second step to avoid the possibility of missing the new event.

11.6.2 Timer overflow interrupt description

The conditions that cause TOF to become set depend on the counting mode (up or up/down). In up-counting mode, the 16-bit timer counter counts from 0x0000 through 0xFFFF and overflows to 0x0000 on the next counting clock. TOF becomes set at the transition from 0xFFFF to 0x0000. When a modulus limit is set, TOF becomes set at the transition from the value set in the modulus register to 0x0000. When the counter is operating in up-/down-counting mode, the TOF flag gets set as the counter changes direction at the transition from the value set in the modulus register and the next lower count value. This corresponds to the end of a PWM period. (The 0x0000 count value corresponds to the center of a period.)

11.6.3 Channel event interrupt description

The meaning of channel interrupts depends on the current mode of the channel (input capture, output compare, edge-aligned PWM, or center-aligned PWM). When a channel is configured as an input capture channel, the ELSnB:ELSnA control bits select rising edges, falling edges, any edge, or no edge (off) as the edge that triggers an input capture event. When the selected edge is detected, the interrupt flag is set. The flag is cleared by the two-step sequence described in Section 11.6.1 "Clearing timer interrupt flags". When a channel is configured as an output compare channel, the interrupt flag is set each time the main timer counter matches the 16-bit value in the channel value register. The flag is cleared by the two-step sequence described in Section 11.6.1 "Clearing timer interrupt flags".

11.6.4 PWM end-of-duty-cycle events

For channels that are configured for PWM operation, there are two possibilities:

  • When the channel is configured for edge-aligned PWM, the channel flag is set when the timer counter matches the channel value register that marks the end of the active duty cycle period.
  • When the channel is configured for center-aligned PWM, the timer count matches the channel value register twice during each PWM cycle. In this CPWM case, the channel flag is set at the start and at the end of the active duty cycle, which are the times when the timer counter matches the channel value register. The flag is cleared by the two-step sequence described in Section 11.6.1 "Clearing timer interrupt flags".

12 Other MCU resources

degrade the accuracy of the measurements. your NXP sales representative. The FXTH87E uses a 6-channel, 10-bit analog-to-digital converter (ADC10) module. temperature and voltage readings are controlled by the MCU. first be powered up long enough to stabilize their outputs before a conversion is started. synchronously with the sampling of the voltages. these measurements and convert them into an 8-bit, 9-bit or 10-bit transfer function. contact your NXP sales representative. Table 96. ADC10 channel assignments

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 ADC10 Channel Input Select Firmware Call(s) Characteristic Optional Z-axis Acceleration Sensor TPMS_READ_COMP_ACCEL_Z AZCODE AD1 Temperature Sensor TPMS_READ_COMP_TEMP_8 TCODE AD2 Band gap Reference TPMS_READ_COMP_VOLTAGE VCODE AD3 GPIO PTA0 TPMS_READ_V0 G0CODE AD4 GPIO PTA1 TPMS_READ_V1 G1CODE AD5 VREG Monitor TPMS_WIRE_CHECK

12.1 Pressure measurement

The pressure measurement consists of an interface to a pressure sensing element. Control bits on the MCU operate the SMI to power up the P-Cell and capture a voltage which is converted by the ADC10. The resulting pressure transfer equation for the 100-500 kPa range: (1) The transfer equation of the 100-900 kPa range is: (2) The transfer equation of the 100-1500 kPa range is: (3) Due to calibration routines and parameters stored in the FXTH87E, the pressure range is selected at production and cannot be changed in the field. Note: Lack of change of the pressure measurement over time may indicate the package pressure port to be blocked or the internal section of the sensor to be contaminated. User application should maintain either locally or at the system data receiver a record of pressure measurements along with temperature and/or accelerometer measurements, and possibly identify the pressure port as blocked or contaminated if no changes are recorded over time.

12.2 Temperature measurements

The temperature is measured from a ΔVB sensor built into channel 1 of the ADC10 in the same manner as is done in the FXTH87E devices with the resulting transfer equation: (4)

12.3 Voltage measurements

Voltage measurements can be made on the internal band gap to estimate the supply voltage on VDD.

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019

12.3.1 Internal band gap

An internal band gap voltage reference is provided to take measurements of the supply voltage. The resulting transfer equation: (5)

12.3.2 External voltages

Measurements of an external voltage on either the PTA0 or PTA1 pins can be made and referenced to the internal band gap voltage. The resulting transfer equation: (6) where x = 0, 1 refers to PTA0 or PTA1.

12.4 Optional acceleration measurements

The acceleration measurement consists of an interface to an optional acceleration sensing element. Control bits on the MCU operate the SMI to power up the g-Cell and capture a voltage which is converted by the ADC10. The data from the ADC10 is then pre-processed by a dynamic range firmware routine that will return the two values necessary to calculate the acceleration, Ay, (y = X-axis or Z-axis, depending on selection) in conjunction with values taken from the tables in the data sheet. The first value from the firmware routine is the offset step identifier, STEP, with integer values 0 to 15 (i.e. the 16 offset steps). The other value is the ADC10 data, AyCODE, with integer values 0 to 511. AyCODE values 1 through 510 are usable; values 0 and 511 indicate fault conditions. The X-axis acceleration is scaled for ~20g range within each of the 16 offset steps, ~10g per step. The Z-axis acceleration is scaled for ~80g range within each of the 16 offset steps, ~80g or ~60g. The steps are at ~40g or ~30g increments, allowing for adequate overlaps. The product data sheet provides tables of acceleration values resulting from characterizations. Acceleration sensitivity, ΔAMAX-MIN, varies between each offset step, and should be calculated by dividing the range of g’s for each offset step by the usable AyCODE range (i.e. 509): (7) Once the sensitivity ΔAMAX-MIN has been calculated, the acceleration Ay can be calculated by the re-using the ARATE-MIN, 1 value of the offset step and the returned AyCODE value with the following transfer function: (8) The pressure, and optional X or Z-axis accelerometer also share the same signal path in the Transducer interface and all the sensors share the same ADC. Therefore, only one of the sensors can be accessed at a given moment. Note: The included accelerometers are designed with a self-test feature. Consult sales/ application support for information regarding the recommended use of the accelerometer self-test features.

12.5 Optional battery condition check

(any of the PTA[3:0] can be used for this purpose). Figure 21. Battery check circuit

  • VDD0 is the voltage determined with the external load resistor connected to VSS
  • VDD1 is the voltage determined with the external load resistor connected to VDD
  • RLOAD is the resistance of the external load resistance in ohms
  • RBATT is the implied battery impedance in ohms

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 It is recommended that this calculation be performed with a reasonable current load on the battery of approximately 3 mA (RLOAD approximately 1000 ohms).

12.6 Measurement firmware

The firmware for making measurements is comprised of two function calls as described in Section 16 "Firmware". Each measurement is a combination of a "read" that returns the raw ADC output data and a "comp" routine which compensates that raw reading based on information contained in the Universal Uncompensated Measurement Array (UUMA) assigned in RAM memory. The read routines fill specific locations in the UUMA with raw data; but the compensation routines depend what is already present in the UUMA as shown in the data flow in Figure 22. The user, therefore, has the option to decide how often each measurement (and its component terms) are made. The resulting power consumption is then the sum of using these components are defined in the product data sheet. A typical flow for a compensated pressure measurement would be: 1. Call the TPMS_READ_PRESSURE routine which yields a raw pressure value and fills the UUMA with this data. 2. Call the TPMS_READ_TEMPERATURE routine which yields a raw temperature value and fills the UUMA with this data. 3. Call the TPMS_READ_VOLTAGE routine which yields a raw voltage value and fills the UUMA with this data. 4. Call the TPMS_COMP_PRESSURE routine which then takes the raw pressure, temperature and voltage values from the UUMA and compensates to provide a true pressure reading to the accuracy as specified in the product data sheet.

Figure 22. Data flow for measurements

12.7 Thermal shutdown

over the full temperature range from TL to TH.

12.7.1 Low temperature shutdown

MCU will turn off all operating functions and enter the STOP1 mode.

12.7.2 High temperature shutdown

12.7.3 Temperature shutdown recovery

MCU will be reset and begin execution from the reset vector located at $DFFE/$DFFF. the SIMOPT1 register at address $1802. The TRE bit is cleared by an MCU reset. bit is cleared by an MCU reset. TRE bit is set and temperature falls back within the TRESET temperature range. restart when temperature falls back to the TRESET range. The TRE bit cannot be set. Figure 23. Temperature restart response This sequence is further explained by the user software flowchart in Figure 24.

Figure 24. Flowchart for using TR module

12.8 Free-Running Counter (FRC)

STOP4, STOP3, and STOP1 modes, unless halted as defined below.

13 Periodic Wakeup Timer

from any of the STOP modes. It also has an optional periodic reset to restart the MCU. combination of control bits will disable both the wakeup interrupt and the periodic reset.

13.1 Block diagram

set wakeup and/or reset time intervals. Figure 25. Wakeup timer block diagram used to calculate the correct value for the WDIV[5:0] bits for a WCLK period of 1 second. TPM1 is being used for another task.

return a zero content if done immediately after the interrupt or reset is generated. precedence and the interrupt will not be generated. The wakeup interrupt (WUKI) cannot be masked by clearing the I-bit.

13.2 Wakeup divider register — PWUDIV

period as described in Table 97. Table 97. PWU divider register (PWUDIV) (address $0038) Table 98. PWUDIV register field descriptions period for WCLK. Other resets have no effect on these bits.

13.3 PWU control/status register 0 — PWUCS0 (address $0039)

Table 99. PWU Control/Status register 0 (PWUCS0) (address $0039) Table 100. PWUSC0 register field descriptions Wakeup Interrupt Flag — The WUF bit indicates when a wakeup interrupt has been generated by the PWU. by writing a one to the WUFAK bit. Writing a zero to this bit has no effect. Reset clears this bit. 0 Wakeup interrupt not generated or was previously acknowledged. 1 Wakeup interrupt generated. wakeup interrupt is generated. The count gives a range of wakeup times from 1 to 63 WCLK clocks. WUT[5:0] bits has no effect. prevents disabling both the periodic wakeup and the periodic reset at the same time. See Table 101. The WUT[5:0] bits are preset to a value of $3F (decimal 63) by any resets. Table 101. Limitations on clearing WUT/PRST [2] Wakeup divider preset to $3F.

13.4 PWU control/status register 1 — PWUCS1

period and provide interrupt flag and acknowledge bits as described in Table 102. Table 102. PWU Control/Status register 1 (PWUCS1) (address $003A) Table 103. PWUSC1 register field descriptions power on reset, but is unaffected by other resets. 0 Periodic reset not generated or previously acknowledged. bits are preset to a value of 63 by any resets.

13.5 PWU wakeup status register — PWUS

Table 102. The counter contents are captured when the register is read. Table 104. PWU wakeup status register (PWUS) (address $001F)

Table 105. PWUS register field descriptions

0 CSTAT = WUT counter status

1 CSTAT = PRST counter status

unused Unused — An unused bit that always reads as a logical zero. immediately after a WUF or PRF generated flag will return zero contents.

13.6 Functional modes

13.6.1 RUN mode

interrupt; write 1 to WUFACK to clear this flag. flag will be set to indicate periodic reset; write 1 to PRFACK to clear this flag. All registers will continue to hold their programmed values after interrupt or reset is taken.

13.6.2 STOP4 mode

indicate wakeup timer interrupt, write 1 to WUFACK to clear this flag. reset; write 1 to PRFACK to clear this flag. All registers will continue to hold their programmed values after interrupt or reset is taken.

13.6.3 STOP1 mode

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 If the module generates a periodic reset the module will cause the MCU to exit the power saving mode as a POR. The PRF flag will be set to indicate periodic reset; write 1 to PRFACK to clear this flag. The SRS register will have just the POR bit set. In this STOP mode exit all registers will continue to hold their programmed values.

13.6.4 Active BDM/foreground commands

The PWU is frozen in ACTIVE BACKGROUND mode or executing foreground commands, so PWU counters will also be stopped. Normal PWU operation will resume as MCU exits BDM or foreground command is finished.

14 LF Receiver

The low-frequency receiver (LFR) is a very low-power, low-frequency, receiver system for short-range communication in TPMS. The module allows an external coil to be connected to two dedicated differential input pins. In TPMS systems a single coil may be oriented for optimal coupling between the receiver in the tire or wheel and a transmitter coil on the vehicle body or chassis. This LFR system minimizes power consumption by allowing flexibility in choosing the ratio of on to off times and by turning off power to blocks of circuitry until they are needed during signal reception and protocol recognition. In addition, this LFR system can autonomously listen for valid LF signals, check for protocol and ID information so the main MCU can remain in a very low power standby mode until valid message data has been received. The LFR can be configured for various message protocols and telegrams to allow it to be used in a broad range of applications. The message preamble must be a series of Manchester coded bits at the nominal 3.906-kbps data rate. A synchronization pattern is used to mark the boundary between the preamble and the beginning of Manchester encoded information in the message body. The synchronization pattern is a non- Manchester specific TPMS pattern. Messages can optionally include none, an 8-bit or a 16- bit ID value. Messages may contain any number of data bytes with the end-of- message indicated by detecting an illegal Manchester bit at a data byte boundary. It is not intended that LFR may be actively receiving/decoding LF signals while physical parameter measurements are being made; or during the time that the RFM may be actively powered up and/or transmitting RF data. The resulting interactions will degrade the accuracy of the LF detection.

  • DATADECODING 129 kHz typ 1 kHz_clock typ LOGIC BLOCK 1
  • ON/OFF CYCLING
  • CARRIER DETECTION

Figure 26. Block diagram please refer to Section 14.17 "LFR register definition".

14.1 Features

  • Differential input LF detector (two dedicated pins): – Selectable sensitivity (two levels: Low Sens (LS) and High Sens (HS)). – Thresholds trimmed at the factory with trim setting saved in nonvolatile memory. – LFR has a reference oscillator (LFRO) trimmed at the factory with trim setting saved in nonvolatile memory. – Selectable signal sampling time interval and on-time. – Sample interval and on times controlled by LFR state machine or directly by the MCU.
  • Configurable receive mode: – Simple LF carrier detection/Telegram decode. (CARMOD)
  • Configurable message protocol (telegram structure): – Various SYNC decoding (SYNC[1:0]) 6-bit time SYNC requirements 7.5-bit time SYNC requirements 9-bit time SYNC requirements – Optional ID (ID[1:0]) 8-bit or 16-bit ID On or off – 0-n bytes of message data. End-of-data marked by loss of Manchester at a byte boundary.

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019

  • Optional continuous monitoring and decode of the LF detector.
  • Selectable MCU interrupt when a received data byte is ready in an LFR buffer, when a Manchester error is detected in the frame, when an ID is received or when a valid carrier has been detected.

14.2 Modes of operation

The LFR is a peripheral module on an MCU. After being configured by application software, the LFR can operate autonomously to detect and verify incoming LF messages. When a valid message or carrier pulse is received and verified the LFR can wake the MCU from standby modes to read received data or act upon a carrier detection. The primary modes of operation for the LFR are:

  • Disabled. Everything off and drawing minimal leakage current. LFR register contents will be retained.
  • Carrier detect/listen. Minimum circuitry enabled to detect any incoming LF signal, check it for the appropriate signal level, frequency and duration.
  • TPMS protocol verification.
  • Data reception.

14.3 Power management

In addition to using low power circuit design techniques, the LFR module provides system-level features to minimize system energy requirements. In an MCU that includes the LFR module, all MCU circuitry except a very low current 1-kHz oscillator (LFO) and minimum regulator circuitry can be disabled. After a reset, the MCU would initialize the LFR module and then enter a very low power standby mode (depending upon the MCU, this could be lower than 1 uA for the MCU portion). The LFR module includes everything it needs to periodically listen for LF messages, perform Manchester decoding, verify the message telegram, and assemble incoming data into 8-bit bytes. The LFR does not wake the MCU unless a valid message is being received and a data byte is ready to be read. The LFR cycles between an off state, where everything is disabled, and an on state, where it listens for a carrier signal. The on time is controlled by LFONTM[3:0] control bits in the LFCTL2 register. The time between the start of each sample on time is controlled by LFSTM[3:0] control bits in the LFCTL2 register. Even lower duty cycles can be achieved by using the MCU to wake once per second and maintain a software counter to delay for an arbitrarily long time before enabling the LFR to perform a series of carrier detect cycles. Within the LFR, circuits remain disabled until they are needed. When the LFR is listening for a carrier signal, only a 1-kHz clock source, a portion of the input amplifier and a periodic auto-zero are running. After a carrier signal is detected, with high enough amplitude, frequency and duration the LFRO oscillator is enabled so the LFR can begin to decode the incoming information. The LFR module has a power up settling time of 2-LFO period before any active operations. In the ON/OFF cycle, those 2 ms are hidden in the sampling time during the off time.

14.4 Input amplifier

The LFR module receives LF modulated signals through a dedicated differential pair of inputs which is connected to an external coil. The enable control (LFEN) allows the user

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 to enable the LF input depending on the application requirements. The SENS[1:0] bits in the LFCTL1 register allows the user to select one of two input sensitivity thresholds which determines the signal level required before the input carrier will be detected. The sensitivity setting is used during carrier detection but does not affect reception after the carrier has been detected. When the CARMOD bit is cleared, after a carrier with sufficient amplitude, frequency and duration has been detected the output stage of the amplifier is turned on to allow data reception.

14.5 LFR data mode states

The modes of operation the LFR state machine will sequence as shown in Figure 27.

14.6 Carrier detect

Carrier detection includes a check for a certain number of edges on a signal that is greater than the input sensitivity threshold. During the check for carrier edges, only the 1 kHz low frequency oscillator (LFO) clock source is running so power consumption remains very low. During carrier detection the incoming signal is amplified and passed through a sensitivity threshold comparator. The SENS[1:0] bits in the LFCTL1 register selects two levels of sensitivity and determines the signal amplitude that is needed to allow edges to be seen at the output of the sensitivity threshold comparator. When a carrier is above this threshold, a block is powered on and validates the carrier. This frequency and duration check function can be disabled by clearing the VALEN bit. If VALEN is set, the block checks for the carrier duration and the carrier frequency. The time needed to validate a carrier is programmed by the LFCDTM register. The carrier frequency should be 125 kHz. If the signal above the threshold is not within the frequency range or not present during enough time, then the carrier will not be validated and the validation block will turn off. If no carrier signal is validated within the on time of the LFR, the state machine returns to the off state and the alternating cycle of on time and off time continues. Carrier edge counts start at zero when a new on time begins. In the data mode (CARMOD = 0), if the required number of carrier edges are detected before the end of the ON time, the LFR will remain ON to complete the reception of a message telegram. In the carrier detect mode (CARMOD = 1) there is no need to enable other LFR circuitry to evaluate any other message components after the required number of carrier edges are detected. One or several consecutive carriers can be validated by this process before the LFCDF flag is set. The LFCC control bits are used to program the number of consecutive ON times where a complete carrier validation is needed before interrupting the MCU. In this case, the LFCDF flag is set and, provided the LFCDIE interrupt enable is also set, an interrupt is issued to wake the MCU. In carrier detect mode, the LFCDIE control bit should always be set because the intended purpose of the carrier detect mode is to wake the MCU when a carrier is detected. When LFCDF is set, the LFR waits until it is cleared before it continues the alternating cycle of on time and off time, starting with an off time. In data mode, when a carrier is detected the averaging filter is powered on and the LFR continues to the next state to look for the rest of a message telegram; and the LFR module will search for valid SYNC word (with length programmed through the SYNC bits in the LFCTL3 register depending on preamble type). If the external LF field is not

through TIMOUT bit the LFCTL4 register.

5 LFO cycles

Figure 27. FXTH87E LFR state machine diagram

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019

14.7 Auto-zero sequence

An auto-zero sequence is performed periodically on the input amplifier to cancel offset errors. During reception of the SYNC pattern and body of the message, auto-zero operations are synchronized to data edges of the incoming signal to avoid interfering with normal reception. During the auto-zero sequence, the input amplifier is temporarily disconnected from the external coil and connected to ground. The auto-zero sequence takes roughly 64 μs. It is performed at each LFO period in carrier mode and on one over four decoded data edges in data mode. When the DECEN bit is cleared, the auto-zero sequence is performed at each LFO period. During the 64 μs of the auto-zero sequence, the receiver is holding the state "0" or "1" previously decoded. Since the LFR receiver is not active during this time, the possible data-rate that the analog can detect is at least limited by this duration.

14.8 Data recovery

Rectified signals from the amplifier output are connected to the input of an averaging filter and data slicer. The slicer thus compares the rectified signal with its own average value to decode the data. When a carrier is present, the slicer output voltage rises and when the carrier stops the slicer output voltage falls. The output of this comparator provides a binary digital signal that indicates whether the carrier is present or not. This digital signal is connected to the data clock recovery circuit, the SYNC detect circuit, and the Manchester decoder circuit. The Manchester decoder uses the digital output of the data slicer to detect the logic level of each incoming data bit and to synchronize the decoder state machine. The LFPOL polarity bit in the LFCTRLA register selects the expected encoding of the Manchester data bit. If a strong signal (above roughly 100 mV p-p differential) is entered into the LFR, the input impedance will switch instantaneously to a lower programmed value (the LOWQ[1:0] bits in the LFCTRLC) and be maintained during the current data packet if the DEQEN bit is set. At the next ON time, the default high input impedance will be set again. The strong signal detection and the automatic impedance change can be disabled by clearing the DEQEN bit.

14.9 Data clock recovery and synchronization

Data clock recovery and synchronization takes place during the SYNC portion of an incoming message. The preamble must be modulated Manchester data. The type of required SYNC pattern determines the allowed preamble type depending on the SYNC[1:0] control bits. The design data rate is 3.906 kbps which gives a bit time equivalent to about 32 cycles of the LF carrier frequency. In a Manchester encoded bit time, the carrier should be present for either the first half or the second half of the bit time depending on whether the bit is a logic zero or a logic one. The LFRO clock source is 32 times the target data rate. The LFRO is used for decoding data and also sequencing auto-zero operations.

14.10 Manchester decode

carrier levels at the summing node for the rectified output of the LF input amplifier. Figure 28. Manchester encoded datagram for LFPOL = 0 the bit time as shown in Figure 28. Figure 29. Manchester encoded datagram for LFPOL = 1

14.11 Duty-cycle for data mode

rise and fall times of the incoming LF carrier as shown in Figure 30. Figure 30. Definition of duty-cycle of 40%

Figure 31. Impact of duty-cycle on SYNC pattern

14.12 Input signal envelope

Figure 33. Excessive filtering will cause the received message error rate (MER) to

  • Antenna Q-factor acts as a 1st order low-pass filter on the LF envelope
  • Filter time constant: t = R.C.
  • Recommended τ < 15 s LFA LFB Antenna model aaa-028025 C R

Figure 32. Antenna Q-factor equivalent model for the LF envelope

  • Recommended τ < 15 s
  • Ideal case: τ = 0 (Q-factor = 0)
  • Use case: τ > 0 (Q-factor > 0) τ aaa-028026 High state part of Manchester symbol Low state part of Manchester symbol Vpp 0.63 × Vpp

Figure 33. LF envelope filtering

14.13 Telegram verification

non-Manchester pattern as shown in Figure 34.

1.5 T T T

Figure 34. SYNC patterns defined by application software.

next byte of the message the LFEOMF bit will also be set. Figure 35. The SYNC pattern will only be matched for the bit times specified by the is as described for the SYNC[1:0] bits in the LFCTL3 register. Figure 35. Telegram format (carrier preamble)

14.14 Error detection and handling

be performed by the LFR and not require additional software processing by the MCU.

14.15 Continuous ON mode

LFEN bit is set. The Continuously ON mode is controlled by setting the LFSTM[3:0] bits. after having changed the CARMOD bit.

14.16 Initialization information

constant until the next MCU reset. sources in order to avoid any immediate interrupt requests.

14.17 LFR register definition

14.17.1 LF control register 1 (LFCTL1)

input sensitivity controls. The LFCTL1 register also contains a register select bit, LPAGE. Table 106. LFR control register 1 (LFCTL1) (address $0020) Table 107. LFCTL1 register field descriptions sequence is performed for 64 μsec and then the LFR is ready to receive signals.

0 LF receiver in standby

1 LF receiver active

0 Reset completed

1 Start a soft reset

Carrier Mode — This read/write control bit selects the basic operating mode for the LFR.

0 Data receive mode

1 Carrier detect mode — wake the MCU when a carrier signal is detected if LFCDIE is set

has no effect on the LFCTL1 and LFCTL2 registers. This bit is cleared by LFR reset.

0 Access page 0

1 Access page 1

Wakeup ID Selection — Selects the existence and length of the wakeup ID. Reset clears these bits.

00 No ID expected

Sensitivity Control — These two read/write control bits select the sensitivity thresholds for the LFR input. only used in the carrier detect path and do not affect reception of the message body.

00 Performance not specified

01 Low sensitivity (SDET_L; SNODET_L)

10 High sensitivity (SDET_H; SNODET_H)

11 Performance not specified

14.17.2 LF control register 2 (LFCTL2)

time interval between samples as shown in Table 108. Table 108. LFR control register 2 (LFCTL2) (address $0021) Table 109. LFCTL2 register field descriptions

0001 Sampled decoding mode every 16 LFO clock periods (16 milliseconds nominal)

0010 Sampled decoding mode every 32 LFO clock periods (32 milliseconds nominal)

0011 Sampled decoding mode every 64 LFO clock periods (64 milliseconds nominal)

0100 Sampled decoding mode every 128 LFO clock periods (128 milliseconds nominal)

0101 Sampled decoding mode every 256 LFO clock periods (256 millisecond nominal)

0110 Sampled decoding mode every 512 LFO clock periods (512 milliseconds nominal)

0111 Sampled decoding mode every 1024 LFO clock periods (1024 milliseconds nominal)

1000 Sampled decoding mode every 2048 LFO clock periods (2048 milliseconds nominal)

1001 Sampled decoding mode every 4096 LFO clock periods (4096 milliseconds nominal)

or timeout occurrence. Reset forces the LFONTM bits to 0:0:0. *LFONTM times will differ between LF wakeup and LF datagram reception. Figure 36. LF detector sampling timing

14.17.3 LF control register 3 (LFCTL3)

carrier detection time when using the carrier detect mode. Table 110. LFR control register 3 (LFCTL3) (address ($0022)

Table 111. LFCTL3 register field descriptions presence of a carrier. It may change at any time. This bit is read only and unaffected by any reset.

0 LF detector output low (no signal above threshold)

1 LF detector output high (received signal above threshold)

sequence. Reset clears this bit. 0 CARMOD bit does not change and determines detector mode. 1 CARMOD bit will be toggled every LFON detection sequence, starting by CARMOD selection. Therefore, the reception chain will alternately look for a carrier frame or for a data frame. allow for proper averaging filter operation. 00 For factory test purposes, not intended for use in any application. been validated the LFCDTM[3:0] bits ignored during the decode of the rest of the data.

0000 Carrier detect = 8 (64 μsec) Data mode detect = 8 (64 μsec)

0001 Carrier detect = 16 (128 μsec) Data mode detect = 8 (64 μsec)

0010 Carrier detect = 32 (256 μsec) Data mode detect = 8 (64 μsec)

0011 Carrier detect = 64 (512 μsec) Data mode detect = 8 (64 μsec)

0100 Carrier detect = 128 (1024 μsec) Data mode detect = 8 (64 μsec)

0101 Carrier detect = 256 (2048 μsec) Data mode detect = 8 (64 μsec)

0110 Carrier detect = 512 (4096 μsec) Data mode detect = 8 (64 μsec)

0111 Carrier detect = 1024 (8192 μsec) Data mode detect = 8 (64 μsec)

1000 Carrier detect = 8 (64 μsec) Data mode detect = 8 (64 μsec)

1001 Carrier detect = 16 (128 μsec) Data mode detect = 16 (128 μsec)

1010 Carrier detect = 32 (256 μsec) Data mode detect = 32 (256 μsec)

1011 Carrier detect = 64 (512 μsec) Data mode detect = 64 (512 μsec)

1100 Carrier detect = 128 (1024 μsec) Data mode detect = 128 (1024 μsec) (see note)

1101 Carrier detect = 256 (2048 μsec) Data mode detect = 256 (2048 μsec) (see note)

1110 Carrier detect = 512 (4096 μsec) Data mode detect = 512 (4096 μsec) (see note)

1111 Carrier detect = 1024 (8192 μsec) Data mode detect = 1024 (8192 μsec) (see note)

the complete 64 μsec period of the auto-zero.

14.17.4 LFR control register 4 (LFCTL4)

in order to avoid an immediate interrupt request. Table 112. LFR control register 4 (LFCTL4) (address $0023) Table 113. LFCTL4 register field descriptions LFR data register is full. Reset clears LFDRIE. 0 LFDRF interrupts disabled. Use software polling. an error in reception of a non-Manchester encoded bit time following the SYNC time. Reset clears LFERIE. 0 LFERF interrupts disabled. Use software polling. 1 LFERF interrupts are enabled. If LFERIE is set, then an interrupt is requested when LFERF = 1. cleared. Reset clears LFCDIE. 0 LFCDF interrupts disabled. 1 LFR LFCDF interrupts are enabled. If LFCDIE is set, then an interrupt is requested when LFCDF = 1. detects a match to the ID code selected in the LFIDH:L registers. Reset clears LFIDIE. 0 LFIDF interrupts disabled. 1 LFIDF interrupts are enabled. If LFIDIE is set, then an interrupt is requested when LFIDF = 1. stream. Reset sets the DECEN bit. 0 Digital decoder is disabled. 1 Digital decoder is enabled. LF Validation Enable — This read/write bit enables the carrier validation process. Reset sets this bit. 0 Carrier Validation disabled. 1 Carrier Validation enabled.

delay time. These time intervals are clocked by the internal LFRO clock. Reset clears TIMOUT bit. 00 SYNC word is continuously searched — no timeout. 01 SYNC search time set to nominal 8 milliseconds. 10 SYNC search time set to nominal 24 milliseconds. 11 SYNC search time set to nominal 48 milliseconds.

14.17.5 LFR status register (LFS, LPAGE = 0)

Table 114. LFR status register (LFS, LPAGE = 0) (address $0024) Table 115. LFS register field descriptions bit or reading the LFDATA register. LFDRF is also cleared by reset. 0 No new data in LFDATA register. 1 A new byte of data has been received and can be read from the LFDATA register. 1 Error detected in the Manchester data mode. working if TOGMOD = 1. Clear LFCDF by writing a one to the LFIAK bit. LFCDF is also cleared by reset. 1 Carrier detection has occurred. MCU if the LFIDIE bit is set. Clear LFIDF by writing a one to the LFIAK bit. LFIDF is also cleared by reset. 1 wakeup ID has been detected.

not read from LFDATA register yet. This indicates that the MCU has lost the previously received data byte. writing a one to the LFIAK bit. LFOVF is also cleared by reset. 1 Previous data over-written before MCU read it. writing a one to the LFIAK bit. LFEOMF is also cleared by reset.

0 Low time transition from carrier to data mode

1 Low consumption during sniff mode

positive edge of the MCU bus clock. Then, reading the LFIAK bit is allowed but will always return zero. Writing a zero the LFIAK bit has no effect. Reset has no effect on this bit. 1 Clears the LFDRF, LFERF, LFCDF, LFIDF, LFOVF and LFEOMF flag bits.

14.17.6 LFR data register (LFDATA, LPAGE = 0)

Table 116. LFR data register (LFDATA) when LPAGE = 0 (address $0025)

Table 117. LFDATA register field descriptions and any writes to these bits will be ignored. Reading this register will clear the LFDRF.

14.17.7 LFR ID registers (LFIDH:LFIDL, LPAGE = 0)

Table 118. LFR ID low byte (LFIDL) (address $0026) Table 119. LFR ID high byte (LFIDH) (address $0027) Table 120. LFR ID register field description ID[15:0] ID bits 15 through 0 — These read/write bits contain bits 15 through 0 of the 16-bit ID value.

14.17.7.1 LF Control E — LFCTRLE

Table 121. LF control E (LFCTRLE) (address $0021)

Table 122. LFCTRLE register field description Reserved Reserved bits — Not for user access. LOGAMP AZ Sequencer Control — Control bits for AZ and trim within the LOGAMP.

14.17.8 LFR control register D (LFCTRLD, LPAGE = 1)

only accessible when the LPAGE bit is set. Table 123. LFR control register D (LFCTRLD, LPAGE = 1) (address $0022) Table 124. LFCTRLD register field descriptions

00 No delay

01 No delay

10 One-half of 125 kHz clock period delay — recommended setting

11 One and one-half of 125 kHz clock periods delay

0 DeQing system not activated

1 DeQing system activated

00 AZ starts after LFCPTAZ numbers of input data edges. 01 Z starts randomly adding –1, 0 or 1 to LFCPTAZ value between each AZ. 10 AZ starts after LFCPTAZ numbers of input data edges and when the input data (d_data) state is 0.

11 AZ starts after LFCPTAZ numbers of input data edges and when the input data (d_data) state is 1 —

0 Any error will stop the ON time. 1 If remaining ON time, the LFR will go back to sniff mode at any error — recommended setting. Accurate 125 kHz Check — The bit controls the CARVAL frequency check method.

00 CARVAL validates on n (2*32 μs packets), n depending on LFCDTM value — recommended setting for

10 CARVAL validates on n (8*8 μs packet), n depending on LFCDTM value — recommended setting for

therefore carries the side effect of narrowing the 125 kHz carrier bandwidth tolerance.

14.17.9 LFR control register C (LFCTRLC, LPAGE = 1)

accessible when the LPAGE bit is set. Table 125. LFR control register C (LFCTRLC, LPAGE = 1) (address $0023) Table 126. LFCTRLC register field descriptions 3rd Amplifier gain — These bits controls the 3rd amplifier gain.

00 Gain of 2 — recommended setting

01 Gain of 3

10 Gain of 4

11 Gain of 6

Final stage select — These bits select the final stage of the LOGAMP.

00 Continuous time biasing — Fixed Gain 6

01 Continuous time biasing — Programmable Gain — recommended setting

Data AZ enable — This bit allows the AZ sequence during data frame.

0 AZ during data disabled

1 AZ during data enabled — recommended setting

DeQing Resistor — These bits select the resistor added in parallel to the input network.

DeQing System enable — The bit controls the DeQing system.

14.17.10 LFR control register B (LFCTRLB, LPAGE = 1)

accessible when the LPAGE bit is set. Table 127. LFR control register B (LFCTRLB, LPAGE = 1) (address $0024) Table 128. LFCTRLB register field descriptions

00 Standard low pass filtering activated — recommended setting

01 Standard low pass filtering activated

10 Bi-phase filtering activated — Low offset from input signal low level

11 Bi-phase filtering activated — High offset from input signal low level

bit time. The LFPOL is not used in Carrier mode. Reset clears LFPOL bit. 0 Zero is falling edge in middle of a bit time, one is a rising edge in the middle of bit time. 1 Zero is rising edge in middle of a bit time, one is a falling edge in the middle of bit time. minimum number of data edges between two auto-zero requests during a data frame.

14.17.11 LFR control register A (LFCTRLA, LPAGE = 1)

is only accessible when the LPAGE bit is set. Table 129. LFR control register A (LFCTRLA, LPAGE = 1) (address $0025)

Table 130. LFCTRLA register field descriptions Reserved Reserved bits — Not for user access. flag is risen; and is useful in detecting long duration carrier pulses. This counter is disabled if TOGMOD = 1.

15 RF module

performance of the RF output spectrum. output or direct control from the MCU. The overall block diagram is shown in Figure 37.

Figure 37. RF transmitter block diagram

15.1 RF data modes

15.1.1 RF data buffer mode

when any of the LFR, SMI or MCU are operating. The RF data buffer consists of a dedicated RFM state machine and a 256-bit data buffer. registers A - PLLCR[1:0], RPAGE = 0".

reading back the state of the SEND control bit or the RFIF status bit.

  1. Use of a programmable timer (random, base time, time adder).

interframe timing by use of the IFPD bit. RFM registers after the SEND has been set and the transmission is still in progress. Changing RFM register contents during a transmission can lead to data faults or errors.

15.1.2 MCU direct mode

rate and its stability will depend on the internal HFO oscillator.

15.2 RF output buffer data frame

Figure 38. The actual data being transmitted in a given data frame and any combinations of data frames into a single datagram is dependent on the user software. selected by the RPAGE bit in the RFCR2. most significant byte (RFB15). This is often referred to as "little-endian" data ordering.

Figure 38. Data frame formats

15.2.1 Data buffer length

generated if the RFIE bit is set.

15.2.2 End of Message (EOM)

15.3 Transmission randomization

RFM crystal oscillator, VCO and PLL turned off by the IFPD bit. Figure 39. Datagram overview the MCU or using this interval timing generator. tBASE, tRAND and tFN may be all zero in the initial interval. tBASE, tRAND and tFN may be all zero in an interframe interval. All interframe intervals may have different tBASE, tRAND and tFN times. Figure 40. Initial and interframe timing effective Interframe Interval will be equal to the larger of tBASE or tFN settings.

15.3.1 Initial time interval

  • tINIT = Total time interval before first frame is transmitted in ms
  • tBASE = Base time in ms; ≤ 5 ms not recommended
  • tRAND = Pseudo-random time in ms based on a Galois 7-bit LFSR The components of this time are described in the following sections.

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019

15.3.2 Interframe time intervals

When generating an interframe time interval the MCU loads the RFM interval generator variables and then goes to the STOP1 mode. When the interframe time interval ends the data in the RFM data buffer is automatically sent and the MCU will wake at the end of the transmission. The interframe time interval is made up of three components: (12) where:

  • tIFRM = Total time interval between each transmitted frame in ms
  • tBASE = Base time in ms; ≤ 5 ms not recommended
  • tFN = Time adder in ms for frame number
  • tRAND = Pseudo-random time in ms based on a Galois 7-bit LFSR The components of this time are described in the following sections.

15.3.3 Base time interval

The base time interval, tBASE, is used in the initial time interval and in datagram transmissions with two or more frames. The programmable frame space interval is based on a simple 8-bit, count-down timer as described by the RFBT[7:0] control bits in the RFCR4 register. This time interval is forced to zero when the RFBT[7:0] are all clear. The range of the base time must be set to 0 or between 5 and 255 ms using a clock generated from the MFO divided by 125.

15.3.4 Pseudo-random time interval

The pseudo-random time interval, tRAND, is used both in the initial and the interframe time intervals if the LFSR[6;0] bits are set to something other than all zeros. When the ISPC bit is set the pseudo-random initial time interval before the first data frame will be 40 times the value of tRAND. When the LFSR[6:0] bits are used the tRAND time will vary based on a pseudo- random generated binary number using a Galois linear feedback shift register (LFSR) implemented using the primitive polynomial for a 7-stage register as shown in Figure 41. This LFSR creates a sequence of 127 binary numbers including $01 through $3F which are each repeated only once in each sequence of 127 clocks of the shift register. The LFSR is initialized to $40 during power up of the device. When a random interval is to be determined the contents of the LFSR are sampled as the "random number" for calculating the required interval time. Following the use of the random interval the LFSR is clocked once to advance it to the next pseudo-random number. Note: The LFSR bits in RFCR5 are the seed and not the current LFSR random number, which is not accessible. The range of the pseudo-random time is 1 to 127 ms using a clock generated from the MFO divided by 125. The current value of the LFSR can be changed and/or read by the LFSR[6:0] bits in the RFCR5 register.

Figure 41. LFSR implementation Table 131. Randomization interval times

15.3.5 Frame number time

Table 132. If the frame number time is not used, the value of the selected time should be set to zero. The maximum number of frames is defined by the FNUM[3:0] control bits. RFFT[5:0] bits in the RFCR6 register. Table 132. Frame number interval times

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 Nominal frame number time interval added (ms)Value of FNUM[3:0] Number of frames Frame interval where time added Minimum Maximum 3 4 3 - 4 3 189 4 5 4 - 5 4 252 5 6 5 - 6 5 315 6 7 6 - 7 6 378 7 8 7 - 8 7 441 8 9 8 - 9 8 504 9 10 9 - 10 9 567 10 11 10 - 11 10 630 11 12 11 - 12 11 693 12 13 12 - 13 12 756 13 14 13 - 14 13 819 14 15 14 - 15 14 882 15 16 15 - 16 15 945

15.4 RFM in STOP1 mode

The entire RF transmitter digital section can remain powered up, if enabled by the RFEN bit (see Section 7.3 "Computer Operating Properly (COP) Watchdog"), when the MCU goes into the STOP1 mode.

15.5 Data encoding

The CODE[1:0] control bits select either Manchester, Bi-Phase, NRZ or MCU direct data encoding of each data bit being transferred from the RF data buffer to the RF output stage. Further, the polarity of the selected encoding method can be inverted using the POL control bit.

15.5.1 Manchester encoding

When the CODE[1:0] bits are both clear the data is Manchester encoded format, with data transmitted as a transition in voltage occurring in the middle of the bit time. The polarity of this transition is selected by the POL bit. When the POL bit is cleared, then a logical LOW is defined as an increase in signal in the middle of a bit time and a logical HIGH is defined as a decrease in signal in the middle of a bit time as shown in Figure 42. When the POL bit is set, then a logical LOW is defined as an decrease in signal in the middle of a bit time and a logical HIGH is defined as a increase in signal in the middle of a bit time as shown in Figure 43. Since there is always a transition in the middle of the bit time there must also be a transition at the start of a bit time if consecutive "1" or "0" data are present.

15.5.2 Bi-Phase encoding

When the CODE[1:0] bits are 0:1 then the data is Bi-Phase encoded format, with data transmitted as the presence or absence of a transition in signal in the middle of the bit

(high or low) during the middle of the bit time.

15.5.3 NRZ encoding

using NRZ encoding running at twice the desired data rate. Figure 42. Manchester data bit encoding (POL = 0)

Figure 45. Bi-Phase data bit encoding (POL = 1)

15.6 RF output stage

15.6.1 Modulation method

15.6.2 Carrier frequency

the PLL will be configured for a carrier center frequency of the 434 MHz.

15.6.3 RF power output

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019

15.6.4 Transmission error

Any transmission will be aborted if one of the following occurs: 1. The RCTS signal does not become active within the tLOCK time. 2. The PLL falls out of lock after once being set and the SEND bit is still active. 3. The XCO monitor output falls. If either of these cases occurs the RF output will be turned off; the SEND control bit will be cleared; and the transmission error status flag, RFEF, will be set. The RFEF bit triggers an interrupt of the MCU if the RFIEN is set. The RFEF bit is cleared by writing a logical one to the RFIAK bit.

15.6.5 Supply voltage check during RF transmission

A separate low voltage detector can be enabled during the RF transmission and a status bit checked for low voltage drops due to a weak battery during the higher transmission currents. This RF LVD can be enabled by setting the RFLVDEN bit and the resulting status is reported on the RFVF bit. The RFVF bit can be cleared by writing a logical one to the RFIAK bit if the supply voltage has risen above the detect threshold. Further, if the voltage falls far enough for the VCO and PLL to fall out-of-lock, then the RF output will be turned off and the transmission will be terminated.

15.6.6 RF Reset (RFMRST)

The RF state machine, crystal oscillator, PLL and VCO can be reset to the initial off state by the RFMRST signal generated by one of the following methods: 1. Internal RFM power-on reset (RFPOR). 2. Writing a one to the RFMRST bit in the RFCR7. Any of these reset methods will not alter any data stored in the data buffer.

15.7 RF interrupt

The RFM will interrupt the MCU when the SEND bit is cleared at the end of a data buffer transmission. This interrupt occurs at the end of a programmed set of frames. If the number of frame count FNUM[3:0] is set to zero, then only one frame is sent and the interrupt occurs at the end of that first frame transmitted. If the number of the frame count is greater than zero, then the interrupt will be generated depending on the state of the IFID bit. The interrupt will also create a flag bit, RFIF, which can be cleared by writing a logical one to the RFIAK bit. The interrupt can be enabled/disabled by the RFIEN bit.

15.8 Datagram transmission times

In order to comply with FCC requirements in the US market the periodically transmitted datagram must be less than 1 second in length and be separated by an off time that is at least 10 seconds or at least 30 times longer than the transmission time, whichever is longer. The user software must adhere to this ruling for products intended for the US market.

15.9 RFM registers

access to the output data buffer.

15.9.1 RFM Control Register 0 — RFCR0

Table 133. RFM control register 0 (RFCR0) (address $0030) Table 134. RFCR0 field descriptions $34 by the RFMRST signal which results in a default data rate of 9600 bits/sec. Table 135. Data rate option examples rate of approximately 9600 bps.

15.10 RFM control register 1 — RFCR1

The RFCR1 register contains eight control bits for the RFM as described in Table 136.

Table 136. RFM control register 1 (RFCR1) (address $0031) Table 137. RFCR1 field descriptions

  1. A value of $00 for the FRM[7:0] control bits will result in no frames being sent. The FRM[7:0] control

bits are cleared by RFMRST signal.

15.11 RFM control register 2 — RFCR2

The RFCR2 register contains eight control bits for the RFM as described in Table 138. Table 138. RFM control register 2 (RFCR2) (address $0032) Table 139. RFCR2 field descriptions prematurely interrupted by writing a logical zero to the SEND bit. 0 Data transmission ended or transmission not in progress. 1 Start data transmission or transmission in progress. RFM registers at addresses $0038 through $003B. This bit is cleared by a reset of the MCU. 0 Select the lower 16 bytes of the RFM data buffer. 1 Select the upper 16 bytes of the RFM data buffer. state at the end of each datagram. The EOM control bit is cleared by a RFMRST.

Codes greater than 10100 are reserved for test purposes and should not be used.

15.11.1 Power working domains

15.11.1.1 PTYP

15.11.1.2 PMIN

Figure 46. The power consumption in this domain is given as the maximum consumption two areas according to the lowest supply voltage encountered (1.8 or 2.5 VDC).

  • TA = –40 °C to 0 °C and VDD = 1.8 V to 3.6 V PMIN_HOT
  • TA = 0 °C to 25 °C and VDD = 2.5 V to 3.6 V
  • TA = 60 °C to 125 °C and VDD = 2.5 V to 3.6 V aaa-028039 VDD = 3.6 V VDD = 3.0 V PMIN_COLD PMIN_HOT PTYP PMIN_HOT VDD = 2.5 V VDD = 1.8 V TA = -40 °C TA = 0 °C TA = 25 °C TA = 60°C TA = 105 °C Typical consumption

Figure 46. RF power domains

15.12 RFM control register 3 — RFCR3

which sets the number of frames in each RF datagram. Table 140. RFM control register 3 (RFCR3) (address $0033) Table 141. RFCR3 field descriptions 0 The XCO remains powered up as long as the SEND bit is set. 1 The XCO is powered down during RFM controlled interframe timing events. Initial Random Space — When the ISPC bit is set the initial time delay before the first frame will be enabled. This bit is cleared by an RFM reset. 1 Initial time interval enabled.

interrupted. The IFID control bit is cleared by the RFMRST signal. 0 The RFIF bit is set and the MCU interrupted if the RFIEN bit is set, after the last frame transmitted. additional interframe message is transmitted. cleared by an RFM reset. The number of frame transmitted is the binary number plus one.

15.13 RFM control register 4 — RFCR4

Table 142. RFCR4 register — base time variable (address $0034) Table 143. RFCR4 field descriptions

15.14 RFM control register 5 — RFCR5

causing the random time variable to be ignored. Table 144. RFCR5 register — pseudo-random time variable (address $0035)

Table 145. RFCR5 field descriptions the Japanese regulation. The BOOST control bit is cleared by the RFMRST signal. 0 The VCO runs at its lower power consumption level (higher phase noise). 1 The VCO runs at its higher power consumption level (lower phase noise). for each count of the resulting LFSR[6:0] bits. A value of $00 placed in the LFSR causes the LFSR to stay at the $00 state on each clocking of the LFSR. than $00 be written to the LFSR[6:0] bits. that the effective Interframe Interval will be equal to the larger of RFBT or RFFT settings.

15.15 RFM control register 6 — RFCR6

Table 146. RFCR6 register — frame number time — RFTS[1:0] = 1:0 (address $0036) Table 147. RFCR6 field descriptions bit is cleared by the RFMRST signal. Not normally need to be adjusted by the end user.

15.16 RFM control register 7 — RFCR7

Table 148. RFM transmit control registers (RFCR7) (address $0037)

Table 149. RFCR7 field descriptions 0 RF transmission in progress or not in the data buffer mode. 1 RF transmission completed in the data buffer mode. prior RF transmission as described in Section 15.6.4 "Transmission error". Writes to this bit will be ignored. 0 No RF transmission error occurred. 1 RF transmission error occurred. 0 Voltage is and has been above RF LVD rising threshold or the RF LVD is disabled. 1 Voltage has dropped below the RF LVD falling threshold since last reset of this bit. signal has no effect on this bit. 1 Clear the RFIF, RFEF, and RFVF bits. interrupt to the MCU. The RFMRST signal clears this bit. events are routed to the RF LVD Trigger Flag. This bit is cleared by the RFMRST signal. and the RFM is ready to send data. This bit is cleared by the RFMRST signal. not affected by a reset of the MCU. This bit will always read as a zero.

15.17 PLL control registers A - PLLCR[1:0], RPAGE = 0

and Table 151. These bits are only accessible when the RPAGE bit is cleared. Table 150. PLL control registers A (PLLCR[1:0], RPAGE = 0) (address ($0038) Table 151. PLL control registers A (PLLCR[1:0], RPAGE = 0) (address ($0039) Table 152. PLLCR[1:0] field descriptions The AFREQ[12:0] control bits are cleared by the RFMRST signal. 1 LSB of AFREQ[12:0] = 3.17 kHz. CODE[1:0] bits. The POL control bit is cleared by the RFMRST signal.

0 NRZ and MCU direct DATA bit data non-inverted and Manchester encoding polarity as in Figure 42

and Bi-Phase encoding polarity as in Figure 44.

1 NRZ and MCU direct DATA bit data inverted and Manchester encoding polarity as in Figure 43 and

Bi-Phase encoding polarity as in Figure 45. source of data for the RF output. The CODE[1:0] control bits are cleared by the RFMRST signal. 00 Manchester encoded data from the RFM data buffer. 01 Bi-Phase encoded data from the RFM data buffer.

10 NRZ direct data from the RFM data buffer (can be mixed NRZ and Manchester at 2X the data

11 MCU direct mode with RF output driven by the state of the DATA bit.

15.18 PLL control registers B - PLLCR[3:2], RPAGE = 0

and Table 154. These bits are only accessible when the RPAGE bit is cleared. Table 153. PLL control registers B (PLLCR[3:2], RPAGE = 0) (address $003A) Table 154. PLL control registers B (PLLCR[3:2], RPAGE = 0) (address $003B) Table 155. PLLCR[3:2] field descriptions The BFREQ[12:0] control bits are cleared by the RFMRST signal. 1 LSB of BFREQ[12:0] = 3.17 kHz. frequency. The CF control bit is cleared by the RFMRST signal. 0 Configured for 315 MHz, 12.1154 PLL divider using a 26.000 MHz external crystal. 1 Configured for 434 MHz, 16.6923 PLL divider using a 26.000 MHz external crystal. control bit is cleared by the RFMRST signal. 1 DX 500 kHz signal connected to the TPM1 module.

15.19 EPR register — EPR (RPAGE = 1)

function of the upper 4 bits depends on the state of the VCD_EN bit. Table 156. RFM EPR registers (EPR, RPAGE = 1, VCD_EN = 0) (address $0038) Table 157. RFM EPR registers (EPR, RPAGE = 1, VCD_EN = 1) (address $0038) Table 158. EPR field descriptions Reserved Reserved bit — Not for user access if the VCD_EN bit is clear. $03. These bits are only accessible if the VCD_EN bit is clear. Reserved Reserved bits — Not for user access. VCD Enable bit — This bit allows access to the VCD[3:0] bits. This bit is cleared by the RFMRST signal. 0 PLL_LPF_[2:0] bits accessed.

15.20 RF DATA registers — RFD[31:0]

described in Table 159. These bits are unaffected by any reset. most significant byte (RFB31). This is often referred to as "little-endian" data ordering. Table 159. RF data registers (RFD[31:0]) Table 160. RFD[31:0] field descriptions bits are unaffected by any reset. clear. These bits are unaffected by any reset.

15.21 VCO calibration machine

predefined reference voltage applied to the VCO.

  • Calibration supports maxband VCO sub-bands. Maxband corresponds to the band where the VCO frequency is maximum.
  • A successive approximation algorithm is used to calculate the optimum sub-band.
  • Fc, the Center Frequency (AFREQ+BFREQ)/2 is used as the reference frequency for the VCO calibration in FSK mode (MOD = 1).
  • BFREQ is used as the reference frequency for the VCO calibration in OOK mode (MOD = 0).
  • Calibration occurs every time the VCO is enabled.
  • The calibration takes approximately 5 μs. The state machine of the calibration is shown in Figure 47. Count the number of cycles of the VCO Compare VCOcount and Targetedcount VCOband = maxband/2 Bestband = maxband/2 Difference = maxband/4 VCOband = VCOband - Difference Difference = Difference/2 VCOband = VCOband + Difference Bestband = VCOband VCOband = VCOband - Difference Difference = 1? no yes Bestband is first best band found or the closest band found
  • Maxband is the number of sub-band of the VCO
  • Bestband is the band which is going to be chosen
  • Difference is an internal variable. VCOcount = Targetedcount VCOcount < TargetedcountVCOcount > Targetedcount aaa-028040

Figure 47. VCO calibration state machine

16 Firmware

development time for the main internal operations.

16.1 Software jump table

16.2 Function documentation

can be found in the latest version of the FXTH87E Embedded Firmware User Guide.

16.2.1 General rules

  1. No output parameter can use the extreme codes (all zero’s or all one’s).
  2. The all zero’s output code will always indicate a fault and the status byte will indicate
  3. While firmware is processing, CPU resources are unavailable for application.
  4. Each measured parameter will return a limit code ($00, $FF or $1FF) if an error
  5. External ADC voltage measurements on the PTA[1:0] pins will return a full range code

that is ratiometric to the supply voltage.

16.2.1.1 FXTH87E single Z-axis firmware routines

pointing to the location of the firmware function. Table 161. FXTH87Ex02 single Z-axis firmware summary and jump routines

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 Address Routine Description E03C Reserved Reserved E03F TPMS_RF_SET_TX Initiate RF transmission E042 TPMS_RF_DYNAMIC_POWER Adjusts PA for uniform power output E045 TPMS_MSG_INIT Initialization of the emulated serial communication E048 TPMS_MSG_READ Reading data from emulated serial interface E04B TPMS_MSG_WRITE Writing data on emulated serial interface E04E TPMS_CHECKSUM_XOR Calculates a checksum for given buffer in XOR E051 TPMS_CRC8 Calculates CRC8 on portion of memory E054 TPMS_CRC16 Calculates CRC16 on portion of memory E057 TPMS_SQUARE_ROOT Calculates square root E05A TPMS_READ_ID Reads device ID stored in FLASH E05D TPMS_LF_ENABLE Enable/Disable LF for Carrier or Data E060 TPMS_LF_READ_DATA Reading LF data E063[1] TPMS_WIRE_AND_ADC_CHECK Performs checks of internal bond wires E066 TPMS_FLASH_WRITE Write to FLASH E069 TPMS_FLASH_CHECK Performs checksum on NXP firmware FLASH E06C TPMS_FLASH_ERASE Erases one page (512 bytes) of FLASH at a time E06F TPMS_READ_DYNAMIC_ACCEL Offsets Z-axis acceleration with one of 15 steps E072 TPMS_RF_ENABLE Enable RFM E075 TPMS_FLASH_PROTECTION Lock out FLASH E078 Reserved Reserved E07B TPMS_MULT_SIGN_INT16 Multiple two signed 16-bit numbers together E07E TPMS_VREG_CHECK Verify that external capacitor connected to VREG pin E081 TPMS_PRECHARGE_VREG Precharge external capacitor on VREG pin E084 Reserved Reserved E087 TPMS_READ_ACCEL_CONT_START Enable the TPMS_READ_ACCEL_CONT function. E08A TPMS_READ_ACCEL_CONT Take continuous acceleration readings and store to assigned location. E08D TPMS_READ_ACCEL_CONT_STOP Disable the TPMS_READ_ACCEL_CONT function. [1] The Wire and ADC Check firmware routine is designed to return a conversion value of 0x00. In cases of combined elevated temperature and low battery voltage, noise in the ADC system may result in a value above just above 0x00. Under these conditions, a false error result may be possible. Users are advised to call the Wire and ADC Check in conditions of minimal noise in order to minimize the possibility of false error results. Characterizations indicate the probability of false errors is minimized when the battery voltage is above 2.7V at any rated temperature, or when the battery voltage falls below 2.7V, the temperature is below 85oC. It is recommended that when needed, the application call the Wire and ADC Check when the temperature is below 85oC and battery voltage is above 2.2V at minimum.

16.2.1.2 FXTH87E dual XZ-axis firmware routines

The details on the use and execution of each firmware routine is documented in the CodeWarrior project file that is supplied by NXP. Any future updates to these firmware routines will be contained in that file. A summary of the firmware routines available is given in Table 162.

pointing to the location of the firmware function. Table 162. FXTH87Ex1x dual XZ-axis firmware summary and jump routines with dynamic offset adjustment.

and battery voltage is above 2.2V at minimum.

16.2.2 Device identification

can be read by use of the TPMS_READ_ID routine. Table 163. Device ID coding summary

00 CODE0 $E0A0 Reserved — Firmware Revision/Software Information

01 CODE1 $FDF2 ES2 ES1 ES0 PRESS ACC1 ACC0 SPCLA SPCLP

02 CODE2 $FDF3 ID7 ID6 ID5 ID4 ID3 ID2 ID1 ID0

03 CODE3 $FDF4 ID15 ID14 ID13 ID12 ID11 ID10 ID9 ID8

04 CODE4 $FDF5 ID23 ID22 ID21 ID20 ID19 ID18 ID17 ID16

05 CODE5 $FDF6 ID31 ID30 ID29 ID28 ID27 ID26 ID25 ID24

flash programming processes. Table 164. Device ID coding descriptions Reserved for NXP firmware description. Revision number for the multiple-chip-module silicon. Calibrated range for pressure. The range is a combination of this bit and the PRESS-L bit, below. Special calibration for accelerometer. Calibrated range for pressure. The range is a combination of this bit and the PRESS-H bit, above. bit 0 = 1, bit 4 = 1 indicates a 100-1500 kPa range. sequential counter for each product type. 4-bit number assigned to vendor type. bits are programmed as described above at Table 163.

16.2.3 Definition of signal ranges

definition the signal source would normally output a signal between SINLO and SINHI. Figure 48. Measurement signal range definitions of range and generate error bits and the output is forced to the 0 value. to a value of 1. Overflow results will be forced to a value of 510. and overflow rule mentioned above is used.

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019

16.3 Memory resource usage

The firmware uses the top 8192 bytes of the FLASH memory map. At address $FC00, 1024 bytes are protected from erasure, containing the sensitivity and offset coefficients for the transducers and clocks. The firmware uses no specific bytes of the RAM but will cause additional stacking of temporary values. The firmware uses two bytes ($008E and $008F) of the Parameter Registers for global flags for all routines.

16.3.1 Software stack

The RESET firmware function sets the SP register to the last address in the RAM. The user can change the default stack location to meet its own application needs.

17 Development support

17.1 Introduction

This chapter describes the single-wire BACKGROUND DEBUG mode (BDM), which uses the on-chip BACKGROUND DEBUG controller (BDC) module.

17.1.1 Features

Features of the BDC module include:

  • Single pin for mode selection and background communications
  • BDC registers are not located in the memory map
  • SYNC command to determine target communications rate
  • Non-intrusive commands for memory access
  • ACTIVE BACKGROUND mode commands for CPU register access
  • GO and TRACE1 commands
  • BACKGROUND command can wake CPU from STOP or WAIT modes
  • One hardware address breakpoint built into BDC
  • Oscillator runs in STOP mode, if BDC enabled
  • COP watchdog disabled while in ACTIVE BACKGROUND mode

17.2 Background debug controller (BDC)

All MCUs in the HCS08 Family contain a single-wire BACKGROUND DEBUG interface that supports in-circuit programming of on-chip nonvolatile memory and sophisticated non-intrusive debug capabilities. Unlike debug interfaces on earlier 8-bit MCUs, this system does not interfere with normal application resources. It does not use any user memory or locations in the memory map and does not share any on-chip peripherals. BDC commands are divided into two groups:

  • ACTIVE BACKGROUND mode commands require that the target MCU is in ACTIVE BACKGROUND mode (the user program is not running). ACTIVE BACKGROUND mode commands allow the CPU registers to be read or written, and allow the user
  • Non-intrusive commands can be executed at any time even while the user’s program is running. Non-intrusive commands allow a user to read or write MCU memory locations or access status and control registers within the BACKGROUND DEBUG controller. Typically, a relatively simple interface pod is used to translate commands from a host computer into commands for the custom serial interface to the single-wire BACKGROUND DEBUG system. Depending on the development tool vendor, this interface pod may use a standard RS-232 serial port, a parallel printer port, or some other type of communications such as a universal serial bus (USB) to communicate between the host PC and the pod. The pod typically connects to the target system with ground, the BKGD/PTA4 pin, RESET, and sometimes VDD. An open-drain connection to reset allows the host to force a target system reset, which is useful to regain control of a lost target system or to control startup of a target system before the on-chip nonvolatile memory has been programmed. Sometimes VDD can be used to allow the pod to use power from the target system to avoid the need for a separate power supply. However, if the pod is powered separately, it can be connected to a running target system without forcing a target system reset or otherwise disturbing the running application program. 5NO CONNECT NO CONNECT RESET BKGD GND VDD aaa-028042

Figure 49. BDM tool connector

17.2.1 BKGD/PTA4 pin description

Section 17.2.2 "Communication details". response signal from which the host can determine the correct communication speed.

17.2.2 Communication details

falling edge whether data is transmitted or received. is aborted without affecting the memory or operating mode of the target MCU system. clock signal is shown for reference in counting cycles. no need to treat the line as an open-drain signal during this period. Figure 50. BDC host-to-target serial bit timing

17.2.3 BDC commands

17.2.3.1 Coding structure nomenclature

Table 165. BDC command summary document order no. HCS08RMv1/D. document order no. HCS08RMv1/D.

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 Command Mnemonic Active BDM/ Non-intrusive Coding Structure Description READ_LAST Non-intrusive E8/SS/RD Re-read byte from address just read and report status WRITE_BYTE Non-intrusive C0/AAAA/WD/d Write a byte to target memory WRITE_BYTE_WS Non-intrusive C1/AAAA/WD/d/SS Write a byte and report status READ_BKPT Non-intrusive E2/RBKP Read BDCBKPT breakpoint register WRITE_BKPT Non-intrusive C2/WBKP Write BDCBKPT breakpoint register GO Active BDM 08/d Go to execute the user application program starting at the address currently in the PC TRACE1 Active BDM 10/d Trace 1 user instruction at the address in the PC, then return to ACTIVE BACKGROUND mode TAGGO Active BDM 18/d Same as GO but enable external tagging (HCS08 devices have no external tagging pin) READ_A Active BDM 68/d/RD Read accumulator (A) READ_CCR Active BDM 69/d/RD Read condition code register (CCR) READ_PC Active BDM 6B/d/RD16 Read program counter (PC) READ_HX Active BDM 6C/d/RD16 Read H and X register pair (H:X) READ_SP Active BDM 6F/d/RD16 Read stack pointer (SP) READ_NEXT Active BDM 70/d/RD Increment H:X by one then read memory byte located at H:X READ_NEXT_WS Active BDM 71/d/SS/RD Increment H:X by one then read memory byte located at H:X. Report status and data. WRITE_A Active BDM 48/WD/d Write accumulator (A) WRITE_CCR Active BDM 49/WD/d Write condition code register (CCR) WRITE_PC Active BDM 4B/WD16/d Write program counter (PC) WRITE_HX Active BDM 4C/WD16/d Write H and X register pair (H:X) WRITE_SP Active BDM 4F/WD16/d Write stack pointer (SP) WRITE_NEXT Active BDM 50/WD/d Increment H:X by one, then write memory byte located at H:X WRITE_NEXT_WS Active BDM 51/WD/d/SS Increment H:X by one, then write memory byte located at H:X. Also report status. [1] The SYNC command is a special operation that does not have a command code. The SYNC command is unlike other BDC commands because the host does not necessarily know the correct communications speed to use for BDC communications until after it has analyzed the response to the SYNC command. To issue a SYNC command, the host:

  • Drives the BKGD/PTA4 pin low for at least 128 cycles of the slowest possible BDC clock (The slowest clock is normally the reference oscillator/64 or the self-clocked rate/64.)

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019

  • Drives BKGD/PTA4 high for a brief speedup pulse to get a fast rise time (This speedup pulse is typically one cycle of the fastest clock in the system.)
  • Removes all drive to the BKGD/PTA4 pin so it reverts to high impedance
  • Monitors the BKGD/PTA4 pin for the sync response pulse The target, upon detecting the SYNC request from the host (which is a much longer low time than would ever occur during normal BDC communications):
  • Waits for BKGD/PTA4 to return to a logic high
  • Delays 16 cycles to allow the host to STOP driving the high speedup pulse
  • Drives BKGD/PTA4 low for 128 BDC clock cycles
  • Drives a 1-cycle high speedup pulse to force a fast rise time on BKGD/PTA4
  • Removes all drive to the BKGD/PTA4 pin so it reverts to high impedance The host measures the low time of this 128-cycle sync response pulse and determines the correct speed for subsequent BDC communications. Typically, the host can determine the correct communication speed within a few percent of the actual target speed and the communication protocol can easily tolerate speed errors of several percent.

17.2.4 BDC hardware breakpoint

The BDC includes one relatively simple hardware breakpoint that compares the CPU address bus to a 16-bit match value in the BDCBKPT register. This breakpoint can generate a forced breakpoint or a tagged breakpoint. A forced breakpoint causes the CPU to enter ACTIVE BACKGROUND mode at the first instruction boundary following any access to the breakpoint address. The tagged breakpoint causes the instruction opcode at the breakpoint address to be tagged so that the CPU will enter ACTIVE BACKGROUND mode rather than executing that instruction if and when it reaches the end of the instruction queue. This implies that tagged breakpoints can only be placed at the address of an instruction opcode while forced breakpoints can be set at any address. The breakpoint enable (BKPTEN) control bit in the BDC status and control register (BDCSCR) is used to enable the breakpoint logic (BKPTEN = 1). When BKPTEN = 0, its default value after reset, the breakpoint logic is disabled and no BDC breakpoints are requested regardless of the values in other BDC breakpoint registers and control bits. The force/tag select (FTS) control bit in BDCSCR is used to select forced (FTS = 1) or tagged (FTS = 0) type breakpoints.

17.3 Register definition

This section contains the descriptions of the BDC registers and control bits. This section refers to registers and control bits only by their names. A NXP-provided equate or header file is used to translate these names into the appropriate absolute addresses.

17.3.1 BDC registers and control bits

The BDC has two registers:

  • The BDC status and control register (BDCSCR) is an 8-bit register containing control and status bits for the BACKGROUND DEBUG controller.
  • The BDC breakpoint match register (BDCBKPT) holds a 16-bit breakpoint match address.

17.3.2 BDC status and control register (BDCSCR)

the normal memory map of the MCU. Table 166. BDC status and control register (BDCSCR) Table 167. BDCSCR register field descriptions until a normal reset clears it.

0 BDM cannot be made active (non-intrusive commands still allowed)

1 BDM can be made active to allow ACTIVE BACKGROUND mode commands

BACKGROUND Mode Active Status — This is a read-only status bit.

0 BDM not active (user application program running)

1 BDM active and waiting for serial commands

control bit and BDCBKPT match register are ignored.

0 BDC breakpoint disabled

1 BDC breakpoint enabled

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 Field Description FTS Force/Tag Select — When FTS = 1, a breakpoint is requested whenever the CPU address bus matches the BDCBKPT match register. When FTS = 0, a match between the CPU address bus and the BDCBKPT register causes the fetched opcode to be tagged. If this tagged opcode ever reaches the end of the instruction queue, the CPU enters ACTIVE BACKGROUND mode rather than executing the tagged opcode.

0 Tag opcode at breakpoint address and enter ACTIVE BACKGROUND mode if CPU attempts to execute

1 Breakpoint match forces ACTIVE BACKGROUND mode at next instruction boundary (address need not

be an opcode) CLKSW Select Source for BDC Communications Clock — CLKSW defaults to 0, which selects the alternate BDC clock source.

0 Alternate BDC clock source

1 MCU bus clock

WAIT or STOP Status — When the target CPU is in WAIT or STOP mode, most BDC commands cannot function. However, the BACKGROUND command can be used to force the target CPU out of WAIT or STOP and into ACTIVE BACKGROUND mode where all BDC commands work. Whenever the host forces the target MCU into ACTIVE BACKGROUND mode, the host should issue a READ_STATUS command to check that BDMACT = 1 before attempting other BDC commands.

0 Target CPU is running user application code or in ACTIVE BACKGROUND mode (was not in WAIT or

STOP mode when BACKGROUND became active)

1 Target CPU is in WAIT or STOP mode, or a BACKGROUND command was used to change from WAIT or

STOP to ACTIVE BACKGROUND mode WSF WAIT or STOP Failure Status — This status bit is set if a memory access command failed due to the target CPU executing a WAIT or STOP instruction at or about the same time. The usual recovery strategy is to issue a BACKGROUND command to get out of WAIT or STOP mode into ACTIVE BACKGROUND mode, repeat the command that failed, then return to the user program. (Typically, the host would restore CPU registers and stack values and re-execute the WAIT or STOP instruction.)

0 Memory access did not conflict with a WAIT or STOP instruction

1 Memory access command failed because the CPU entered WAIT or STOP mode

Data Valid Failure Status — This status bit is not used in the MC9S08RA16 because it does not have any slow access memory.

0 Memory access did not conflict with a slow memory access

1 Memory access command failed because CPU was not finished with a slow memory access

17.3.3 BDC breakpoint match register (BDCBKPT)

This 16-bit register holds the address for the hardware breakpoint in the BDC. The BKPTEN and FTS control bits in BDCSCR are used to enable and configure the breakpoint logic. Dedicated serial BDC commands (READ_BKPT and WRITE_BKPT) are used to read and write the BDCBKPT register but is not accessible to user programs because it is not located in the normal memory map of the MCU. Breakpoints are normally set while the target MCU is in ACTIVE BACKGROUND mode before running the user application program. For additional information about setup and use of the hardware breakpoint logic in the BDC, refer to Section 17.2.4 "BDC hardware breakpoint".

17.3.4 System background debug force reset register (SBDFR)

This register contains a single write-only control bit. A serial BACKGROUND mode command such as WRITE_BYTE must be used to write to SBDFR. Attempts to write this register from a user program are ignored. Reads always return 0x00.

Table 168. System background debug force reset register (SBDFR) [1] BDFR is writable only through serial BACKGROUND mode debug commands, not from user programs. Table 169. SBDFR register field description reset. This bit cannot be written from a user program.

18 Battery charge consumption modeling

18.1 Standby current

  • QSTDBY = Standby charge over lifetime, tTOT, in mA-hr
  • tTOT = Total lifetime in hours
  • ISTDBY = General standby current in μA
  • ILF = LFR detector (if used) current in μA

18.2 Measurement events

  • QMEAS = Total measurement charge over lifetime in mA-sec
  • QPRESS = Measurement charge per pressure measurement in μA-sec
  • QTEMP = Measurement charge per temperature measurement in μA-sec
  • QVOLT = Measurement charge per voltage measurement in μA-sec
  • nPRESS = Total number of pressure measurements over lifetime
  • nTEMP = Total number of temperature measurements over lifetime

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019

  • nVOLT = Total number of voltage measurements over lifetime

18.3 Transmission events

The overall charge consumed by the transmissions is: (15) where:

  • QXMT = Transmit charge over lifetime, tTOT, in mA-hr
  • QFRM = Transmit charge per frame of data in μA-sec
  • nXMT = Number of transmissions over lifetime
  • F = Frames transmitted during each datagram

18.4 Total consumption

The overall charge consumed is: (16) where:

  • QTOT = Total charge over lifetime, tTOT, in mA-hr
  • QSTDBY = Standby charge over lifetime in mA-hr
  • QMEAS = Measurement charge over lifetime in mA-hr
  • QXMT = Transmit charge over lifetime in mA-hr
  • Y = Lifetime in years
  • SD = Battery self-discharge rate in %/year Additional margin in battery capacity can be added to the calculated value of QTOT.

Table 170. Revision history two paragraphs embedded in the graphic. paragraphs into the narrative of Section 4.3 following Figure 5. – Inserted a note as the last paragraph of Section 4.3.

  • Section 19: Revised the description for FXTH87ERM v.2.0 from "Product data sheet" to "Product reference manual." FXTH87ERM v.4.0 20181129 • Performed minor corrections throughout the narrative to conform with NXP guidelines.
  • Section 1.3 "Related documentation": Revised the steps providing a direct link to the FXTH87E page on NXP.com.
  • Section 2.2 "Features and benefits": Added "Optional XZ- or" before the feature "Z-axis accelerometer with adjustable offset option".
  • Section 2.4 "Part number definition": Added Section 2.4 to document part numbering.
  • Section 2.5 "Part marking definition": Added Section 2.5 to document part marking.
  • Section 3.1 "Overall block diagram": Revised the title from "Block diagram" to "Overall block diagram".
  • Section 4 "Pinning information": Added "This section describes the pin layout and general function of each pin." as the first paragraph in Section 4
  • Section 4.3, Figure 5: Minor updates to text within the image and in the paragraphs below the image.
  • Section 16.2.2 "Device identification", Table 164: Revised the description "special calibration for accelerometer" for "Field CODE1, 1" as follows: – Changed "0 = standard –240 to +270 g Z-axis" to "0 = standard -215 to +305 g Z-axis" – Changed "1 = extended –270 to +400 g Z-axis" to "1 = extended -285 to +400 g Z-axis"

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 Document ID Release date Description FXTH87ERM v.3.0 20180305 • Section 2.2 "Features and benefits": Revised bullet "Real-Time Interrupt driven by LFO with interrupt intervals of 8, 16, 32, 64, 128, 256, 512 or 1024 ms" to "Real-Time Interrupt driven by LFO with interrupt intervals of 2, 4, 8, 16, 32, 64, or 128 ms."

  • Figure 5: Added second paragraph.
  • Section 4.4.10: Added content to second paragraph.
  • Table 5: Updated Note 1.
  • Section 6.1 "MCU memory map": Corrected paragraph following graphic, sentence "... vectors to the user area from $DFC0 through $DFFF" to "... vectors to the user area from $DFE0 through $DFFF".
  • Figure 8: Updated graphic.
  • Section 6.8 "Security": Corrected second paragraph sentence "...state of SEC[1:0] = 1 1 unsecures the device" to "...state of SEC[1:0] = 1 1 secures the device".
  • Table 31: Updated description for Vector 12.
  • Table 35: Updated description for Field 7, RTIF.
  • Table 40: Corrected Field 1 BKGDPE description "... applications as an input-only" to ... application as an output-only" and "0 BKGD function disabled, PTA4 enabled" to "0 BKGD function disabled, PTA4 output-only enabled".
  • Table 56: Added note to description.
  • Table 125: Corrected DEQEN bit reset value from "1" to "0".
  • Table 152: Corrected figure links in Field 2, POL. FXTH87ERM v.2.0 20170919 • Product reference manual

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019

20 Legal information

20.1 Definitions

Draft — The document is a draft version only. The content is still under internal review and subject to formal approval, which may result in modifications or additions. NXP Semiconductors does not give any representations or warranties as to the accuracy or completeness of information included herein and shall have no liability for the consequences of use of such information.

20.2 Disclaimers

Limited warranty and liability — Information in this document is believed to be accurate and reliable. However, NXP Semiconductors does not give any representations or warranties, expressed or implied, as to the accuracy or completeness of such information and shall have no liability for the consequences of use of such information. NXP Semiconductors takes no responsibility for the content in this document if provided by an information source outside of NXP Semiconductors. In no event shall NXP Semiconductors be liable for any indirect, incidental, punitive, special or consequential damages (including - without limitation - lost profits, lost savings, business interruption, costs related to the removal or replacement of any products or rework charges) whether or not such damages are based on tort (including negligence), warranty, breach of contract or any other legal theory. Notwithstanding any damages that customer might incur for any reason whatsoever, NXP Semiconductors’ aggregate and cumulative liability towards customer for the products described herein shall be limited in accordance with the Terms and conditions of commercial sale of NXP Semiconductors. Right to make changes — NXP Semiconductors reserves the right to make changes to information published in this document, including without limitation specifications and product descriptions, at any time and without notice. This document supersedes and replaces all information supplied prior to the publication hereof. Applications — Applications that are described herein for any of these products are for illustrative purposes only. NXP Semiconductors makes no representation or warranty that such applications will be suitable for the specified use without further testing or modification. Customers are responsible for the design and operation of their applications and products using NXP Semiconductors products, and NXP Semiconductors accepts no liability for any assistance with applications or customer product design. It is customer’s sole responsibility to determine whether the NXP Semiconductors product is suitable and fit for the customer’s applications and products planned, as well as for the planned application and use of customer’s third party customer(s). Customers should provide appropriate design and operating safeguards to minimize the risks associated with their applications and products. NXP Semiconductors does not accept any liability related to any default, damage, costs or problem which is based on any weakness or default in the customer’s applications or products, or the application or use by customer’s third party customer(s). Customer is responsible for doing all necessary testing for the customer’s applications and products using NXP Semiconductors products in order to avoid a default of the applications and the products or of the application or use by customer’s third party customer(s). NXP does not accept any liability in this respect. Suitability for use in automotive applications — This NXP Semiconductors product has been qualified for use in automotive applications. Unless otherwise agreed in writing, the product is not designed, authorized or warranted to be suitable for use in life support, life-critical or safety-critical systems or equipment, nor in applications where failure or malfunction of an NXP Semiconductors product can reasonably be expected to result in personal injury, death or severe property or environmental damage. NXP Semiconductors and its suppliers accept no liability for inclusion and/or use of NXP Semiconductors products in such equipment or applications and therefore such inclusion and/or use is at the customer's own risk. Quick reference data — The Quick reference data is an extract of the product data given in the Limiting values and Characteristics sections of this document, and as such is not complete, exhaustive or legally binding. Export control — This document as well as the item(s) described herein may be subject to export control regulations. Export might require a prior authorization from competent authorities. Translations — A non-English (translated) version of a document is for reference only. The English version shall prevail in case of any discrepancy between the translated and English versions.

20.3 Trademarks

Notice: All referenced brands, product names, service names and trademarks are the property of their respective owners. CodeWarrior — is a trademark of NXP B.V. NXP — is a trademark of NXP B.V.

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 Tables Tab. 14. FLASH clock divider register (FCDIV) Tab. 17. FLASH options register (FOPT) (address Tab. 20. FLASH configuration register (FCNFG) Tab. 22. FLASH protection register (FPROT) Tab. 24. FLASH status register (FSTAT) (address Tab. 26. FLASH command register (FCMD) (address Tab. 34. RTI Status/Control register (SRTISC) Tab. 37. System reset status register (SRS) (address Tab. 39. System option register 1 (SIMOPT1) Tab. 41. System option register 2 (SIMOPT2) Tab. 43. System power management status and control 1 register (SPMSC1) (address Tab. 45. System power management status and control 2 register (SPMSC2) (address Tab. 47. System power management status and control 3 register (SPMSC3) (address Tab. 51. FRC_TIMER register, MSbyte and LSbyte Tab. 52. SIM STOP exit status (SIMSES) (address Tab. 55. Port A data register (PTAD) (address $0000) .. 55 Tab. 57. Internal pullup enable for port A register Tab. 58. Port A register pullup enable field Tab. 59. Data direction for port A register (PTADD) Tab. 61. Port B data register (PTBD) (address $0004) .. 56 Tab. 63. Internal pullup enable for port B register Tab. 64. Port B register pullup enable field Tab. 65. Data direction for port B register (PTBDD) Tab. 68. KBI status and control register (address Tab. 79. Timer status and control register (TPM1SC) Tab. 82. Timer counter register high (TPM1CNTH) Tab. 83. Timer counter register low (TPM1CNTL)

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 Tab. 84. Timer counter modulo register high Tab. 85. Timer counter modulo register low Tab. 86. Timer channel 0 status and control register Tab. 89. Timer channel 0 value register high Tab. 90. Timer channel 0 value register low Tab. 91. Timer channel 1 status and control register Tab. 94. Timer channel 1 value register high Tab. 95. Timer channel 1 value register low Tab. 97. PWU divider register (PWUDIV) (address Tab. 99. PWU Control/Status register 0 (PWUCS0) Tab. 102. PWU Control/Status register 1 (PWUCS1) Tab. 104. PWU wakeup status register (PWUS) Tab. 106. LFR control register 1 (LFCTL1) (address Tab. 108. LFR control register 2 (LFCTL2) (address Tab. 110. LFR control register 3 (LFCTL3) (address Tab. 112. LFR control register 4 (LFCTL4) (address Tab. 114. LFR status register (LFS, LPAGE = 0) Tab. 116. LFR data register (LFDATA) when LPAGE = Tab. 123. LFR control register D (LFCTRLD, LPAGE = Tab. 125. LFR control register C (LFCTRLC, LPAGE = Tab. 127. LFR control register B (LFCTRLB, LPAGE = Tab. 129. LFR control register A (LFCTRLA, LPAGE = Tab. 133. RFM control register 0 (RFCR0) (address Tab. 136. RFM control register 1 (RFCR1) (address Tab. 138. RFM control register 2 (RFCR2) (address Tab. 140. RFM control register 3 (RFCR3) (address Tab. 142. RFCR4 register — base time variable Tab. 144. RFCR5 register — pseudo-random time Tab. 146. RFCR6 register — frame number time — Tab. 148. RFM transmit control registers (RFCR7) Tab. 150. PLL control registers A (PLLCR[1:0], Tab. 151. PLL control registers A (PLLCR[1:0], Tab. 153. PLL control registers B (PLLCR[3:2], Tab. 154. PLL control registers B (PLLCR[3:2], Tab. 156. RFM EPR registers (EPR, RPAGE = 1, Tab. 157. RFM EPR registers (EPR, RPAGE = 1, Tab. 161. FXTH87Ex02 single Z-axis firmware Tab. 162. FXTH87Ex1x dual XZ-axis firmware

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019 Tab. 168. System background debug force reset Figures Fig. 4. FXTH87E QFN optional Z-axis Fig. 28. Manchester encoded datagram for LFPOL = Fig. 29. Manchester encoded datagram for LFPOL = Fig. 32. Antenna Q-factor equivalent model for the Fig. 51. BDC target-to-host serial bit timing (Logic 1) ..166 Fig. 52. BDM target-to-host serial bit timing (Logic 0) ..166

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019

7.11.5 System Power Management Status and

7.11.6 System Power Management Status and

10.4.6.4 Indexed, 8-Bit Offset with Post Increment

11.4.2 Timer counter registers

11.4.3 Timer counter modulo registers

11.4.4 Timer channel 0 status and control register

11.4.5 Timer channel value registers

11.4.6 Timer channel 1 status and control register

11.4.7 Timer channel value registers

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Reference manual Rev. 5.0 — 4 February 2019

13.3 PWU control/status register 0 — PWUCS0

14.17.7 LFR ID registers (LFIDH:LFIDL, LPAGE = 0) ..129

14.17.8 LFR control register D (LFCTRLD, LPAGE =

14.17.9 LFR control register C (LFCTRLC, LPAGE =

14.17.10 LFR control register B (LFCTRLB, LPAGE =

14.17.11 LFR control register A (LFCTRLA, LPAGE =

15.6.5 Supply voltage check during RF

15.17 PLL control registers A - PLLCR[1:0],

15.18 PLL control registers B - PLLCR[3:2],

17.3.3 BDC breakpoint match register (BDCBKPT) .. 171

17.3.4 System background debug force reset

NXP Semiconductors FXTH87E FXTH87E, Family of Tire Pressure Monitor Sensors Please be aware that important notices concerning this document and the product(s) described herein, have been included in section 'Legal information'. © NXP B.V. 2019. All rights reserved. For more information, please visit: http://www.nxp.com For sales office addresses, please send an email to: salesaddresses@nxp.com Date of release: 4 February 2019 Document identifier: FXTH87ERM