PN5180A0XX NXP | Alldatasheet

Document overview

  • Manufacturer or author: Provided By www.digicamel.com(FREE DATASHEET DOWNLOAD SITE)
  • PDF pages: 160

Technical content

Datasheet sections

  • 1 Introduction
  • 2 General description
  • 3 Features and benefits
  • 4 Applications
  • 5 Quick reference data
  • 6 Firmware versions
  • 7 Ordering information
  • 8 Marking
  • 8.1 Package marking drawing
  • 9 Block diagram
  • 10 Pinning information
  • 10.1 Pin description
  • 11 Functional description
  • 11.1 Introduction
  • 11.2 Power-up and Clock
  • 11.2.1 Power Management Unit
  • 11.2.1.1 Supply Connections and Power-up
  • 11.2.1.2 Power-down / Reset
  • 11.2.1.3 Standby
  • 11.2.1.4 Temperature Sensor
  • 11.2.2 Reset and start-up time
  • 11.2.3 Clock concept
  • 11.3 Timer and Interrupt system
  • 11.3.1 General Purpose Timer
  • 11.3.2 Interrupt System
  • 11.3.2.1 IRQ PIN
  • 11.3.2.2 IRQ_STATUS Register
  • 11.4 SPI Host Interface
  • 11.4.1 Physical Host Interface
  • 11.4.2 Timing Specification SPI
  • 11.4.3 Logical Host Interface
  • 11.4.3.1 Host Interface Command
  • 11.4.3.2 Transmission Buffer
  • 11.4.3.3 Host Interface Command List
  • 11.5 Memories
  • 11.5.1 Overview
  • 11.5.2 EEPROM
  • 11.5.3 RAM
  • 11.5.4 Register
  • 11.6 Debug Signals
  • 11.6.1 General functionality
  • 11.6.2 Digital Debug Configuration
  • 11.6.2.1 Debug signal groups
  • 11.6.2.2 Digital Debug Output Pin Configuration
  • 11.6.3 Analog Debug Configuration
  • 11.7 AUX2 / DWL_REQ
  • 11.7.1 Firmware update
  • 11.7.2 Firmware update command set
  • 11.8 RF Functionality
  • 11.8.1 Supported RF Protocols
  • 11.8.1.1 Communication mode for ISO/IEC
  • 11.8.1.2 ISO/IEC14443 B functionality
  • 11.8.1.3 FeliCa RF functionality
  • 11.8.1.4 ISO/IEC15693 functionality
  • 11.8.1.5 ISO/IEC18000-3 Mode 3 functionality
  • 11.8.1.6 NFCIP-1 modes
  • 11.8.1.7 ISO/IEC14443 A Card operation mode
  • 11.8.1.8 NFC Configuration
  • 11.8.1.9 Mode Detector
  • 11.8.2 RF-field handling
  • 11.8.3 Transmitter TX
  • 11.8.3.3 TX Wait
  • 11.8.3.4 Over- and Undershoot prevention
  • 11.8.4 Dynamic Power Control (DPC)
  • 11.8.5 Adaptive Waveform Control (AWC)
  • 11.8.6 Adaptive Receiver Control (ARC)
  • 11.8.7 Transceive state machine
  • 11.8.8 Autocoll (Card Emulation)
  • 11.8.9 Receiver RX
  • 11.8.9.1 Reader Mode Receiver
  • 11.8.9.2 Automatic Gain Control
  • 11.8.9.3 RX Wait
  • 11.8.9.4 EMD Error handling
  • 11.8.10 Low-Power Card Detection (LPCD)
  • 11.8.10.1 Check Card register
  • 11.9 Register overview
  • 11.9.1 Register overview
  • 11.9.2 Register description
  • 12 Secure Firmware Update
  • 12.1 General functionality
  • 12.1.1 Physical Host Interface during Secure
  • 12.2 Download protection
  • 12.3 Commands
  • 12.3.1 Frame format
  • 12.3.2 Command Code Overview
  • 12.3.3 Command Code Response
  • 12.3.4 Command Code Description
  • 12.3.4.1 RESET
  • 12.3.4.2 GET_VERSION
  • 12.3.4.3 SECURE_WRITE
  • 12.3.4.4 GET_DIE_ID
  • 12.3.5 Error handling
  • 13 Limiting values
  • 14 Recommended operating conditions
  • 15 Thermal characteristics
  • 16 Characteristics
  • 17 Application information
  • 17.1 Typical component values
  • 17.2 Power supply of a microcontroller by the
  • 17.3 Zero Power wake-up
  • 17.4 LPCD while using an external DC-DC
  • 18 Packaging information
  • 19 Handling information
  • 20 Package outline
  • 21 Appendix
  • 21.1 Timer Delay for start of reception

PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes Rev. 3.8 — 4 May 2021 Product data sheet

436538 COMPANY PUBLIC

1 Introduction

This document describes the functionality and electrical specification of the high-power NFC IC PN5180A0HN/C3, PN5180A0ET/C3 with firmware versions equal or higher than FW3.A and PN5180A0HN/C4, PN5180A0ET/C4 with firmware versions equal or higher than FW4.1. The package description of the PN5180A0ET/C3 and PN5180A0ET/C4 is described in an addendum to this document. Additional documents supporting a design-in of the PN5180 are available from NXP, this additional design-in information is not part of this document.

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes

2 General description

As a highly integrated high performance full NFC Forum-compliant frontend IC for contactless communication at 13.56 MHz, this frontend IC utilizes an outstanding modulation and demodulation concept completely integrated for different kinds of contactless communication methods and protocols. The PN5180 ensures maximum interoperability for next generation of NFC enabled mobile phones. The PN5180 is optimized for point of sales terminal applications and implements a high-power NFC frontend functionality which allows to achieve EMV compliance on RF level without additional external active components. The PN5180 frontend IC supports the following RF operating modes:

  • Reader/Writer mode supporting ISO/IEC 14443 type A up to 848 kBit/s
  • Reader/Writer communication mode for MIFARE Classic contactless IC
  • Reader/Writer mode supporting ISO/IEC 14443 type B up to 848 kBit/s
  • Reader/Writer mode supporting JIS X 6319-4 (comparable with FeliCa scheme)
  • Supports reading of all NFC tag types (type 1, type 2, type 3, type 4A and type 4B)
  • Reader/Writer mode supporting ISO/IEC 15693
  • Reader/Writer mode supporting ISO/IEC 18000-3 Mode 3
  • ISO/IEC 18092 (NFC-IP1)
  • ISO/IEC 21481 (NFC-IP-2)
  • ISO/IEC 14443 type A Card emulation up to 848 kBit/s One host interface based on SPI is implemented:
  • SPI interface with data rates up to 7 Mbit/s with MOSI, MISO, NSS and SCK signals
  • Interrupt request line to inform host controller on events
  • EEPROM configurable pull-up resistor on SPI MISO line
  • Busy line to indicate to host availability of data for reading The PN5180 supports highly innovative and unique features which do not require any host controller interaction. These unique features include Dynamic Power Control (DPC), Adaptive Waveform Control (AWC), Adaptive Receiver Control (ARC), and fully automatic EMD error handling. The independency of real-time host controller interactions makes this product the best choice for systems which operate a pre-emptive multitasking OS like Linux or Android. As new power-saving feature the PN5180 allows using a general-purpose output to control an external LDO or DC-DC during Low-Power Card Detection. One general- purpose output is used to wake up an LDO or DC-DC from power-saving mode before the RF field for an LPCD polling cycle is switched on. The PN5180 supports an external silicon system-power-on switch by using the energy of the RF field generated by an NFC phone to switch on the system, like it is generated during the NFC polling loop. This unique and new Zero-Power-Wake-up feature allows designing systems with a power consumption close to zero during standby. Product data sheet Rev. 3.8 — 4 May 2021 COMPANY PUBLIC 436538 2 / 160

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes

3 Features and benefits

  • Transmitter current up to 250 mA
  • Dynamic Power Control (DPC) for optimized RF performance, even under detuned antenna conditions
  • Adaptive Waveform Control (AWC) automatically adjusts the transmitter modulation for RF compliancy
  • Adaptive Receiver Control (ARC) automatically adjusts the receiver parameters for always reliable communication
  • Includes NXP ISO/IEC14443-A and Innovatron ISO/IEC14443-B intellectual property licensing rights
  • Full compliancy with all standards relevant to NFC, contactless operation and EMVCo 3.0
  • Active load modulation supports smaller antenna in Card Emulation Mode
  • Automatic EMD handling performed without host interaction relaxes the timing requirements on the Host Controller
  • Low-power card detection (LPCD) minimizes current consumption during polling
  • Automatic support of system LDO or system DC-DC power-down mode during LPCD
  • Zero-Power-Wake-up
  • Small, industry-standard packages
  • NFC Cockpit: PC-based support tool for fast configuration of register settings
  • Development kit with 32-bit NXP LPC1769 MCU and antenna
  • NFC Reader Library with source code ready for EMVCo 3.0 L1 and NFC Forum compliance Product data sheet Rev. 3.8 — 4 May 2021 COMPANY PUBLIC 436538 3 / 160

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes

4 Applications

  • Payment
  • Physical-access
  • eGov
  • Industrial Product data sheet Rev. 3.8 — 4 May 2021 COMPANY PUBLIC 436538 4 / 160

5 Quick reference data

Table 1. Quick reference data

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes

6 Firmware versions

Firmware versions covered by this data sheet: Version 3.A (obsolete): Supports EMVCo2.6 and more ARC Parameters

  • By Default the EEPROM LPCD_REFERENCE_VALUE is set to 8
  • By Default the EEPROM LPCD Selection is set to AUTO CALIBRATION. Bit Field [1:0] 00 - Auto Calibration 01 - Self-Calibration 10 & 11 - RFU.
  • ARC Parameters supported: MIN_LEVELP, MINLEVEL, RX_HPCF and RX_GAIN Version 3.C: Supports EMVCo2.6 and replaces the version 3.A.
  • This version allows updating Firmware versions with lower version numbers after installing this firmware 3.C Version 4.0: Supports EMVCo2.6. and EMVCo 3.0 This version is available on the hardware PN5180A0HN/C3 and PN5180A0ET/C3.
  • This is the firmware version available on the product PN5180A0HN/C3 (HVQFN package) and PN5180A0ET/C3 (BGA package). This version is functionally compliant to the FW3.A
  • This firmware does not allow the installation of any lower firmware version than 4.x. For example, installation of FW 3.x is not possible once this firmware is installed. Version 4.1: Supports EMVCo2.6 and EMVCo3.0. This version is available as firmware and on the hardware PN5180A0HN/C4 and PN5180A0ET/C4.
  • This is the firmware version available on the product PN5180A0HN/C4 (HVQFN package) and PN5180A0ET/C4 (BGA package). This version is functionally compliant to the FW4.1
  • This firmware does not allow the installation of any lower firmware version than 4.x. For example, installation of FW 3.x is not possible on this product version. NXP recommends using this firmware version for new designs.
  • This firmware release is a software upgrade of existing PN5180 products. All hardware versions of the PN5180A0HN can be updated using this firmware version. Once installed, it is not possible to install a firmware version lower than 4.0.
  • The firmware supports advanced FeliCa EMD handling using a new FELICA_EMD_CONTROL register. It is recommended to initialize this register for FeliCa reader mode with a value of 00FF0019h.
  • The firmware allows circumventing communication issues with legacy Type-B cards via EEPROM configuration. It allows enabling/disabling an extra modulation pulse after every DPC gear switch from lower to higher gear number (higher to lower power level). This extra modulation pulse with the same modulation index as in the normal PCD Product data sheet Rev. 3.8 — 4 May 2021 COMPANY PUBLIC 436538 6 / 160

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes to PICC communication can trigger and properly reset the Type B PICC UART and improve the communication for some type of cards.” Product data sheet Rev. 3.8 — 4 May 2021 COMPANY PUBLIC 436538 7 / 160

7 Ordering information

Table 2. Ordering information The PN5180 is not available with other pre-installed firmware versions than listed above.

8 Marking

for sale (volume production).

  1. (Product life cycle status release for sale): blank

Table 3. Marking code HVQFN40

8.1 Package marking drawing

Figure 1. Marking PN5180 in HVQFN40 available through the NXP DocStore.

9 Block diagram

Figure 2. PN5180 Block diagram

10 Pinning information

Figure 3. Pin configuration for HVQFN40 (SOT618-1)

10.1 Pin description

2 I/O Analog test bus or Download request

Table 4. Pin description HVQFN40

24 MHz, other clock frequencies not supported)

Table 4. Pin description HVQFN40...continued The central heat sink of the HVQFN40 package shall be connected to GND. available through the NXP DocStore.

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes

11 Functional description

11.1 Introduction

The PN5180 is a High-Power NFC frontend. It implements the RF functionality like an antenna driving and receiver circuitry and all the low-level functionality to realize an NFC Forum-compliant reader. The PN5180 connects to a host microcontroller with a SPI interface for configuration, NFC data exchange and high-level NFC protocol implementation. The PN5180 allows different supply voltages for NFC drivers, internal supply and host interface providing a maximum of flexibility. The chip supply voltage and the NFC driver voltage can be chosen independently from each other. The PN5180 uses an external 27.12 MHz crystal as clock source for generating the RF field and its internal digital logic. In addition, an internal PLL allows using an accurate external clock source of either 8, 12, 16, 24 MHz. This saves the 27.12 MHz crystal in systems which implement one of the mentioned clock frequencies (e.g. for USB or system clock). Two types of memory are implemented in the PN5180: RAM and EEPROM. Internal registers of the PN5180 state machine store configuration data. The internal registers are reset to initial default values. In case of a Power-On, a low level on the pin RESET_N (Hardware triggered reset), a SOFT_RESET (Software triggered reset) by writing a "1" to the SYSTEM_CONFIG register (address 0000h), bit 8 and after leaving the standby mode. The RF configuration for dedicated RF protocols is defined by EEPROM data which is copied by a command issued from the host microcontroller - LOAD_RF_CONFIG- into the registers of the PN5180. The PN5180 is initialized with EEPROM data for the LOAD_RF_CONFIG command which has been tested to work well for one typical antenna. For customer-specific antenna sizes and dedicated antenna environment conditions like metal or ferrite, the pre-defined EEPROM settings can be modified by the user. This allows users to achieve the maximum RF performance from a given antenna design. It is mandatory to use the command LOAD_RF_CONFIG for the selection of a specific RF protocol. The command LOAD_RF_CONFIG initializes the registers faster compared to individual register writes.

11.2 Power-up and Clock

11.2.1 Power Management Unit

11.2.1.1 Supply Connections and Power-up

The Power Management Unit of the PN5180 generates internal supplies required for operation. The following pins are used to supply the IC: Product data sheet Rev. 3.8 — 4 May 2021 COMPANY PUBLIC 436538 13 / 160

  • PVDD - supply voltage for the SPI interface and control connections
  • VBAT - Supply Voltage input
  • TVDD - Transmitter supply
  • AVDD - Analog supply input, connected to VDD
  • DVDD - Digital supply input, connected to VDD
  • VDD - 1.8 V output, to be connected to AVDD and DVDD Decoupling capacitors shall be placed as close as possible to the pins of the package. Any additional filtering/damping of the transmitter supply, e.g. by ferrite beads, might have an impact on the analog RF signal quality and shall be monitored carefully. Power-up sequence of the PN5180
  • First ramp VBAT, PVDD can immediately follow, latest 2 ms after VBAT reaches 1.8 V.
  • There is no timing dependency on TVDD, only that TVDD shall rise at the same time or later than VBAT.
  • VBAT must have an equal or higher level than PVDD
  • TVDD has no other relationship to VBAT or PVDD aaa-020676 1.8 V max PVDD time VBAT voltage

Figure 4. Power-up voltages microcontroller by an IDLE IRQ. functionalities which are configurable in EEPROM. allow a collision avoidance with another RF field.

11.2.1.2 Power-down / Reset

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes in a low-power state. All digital input buffers are separated from the input pads and clamped internally (except pin RESET_N itself and the driver of the transmitter TX1, TX2). IRQ, BUSY, AUX1, AUX2 have an internal pull-down resistor which is activated on RESET_N ==0. All other output pins are switched to high impedance. To leave the power-down mode, the level at the pin RESET_N has to be set to HIGH. This high level starts the internal start-up sequence from Power-Down. After setting the pin RESET_N to high and starting the chip from Power-Down, all registers are set to default state (chip reset). The Power-down does not change any data in EEprom memory. Setting all registers to default state can be achieved either by toggling the pin RESET_N or by writing a "1" into the SYSTEM_CONFIG register (0000h) bit8, SOFT_RESET. In contrast to a LOW level on pin RESET_N, a soft reset does not set the chip into a low- power state.

11.2.1.3 Standby

The standby mode is entered immediately after sending the instruction SWITCH_MODE with standby command. All internal current sinks are set to low-power state. In opposition to the power-down mode, the digital input buffers are not separated by the input pads and keep their functionality. The digital output pins do not change their state. During standby mode, all registers values, the buffer content and the configuration itself are not kept, exceptions are the registers with addresses 05h(PADCONFIG), 07h(PADOUT) 25h (TEMP_CONTROL). To leave the standby mode, various possibilities do exist. The conditions for wake-up are configured in the register STBY_CFG.

  • Wake-up via Timer
  • Wake-up via RF level detector
  • Low Level on RESET_N
  • PVDD disappears Any host communication (data is not validated) triggers the internal start-up sequence. The reader IC is in operation mode when the internal start-up sequence is finalized, and is indicating this by an IDLE IRQ.

11.2.1.4 Temperature Sensor

The PN5180 implements a configurable temperature sensor. The temperature sensor is configurable by the TEMP_CONTROL register (25h). The Temperature Sensor supports temperature settings for 85 °C, 115 °C, 125 °C and 135 °C. In case the sensed device temperature is higher than configured, a TEMPSENS_ERROR IRQ is raised. In case of an TEMPSENS_ERROR, the Firmware is switching off the RF Field. Additionally host can set the device into standby as response to the raised IRQ. In case the sensed device temperature is higher than the configured, FW is automatically switching off the RF field in-order to protect the TX drivers and sets the TEMPSENS_ERROR_IRQ_STAT in the IRQ_STATUS register to 1. The host can either poll on the TEMPSENS_ERROR_IRQ_STAT or enable the bit TEMPSENS_ERROR_IRQ_EN in IRQ_ENABLE register to get an interrupt on the IRQ pin. Product data sheet Rev. 3.8 — 4 May 2021 COMPANY PUBLIC 436538 15 / 160

11.2.2 Reset and start-up time

receive commands on the host interface.

11.2.3 Clock concept

The clock applied to the PN5180 provides a time basis for the RF encoder and decoder. In card emulation mode, the clock is also required. cycle and clock jitter (see Table 141). The crystal is a component which is impacting the overall performance of the system. detection is used. The values of these resistors depend on the crystal which is used. Figure 5. Connection of crystal

11.3 Timer and Interrupt system

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes

11.3.1 General Purpose Timer

The Timers are used to measure certain intervals between certain configurable events of the receiver, transmitter and other RF-events. The timer signals its expiration by raising a flag and the value of the timer may be accessed via the register-set. Three general-purpose timers T0, T1, and T2 running with the PN5180 clock with several start conditions, stop conditions, time resolutions, and maximal timer periods are implemented. For automatic timeout handling during MIFARE Classic Authentication Timer2 is blocked during this operation. In case EMVCo EMD handling is enabled (EMD_CONTROL register (address 0028h), bit EMD_ENABLE) Timer1 is automatically restarted when an EMD event occurs. Timers T0 to T2 has a resolution of 20 bits and may be operated at clock frequencies derived from the 13.56 MHz system clock. Several start events can be configured: start now, start on external RF-field on/off and start on Rx (receive)/Tx (transmit) started/ ended. The timers allow reload of the counter value. At expiration of the timers, a flag is raised and an IRQ is triggered. The clock may be divided by a prescaler for frequencies of:

  • 6.78 MHz
  • 3.39 MHz
  • 1.70 MHz
  • 848 kHz
  • 424 kHz
  • 212 kHz
  • 106 kHz
  • 53 kHz

11.3.2 Interrupt System

11.3.2.1 IRQ PIN

The IRQ_ENABLE configures, which of the interrupts are routed to the IRQ pin of the PN5180. All of the interrupts can be enabled and disabled independent from each other. The IRQ on the pin can either be cleared by writing to the IRQ_CLEAR register or by reading the IRQ_STATUS register (EEPROM configuration). If not all enabled IRQ’s are cleared, the IRQ pin remains active. The polarity of the external IRQ signal is configured by EEPROM in IRQ_PIN_CONFIG (01Ah).

11.3.2.2 IRQ_STATUS Register

The IRQ_STATUS register contains the status flags. The status flags cannot be disabled. Status Flag can either be cleared by writing to the IRQ_CLEAR register or when the IRQ_STATUS register is read (EEPROM configuration) The PN5180 indicates certain events by setting bits in the register GENERAL_IRQ_STATUS and additionally, if activated, on the pin IRQ. LPCD_IRQ, GENERAL_ERROR_IRQ and HV_ERROR_IRQ are non-maskable interrupts. Product data sheet Rev. 3.8 — 4 May 2021 COMPANY PUBLIC 436538 17 / 160

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes

11.4 SPI Host Interface

The following description of the SPI host interface is valid for the NFC operation mode. The Secure Firmware Download mode uses a different physical host interface handling. Details are described in chapter 12.

11.4.1 Physical Host Interface

The interface of the PN5180 to a host microcontroller is based on a SPI interface, extended by signal line BUSY. The maximum SPI speed is 7 Mbit/s and fixed to CPOL = 0 and CPHA = 0. Only a half-duplex data transfer is supported. There is no chaining allowed, meaning that the whole instruction has to be sent or the whole receive buffer has to be read out. The whole transmit buffer shall be written at once as well. No NSS assertion is allowed during data transfer. As the MISO line is per default high-ohmic in case of NSS high, an internal pull-up resistor can be enabled via EEPROM. The BUSY signal is used to indicate that the PN5180 is not able to send or receive data over the SPI interface. The host interface is designed to support the typical interface supply voltages of 1.8 V and 3.3 V of CPUs. A dedicated supply input which defines the host interface supply voltage independent from other supplies is available (PVDD). Only a voltage of 1.8 V or 3.3 V is supported, but no voltage in the range of 1.95 V to 2.7 V.

  • Master In Slave Out (MISO) The MISO line is configured as an output in a slave device. It is used to transfer data from the slave to the master, with the most significant bit sent first. The MISO signal is put into 3-state mode when NSS is high.
  • Master Out Slave In (MOSI) The MOSI line is configured as an input in a slave device. It is used to transfer data from the master to a slave, with the most significant bit sent first.
  • Serial Clock (SCK) The serial clock is used to synchronize data movement both in and out of the device through its MOSI and MISO lines.
  • Not Slave Select (NSS) The slave select input (NSS) line is used to select a slave device. It shall be set to low before any data transaction starts and must stay low during the transaction.
  • Busy During frame reception, the BUSY line goes ACTIVE and goes to IDLE when PN5180 is able to receive a new frame or data is available (depending if SET or GET frame is issued). If there is a parameter error, the IRQ is set to ACTIVE and a GENERAL_ERROR_IRQ is set. Both master and slave devices must operate with the same timing. The master device always places data on the MOSI line a half cycle before the clock edge SCK, in order for the slave device to latch the data. The BUSY line is used to indicate that the system is processing data and cannot receive any data from a host. The system handles the busy signal different for normal mode and debug mode (test bus enabled). In the sequence below, step 3 is optional for the normal Product data sheet Rev. 3.8 — 4 May 2021 COMPANY PUBLIC 436538 18 / 160

Figure 9. Reading data from the PN5180

11.4.2 Timing Specification SPI

Figure 10. Connection to host with SPI indicated by the BUSY signal de-asserted.

11.4.3 Logical Host Interface

11.4.3.1 Host Interface Command

is 1 byte. This provides a constant offset at which message data begins.

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes aaa-023432 lnstruction Payload 1 Payload N Byte 1 Byte 2 Byte N - Size of payload depends on Instruction - Minimum payload is 1 byte Figure 11. Instruction Payload All commands are packed into one SPI Frame. An SPI Frame consists of multiple bytes. No NSS toggles allowed during sending of an SPI frame. parameters passed follow the little endian approach (Least Significant Byte first). (max. 260 bytes). The actual payload size depends on the instruction used. Figure 12. Instruction Response status register contain information on the exception.

11.4.3.2 Transmission Buffer

11.4.3.3 Host Interface Command List

Description

WRITE_REGISTER 0x00 Write one 32bit register value WRITE_REGISTER_OR_MASK 0x01 Sets one 32bit register value using a 32 bit OR mask WRITE_REGISTER_AND_MASK 0x02 Sets one 32bit register value using a 32 bit AND mask WRITE_REGISTER_MULTIPLE 0x03 Processes an array of register addresses in random order and performs the defined action on these addresses. READ_REGISTER 0x04 Reads one 32bit register value Table 5. 1-Byte Direct Commands and Direct Command Codes

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes Command Command code READ_REGISTER_MULTIPLE 0x05 Reads from an array of max.18 register addresses in random order WRITE_EEPROM 0x06 Processes an array of EEPROM addresses in random order and writes the value to these addresses READ_EEPROM 0x07 Processes an array of EEPROM addresses from a start address and reads the values from these addresses WRITE_TX_DATA 0x08 This instruction is used to write data into the transmission buffer SEND_DATA 0x09 This instruction is used to write data into the transmission buffer, the START_SEND bit is automatically set. READ_DATA 0x0A This instruction is used to read data from reception buffer, after successful reception. SWITCH_MODE 0x0B This instruction is used to switch the mode. It is only possible to switch from NormalMode to standby, LPCD or Autocoll. MIFARE_AUTHENTICATE 0x0C This instruction is used to perform a MIFARE Classic Authentication on an activated card. EPC_INVENTORY 0x0D This instruction is used to perform an inventory of ISO18000-3M3 tags. EPC_RESUME_INVENTORY 0x0E This instruction is used to resume the inventory algorithm in case it is paused. EPC_RETRIEVE_INVENTORY_ RESULT_SIZE 0x0F This instruction is used to retrieve the size of the inventory result. EPC_RETRIEVE_INVENTORY_RESULT 0x10 This instruction is used to retrieve the result of a preceding EPC_ INVENTORY or EPC_RESUME_INVENTORY instruction. LOAD_RF_CONFIG 0x11 This instruction is used to load the RF configuration from EEPROM into the configuration registers. UPDATE_RF_CONFIG 0x12 This instruction is used to update the RF configuration within EEPROM. RETRIEVE_RF_CONFIG_SIZE 0x13 This instruction is used to retrieve the number of registers for a selected RF configuration RETRIEVE_RF_CONFIG 0x14 This instruction is used to read out an RF configuration. The register address-value-pairs are available in the response - 0x15 RFU RF_ON 0x16 This instruction switch on the RF Field RF_OFF 0x17 This instruction switch off the RF Field CONFIGURE_TESTBUS_DIGITAL 0x18 Enables the Digital test bus CONFIGURE_TESTBUS_ANALOG 0x19 Enables the Analog test bus Table 5. 1-Byte Direct Commands and Direct Command Codes...continued

1 Register addressParameter

4 Register content

Table 6. WRITE_REGISTER This command is used to write a 32-bit value (little endian) to a configuration register.

4 OR_MASK

Table 7. WRITE_REGISTER mask. The modified content is written back to the register.

4 AND_MASK

Table 8. WRITE_REGISTER_AND_MAKSK

mask. The modified content is written back to the register. Table 9. WRITE_REGISTER_MULTIPLE This instruction allows processing actions on multiple addresses with a single command. command processes this array, register addresses are allowed to be in random order. For each address, an individual ACTION can be defined. Parameter value is either the REGISTER_DATA, the OR MASK or the AND_MASK.

  • 0x01 WRITE_REGISTER
  • 0x02 WRITE_REGISTER_OR_MASK
  • 0x03 WRITE_REGISTER_AND_MASK Note: In case of an exception, the operation is not rolled-back, i.e. registers which have been modified until exception occurs remain in modified state. Host has to take proper actions to recover to a defined state. aaa-023442 Command: 0x03 Byte 1 Write Multiple Registers: Register address Byte 2 WRITE_REGISTER: 0x01 Byte 3 Register content Byte 4 LSB MSB .... Register content Byte 5 Register content Byte 6 Register content Byte 7

Figure 13. Write_Register_Multiple

Table 11. READ_REGISTER_MULTIPLE...continued addresses within the command parameter. the range from 1 – 18, inclusive. If the condition is not fulfilled, an exception is raised.

1 Address in EEPROM from which write operation starts

Table 12. WRITE_EEPROM ‘EEPROM Address’. The data is written in sequential order. not fulfilled, an exception is raised.

1 Address in EEPROM from which read operation starts

1 Number of bytes to read from EEPROM

Table 13. READ_EEPROM

Table 13. READ_EEPROM...continued Table 14. WRITE_DATA started by configuring the corresponding registers. condition is not fulfilled, an exception is raised.

1 Number of valid bits in last Byte

Table 15. SEND_DATA

This command writes data to the RF transmission buffer and starts the RF transmission. transmitted for the last byte (for non-byte aligned frames). transmission but does not perform any configuration.

0 All bits of last byte are transmitted

1-7 Number of bits within last byte to be transmitted. Table 16. Coding of ‘valid bits in last byte’ command starts the transmission but does not wait for the end of transmission. with ‘Transceive’ command set. If the condition is not fulfilled, an exception is raised. Table 17. READ_DATA This command reads data from the RF reception buffer, after a successful reception. the number of bytes to be read via the SPI interface. reception buffer is invalid. If the condition is not fulfilled, an exception is raised.

1 Mode

Table 18. SWITCH_MODE this instruction. The modes Standby, LPCD and Autocoll terminate on specific conditions. controller has to reset the PN5180. range from 1 – 2690, inclusive. Wake-up Counter Value 2 Used value for wake-up counter in msecs. Table 19. Standby configuration Table 20. Standby wake-up counter configuration

being in this mode. Termination is indicated using an interrupt. Wake-up Counter Value 2 Used value for wake-up counter in msecs. Maximum supported value is 2690. Table 21. LPCD wake-up counter configuration indicated using an interrupt. Wake-up Counter Value 2 Used value for wake-up counter in msecs. Maximum supported value is 2690. Table 22. Autocoll wake-up counter configuration

2 Same as 1 but without entering standby

Table 23. Autocoll parameter Table 24. Autocoll bit mask indicating the RF technologies

Table 24. Autocoll bit mask indicating the RF technologies...continued

6 Key: Authentication key to be used

1 Block address: The address of the block for which the

authentication has to be performed.

4 UID of the card

Table 25. MIFARE_AUTHENTICATE This command is used to perform a MIFARE Classic Authentication on an activated card. response contains 1 byte indicating the authentication status. Field ‘Key’ must be 6 bytes long. Field ‘Key Type’ must contain the value 0x60 or 0x61. execution of this instruction. set accordingly (see Table 25). If the condition is not fulfilled, an exception is raised. 0 Authentication successful. 1 Authentication failed (permission denied). 2 Timeout waiting for card response (card not present). Table 26. Authentication status return value

0 No Select command is set prior to "BeginRound"

0 All bits of last byte of 'Select command' field are

a BeginRound command. CRC-16c shall not be included.

3 BeginRound: Contains the BeginRound command (according to

ISO18000-3). CRC-5 shall not be included. 1 Response contains only one timeslot. valid card response, also the card handle is included. Table 27. EPC_INVENTORY PARAMETERS guarantee the timings specified by this standard.

Figure 16. EPC GEN2 Inventory command

'Response Size' field in EPC_RETRIEVE_INVENTORY_RESULT_SIZE is greater than 0.

  1. Execute EPC_INVENTORY to start the inventory
  2. Execute EPC_RETRIEVE_INVENTORY_RESULT_SIZE
  3. If size is 0, inventory has finished.
  4. Otherwise, execute EPC_RETRIEVE_INVENTORY_RESULT
  5. Execute EPC_RESUME_INVENTORY and proceed with step 2.

Table 29. EPC_RETRIEVE_INVENTORY_RESULT_SIZE PARAMETERS results are available which means inventory algorithm has finished. Field Parameter1 must be present. If the condition is not fulfilled, an exception is raised. Table 30. EPC_RETRIEVE_INVENTORY_RESULT PARAMETERS

1 Transmitter configuration byteParameter

1 Receiver configuration byte

Table 31. LOAD_RF_CONFIG PARAMETERS configuration) and transmitter (Transmitter configuration). The PN5180 is pre-configured by EEPROM with settings for all supported protocols. settings for this protocol are changed.

  1. UPDATE_RF_CONFIG allows updating the EEPROM content defining all protocol-specific

configurations. For each protocol, a user-defined configuration can be defined.

  1. LOAD_RF_CONFIG allows loading a protocol-specific configuration from EEPROM to

registers as actual RF configuration. Figure 19. LoadRFConfig the transmitter parameter is 0xFF, transmitter configuration is not changed. not fulfilled, an exception is raised.

00 ISO 14443-A / NFC PI-106 106 80 ISO 14443-A / NFC PI-106 106

01 ISO 14443-A 212 81 ISO 14443-A 212

02 ISO 14443-A 424 82 ISO 14443-A 424

03 ISO 14443-A 848 83 ISO 14443-A 848

04 ISO 14443-B 106 84 ISO 14443-B 106

05 ISO 14443-B 212 85 ISO 14443-B 212

06 ISO 14443-B 424 86 ISO 14443-B 424

07 ISO 14443-B 848 87 ISO 14443-B 848

Table 32. LOAD_RF_CONFIG: Selection of protocol register settings

08 FeliCa / NFC PI 212 212 88 FeliCa / NFC PI 212 212

09 FeliCa / NFC PI 424 424 89 FeliCa / NFC PI 212 424

14 ISO 14443-A PICC 212 94 ISO 14443-A PICC 212

15 ISO 14443-A PICC 424 95 ISO 14443-A PICC 424

16 ISO 14443-A PICC 848 96 ISO 14443-A PICC 848

17 NFC Passive Target 212 97 NFC Passive Target 212

18 NFC Passive Target 424 98 NFC Passive Target 424

19 NFC Active Target 106 106 99 ISO 14443-A 106

Table 32. LOAD_RF_CONFIG: Selection of protocol register settings...continued Table 33. UPDATE_RF_CONFIG PARAMETERS

The size of the array of ‘Configuration data’ must be in the range from 1 – 42, inclusive. registers has to be retrieved. Table 34. RETRIEVE_RF_CONFIG_SIZE PARAMETERS configuration. The size is available in the response to this instruction. inclusive. If the condition is not fulfilled, an exception is raised. registers has to be retrieved. Table 35. RETRIEVE_RF_CONFIG PARAMETERS RETRIEVE_RF_CONFIGURATION_SIZE has to be executed first.

inclusive. If the condition is not fulfilled, an exception is raised. Table 36. RFU This command is reserved for future use. Table 37. RF_ON set after the field is switched on. Table 38. RF_OFF is set after the field is switched off.

1 Signal BankParameter

Table 39. CONFIGURE_TESTBUS_DIGITAL This command defines the type of digital test signals and their output pins on the chip. TESTBUS_ENABLE) before any signal will appear on the output pins. output pins are able to provide a digital output signal at the same time. Table 40. TB_POS CONFIGURE_TESTBUS_DIGITAL. Two parameters are passed within this command. one signal can be selected for output on a pin of the PN5180 (4 bits).

  1. A value of 8 on this position selects the 13.56 MHz clock to be put out on the selected

The high nibble of parameter 2 (1 byte) selects the output pin for the selected test signal.

01 Clock signal group

30 Card mode protocol group

58 Transceive group

70 Receiver data transfer group

73 Receiver error group

Table 41. Debug Signal Group Selection

7 CLIF clock reset

6 Signal indicating the PLL is locked

5 Signal indicating an external Field is present

Table 42. Clock Signal Group

1 Output TX envelope

0 Tx-IRQ

Table 43. Transmitter Encoder Group

7 Running flag of timer T0

6 Expiration flag of timer T0

5 Running flag of timer T1

4 Expiration flag of timer T1

3 Running flag of timer T2

2 Expiration flag of timer T2

Table 44. Timer Group

7 Synchronized clock-fail signal

6 Flag indicating that ISO/IEC14443-Type A (Miller) was detected

5 Flag indicating that FeliCa 212 kBd (Manchester) was detected

4 Flag indicating that FeliCa 424 kBd (Manchester) was detected

3 Flag indicating that ISO/IEC14443-Type B (NRZ) was detected

2 Flag indicating that the EOF was detected

1 CM data signal (Miller / Manchester / NRZ)

0 Signal indicating that the current data is valid

Table 45. Card mode Protocol Group

7 Signal indicating that the tx prefetch was completed

6 Signal initiating a tx prefetch at the BufferManager

5 Start of transmission signal to TxEncoder

2 Transceive state2

Table 46. Transceive Group

1 Transceive state1

0 Transceive state0

Table 46. Transceive Group...continued

7 Signal from SigPro indicating a collision

6 Signal from SigPro indicating end of data

5 Signal from SigPro indicating that data is valid

4 Signal from SigPro indicating received data

3 Status signal set by rx_start, ends when RX is completely over

2 Status signal indicating actual reception of data

1 Reset signal for receiver chain (at start of RX)

0 Internal RxDec bitclk

Table 47. Receiver Data Transfer Group

7 Combination of data/protocol error and collision

6 Set if RxMultiple is set, and the LEN byte indicates more than 28 bytes

2 Set if a collision has been detected

1 Protocol error flag

0 Data integrity error flag (Parity, CRC (Collision))

Table 48. Receiver Error Group Table 49. CONFIGURE_TESTBUS_ANALOG

1 Defines test signal to be provided on AUX1, the analog test signal

Table 49. CONFIGURE_TESTBUS_ANALOG...continued This command enables the Analog test bus. TESTBUS_ENABLE) before any signal will appear on the output pins. Table 50. ANALOG TEST SIGNALS

11.5 Memories

11.5.1 Overview

The PN5180 implements two different memories: EEPROM and RAM.

registers defining the RF behavior.

11.5.2 EEPROM

(Buffers) does not keep any data stored in this volatile memory. The EEPROM address range is from 0x00 to 0xFF. configuration and RF settings for fast configuration. as loaded into the PN5180 during production. the content of these EEPROM addresses.

  • EEPROM address 0x12: 0x0A
  • EEPROM address 0x13: 0x03 FW 4.0
  • EEPROM address 0x12: 0x00
  • EEPROM address 0x13: 0x04 FW 4.1
  • EEPROM address 0x12: 0x01
  • EEPROM address 0x13: 0x04 0x14 EEPROM Version R 2 15-0 EEPROM Version Number (default initialization values, e.g. for Load_RF_Config, register reset values, default DPC settings) For PN5180A0HN/C1 and PN5180A0HN/C2: Version is: 00 93 0x16 IDLE_IRQ_AFTER_BOOT RW 1 7-0 This enables the IDLE IRQ to be set after the boot has finished 0x17 TESTBUS_ENABLE RW 1 7-0 If bit 7 is set, the test bus functionality is enabled. 0x18 XTAL_BOOT_TIME RW 2 15-0 XTAL boot time in us 7-0 Configures the state (active high/low) and clearing conditions for the IRQ pin 0x1A IRQ_PIN_CONFIG RW 1

0 Cleared: IRQ active low

Table 51. EEPROM Addresses

in case a 13.56 MHz Crystal is not used. 4-byte words to the memory, little endian.

8 MHz: 03A35310 - 02A12210

12 MHz: 02A38288 - 02E10190

16 MHz: 02E2B1D8 - 02D11150

24 MHz: 02D35138 - 02E0E158 (default)

27.12 MHz crystal or external clock with PLL

Table 51. EEPROM Addresses...continued

each of the authentication stages. VALUE, bit 3:0) and starts LPCD afterwards.

RF On Field handling Procedure. detection. This time applies only in card mode.

0 DPC_ENABLE cleared: OFF; set: ENABLE

10 Duration enable

13 Step size enable

0x5F DPC_THRSH_HIGH RW 30 - Defines the AGC high threshold for each gear.

1 Digital delay can be enabled in firmware by

setting Bit3 of bMisc_Config byte in EEPROM. delay in FW. 1: Enable digital delay.

4 DPC_XI_RAM_CORRECTION Enable/Disable

0xF3 NumPadSignalMaps R/W 1 7-0 Number of Pad signal maps configured.

11.5.3 RAM

11.5.4 Register

Registers configure the PN5180 for a specific RF protocol and other functionality. the register as done by the command LOAD_RF_CONFIG.

11.6 Debug Signals

11.6.1 General functionality

address: 0x17, TESTBUS_ENABLE). CONFIGURE_TESTBUS_DIGITAL and CONFIGURE_TESTBUS_ANALOG.

11.6.2 Digital Debug Configuration

CONFIGURE_TESTBUS_DIGITAL. Two parameters are passed within this command. one signal can be selected for output on a pin of the PN5180 (4 bits).

  1. A value of 8 on this position selects the 13.56 MHz clock to be put out on the selected

The high nibble of parameter 2 (1 byte) selects the output pin for the selected test signal. Table 52. Debug Signal Group Selection

11.6.2.1 Debug signal groups

Table 53. Clock Signal Group

Table 53. Clock Signal Group...continued Table 54. Transmitter Encoder Group Table 55. Timer Group Table 56. Card mode Protocol Group

Table 56. Card mode Protocol Group...continued Table 57. Transceive Group Table 58. Receiver Data Transfer Group

Table 58. Receiver Data Transfer Group...continued Table 59. Receiver Error Group

11.6.2.2 Digital Debug Output Pin Configuration

0 IRQ pin (B2 on TFBGA64 -39 on HVQFN40)

1 GPO1 pin (B3 on TFBGA64 - 38 on HVQFN40)

2 AUX2 pin (C1 on TFBGA64 - 02 on HVQFN40)

3 AUX1 pin (B1 on TFBGA64 - 40 on HVQFN40)

Table 60. Debug Signal Output Pin Configuration

11.6.3 Analog Debug Configuration

For the output of an analog debug signal, two pins are available, AUX1 and AUX2. two analog output signals can be provided at the output pins AUX1, AUX2. command CONFIGURE_TESTBUS_ANALOG.

11.7 AUX2 / DWL_REQ

11.7.1 Firmware update

The PN5180 offers the possibility to upgrade the internal Firmware. AUX2/DWL_REQ pin during start-up is high, the PN5180 enters the download mode. mode and the pin can be used for general debug purpose.

11.7.2 Firmware update command set

firmware. The physical SPI host interface is used for download of a new firmware image. installed on the PN5180 is not possible.

11.8 RF Functionality

11.8.1 Supported RF Protocols

11.8.1.1 Communication mode for ISO/IEC 14443 type A and for MIFARE Classic

The physical level of the communication is shown in Figure 19. Figure 20. Read/write mode for ISO/IEC 14443 type A and read/write mode for MIFARE The physical parameters are described in Table 61.

Table 61. Communication overview for ISO/IEC 14443 type A and read/write mode for MIFARE Classic Figure 21. Data coding and framing according to ISO/IEC 14443 A card response The internal CRC coprocessor calculates the CRC value based on the selected protocol.

11.8.1.2 ISO/IEC14443 B functionality

The physical level of the communication is shown in Figure 21.

  1. Reader to Card NRZ, transfer speed 106 kbit/s to 848 kbit/s
  2. Card to reader, Subcarrier Load Modulation Manchester Coded or BPSK, transfer speed 106

Figure 22. ISO/IEC 14443 B read/write mode communication diagram The physical parameters are described in Table 62. Table 62. Communication overview for ISO/IEC 14443 B reader/writer The PN5180 requires the host to manage the ISO/IEC 14443 B protocol.

11.8.1.3 FeliCa RF functionality

to the FeliCa specification. The communication on a physical level is shown in Figure 22.

  1. PICC to PCD, > Load modulation

Figure 23. FeliCa read/write communication diagram The physical parameters are described in Table 63. Table 63. Communication for FeliCa reader/writer

Table 63. Communication for FeliCa reader/writer...continued The PN5180 needs to be connected to a host which implements the FeliCa protocol. register TRANSCEIVE_CONTROL in combination with the transceive state machine. Unlike for normal operation, the receiver is enabled again after a reception is finished. number of data bytes allowed per frame is limited to 28. Figure 24. RxMultiple data format

  1. Correct reception - Data integrity is correct (no CRC error), and additionally the
  2. Erroneous reception - Data is incorrect (data integrity error - CRC wrong) but frame
  3. Erroneous reception - the length byte received indicates a frame length greater than
  4. No data is copied to buffer but status byte with LenError bit set is written.
  5. Erroneous reception - the length byte is larger than the number of data bytes, which

change to next expected state is executed (WaitTransmit for transceive command). It is possible to issue the IDLE command in order to leave the RxMultiple cycle. RX_NUM_FRAMES_RECEIVED is cleared.

11.8.1.4 ISO/IEC15693 functionality

The physical parameters are described below. Table 64. Communication for ISO/IEC 15693 reader/writer "reader to card" Table 65. Communication for ISO/IEC 15693 reader/writer "card to reader"

Table 65. Communication for ISO/IEC 15693 reader/writer "card to reader"...continued [1] Fast inventory (page) read command only (ICODE proprietary command).

11.8.1.5 ISO/IEC18000-3 Mode 3 functionality

explanation of the protocol, refer to the ISO/IEC 18000-3 standard. Figure 25. EPC_GEN2 Card presence check

Figure 26. EPC GEN2 possible timeslot answers

11.8.1.6 NFCIP-1 modes

  • Active Communication mode means both the initiator and the target are using their own RF field to transmit data.
  • Passive Communication mode means that the target answers to an initiator command in a load modulation scheme. The initiator is active in terms of generating the RF field.
  • Initiator: Generates RF field at 13.56 MHz and starts the NFCIP-1 communication.
  • Target: responds to initiator command either in a load modulation scheme in Passive Communication mode or using a self-generated and self-modulated RF field for Active Communication mode. In order, to support the NFCIP-1 standard the PN5180 supports the Active and Passive Communication mode at the transfer speeds 106 kbit/s, 212 kbit/s and 424 kbit/s as defined in the NFCIP-1 standard. Active communication mode Active communication mode means both the initiator and the target are using their own RF field to transmit data. Product data sheet Rev. 3.8 — 4 May 2021 COMPANY PUBLIC 436538 64 / 160

Table 67. Communication overview for passive communication mode A dedicated host controller firmware is required to handle the NFCIP-1 protocol. Note: Transfer Speeds above 424 kbit/s are not defined in the NFCIP-1 standard.

  • Speed shall not be changed while continuous data exchange in a transaction.
  • Transaction includes initialization, anticollision methods and data exchange (in continuous way, meaning no interruption by another transaction). In order not to disturb current infrastructure based on 13.56 MHz, the following general rules to start an NFCIP-1 communication are defined: 1. Per default, an NFCIP-1 device is in Target mode - meaning its RF field is switched off. 2. The RF level detector is active. 3. Only if it is required by the application the NFCIP-1 device shall switch to Initiator mode. 4. An initiator shall only switch on its RF field if no external RF field is detected by the RF Level detector during a time of TIDT. (Details are specified in the ISO/IEC 18092) 5. The initiator performs initialization according to the selected mode.

11.8.1.7 ISO/IEC14443 A Card operation mode

PN5180 can be configured to act as an ISO/IEC 14443 A compliant card. according to the ISO/IEC 14443 A interface description. card activation had been successfully performed.

Figure 29. Target Mode case: Timer stop for started reception

11.8.1.8 NFC Configuration

can be handled by a host firmware as a normal data byte.

11.8.1.9 Mode Detector

emulate type A cards and peer to peer active target modes according to ISO/IEC18092.

11.8.2 RF-field handling

control the RF field is available. After power-up, the RF-field is off. cause for the error can be examined in the RF_STATUS. In order to switch off the RF-field generation, the RF_OFF instruction needs to be sent. Active Mode is supported by configuring the RF_ON instruction.

11.8.3 Transmitter TX

protocols as defined by standards ISO/IEC14443 A and B, FeliCa and ISO/IEC 18092. Figure 30. PN5180 Output driver

000 High impedance The high impedance of the transmitters

ACG according to application requirements.

110 RF high side push Open-drain, only high side (push) MOS

101 RF low side pull Open-drain, only low side (pull) MOS

Table 68. Settings for TX1 and TX2 can be achieved for the antenna voltage amplitude at the beginning of a modulation. TX1_INV_CM and TX2_INV_CM if the PN5180 is operating in card emulation mode.

Table 69. Modulation degree configuration

Table 69. Modulation degree configuration...continued

11.8.3.3 TX Wait

to PCD frame delay time (FDT). started when the devices own RF-Field is switched on. bit in the SYSTEM_CONFIG register or sending the instruction SEND_DATA.

11.8.3.4 Over- and Undershoot prevention

‘001’ (binary) with a length of three. Figure 31. Overshoot/Undershoot prevention Transmitter output which allows to control the signal shaping of the antenna output. residual carrier for the period the overshoot prevention pattern is active.

11.8.4 Dynamic Power Control (DPC)

on the loading condition of the antenna. controlled dependent on the selected protocol and the measured antenna load.

Figure 34. Lookup tables for AGC value-dependent dynamic configuration Figure 35. Transmitter supply voltage configuration, VDD(TVDD) > 3.5 V

11.8.5 Adaptive Waveform Control (AWC)

configuring not only a dedicated wave shaping configuration for the corresponding gear. dependent on the different protocols. TAU_MODE_FALLING, TAU_MODE_RISING and TX_RESIDUAL_CARRIER. Table 70. Wave shaping lookup table

Figure 36. DPC, AGC and AWC configuration

11.8.6 Adaptive Receiver Control (ARC)

registers which allow to be dynamically controlled are RX_GAIN and RX_HPCF. Gain configuration (ARC) in the EEPROM. configured since the ARC table offset changes as a result of the changed AWC size. MIN_LEVELP register configuration done by Load Protocol.

3:0 DPC GEAR: the gear number, at which the related change shall apply. Table 71. Adaptive Receiver Control lookup table

11.8.7 Transceive state machine

data dependent on the conditions of the interface. setting the SYSTEM_CONFIG.command to IDLE. start_send or by using the command SET_INSTR_SEND_DATA.

Figure 37. Transceive state machine

11.8.8 Autocoll (Card Emulation)

NFC-Forum Active and Passive Target activation (Card Emulation Mode).

  • Autocoll mode0: Autocoll mode is left when no RF field is present
  • Autocoll mode1: Autocoll mode is left when one technology is activated by an external reader. During RFoff, the chip enters standby mode automatically Product data sheet Rev. 3.8 — 4 May 2021 COMPANY PUBLIC 436538 77 / 160
  • Autocoll mode2: Autocoll mode is left when one technology is activated by an external reader. During RFoff, the chip does not enter standby mode. At start-up, the Autocoll state machine automatically performs a LOAD_RF_CONFIG with the General Target Mode Settings. When a technology is detected during activation, the Autocoll state machine performs an additional LOAD_RF_CONFIG with the corresponding technology. The card configuration for the activation is stored in EEPROM. If RandomUID is enabled (EEPROM configuration, Address 0x51), a random UID is generated after each RF-off. For all active target modes, the own RF field is automatically switched on after the initiator has switched off its own filed. aaa-020625 ReqA/WupA no no no Passive Target A enabled? IDLE READYREADY* Send SensF response Frame received entry HALT Yes and Autocoll_state_a == HALT Yes and Autocoll_state_a == IDLE ISO14443-3A PICC state machine ACTIVE Passive Target A106 IRQ line is asserted Load Protocol PICC-A106 done RX_IRQ and CARD_ACTIVATED_IRQ are set Passive Target F212/424* IRQ line is asserted Load Protocol PICC-F212 or PICC-F424 done RX_IRQ and CARD_ACTIVATED_IRQ are set *the determined baudrate can be found in the SIGPRO_CONFIG register ** Autocoll_state_a is defined in the register SYSTEM_CONFIG Active Target A106/F212/F424* IRQ line is asserted Load Protocol AT106/AT212/ AT424 done RX_IRQ is set ACTIVE* yes SensF received and Passive Target F enabled SC = 0xFFFF or EE-Value yes yes SensFReq received any other frame received Any CL Error Frame received and no error Active Mode enabled yes no no

Figure 38. Autocall state machine

11.8.9 Receiver RX

11.8.9.1 Reader Mode Receiver

improves the signal quality. steps. The low-pass cut-off frequency is above 2 MHz. channel is used in this case. Table 72. Table 71.

Figure 39. PN5180 Receiver Block diagram

11.8.9.2 Automatic Gain Control

received 13.56 MHz input sine-wave signal from the antenna (input pins RXP and RXN). RXN. For symmetric antennas, the voltage levels are the same on the pins RXP, RXN. 1.5 V to 1.65 V even under dynamic changing antenna detuning conditions. variable resistor is 10 bits. By varying the on-chip resistor, the amplitude of the input signal can be modified. sampled comparator, until the peak of the input signal matches the reference voltage. The amplitude of the RX input is therefore automatically controlled by the AGC circuit. DC coupled (AGC_VALUE <9:0>, all bits set to 1). writing any AGC configuration done previously by the host.

11.8.9.3 RX Wait

switches off its own RF-Field and an external RF-Field was detected.

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes The guard time rx_wait can be disabled by setting the register RX_WAIT_VALUE to 00h meaning the receiver is immediately enabled.

11.8.9.4 EMD Error handling

The PN5180 supports EMD handling according to the EMVCo standard. To support further extension the EMD block is configurable to allow adoption for further standard updates. The PN5180 supports automatically restart of the receiver and CLIF timer1 is restarted in case of an EMD event. The CLIF timer is selectable in the EMD_CONTROL register. An EMD event is generated:

  • Independent of received number of bytes
  • Any Residual bits and EMD_CONTROL.emd_transmission_error_above_noise = 0
  • When the received number of bytes without CRC is <= EMD_CONTROL.emd_noise_bytes_threshold
  • Independent of received number of bytes
  • Any Residual bits and EMD_CONTROL.emd_transmission_error_above_noise = 0
  • When the received number of bytes without CRC is <= EMD_CONTROL.emd_noise_bytes_threshold
  • Missing CRC (1 byte frame) when EMD_CONTROL.emd_missing_crc_is_protocol_error_type_X = 0

11.8.10 Low-Power Card Detection (LPCD)

The low-power card detection is an energy-saving configuration option for the PN5180. A low frequency oscillator (LFO) is implemented to drive a wake-up counter, waking-up PN5180 from standby mode. This allows implementation of low-power card detection polling loop at application level. The SWITCH_MODE instruction allows entering the LPCD mode with a given standby duration value. Product data sheet Rev. 3.8 — 4 May 2021 COMPANY PUBLIC 436538 81 / 160

Figure 40. LPCD configuration Before entering the LPCD mode, an LPCD reference value needs to be determined. Three options do exist for generating this reference value. instruction), which defines the duration of the standby of the PN5180. (EEPROM configuration) and then the AGC value is compared to a reference value.

  • If the AGC value exceeds the reference value, a LPCD_IRQ is raised to the host. The register configurations done by the host are not restored after wake-up. command. The host has to configure the NFC frontend for a dedicated protocol operation to allow a polling for a card.
  • If the AGC value does not exceed the limit of the reference value, no LPC_IRQ is raised and the IC is set to the first phase (standby mode) again. As an additional feature the GPO1 (general-purpose output) pin can be enabled to wake up an external DC-DC from power down for the TVDD supply. The GPO1 allows setting to high before the transmitter is switched on. This allows the wake-up of an external DC- DC from power down. The GPO1 can be set to low after the RF field is switched off to set an external DC-DC into power-down mode. The time of toggling the GPO in relation to the RF-on and RF-off timings can be configured in EEPROM addresses 0x39 and 0x3A. These two phases are executed in a loop until 1. Card / metal is detected (LPCD_IRQ is raised). 2. Reset occurs, which resets all the system configurations. The LPCD is also stopped in this case. 3. NSS on Host IF 4. RF Level Detected The behavior of the generated field is different dependent on the activation state of the DPC function:
  • If the DPC feature is not active, the ISO/IEC14443 type A 106 kbit/s settings are used during the sensing time.
  • If the DPC is active, the RF_ON command is executed. The RF field is switched on as soon as the timer configured by the SWITCH_MODE command elapses. The RF field is switched on for a duration as defined for an activated DPC. The timer for the LPCD_FIELD_ON_TIME starts to count as soon as the RF_ON command terminates. EEPROM address Name Bit value Description 0x34 LPCD_REFERENCE_VALUE - - 2 bytes: bit 15:4 RFU; bit 3:0 AGC gear 0x36 LPCD_FIELD_ON_TIME - - 1 byte: Defines the RF-ON time for the AGC measurement. The minimum RF-ON time depends on the antenna configuration and the connected matching network. It needs to be chosen in such a way that a stable condition for the AGC measurement is given at the end of the time. The byte defines the delay multiplied by 8 in microseconds. 0x37 LPCD_THRESHOLD - - 1 byte: Defines the AGC threshold value. This value is used to compare against the current AGC value during the low- power card detection phase. if the difference between AGC reference value and current AGC value is greater than LPCD_THRESHOLD, the IC wakes up from LPCD. - - This byte in EEPROM is used to control the GPO assertion during wake-up and LPCD card detect. - Defines the source of the LPCD reference value 0x38 from firmware version 3.A onwards LPCD_REFVAL_GPO_CONTROL 1:0

00 LPCD AUTO CALIBRATION

Table 73. Low-Power Card Detection: EEPROM configuration

01 LPCD SELF CALIBRATION

10 RFU

11 RFU

up from standby, before the RF field is switched on.

0 Disable Control for external TVDD DC-DC via GPO1

1 Enable Control for external TVDD DC-DC via GPO1

0 Disable Control of external TVDD DC-DC via GPO2 on

1 Enable Control of external TVDD DC-DC via GPO2 on

0 Disable Control of external TVDD DC-DC via GPO1 on

1 Enable Control of external TVDD DC-DC via GPO1 on

multiplied by 5 in microseconds. Table 73. Low-Power Card Detection: EEPROM configuration...continued

11.8.10.1 Check Card register

only the second phase - the detection phase is executed.

11.9 Register overview

11.9.1 Register overview

Table 74. Register address overview

Table 74. Register address overview...continued

11.9.2 Register description

allowed range for the bits of a symbol.

8 SOFT_RESET W 0*,1 performs a reset of the device by writing a "1" into

7 RFU R/W 0*,1 RFU

6 MFC_CRYPTO_ON R/W 0*,1 If set to 1, the mfc-crypto is enabled for end-/de-

5 PRBS_TYPE R/W 0*,1 Defines the PRBS type; If set to 1, PRBS15 is

4 RFU R/W 0*,1 RFU

3 START_SEND R/W 0*,1 If set to 1, this triggers the data transmission

000 IDLE/StopCom Command; stops all ongoing

001 RFU

Table 75. SYSTEM_CONFIG register (address 0000h) bit description

010 RFU

011 Transceive command; initiates a transceive cycle.

100 KeepCommand command; This command does not

101 LoopBack command; This command is for test

same time enables the receiver.

110 PRBS command, performs an endless transmission

111 RFU

Table 75. SYSTEM_CONFIG register (address 0000h) bit description...continued

19 LPCD_IRQ_STAT R 1 Low-Power Card Detection IRQ, fixed always to 1

18 HV_ERROR_IRQ_STAT R 1 EEPROM Failure during Programming IRQ, fixed

17 GENERAL_ERROR_IRQ_STAT R 1 General Error IRQ - fixed always to 1

16 TEMPSENS_ERROR_IRQ_EN R/W 0*, 1 Enable IRQ propagation to the pin for the

15 RX_SC_DET_IRQ_EN R/W 0*, 1 Enable IRQ propagation to the pin for the RX

14 RX_SOF_DET_IRQ_EN R/W 0*, 1 Enable IRQ propagation to the pin for the RX SOF

13 TIMER2_IRQ_EN R/W 0*, 1 Enable IRQ propagation to the pin for the Timer2

12 TIMER1_IRQ_EN R/W 0*, 1 Enable IRQ propagation to the pin for the Timer1

11 TIMER0_IRQ_EN R/W 0*, 1 Enable IRQ propagation to the pin for the Timer0

10 RF_ACTIVE_ERROR_IRQ_EN R/W 0*, 1 Enable IRQ propagation to the pin for the RF active

9 TX_RFON_IRQ_EN R/W 0*, 1 Enable IRQ propagation to the pin for the RF Field

8 TX_RFOFF_IRQ_EN R/W 0*, 1 Enable IRQ propagation to the pin for the RF Field

7 RFON_DET_IRQ_EN R/W 0*, 1 Enable IRQ propagation to the pin for the RF Field

Table 76. IRQ_ENABLE register (address 0001h) bit description

6 RFOFF_DET_IRQ_EN R/W 0*, 1 Enable IRQ propagation to the pin for the RF Field

5 STATE_CHANGE_IRQ_EN R/W 0*, 1 Enable IRQ propagation to the pin for the State

4 CARD_ACTIVATED_IRQ_EN R/W 0*, 1 Enable IRQ propagation to the pin when PN5180 is

3 MODE_DETECTED_IRQ_EN R/W 0*, 1 Enable IRQ propagation to the pin when PN5180 is

2 IDLE_IRQ_EN R/W 0*, 1 Enable IRQ propagation to the pin for the IDLE mode

1 TX_IRQ_EN R/W 0*, 1 Enable IRQ propagation to the pin for End of RF

0 RX_IRQ_EN R/W 0*, 1 Enable IRQ propagation to the pin for End of RF

Table 76. IRQ_ENABLE register (address 0001h) bit description...continued

19 LPCD_IRQ_STAT R 0*, 1 Low-Power Card Detection IRQ

18 HV_ERROR_IRQ_STAT R 0*, 1 EEPROM Failure during Programming IRQ

17 GENERAL_ERROR_IRQ_STAT R 0*, 1 General Error IRQ

16 TEMPSENS_ERROR_IRQ_STAT R 0*, 1 Temperature Sensor IRQ

15 RX_SC_DET_IRQ_STAT R 0*, 1 RX Subcarrier Detection IRQ

14 RX_SOF_DET_IRQ_STAT R 0*, 1 RX SOF Detection IRQ

13 TIMER2_IRQ_STAT R 0*, 1 Timer2 IRQ

12 TIMER1_IRQ_STAT R 0*, 1 Timer1 IRQ

11 TIMER0_IRQ_STAT R 0*, 1 Timer0 IRQ

10 RF_ACTIVE_ERROR_IRQ_STAT R 0*, 1 RF active error IRQ

9 TX_RFON_IRQ_STAT R 0*, 1 RF Field ON in PCD IRQ

8 TX_RFOFF_IRQ_STAT R 0*, 1 RF Field OFF in PCD IRQ

7 RFON_DET_IRQ_STAT R 0*, 1 RF Field ON detection IRQ

6 RFOFF_DET_IRQ_STAT R 0*, 1 RF Field OFF detection IRQ

5 STATE_CHANGE_IRQ_STAT R 0*, 1 State Change in the transceive state machine IRQ

4 CARD_ACTIVATED_IRQ_STAT R 0*, 1 Activated as a Card IRQ

3 MODE_DETECTED_IRQ_STAT R 0*, 1 External modulation scheme detection IRQ

2 IDLE_IRQ_STAT R 0*, 1 IDLE IRQ

1 TX_IRQ_STAT R 0*, 1 End of RF transmission IRQ

0 RX_IRQ_STAT R 0*, 1 End of RF reception IRQ

Table 77. IRQ_STATUS register (address 0002h) bit description

19 LPCD_IRQ_CLR R/W 0*, 1 Clear Low-Power Card Detection IRQ

18 HV_ERROR_IRQ_CLR R/W 0*, 1 Clear EEPROM Failure during Programming IRQ

17 GENERAL_ERROR_IRQ_CLR R/W 0*, 1 Clear General Error IRQ

16 TEMPSENS_ERROR_IRQ_CLR R/W 0*, 1 Clear Temperature Sensor IRQ

15 RX_SC_DET_IRQ_CLR R/W 0*, 1 Clear RX Subcarrier Detection IRQ

14 RX_SOF_DET_IRQ_CLR R/W 0*, 1 Clear RX SOF Detection IRQ

13 TIMER2_IRQ_CLR R/W 0*, 1 Clear Timer2 IRQ

12 TIMER1_IRQ_CLR R/W 0*, 1 Clear Timer1 IRQ

11 TIMER0_IRQ_CLR R/W 0*, 1 Clear Timer0 IRQ

10 RF_ACTIVE_ERROR_IRQ_CLR R/W 0*, 1 Clear RF active error IRQ

9 TX_RFON_IRQ_CLR R/W 0*, 1 Clear RF Field ON in PCD IRQ

8 TX_RFOFF_IRQ_CLR R/W 0*, 1 Clear RF Field OFF in PCD IRQ

7 RFON_DET_IRQ_CLR R/W 0*, 1 Clear RF Field ON detection IRQ

6 RFOFF_DET_IRQ_CLR R/W 0*, 1 Clear RF Field OFF detection IRQ

5 STATE_CHANGE_IRQ_CLR R/W 0*, 1 Clear State Change in the transceive state machine

4 CARD_ACTIVATED_IRQ_CLR R/W 0*, 1 Clear Activated as a Card IRQ

3 MODE_DETECTED_IRQ_CLR R/W 0*, 1 Clear External modulation scheme detection IRQ

2 IDLE_IRQ_CLR R/W 0*, 1 Clear IDLE IRQ

1 TX_IRQ_CLR R/W 0*, 1 Clear End of RF transmission IRQ

0 RX_IRQ_CLR R/W 0*, 1 Clear End of RF reception IRQ

Table 78. IRQ_CLEAR register (address 0003h) bit description Table 79. TRANSCEIVE_CONTROL register (address 0004h) bit description

3 TX_SKIP_SEND_ENABLE R/W 0*, 1 If set, not transmission is started after tx_wait is

2 TX_FRAMESTEP_ENABLE R/W 0*, 1 If set, at every start of transmission; each byte of

1 RX_MULTIPLE_ENABLE R/W 0*, 1 If set, the receiver is reactivated after the end of

containing all relevant status information of the frame. 0 INITIATOR R/W 0*, 1 If set, the CLIF is configured for initiator mode. Table 79. TRANSCEIVE_CONTROL register (address 0004h) bit description...continued

7 EN_SLEW_RATE_CONTROL R/W 0*, 1 Enables slew rate control of digital pads: The Rise/

Fall Time can be adjusted by the slew rate control. Table 80. PADCONFIG register (address 0005h) bit description

Table 81. PAD_OUT register (address 0007h) bit description

20 T0_RUNNING R 0*, 1 Indicates that timer T0 is running (busy)

Table 82. TIMER0_STATUS register (address 0008h) bit description

20 T1_RUNNING R 0*, 1 Indicates that timer T1 is running (busy)

Table 83. TIMER1_STATUS register (address 0009h) bit description

20 T2_RUNNING R 0*, 1 Indicates that timer T2 is running (busy)

Table 84. TIMER2_STATUS register (address 000Ah) bit description Reload value of the timer T0. Table 85. TIMER0_RELOAD register (address 000Bh) bit description

Reload value of the timer T1. Table 86. TIMER1_RELOAD register (address 000Ch) bit description Reload value of the timer T2. Table 87. TIMER2_RELOAD register (address 000Dh) bit description

20 T0_STOP_ON_RX_STARTED R/W 0* T0_STOP_EVENT: If set; the timer T0 is stopped

protocol-dependent and listed in the appendix.

19 T0_STOP_ON_TX_STARTED R/W 0* T0_STOP_EVENT: If set; the timer T0 is stopped

when a data transmission begins.

18 T0_STOP_ON_RF_ON_EXT R/W 0* T0_STOP_EVENT: If set; the timer T0 is stopped

when the external RF field is detected.

17 T0_STOP_ON_RF_OFF_EXT R/W 0* T0_STOP_EVENT: If set; the timer T0 is stopped

when the external RF field vanishes.

16 T0_STOP_ON_RF_ON_INT R/W 0* T0_STOP_EVENT: If set; the timer T0 is stopped

when the internal RF field is turned on.

15 T0_STOP_ON_RF_OFF_INT R/W 0* T0_STOP_EVENT: If set; the timer T0 is stopped

when the internal RF field is turned off.

14 T0_START_ON_RX_STARTED R/W 0* T0_START_EVENT: If set; the timer T0 is started

when a data reception begins (first bit is received).

13 T0_START_ON_RX_ENDED R/W 0* T0_START_EVENT: If set; the timer T0 is started

12 T0_START_ON_TX_STARTED R/W 0* T0_START_EVENT: If set; the timer T0 is started

when a data transmission begins.

11 T0_START_ON_TX_ENDED R/W 0* T0_START_EVENT: If set; the timer T0 is started

when a data transmission ends.

10 T0_START_ON_RF_ON_EXT R/W 0* T0_START_EVENT: If set; the timer T0 is started

when the external RF field is detected.

9 T0_START_ON_RF_OFF_EXT R/W 0* T0_START_EVENT: If set; the timer T0 is started

when the external RF field is not detected anymore.

8 T0_START_ON_RF_ON_INT R/W 0* T0_START_EVENT: If set; the timer T0 is started

when an internal RF field is turned on.

7 T0_START_ON_RF_OFF_INT R/W 0* T0_START_EVENT: If set; the timer T0 is started

when an internal RF field is turned off. Table 88. TIMER0_CONFIG register (address 000Eh) bit description

6 T0_START_NOW R/W 0* T0_START_EVENT: If set; the timer T0 is started

(chosen by T0_PRESCALE_SEL). reloads its preset value and continues counting down.

0 T0_ENABLE R/W 0* Enables the timer T0

Table 88. TIMER0_CONFIG register (address 000Eh) bit description...continued

20 T1_STOP_ON_RX_STARTED R/W 0* T1_STOP_EVENT: If set; the timer T1 is stopped

protocol-dependent and listed in the appendix.

19 T1_STOP_ON_TX_STARTED R/W 0* T1_STOP_EVENT: If set; the timer T1 is stopped

when a data transmission begins.

18 T1_STOP_ON_RF_ON_EXT R/W 0* T1_STOP_EVENT: If set; the timer T1 is stopped

when the external RF field is detected.

17 T1_STOP_ON_RF_OFF_EXT R/W 0* T1_STOP_EVENT: If set; the timer T1 is stopped

when the external RF field vanishes.

16 T1_STOP_ON_RF_ON_INT R/W 0* T1_STOP_EVENT: If set; the timer T1 is stopped

when the internal RF field is turned on.

15 T1_STOP_ON_RF_OFF_INT R/W 0* T1_STOP_EVENT: If set; the timer T1 is stopped

when the internal RF field is turned off.

14 T1_START_ON_RX_STARTED R/W 0* T1_START_EVENT: If set; the timer T1 is started

when a data reception begins (first bit is received).

13 T1_START_ON_RX_ENDED R/W 0* T1_START_EVENT: If set; the timer T1 is started

Table 89. TIMER1_CONFIG register (address 000Fh) bit description

12 T1_START_ON_TX_STARTED R/W 0* T1_START_EVENT: If set; the timer T1 is started

when a data transmission begins.

11 T1_START_ON_TX_ENDED R/W 0* T1_START_EVENT: If set; the timer T1 is started

when a data transmission ends.

10 T1_START_ON_RF_ON_EXT R/W 0* T1_START_EVENT: If set; the timer T1 is started

when the external RF field is detected.

9 T1_START_ON_RF_OFF_EXT R/W 0* T1_START_EVENT: If set; the timer T1 is started

when the external RF field is not detected anymore.

8 T1_START_ON_RF_ON_INT R/W 0* T1_START_EVENT: If set; the timer T1 is started

when an internal RF field is turned on.

7 T1_START_ON_RF_OFF_INT R/W 0* T1_START_EVENT: If set; the timer T1 is started

when an internal RF field is turned off.

6 T1_START_NOW R/W 0* T1_START_EVENT: If set; the timer T1 is started

(chosen by T1_PRESCALE_SEL). reloads its preset value and continues counting down.

0 T1_ENABLE R/W 0* Enables the timer T1

Table 89. TIMER1_CONFIG register (address 000Fh) bit description...continued

20 T2_STOP_ON_RX_STARTED R/W 0* T2_STOP_EVENT: If set; the timer T2 is stopped

protocol-dependent and listed in the appendix.

19 T2_STOP_ON_TX_STARTED R/W 0* T2_STOP_EVENT: If set; the timer T2 is stopped

when a data transmission begins. Table 90. TIMER2_CONFIG register (address 0010h) bit description

18 T2_STOP_ON_RF_ON_EXT R/W 0* T2_STOP_EVENT: If set; the timer T2 is stopped

when the external RF field is detected.

17 T2_STOP_ON_RF_OFF_EXT R/W 0* T2_STOP_EVENT: If set; the timer T2 is stopped

when the external RF field vanishes.

16 T2_STOP_ON_RF_ON_INT R/W 0* T2_STOP_EVENT: If set; the timer T2 is stopped

when the internal RF field is turned on.

15 T2_STOP_ON_RF_OFF_INT R/W 0* T2_STOP_EVENT: If set; the timer T2 is stopped

when the internal RF field is turned off.

14 T2_START_ON_RX_STARTED R/W 0* T2_START_EVENT: If set; the timer T2 is started

when a data reception begins (first bit is received).

13 T2_START_ON_RX_ENDED R/W 0* T2_START_EVENT: If set; the timer T2 is started

12 T2_START_ON_TX_STARTED R/W 0* T2_START_EVENT: If set; the timer T2 is started

when a data transmission begins.

11 T2_START_ON_TX_ENDED R/W 0* T2_START_EVENT: If set; the timer T2 is started

when a data transmission ends.

10 T2_START_ON_RF_ON_EXT R/W 0* T2_START_EVENT: If set; the timer T2T2 is started

when the external RF field is detected.

9 T2_START_ON_RF_OFF_EXT R/W 0* T2_START_EVENT: If set; the timer T2 is started

when the external RF field is not detected anymore.

8 T2_START_ON_RF_ON_INT R/W 0* T2_START_EVENT: If set; the timer T2 is started

when an internal RF field is turned on.

7 T2_START_ON_RF_OFF_INT R/W 0* T2_START_EVENT: If set; the timer T2 is started

when an internal RF field is turned off.

6 T2_START_NOW R/W 0* T2_START_EVENT: If set; the timer T2 is started

(chosen by T2_PRESCALE_SEL). Table 90. TIMER2_CONFIG register (address 0010h) bit description...continued

reloads its preset value and continues counting down.

0 T2_ENABLE R/W 0* Enables the timer T2

Table 91. RX_WAIT_CONFIG (address 0011h) bit description

11 RX_PARITY_TYPE R/W 0* Defines which type of the parity-bit is used Note:

10 RX_PARITY_ENABLE R/W 0* If set to 1; a parity-bit for each byte is expected;

the RX_DATA_INTEGRITY_ERROR flag is set.

9 VALUES_AFTER_COLLISION R/W 0* This bit defined the value of bits received after a

the following bit positions. Table 92. CRC_RX_CONFIG (address 0012h) bit description

000b* Preset values of the CRC register for the Rx-Decoder.

2 RX_CRC_TYPE R/W

Mode detector for ISO14443 type A and FeliCa.

1 RX_CRC_INV R/W

1 Inverted CRC value: F0B8h, this bit is set by the

Mode detector for ISO14443 type B.

0 RX_CRC_ENABLE R/W 0* If set; the Rx-Decoder checks the CRC for

Table 92. CRC_RX_CONFIG (address 0012h) bit description...continued value is included in the RX_COLL_POS. Table 93. RX_STATUS register (address 0013h) bit description

18 RX_COLLISION_DETECTED R 0* This flag is set to 1, when a collision has occurred.

17 RX_PROTOCOL_ERROR R 0* This flag is set to 1, when a protocol error has

wrong number of received data bytes.

16 RX_DATA_INTEGRITY_ERROR R 0* This flag is set to 1, if a data integrity error has been

is not set to 1 if there is a wrong parity. updated when the RxIRQ is raised. Table 93. RX_STATUS register (address 0013h) bit description...continued LSB of the defined pattern; all other bits are ignored.

0 TX_UNDERSHOOT_PROT_

Table 94. TX_UNDERSHOOT_CONFIG register (address 0014h) bit description

MSB of the defined pattern, all other bits are ignored.

0 TX_OVERSHOOT_PROT _

R/W 0*, 1 If set to 1, the overshoot protection is enabled. Table 95. TX_OVERSHOOT_CONFIG register (address 0015h) bit description by the number of carrier clocks + 1. value instead of TX_WAIT_PRESCALER. and in ISO/IEC 14443 type A. Table 96. TX_DATA_MOD register (address 0016h) bit description

Defines the tx_wait timer value. reloaded with the TX_WAIT_PRESCALER value. prescaler has to be set to 0x7F as well. Table 97. TX_WAIT_CONFIG register (address 0017h) bit description

13 TX_PARITY_LAST_INV_

12 TX_PARITY_TYPE R/W 0 Defines the type of the parity bit 0 Even Parity is

11 TX_PARITY_ENABLE R/W 0 If set to 1; a parity bit is calculated and appended to

then a NO_DATA_ERROR occurs.

10 TX_DATA_ENABLE R/W 0 If set to 1; transmission of data is enabled otherwise

only symbols are transmitted. sent 10b Symbol1 is sent 11b Symbol2 is sent. Table 98. TX_CONFIG register (address 0018h) bit description

Table 98. TX_CONFIG register (address 0018h) bit description...continued

6 TX_CRC_BYTE2_ENABLE R/W 0 If set; the CRC is calculated from the second byte

000-101b Preset values of the CRC register for the Tx-Encoder.

2 TX_CRC_TYPE R/W

1 TX_CRC_INV R/W

1 Inverted CRC checksum

0 TX_CRC_ENABLE R/W 0*, 1 If set to one, the Tx-Encoder computes and transmits

Table 99. CRC_TX_CONFIG (address 0019h) bit description

MSB is only relevant for reader mode. communication mode is detected.

001 Reserved

010 Reserved

011 Reserved

detector for ISO/IEC14443 type A and B. detector for FeliCa 212 kBd. detector for FeliCa 424 kBd. Table 100. SIGPRO_CONFIG register (address 001Ah) bit description

31 RFU R 0 Reserved

enabled and the communication mode is detected. 28:26 EDGE_DETECT_TAP_SEL Selects the number of taps of the edge-detector filter. 12:0 BIT_DETECT_TH Threshold for the "bit" decision block of the ADCBCM. Table 101. SIGPRO_CM_CONFIG register (address 001Bh) bit description

001 Use only I channel

010 Use only Q channel

011 RFU

100 Use the strongest channel

101 Use the first channel

20 BPSK_FILT6 R/W 0*-1 Reserved for test

19 RESYNC_EQ_ON R/W 0-1* Resynchronization during the SOF for an equal

correlation value is done (default = activated). 18 CORR_RESET_ON R/W 0 The correlator is reset at a reset (default = activated).

16 DATA_BEFORE_MIN R/W 0 Data is received even before the first minimum at the

SOF (default: = deactivated). values in the look-up table are not absolute values.

7 USE_SMALL_EVAL R 0 Defines the length of the evaluation period for the

Table 102. SIGPRO_RM_CONFIG register (address 001Ch) bit description

11 No Collision

4 PRE_FILTER R/W If set to 1 four samples are combined to one data.

3 RECT_FILTER R/W 0 If set to one; the ADC-values are changed to a more

2 SYNC_HIGH R/W 0*-1 Defines if the bit grid is fixed at maximum (1) or at a

minimum(0) value of the correlation. 1 FSK R 0 If set to 1; the demodulation scheme is FSK. 0 BPSK R/W 0* If set to 1, the demodulation scheme is BPSK. Table 102. SIGPRO_RM_CONFIG register (address 001Ch) bit description...continued

19 DPLL_ENABLE R 0* This bit indicates that the DPLL Controller has

18 CRC_OK R 0 This bit indicates the status of the actual CRC

evaluated at the end of a communication.

17 TX_RF_STATUS R 0 If set to 1 this bit indicates that the drivers are turned

16 RF_DET_STATUS R 0 If set to 1 this bit indicates that an external RF-Field

soon as the bit TX_RF_ENABLE is set to 1. Table 103. RF_STATUS register (address 001Dh) bit description

1 External field was detected on within TIDT timing

2 External field was detected on within TADT timing

3 No external field was detected within TADT timings

4 Peer did switch off RF-Field but no Rx event was

Table 103. RF_STATUS register (address 001Dh) bit description...continued given by (AGC_TIME_CONSTANT+1) * 13.56 MHz.

3 AGC_INPUT_SEL R/W 0* Selects the AGC value to be loaded into the AGC and

2 AGC_LOAD W 0* If set; the RX divider setting is loaded from AGC_

data. This bit is automatically cleared. Table 104. AGC_CONFIG register (address 001Eh) bit description

1 AGC_MODE_SEL R/W 1* Selects the fix AGC value:

the RX divider with a new value. Table 104. AGC_CONFIG register (address 001Eh) bit description...continued Table 105. AGC_VALUE register (address 001Fh) bit description period the overshoot prevention pattern is active.

18 TX_CW_TO_MAX_ALM_CM R/W 0* TX HI output is the maximum voltage obtainable from

12 TX_BYPASS_SC_SHAPING R/W 0* Bypasses switched capacitor TX shaping of the

fastest slew rate) for both the falling and rising edge. Table 106. RF_CONTROL_TX register (address 0020h) bit description

Table 106. RF_CONTROL_TX register (address 0020h) bit description...continued

18 TX_ALM_ENABLE R/W 0* If set to 1 ALM (active load modulation) is used for

7 TX2_INV_RM R/W 0* If 1 -> TX2 output is inverted (clk_13m56_n is used);

6 TX2_INV_CM R/W 0* If 1 -> TX2 output is inverted (clk_13m56_n is used);

5 TX1_INV_RM R/W 0* If 1 -> TX1 output is inverted (clk_13m56_n is used);

4 TX1_INV_CM R/W 0* If 1 -> TX1 output is inverted (clk_13m56_n is used);

  1. 13.56 MHz clock derived from 27.12 MHz quartz

0 CLOCK_ENABLE_DPLL R/W 0* Enables the DPLL

Table 107. RF_CONTROL_TX_CLK register (address 0021h) bit description Table 108. RF_CONTROL_RX register (address 0022h) bit description

Table 108. RF_CONTROL_RX register (address 0022h) bit description...continued

14 CM_PD_NFC_DET R/W 0* Power Down NFC level detector

Table 109. LD_CONTROL register (address 0023h) bit description

9 LDO_TVDD_OK R 0* If set, bit indicates that LDO voltage is available on

8 PARAMETER_ERROR R 0* Parameter Error on Host Communication

7 SYNTAX_ERROR R 0* Syntax Error on Host Communication

6 SEMANTIC_ERROR R 0* Semantic Error on Host Communication

5 STBY_PREVENT_RFLD R 0* Entry of STBY mode prevented due to existing RFLD

4 BOOT_TEMP R 0* Boot Reason Temp Sensor

3 BOOT_SOFT_RESET R 0* Boot Reason due to SOFT RESET

2 BOOT_WUC R 0* Boot Reason wake-up Counter

1 BOOT_RFLD R 0* Boot Reason RF Level Detector

0 BOOT_POR R 0* Boot Reason "Power on" or pin RESET_N set to

Table 110. SYSTEM_STATUS register (address 0024h) bit description

3 TEMP_ENABLE_HYST R/W 0* Enable hystereses of Temperature Sensor

2 TEMP_ENABLE R/W 0* Enable Temp Sensor

  • 00b: 85 deg
  • 01b: 115 deg
  • 10b: 125 deg
  • 11b: 135 deg

Table 111. TEMP_CONTROL register (address 0025h) bit description 13:10 AGC_GEAR R/W 0 Gear number used during LPCD Self-Calibration. reading or writing this register. Writing data to these bits has no functional effect. Table 112. AGC_REF_CONFIG register (address 0026h) bit description value the AGC_VALUE. The AGC_VALUE is used in the LPCD self-calibration. Writing data to this register is required before starting the LPCD in Self-calibration mode. previously read AGC_VALUE has to be written in any case. used in the LPCD self-calibration. AGC_REF_CONFIG, using the previously read AGC_VALUE.

3 TX_CW_TO_MAX_RM R/W 0 Maximum output voltage on TX driver

0 TX_CW_AMP_REF2TVDD RW 0 If set to 1 the reference of the unmodulated carrier is

Table 113. DPC_CONFIG register (address 0027h) bit description

7 EMD_MISSING_CRC_IS_

6 EMD_MISSING_CRC_IS_

1 EMD_TRANSMISSION_

For transmission errors >= 4 bytes the host is notified.

0 EMD_ENABLE R/W 0 Enable EMD handling

Table 114. EMD_CONTROL register (address 0028h) bit description

7 ANT_INVERT_ON_TXACTIVE R/W 0 If set to 1, the ANT short interface in card mode

transmission). Note: this bit is only valid in card mode. Table 115. ANT_CONTROL register (address 0029h) bit description

6 ANT_ALM_AUTO_SWITCH_

5 ANT_ALM_FW_RESET R/W 0 If set to 1 the ANT setting for ALM is reset to its initial

4 ANT_SHORT_SELECT_RM R/W 0 Selects the control of the ANT modulation interface in

Table 115. ANT_CONTROL register (address 0029h) bit description...continued

1 TX_CM_GSN_TXACTIVE RW 0 If set, CM GSN value is switched with tx_active

0 TX_INVERT RW 0 If this bit is set, the resulting signal is inverted

Table 116. TX_CONTROL register (address 0036h) bit description sent as preamble before the actual data. 15:12 SYNC_LEN R/W 0* Defines how many Bits of Sync_Val are valid. Example: 0 configures 1 Bit to be valid.

10 LAST_SYNC_HALF R/W 0* The last Bit of the Sync code has only half of the

length compared to all other bits (EPC V2). Table 117. SIGPRO_RM_CONFIG_EXTENSION register (address 0039h) bit description

9:8 SYNC_TYPE R/W 0* Set to 0 all 16 bits of SyncVal are interpreted as bits. Table 117. SIGPRO_RM_CONFIG_EXTENSION register (address 0039h) bit description...continued SIGPRO_RM_CONFIG_EXTENSION, bits 16:31 (16 bits). required after each LoadRfConfig command. SYNC_LEN = 0xF (1111b). or equal to FELICA_EMD_LENGTH_BYTE_MAX. FELICA_EMD_LEN_CHECK_ENABLE is set. or equal to FELICA_EMD_LENGTHBYTE_MIN. FELICA_EMD_LEN_CHECK_ENABLE is set.

4 FELICA_EMD_INTEGRITY_

response with integrity error is treated as EMD.

3 FELICA_EMD_PROTOCOL_

R/W 0*,1 Enable FeliCa EMD protocol error check.

2 FELICA_EMD_RC_CHECK_

effect, if FELICA_EMD_ENABLE is set.

1 FELICA_EMD_LEN_CHECK_

R/W 0*,1 Enable length check. If set, the length byte of the received data is checked. effect, if FELICA_EMD_ENABLE is set. Table 118. FELICA_EMD_CONTROL register (address 0043h) bit description (only available from firmware V4.1

0 FELICA_EMD_ENABLE R/W 0*, 1 Enable FeliCa EMD handling. CONTROL register are ignored.

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes

12 Secure Firmware Update

12.1 General functionality

The PN5180 supports a secure update of the implemented firmware. The secure firmware download mode is using a dedicated command set and framing which is different from the standard host interface commands used for NFC operation of the device. In Secure Firmware update mode, the PN5180 requires a dedicated physical handling of the SPI interface lines and the BUSY line. The secure firmware download mode is entered by setting the DWL_REQ pin to high during startup of the device. This pin can be used for any other functionality after startup, the level of this pin has no impact on the download functionality after startup during standard NFC operation. The firmware binary file which is used to update the PN5180 is protected with a signature. This prevents a download of any other software which is not signed by NXP. An anti-tearing function is implemented in order to detect supply voltage removal or memory fault. During the secure firmware download, the normal mode NFC operation is not available and only the command set defined for the secure firmware download is valid. In case of any failure or exception during the download, the PN5180 remains in the secure firmware download mode until a full firmware update sequence has been performed successfully. Updating the firmware of the PN5180 programs the memories for user EEPROM and RF configuration with default values. Any previous user configuration will be overwritten. The user has to take care to restore the data of these memories after a secure firmware update. The PN5180 can be used for firmware update as follows: 1. Set DWL_REQ pin to high 2. Reset 3. The PN1580 boots in download mode 4. Download new firmware version 5. Execute the check integrity command to verify the successful update (The CheckIntegrity command cannot be called while a download session is open) 6. Reset the PN5180 7. The device starts in NFC operation mode

12.1.1 Physical Host Interface during Secure Firmware Download

In Secure Firmware update mode, the PN5180 is using a different physical host interface signaling than in NFC operation mode. The BUSY line is used in a different way than for NFC operation mode, and the data is packed in frames protected by a CRC16 checksum. Product data sheet Rev. 3.8 — 4 May 2021 COMPANY PUBLIC 436538 114 / 160

  1. 2 byte header (chunk bit + length of (Payload + status))
  2. (LENGTH-1) byte payload (the LENGTH in the header includes the 1 byte status,
  3. 2 byte CRC16 (is not included in the header length number)

Figure 44. Secure Firmware Download: SPI Read (byte level information)

12.2 Download protection

into the memory of the device. without verifying the authenticity and integrity of the new data beforehand.

  1. Major number: 8 bit (MSB)
  2. Minor number: 8 bit (LSB)

therefore increasing major firmware versions is always possible. after a firmware update to check if the update had been successful.

to retrieve this firmware version information.

  • Reset (hard or soft)
  • Failure of the Signature verification of the first secure write command
  • Hash chain is broken during the download between two consecutive secure write commands
  • Protocol error in framing
  • Address mismatch
  • Critical memory failure The PN5180 provides comprehensive mechanisms to recover from all these conditions.

12.3 Commands

12.3.1 Frame format

Figure 45. Framing for Secure Firmware Download

  • RFU (bit 11..15)
  • Chunk flag used for fragmentation (bit 10)
  • length of the frame (bit 0..9 bit) Frame ( (n+1) byte)
  • Command (1 byte)
  • Payload of the command: (n-byte) CRC (2 bytes)
  • The CRC16 is compliant to X.25 (CRC-CCITT, ISO/IEC13239) standard with polynomial x^16 + x^12 + x^5 +1 and preload value 0xFFFF. The payload of one command consists of
  • Memory block address: 3 bytes Memory block size: 2 bytes
  • Memory data block: 512 bytes maximum
  • Hash of the next frame: 32 bytes Product data sheet Rev. 3.8 — 4 May 2021 COMPANY PUBLIC 436538 117 / 160

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes The first write command used for a secure firmware download includes the version number, and a hash value over the following command and the RSA signature. Every following command includes the actual data block to be updated and the hash value over the following command and data. The last command does not contain any hash value. The Payload including command can be split into chunks which allows the transfer of large payloads. aaa-024735 000001b Length Chunk 1 CRC16 CRC16000000b Length OpCode Payload 2 bytes6 bitsDL command Host side Encapsulated transport 10 bits 1 byte n bytes 000001b Length Chunk 2 CRC16 000000b Length Chunk 3 CRC16 Figure 46. Splitting commands by chunks

12.3.2 Command Code Overview

RESET F0 This command resets the IC GET_VERSION F1 This command provides the IC version and firmware version SECURE_WRITE C0 Writes chunks of data to the IC GET_DIE_ID F4 The command returns the die Identifier - all other RFU Table 119. Secure Firmware Download Commands the packet length), frame (opcode/command-code and payload) and end (CRC16). Figure 47. Secure Firmware Download command and data structure

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes

12.3.3 Command Code Response

A response message is always a multiple of 4 bytes. The first byte of the response is used to indicate the status of the last executed command. Command Command code (hex) OK 00 command processed properly ERROR 01-FF any response different from 0x00 indicates an error Table 120. Secure Firmware Command Status Return Codes

12.3.4 Command Code Description

12.3.4.1 RESET

sent. STAT is the status return code.

12.3.4.2 GET_VERSION

FM1V 1 Firmware major version FM2V 1 Firmware minor version Table 121. Secure Firmware update: GetVersion command response

12.3.4.3 SECURE_WRITE

The secure write function differs between first, middle and last write frames.

Table 122. Secure Firmware update: First Secure Write Command response

12.3.4.4 GET_DIE_ID

12.3.5 Error handling

error case, a new firmware download is required.

13 Limiting values

In accordance with the Absolute Maximum Rating System (IEC 60134). Table 123. Limiting Values

14 Recommended operating conditions

conditions section for extended periods may affect device reliability. when it is used within the recommended operating conditions. Table 124. Recommended Operating Conditions during power-on of the system.

15 Thermal characteristics

40 K/W

Table 125. Thermal characteristics HVQFN40 package

66 K/W

Table 126. Thermal characteristics TFBGA64 package Table 127. Junction Temperature

16 Characteristics

3.0 V; hard power-down; pin RESET_N set

Table 128. Current consumption Table 129. Reset pin RESET_N Table 130. Input Pin (AUX2) / DWL_REQ Table 131. output Pin AUX2 / (DWL_REQ)

Table 131. output Pin AUX2 / (DWL_REQ)...continued Table 132. GPO pin characteristics Table 133. CLK1, CLK2 pin characteristics Table 134. Output pin characteristics IRQ Table 135. Input pins SCLK, MOSI, NSS

Table 135. Input pins SCLK, MOSI, NSS...continued Table 136. Output pin MISO Table 137. Timing conditions SPI Table 138. Output pins ANT1 and ANT2

Table 139. Input pins RXp and RXn Table 140. Output pins TX1 and TX2 Table 141. Start-up time a host by raising an IDLE IRQ. Table 142. Crystal requirements for ISO/IEC14443 compliant operation Table 143. Reference input frequency requirements for 8 MHz, 12 MHz, 16 MHz and 24

2830 DVDD

27.12 MHz

Figure 48. Application diagram with minimum components (HVQFN40)

17.1 Typical component values

dependent on antenna design. Table 144. Table 140.

17.2 Power supply of a microcontroller by the PN5180 / LDO_OUT

The PN5180 is able to provide a regulated 3.3 V voltage with currents of up to 100 mA. This regulated voltage is available on pin LDO_OUT. EEPROM Address 0xE8, Misc_Config (bit 3) - if set the 3.3 V output is enabled. The supply voltage will be available during Idle mode.

Figure 49. Conditions for external 3.3 V supply voltage

17.3 Zero Power wake-up

an RF field which can be used to toggle this silicon main switch. No configuration of registers is required to use this functionality.

17.4 LPCD while using an external DC-DC

external DC-DC during Low-Power Card Detection. sufficiently early to allow a settling of the supplied output.

  1. The GPO wakes up the DC-DC

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes 2. The PN5180 switches on the RF (low-power card detection cycle) 3. If no card had been detected, the RF is switched off 4. The GPO sets the DC-DC in power-saving mode The GPO function as such can be enabled by the EEPROM register: LPCD_REFVAL_GPO_CONTROL.

  • The time between trigger of the DC-DC and RF-OFF is configured by the EEPROM register: LPCD_GPO_TOGGLE_AFTER_FIELD_OFF
  • The time between trigger of the DC-DC and RF-ON is configured by the EEPROM register: LPCD_GPO_TOGGLE_BEFORE_FIELD_ON This functionality allows implementing power efficient LPCD function even in case of a required DC-DC. Product data sheet Rev. 3.8 — 4 May 2021 COMPANY PUBLIC 436538 131 / 160

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes

18 Packaging information

Moisture Sensitivity Level (MSL) evaluation has been performed according to SNW- FQ-225B rev.04/07/07 (JEDEC J-STD-020C). MSL for the HVQFN40 package is level 3 which means 260 °C convection reflow temperature.

  • 1-week out-of-pack floor life at maximum ambient temperature 30°C/ 60 % RH (Relative Humidity) to limit possible moisture intrusion.
  • When used in production, stored under nitrogen conditions for not more than 8 days MSL for the TFBGA64 package is level 1:
  • No dry pack is required.
  • No out-of-pack floor live spec. required. Product data sheet Rev. 3.8 — 4 May 2021 COMPANY PUBLIC 436538 132 / 160

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes

19 Handling information

This device is sensitive to ElectroStatic Discharge (ESD). Observe precautions for handling electrostatic sensitive devices. Such precautions are described in the ANSI/ESD S20.20, IEC/ST 61340-5, JESD625-A or equivalent standards. Product data sheet Rev. 3.8 — 4 May 2021 COMPANY PUBLIC 436538 133 / 160

  1. Plastic or metal protrusions of 0.075 mm maximum per side are not included.

Figure 50. Package outline SOT618-1

Figure 51. Package outline SOT1336-1

21 Appendix

21.1 Timer Delay for start of reception measurement

21.2 Default protocol settings for LOAD_RF_CONFIG, Transmitter

21.2.1 ISO/IEC 14443 A-106

Table 145. ISO/IEC 14443 A-106

21.2.2 ISO/IEC 14443 A-212

Table 146. ISO/IEC 14443 A-212

21.2.3 ISO/IEC 14443 A-424

Table 147. ISO/IEC 14443 A-424

21.2.4 ISO/IEC 14443 A-848

Table 148. ISO/IEC 14443 A-848

21.2.5 ISO/IEC 14443 B-106

Table 149. ISO/IEC 14443 B-106

21.2.6 ISO/IEC 14443 B-212

Table 150. ISO/IEC 14443 B-212

21.2.7 ISO/IEC 14443 B-424

Table 151. ISO/IEC 14443 B-424

Table 151. ISO/IEC 14443 B-424...continued

21.2.8 ISO/IEC 14443 B-848

Table 152. ISO/IEC 14443 B-848

21.2.9 FeliCa-212

Table 153. FeliCa-212

21.2.10 FeliCa-424

Table 154. FeliCa-424

21.2.11 NFC active initiator A-106

Table 155. NFC active initiator A-106

Table 155. NFC active initiator A-106...continued

21.2.12 NFC active initiator A-212

Table 156. NFC active initiator A-212

21.2.13 NFC active initiator A-424

Table 157. NFC active initiator A-424

21.2.14 ISO/IEC15693-26

Table 158. ISO/IEC15693-26

21.2.15 ISO/IEC15693-53

Table 159. ISO/IEC15693-53 Table 160. ISO/IEC18003M3 - TARI=18.88us Table 161. ISO/IEC18003M3 - TARI=9.44 μs

21.2.18 PICC ISO/IEC14443-A 106

Table 162. PICC ISO/IEC14443-A 106

21.2.19 PICC ISO/IEC14443-A 212

Table 163. PICC ISO/IEC14443-A 212

21.2.20 PICC ISO/IEC14443-A 424

Table 164. PICC ISO/IEC14443-A 424

21.2.21 PICC ISO/IEC14443-A 848

Table 165. PICC ISO/IEC14443-A 848

21.2.22 NFC passive target 212

Table 166. NFC passive target 212

21.2.23 NFC passive target 424

Table 167. NFC passive target 424

Table 167. NFC passive target 424...continued

21.2.24 NFC active target 106

Table 168. NFC active target 106

21.2.25 NFC active target 212

Table 169. NFC active target 212

21.2.26 NFC active target 424

Table 170. NFC active target 424

21.2.27 NFC general target mode - all data rates

Table 171. NFC general target mode - all data rates

21.3 Default protocol settings for LOAD_RF_CONFIG, Receiver

21.3.1 ISO/IEC 14443 A-106

Table 172. ISO/IEC 14443 A-106

21.3.2 ISO/IEC 14443 A-212

Table 173. ISO/IEC 14443 A-212

21.3.3 ISO/IEC 14443 A-424

Table 174. ISO/IEC 14443 A-424

21.3.4 ISO/IEC 14443 A-848

Table 175. ISO/IEC 14443 A-848

21.3.5 ISO/IEC 14443 B-106

Table 176. ISO/IEC 14443 B-106

21.3.6 ISO/IEC 14443 B-212

Table 177. ISO/IEC 14443 B-212

21.3.7 ISO/IEC 14443 B-424

Table 178. ISO/IEC 14443 B-424

21.3.8 ISO/IEC 14443 B-848

Table 179. ISO/IEC 14443 B-848

21.3.9 FeliCa 212

Table 180. FeliCa 212

21.3.10 FeliCa 424

Table 181. FeliCa 424

21.3.11 NFC Active Initiator 106

Table 182. NFC Active Initiator 106

21.3.12 NFC Active Initiator 212

Table 183. NFC Active Initiator 212

21.3.13 NFC Active Initiator 424

Table 184. NFC Active Initiator 424

21.3.14 ISO/IEC 15693-26

Table 185. ISO/IEC 15693-26

21.3.15 ISO/IEC 15693-53

Table 186. ISO/IEC 15693-53 Table 187. ISO 18003M3- Tari 18.88

Table 188. ISO 18003M3- Tari 9.44 848_2 Table 189. ISO18003M3- Tari 9.44 -848_4

21.3.19 ISO 14443A-PICC 106

Table 190. ISO 14443A-PICC 106

21.3.20 ISO 14443A-PICC 212

Table 191. ISO 14443A-PICC 212

Table 191. ISO 14443A-PICC 212...continued

21.3.21 ISO 14443A-PICC 424

Table 192. ISO 14443A-PICC 424

21.3.22 ISO 14443A-PICC 848

Table 193. ISO 14443A-PICC 848

21.3.23 NFC-Passive target -212

Table 194. NFC-Passive target -212

21.3.24 NFC-Passive target -424

Table 195. NFC-Passive target -424

21.3.25 NFC-active target - 106

Table 196. NFC-active target - 106

21.3.26 NFC-active target - 212

Table 197. NFC-active target - 212

21.3.27 NFC-active target - 424

Table 198. NFC-active target - 424

21.3.28 NFC-General target mode - all data rates

Table 199. NFC-General target mode - all data rates

22 Abbreviations

Table 200. Abbreviations

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes

23 References

  1. ISO/IEC 14443 - parts 2: 2001 COR 1 2007 (01/11/2007), part 3: 2001 COR 1 2006 (01/09/2006) and part 4: 2nd edition 2008 (15/07/2008) Product data sheet Rev. 3.8 — 4 May 2021 COMPANY PUBLIC 436538 151 / 160
  • The format of this data sheet has been redesigned to comply with the new identity guidelines of NXP Semiconductors. PN5180A0xx/C3,C4 v. 3.6 20200602 Product data sheet PN5180A0xx/C3 v. 3.5 Modifications: • Description for firmware versions updated
  • Table 2 "Ordering information": PN5180A0ET/C4 and PN5180A0HN/C4 added
  • In Table 51 "EEPROM Addresses": each setting is 4 bits, 1 sign bit and 3 value bits. Wrong entry of 2 bit value had been corrected to 3-bit value. PN5180A0xx/C3 v. 3.5 20191211 Product data sheet PN5180A0xx/C3 v. 3.4 PN5180A0xx/C3 v. 3.4 20180507 Product data sheet PN5180A0xx/C3 v. 3.2 PN5180A0xx/C3 v. 3.3 20180419 Product data sheet PN5180A0xx/C3 v. 3.2 PN5180A0xx/C3 v. 3.2 20171220 Product data sheet PN5180A0xx/C3 v. 3.1 PN5180A0xx/C3 v. 3.1 20170731 Product data sheet PN5180A0xx/C3 v. 3.0 PN5180A0xx/C3 v. 3.0 20170718 Product data sheet -

Table 201. Revision history

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes

25 Legal information

25.1 Data sheet status

Document status[1][2] Product status[3] Definition Objective [short] data sheet Development This document contains data from the objective specification for product development. Preliminary [short] data sheet Qualification This document contains data from the preliminary specification. Product [short] data sheet Production This document contains the product specification. [1] Please consult the most recently issued document before initiating or completing a design. [2] The term 'short data sheet' is explained in section "Definitions". [3] The product status of device(s) described in this document may have changed since this document was published and may differ in case of multiple devices. The latest product status information is available on the Internet at URL http://www.nxp.com.

25.2 Definitions

Draft — A draft status on a document indicates that the content is still under internal review and subject to formal approval, which may result in modifications or additions. NXP Semiconductors does not give any representations or warranties as to the accuracy or completeness of information included in a draft version of a document and shall have no liability for the consequences of use of such information. Short data sheet — A short data sheet is an extract from a full data sheet with the same product type number(s) and title. A short data sheet is intended for quick reference only and should not be relied upon to contain detailed and full information. For detailed and full information see the relevant full data sheet, which is available on request via the local NXP Semiconductors sales office. In case of any inconsistency or conflict with the short data sheet, the full data sheet shall prevail. Product specification — The information and data provided in a Product data sheet shall define the specification of the product as agreed between NXP Semiconductors and its customer, unless NXP Semiconductors and customer have explicitly agreed otherwise in writing. In no event however, shall an agreement be valid in which the NXP Semiconductors product is deemed to offer functions and qualities beyond those described in the Product data sheet.

25.3 Disclaimers

Limited warranty and liability — Information in this document is believed to be accurate and reliable. However, NXP Semiconductors does not give any representations or warranties, expressed or implied, as to the accuracy or completeness of such information and shall have no liability for the consequences of use of such information. NXP Semiconductors takes no responsibility for the content in this document if provided by an information source outside of NXP Semiconductors. In no event shall NXP Semiconductors be liable for any indirect, incidental, punitive, special or consequential damages (including - without limitation - lost profits, lost savings, business interruption, costs related to the removal or replacement of any products or rework charges) whether or not such damages are based on tort (including negligence), warranty, breach of contract or any other legal theory. Notwithstanding any damages that customer might incur for any reason whatsoever, NXP Semiconductors’ aggregate and cumulative liability towards customer for the products described herein shall be limited in accordance with the Terms and conditions of commercial sale of NXP Semiconductors. Right to make changes — NXP Semiconductors reserves the right to make changes to information published in this document, including without limitation specifications and product descriptions, at any time and without notice. This document supersedes and replaces all information supplied prior to the publication hereof. Suitability for use — NXP Semiconductors products are not designed, authorized or warranted to be suitable for use in life support, life-critical or safety-critical systems or equipment, nor in applications where failure or malfunction of an NXP Semiconductors product can reasonably be expected to result in personal injury, death or severe property or environmental damage. NXP Semiconductors and its suppliers accept no liability for inclusion and/or use of NXP Semiconductors products in such equipment or applications and therefore such inclusion and/or use is at the customer’s own risk. Applications — Applications that are described herein for any of these products are for illustrative purposes only. NXP Semiconductors makes no representation or warranty that such applications will be suitable for the specified use without further testing or modification. Customers are responsible for the design and operation of their applications and products using NXP Semiconductors products, and NXP Semiconductors accepts no liability for any assistance with applications or customer product design. It is customer’s sole responsibility to determine whether the NXP Semiconductors product is suitable and fit for the customer’s applications and products planned, as well as for the planned application and use of customer’s third party customer(s). Customers should provide appropriate design and operating safeguards to minimize the risks associated with their applications and products. NXP Semiconductors does not accept any liability related to any default, damage, costs or problem which is based on any weakness or default in the customer’s applications or products, or the application or use by customer’s third party customer(s). Customer is responsible for doing all necessary testing for the customer’s applications and products using NXP Semiconductors products in order to avoid a default of the applications and the products or of the application or use by customer’s third party customer(s). NXP does not accept any liability in this respect. Limiting values — Stress above one or more limiting values (as defined in the Absolute Maximum Ratings System of IEC 60134) will cause permanent damage to the device. Limiting values are stress ratings only and (proper) operation of the device at these or any other conditions above those given in the Recommended operating conditions section (if present) or the Characteristics sections of this document is not warranted. Constant or repeated exposure to limiting values will permanently and irreversibly affect the quality and reliability of the device. Terms and conditions of commercial sale — NXP Semiconductors products are sold subject to the general terms and conditions of commercial sale, as published at http://www.nxp.com/profile/terms, unless otherwise agreed in a valid written individual agreement. In case an individual agreement is concluded only the terms and conditions of the respective agreement shall apply. NXP Semiconductors hereby expressly objects to applying the customer’s general terms and conditions with regard to the purchase of NXP Semiconductors products by customer. Product data sheet Rev. 3.8 — 4 May 2021 COMPANY PUBLIC 436538 153 / 160

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes No offer to sell or license — Nothing in this document may be interpreted or construed as an offer to sell products that is open for acceptance or the grant, conveyance or implication of any license under any copyrights, patents or other industrial or intellectual property rights. Quick reference data — The Quick reference data is an extract of the product data given in the Limiting values and Characteristics sections of this document, and as such is not complete, exhaustive or legally binding. Export control — This document as well as the item(s) described herein may be subject to export control regulations. Export might require a prior authorization from competent authorities. Non-automotive qualified products — Unless this data sheet expressly states that this specific NXP Semiconductors product is automotive qualified, the product is not suitable for automotive use. It is neither qualified nor tested in accordance with automotive testing or application requirements. NXP Semiconductors accepts no liability for inclusion and/or use of non- automotive qualified products in automotive equipment or applications. In the event that customer uses the product for design-in and use in automotive applications to automotive specifications and standards, customer (a) shall use the product without NXP Semiconductors’ warranty of the product for such automotive applications, use and specifications, and (b) whenever customer uses the product for automotive applications beyond NXP Semiconductors’ specifications such use shall be solely at customer’s own risk, and (c) customer fully indemnifies NXP Semiconductors for any liability, damages or failed product claims resulting from customer design and use of the product for automotive applications beyond NXP Semiconductors’ standard warranty and NXP Semiconductors’ product specifications. Translations — A non-English (translated) version of a document is for reference only. The English version shall prevail in case of any discrepancy between the translated and English versions. Security — Customer understands that all NXP products may be subject to unidentified or documented vulnerabilities. Customer is responsible for the design and operation of its applications and products throughout their lifecycles to reduce the effect of these vulnerabilities on customer’s applications and products. Customer’s responsibility also extends to other open and/or proprietary technologies supported by NXP products for use in customer’s applications. NXP accepts no liability for any vulnerability. Customer should regularly check security updates from NXP and follow up appropriately. Customer shall select products with security features that best meet rules, regulations, and standards of the intended application and make the ultimate design decisions regarding its products and is solely responsible for compliance with all legal, regulatory, and security related requirements concerning its products, regardless of any information or support that may be provided by NXP. NXP has a Product Security Incident Response Team (PSIRT) (reachable at PSIRT@nxp.com) that manages the investigation, reporting, and solution release to security vulnerabilities of NXP products.

25.4 Licenses

Purchase of NXP ICs with ISO/IEC 14443 type B functionality RATP/Innovatron Technology This NXP Semiconductors IC is ISO/IEC

14443 Type B software enabled and is

licensed under Innovatron’s Contactless Card patents license for ISO/IEC 14443 B. The license includes the right to use the IC in systems and/or end-user equipment. Purchase of NXP ICs with NFC technology Purchase of an NXP Semiconductors IC that complies with one of the Near Field Communication (NFC) standards ISO/IEC 18092 and ISO/ IEC 21481 does not convey an implied license under any patent right infringed by implementation of any of those standards. Purchase of NXP Semiconductors IC does not include a license to any NXP patent (or other IP right) covering combinations of those products with other products, whether hardware or software.

25.5 Trademarks

Notice: All referenced brands, product names, service names and trademarks are the property of their respective owners. MIFARE — is a trademark of NXP B.V. ICODE and I-CODE — are trademarks of NXP B.V. MIFARE Classic — is a trademark of NXP B.V. NXP — wordmark and logo are trademarks of NXP B.V. FeliCa — is a trademark of Sony Corporation. Product data sheet Rev. 3.8 — 4 May 2021 COMPANY PUBLIC 436538 154 / 160

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes Tables Tab. 5. 1-Byte Direct Commands and Direct Tab. 24. Autocoll bit mask indicating the RF Tab. 28. EPC_RESUME_INVENTORY Tab. 29. EPC_RETRIEVE_INVENTORY_RESULT_ Tab. 30. EPC_RETRIEVE_INVENTORY_RESULT Tab. 32. LOAD_RF_CONFIG: Selection of protocol Tab. 34. RETRIEVE_RF_CONFIG_SIZE Tab. 61. Communication overview for ISO/IEC 14443 type A and read/write mode for Tab. 62. Communication overview for ISO/IEC Tab. 64. Communication for ISO/IEC 15693 reader/ Tab. 65. Communication for ISO/IEC 15693 reader/ Tab. 66. Communication overview for active Tab. 67. Communication overview for passive Tab. 73. Low-Power Card Detection: EEPROM Tab. 75. SYSTEM_CONFIG register (address Tab. 76. IRQ_ENABLE register (address 0001h) bit Tab. 77. IRQ_STATUS register (address 0002h) bit Tab. 78. IRQ_CLEAR register (address 0003h) bit Tab. 79. TRANSCEIVE_CONTROL register Tab. 80. PADCONFIG register (address 0005h) bit Tab. 81. PAD_OUT register (address 0007h) bit Tab. 82. TIMER0_STATUS register (address 0008h) Tab. 83. TIMER1_STATUS register (address 0009h) Tab. 84. TIMER2_STATUS register (address 000Ah) Tab. 85. TIMER0_RELOAD register (address Product data sheet Rev. 3.8 — 4 May 2021 COMPANY PUBLIC 436538 155 / 160

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes Tab. 86. TIMER1_RELOAD register (address Tab. 87. TIMER2_RELOAD register (address Tab. 88. TIMER0_CONFIG register (address Tab. 89. TIMER1_CONFIG register (address Tab. 90. TIMER2_CONFIG register (address 0010h) Tab. 91. RX_WAIT_CONFIG (address 0011h) bit Tab. 92. CRC_RX_CONFIG (address 0012h) bit Tab. 93. RX_STATUS register (address 0013h) bit Tab. 94. TX_UNDERSHOOT_CONFIG register Tab. 95. TX_OVERSHOOT_CONFIG register Tab. 96. TX_DATA_MOD register (address 0016h) Tab. 97. TX_WAIT_CONFIG register (address Tab. 98. TX_CONFIG register (address 0018h) bit Tab. 99. CRC_TX_CONFIG (address 0019h) bit Tab. 100. SIGPRO_CONFIG register (address Tab. 101. SIGPRO_CM_CONFIG register (address Tab. 102. SIGPRO_RM_CONFIG register (address Tab. 103. RF_STATUS register (address 001Dh) bit Tab. 104. AGC_CONFIG register (address 001Eh) bit Tab. 105. AGC_VALUE register (address 001Fh) bit Tab. 106. RF_CONTROL_TX register (address Tab. 107. RF_CONTROL_TX_CLK register (address Tab. 108. RF_CONTROL_RX register (address Tab. 109. LD_CONTROL register (address 0023h) bit Tab. 110. SYSTEM_STATUS register (address Tab. 111. TEMP_CONTROL register (address Tab. 112. AGC_REF_CONFIG register (address Tab. 113. DPC_CONFIG register (address 0027h) bit Tab. 114. EMD_CONTROL register (address 0028h) Tab. 115. ANT_CONTROL register (address 0029h) Tab. 116. TX_CONTROL register (address 0036h) bit Tab. 117. SIGPRO_RM_CONFIG_EXTENSION Tab. 118. FELICA_EMD_CONTROL register (address 0043h) bit description (only Tab. 120. Secure Firmware Command Status Return Tab. 121. Secure Firmware update: GetVersion Tab. 122. Secure Firmware update: First Secure Tab. 125. Thermal characteristics HVQFN40 package . 123 Tab. 126. Thermal characteristics TFBGA64 package ..123 Tab. 142. Crystal requirements for ISO/IEC14443 Tab. 143. Reference input frequency requirements for Product data sheet Rev. 3.8 — 4 May 2021 COMPANY PUBLIC 436538 156 / 160

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes Product data sheet Rev. 3.8 — 4 May 2021 COMPANY PUBLIC 436538 157 / 160

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes Figures Fig. 3. Pin configuration for HVQFN40 Fig. 7. Read RX of SPI data using BUSY line with Fig. 20. Read/write mode for ISO/IEC 14443 type A Fig. 21. Data coding and framing according to ISO/ Fig. 22. ISO/IEC 14443 B read/write mode Fig. 29. Target Mode case: Timer stop for started Fig. 32. AGC value defining the RF output power Fig. 33. AGC value defining the waveshape Fig. 34. Lookup tables for AGC value-dependent Fig. 35. Transmitter supply voltage configuration, Fig. 41. Example SPI WRITE data send in single Fig. 42. Example SPI READ data retrieved in two Fig. 43. Secure Firmware Download: SPI Write Fig. 44. Secure Firmware Download: SPI Read Fig. 47. Secure Firmware Download command and Fig. 48. Application diagram with minimum Fig. 49. Conditions for external 3.3 V supply voltage . 130 Product data sheet Rev. 3.8 — 4 May 2021 COMPANY PUBLIC 436538 158 / 160

NXP Semiconductors PN5180A0xx/C3,C4 High-performance multiprotocol full NFC frontend, supporting all NFC Forum modes

21.2 Default protocol settings for LOAD_RF_

21.3 Default protocol settings for LOAD_RF_

Please be aware that important notices concerning this document and the product(s) described herein, have been included in section 'Legal information'. © NXP B.V. 2021. All rights reserved. For more information, please visit: http://www.nxp.com For sales office addresses, please send an email to: salesaddresses@nxp.com Date of release: 4 May 2021 Document identifier: PN5180A0xx_C3_C4 Document number: 436538