SRIX4K_07 STMICROELECTRONICS | Alldatasheet

Document overview

  • Manufacturer or author: Provided By ALLDATASHEET.COM(FREE DATASHEET DOWNLOAD SITE)
  • PDF pages: 50

Technical content

Datasheet sections

  • 1 Description
  • 2 Signal description
  • 2.0.1 AC1, AC0
  • 3 Data transfer
  • 3.1 Input data transfer from the Reader to the SRIX4K (request frame)
  • 3.1.1 Character transmission format for request frame
  • 3.1.2 Request start of frame
  • 3.1.3 Request end of frame
  • 3.2 Output data transfer from the SRIX4K to the Reader (answer frame)
  • 3.2.1 Character transmission format for answer frame
  • 3.2.2 Answer start of frame
  • 3.2.3 Answer end of frame
  • 3.3 Transmission frame
  • 3.4 CRC
  • 4 Memory mapping
  • 4.1 Resettable OTP area
  • 4.3 EEPROM area
  • 4.4 System area
  • 4.4.1 OTP_Lock_Reg
  • 4.4.2 Fixed Chip_ID (Option)
  • 5 SRIX4K operation
  • 6 SRIX4K states
  • 6.1 POWER-OFF state
  • 6.2 READY state
  • 6.3 INVENTORY state
  • 6.4 SELECTED state
  • 6.5 DESELECTED state

Features

■ ISO 14443-2 Type B air interface compliant ■ ISO 14443-3 Type B frame format compliant ■ 13.56 MHz carrier frequency ■ 847 kHz subcarrier frequency ■ 106 Kbit/second data transfer ■ France Telecom proprietary anti-clone function ■ 8 bit Chip_ID based anticollision system ■ 2 count-down binary counters with automated antitearing protection ■ 64-bit Unique Identifier ■ 4096-bit EEPROM with Write Protect feature ■ READ BLOCK and WRITE BLOCK (32 bits) ■ Internal tuning capacitor ■ 1million ERASE/WRITE cycles ■ 40-year data retention ■ Self-timed programming cycle ■ 5 ms typical programming time ■ Packages – ECOPACK® (RoHS compliant) Wafer Antenna (A3) Antenna (A4) Antenna (A5)

1 Description

contains a 4096-bit user EEPROM fabricated with STMicroelectronics CMOS technology. 106 Kbit/s in both reception and emission modes. Figure 1. Logic diagram system with a high level of security. Table 1. Signal names

4 Kbit

  • READ_BLOCK
  • WRITE_BLOCK
  • INITIATE
  • PCALL16
  • SLOT_MARKER
  • SELECT
  • COMPLETION
  • RESET_TO_INVENTORY
  • AUTHENTICATE
  • GET_UID The SRIX4K memory is organized in three areas, as described in Figure 3. The first area is a resettable OTP (one time programmable) area in which bits can only be switched from 1 to 0. Using a special command, it is possible to erase all bits of this area to 1. The second area provides two 32-bit binary counters which can only be decremented from FFFF FFFFh to 0000 0000h, and gives a capacity of 4,294,967,296 units per counter. The last area is the EEPROM memory. It is accessible by block of 32 bits and includes an auto-erase cycle during each WRITE_BLOCK command.

Figure 2. Die floor plan

2 Signal description

2.0.1 AC1, AC0

The pads for the Antenna Coil. AC1 and AC0 must be directly bonded to the antenna.

3 Data transfer

3.1 Input data transfer from the Reader to the SRIX4K (request

represented in Figure 3. The data transfer rate is 106 Kbits/s. Figure 3. 10% ASK modulation of the received wave

3.1.1 Character transmission format for request frame

(Elementary Time Unit), is equal to 9.44 µs (1/106 kHz). command, but it does not generate an error frame. Figure 4. SRIX4K request frame character format

1 ETU

3.1.2 Request start of frame

– followed by at least 2 ETUs (and at most 3) at logic-1. Figure 5. Request start of frame

3.1.3 Request end of frame

– followed by a single rising edge. Figure 6. Request end of frame Table 2. Bit description

3.2 Output data transfer from th e SRIX4K to the Reader (answer

s as shown in Figure 7, and as specified in the ISO 14443-2 Type B Standard. Figure 7. Wave transmitted using BPSK subcarrier modulation

3.2.1 Character transmission format for answer frame

3.2.2 Answer start of frame

Figure 8. Answer start of frame

3.2.3 Answer end of frame

– followed by 2 ETUs at logic-1. Figure 9. Answer end of frame

3.3 Transmission frame

13.56 MHz carrier frequency is modulated by the SRIX4K at 847 kHz for a period of

Figure 10. Example of a complete transmission frame

3.4 CRC

The two-byte CRC is present in every Request and in every Answer Frame, before the EOF . The CRC is calculated on all the bytes between SOF (not included) and the CRC field. Upon reception of a Request from a reader, the SRIX4K verifies that the CRC value is valid. If it is invalid, the SRIX4K discards the frame and does not answer the reader. CRC. In case of error, the actions to be taken are the reader designer’s responsibility. the least significant bit first. Figure 11. CRC tr ansmission rules

4 Memory mapping

The SRIX4K is organized as 128 blocks of 32 bits as shown in Figure 3. All blocks are accessible by the READ_BLOCK command. Depending on the write access, they can be updated by the WRITE_BLOCK command. A WRITE_BLOCK updates all the 32 bits of the block. Table 3. SRIX4K memory mapping

Description

5 32 bits binary counter Count down Counter6 32 bits binary counter 7U s e r A r e a Lockable EEPROM 8U s e r A r e a 9U s e r A r e a

10 User Area

11 User Area

12 User Area

13 User Area

14 User Area

15 User Area

16 User Area

EEPROM... User Area

127 User Area

255 OTP_Lock_Reg ST Reserved Fixed Chip_ID

(Option) System OTP bits UID0 64 bits UID Area ROM UID1

4.1 Resettable OTP area

In this area contains five individual 32-bit Boolean Words (see Figure 12 for a map of the area). A WRITE_BLOCK command will not erase the previous contents of the block as the Write cycle is not preceded by an Auto Erase cycle. This feature can be used to reset selected bits from 1 to 0. All bits previously at 0 remain unchanged. When the 32 bits of a block are all at 0, the block is empty, and cannot be updated any more. See Figure 13 and Figure 14 for examples of the result of the WRITE_BLOCK command in the resettable OTP area. Figure 12. Resettable OTP area (addresses 0 to 4) Figure 13. WRITE_BLOCK update in Standard mode (binary format) Section 4.2: 32-bit binary counters for details). 1 ... 1 1 01011 11 1 0 11 1 ... 1 0 01011 00 1 1 11 1 ... 1 0 01011 00 1 0 11 Previous data stored in block Data to be written New data stored in block b31 b0

Figure 16. Count down example (binary format)

4.3 EEPROM area

EEPROM area always includes an Auto-Erase cycle prior to the Write cycle. details). Once protected, these blocks (7 to 15) cannot be unprotected.

Figure 17. EEPROM (a ddresses 7 to 127)

4.4 System area

OTP_Lock_Reg, Fixed Chip_ID and ST Reserved. See Figure 18 for a map of this area. a block are at 0, the block is empty and cannot be updated any more. Figure 18. System area ... User Area User Area User Area User Area User Area 127 User Area User Area EEPROM Block Address 255 MSb b31 b24 b23 32-bit Block b16 b15 b8 b7 b0 LSb OTPOTP_Lock_Reg ST Reserved Fixed Chip_ID (Option) ai07663

4.4.1 OTP_Lock_Reg

The 8 bits, b31 to b24, of the System Area (block address 255) are used as OTP_Lock_Reg bits in the SRIX4K. They control the Write access to the 9 EEPROM blocks with addresses 7 to 15 as follows: – When b 24 is at 0, blocks 7 and 8 are Write-protected – When b 25 is at 0, block 9 is Write-protected – When b 26 is at 0, block 10 is Write-protected – When b 27 is at 0, block 11 is Write-protected – When b 28 is at 0, block 12 is Write-protected – When b 29 is at 0, block 13 is Write-protected – When b 30 is at 0, block 14 is Write-protected – When b 31 is at 0, block 15 is Write-protected. The OTP_Lock_Reg bits cannot be erased. Once Write-protected, EEPROM blocks behave like ROM blocks and cannot be unprotected.

4.4.2 Fixed Chip_ID (Option)

The SRIX4K is provided with an anticollision feature based on a random 8-bit Chip_ID. Prior to selecting an SRIX4K, an anticollision sequence has to be run to search for the Chip_ID of the SRIX4K. This is a very flexible feature, however the searching loop requires time to run. For some applications, much time could be saved by knowing the value of the SRIX4K Chip_ID beforehand, so that the SRIX4K can be identified and selected directly without having to run an anticollision sequence. This is why the SRIX4K was designed with an optional mask setting used to program a fixed 8-bit Chip_ID to bits b 7 to b0 of the system area. When the fixed Chip_ID option is used, the random Chip_ID function is disabled.

5 SRIX4K operation

All commands, data and CRC are transmitted to the SRIX4K as 10-bit characters using ASK modulation. The start bit of the 10 bits, b0, is sent first. The command frame received by the SRIX4K at the antenna is demodulated by the 10% ASK demodulator, and decoded by the internal logic. Prior to any operation, the SRIX4K must have been selected by a SELECT command. Each frame transmitted to the SRIX4K must start with a Start Of Frame, followed by one or more data characters, two CRC Bytes and the final End Of Frame. When an invalid frame is decoded by the SRIX4K (wrong command or CRC error), the memory does not return any error code. When a valid frame is received, the SRIX4K may have to return data to the reader. In this case, data is returned using BPSK encoding, in the form of 10-bit characters framed by an SOF and an EOF . The transfer is ended by the SRIX4K sending the 2 CRC Bytes and the EOF .

6 SRIX4K states

The SRIX4K can be switched into different states. Depending on the current state of the SRIX4K, its logic will only answer to specific commands. These states are mainly used during the anticollision sequence, to identify and to access the SRIX4K in a very short time. The SRIX4K provides 6 different states, as described in the following paragraphs and in Figure 19.

6.1 POWER-OFF state

The SRIX4K is in POWER-OFF state when the electromagnetic field around the tag is not strong enough. In this state, the SRIX4K does not respond to any command.

6.2 READY state

When the electromagnetic field is strong enough, the SRIX4K enters the READY state. After Power-up, the Chip_ID is initialized with a random value. The whole logic is reset and remains in this state until an INITIATE() command is issued. Any other command will be ignored by the SRIX4K.

6.3 INVENTORY state

The SRIX4K switches from the READY to the INVENTORY state after an INITIATE() command has been issued. In INVENTORY state, the SRIX4K will respond to any anticollision commands: INITIATE(), PCALL16() and SLOT_MARKER(), and then remain in the INVENTORY state. It will switch to the SELECTED state after a SELECT(Chip_ID) command is issued, if the Chip_ID in the command matches its own. If not, it will remain in INVENTORY state.

6.4 SELECTED state

In SELECTED state, the SRIX4K is active and responds to all READ_BLOCK(), WRITE_BLOCK(), AUTHENTICATE() and GET_UID() commands. When an SRIX4K has entered the SELECTED state, it no longer responds to anticollision commands. So that the reader can access another tag, the SRIX4K can be switched to the DESELECTED state by sending a SELECT(Chip_ID2) with a Chip_ID that does not match its own, or it can be placed in DEACTIVATED state by issuing a COMPLETION() command. Only one SRIX4K can be in SELECTED state at a time.

6.5 DESELECTED state

Once the SRIX4K is in DESELECTED state, only a SELECT(Chip_ID) command with a Chip_ID matching its own can switch it back to SELECTED state. All other commands are ignored.

6.6 DEACTIVATED state

When in this state, the SRIX4K can only be turned off. All commands are ignored. Figure 19. State transition diagram

7 Anticollision

  • INITIATE()
  • PCALL16()
  • SLOT_MARKER(). The reader is the master of the communication with one or more SRIX4K device(s). It initiates the tag communication activity by issuing an INITIATE(), PCALL16() or SLOT_MARKER() command to prompt the SRIX4K to answer. During the anticollision sequence, it might happen that two or more SRIX4K devices respond simultaneously, so causing a collision. The command set allows the reader to handle the sequence, to separate SRIX4K transmissions into different time slots. Once the anticollision sequence has completed, SRIX4K communication is fully under the control of the reader, allowing only one SRIX4K to transmit at a time. The Anticollision scheme is based on the definition of time slots during which the SRIX4K devices are invited to answer with minimum identification data: the Chip_ID. The number of slots is fixed at 16 for the PCALL16() command. For the INITIATE() command, there is no slot and the SRIX4K answers after the command is issued. SRIX4K devices are allowed to answer only once during the anticollision sequence. Consequently, even if there are several SRIX4K devices present in the reader field, there will probably be a slot in which only one SRIX4K answers, allowing the reader to capture its Chip_ID. Using the Chip_ID, the reader can then establish a communication channel with the identified SRIX4K. The purpose of the anticollision sequence is to allow the reader to select one SRIX4K at a time. The SRIX4K is given an 8-bit Chip_ID value used by the reader to select only one among up to 256 tags present within its field range. The Chip_ID is initialized with a random value during the READY state, or after an INITIATE() command in the INVENTORY state. The four least significant bits ( b0 to b3) of the Chip_ID are also known as the CHIP_SLOT_NUMBER. This 4-bit value is used by the PCALL16() and SLOT_MARKER() commands during the anticollision sequence in the INVENTORY state.

Figure 20. SRIX4K Ch ip_ID description

Figure 21. Description of a possible anticollision sequence

  1. The value X in the Answer Chip_ID means a random hexadecimal character from 0 to F.

7.1 Description of an anticollision sequence

SLOT_MARKER(SN) anticollision commands. received the INITIATE() command and entered the INVENTORY state. generate a new sequence in order to identify all unidentified SRIX4K devices in the field. The anticollision sequence can stop when all SRIX4K devices have been identified. Table 4. Standard anticollision sequence – If no answer is detected, go to step1. SRIX4K, deselect the tag and go to step1. – If a collision (many answers) is detected, go to step2. – If no answer or collision is detected, go to step3. – If 1 answer is detected, store the Chip_ID, Send SELECT() and go to step3. – If no answer or collision is detected, go to step4. – If 1 answer is detected, store the Chip_ID, Send SELECT() and go to step4. – If no answer or collision is detected, go to step5. – If 1 answer is detected, store the Chip_ID, Send SELECT() and go to step5. Send SLOT_MARKER(3 up to 14) ... – If no answer or collision is detected, go to stepN+1. – If 1 answer is detected, store the Chip_ID, Send SELECT() and go to stepN+1. – If no answer or collision is detected, go to step18. – If 1 answer is detected, store the Chip_ID, Send SELECT() and go to step18. DESELECTED or DEACTIVATED state, depending on the application needs. – If collisions were detected between Step2 and Step17, go to Step2. – If no collision was detected between Step2 and Step17, go to Step1.

Figure 22. Example of an anticollision sequence Each tag get a new random Chip_ID.

SRIX4K Anti-clone function

8 Anti-clone function

The SRIX4K provides an anti-clone function that allows the application to authentication the device. This function uses reserved data that is stored in the SRIX4K memory at its time of manufacture. The Authentication system is based on a proprietary challenge/response mechanism which allows the application software to authenticate any member of the secure memory tag SRXxxx family from STMicroelectronics (of which the SRIX4K is the prime example). A reader system, based on the ST CRX14 chip coupler, can check each SRIX4K tag for authenticity, and protect the application system against silicon copies or emulators. A complete description of the Authentication system is available under Non Disclosure Agreement (NDA) with STMicroelectronics. For more details about this SRIX4K function, please contact your nearest STMicroelectronics sales office.

9 SRIX4K commands

Table 5. Command code

9.1 INITIATE() command

Figure 23. INITIATE request format Figure 24. INITIATE response format Figure 25. INITIATE Frame Exchange Between Reader and SRIX4K

9.2 PCALL16() command

The SRIX4K must be in INVENTORY state to interpret the PCALL16() command. CHIP_SLOT_NUMBER value (in the 4 least significant bits of the Chip_ID). until a new PCALL16() or INITIATE() command is issued, or until the SRIX4K is powered off. INVENTORY state present in the reader field range. Figure 26. PCALL16 request format Figure 27. PCALL16 response format Figure 28. PCALL16 frame exchange between Reader and SRIX4K

9.3 SLOT_MARKER(SN) command

The SRIX4K must be in INVENTORY state to interpret the SLOT_MARKER(SN) command. between 1 and 15. The value 0 is reserved by the PCALL16() command. CHIP_SLOT_NUMBER value with the SLOT_NUMBER value given in the command code. INVENTORY state present in the reader field range. Figure 29. SLOT_MARKER request format Figure 30. SLOT_MARKER response format Figure 31. SLOT_MARKER frame exch ange between Reader and SRIX4K

9.4 SELECT(Chip_ID) command

Chip_ID that does not match its own is automatically switched to DESELECTED state. Figure 32. SELECT request format Figure 33. SELECT Response Format Figure 34. SELECT frame exchange between Reader and SRIX4K

9.5 COMPLETION() command

the field. The COMPLETION() command does not generate a response. All SRIX4K devices not in SELECTED state ignore the COMPLETION() command. Figure 35. COMPLETION request format Figure 36. COMPLETION response format Figure 37. COMPLETION frame exchange between Reader and SRIX4K

9.6 RESET_TO_INVENTORY() command

commands and so, to set new random Chip_IDs. The RESET_TO_INVENTORY() command does not generate a response. Figure 38. RESET_TO_INVENTORY request format Figure 39. RESET_TO_INVENTORY response format Figure 40. RESET_TO_INVENTORY frame exchange between Reader and SRIX4K

9.7 READ_BLOCK(Addr) command

Significant Byte first and each byte is transmitted with the least significant bit first. The address byte gives access to the 128 blocks of the SRIX4K (addresses 0 to 127). commands sent to the SRIX4K before a SELECT() command is issued are ignored. Figure 41. READ_BLOCK request format Figure 42. READ_BLOCK response format Figure 43. READ_BLOCK frame exchange between Reader and SRIX4K

9.8 WRITE_BLOCK (Add r, Data) command

transmitted with the least significant bit first. The address Byte gives access to the 128 blocks of the SRIX4K (addresses 0 to 127). – Figure 12: Resettable OTP area (addresses 0 to 4). – Figure 15: Binary counter (addresses 5 to 6). – Figure 17: EEPROM (addresses 7 to 127). W, that the data was correctly programmed. commands sent to the SRIX4K before a SELECT() command is issued, are ignored. Figure 44. WRITE_BLOCK request format – DATA 4: Most significant data Byte. Figure 45. WRITE_BLOCK response format

Figure 46. WRITE_BLOCK frame exchange between Reader and SRIX4K

9.9 GET_UID() command

the SRIX4K before a SELECT() command is issued, are ignored. Figure 47. GET_UID request format Figure 48. GET_UID response format – UID 7: Most significant UID Byte.

Members of the SRIX4K family are uniquely identified by a 64-bit Unique Identifier (UID).

  • an 8-bit prefix, with the most significant bits set to D0h
  • an 8-bit IC Manufacturer code (ISO/IEC 7816-6/AM1) set to 02h (for STMicroelectronics)
  • a 6-bit IC code set to 00 0011b = 3d for SRIX4K
  • a 42-bit Unique Serial Number

Figure 49. 64-bit unique identifier of the SRIX4K Figure 50. GET_UID frame exchange between Reader and SRIX4K

9.10 Power-On state

– It is in the low-power state. – It shows highest impedance with respect to the reader antenna field. – It will not respond to any command except INITIATE().

10 Maximum rating

Program and other relevant quality documents. Table 6. Absolute maximum ratings

  1. ESD test: ISO 10373-6 for proximity cards

11 DC and ac parameters

  1. All timing measurements were performed on a reference antenna with the following characteristics:

Table 7. Operating conditions Table 8. DC characteristics Table 9. AC characteristics

Figure 51. SRIX4K synchronous timing, transmit and receive

compliance with JEDEC Standard JESD97. The maximum ratings related to soldering conditions are also marked on the inner box label. ECOPACK is an ST trademark. ECOPACK specifications are available at: www.st.com. Figure 52. A3 antenna specification Table 10. A3 antenna specification

Figure 53. A4 antenna specification Table 11. A4 antenna specification

Figure 54. A5 antenna specification Table 12. A5 antenna specification

13 Part numbering

Note: Devices are shipped from the factory with the memory content bits erased to 1. of this device, please contact your nearest ST Sales Office. Table 13. Ordering information scheme

ISO 14443 Type B CRC calculation SRIX4K Appendix A ISO 14443 Type B CRC calculation #include <stdio.h> #include <stdlib.h> #include <string.h> #include <ctype.h> #define BYTE unsigned char #define USHORT unsigned short unsigned short UpdateCrc(BYTE ch, USHORT *lpwCrc) ch = (ch^(BYTE)((*lpwCrc) & 0x00FF)); ch = (ch^(ch<<4)); *lpwCrc = (*lpwCrc >> 8)^((USHORT)ch << 8)^((USHORT)ch<<3)^((USHORT)ch>>4); return(*lpwCrc); void ComputeCrc(char *Data, int Length, BYTE *TransmitFirst, BYTE *TransmitSecond) BYTE chBlock; USHORTt wCrc; wCrc = 0xFFFF; // ISO 3309 do chBlock = *Data++; UpdateCrc(chBlock, &wCrc); } while (--Length); wCrc = ~wCrc; // ISO 3309 *TransmitFirst = (BYTE) (wCrc & 0xFF); *TransmitSecond = (BYTE) ((wCrc >> 8) & 0xFF); return; int main(void) BYTE BuffCRC_B[10] = {0x0A, 0x12, 0x34, 0x56}, First, Second, i; printf("Crc-16 G(x) = x^16 + x^12 + x^5 + 1”); printf("CRC_B of [ "); for(i=0; i<4; i++) printf("%02X ",BuffCRC_B[i]); ComputeCrc(BuffCRC_B, 4, &First, &Second); printf("] Transmitted: %02X then %02X.”, First, Second); return(0);

Revision history

Table 14. Document revision history 29-Nov-2004 4.0 Package mechanical section revised. RET and CTUN parameters added to Table 8: DC characteristics. Document reformatted. Small text changes. All antennas are ECOPACK® compliant. removed, typical value added in Table 8: DC characteristics.