NFC Forum Type 4 Tag IC with 2-Kbit EEPROM and RF Session digital output

Document overview

  • Manufacturer or author: STMICROELECTRONICS
  • PDF pages: 51

Technical content

Datasheet sections

  • 1 Functional description
  • 1.1 Functional modes
  • 1.1.1 Tag mode
  • 2 Signal descriptions
  • 2.1 Antenna coil (AC0, AC1)
  • 2.2 Ground (VSS)
  • 2.3 RF Session output
  • 2.3.1 Session Open configuration (RF Session field = 0x11)
  • 3 SRTAG2K-D memory management
  • 3.1 Memory structure
  • 3.1.1 File identifier
  • 3.1.2 CC file layout
  • 3.1.3 NDEF file layout
  • 3.1.4 System file layout
  • 3.2 Read and write access rights to the memory
  • 3.2.1 State of the Read and Write access rights
  • 3.2.2 Changing the read access right to NDEF files
  • 3.2.3 Changing the write access right to NDEF files
  • 3.3 Access right life time
  • 3.4 NDEF file passwords
  • 4 Communication mechanism
  • 4.1 Master and slave
  • 5 RF command sets
  • 5.1 Structure of the command sets
  • 5.2 I-Block format
  • 5.2.1 C-APDU: payload format of a command
  • 5.2.2 R-APDU: payload format of a response
  • 5.3 R-Block format
  • 5.4 S-Block format

Datasheet sections

  • 7.7 Changing an NDEF password procedure
  • 7.8 Changing a File type Procedure
  • 8 UID: Unique identifier
  • 9 Maximum rating
  • 10 RF Session pad parameters
  • 11 RF electrical parameters
  • 12 Package mechanical data
  • 12.1 Mechanical data for the UFDFPN8 package
  • 13 Part numbering
  • 14 Revision history

Features

  • NFC Forum Type 4 Tag
  • ISO/IEC 14443 Type A
  • 106 Kbps data rate
  • Internal tuning capacitance: 25 pF Memory
  • 256-byte (2-kbit) EEPROM
  • Support of NDEF data structure
  • Data retention: 200 years
  • Endurance: 1 million erase-write cycles
  • Read up to 246 bytes in a single command
  • Write up to 246 bytes in a single command
  • 7 bytes unique identifier (UID)
  • 128 bits passwords protection Package
  • UFDFPN8 ECOPACK®2 Digital pad
  • RF Session output

Description

The SRTAG2K-D device is a dynamic NFC/RFID tag IC. It embeds an EEPROM memory. It can be operated from a 13.56 MHz RFID reader or an NFC phone. The RF protocol is compatible with ISO/IEC 14443 Type A and NFC Forum Type 4 Tag. UFDFPN8 (MC) Wafer (SB12I)

6.1 Anticollision and Device Activation command set for the RF interface . . 39

Table 58. UFDFPN8 - 8-lead ultra thin fine pitch dual flat package, no lead,

1 Functional description

Figure 1 displays the block diagram of the SRTAG2K-D device. Figure 1. SRTAG2K-D block diagram

Figure 2. 8-pin package connections

  1. See Package mechanical data section for packa ge dimensions, and how to identify pin 1.

1.1 Functional modes

The SRTAG2K-D has just one functional mode available (see Table 2).

1.1.1 Tag mode

reader or an NFC phone). The User memory can only be accessed by the RF commands. Table 1. Signal names

  1. An external pull-up > 4.7 k Ω is required.

Table 2. Functional mode

2 Signal descriptions

2.1 Antenna coil (AC0, AC1)

to connect any other DC or AC path to AC0 or AC1.

2.2 Ground (V SS)

2.3 RF Session output

2.3.1 Session Open configurat ion (RF Session field = 0x11)

"Session Open" pad goes to the Low state when an RF session is ongoing (see Figure 3). RF Session pad is driven low after a delay (1) when the session is open. RF Session pad is released after a delay (2) when the session is released. Figure 3. Session Open (RF Session field = 0x11)

  1. CmdEOFtoGPlow (RF command End of frame to RF Session pad low)
  2. CmdEOFtoGPHZ (RF command End of frame to RF Session pad HZ)

3 SRTAG2K-D memory management

3.1 Memory structure

  • One Capability Container file
  • One NDEF file
  • One System file: this is an ST-proprietary file The System file contains some information on the configuration of the SRTAG2K-D device. The CC file gives some information about the SRTAG2K-D itself and the NDEF file. The NDEF file contains the User data.

3.1.1 File identifier

The file identifier is the value used in the Select command to select a file.

3.1.2 CC file layout

read-only file for the RF host and cannot be modified by issuing a write command. a specific process (refer to Section 7: Functional procedures). Table 3. File identifier

3.1.3 NDEF file layout

Section 5.6.7: ReadBinary command. Table 4. CC file layout for 1 NDEF file

3.1.4 System file layout

3.2 Read and write access rights to the memory

passwords, one for the read access and the other one for the write access. Table 5. NDEF file layout Table 6. Field list

  1. x values are defined by ST to insure UID unicity.

read or write access right is defined for the NDEF file.

3.2.1 State of the Read and Write access rights

file. For more details, refer to Section 3.1.2: CC file layout. The state 0xFF and 0xFE cannot be changed by using the Read or Write passwords.

3.2.2 Changing the read access right to NDEF files

The state diagram on Figure 4 shows how to change the access right to read an NDEF file. Table 7. Read access right

  1. The read password shall be sent before reading in the NDEF file.

Table 8. Write access right

  1. The write password shall be sent before writing in the NDEF file.

Figure 4. Changing the read access right to an NDEF file

  1. See the procedure to lock the read access ( Section 7.4: Locking an NDEF file).
  2. See the procedure to unlock the read access ( Section 7.5: Unlocking an NDEF file).
  3. See the procedure to permanently lock the read access ( Section 7.6: Reaching the read-only state for an
  4. Proprietary state, not defined by NFC Forum Type 4 Tag.

3.2.3 Changing the write access right to NDEF files

The state diagram on Figure 5 shows how to change the write access right to an NDEF file. Figure 5. Changing the write access right to an NDEF file

  1. See the procedure to lock the write access.
  2. See the procedure to unlock the write access.
  3. See the procedure to permanently lock the write access ( Section 7.6: Reaching the read-only state for an
  4. Proprietary state, not defined by NFC Forum Type 4 Tag.

SRTAG2K-D memory management SRTAG2K-D

3.3 Access right life time

The access right life time is validated while the NDEF file is selected or until the end of the RF session. Once the read or write access right is granted, the host can send one or more ReadBinary or UpdateBinary commands. At the end of a session or when the host selects another file, the read and write access rights are initialized.

3.4 NDEF file passwords

The NDEF file passwords protect the read or write access from an RF interface from/to an NDEF file. Two NDEF file passwords are available for each NDEF file:

  • Read password
  • Write password The length of a password is 128 bits (16 bytes).

SRTAG2K-D Communication mechanism

4 Communication mechanism

This chapter describes the principle of communication between an RF host and the SRTAG2K-D device.

4.1 Master and slave

The SRTAG2K-D acts as a slave device on the RF channel and therefore waits for a command from the RF host before sending its response. The RF host shall generate the RF field and the RF commands.

5 RF command sets

This section describes the SRTAG2K-D command sets that can be issued by the RF host.

  • the NFC Forum Type 4 Tag command set
  • the ISO/IEC 7816-4 command set
  • the proprietary command set The NFC Forum Type 4 Tag command set and the ISO/IEC 7816-4 command set use the I- Block format. For more details about the I-Block format, refer to Section 5.2: I-Block format. Two other command formats exist:
  • the commands using the R-Block format
  • the commands using the S-Block format For more details about these formats, refer to the corresponding sections: Section 5.3: R- Block format and Section 5.4: S-Block format. This section gives a brief description of the RF host commands. The format of these command sets is the I-Block format. Table 9 lists the RF command sets.

Table 9. RF command sets

5.1 Structure of the command sets

  • I-Block: to exchange the command and the response
  • R-Block: to exchange positive or negative acknowledgement
  • S-Block: to use either the Deselect command or the Frame Waiting eXtension (WTX) command or response This section describes the structure of the I-Block, R-block and S-Block. This format is used for the application command set.

5.2 I-Block format

composed of three fields. Table 10 details the I-Block format. Table 10. I-Block format

2 CRC bytes

5.2.1 C-APDU: payload format of a command

The C-APDU format is used by the RF host to send a command to the SRTAG2K-D. Table 12 describes its format. Table 11. PCB field of the I-Block format Table 12. C-APDU format

5.2.2 R-APDU: payload format of a response

format. This format is described in Table 13.

5.3 R-Block format

  • R(ACK): the acknowledgement block sent by the RF host or by the SRTAG2K-D
  • R(NAK): the non-acknowledgement block sent by the RF host or by the SRTAG2K-D

Table 13. R-APDU format Table 14. R-Block format

5.4 S-Block format

  • S(DES): the deselect command
  • S(WTX): the Waiting Frame eXtension command or response. A Waiting Time eXtension request occurs, in RF or I2C, when the operating time needed by M24SRxx is greater than 9.6 ms. The WTX field indicates the increase time factor to be used in this command execution (FDTtemp = WTX * 9.6 ms).

Table 15. R-Block detailed format Table 16. S-Block format

  1. This field is present when b5-b4 bits are set to 0b11 (S-Block is a WTX). see Table 17: S-Block detailed format.

5.5 CRC of the RF frame

The two CRC bytes check the data transmission between the RF host and the SRTAG2K-D. bits, SOF and EOF, and the CRC itself. the register content shall not be inverted after calculation.

5.6 NFC Forum Type 4 Tag protocol

5.6.1 Commands set

SRTAG2K-D command set is built to easily support the NFC Forum Type 4 Tag protocol. Table 17. S-Block detailed format Table 18. Command set overview

5.6.2 Status and error codes

This section lists the status and the error code of the SRTAG2K-D. Table 18. Command set overview (continued) Table 19. Status code of the SRTAG2K-D Table 20. Error code of the SRTAG2K-D

5.6.3 NDEF Tag Applic ation Select command

the RF host shall send this command to activate the NDEF Tag Application. Table 21) in addition to the sequence defined in the NFC Forum digital protocol. (called NDEF Tag Application Select). Table 22 defines the R-APDU of the NDEF Tag Application Select command.

5.6.4 Capability Cont ainer Select command

The CC file is selected when this command returns "command completed" in the R-APDU. Table 21. C-APDU of the NDEF Tag Application Select command Table 22. R-APDU of the NDEF Tag Application Select command

Table 24 defines the R-APDU of the CC Select command.

5.6.5 NDEF Select command

The RF host uses the NDEF Select command to select the NDEF file. Table 23. C-APDU of the Capability Container Select command Table 24. R-APDU of the Capability Container Select command Table 25. C-APDU of the NDEF Select command

Table 26 defines the R-APDU of the NDEF Select command.

5.6.6 System File Select command

The RF host uses this command to select the system file. Table 28 defines the R-APDU of the System File Select command.

5.6.7 ReadBinary command

and sends back its value in the R-APDU response. Table 26. R-APDU of the NDEF Select command Table 27. C-APDU of the System File Select command Table 28. R-APDU of the System File Select command

than the selected file length. Table 29 defines the ReadBinary command. Table 30 defines the R-APDU of the ReadBinary command.

5.6.8 UpdateBinary command

request a timing extension (see Section 5.4). Table 31 defines the UpdateBinary command. a. For more details about CC file, refer to Section 3.1.2: CC file layout. For more details about NDEF file, refer to Section 3.1.3: NDEF file layout. For more details about System file, refer to Section 3.1.4: System file layout. Table 29. C-APDU of the ReadBinary command Table 30. R-APDU of the ReadBinary command

Table 32 defines the R-APDU of the UpdateBinary command. Note: For further return code s and definitions, refer to Status and error codes. Table 31. C-APDU of the UpdateBinary command Table 32. R-APDU of the UpdateBinary command

5.7 ISO/IEC 7816-4 commands

the NDEF file. This command set is used to manage the right access of the NDEF file.

5.7.1 Verify command

  1. Check if a password is required to access to the NDEF file (the LC field = 0x00).
  2. Check that the password embedded in the Verify command allows the access to the

memory (the Lc field = 0x10 and the password is present). whether the operation has been successful in the response. After a successful command, an access is granted for the whole NDEF file. Table 33 defines the Verify command. Table 33. Verify command format

Table 34 defines the R-APDU of the Verify command.

5.7.2 Change Reference Data command

security attributes for this command. shall be issued. Thus, this command changes the reference data of the NDEF file. Table 35 defines the Change Reference Data command. Table 35. Change reference data command format Table 36 defines the R-APDU of the Change Reference Data command. Table 34. R-APDU of the Verify command

  1. At each session, the RF host can check a password 3 times.

encodes the number of further allowed retries.

5.7.3 Enable Verification Requirement command

security attributes for this command. this case, the response timing will be around 5 ms. shall be issued. Thus, this command changes the access right of the NDEF file. Table 37 defines the Enable Verification requirement command. The last five bits identify the password sent in the Verify command. Table 38 defines the R-APDU of the Enable Verification Requirement command. Table 36. R-APDU of the Change Reference Data command Table 37. Enable Verification Requirement command format

5.7.4 Disable Verification Requirement command

security attributes for this command. shall be issued. Thus, this command changes the access right of the NDEF file. this case, the response timing will be around 6 ms. Table 39 defines the Disable Verification Requirement command. Table 40 defines the R-APDU of the Disable Verification Requirement command. Table 38. R-APDU of the Enable Verification Requirement command Table 39. Disable Verification Requirement command format

5.8 ST Proprietary command set

The RF host can be issued with the command set described in this chapter.

5.8.1 ExtendedReadBinary command

memory field and sends back its value in the R-APDU response. read goes beyond the end of the file. Table 42 defines the R-APDU of the read binary command. Table 40. R-APDU of the Disable Verification Requirement command Table 41. C-APDU of the ExtendedReadBinary command

5.8.2 EnablePermanentState command

The command configures the NDEF file to the ReadOnly or to the WriteOnly State. this case, the response timing will be around 6 ms. Table 43 defines the EnablePermanentState requirement command. Table 44 defines the R-APDU of the EnablePermanentState command. Table 42. R-APDU of the ExtendedReadBinary command Table 43. EnablePermanentState command format Table 44. R-APDU table of the EnablePermanentState command

5.9 Specific RF command set

This section describes the command set that can be issued only by the RF host.

5.9.1 Anticollision command set

commands is described in the NFC Forum Digital Protocol specification.

5.9.2 RATS comma nd and ATS response

Activation (as defined in NFC Forum Digital Protocol specification). Table 44. R-APDU table of the EnablePermanentState command (continued) Table 45. Commands issues by the RF host Table 46. RATS command

receive. Table 47 gives the conversion from FDSI to FSD. The DID field defines the value of the addressed SRTAG2K-D. the command and will not reply. reader shall wait after receiving the response of the SRTAG2K-D.

5.9.3 PPS comm and & response

14443-4, in the Protocol Activation of PICC Type A. D) and descending (SRTAG2K-D to RF host) data rates. Table 47. Conversion from FDSI to FSD Table 48. ATS response

The ascending and descending data rates shall be coded as described in Table 50. When the SRTAG2K-D is able to change both data rates, it returns the following response. Table 51 gives the details sof the PPS response. Table 49. PPS command Table 50. Ascending and descending data rate coding Table 51. PPS response

SRTAG2K-D RF device operation

6 RF device operation

6.1 Anticollision and Device Acti vation command set for the RF

The SRTAG2K-D device supports the command set defined in the NFC-A Technology and the Type 4A Tag Platform chapters of the NFC Digital Protocol V1.0 specification.

6.2 Open an RFsession

Once the RF host has terminated the anticollision procedure and retrieve the ATS response, it shall send the SelectApplication command. The SRTAG2K-D will open an RF session. At this point, the RF host can send the applicative command set.

6.3 Close an RFsession

The RF host can close the RF session by issuing one of these methods:

  • send an S(DES) command
  • turn off the RF field

6.4 Applicative command set

The applicative command set is composed of the following command sets:

  • the NFC Forum Type 4 Tag command set
  • the ISO/IEC 7816-4 command set
  • the proprietary command set

Functional procedures SRTAG2K-D

7 Functional procedures

This section describes some procedure to access the memory or manage its protection.

7.1 Selection of an NDEF message

The RF host shall use this procedure to detect the NDEF message inside an SRTAG2K-D. The NDEF detection procedure is as follows: 1. Open an RF session 2. Send the SelectND EFTagApplication command 3. Select the CC file 4. Read the CC file 5. Select the NDEF file.

7.2 Reading of an NDEF message

The RF host executes the NDEF read procedure to read the NDEF file. 1. Detect successfully t he NDEF file using the NDEF detection procedure 2. Check that the read access without any security is granted for the NDEF file from the information provided by the CC file 3. Select the NDEF file 4. Read the NDEF file.

7.3 Reading a locked NDEF file

The RF host executes this procedure to read an NDEF file which has been locked previously. 1. Select the NDEF Tag Application 2. Select the NDEF file 3. Verify the Read password by using the Verify command 4. Read the data in the NDEF file.

7.4 Locking an NDEF file

The RF host executes this procedure to protect an NDEF file. 1. Select the NDEF Tag Application 2. Check the right access provided by the CC file 3. Select the NDEF file 4. Transmit the NDEF file Write password by using the Verify command 5. Lock the NDEF file by sending the Enable verification command.

SRTAG2K-D Functional procedures

7.5 Unlocking an NDEF file

The RF host executes this procedure to read an NDEF file which has been locked previously. 1. Select the NDEF Tag Application 2. Select the NDEF file 3. Verify the NDEF file Write password by using the Verify command 4. Unlock the NDEF file by sending the Disable verification command.

7.6 Reaching the read-onl y state for an NDEF file

The RF host executes this procedure to read an NDEF file which has been locked previously. 1. Select the NDEF Tag Application 2. Select the NDEF file 3. Transmit the NDEF file Write password by using the Verify command 4. Send an EnablePermanentState command as the Write access right of the previous Select NDEF file.

7.7 Changing an NDEF password procedure

The RF host could use this procedure to change one NDEF password. it can be a Read or Write password. 1. Select the NDEF Tag Application 2. Select the NDEF file 3. Transmit the NDEF file Write password by using the Verify command 4. Change the password by sending a ChangeReferenceData command.

7.8 Changing a File type Procedure

The RF host executes this procedure to change the File Type of a file for which all access rights were previously granted. 1. Select the NDEF Tag Application 2. Select the File to be modified 3. Set the File Length to 0x00 using the UpdateBinary command 4. Send an UpdateFileType command with the New file Type as data.

8 UID: Unique identifier

  • The IC manufacturer code on 1 byte (0x02 for STMicroelectronics).
  • The Product code on 1 byte.
  • A device number on 5 bytes. Table 52 describes the UID format.

Table 52. UID format

9 Maximum rating

conditions above those indicated in the operating sections of this specification is not implied. Table 53. Absolute maximum ratings

  1. Counted from ST shipment date.
  2. Compliant with JEDEC Std J-STD-020D (for small body, Sn-Pb or Pb assembly), the ST ECOPACK ®

directive 2011/65/EU, July 2011).

  1. Based on characterization, not tested in producti on. Maximum absorbed power = 100 mW @ 7.5 A/m

Table 54. DC characteristics

10 RF Session pad parameters

This section lists the timing of the RF Session pad according to its configuration. Table 55. RF Session pad timings measurement (1)

11 RF electrical parameters

characteristics of the device in RF mode. performed under the Measurement Conditions summarized in the relevant tables. conditions when relying on the quoted parameters. Table 56. Default operating conditions Table 57. RF characteristics (1)

  1. All timing characterizations were performed on a re ference antenna with the following characteristics:
  2. Characterized only, at room temperature only, measured at VAC0-VAC1 = 2 V peak to peak at 13.56 MHz.

specifications, grade definitions and product status are available at: www.st.com. ECOPACK® is an ST trademark.

12.1 Mechanical data for the UFDFPN8 package

Figure 6. UFDFPN8 - 8-lead ultra thin fine pitch dual flat package, no lead, 2x3 mm,

  1. The central pad (area E2 by D2 in the above illustration) is internally pulled to VSS. It must not be

connected to any other voltage or signal line on the PCB, for example during the soldering process.

  1. Values in inches are converted from mm and rounded to 4 decimal digits.
  2. Applied for exposed die paddle and terminals. Exclude embedded part of exposed die paddle from

13 Part numbering

Table 59. Ordering information scheme for packaged devices

Table 60. Document revision history 31-Oct-2013 1 Initial release. Added Section 7.8: Changing a File type Procedure. Added Table 54: DC characteristics.