STM1403_08 STMICROELECTRONICS | Alldatasheet

Document overview

  • Manufacturer or author: Provided By ALLDATASHEET.COM(FREE DATASHEET DOWNLOAD SITE)
  • PDF pages: 34

Technical content

Datasheet sections

  • 1 Description
  • 1.1 V OUT pin modes
  • 1.1.1 STM1403A
  • 1.1.2 STM1403B
  • 1.1.3 STM1403C
  • 2 Pin descriptions
  • 2.1 SAL , security alarm output (open drain)
  • 2.1.1 TP 1, TP3
  • 2.1.2 TP 2, TP4
  • 2.1.3 Vccsw , VCC switch output
  • 2.1.4 BLD , VBAT low voltage detect output (open drain)
  • 2.1.5 Active-low RST output (open drain)
  • 2.1.6 MR , manual reset input
  • 2.1.7 PFO , power-fail output (open drain)
  • 2.1.8 PFI, power-fail input
  • 2.1.10 V OUT
  • 2.1.11 V TPU
  • 2.1.12 V CC
  • 2.1.13 V BAT
  • 2.1.14 V SS
  • 3 Operation
  • 3.1 Reset input
  • 3.2 Push-button reset input
  • 3.3 Backup battery switchover
  • 3.4 Power-fail input/output
  • 3.5 Applications information
  • 3.6 Negative-going V
  • 4 Tamper detection
  • 4.1 Physical

Features

■ STM1403 supports FIPS-140 security level 3+ –F o u r high-impedance physical tamper inputs – Over/under operating voltage detector – Security alarm (SAL ) on tamper detection ■ Supervisory functions – Automatic battery switchover –R S T output (open drain) – Manual (push-button) reset input (MR ) – Power-fail comparator (PFI/PFO ) ■ Vccsw (VCC switch output) – Low when switched to V CC – High when switched to V BAT (BATT ON indicator) ■ Battery low voltage detector (power-up) ■ Optional VREF (1.237 V) – (Available for STM1403A only) ■ Low battery supply current (2.8 µA, typ) ■ Secure low profile 16-pin, 3 x 3 mm, QFN package QFN16, 3 mm x 3 mm (Q) Table 1. Device summary

  1. Reset output, power-fail comparat or, battery low detection (SAL, RST, PFO, and BLD are open drain).
  2. Normal mode: low when V OUT is internally switched to VCC and high when VOUT is internally switched to battery.
  3. Contact local ST sales office for availability.

REF pin for STM1403A. It is the VTPU pin for STM1403B/C.

Table 8. QFN16 – 16-lead, quad, flat package, no lead, 3 x 3 mm body size, mechanical data . . . 31

1 Description

The STM1403 family of security supervisors are a low power family of intrusion (tamper) detection chips targeted at manufacturers of POS terminals and other systems, to enable them to meet physical and/or environmental intrusion monitoring requirements as mandated by various standards, such as Federal Information Processing Standards (FIPS) Pub 140 entitled “Security Requirements for Cryptographic Modules,” published by the National Institute of Standards and Technology, U.S. Department of Commerce), EMVCo, ISO, ZKA, and VISA PED. STM1403 supports target levels 3 and lower. The STM1403 includes automatic battery switchover, RST output (open drain), manual (push-button) reset input (MR), power-fail comparator (PFI/PFO), physical and/or environmental tamper detect/security alarm, and battery low voltage detect features. The STM1403A also offers a VREF (1.237 V) as an option on pin 9. On the STM1403B/C, this pin is VTPU (internally switched VCC or VBAT).

1.1 V OUT pin modes

The STM1403 is available in three versions, corresponding to three modes of the VOUT pin (supply voltage out), when the SAL (security alarm) is asserted (active-low) upon tamper detection:

1.1.1 STM1403A

VOUT stays ON (at VCC or VBAT) when SAL is driven low (activated).

1.1.2 STM1403B

VOUT is set to High-Z when SAL is driven low (activated).

1.1.3 STM1403C

VOUT is driven to ground when SAL is activated (may be used when VOUT is connected directly to the VCC pin of the external SRAM that holds the cryptographic codes). All variants (see Table 1: Device summary) are pin-compatible and available in a security- friendly, low profile, 16-pin QFN package.

Figure 1. Logic diagram

  1. V REF only for STM1403A; VTPU for STM1403B/C.
  2. Normal mode: low when V OUT is internally switched to VCC and high when VOUT is internally switched to
  3. SAL , RST, PFO, and BLD are open drain.

Table 2. Signal names Note: See Section 2: Pin descriptions on page 11 for details.

  1. Normal mode: low when V OUT is internally switched to VCC and high when VOUT is internally switched to
  2. SAL , RST, PFO, and BLD are open drain.
  3. V REF only for STM1403A; VTPU for STM1403B/C.

1.237 V reference voltage

2 Pin descriptions

See Figure 1: Logic diagram and Table 2: Signal names for a brief overview of the signals connected to this device.

2.1 SAL , security alarm output (open drain)

This signal can be generated when ANY of the following conditions occur:

  • VINT > VHV, where VHV = upper voltage trip limit (4.2 V typ); and where VINT = VCC or VBAT;
  • VINT < VLV, where VLV = lower voltage trip limit (2.0 V typ); and where VINT = VCC or VBAT; or
  • When any of the physical tamper inputs, TP1 to TP4, change from their normal states to the opposite (i.e., intrusion of a physical enclosure). Note: 1 The default state of the SAL output during initial power-up is undetermined.

2 The alarm function will operate either with VCC on or when the part is internally switched

from VCC to VBAT.

2.1.1 TP 1, TP3

Physical tamper detect pin set normally to high (NH). They are connected externally through a closed switch or a high-impedance resistor to VOUT (in the case of STM1403A) or VTPU (in the case of STM1403B/C. A tamper condition will be detected when the input pin is pulled low (see Figure 5 and Figure 6). If not used, tie the pin to VOUT (for STM1403A) or VTPU (for STM1403B/C).

2.1.2 TP 2, TP4

Physical tamper detect pin set normally to low (NL). They are connected externally through a high-impedance resistor or a closed switch to V SS. A tamper condition will be detected when the input pin is pulled high (see Figure 7 and Figure 8). If not used, tie the pin to VSS.

2.1.3 Vccsw , VCC switch output

This output is low when VOUT (see Section 2.1.10: VOUT on page 13) is internally switched to VCC; in this mode it may be used to turn on an external p-channel MOSFET switch which can source an external device directly from VCC for currents greater than 80 mA (bypassing the STM1403). This pin goes high when VOUT is internally switched to VBAT and may be used as a “BATT ON” indicator. If a security alarm (SAL) is issued on tamper, then the state of the Vccsw pin is as follows:

  1. STM1403A (V OUT remains ON when SAL is active-low): Vccsw pin will continue to operate in normal mode; 2. STM1403B (V OUT is taken to High-Z when SAL is active-low): Vccsw pin will be set to high when this occurs; and 3. STM1403C (V OUT is driven to ground when SAL is active-low): Vccsw pin will be set to high when this occurs.

2.1.4 BLD , VBAT low voltage detect output (open drain)

This is an internally loaded test of the battery, activated only during a power-up sequence to insure that the battery is good either prior to or after encapsulation of the module. There are three customer options for V DET:

  • 2.3 V (2.5 V – external diode drop of about 0.2 V) for a 3 V lithium cell
  • 2.5 V (2.7 V – 0.2 V) for a 3 V lithium cell or
  • 3.2 V (3.4 V – 0.2 V) for a 3.68 V lithium “AA” battery This output pin will go active-low when it detects a voltage on the VBAT pin below VDET. BLD will be released when VCC drops below VRST.

2.1.5 Active-low RST output (open drain)

Goes low and stays low when VCC drops below VRST (reset threshold selected by the customer), or when MR is logic low. It remains low for trec (200ms, typical) AFTER VCC rises above VRST and MR goes from low to high.

2.1.6 MR , manual reset input

A logic low on MR asserts the RST output. The RST output remains asserted as long as MR is low and for trec after MR returns to high. This active low input has an internal 40 kΩ (typical) pull-up resistor. It can be driven from a TTL or CMOS logic line or shorted to ground with a switch. Leave it open if unused.

2.1.7 PFO , power-fail output (open drain)

When PFI is less than VPFI (power-fail input threshold voltage) or VCC falls below VSW (battery switchover threshold ~ 2.4 V), PFO goes low, otherwise, PFO remains high. Leave this pin open if unused.

2.1.8 PFI, power-fail input

When PFI is less than VPFI, or when VCC falls below VSW (see PFO, above), PFO goes active-low. If this function is unused, connect this pin to VSS. 2.1.9 V REF, reference voltage output (1.237, typ) This is valid only when VCC is between 2.4 V and 3.6 V. When VCC falls below 2.4 V (VSW), VREF is pulled to ground with an internal 100 kΩ resistor. This is an optional feature available on the STM1403A. On the STM1403B/C, this pin is VTPU (internally switched VCC or VBAT). If unused, this pin should float.

2.1.10 V OUT

This is the supply voltage output. When VCC rises above VSO (battery backup switchover voltage), VOUT is supplied from VCC. In this condition, VOUT may be connected externally to VCC through a p-channel MOSFET switch. When VCC falls below the lower value of VSW (~2.4 V), or VBAT, VOUT is supplied from VBAT. It is recommended that the VOUT pin be connected externally to a capacitor that will retain a charge for a period of time, in case an intruder forces VCC or VBAT to ground. The rectifying diode connected from the positive terminal of the battery to the VBAT pin of the STM1403 will prevent discharge of the capacitor. Three variations of parts will be offered with the following options: 1. STM1403A: V OUT remains ON when SAL is active-low; Vccsw pin will continue to operate in normal mode (see Section 2.1.3: Vccsw, VCC switch output on page 11); 2. STM1403B: V OUT is taken to High-Z when SAL is active-low; Vccsw pin will be set to high when this occurs; and 3. STM1403C: V OUT is driven to ground when SAL is active-low; Vccsw pin will be set to high when this occurs.

2.1.11 V TPU

For STM1403B and STM1403C, this pin provides pull-up voltage for the physical tamper pins (TP1-4). This pin is not to be used as voltage supply source for any other purpose. Note: V TPU is the internally switched supply voltage from either the VCC pin or the VBAT pin.

2.1.12 V CC

This is the supply voltage (2.2 V to 3.6 V).

2.1.13 V BAT

This is the secondary (backup battery) supply voltage. The pin is connected to the positive terminal of the battery with a rectifying diode like the BAT54J from STMicroelectronics for reverse charge protection. Voltage at this pin, after diode rectification, will be approximately

0.2 V less than the battery voltage, and will depend on the type of battery used as well as

BAT being drawn. (A capacitor of at least 1.0 µF connected between the VBAT pin and VSS is required.) If no battery is used, connect the VBAT pin to the VCC pin.

2.1.14 V SS

Ground, VSS, is the reference for the power supply. It must be connected to system ground.

3 Operation

3.1 Reset input

The STM1403 security supervisor asserts a reset signal to the MCU whenever V CC goes below the reset threshold (VRST), or when the push-button reset input (MR) is taken low. RST is guaranteed to be a logic low for 0V < VCC < VRST if VBAT is greater than 1V. Without a backup battery, RST is guaranteed valid down to VCC =1V. During power-up, once VCC exceeds the reset threshold an internal timer keeps RST low for the reset time-out period, trec. After this interval RST returns high. If VCC drops below the reset threshold, RST goes low. Each time RST is asserted, it stays low for at least the reset time-out period (trec). Any time VCC goes below the reset threshold the internal timer clears. The reset timer starts when VCC returns above the reset threshold.

3.2 Push-button reset input

A logic low on MR asserts reset. Reset remains asserted while MR is low, and for trec (see Figure 25 on page 24) after it returns high. The MR input has an internal 40 kΩ pull-up resistor, allowing it to be left open if not used. This input can be driven with TTL/CMOS-logic levels or with open-drain/collector outputs. Connect a normally open momentary switch from MR to ground to create a manual reset function; external debounce circuitry is not required. If MR is driven from long cables or the device is used in a noisy environment, connect a 0.1 µF capacitor from MR to VSS to provide additional noise immunity. MR may float, or be tied to VCC when not used.

3.3 Backup battery switchover

In the event of a power failure, it may be necessary to preserve the contents of external SRAM through V OUT. With a backup battery installed with voltage VBAT, the devices automatically switch the SRAM to the backup supply when VCC falls. Note: If backup battery is not used, connect both V BAT and VOUT to VCC. This family of security supervisors does not always connect VBAT to VOUT when VBAT is greater than VCC. VBAT connects to VOUT (through a 100 Ω switch) when VCC is below VSW battery) to have a higher voltage than VCC. Assuming that VBAT > 2.0 V, switchover at VSO ensures that battery backup mode is entered before VOUT gets too close to the 2.0 V minimum required to reliably retain data in most external SRAMs. When VCC recovers, hysteresis is used to avoid oscillation around the VSO point. VOUT is connected to VCC through a 3 Ω PMOS power switch. Note: The backup battery may be removed while V CC is valid, assuming VBAT is adequately decoupled (0.1 µF typ), without danger of triggering a reset.

Table 3. I/O status in battery backup

3.4 Power-fail input/output

STM1403 or the microprocessor drops below the minimum operating voltage. connected to MR so that a low voltage on PFI will generate a reset output.

3.5 Applications information

Figure 9. Power-fail comparator waveform

3.6 Negative-going V CC transients and undershoot

The STM1403 devices are relatively immune to negative-going VCC transients (glitches). provides additional transient immunity (see Figure 10). CC to VSS (cathode connected to VCC, anode to VSS). recommended for surface mount. Figure 10. Supply voltage protection

4 Tamper detection

4.1 Physical

There are four (4) high-impedance physical tamper detect input pins, 2 normally set to high (NH) and 2 normally set to low (NL). Each input is designed with a glitch immunity (see Table 7 on page 28). These inputs can be connected externally to several types of actuator devices (e.g., switches, wire mesh). A tamper on any one of the four inputs that causes its state to change will trigger the security alarm (SAL ) and drive it to active-low. Once the tamper condition no longer exists, the SAL will return to its normal high state. TP1 and TP3 are set normally to high (NH). They are connected externally through a closed switch or a high-impedance resistor to VOUT (in the case of STM1403A) or VTPU (in the case of STM1403B/C), A tamper condition will be detected when the input pin is pulled low (see Figure 5 and Figure 6). If not used, tie the pin to VOUT or VTPU. TP2 and TP4 are set normally to low (NL). They are connected externally through a high- impedance resistor or a closed switch to VSS. A tamper condition will be detected when the input pin is pulled high (see Figure 7 and Figure 8). If not used, tie the pin to VSS.

4.2 Supply voltage

The internally switched supply voltage, VINT (either VCC input or VBAT input) is continuously monitored. If VINT should exceed the over voltage trip point, VHV (set at 4.2V, typical), or should go below the under voltage trip point, VLV (set at 2.0 V, typical). SAL will be driven active-low. Once the tamper condition no longer exists, the SAL pin will return to its normal high state. When no tamper condition exists, SAL is normally high (see Section 2: Pin descriptions on page 11). When a tamper is detected, the SAL is activated (driven low), independent of the part type. VOUT can be driven to one of three states, depending on which variant of STM1403 is being used (see Table 1: Device summary on page 1):

  • ON
  • High-Z or
  • Ground (VSS) Note: The STM1403 must be initially powered above V RST to enable the tamper detection alarms. For example, if the battery is on while VCC = 0V, no alarm condition can be detected until VCC rises above VRST (and trec expires). From this point on, alarms can be detected either on battery or VCC. This is done to avoid false alarms when the device goes from no power to its operational state.

5 Typical operating characteristics

Note: Typical values are at T A = 25°C. Figure 11. V BAT -to-VOUT on-resistance vs. temperature Figure 12. Supply current vs. temperature (no load)

6 Maximum ratings

Program and other relevant quality documents. exceed 180°C for between 90 to 150 seconds). Table 4. Absolute maximum ratings

7 DC and AC parameters

Figure 24. AC testing input/output waveforms Figure 25. MR timing waveform Figure 26. STM1403 switchover diagram, condition A (V BAT < VSW) Figure 27. STM1403 switchover diagram, condition B (V BAT > VSW) Table 5. Operating and AC measurement condition

Table 6. DC and AC characteristics

Table 6. DC and AC characteristics (continued)

  1. Valid for ambient operating temperature: T A = –40 to 85°C; VCC = VRST (max) to 3.6 V; and VBAT = 2.8 V (except where

noted); typical values are for 3.3 V and 25°C.

  1. V CC supply current, logic input leakage, push-button reset functionality, PFI functionality, state of RST tested at
  2. The leakage current measured on the RST , SAL, PFO, and BLD pins are tested with the output not asserted (output high
  3. When V BAT > VCC > VSW, VOUT remains connected to VCC until VCC drops below VSW.
  4. When V SW > VCC > VBAT, VOUT remains connected to VCC until VCC drops below the battery voltage (VBAT) – 75 mV.
  5. Maximum external capacitive load on V REF pin cannot exceed 1nF.
  6. The reset threshold tolerance is wider for V CC rising than for VCC falling due to the 10 mV (typ) hysteresis, which prevents

Table 7. Physical and environmental tamper detection levels

  1. Valid for ambient operating temperature: T A = –40 to 85°C; VCC = VLV to VHV (except where noted).

1.3 V(2)

  1. In the case of STM1403A, physical tamper input pins (TP X) are referenced to VOUT (pin 12). In the case of

STM1403B or C, TPX are referenced to VTPU pin (pin 9).

0.3 V(2) V

8 Package mechanical data

compliance with JEDEC Standard JESD97. The maximum ratings related to soldering conditions are also marked on the inner box label. ECOPACK is an ST trademark. ECOPACK specifications are available at: www.st.com. Figure 28. QFN16 – 16-lead, quad, flat package, no lead, 3 x 3 mm body size, outline Note: Drawing is not to scale.

Figure 29. QFN16 – 16-lead, quad, flat package, no lead, 3 x 3 mm, recommended Note: Substrate pad should be tied to V SS. Table 8. QFN16 – 16-lead, quad, flat package, no lead, 3 x 3 mm body size,

9 Part numbering

Table 9. Ordering information scheme (see Figure 30 on page 32 for marking information)

  1. Contact local ST sales office for availability.

Figure 30. Topside marking information

Table 10. Document revision history 07-Feb-2007 4 Update cover page, Table 7, and part numbering (Table 9). 20-Aug-2008 5 Minor formatting changes, updated Table 1 and 7.