Part Number Hot Search : 
SY100S IPB100N 74HC85AP 00ADA330 MIC5400 74LS08 P5N50 P6A10
Product Description
Full Text Search
 

To Download HCS412TSN Datasheet File

  If you can't view the Datasheet, Please click here to try to view without PDF Reader .  
 
 


  Datasheet File OCR Text:
 HCS412
KEELOQ(R) Code Hopping Encoder and Transponder
FEATURES
Security
* * * * * Programmable 64-bit encoder crypt key Two 64-bit IFF keys Keys are read protected 32-bit bi-directional challenge and response using one of two possible keys 69-bit transmission length * 32-bit hopping code, * 37-bit nonencrypted portion Programmable 28/32-bit serial number 60-bit, read protected seed for secure learning Two IFF encryption algorithms Delayed counter increment mechanism Asynchronous transponder communication Transmissions include button Queuing information
PACKAGE TYPES
PDIP, SOIC
S0 S1 S2/RFEN/LC1 LC0 1 8 VDD LED DATA GND
HCS412
2 3 4
7 6 5
BLOCK DIAGRAM
VDD Power Control Oscillator
* * * * * *
Configuration Register S0 S1 Debounce Control and Queuer Address EEPROM Decoding
Wake-up Logic
LED
* * * * * * * * * * * * *
2.0V to 6.3V operation Three switch inputs: S2, S1, S0 - seven functions Battery-less bi-directional transponder capability Selectable baud rate and code word blanking Automatic code word completion Battery low detector PWM or Manchester data encoding Combined transmitter, transponder operation Anticollision of multiple transponders Passive proximity activation Device protected against reverse battery Intelligent damping for high Q LC-circuits 100 mVPP sensitive LC input
Transponder Circuitry
LC0 RFEN/S2/LC1
PPM Detector DATA PPM Manch. Encoder
DATA
DATA Driver
Other
* * * * * * * * * * Simple programming interface On-chip tunable RC oscillator, 10% On-chip EEPROM 64-bit user EEPROM in Transponder mode Battery-low LED indication Serialized Quick Turn Programming (SQTPSM ) 8-pin PDIP/SOIC RF Enable output ASK and FSK PLL interface option Built in LC input amplifier
Typical Applications
* * * * * * * Automotive remote entry systems Automotive alarm systems Automotive immobilizers Gate and garage openers Electronic door locks (Home/Office/Hotel) Burglar alarm systems Proximity access control
(c) 2002 Microchip Technology Inc.
Preliminary
DS41099C-page 1
Register
LED Control
Control Logic and Counters
Operating
Encryption/Increment Logic
HCS412
GENERAL DESCRIPTION
The HCS412 combines patented KEELOQ code hopping technology with bi-directional transponder challenge-and-response security into a single chip solution for logical and physical access control. When used as a code hopping encoder, the HCS412 is ideally suited to keyless entry systems; vehicle and garage door access in particular. The same HCS412 can also be used as a secure bi-directional transponder for contactless token verification. These capabilities make the HCS412 ideal for combined secure access control and identification applications, dramatically reducing the cost of hybrid transmitter/transponder solutions. * Learn - Learning involves the receiver calculating the transmitter's appropriate crypt key, decrypting the received hopping code and storing the serial number, synchronization counter value and crypt key in EEPROM (Section 6.1). The KEELOQ product family facilitates several learning strategies to be implemented on the decoder. The following are examples of what can be done. - Simple Learning The receiver uses a fixed crypt key, common to all components of all systems by the same manufacturer, to decrypt the received code word's encrypted portion. - Normal Learning The receiver uses information transmitted during normal operation to derive the crypt key and decrypt the received code word's encrypted portion. - Secure Learn The transmitter is activated through a special button combination to transmit a stored 60-bit seed value used to generate the transmitter's crypt key. The receiver uses this seed value to derive the same crypt key and decrypt the received code word's encrypted portion. * Manufacturer's code - A unique and secret 64bit number used to generate unique encoder crypt keys. Each encoder is programmed with a crypt key that is a function of the manufacturer's code. Each decoder is programmed with the manufacturer code itself. * Anticollision - A scheme whereby transponders in the same field can be addressed individually preventing simultaneous response to a command (Section 4.3.1). * IFF - Identify Friend or Foe (Section 1.2). * Proximity Activation - A method whereby an encoder automatically initiates a transmission in response to detecting an inductive field (Section 4.4.1). * Transport code - An access code, `password' known only by the manufacturer, allowing program access to certain secure device memory areas (Section 4.3.3). * AGC - Automatic Gain Control.
1.0
SYSTEM OVERVIEW
Key Terms The following is a list of key terms used throughout this data sheet. For additional information on terminology, please refer to the KEELOQ introductory Technical Brief (TB003). * RKE - Remote Keyless Entry. * PKE - Passive Keyless Entry. * Button Status - Indicates what transponder button input(s) activated the transmission. Encompasses the 4 button status bits LC0, S2, S1 and S0 (Figure 3-2). * Code Hopping - A method by which a code, viewed externally to the system, appears to change unpredictably each time it is transmitted (Section 1.1.3). * Code word - A block of data that is repeatedly transmitted upon button activation (Section 3.2). * Transmission - A data stream consisting of repeating code words. * Crypt key - A unique and secret 64-bit number used to encrypt and decrypt data. In a symmetrical block cipher such as the KEELOQ algorithm, the encryption and decryption keys are equal and will therefore be referred to generally as the crypt key. * Encoder - A device that generates and encodes data. * Encryption Algorithm - A recipe whereby data is scrambled using a crypt key. The data can only be interpreted by the respective decryption algorithm using the same crypt key. * Decoder - A device that decodes data received from an encoder. * Transponder Reader (Reader, for short) - A device that authenticates a token using bi-directional communication. * Decryption algorithm - A recipe whereby data scrambled by an encryption algorithm can be unscrambled using the same crypt key.
DS41099C-page 2
Preliminary
(c) 2002 Microchip Technology Inc.
HCS412
1.1 Encoder Overview
The HCS412 code hopping transcoder is designed specifically for passive entry systems; primarily vehicle access. The transcoder portion of a passive entry system is integrated into a transmitter, carried by the user and operated to gain access to a vehicle or restricted area. The HCS412 is meant to be a cost-effective yet secure solution to such systems, requiring very few external components (Figure 2-6). 1.1.1 LOW-END SYSTEM SECURITY RISKS The 16-bit synchronization counter is the basis behind the transmitted code word changing for each transmission; it increments each time a button is pressed. Once the device detects a button press, it reads the button inputs and updates the synchronization counter. The synchronization counter and crypt key are input to the encryption algorithm and the output is 32 bits of encrypted information. This encrypted data will change with every button press, its value appearing externally to `randomly hop around', hence it is referred to as the hopping portion of the code word. The 32-bit hopping code is combined with the button information and serial number to form the code word transmitted to the receiver. The code word format is explained in greater detail in Section 3.2. `grabbing' or code `scanning'. The high security level of the HCS412 is based on the patented KEELOQ technology. A block cipher based on a block length of 32 bits and a key length of 64 bits is used. The algorithm obscures the information in such a way that even if the transmission information (before coding) differs by only one bit from that of the previous transmission, statistically greater than 50 percent of the next transmission's encrypted bits will change. 1.1.3 Most low-end keyless entry transmitters are given a fixed identification code that is transmitted every time a button is pushed. The number of unique identification codes in a low-end system is usually a relatively small number. These shortcomings provide an opportunity for a sophisticated thief to create a device that `grabs' a transmission and retransmits it later, or a device that quickly `scans' all possible identification codes until the correct one is found. 1.1.2 HCS412 SECURITY HCS412 HOPPING CODE
The HCS412, on the other hand, employs the KEELOQ code hopping technology coupled with a transmission length of 69 bits to virtually eliminate the use of code
FIGURE 1-1:
BUILDING THE TRANSMITTED CODE WORD (ENCODER)
Transmitted Information KEELOQ Encryption Algorithm 32 Bits of Encrypted Data Serial Number Button Press Information
EEPROM Array Crypt Key Sync Counter Serial Number
1.2
Identify Friend or Foe (IFF) Overview
Validation of a token first involves an authentication device sending a random challenge to the token. The token then replies with a calculated response that is a function of the received challenge and the stored crypt key. The authentication device, transponder reader, performs the same calculation and compares it to the token's response. If they match, the token is identified as valid and the transponder reader can take appropriate action. The HCS412's 32-bit IFF response is generated using one of two possible encryption algorithms and one of two possible crypt keys; four combinations total. The authenticating device precedes the challenge with a five bit command word dictating which algorithm and key to use in calculating the response.
The bi-directional communication path required for IFF is typically inductive for short range (<10cm) transponder applications and an inductive challenge, RF response for longer range (~1.5m) passive entry applications.
(c) 2002 Microchip Technology Inc.
Preliminary
DS41099C-page 3
HCS412
2.0
2.1
DEVICE DESCRIPTION
Pinout Description
The HCS412's footprint is identical to other encoders in the KEELOQ family, except for the two pins reserved for low frequency communication.
TABLE 2-1:
Pin Name S0 S1 S2/RFEN/LC1
PINOUT SUMMARY
Pin Number 1 2 3 Description Button input pin with Schmitt Trigger detector and internal 60 k (nominal) pull-down resistor (Figure 2-1). Button input pin with Schmitt Trigger detector and internal 60 k (nominal) pull-down resistor (Figure 2-1). Multi-purpose input / output pin (Figure 2-2). * Button input pin with Schmitt Trigger detector and internal pull-down resistor. * RFEN output driver. * LC1 low frequency (LF) antenna output driver for inductive responses and LC bias. * Programming clock signal input. Low frequency (LF) antenna input with automatic gain control for inductive reception and low frequency output driver for inductive responses (Figure 2-3). Ground reference. Transmission data output driver. Programming input / output data signal (Figure 2-4). LED output driver (Figure 2-5). Positive supply voltage.
LC0 GND DATA LED VDD
4 5 6 7 8
FIGURE 2-1:
S0 S1
S0/S1 PIN DIAGRAM
SWITCH > IN 60 k
FIGURE 2-3:
LC0 PIN DIAGRAM
RECTIFIER AND REGULATOR VDD
S2LC OPTION LC0 100 AMP AND DET
FIGURE 2-2:
S2/RFEN/LC1 PIN DIAGRAM
S2LC OPTION
> LC INPUT 10V VDD
OUT
100
>
SWITCH 2 INPUT
< LC OUTPUT
10V
DS41099C-page 4
>
VBIAS
RFEN
Preliminary
(c) 2002 Microchip Technology Inc.
HCS412
FIGURE 2-4: DATA PIN DIAGRAM FIGURE 2-5: LED PIN DIAGRAM
LED DATA < IN OE > LED_ON >
R
DATA OUT > 120 k
DATA
FIGURE 2-6:
TYPICAL APPLICATION CIRCUITS
Battery-less Short Range Transponder
S0 S1 LC1 LC0 1 8 VDD LED DATA GND
HCS412
2 3 4
7 6 5
Long Range / Proximity Activated Transponder / Encoder
S0 S1 LC1 LC0 1 8 VDD LED DATA GND RF
HCS412
2 3 4
7 6 5
Short Range Transponder with RFEN Control / Long Range Encoder
S0 S1 RFEN LC0 1 8 VDD LED DATA GND RF
HCS412
2 3 4
7 6 5
(c) 2002 Microchip Technology Inc.
Preliminary
DS41099C-page 5
HCS412
2.2
2.2.1
Architecture Overview
WAKE-UP LOGIC AND POWER DISTRIBUTION
The HCS412 automatically goes into a low-power Standby mode once connected to the supply voltage. Power is supplied to the minimum circuitry required to detect a wake-up condition; button activation or LC signal detection. The HCS412 will wake from Low-power mode when a button input is pulled high or a signal is detected on the LC0 LF antenna input pin. Waking involves powering the main logic circuitry that controls device operation. The button and transponder inputs are then sampled to determine which input activated the device. A button input activation places the device into Encoder mode. A signal detected on the transponder input places the device into Transponder mode. Encoder mode has priority over Transponder mode so a signal on the transponder input would be ignored if it occurred simultaneously to a button activation; ignored until the button input is released. 2.2.2 CONTROL LOGIC
The EEPROM is programmed during production by clocking (S2 pin) the data into the DATA pin (Section 7.0). Certain EEPROM locations can also be remotely read/written through the LF communication path (Section 4.3). 2.2.4 CONFIGURATION REGISTER
The first activation after connecting power to the HCS412, the device retrieves the configuration from EEPROM storage and buffers the information in a configuration register. The configuration register then dictates various device operation options including the RC oscillator tuning, the S2/RFEN/LC1 pin configuration, low voltage trip point, modulation format,... 2.2.5 ONBOARD RC OSCILLATOR AND OSCILLATOR TUNE VALUE (OSCT)
The HCS412 has an onboard RC oscillator. As the RC oscillator is susceptible to variations in process parameters, temperature and operating voltage, oscillator tuning is provided for more accurate timing characteristics. The 4-bit Oscillator Tune Value (OSCT) (Table 2-2) allows tuning within 4% of the optimal oscillator speed at the voltage and temperature used when tuning the device. A properly tuned oscillator is then accurate over temperature and voltage variations to within 10% of the tuned value. Oscillator speed is significantly affected by changes in the device supply voltage. It is therefore best to tune the HCS412 such that the variance in oscillator speed be symmetrical about an operating mid-point (Figure 2-7). ie... * If the design is to run on a single lithium battery, tune the oscillator while supplying the HCS412 with ~2.5V (middle of the 3V to 2V usable battery life). * If the design is to run on two lithium batteries, tune the oscillator while supplying the HCS412 with ~4V (middle of 6V to 2V battery life). * If the design is to run on 5V, tune the oscillator while supplying the HCS412 with 5V. Say the HCS412's oscillator is tuned to be optimal at a 6V supply voltage but the device will operate on a single lithium battery. The resulting oscillator variance over temperature and voltage will not be 4% but will be more like -7% to -15%. Programming using a supply voltage other than 5V may not be practical. In these cases, adjust the oscillator tune value such that the device will run optimally at the target voltage. (i.e., If programming using 5V a device that will run at 3V, program the device to run slow at 5V such that it will run optimally at 3V).
A dedicated state machine, timer and a 32-bit shift register perform the control, timing and data manipulation in the HCS412. This includes the data encryption, data output modulation and reading of and writing to the onboard EEPROM. 2.2.3 EEPROM
The HCS412 contains nonvolatile EEPROM to store configuration options, user data and the synchronization counter. The configuration options are programmed during production and include the read protected security-related information such as crypt keys, serial number and discrimination value (Table 7-2). The 64 bits (4x16-bit words) of user EEPROM are read/ write accessible through the low frequency communication path as well as in-circuit, wire programmable during production. The initial synchronization counter value is programmed during production. The counter is implemented in Grey code and updated using bit writes to minimize EEPROM writing over the life of the product. The user need not worry about counter format conversion as the transmitted counter value is in binary format. Counter corruption is protected for by the use of a semaphore word as well as by the internal circuitry ensuring the EEPROM write voltage is at an acceptable level prior to each write.
DS41099C-page 6
Preliminary
(c) 2002 Microchip Technology Inc.
HCS412
TABLE 2-2:
OSCT3:0 0111b + 0011b 0010b 0001b 0000b 1111b 1110b 1101b 1000b
OSCILLATOR CALIBRATION VALUE (OSCT)
Description Slowest Oscillator Setting (long TE) : : Slower (longer TE) : Nominal Setting : Faster (shorter TE) : : Fastest Oscillator Setting (short TE)
FIGURE 2-8:
Volts (V) 5.0 4.8 4.6 4.4 4.2 4.0 3.8 2.8 2.6 2.4 2.2 2.0 1.8 1.6 -40
TYPICAL VOLTAGE TRIP POINTS
VLOW
VLOW sel = 1
VLOW sel = 0
FIGURE 2-7:
NORMALIZED RFTE
1.10 1.08 1.06 1.04 1.02 1.00 0.98 0.96 0.94 0.92 0.90
HCS412 NORMALIZED RFTE VERSUS TEMP
0
50
85 Temp (C)
Nominal VLOW trip point
RFTE
TABLE 2-3:
VLOWSEL 0 1
VLOWSEL OPTIONS
Nominal Trip Point 2.2V 4.4V Description for 3V battery applications for 6V battery applications
TABLE 2-4:
RFTE
VLOW STATUS BIT
Description VDD is above selected trip voltage VDD is below selected trip voltage
VLOW
-50 -40 -30 -20 -10 0 10 20 30 40 50 60 70 80 90
0 1 2.2.7
VDD LEGEND = 2.0V = 3.0V = 6.0V
Temperature C
THE S2/RFEN/LC1 PIN
Note: 2.2.6
Values are for calibrated oscillator.
LOW VOLTAGE DETECTOR
The HCS412's battery voltage detector detects when the supply voltage drops below a predetermined value. The value is selected by the Low Voltage Trip Point Select (VLOWSEL) configuration option. The low voltage detector result is included in encoder transmissions (VLOW) allowing the receiver to indicate when the transmitter battery is low (Figure 3-2). The HCS412 indicates a low battery condition by changing the LED operation (Figure 3-9).
The S2/RFEN/LC1 pin may be used as a button input, RF enable output or as an interface to the LF antenna. Select between LC1 antenna interface and S2/RFEN functionality with the button/transponder select (S2LC) configuration option (Table 2-2). 2.2.7.1 S2 BUTTON INPUT CONSIDERATIONS
The S2/RFEN/LC1 pin defaults to LF antenna output LC1 when the HCS412 is first connected to the supply voltage (i.e., battery replacement). The configuration register controlling the pin's function is loaded on the first device activation after battery replacement. A desired S2 input state is therefore enabled only after the first activation of either S0, S1 or LC0. The transponder bias circuitry switches off and the internal pull-down resistor is enabled when the S2/ RFEN/LC1 pin reaches button input configuration. There will be an extra delay the first activation after connecting to the supply voltage while the HCS412 retrieves the configuration word and configures the pins accordingly.
(c) 2002 Microchip Technology Inc.
Preliminary
DS41099C-page 7
HCS412
2.2.7.2 TRANSPONDER INTERFACE Connecting an LC resonant circuit between the LC0 and the LC1 pins creates the bi-directional low frequency communication path with the HCS412. The internal circuitry on the HCS412 provides the following functions: * LF input amplifier and envelope detector to detect and shape the incoming low frequency excitation signal. * 10V zener input protection from excessive antenna voltage generated when proximate to very strong magnetic fields. * LF antenna clamping transistors for inductive responses back to the transponder reader. The antenna ends are shorted together, `clamped', dissipating the oscillatory energy. The reader detects this as a momentary load on its excitation antenna. * Damping circuitry that improves communication when using high-Q LC antenna circuits. * Incoming LF energy rectification and regulation for the supply voltage in battery-less or low battery transponder instances. During normal transponder operation, the LC1 pin functions to bias the LC0 AGC amplifier input. The amplifier gain control sets the optimum level of amplification in respect to the incoming signal strength. The signal then passes through an envelope detector before interpretation in the logic circuit. 2.2.7.3 RF ENABLE OUTPUT
When the RF enable (RFEN) configuration option is enabled, the RFEN signal output is coordinated with the DATA output pin to provide typical ASK or FSK PLL activation.
TABLE 2-1:
RFEN 0 1
RFEN OPTION
Description RF Enable output is disabled. RF Enable output is enabled.
TABLE 2-2:
S2LC 0
S2/RFEN/LC1 CONFIGURATION OPTION
Resulting S2/RFEN/LC1 Configuration * LC1 low frequency antenna output driver for inductive responses and LC bias. Note: LC0 low frequency antenna input is also enabled. * S2 button input pin with Schmitt Trigger detector and internal pull-down resistor. * RFEN output driver. Note: LC0 and LC1 low frequency antenna interfaces are disabled and the transponder circuitry is switched off to reduce standby current.
1
3.0
3.1
3.1.1
ENCODER OPERATION
Encoder Activation
BUTTON ACTIVATION
3.1.2
PROXIMITY ACTIVATION
The main way to enter Encoder mode is when the wake-up circuit detects a button input activation; button input transition from GND to VDD. The HCS412 control logic wakes and delays a switch debounce time prior to sampling the button inputs. The button input states, cumulatively called the button status, determine whether the HCS412 transmits a code hopping or seed transmission, Table 3-1. Additional button activations added during a transmission will immediately RESET the HCS412, perhaps leaving the current code word incomplete. The device will start a new transmission which includes the updated button code value. Buttons removed during a transmission will have no effect unless no buttons remain activated. If no button activations remain, the minimum number of compete code words will be completed (Section 3.4.1) and the device will return to Standby mode.
The other way to enter Encoder mode is if the S2/LC option is configured for LC operation and the wake-up circuit detects a signal on the LC0 LF antenna input pin. This form of activation is called Proximity activation as a code hopping transmission would be initiated when the device was proximate to a LF field. Refer to Section 4.4 for details on configuring the HCS412 for Proximity Activation.
DS41099C-page 8
Preliminary
(c) 2002 Microchip Technology Inc.
HCS412
TABLE 3-1: ENCODER MODE ACTIVATION
SEED S1 0 1 1 S0 1 0 1 X X 0 0 1 1 X X X X 1 1 1 1 0 0 1 1 1 0 0 1 X X X 0 0 1 1 1 0 0 0 X X X 0 1 0 1 X X X 0 1 0 1 X Code hopping transmission Code hopping transmission Code hopping transmission Code hopping code words until time = TDSD, then seed code words. SEED transmissions temporarily enabled until the 7lsb's of the synchronization counter wrap 7Fh to 00h. Then only code hopping code words. Code hopping code words until time = TDSD, then seed code words. Code hopping transmission (2 key IFF enabled) Code hopping transmission Code hopping transmission Code hopping transmission Code hopping transmission Limited SEED transmissions - temporarily enabled until the 7lsb's of the synchronization counter wrap 7Fh to 00h. SEED transmission Code hopping transmission (2 key IFF enabled) Proximity activated code hopping transmission. TMPSD Resulting Transmission 4-Bit Button Status LC0 S2 (Note 1) X X X 0 0 0
Note 1: The transmitted button status will reflect the state of the LC0 input when the button inputs are sampled.
3.2
Transmitted Code Word
The HCS412 transmits a 69-bit code word in response to a button or proximity activation (Figure 3-1). Each code word contains a 50% duty cycle preamble, header, 32 bits of encrypted data and 37 bits of fixed code data followed by a guard period before another code word can begin. The 32 bits of Encrypted Data include 4 button bits, 2 counter overflow bits, 10 discrimination bits and the 16bit synchronization counter value (Figure 3-2).
The content of the 37 bits of Fixed Code Data varies with the extended serial number (XSER) option (Figure 3-2). * If the extended serial number option is disabled (XSER = 0), the 37 bits include 5 status bits, 4 button status bits and the 28-bit serial number. * If the extended serial number option is enabled (XSER = 1), the 37 bits include 5 status bits and the 32-bit serial number.
FIGURE 3-1:
CODE WORD FORMAT
50% Duty Cycle Preamble TP Header TH Encrypted Portion of Transmission THOP Fixed Portion of Transmission TFIX Guard Time TG
(c) 2002 Microchip Technology Inc.
Preliminary
DS41099C-page 9
HCS412
FIGURE 3-2: CODE WORD ORGANIZATION
28-bit Serial Number (XSER = 0)
Fixed Code Portion (37 Bits) QUE 2 Bits CRC 2 Bits VLOW 1-Bit BUT 4 Bits SER 1 12 MSb's SER 0 Least Sig16 Bits Hopping Code Portion Message (32 Bits) Counter BUT DISCRIM Overflow 4 Bits 10 Bits 2 Bits 15 S2 S1 S0 LC0 S2 S1 S0 LC0 OVR1 OVR0 Synchronization Counter 16 Bits 0
Q1 Q0 C1 C0
MSb
LSb 69 Data bits Transmitted LSb first.
32-bit Serial Number (XSER = 1)
Fixed Code Portion (37 Bits) QUE 2 Bits CRC 2 Bits VLOW 1-Bit SER 1 Most Sig 16 Bits SER 0 Least Sig 16 Bits
Hopping Code Portion Message (32 Bits) Counter DISCRIM BUT Overflow 10 Bits 4 Bits 2 Bits 15 S2 S1 S0 LC0 OVR1 OVR0 Synchronization Counter 16 Bits 0
Q1 Q0 C1 C0
MSb
Shaded data included in CRC calculation
LSb 69 Data bits Transmitted LSb first.
3.2.1
QUEUE COUNTER (QUE)
The QUE counter can be used to request secondary decoder functions using only a single transmitter button. Typically a decoder must keep track of incoming transmissions to determine when a double button press occurs, perhaps an unlock all doors request. The QUE counter removes this burden from the decoder by counting multiple button presses. The 2-bit QUE counter is incremented each time an active button input is released for at least the Debounce Time (TDBR), then reactivated (button pressed again) within the Queue Time (TQUE). The
counter increments up from 0 to a maximum of 3, returning to 0 only after a different button activation or after button activations spaced greater than the Queue Time (TQUE) apart. The current transmission aborts, after completing the minimum number of code words (Section 3.4.1), when the active button input is released. A button re-activation within Queue Time (TQUE) then initiates a new transmission (new synchronization counter, encrypted data) using the updated QUE value. Figure 3-3 shows the timing diagram to increment the queue counter value.
FIGURE 3-3:
QUE COUNTER TIMING DIAGRAM
1st Button Press All Buttons Released 2nd Button Press
Input Sx
Code Words Transmitted
QUE1:0 = 002 Synch CNT = X
QUE1:0 = 012 Synch CNT = X+1
t1 = 0
t1 > TDBP t2 = 0 TDBR < t < TQUE
DS41099C-page 10
Preliminary
(c) 2002 Microchip Technology Inc.
HCS412
3.2.2 CYCLE REDUNDANCY CHECK (CRC) 3.2.4 The CRC bits may be used to check the received data integrity, but it is not recommended when operating near the low voltage trip point, see Note below. The CRC is calculated on the 65 previously transmitted bits (Figure 3-2), detecting all single bit and 66% of all double bit errors. COUNTER OVERFLOW BITS (OVR1, OVR0)
The Counter Overflow Bits may be utilized to increase the synchronization counter range from the nominal 65,535 to 131,070 or 196,605. The bits must be programmed during production as `1's to be utilized. OVR0 is cleared the first time the synchronization counter wraps from FFFFh to 0000h. OVR1 is cleared the second time the synchronization counter wraps to zero. The two bits remain at `0' after all subsequent counter wraps. 3.2.5 EXTENDED SERIAL NUMBER (XSER)
EQUATION 3-1: and with
CRC CALCULATION
CRC [ 1 ] n + 1 = CRC [ 0 ]n Din
CRC [ 0 ] n + 1 = ( CRC [ 0 ] n Din ) CRC [ 1 ] n CRC [ 1, 0 ] 0 = 0
and Din the nth transmission bit 0 n 64 Note: The CRC may be wrong when the operating voltage is near VLOW trip point. VLOW is sampled twice each transmission, once for the CRC calculation (DATA output is LOW) and once when the VLOW bit is transmitted (DATA output is HIGH). VDD varying slightly during a transmission could lead to a different VLOW status transmitted than that used in the CRC calculation. Work around: If the CRC is incorrect, recalculate for the opposite value of VLOW. 3.2.3 LOW VOLTAGE DETECTOR STATUS (VLOW)
The Extended Serial Number option determines whether the serial number is 28 or 32 bits. When configured for a 28-bit serial number, the most significant nibble of the 32 bits reserved for the serial number is replaced with a copy of the 4-bit button status, Figure 3-2. 3.2.6 DISCRIMINATION VALUE (DISC)
The Discrimination Value is a 10-bit fixed value typically used by the decoder in a post-decryption check. It may be any value, but in a typical system it will be programmed as the 10 Least Significant bits of the serial number. The discrimination bits are part of the information that form the encrypted portion of the transmission (Figure 3-2). After the receiver has decrypted a transmission, the discrimination bits are checked against the receiver's stored value to verify that the decryption process was valid. If the discrimination value was programmed equal to the 10 LSb's of the serial number then it may merely be compared to the respective bits of the received serial number. 3.2.7 SEED CODE WORD DATA FORMAT
The low voltage detector result is included in every transmitted code word. The HCS412 samples the voltage detector output at the onset of a transmission and just before the VLOW bit is transmitted in each code word. The first sample is used in the CRC calculation and the subsequent samples determine what VLOW value will be transmitted. The transmitted VLOW status will be a `0' as long as VDD remains above the selected low voltage trip point. VLOW will change to a `1' if VDD drops below the selected low voltage trip point.
The Seed Code Word transmission allows for what is known as a secure learning function, increasing a system's security. The seed code word also consists of 69 bits, but the 32 bits of code hopping data and the 28 bits of fixed data are replaced by a 60-bit seed value that was stored during production (Figure 3-4). Instead of using the normal key generation inputs to create the crypt key, this seed value is used. Seed transmissions are either: * permanently enabled * permanently disabled * temporarily enabled (limited) until the 7 Least Significant bits of the synchronization counter wrap from 7Fh to 00h. The Seed Enable (SEED) and Temporary Seed Enable (TMPSD) configuration options control the function (Table 3-4).
TABLE 3-2:
VLOW 0 1
LOW VOLTAGE STATUS BIT
Description VDD is above trip voltage (VLOWSEL) VDD is below trip voltage (VLOWSEL)
TABLE 3-3:
LOW VOLTAGE TRIP POINT SELECTION OPTIONS
Nominal Trip Point 2.2V 4.4V Description for 3V battery applications for 6V battery applications
VLOWSEL 0 1
(c) 2002 Microchip Technology Inc.
Preliminary
DS41099C-page 11
HCS412
FIGURE 3-4:
QUE 2 Bits CRC 2 Bits
SEED CODE WORD DATA FORMAT
VLOW 1-Bit
BUT 4 Bits
SDVAL3 12 Most Sig Bits
SDVAL2 16 Bits
SDVAL1 16 Bits
SDVAL0 16 Least Sig Bits
Q1 Q0 C1 C0
MSb
S2 S1 S0 LC0
LSb 69 Data bits Transmitted LSb first.
Shaded data included in CRC calculation Note: SEED transmissions only allowed when appropriate configuration bits are set.
TABLE 3-4:
SEED 0 0 1 1
SEED TRANSMISSION OPTIONS
TMPSD 0 1 0 1 Description SEED transmissions permanently disabled Limited SEED transmissions (Note 1) - temporarily enabled until the 7 LSb's of the synchronization counter wrap from 7Fh to 00h SEED transmissions permanently enabled (Note 1) SEED transmissions permanently disabled (2 key IFF enabled)
Note 1: Refer to Table 3-1 for appropriate button activation of SEED transmissions.
3.3
Transmission Data Modulation
The data modulation format is selectable between Pulse Width Modulation (PWM) and Manchester using the Data Modulation (MOD) configuration option. Regardless of the modulation format, each code word contains a leading 50% duty cycle preamble and a synchronization header to wake the receiver and provide synchronization events for the receive routine. Each code word also contains a trailing guard time, separating code words. Manchester encoding further includes a leading and closing `1' around each 69-bit data block. The same code word repeats as long as the same input pins remain active, until a time-out occurs or a delayed seed transmission is activated.
The modulated data timing is typically referred to in multiples of a Basic Timing Element (RFTE). `RF' TE because the DATA pin output is typically sent through a RF transmitter to the decoder or transponder reader. RFTE may be selected using the Transmission Baud Rate (RFBSL) configuration option (Table 3-6).
TABLE 3-5:
Period Preamble Header Data Guard
TRANSMISSION MODULATION TIMING
PWM 31* 10 207 46 Manchester 31* 4 142 31 Units RFTE RFTE RFTE RFTE
* Enabling long preambles extends the first code word's preamble to TLPRE milliseconds.
TABLE 3-6:
RFBSL1:0 00b 01b 10b 11b
BAUD RATE SELECTION (RFBSL)
CWBE X 0 1 0 1 0 1 PWM RFTE 400 s 200 s 200 s 100 s 100 s 100 s 100 s Manchester RFTE 800 s 400 s 400 s 200 s 200 s 200 s 200 s Transmit... All code words All code words Every other code word All code words Every other code word All code word Every fourth code word
DS41099C-page 12
Preliminary
(c) 2002 Microchip Technology Inc.
HCS412
FIGURE 3-5: PWM TRANSMISSION FORMAT--MOD = 0
1 CODE WORD TOTAL TRANSMISSION: Preamble Sync Encrypt Fixed TE LOGIC "0" LOGIC "1" TE Guard TE Preamble Sync Encrypt
31 RFTE Preamble, 50% Duty Cycle Long Preamble (LPRE) disabled
10TE Header
Encrypted Portion
Fixed Code Portion
Guard Time
CODE WORD
FIGURE 3-6:
MANCHESTER TRANSMISSION FORMAT--MOD = 1
1 CODE WORD Preamble Sync Encrypt Fixed Guard Preamble Sync Encrypt
TOTAL TRANSMISSION:
TE
TE
LOGIC "0"
START bit bit 0 bit 1 bit 2
LOGIC "1"
STOP bit
50% Duty Preamble
Header
Encrypted Portion
CODE WORD
Fixed Code Portion
Guard Time
3.4
3.4.1
Encoder Special Features
CODE WORD COMPLETION AND MINIMUM CODE WORDS
3.4.2
AUTO-SHUTOFF
The code word completion feature ensures that entire code words are transmitted, even if the active button is released before the code word transmission is complete. If the button is held down beyond the time for one code word, multiple complete code words will result. The device default is that a momentary button press will transmit at least one complete code word. Enable the Minimum Four Code Words (MTX4) configuration option to extend this feature such that a minimum of 4 code words are completed on a momentary button activation.
The Auto-shutoff function prevents battery drain should a button get stuck for a long period of time. The time period (TTO) is approximately 20 seconds, after which the device will enter Time-out mode. The device will stop transmitting in Time-out mode but there will be leakage across the stuck button input's internal pull-down resistor. The current draw will therefore be higher than when in Standby mode. 3.4.3 CODE WORD BLANKING ENABLE
Federal Communications Commission (FCC) part 15 rules specify the limits on worst case average fundamental power and harmonics that can be transmitted in a 100 ms window. For FCC approval purposes, it may therefore be advantageous to minimize the transmission duty cycle. This can be achieved by minimizing the on-time of the individual bits as well as by blanking out consecutive code words.
(c) 2002 Microchip Technology Inc.
Preliminary
DS41099C-page 13
HCS412
The Code Word Blanking Enable (CWBE) option may be used to reduce the average power of a transmission by transmitting only every second or every fourth code word (Figure 3-7). This selectable feature is determined in conjunction with the baud rate selection bit RFBSL (Table 3-7). Enabling the CWBE option may similarly allow the user to transmit a higher amplitude transmission as the time averaged power is reduced. CWBE effectively halves the RF on-time for a given transmission so the RF output power could theoretically be doubled while maintaining the same time averaged output power.
FIGURE 3-7:
CODE WORD BLANKING
Code Word Code Word Code Word Code Word Code Word Code Word Code Word Code Word Code Word Code Word Code Word Code Word
RF Output Amplitude = A CWBE Disabled (All words transmitted) CWBE Enabled (1 out of 2 transmitted) A 2A
CWBE Enabled (1 out of 4 transmitted)
4A
Code Word
Code Word
TABLE 3-7:
RFBSL1:0 00b 01b 10b 11b
CODE WORD BLANKING ENABLE (CWBE)
CWBE X 0 1 0 1 0 1 PWM RFTE 400 s 200 s 200 s 100 s 100 s 100 s 100 s Manchester RFTE 800 s 400 s 400 s 200 s 200 s 200 s 200 s Transmit... All code words All code words Every other code word All code words Every other code word All code word Every fourth code word The PLL Interface (AFSK) configuration option controls the output as shown in Figure 3-8.
3.4.4
DELAYED INCREMENT (DINC)
The HCS412's Delayed Increment feature advances the synchronization counter by 12 a period of TTO after the encoder activation occurs, for additional security. The next activation will show a synchronization counter increase of 13, not 1. If the active button is released before the time-out TTO has elapsed, the device stops transmitting but remains powered for the duration of the time-out period. The device will then advance the stored synchronization counter by 12 before powering down. If the active button is released before the time-out TTO has elapsed and another activation occurs while waiting out the time-out period, the time-out counter will RESET and the resulting transmission will contain synchronization counter value +1. Note: If delayed increment is enabled, the QUE counter will not reset to 0 until timeout TTO has elapsed. 3.4.5 PLL INTERFACE
TABLE 3-8:
AFSK 0 1 3.4.6
PLL INTERFACE(AFSK)
Description ASK PLL Setup FSK PLL Setup
LED OUTPUT
During normal operation (good battery), while transmitting data the device's LED pin will periodically be driven low as indicated in Figure 3-9. If the supply voltage drops below the trip point specified by VLDWSEL, the LED pin will be driven low only once for a longer period of time. 3.4.7 LONG PREAMBLE (LPRE)
If the RFEN/S2/LC1 pin is configured as an RF enable output, the pin's behavior is coordinated with the DATA pin to enable a typical PLL's ASK or FSK mode.
Enabling the Long Preamble configuration option extends the first code word's 50% duty cycle preamble to a `long' preamble time TLPRE. The longer preamble will be a square wave at the selected RFTE (Figure 3-10).
DS41099C-page 14
Preliminary
(c) 2002 Microchip Technology Inc.
HCS412
FIGURE 3-8: RF ENABLE/ASK/FSK OPTIONS
AFSK = 0, RFEN = 1
SWITCH S2/RFEN/LC1 DATA
Code Word
TTD TLEDON
Code Word
Code Word
AFSK = 1, RFEN = 0
SWITCH S2/RFEN/LC1 DATA Code Word Code Word Code Word
FIGURE 3-9:
LED OPERATION
NORMAL OPERATION
SWITCH DATA LED
TLEDON TLEDOFF
Code Word
Code Word
Code Word
LOW VOLTAGE OPERATION
SWITCH Code Word DATA LED
TLEDL
Code Word
Code Word
FIGURE 3-10: LONG PREAMBLE ENABLED (LPRE)
First Code Word
TLPRE
Header
Consecutive Code Words First Code Word - Long Preamble
Second Code Word - Normal Preamble
Third Code Word - Normal Preamble
(c) 2002 Microchip Technology Inc.
Preliminary
DS41099C-page 15
HCS412
3.4.8 QLVS FEATURES Setting the HCS412's special QLVS (`Quick Secure Learning') configuration option enables the following options: * Reduces the time (TDSD) before a delayed seed transmission begins. * Disables DATA modulation when the LED pin is driven low (Figure 3-11). - If the PLL Interface option is set to ASK, the DATA pin will go low while the LED pin is low. - If the PLL Interface option is set to FSK, the DATA pin will go high and the RFEN output will go low while the LED pin is low. If the battery is low, the HCS412 transmits only until the LED goes on. * If the Temporary Seed (TMPSD) option is enabled, seed transmission capability can be disabled by applying the button sequence shown in Figure 3-12
FIGURE 3-11: LED, DATA, RFEN INTERACTION WHEN QLVS IS SET
QLVS = 1, RFEN = 1
SWITCH LED
TTD TLEDON
AFSK = 0 (ASK)
S2/RFEN/LC1 DATA
AFSK = 1 (FSK)
S2/RFEN/LC1 DATA
FIGURE 3-12: SEED DISABLE WAVEFORM
50 ms S0, S1 50 ms
1200 ms
DS41099C-page 16
Preliminary
(c) 2002 Microchip Technology Inc.
HCS412
TABLE 3-9: ENCODER TIMING SPECIFICATIONS
VDD = +2.0 to 6.6V Commercial (C):TAMB = 0C to +70C Industrial (I): TAMB = -40C to +85C Parameter Time to second button press Transmit delay from button detect Debounce delay on button press Debounce delay on button release Auto-shutoff time-out period Long preamble LED on time LED off time LED on time (VDD < VLOW Trip Point) Time to delayed SEED transmission Queue Time Symbol TBP TTD TDBP TDBR TTO TLPRE TLEDON TLEDOFF TLEDL TDSD TQUE 18 Min. 44 + Code Word Time 20 14 Typ. 58 + Code Word Time 30 20 20 20 64 32 480 200 3 30 22 Max. 63 + Code Word Time 40 26 Unit ms ms ms ms s ms ms ms ms s ms Note 4 Note 4 Note 5 Note 3 Remarks Note 1 Note 2
Note 1: TBP is the time in which a second button can be pressed without completion of the first code word where the intention was to press the combination of buttons. 2: Transmit delay maximum value, if the previous transmission was successfully transmitted. 3: The auto-shutoff time-out period is not tested. 4: The LED times specified for VDD > VTRIP specified by VLOW in the configuration word. 5: LED on time if VDD < VTRIP specified by VLOW in the configuration word.
(c) 2002 Microchip Technology Inc.
Preliminary
DS41099C-page 17
HCS412
4.0
4.1
TRANSPONDER OPERATION
IFF Mode
* RF responses on the DATA pin modulate according to standard encoder transmissions (Figure 3-5, Figure 3-6). Communication with the HCS412 over the low frequency path (LC pins) uses a basic Timing Element, LFTE. The Low Frequency Baud Rate Select option, LFBSL, sets LFTE to either 100 s or 200 s (Table 4-1). The response on the DATA pin uses the Encoder mode's RF Timing Element (RFTE) and the modulation format set by the MOD configuration option (Table 3-6). The RF responses use the standard Encoder mode format with the 32-bit hopping portion replaced by the response data (Figure 4-19). If the response is only 16 bits, the 32 bits will contain 2 copies of the response (Figure 4-16).
The HCS412's IFF Mode allows it to function as a bidirectional token or transponder. IFF mode capabilities include the following. * A bi-directional challenge and response sequence for IFF validation. HCS412 IFF responses may be directed to use one of two available encryption algorithms and one of two available crypt keys. * Read selected EEPROM areas. * Write selected EEPROM areas. * Request a code hopping transmission. * Proximity Activation of a code hopping transmission.
4.2
IFF Communication
TABLE 4-1:
LFBSL 0 1 4.2.1
LOW FREQUENCY BAUD RATE SELECT BITS
LFTE 200 s 100 s
The transponder reader initiates each communication by turning on the low frequency field, then waits for a HCS412 to Acknowledge the field. The HCS412 enters IFF mode upon detecting a signal on the LC0 LF antenna input pin. Once the incoming signal has remained high for at least the power-up time TPU, the device responds with a field Acknowledge sequence indicating that the it has detected the LF field, is in IFF Mode and is ready to receive commands (Figure 4-1). The HCS412 will repeat the field Acknowledge sequence every 255 LFTE`s if the field remains but no command is received (Figure 4-1). The transponder reader follows the HCS412's field Acknowledge by sending the desired 5-bit command and associated data. LF commands are always preceded by a 2 LFTE low START pulse and are Pulse Position Modulated (PPM) as shown in Figure 4-2. The last command or data bit should be followed by leaving the field on for a minimum of 6 LFTE. HCS412 PPM data responses are preceded by a 1 LFTE low pulse, followed by a 01b preamble before the data begins (Figure 4-4). The responses are sent either on the LC antenna output alone or on both the LC output and the DATA pin, depending on the device configuration (Section 4.4.2). This allows for short-range LF responses as well as long-range RF responses. Data to and from the HCS412 is always sent Least Significant bit first. The data length and modulation format vary according to the command and the transmission path. Data Length and Commands: * Read and Write transfers 16 bits of data. * Challenge and Response transfers 32 bits of data. Modulation Format and Transmission Path: * LF responses on the LC output are Pulse Position Modulated (PPM) according to Figure 4-2.
CALCULATING COMMUNICATION TE
The HCS412's internal oscillator will vary 10% over the device's rated voltage and temperature range. When the oscillator varies, both its transmitted TE and expected TE when receiving will vary. Communication reliability with the token may be improved by calculating the HCS412's TE from the field Acknowledge sequence and using this measured time element in communication to and in reception routines from the token. Always begin and end the time measurement on rising edges. Whether LF or RF, the falling edge decay rates may vary but the rising edge relationships should remain consistent. A common TE calculation method would be to time an 8 TE sequence, then divide the value down to determine the single TE value. An 8 TE measurement will give good resolution and may be easily right-shifted (divide by 2) three times for the math portion of the calculation (Figure 4-1). Accurately measuring TE is important for communicating to an HCS412 as well as for inductive programming a device. The configuration word sent during programming contains the 4-bit oscillator tuning value. Accurately determining TE allows the programmer to calculate the correct oscillator tuning bits to place in the configuration word, whether the device oscillator needs to be sped up or slowed down to meet its desired TE.
DS41099C-page 18
Preliminary
(c) 2002 Microchip Technology Inc.
HCS412
FIGURE 4-1: FIELD ACKNOWLEDGE SEQUENCE
3LFTE TPU Inductive Comms (LC) 8LFTE RF Comms (DATA) 8LFTE 3LFTE 3LFTE TATO 2LFTE Command
Field Ack sequence repeats every 255 LFTE if no command is received. Inductive Comms (LC) 255LFTE RF Comms (DATA)
Communication from reader to HCS412 Filed ACK Sequence from HCS412 to reader
255LFTE
FIGURE 4-2:
LC PIN PULSE POSITION MODULATION (PPM)
Transponder reader communication to the HCS412
0
2 LFTE 2 LFTE Extending the high time is acceptable but the low time should minimally be 1 LFTE. The HCS412 determines bit values from rising edge to rising edge times.
1
Start or previous bit 4 LFTE TBITC 2 LFTE
TBITC
HCS412 response back to the reader
0
LFTE LFTE TBITR
1
2 LFTE LFTE TBITR
Start or previous bit
(c) 2002 Microchip Technology Inc.
Preliminary
DS41099C-page 19
HCS412
4.3 IFF Commands LIST OF AVAILABLE IFF COMMANDS
Command
TABLE 4-2:
Opcode
Anticollision Command (Section 4.3.1) 00000 Read Commands (Section 4.3.2) 00001 00010 00011 00100 00101 00110 00111 Program Command (Section 4.3.5) 01000 Write Commands (Section 4.3.3) 01001 01010 01011 01100 01101 01110 01111 Write configuration word Write low serial number (least significant 16 bits) Write high serial number (most significant 16 bits) Write user EEPROM 0 Write user EEPROM 1 Write user EEPROM 2 Write user EEPROM 3 Program HCS412 EEPROM Read configuration word Read low serial number (least significant 16 bits) Read high serial number (most significant 16 bits) Read user EEPROM 0 Read user EEPROM 1 Read user EEPROM 2 Read user EEPROM 3 Select HCS412, used if Anticollision enabled
Challenge and Response Commands (Section 4.3.6) 10000 10001 10100 10101 Challenge and Response using key-1 and IFF algorithm Challenge and Response using key-1 and HOP algorithm Challenge and Response using key-2 and IFF algorithm Challenge and Response using key-2 and HOP algorithm
Request Hopping Code Command (Section 4.3.7) 11000 Default IFF Command (Section 4.3.8) 11100 Enable default IFF communication Request Hopping Code transmission
DS41099C-page 20
Preliminary
(c) 2002 Microchip Technology Inc.
HCS412
4.3.1 ANTICOLLISION Multiple tokens in the same inductive field will simultaneously respond to inductive commands. The responses will collide making token authentication impossible. Enabling anticollision allows addressing of an individual token, regardless how many tokens are in the field. The HCS412 method is that all tokens trained to a given vehicle will have the same 25 MSb's of their serial number. The serial numbers of up to 8 tokens trained to access a given vehicle will differ only in the 3 LSb's. Think of the 25 MSb's of the HCS412's serial number as the vehicle ID and the 3 LSb's as the token ID. The vehicle ID associates the token with a given vehicle and the token ID makes it a uniquely addressable (selectable) 1 of 8 possible tokens authorized to access the vehicle. The transponder reader addresses an individual token, HCS412, by sending a `SELECT ENCODER' command. The command is followed by from 1 to 25 bits of the HCS412's serial number, starting with bit 3 (Least Significant bit first) (Figure 4-3). Clocking out `1's then increments the 3 LSb's, the first `1' setting the bits to 000b. When the value matches the 3 LSb's of a token, the token responds with an Encoder Select Acknowledge. The reader must halt clocking out further `1's or risk selecting multiple tokens. Any remaining tokens in the field will be unselected, responding only if a new device selection sequence selects them. Removing the field will also RESET a selected/unselected state if removed long enough to result in a device RESET. The ability to isolate a single HCS412 for communication greatly depends on the number of Most Significant serial number bits included in the device selection sequence. The more serial number bits sent, the more narrow the device selection. All bits not transmitted are treated as wildcards. Sending only 1 bit, bit 3 as a `0', will only narrow the number of tokens allowed to respond to all with bit 3 equal to `0'. When the transponder reader sends the full 25 MSb's of the serial number, it narrows all possible tokens down to only those trained to the vehicle - only those tokens whose serial number's 25 MSb's match.
TABLE 4-3:
Command 00000
DEVICE SELECT COMMAND
Description Select HCS412, used if Anticollision enabled Expected data In The desired HCS412's serial number Response Encoder select Acknowledge if serial number match
FIGURE 4-3:
Activate Field
ANTICOLLISION - DEVICE SELECTION
ACK Delay to Command Command Delay to Serial Most Sig X Bits of Serial Number Delay Clock Serial 3 LSb's ACK
TOTD 0 0 0 0 0
1 to 25 bits of the Serial Number, starting with Bit 3.
2ms `1' `1'
4th `1' interrupted by ACK, indicating selection @ LSb = 011b
000b 001b 010b 011b
`1'
MSb
RF Comms
2 LFTE Start
2 LFTE Start
:
Command
Bit X
Bit 3
Bit 4
Bit 5
LSb
Inductive Comms
2 LFTE Start
TESA
Communication from reader to HCS412 Communication from HCS412 to reader
1 to 25 bits of the Serial Number, starting with Bit 3.
Encoder Select ACK Send `1's to increment 3LSb's
28-bit Serial Number
(c) 2002 Microchip Technology Inc.
Bit 27 Bit 26 Bit 25 Bit 24 Bit 23 Bit 22 Bit 21 Bit 20 Bit 19 Bit 18 Bit 17 Bit 16 Bit 15 Bit 14 Bit 13 Bit 12 Bit 11 Bit 10 Bit 9 Bit 8 Bit 7 Bit 6 Bit 5 Bit 4 Bit 3 Bit 2 Bit 1 Bit 0
Preliminary
DS41099C-page 21
`1'
HCS412
4.3.2 READ The following locations are available to read: * The 64-bit general purpose user EEPROM. (USER[3:0]). * The 32-bit serial number (SER[1:0]). The serial number is also transmitted in each code hopping transmission. * The16-bit Configuration word containing all nonsecurity related options. The transponder reader sends one of seven possible read commands indicating which 16-bit EEPROM word to retrieve (Table 4-4). The HCS412 retrieves the data and returns the 16-bit response. Each Read response is preceded by a 1LFTE low START pulse and `01b' preamble (Figure 4-4).
TABLE 4-4:
Command 00001 00010 00011 00100 00101 00110 00111
LIST OF READ COMMANDS
Description Read Configuration word Read low serial number Read high serial number Read user EEPROM 0 Read user EEPROM 1 Read user EEPROM 2 Read user EEPROM 3 Expected data In None None None None None None None Response 16-bit Configuration word Lower 16 bits of serial number (SER0) Higher 16 bits of serial number (SER1) 16 Bits of User EEPROM USR0 16 Bits of User EEPROM USR1 16 Bits of User EEPROM USR2 16 Bits of User EEPROM USR3
FIGURE 4-4:
READ
Activate Field ACK Delay to Command
TATO bit0 bit1 TPU bit2 0 0
Command
Delay until Response
TRT
16-bit Response
01b Preamble 01 6 LFTE
MSb
ACK
Command
Communication from reader to HCS412 Communication from HCS412 to reader
2 LFTE Start
1 LFTE Start
16-bit Response
4.3.3
WRITE
The transponder reader sends one of seven possible write commands (Table 4-5) indicating which 16-bit EEPROM word to write to. The 16-bit data to be written follows the command. The HCS412 will attempt to write the value into EEPROM and respond with an Acknowledge sequence if successful. The following locations are available to write: * The 64-bit general purpose user EEPROM. (USER[3:0]) (Figure 4-6). * The 32-bit serial number (SER[1:0]). The serial number is also transmitted in each code hopping transmission (Figure 4-5). * The16-bit Configuration word containing all nonsecurity related configuration options. If the configuration is written, the device must be RESET before the new settings take effect (Figure 4-5).
A Transport Code, write access password, protects the serial number and configuration word from undesired modification. For these locations the reader must follow the WRITE command with the appropriate 28-bit transport code, then the 16 bits of data to write. Only a correct match with the transport code programmed during production will allow write access to the serial number and configuration word (Figure 4-5). The delay to a successful write Acknowledge will vary depending on the number of bits changed.
DS41099C-page 22
Preliminary
(c) 2002 Microchip Technology Inc.
MSb
LSb
LSb
HCS412
TABLE 4-5:
Command 01001 01010 01011 01100 01101 01110 01111
LIST OF WRITE COMMANDS
Description Write Configuration word Write low serial number Write high serial number Write user EEPROM 0 Write user EEPROM 1 Write user EEPROM 2 Write user EEPROM 3 Expected data In 28-bit Transport code; 16-Bit configuration word 28-bit Transport code; Least Significant 16 bits of the serial number (SER0) 28-bit Transport code; Most Significant 16 bits of the serial number (SER1) 16 Bit User EEPROM USR0 16 Bit User EEPROM USR1 16 Bit User EEPROM USR2 16 Bit User EEPROM USR3 Response if Write is Successful Write Acknowledge pulse Write Acknowledge pulse Write Acknowledge pulse Write Acknowledge pulse Write Acknowledge pulse Write Acknowledge pulse Write Acknowledge pulse
FIGURE 4-5:
Activate Field
WRITE TO SERIAL NUMBER OR CONFIGURATION
ACK Delay to Command Command Delay to TCODE
TOTD bit0 bit1 TATO 0 1
28-bit Transport Code
Delay to Data
TTTD
16 bits Data
Delay before Write Write ACK ACK
TWR
TPU
MSb
0
MSb
ACK 2 LFTE Start
Command
MSb
LSb
LSb
LSb
2 LFTE Start
28-bit Transport Code 2 LFTE Start
16 Data Bits
Write Delay
ACK
Communication from reader to HCS412 Communication from HCS412 to reader
FIGURE 4-6:
Activate Field
WRITE TO USER AREA
ACK Delay to Command Command Delay to Data
TOTD bit0 bit1 1 1 0
16 bits Data
Delay before Write Write ACK ACK
TWR
TATO TPU
MSb
ACK 2 LFTE Start
Command
16 Data Bits
MSb
LSb
LSb
Write Delay
ACK
Communication from reader to HCS412 Communication from HCS412 to reader
2 LFTE Start
(c) 2002 Microchip Technology Inc.
Preliminary
DS41099C-page 23
HCS412
4.3.4 BULK ERASE A Bulk Erase resets the HCS412's memory map to all zeros. The transponder reader selects the appropriate device through anticollision, as need be, issues the PROGRAM command followed by the device's 28-bit transport code, then resets the device by removing the field for 100 ms. Resetting the device after the PROGRAM command results in a bulk erase, resetting the EEPROM memory map to all zeros. This is important to remember as the reader must now communicate to the device using the communication options resulting from a zero'd configuration word - baud rates, modulation format, etc. (Table 5-1).
FIGURE 4-7:
BULK ERASE
ACK Delay to Command Command Delay to TCODE
TOTD 0 0 0 1 TPU 0 TATO
Activate Field
28-bit Transport Code
Delay
6ms
Device Reset
100ms
MSb
ACK 2 LFTE Start
Program Command
Communication from reader to HCS412 Communication from HCS412 to reader
2 LFTE Start
28-bit Transport Code
4.3.5
PROGRAM
Inductive programming a HCS412 begins with a bulk erase sequence (Section 4.3.4), followed by issuing the PROGRAM command and the desired EEPROM memory map's 18x16-bit words (Section 5.0). The HCS412 will send a write Acknowledge after each word has been successfully written, indicating the device is ready to receive the next 16-bit word. After a complete 18 word memory map has been received and written, the HCS412 PPM modulates 18 bursts of 16-bit words on the LC pins for write verifica-
tion. Each word follows the standard HCS412 response format with a leading 1LFTE low START pulse and `01b' preamble (Figure 4-10). Since the bulk erase resets the configuration options to all zeros, the oscillator tuning value will also be cleared. The correct tuning value is required when the programming sequence sends the new configuration word. The value may either be obtained by reading the configuration word prior to bulk erase to extract the value or by determining TE from the field Acknowledge sequence and calculating the tuning value appropriately (Section 4.2.1).
TABLE 4-6:
Command 01000
PROGRAM COMMANDS
Description Program HCS412 EEPROM Expected data In Transport code (28 bits); Complete memory map: 18 x 16-bit words (288 bits) Response Write Acknowledge pulse after each 16-bit word, 288 bits transmitted in 18 bursts of 16-bit words
FIGURE 4-8:
PROGRAM SEQUENCE - FIRST WORD
ACK Delay to Command Command Delay to TCODE
TOTD 0 0 0 1 TPU 0 TATO
Activate Field
28-bit Transport Code
MSb
LSb
LSb
Delay to Data
TTTD
16 bits Data
Delay before Write Write ACK ACK
TWR
MSb
MSb
ACK 2 LFTE Start
MSb
Program Command
LSb
LSb
LSb
2 LFTE Start
28-bit Transport Code
16 Data Bits
Write Delay
ACK
2 LFTE Start Repeat 18 times for programming
Communication from reader to HCS412 Communication from HCS412 to reader
DS41099C-page 24
Preliminary
(c) 2002 Microchip Technology Inc.
HCS412
FIGURE 4-9: PROGRAM SEQUENCE - CONSECUTIVE WORDS
16-bit Word 1 KEY1_1, KEY1_0 16-bit Word 2 KEY1_3, KEY1_2 16-bit Word 18 Reserved (all 0's) Successful Write Acknowledge Successful Write Acknowledge Successful Write Acknowledge Successful Write Acknowledge
Start Verify MSb Reserved LSb Reserved 1LFTE Start + `01b' + 16-bit Word 17 CNT1, CNT0
MSb CNT1 LSb Reserved MSb Reserved
16-bit Word 17 CNT1, CNT0
Write 18x16-bit words total.
Program Command
Transport Code
ACK
MSb KEY1_1
Communication from reader to HCS412 Communication from HCS412 to reader
FIGURE 4-10: PROGRAMMING - VERIFICATION
01b Preamble 0 1
MSb KEY1_3
LSb KEY1_0
LSb KEY1_2
1 LFTE Start
16-bit Word 1 KEY1_1, KEY1_0
16-bit Response
16-bit Word 18 All Zeros Successful Write Acknowledge
MSb
LSb
3LFTE Delay between each 16-bit word
1LFTE Start + `01b' + 16-bit Word 2 KEY1_3, KEY1_2
MSb CNT1
LSb CNT0
Successful Write Acknowledge
Transport Code
Program Command
LSb KEY1_0
LSb KEY1_2
MSb KEY1_1
MSb KEY1_3
LSb KEY1_4
MSb KEY1_5
1LFTE Start + `01b' + 16-bit Word 2 KEY1_5, KEY1_4
1LFTE Start + `01b' + 16-bit Word 1 KEY1_1, KEY1_0
Write 18x16-bit words total.
Communication from reader to HCS412 Communication from HCS412 to reader
Approximately 1ms delay before verify begins.
Verify 18x16-bit words total.
4.3.6
IFF CHALLENGE AND RESPONSE
The transponder reader sends one of four possible IFF commands indicating which crypt key and which algorithm to use to encrypt the challenge (Table 4-7). The command is followed by the 32-bit challenge, typically a random number. The HCS412 encrypts the challenge using the designated crypt key and algorithm and responds with the 32-bit encrypted result. The reader authenticates the response by comparing it to the expected value.
The second crypt key and the seed value occupy the same EEPROM storage area. To use the second crypt key for IFF, the Seed Enable (SEED) and the Temporary Seed Enable (TMPSD) configuration options must be disabled. Note: If seed transmissions are not appropriately disabled, the HCS412 will default to using KEY1 for IFF.
TABLE 4-7:
Command 10000 10001 10100 10101
CHALLENGE AND RESPONSE COMMANDS
Description IFF using key-1 and IFF algorithm IFF using key-1 and HOP algorithm IFF using key-2 and IFF algorithm IFF using key-2 and HOP algorithm Expected data In 32-Bit Challenge 32-Bit Challenge 32-Bit Challenge 32-Bit Challenge Response 32-Bit Response 32-Bit Response 32-Bit Response 32-Bit Response
(c) 2002 Microchip Technology Inc.
Preliminary
LSb CNT0
1LFTE Start + `01b' + 16-bit Word 18 Reserved (all 0's)
ACK
DS41099C-page 25
HCS412
FIGURE 4-11: IFF CHALLENGE AND RESPONSE
Activate Field ACK Delay to Command Command Delay to Data
TOTD bit0 bit1 bit2 TATO 0
32-bit Challenge
Delay before Response
TIT
32-bit Response
01b Preamble 1 01
TPU
MSb
MSb
ACK 2 LFTE Start
Command
32-bit Challenge
2 LFTE Start
1 LFTE Start
32-bit Response
Communication from reader to HCS412 Communication from HCS412 to reader
4.3.7
CODE HOPPING REQUEST
The command tells the HCS412 to increment the synchronization counter and build the 32-bit code hopping portion of the code word. * If RF Echo is disabled, the data will be transmitted on the LC lines only (Figure 4-12).
* If RF Echo is enabled, the data will be transmitted in a code word on the DATA line followed by the data transmitted on the LC lines. The DATA line is transmitted first for passive entry support (Figure 4-13). The data format will be the same as described in Section 3.2.
TABLE 4-8:
Command 11000
REQUEST HOPPING CODE COMMANDS
Description Request Hopping Code transmission Expected data In None Response 32-Bit Hopping Code
FIGURE 4-12: CODE HOPPING REQUEST (RF ECHO DISABLED)
Activate Field ACK Delay to Command Command Delay before Response 32-bit Response
TATO 1
TOTH
0 0 0 1 01
01b Preamble
TPU
MSb
ACK
Command
2 LFTE Start
1 LFTE Start
32-Bit PPM Response
Communication from reader to HCS412 Communication from HCS412 to reader
FIGURE 4-13: CODE HOPPING REQUEST (RF ECHO ENABLED)
Opcode (Request Hop Code)
Field ACK Inductive (LF) 32-Bit PPM Response Field ACK
MSb
LSb
LSb
DATA (RF)
MSb
LF Communication from reader to HCS412 LF Communication from HCS412 to reader
DS41099C-page 26
Preliminary
(c) 2002 Microchip Technology Inc.
Fixed Code (37 bits)
Preamble
Header
Hop Code (32 bits)
MSb
LSb
LSb
MSb
LSb
LSb
LSb
HCS412
4.3.8 ENABLE DEFAULT IFF COMMUNICATION Default IFF communication settings: * Anticollision disabled * RF echo disabled * 200 s LF baud rate. The ENABLE DEFAULT IFF COMMUNICATION command defaults certain HCS412 communication options such that the transponder reader may communicate to the device with a common (safe) protocol. The default setting remains for the duration of the communication, returning to normal only after a device RESET.
TABLE 4-9:
Command 11100
DEFAULT IFF COMMUNICATION COMMANDS
Description Enable default IFF communication Expected data In None Response None
FIGURE 4-14: ENABLE DEFAULT IFF COMMUNICATION
Activate Field ACK Delay to Command
TATO 0 1 1 0 1
Command
Delay
Next Command
ACK pulses
Inductive Comms 2 LFTE Start RF Comms Command
MSb LSb
Communication from reader to HCS412 Communication from HCS412 to reader
4.4
IFF Communication Special Features LF COMMUNICATION SPECIAL FEATURES (LFSP)
Description No special options enabled Anticollision enabled (Section 4.3.1) Proximity Activation enabled Anticollision and RF Echo enabled PASSIVE PROXIMITY ACTIVATION (LFSP = 10)
TABLE 4-10:
LFSP1:0 00 01 10 11 4.4.1
The HCS412 sends out Field Acknowledge Sequence in response to detecting the LF field (Figure 4-1). If the HCS412 does not receive a command before the second field Acknowledge sequence [within 255 LFTE`s], it will transmit a normal code hopping transmission for 2 seconds on the DATA pin. After 2 seconds the HCS412 reverts to normal transponder mode. The 2 second transmission does not repeat when the device is in the presence of a continuous LF field. The HCS412 must be RESET, remove and reapply the LF field, to activate another transmission. The button status used in the code hopping transmission indicates a proximity activation by clearing the S0, S1 and S2 button activation flags.
Enabling the Proximity Activation configuration option allows the HCS412 to transmit a hopping code transmission in response to a signal present on the LC0 pin.
FIGURE 4-15: PROXIMITY ACTIVATION
No command received from reader for 255 LFTE. Inductive (LF)
ACK
DATA (RF) LF Communication from reader to HCS412 LF Communication from HCS412 to reader
Transmit hopping code for 2 seconds
(c) 2002 Microchip Technology Inc.
Preliminary
DS41099C-page 27
HCS412
4.4.2 ANTICOLLISION AND RF ECHO (LFSP = 11) LF communication from the token to the transponder reader has much less range than LF communication from the reader to the token. Transmitting the information on the DATA line increases communication range by enabling longer range RF talk back. The information is sent on the DATA line first to benefit longer range passive-entry authentication times.
In addition to enabling anticollision, this mode adds that all HCS412 responses and Acknowledges are echoed on the DATA output line. Responses are first transmitted on the DATA line, followed by the equivalent data transmitted on the LF LC lines (Figure 4-16, Figure 4-17).
FIGURE 4-16: RF ECHO OPTION AND READ COMMAND
Command (Read) Response (16 bits)
TATO TPU TOTH
32-Bit Response 16-Bit Response 16-Bit Response
Inductive (LF)
MSb
DATA (RF)
Preamble
LF Communication from reader to HCS412 LF Communication from HCS412 to reader
FIGURE 4-17: RF ECHO OPTION AND IFF COMMAND
Response (32 bits) Next ACK
MSb
Inductive (LF)
Opcode (IFF)
Fixed Code (37 bits)
Response (32 bits)
Header
DATA (RF)
MSb
LSb
LF Communication from reader to HCS412 LF Communication from HCS412 to reader
FIGURE 4-18: RF ECHO OPTION AND REQUEST HOPPING CODE COMMAND
Field ACK TATO Request Hopping Code Opcode TOTH 32-Bit PPM Response
Fixed Code (37 bits)
Preamble
Response (32 bits)
Header
LSb
MSb
LSb
LSb
ACK
Next Field Ack
Inductive (LF) DATA (RF)
MSb
Preamble
LF Communication from reader to HCS412 LF Communication from HCS412 to reader
DS41099C-page 28
Preliminary
(c) 2002 Microchip Technology Inc.
Fixed Code (37 bits)
Header
Hop Code (32 bits)
MSb
LSb
LSb
Next ACK
HCS412
4.4.3 INTELLIGENT DAMPING (IDAMP)
FIGURE 4-19: INTELLIGENT DAMPING
A high Q-factor LC antenna circuit connected to the HCS412 will continue to resonate after a strong LF field is removed, slowly decaying. The slow decay makes fast communication near the reader difficult as data bit low times disappear. If the Intelligent Damping option is enabled, the HCS412 will clamp the LC pins through a 2 k resistor for 5 s every 1/4 LFTE, whenever the HCS412 is expecting data from the transponder reader. The intelligent damping pulses start 12.5 LFTE after the Acknowledge sequence is complete and continue for 12.5 LFTE. If the HCS412 detects data from the reader while sending out damping pulses, it will continue to send the damping pulses.
5 s
1/4 LFTE
5 s
Field ACK
12.5 LFTE
12.5 LFTE
Bit From reader
TABLE 4-11:
IDAMP 0 1
INTELLIGENT DAMPING (IDAMP)
Description Intelligent damping enabled Intelligent damping disabled
DAMP PULSES
TABLE 4-12:
Time Element Power-up Time
LF TIMING SPECIFICATIONS
Parameter IFFB = 0 IFFB = 1 Symbol LFTE TPU TATO Data = 0 Data = 1 Data = 0 Data = 1 TBITC TBITR TRT TIT TOTD TTTD TESA TWR TOTH Min. 180 90 4.2 13 -- -- -- -- -- 3.87 2.6 2.2 -- -- 10.26 4 6 2 3 13 4.3 -- -- LFTE+100 30 11.4 -- -- -- -- -- 4.73 -- -- -- -- 12.54 Typ. 200 100 6 Max. 220 110 7.8 Units s ms LFTE LFTE LFTE LFTE ms ms ms s ms ms
Acknowledge to Opcode Time PPM Command Bit Time PPM Response Bit Time Read Response Time IFF Response Time Opcode to Data Input Time Transport Code to Data Input Time Encoder Select Acknowledge Time IFF EEPROM Write Time (16 bits) Op Code to Hop Code Response Time
(c) 2002 Microchip Technology Inc.
Preliminary
DS41099C-page 29
HCS412
5.0 CONFIGURATION SUMMARY
HCS412 CONFIGURATION SUMMARY
Reference Section 64-bit Encoder Key 1 Section 3.2.7 60-bit seed value transmitted in CH Mode if (SEED = 1 AND TMPSD = 0) or if (SEED = 0 AND TMPSD = 1). LSB 60 bits of Encoder Key 2. 4 MSb's set to XXXX. (Note 1) Section 4.3.3 Section 3.4.5 Section 2.2.7 Section 3.4.7 Section 3.4.8 Section 2.2.5 28-bit Transport Code PLL Interface Select. RF Enable output active. Long Preamble Enable. Special Features Enable. Oscillator Tune Value. 0 = ASK 0 = Disable 0 = Disable 0 = Disable 1000b 0000b 0111b VLOWSEL IDAMP LFSP Section 2.2.6 Section 4.4.3 Section 4.4 Low Voltage Trip Point Select Intelligent Damping Enable LF Communication Special Features 0 = 2.2 Volt 0 = Enable LFSP1:0 00b 01b 10b 11b LFBSL MOD CWBE MTX4 RFBSL Section 4.2 Section 3.3 Section 3.4.3 Section 3.4.1 Section 3.3 IFF Baud Rate Select (LFTE) DATA pin modulation format Code word Blanking Enable Minimum Four Code words Transmission Baud Rate (RFTE) 0 = 200 us 0 = PWM 0 = Disable 0 = Disable RFBSL1:0 00b 01b 10b 11b S2LC -- TMPSD SEED XSER DINC DISC OVR SER USR CNT -- Section 3.2.7 Section 3.2.7 Section 3.2.5 Section 3.4.4 Section 3.2.6 Section 3.2.4 Section 3.4.1 S2/RFEN/LC1 Pin Configuration bit. Reserved, Set to 0 Temporary Seed Enable (Note 1) Seed Transmission Enable (Note 1) Extended Serial number Delayed Increment 10-bit Discrimination value Counter Overflow Value 32-bit Serial Number 64-bit user EEPROM area 16-bit Synchronization counter Reserved set 0000h 0 = LC -- 0 = Disable 0 = Disable 0 = Disable 0 = Disable PWM 400 us 200 us 100 us 100 us 1 = FSK 1 = Enable 1 = Enable 1 = Enable Fastest Nominal Slowest 1 = 4.4 Volt 1 = Disable Active Feature None Anticollision Prox Activation RF Echo 1 = 100 us 1 = Manch 1 = Enable 1 = Enable Manch 800 us 400 us 200 us 200 us 1 = S Input -- 1 = Enable 1 = Enable 1 = Enable 1 = Enable Description Table 5-1 summarizes the available HCS412 options.
TABLE 5-1:
Symbol KEY1 SDVAL KEY2 TCODE AFSK RFEN LPRE QLVS OSCT
Note 1: If IFF with KEY2 is enabled only if TMPSD = 1 and SEED = 1.
DS41099C-page 30
Preliminary
(c) 2002 Microchip Technology Inc.
HCS412
6.0 INTEGRATING THE HCS412 INTO A SYSTEM
FIGURE 6-1: TYPICAL LEARN SEQUENCE
Use of the HCS412 in a system requires a compatible decoder. This decoder is typically a microcontroller with compatible firmware. Microchip will provide (via a free license agreement) firmware routines that accept transmissions from the HCS412 and decrypt the hopping code portion of the data stream. These routines provide system designers the means to develop their own decoding system.
Enter Learn Mode Wait for Reception of a Valid Code Generate Key from Serial Number Use Generated Key to Decrypt Compare Discrimination Value with Fixed Value
6.1
Learning a Transmitter to a Receiver
A transmitter must first be 'learned' by a decoder before its use is allowed in the system. Several learning strategies are possible, Figure 6-1 details a typical learn sequence. Core to each, the decoder must minimally store each learned transmitter's serial number and current synchronization counter value in EEPROM. Additionally, the decoder typically stores each transmitter's unique crypt key. The maximum number of learned transmitters will therefore be relative to the available EEPROM. A transmitter's serial number is transmitted in the clear but the synchronization counter only exists in the code word's encrypted portion. The decoder obtains the counter value by decrypting using the same key used to encrypt the information. The KEELOQ algorithm is a symmetrical block cipher so the encryption and decryption keys are identical and referred to generally as the crypt key. The encoder receives its crypt key during manufacturing. The decoder is programmed with the ability to generate a crypt key as well as all but one required input to the key generation routine; typically the transmitter's serial number. Figure 6-1 summarizes a typical learn sequence. The decoder receives and authenticates a first transmission; first button press. Authentication involves generating the appropriate crypt key, decrypting, validating the correct key usage via the discrimination bits and buffering the counter value. A second transmission is received and authenticated. A final check verifies the counter values were sequential; consecutive button presses. If the learn sequence is successfully complete, the decoder stores the learned transmitter's serial number, current synchronization counter value and appropriate crypt key. From now on the crypt key will be retrieved from EEPROM during normal operation instead of recalculating it for each transmission received. Certain learning strategies have been patented and care must be taken not to infringe.
Equal ?
No
Yes Wait for Reception of Second Valid Code Use Generated Key to Decrypt Compare Discrimination Value with Fixed Value
Equal ? Yes Counters Sequential ? Yes
No
No
Learn successful Store: Serial number Encryption key Synchronization counter
Learn Unsuccessful
Exit
(c) 2002 Microchip Technology Inc.
Preliminary
DS41099C-page 31
HCS412
6.2 Decoder Operation 6.3
Figure 6-2 summarizes normal decoder operation. The decoder waits until a transmission is received. The received serial number is compared to the EEPROM table of learned transmitters to first determine if this transmitter's use is allowed in the system. If from a learned transmitter, the transmission is decrypted using the stored crypt key and authenticated via the discrimination bits for appropriate crypt key usage. If the decryption was valid the synchronization value is evaluated.
Synchronization with Decoder (Evaluating the Counter)
The KEELOQ technology patent scope includes a sophisticated synchronization technique that does not require the calculation and storage of future codes. The technique securely blocks invalid transmissions while providing transparent resynchronization to transmitters inadvertently activated away from the receiver. Figure 6-3 shows a 3-partition, rotating synchronization window. The size of each window is optional but the technique is fundamental. Each time a transmission is authenticated, the intended function is executed and the transmission's synchronization counter value is stored in EEPROM. From the currently stored counter value there is an initial "Single Operation" forward window of 16 codes. If the difference between a received synchronization counter and the last stored counter is within 16, the intended function will be executed on the single button press and the new synchronization counter will be stored. Storing the new synchronization counter value effectively rotates the entire synchronization window. A "Double Operation" (resynchronization) window further exists from the Single Operation window up to 32K codes forward of the currently stored counter value. It is referred to as "Double Operation" because a transmission with synchronization counter value in this window will require an additional, sequential counter transmission prior to executing the intended function. Upon receiving the sequential transmission the decoder executes the intended function and stores the synchronization counter value. This resynchronization occurs transparently to the user as it is human nature to press the button a second time if the first was unsuccessful.
FIGURE 6-2:
Start
TYPICAL DECODER OPERATION
No
Transmission Received ? Yes
No
Does Serial Number Match ?
Yes Decrypt Transmission Is Decryption Valid ? Yes No Is Counter Within 16 ? No No Is Counter Within 32K ? Yes Save Counter in Temp Location Yes Execute Command and Update Counter
No
The third window is a "Blocked Window" ranging from the double operation window to the currently stored synchronization counter value. Any transmission with synchronization counter value within this window will be ignored. This window excludes previously used, perhaps code-grabbed transmissions from accessing the system. Note: The synchronization method described in this section is only a typical implementation and because it is usually implemented in firmware, it can be altered to fit the needs of a particular system.
DS41099C-page 32
Preliminary
(c) 2002 Microchip Technology Inc.
HCS412
FIGURE 6-3: SYNCHRONIZATION WINDOW
Entire Window rotates to eliminate use of previously used codes Blocked Window (32K Codes) Stored Synchronization Counter Value Double Operation (resynchronization) Window (32K Codes) Single Operation Window (16 Codes)
FIGURE 6-4:
BASIC OPERATION OF RECEIVER (DECODER)
1 Received Information EEPROM Array Manufacturer Code
Button Press Information
Serial Number
32 Bits of Encrypted Data Serial Number 3 KEELOQ Decryption Algorithm Sync Counter Crypt Key
2
Check for Match
Decrypted Synchronization Counter Perform Function 5 Indicated by button press Note: Circled numbers indicate sequence of events.
4
Check for Match
(c) 2002 Microchip Technology Inc.
Preliminary
DS41099C-page 33
HCS412
7.0 PROGRAMMING THE HCS412
The HCS412 requires some parameters programmed into the device before it can be used. The programming cycle allows the user to input all 288 bits in a serial data stream, which are then stored internally in EEPROM. Programming is initiated by forcing the DATA line high, after the S2 line has been held high for the appropriate length of time line (Table 7-1 and Figure 7-2). A delay is required after entering Program mode while the automatic bulk erase cycle completes. The bulk erase writes all EEPROM locations to zeros. The device is then programmed by clocking in the EEPROM memory map (Least Significant bit first) 16 bits at a time, using S2 as the clock line and DATA as the data-in line. After each 16-bit word is loaded, a programming delay is required for the internal program cycle to complete. This delay can take up to Twc. The HCS412 will signal a `write complete' after writing each 16-bit word by sending out a series of ACK pulses TACKH high, TACKL low on DATA. The ACK pulses continue until S2 is dropped. Programming verification is allowed only once, after the programming cycle (Figure 7-3), by reading back the EEPROM memory map. Reading is done by clocking the S2 line and reading the data bits on DATA, again Least Significant bit first. For security reasons, it is not possible to execute a Verify function without first programming the EEPROM. Note: To ensure that the device does not accidentally enter Programming mode, DATA should never be pulled high by the circuit connected to it. Special care should be taken when driving PNP RF transistors.
FIGURE 7-1:
Production Programmer
CREATION AND STORAGE OF CRYPT KEY DURING PRODUCTION
Transmitter Serial Number HCS412 EEPROM Array
Serial Number Crypt Key Sync Counter
Manufacturer's Code
Key Generation Algorithm
Crypt Key
. . .
FIGURE 7-2:
PROGRAMMING WAVEFORMS
H O LD
Bit 16
Enter Program Mode
TPBW
TCLKH TDS
Initiate Data Polling Here
TP
C KL
TCLKL
TPS TPH1 DATA (Data) TPH2
TCLKL
Bit 0 Bit 1 Bit 2
TDH
Bit 3 Bit 14 Bit 15
TWC
Ack
TA
TA
Ack
C KH
S2 (Clock)
Ack
Bit 17
Data for Word 0 (KEY1_0)
Write Cycle Complete Here
Calibration Pulses
Data for Word 1 (KEY1_1)
Repeat for each word (18 times total) Note 1: S0 and S1 button inputs to be held to ground during the entire programming sequence.
FIGURE 7-3:
VERIFY WAVEFORMS
Beginning of Verify Cycle Data from Word 0
End of Programming Cycle
DATA (Data) S2 (Clock)
Bit190 Bit191
Ack
Bit 0
Bit 1 Bit 2
Bit 3
Bit 14
Bit 15
Bit 16 Bit 17
Bit190 Bit191
TWC
TDV
Note: If a Verify operation is to be done, then it must immediately follow the Program cycle.
DS41099C-page 34
Preliminary
(c) 2002 Microchip Technology Inc.
HCS412
7.1 EEPROM Organization HCS412 EEPROM ORGANIZATION
BITS 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0
TABLE 7-1:
16Bit Word 1 2 3 4 5 6 7
KEY1_1 KEY1_3 KEY1_5 KEY1_7 (KEY1 MSB) SEED_1 / KEY2_1 SEED_3 / KEY2_3 SEED_5 / KEY2_5 / TCODE_1 RFEN LPRE AFSK QLVS SEED_7 / KEY2_7 / TCODE_3 (MSB for all 3) LFBSL CWBE MTX4
KEY1_0 (KEY1 LSB) KEY1_2 KEY1_4 KEY1_6 SEED_0 / KEY2_0 (SEED AND KEY2 LSB) SEED_2 / KEY2_2 SEED_4 / KEY2_4 / TCODE_0 (TCODE LSB) SEED_6 / KEY2_6 / TCODE_2 VLOWSEL IDAMP
8
Set to 0
S2LC
9
RFBSL 1 0
MOD
LFSP 1 0
OSCT 3 DINC 2 XSER 1 SEED Units ms ms s ms ms ms s s s s s s s s 0 TMPSD
10 1 11 12 13 14 15 16 17 18
OVR 0 9 8 7 SER1 SER3 USR0 MSB USR1 MSB USR2 MSB USR3 MSB
10bit Discrimination Value 6 5 4 3 2 1 0
SER0 SER2 USR0 LSB USR1 LSB USR2 LSB USR3 LSB CNT0 (Counter LSB) Reserved, set to 0
CNT1 (Counter MSB) Reserved, set to 0
TABLE 7-2:
PROGRAMMING/VERIFY TIMING REQUIREMENTS
Symbol TPS TPH1 TPH2 TPBW TPROG TWC TCLKL TCLKH TDS TDH TDV TPHOLD TACKL TACKH Min. 2 4.0 50 4.0 4.0 50 50 50 0 18 100 800 800 Max. 5.0 -- -- -- -- -- -- -- -- -- 30 -- -- --
VDD = 5.0V 10%, 25 C 5 C Parameter Program mode setup time Hold time 1 Hold time 2 Bulk Write time Program delay time Program cycle time Clock low time Clock high time Data setup time Data hold time Data out valid time Hold time Acknowledge low time Acknowledge high time
(c) 2002 Microchip Technology Inc.
Preliminary
DS41099C-page 35
HCS412
8.0 ELECTRICAL CHARACTERISTICS
ABSOLUTE MAXIMUM RATING
Item Supply voltage Input voltage Output voltage Max output current Storage temperature Lead soldering temp ESD rating (Human Body Model) Rating -0.3 to 6.6 -0.3 to VDD + 0.3 -0.3 to VDD + 0.3 50 -55 to +125 300 4000 Units V V V mA C (Note) C (Note) V Symbol VDD VIN* VOUT IOUT TSTG TLSOL VESD Note:
TABLE 8-1:
Stresses above those listed under "ABSOLUTE MAXIMUM RATINGS" may cause permanent damage to the device.
* If a battery is inserted in reverse, the protection circuitry switches on, protecting the device and draining the battery.
TABLE 8-2:
DC AND TRANSPONDER CHARACTERISTICS
TAMB = 0C to 70C TAMB = -40C to 85C 2.0V < VDD < 6.3V
Commercial (C): Industrial (I):
Parameter Average operating current Note 2 Programming current Standby current High level input voltage Low level input voltage High level output voltage Low level output voltage LED output current Switch input resistor DATA input resistor LC input current LC input clamp voltage LC induced output current LC induced output voltage Carrier frequency LC input sensitivity
Symbol IDD (avg) IDDP IDDS VIH VIL VOH VOL ILED RS RDATA ILC VLCC VDDI VDDV fc VLCS
Min --
Typ1 200 2.3
Max 500 4.0 500 VDD + 0.3 0.15 VDD -- 0.08 VDD 0.08 VDD 7.0 80 160 10.0 -- 2.0 -- -- --
Unit A mA nA V V V V mA k k mA V mA V kHz mVPP Note 3
Conditions VDD = 6.3V VDD = 6.3V LC = off else < 5 A
-- 0.55 VDD -0.3 0.8 VDD 0.8 VDD -- -- 3.0 40 80 -- -- -- -- -- -- --
0.1 -- -- -- -- -- 4.0 60 120 -- 10 4.5 4.0 125 100
VDD = 2V, IOH =- .45 mA VDD = 6.3V, IOH,= -2 mA VDD = 2V, IOH = 0.5 mA VDD = 6.3V, IOH = 5 mA VDD = 3.0V, VLED = 1.5V S0/S1 not S2 VLCC=10 VP-P ILC <10 mA VLCC > 10V 10 V < VLCC, IDD = 0 mA 10 V < VLCC, IDD = -1 mA
Note 1: Typical values at 25C. 2: No load connected. 3: Not tested.
DS41099C-page 36
Preliminary
(c) 2002 Microchip Technology Inc.
HCS412
9.0 PACKAGING INFORMATION
8-Lead Plastic Dual In-line (P) - 300 mil (PDIP) Package Type:
E1
D 2 n 1 E
A
A2
c
L A1
eB
B1 p B
Number of Pins Pitch Top to Seating Plane Molded Package Thickness Base to Seating Plane Shoulder to Shoulder Width Molded Package Width Overall Length Tip to Seating Plane Lead Thickness Upper Lead Width Lower Lead Width Overall Row Spacing Mold Draft Angle Top Mold Draft Angle Bottom * Controlling Parameter Significant Characteristic
Units Dimension Limits n p A A2 A1 E E1 D L c B1 B eB
MIN
INCHES* NOM 8 .100 .155 .130 .313 .250 .373 .130 .012 .058 .018 .370 10 10
MAX
MIN
.140 .115 .015 .300 .240 .360 .125 .008 .045 .014 .310 5 5
.170 .145 .325 .260 .385 .135 .015 .070 .022 .430 15 15
MILLIMETERS NOM 8 2.54 3.56 3.94 2.92 3.30 0.38 7.62 7.94 6.10 6.35 9.14 9.46 3.18 3.30 0.20 0.29 1.14 1.46 0.36 0.46 7.87 9.40 5 10 5 10
MAX
4.32 3.68 8.26 6.60 9.78 3.43 0.38 1.78 0.56 10.92 15 15
Notes: Dimensions D and E1 do not include mold flash or protrusions. Mold flash or protrusions shall not exceed .010" (0.254mm) per side. JEDEC Equivalent: MS-001 Drawing No. C04-018
(c) 2002 Microchip Technology Inc.
Preliminary
DS41099C-page 37
HCS412
Package Type: 8-Lead Plastic Small Outline (SN) - Narrow, 150 mil (SOIC)
E E1
p
D 2 B n 1
h 45
c A A2
L A1
Number of Pins Pitch Overall Height Molded Package Thickness Standoff Overall Width Molded Package Width Overall Length Chamfer Distance Foot Length Foot Angle Lead Thickness Lead Width Mold Draft Angle Top Mold Draft Angle Bottom * Controlling Parameter Significant Characteristic
Units Dimension Limits n p A A2 A1 E E1 D h L c B
MIN
.053 .052 .004 .228 .146 .189 .010 .019 0 .008 .013 0 0
INCHES* NOM 8 .050 .061 .056 .007 .237 .154 .193 .015 .025 4 .009 .017 12 12
MAX
MIN
.069 .061 .010 .244 .157 .197 .020 .030 8 .010 .020 15 15
MILLIMETERS NOM 8 1.27 1.35 1.55 1.32 1.42 0.10 0.18 5.79 6.02 3.71 3.91 4.80 4.90 0.25 0.38 0.48 0.62 0 4 0.20 0.23 0.33 0.42 0 12 0 12
MAX
1.75 1.55 0.25 6.20 3.99 5.00 0.51 0.76 8 0.25 0.51 15 15
Notes: Dimensions D and E1 do not include mold flash or protrusions. Mold flash or protrusions shall not exceed .010" (0.254mm) per side. JEDEC Equivalent: MS-012 Drawing No. C04-057
DS41099C-page 38
Preliminary
(c) 2002 Microchip Technology Inc.
HCS412
9.1 Package Marking Information 8-Lead PDIP (300 mil) XXXXXXXX XXXXXNNN YYWW Example HCS412 XXXXX862 9925
8-Lead SOIC (150 mil) XXXXXXXX XXXXYYWW NNN
Example XXXXXXXX XXXX9925 862
Legend: MM...M XX...X YY WW NNN Note:
Microchip part number information Customer specific information* Year code (last 2 digits of calendar year) Week code (week of January 1 is week `01') Alphanumeric traceability code
In the event the full Microchip part number cannot be marked on one line, it will be carried over to the next line thus limiting the number of available characters for customer specific information.
*
Standard marking consists of Microchip part number, year code, week code and traceability code. For marking beyond this, certain price adders apply. Please check with your Microchip Sales Office. For SQTP devices, any special marking adders are included in SQTP price.
(c) 2002 Microchip Technology Inc.
Preliminary
DS41099C-page 39
HCS412
ON-LINE SUPPORT
Microchip provides on-line support on the Microchip World Wide Web (WWW) site. The web site is used by Microchip as a means to make files and information easily available to customers. To view the site, the user must have access to the Internet and a web browser, such as Netscape or Microsoft Explorer. Files are also available for FTP download from our FTP site.
Systems Information and Upgrade Hot Line
The Systems Information and Upgrade Line provides system users a listing of the latest versions of all of Microchip's development systems software products. Plus, this line provides information on how customers can receive any currently available upgrade kits. The Hot Line Numbers are: 1-800-755-2345 for U.S. and most of Canada, and 1-480-792-7302 for the rest of the world.
Connecting to the Microchip Internet Web Site
The Microchip web site is available by using your favorite Internet browser to attach to: www.microchip.com The file transfer site is available by using an FTP service to connect to: ftp://ftp.microchip.com The web site and file transfer site provide a variety of services. Users may download files for the latest Development Tools, Data Sheets, Application Notes, User's Guides, Articles and Sample Programs. A variety of Microchip specific business information is also available, including listings of Microchip sales offices, distributors and factory representatives. Other data available for consideration is: * Latest Microchip Press Releases * Technical Support Section with Frequently Asked Questions * Design Tips * Device Errata * Job Postings * Microchip Consultant Program Member Listing * Links to other useful web sites related to Microchip Products * Conferences for products, Development Systems, technical information and more * Listing of seminars and events
DS41099C-page 40
Preliminary
(c) 2002 Microchip Technology Inc.
HCS412
READER RESPONSE
It is our intention to provide you with the best documentation possible to ensure successful use of your Microchip product. If you wish to provide your comments on organization, clarity, subject matter, and ways in which our documentation can better serve you, please FAX your comments to the Technical Publications Manager at (480) 792-7578. Please list the following information, and use this outline to provide us with your comments about this Data Sheet. To: RE: Technical Publications Manager Reader Response Total Pages Sent
From: Name Company Address City / State / ZIP / Country Telephone: (_______) _________ - _________ Application (optional): Would you like a reply? Device: HCS412 Questions: Y N Literature Number: DS41099C FAX: (______) _________ - _________
1. What are the best features of this document?
2. How does this document meet your hardware and software development needs?
3. Do you find the organization of this data sheet easy to follow? If not, why?
4. What additions to the data sheet do you think would enhance the structure and subject?
5. What deletions from the data sheet could be made without affecting the overall usefulness?
6. Is there any incorrect or misleading information (what and where)?
7. How would you improve this document?
8. How would you improve our software, systems, and silicon products?
(c) 2002 Microchip Technology Inc.
Preliminary
DS41099C-page 41
HCS412
10.0 HCS412 PRODUCT IDENTIFICATION SYSTEM
-- /X To order or obtain information, e.g., on pricing or delivery, refer to the factory or the listed sales office. HCS412
Package: Temperature Range: Device:
P = Plastic DIP (300 mil body), 8-lead SN = Plastic SOIC (150 mil body), 8-lead - = 0C to +70C I = -40C to +85C HCS412 = Code Hopping Encoder HCS412T = Code Hopping Encoder (Tape and Reel) (SN only)
Sales and Support
Data Sheets Products supported by a preliminary Data Sheet may have an errata sheet describing minor operational differences and recommended workarounds. To determine if an errata sheet exists for a particular device, please contact one of the following: 1. 2. Your local Microchip sales office The Microchip Corporate Literature Center U.S. FAX: (480) 792-7277.
3.
The Microchip Worldwide Site (www.microchip.com)
Please specify which device, revision of silicon and Data Sheet (include Literature #) you are using. New Customer Notification System Register on our web site (www.microchip.com/cn) to receive the most current information on our products.
DS41099C-page 42
Preliminary
(c) 2002 Microchip Technology Inc.
Microchip's Secure Data Products are covered by some or all of the following patents: Code hopping encoder patents issued in Europe, U.S.A., and R.S.A. -- U.S.A.: 5,517,187; Europe: 0459781; R.S.A.: ZA93/4726 Secure learning patents issued in the U.S.A. and R.S.A. -- U.S.A.: 5,686,904; R.S.A.: 95/5429
Information contained in this publication regarding device applications and the like is intended through suggestion only and may be superseded by updates. It is your responsibility to ensure that your application meets with your specifications. No representation or warranty is given and no liability is assumed by Microchip Technology Incorporated with respect to the accuracy or use of such information, or infringement of patents or other intellectual property rights arising from such use or otherwise. Use of Microchip's products as critical components in life support systems is not authorized except with express written approval by Microchip. No licenses are conveyed, implicitly or otherwise, under any intellectual property rights.
Trademarks The Microchip name and logo, the Microchip logo, FilterLab, KEELOQ, microID, MPLAB, PIC, PICmicro, PICMASTER, PICSTART, PRO MATE, SEEVAL and The Embedded Control Solutions Company are registered trademarks of Microchip Technology Incorporated in the U.S.A. and other countries. dsPIC, ECONOMONITOR, FanSense, FlexROM, fuzzyLAB, In-Circuit Serial Programming, ICSP, ICEPID, microPort, Migratable Memory, MPASM, MPLIB, MPLINK, MPSIM, MXDEV, PICC, PICDEM, PICDEM.net, rfPIC, Select Mode and Total Endurance are trademarks of Microchip Technology Incorporated in the U.S.A. Serialized Quick Turn Programming (SQTP) is a service mark of Microchip Technology Incorporated in the U.S.A. All other trademarks mentioned herein are property of their respective companies. (c) 2002, Microchip Technology Incorporated, Printed in the U.S.A., All Rights Reserved.
Printed on recycled paper.
Microchip received QS-9000 quality system certification for its worldwide headquarters, design and wafer fabrication facilities in Chandler and Tempe, Arizona in July 1999. The Company's quality system processes and procedures are QS-9000 compliant for its PICmicro(R) 8-bit MCUs, KEELOQ(R) code hopping devices, Serial EEPROMs and microperipheral products. In addition, Microchip's quality system for the design and manufacture of development systems is ISO 9001 certified.
(c) 2002 Microchip Technology Inc.
Preliminary
DS41099C - page 43
WORLDWIDE SALES AND SERVICE
AMERICAS
Corporate Office
2355 West Chandler Blvd. Chandler, AZ 85224-6199 Tel: 480-792-7200 Fax: 480-792-7277 Technical Support: 480-792-7627 Web Address: http://www.microchip.com
ASIA/PACIFIC
Australia
Microchip Technology Australia Pty Ltd Suite 22, 41 Rawson Street Epping 2121, NSW Australia Tel: 61-2-9868-6733 Fax: 61-2-9868-6755
Japan
Microchip Technology Japan K.K. Benex S-1 6F 3-18-20, Shinyokohama Kohoku-Ku, Yokohama-shi Kanagawa, 222-0033, Japan Tel: 81-45-471- 6166 Fax: 81-45-471-6122
Rocky Mountain
2355 West Chandler Blvd. Chandler, AZ 85224-6199 Tel: 480-792-7966 Fax: 480-792-7456
China - Beijing
Microchip Technology Consulting (Shanghai) Co., Ltd., Beijing Liaison Office Unit 915 Bei Hai Wan Tai Bldg. No. 6 Chaoyangmen Beidajie Beijing, 100027, No. China Tel: 86-10-85282100 Fax: 86-10-85282104
Korea
Microchip Technology Korea 168-1, Youngbo Bldg. 3 Floor Samsung-Dong, Kangnam-Ku Seoul, Korea 135-882 Tel: 82-2-554-7200 Fax: 82-2-558-5934
Atlanta
500 Sugar Mill Road, Suite 200B Atlanta, GA 30350 Tel: 770-640-0034 Fax: 770-640-0307
Singapore
Microchip Technology Singapore Pte Ltd. 200 Middle Road #07-02 Prime Centre Singapore, 188980 Tel: 65-6334-8870 Fax: 65-6334-8850
Boston
2 Lan Drive, Suite 120 Westford, MA 01886 Tel: 978-692-3848 Fax: 978-692-3821
China - Chengdu
Microchip Technology Consulting (Shanghai) Co., Ltd., Chengdu Liaison Office Rm. 2401, 24th Floor, Ming Xing Financial Tower No. 88 TIDU Street Chengdu 610016, China Tel: 86-28-6766200 Fax: 86-28-6766599
Taiwan
Microchip Technology Taiwan 11F-3, No. 207 Tung Hua North Road Taipei, 105, Taiwan Tel: 886-2-2717-7175 Fax: 886-2-2545-0139
Chicago
333 Pierce Road, Suite 180 Itasca, IL 60143 Tel: 630-285-0071 Fax: 630-285-0075
Dallas
4570 Westgrove Drive, Suite 160 Addison, TX 75001 Tel: 972-818-7423 Fax: 972-818-2924
China - Fuzhou
Microchip Technology Consulting (Shanghai) Co., Ltd., Fuzhou Liaison Office Unit 28F, World Trade Plaza No. 71 Wusi Road Fuzhou 350001, China Tel: 86-591-7503506 Fax: 86-591-7503521
EUROPE
Denmark
Microchip Technology Nordic ApS Regus Business Centre Lautrup hoj 1-3 Ballerup DK-2750 Denmark Tel: 45 4420 9895 Fax: 45 4420 9910
Detroit
Tri-Atria Office Building 32255 Northwestern Highway, Suite 190 Farmington Hills, MI 48334 Tel: 248-538-2250 Fax: 248-538-2260
China - Shanghai
Microchip Technology Consulting (Shanghai) Co., Ltd. Room 701, Bldg. B Far East International Plaza No. 317 Xian Xia Road Shanghai, 200051 Tel: 86-21-6275-5700 Fax: 86-21-6275-5060
Kokomo
2767 S. Albright Road Kokomo, Indiana 46902 Tel: 765-864-8360 Fax: 765-864-8387
France
Microchip Technology SARL Parc d'Activite du Moulin de Massy 43 Rue du Saule Trapu Batiment A - ler Etage 91300 Massy, France Tel: 33-1-69-53-63-20 Fax: 33-1-69-30-90-79
Los Angeles
18201 Von Karman, Suite 1090 Irvine, CA 92612 Tel: 949-263-1888 Fax: 949-263-1338
China - Shenzhen
Microchip Technology Consulting (Shanghai) Co., Ltd., Shenzhen Liaison Office Rm. 1315, 13/F, Shenzhen Kerry Centre, Renminnan Lu Shenzhen 518001, China Tel: 86-755-2350361 Fax: 86-755-2366086
New York
150 Motor Parkway, Suite 202 Hauppauge, NY 11788 Tel: 631-273-5305 Fax: 631-273-5335
Germany
Microchip Technology GmbH Gustav-Heinemann Ring 125 D-81739 Munich, Germany Tel: 49-89-627-144 0 Fax: 49-89-627-144-44
San Jose
Microchip Technology Inc. 2107 North First Street, Suite 590 San Jose, CA 95131 Tel: 408-436-7950 Fax: 408-436-7955
Hong Kong
Microchip Technology Hongkong Ltd. Unit 901-6, Tower 2, Metroplaza 223 Hing Fong Road Kwai Fong, N.T., Hong Kong Tel: 852-2401-1200 Fax: 852-2401-3431
Italy
Microchip Technology SRL Centro Direzionale Colleoni Palazzo Taurus 1 V. Le Colleoni 1 20041 Agrate Brianza Milan, Italy Tel: 39-039-65791-1 Fax: 39-039-6899883
Toronto
6285 Northam Drive, Suite 108 Mississauga, Ontario L4V 1X5, Canada Tel: 905-673-0699 Fax: 905-673-6509
India
Microchip Technology Inc. India Liaison Office Divyasree Chambers 1 Floor, Wing A (A3/A4) No. 11, O'Shaugnessey Road Bangalore, 560 025, India Tel: 91-80-2290061 Fax: 91-80-2290062
United Kingdom
Arizona Microchip Technology Ltd. 505 Eskdale Road Winnersh Triangle Wokingham Berkshire, England RG41 5TU Tel: 44 118 921 5869 Fax: 44-118 921-5820
03/01/02
DS41099C-page 44
Preliminary
(c) 2002 Microchip Technology Inc.


▲Up To Search▲   

 
Price & Availability of HCS412TSN

All Rights Reserved © IC-ON-LINE 2003 - 2022  

[Add Bookmark] [Contact Us] [Link exchange] [Privacy policy]
Mirror Sites :  [www.datasheet.hk]   [www.maxim4u.com]  [www.ic-on-line.cn] [www.ic-on-line.com] [www.ic-on-line.net] [www.alldatasheet.com.cn] [www.gdcy.com]  [www.gdcy.net]


 . . . . .
  We use cookies to deliver the best possible web experience and assist with our advertising efforts. By continuing to use this site, you consent to the use of cookies. For more information on cookies, please take a look at our Privacy Policy. X