FM11RF32 32KBits Contactless IC Card Chip

Similar documents
FM11RF005U 512Bits EEPROM Contactless Smart Card IC

FM1208M01 Contactless CPU Card

FM1208 Contactless CPU Card

FM4428 8KBits Memory Card Chip

FM Bytes Memory Card Chip. Datasheet. Dec Datasheet. FM Bytes Memory Card Chip Ver 3.0 1

BL75R06SM 8K-bit EEPROM Contactless smart card chip

IS23SC4439 Preliminary. 1K bytes EEPROM Contactless Smart Card Conform to ISO/IEC 14443A Standard. Table of contents

FM24C1024A. Apr Data Sheet. Data Sheet FM24C1024A 2-wrie Serial EEPROM Ver 1.1 1

MF1ICS General description. Functional specification. 1.1 Key applications. 1.2 Anticollision. Energy. MIFARE card contacts La, Lb.

FM93C46A/56A/66A Three-wire Serial EEPROM

VendaCard MF1ICS50. major cities have adopted MIFARE as their e-ticketing solution of choice.

FM24C04A/08A 2-Wire Serial EEPROM

FM24C32A/64A 2-Wire Serial EEPROM

FM24C128A 2-Wire Serial EEPROM

MF1ICS General description. Functional specification. 1.1 Key applications. 1.2 Anticollision. Product data sheet PUBLIC

UNC20C01R 1Kbyte EEPROM Contactless Card IC

FM24C64D 2-Wire Serial EEPROM With Unique ID and Security Sector

FM K-BIT SPI Serial EEPROM With unique ID and Security Sector

Security & Chip Card ICs SLE 55R04. Intelligent 770 Byte EEPROM with Contactless Interface complying to ISO/IEC Type A and Security Logic

FM24C02A 2-Wire Serial EEPROM

JMY600 Series IC Card Module

FM24C02B/04B/08B/16B 2-Wire Serial EEPROM

FEATURES Contactless transmission of data and supply energy, no battery is needed up to 100mm (depending on the inlay antenna and reader)

MaCaPS International Ltd

AT88RF04C. CryptoRF EEPROM Memory 13.56MHz, 4 Kilobits SUMMARY DATASHEET. Features

Advanced. Card. Systems. Ltd. by Eric Lee. June, Advanced Card Systems Ltd. Room 2910, The Center, 99 Queen's Road Central, Hong Kong.

EWTJ-680 API Specification

Research on the Security Authentication Mode of MF1 S50 Electronic Tag

Inv.# 557 ONE CHIP MICROCONTROLLER FOR ELECTRONIC PLASTIC CARDS Preliminary datasheet September 2010 revised January 2012

AT88SC3216CRF. CryptoRF EEPROM Memory 13.56MHz, 32 Kilobits SUMMARY DATASHEET. Features

mifare DESFire Contactless Multi-Application IC with DES and 3DES Security MF3 IC D40 INTEGRATED CIRCUITS Objective Short Form Specification

KR300 User Manual. Contents

CryptoRF EEPROM Memory 8 Kbits

MF0ICU2. 1. General description. MIFARE Ultralight C. 1.1 Contactless energy and data transfer. 1.2 Anticollision. Rev May

MIFARE Classic 1K - Mainstream contactless smart card IC for fast and easy solution development. energy MIFARE CARD PCD. data

MF1S703x. 1. General description. MIFARE Classic 4K - Mainstream contactless smart card IC for fast and easy solution development. 1.

Supports ISO14443A Mifare Classic 1K, Mifare Classic 4K, Mifare Ultralight. Fast data transfer - Contactless communication up to 106 KHz

JMY600 Series IC Card Module

EWTJ-680 API Specification

Secure Microcontrollers for Smart Cards. AT90SC Summary

Regarding the change of names mentioned in the document, such as Hitachi Electric and Hitachi XX, to Renesas Technology Corp.

Micro RWD MF-IC (Mifare/ICODE/ISO14443B) Reader (low power version with auxiliary outputs)

Download from

Interfacing the NM24C16 Serial EEPROM to the microcontroller. Interfacing the NM24C16 Serial EEPROM to the 8031 Microcontroller AN-957

RFID Radio Frequency Identification The Basic Principle. Semiconductors 4

INTEGRATED CIRCUITS. Standard Card IC MF1 IC S50. Functional Specification. Product Specification Revision 5.0. November Philips Semiconductors

DATA SHEET. HT2DC20S20 HITAG 2 stick transponder INTEGRATED CIRCUITS

a clock signal and a bi-directional data signal (SCL, SDA)

MF1S50YYX_V1. 1 General description. MIFARE Classic EV1 1K - Mainstream contactless smart card IC for fast and easy solution development

JMY504M User's Manual

RFID Beginner s Kit Command Reference Manual Copyright 2003 Intensecomp Pte Ltd All rights reserved.

S1C17 Family EEPROM Emulation Library Manual

AT94K Series Field Programmable System Level Integrated Circuit. Application Note. FPSLIC Baud Rate Generator

esm Series Product Specification Tiny Controller-Based Speech Synthesizer DOC. VERSION 1.1

JMY600 Series IC Card Module

Micro RWD MF (Mifare) Low Power Version (with auxiliary data outputs)

Guide to Loopback Using the DP8390 Chip Set

AT88RF1354 SPI User Guide For CryptoRF

AN MIFARE Type Identification Procedure. Application note COMPANY PUBLIC. Rev August Document information

FM33A0xx Low Power MCU

W83176R-401 W83176G-401

GM 500A Mifare Read/Write Module V1.0 GM 500A Mifare 13.56MHz Read/Write Protocols Interface (I2C/UART) User s Manual

ST19WR08 Dual Contactless Smartcard MCU With RF UART, IART & 8 Kbytes EEPROM Features Contactless specific features

Product Description. Application Note. AVR360: XmodemCRC Receive Utility for the AVR. Features. Theory of Operation. Introduction

Proximity reader for 13.56MHz Contactless module MiFare,ISO14443 type A /B

Regarding the change of names mentioned in the document, such as Hitachi Electric and Hitachi XX, to Renesas Technology Corp.

NFC is the double click in the internet of the things

Silicon Epitaxial Planar Zener Diode for Stabilized Power Supply. Type No. Mark Package Code HZS Series Type No. MHD B 7

Parallel EEPROM Die Products. Die Products. Features. Description. Testing

W83176R-400 W83176G-400

EM55M/Q450. Product Specification. Tiny-Controller-Based MTP/QTP Sound Processor DOC. VERSION 1.3

When is Data Susceptible to Corruption

RFID MODULE Mifare Reader / Writer SL031 User Manual Version 3.0 Jan 2018 StrongLink

FM25Q04 4M-BIT SERIAL FLASH MEMORY

CMT2110A/2210A One-Way RF Link Development Kits User s Guide

Low-Power-Radio Transceiver IC

FeliCa Card User's Manual Excerpted Edition

SL2 ICS50/SL2 ICS General description I CODE SLI-L/I CODE SLI-L HC. 1.1 Anticollision. 1.2 Contactless energy and data transfer

Mifare Open System Rules Programmer Manual

S1V3G340 External SPI-Flash Select Guide

PMEPS60. Getting Started Handbook Doc. Version 1.6. RISC II 2G Series Processor Module ELAN MICROELECTRONICS CORP.

AT91 ARM Thumb Microcontrollers. Application Note. Using the ECC Controller on AT91SAM9260/9263 and AT91SAM7SE Microcontrollers. 1.

WHAT FUTURE FOR CONTACTLESS CARD SECURITY?

Grcard SIM Card. Specification

EASY SOUND est Series

2-wire Serial EEPROM Smart Card Modules AT24C32SC AT24C64SC

S1V30080 Series I2C Interface Sample Program Specifications

H1PROT.PDF 14 Pages Last Revised 02/11/06. Micro RWD H1/S Protocol

INTEGRATED CIRCUITS MF RC531. ISO Reader IC. Short Form Specification Revision 3.2. April Philips Semiconductors

KYTronics Corp.,Ltd KYT-22XX SPECIFICATIONS B 1 OF kytronics.co.kr. 3 rd Floor, A-Dong, Twin Town-Bldg,

RFID MODULE Mifare Reader / Writer SL030 User Manual Version 2.4 Nov 2011 StrongLink

ATA2270-EK1. User Guide

Application Note. Binary Parity Generator and Checker AN-CM-242

Features INSTRUCTION DECODER CONTROL LOGIC AND CLOCK GENERATORS COMPARATOR AND WRITE ENABLE EEPROM ARRAY READ/WRITE AMPS DATA IN/OUT REGISTER 16 BITS

Connecting EPSON Display Controllers to Topway LCD Panels

CIPURSE V2 Certification Program

JMY600 Series IC Card Module

DEFCON 26 - Playing with RFID. by Vanhoecke Vinnie

AVR32752: Using the AVR32 UC3 Static Memory Controller. 32-bit Microcontrollers. Application Note. Features. 1 Introduction

Application Note. SLG46824/6 MTP Arduino Programming Example AN-CM-255

Transcription:

FM11RF32 32KBits Contactless IC Card Chip May. 2008 FM11RF32 32KBits Contactless IC Card Chip Ver 2.1 1

INFORMATION IN THIS DOCUMENT IS INTENDED AS A REFERENCE TO ASSIST OUR CUSTOMERS IN THE SELECTION OF SHANGHAI FUDAN MICROELECTRONICS CO., LTD PRODUCT BEST SUITED TO THE CUSTOMER'S APPLICATION; THEY DO NOT CONVEY ANY LICENSE UNDER ANY INTELLECTUAL PROPERTY RIGHTS, OR ANY OTHER RIGHTS, BELONGING TO SHANGHAI FUDAN MICROELECTRONICS CO., LTD OR A THIRD PARTY. WHEN USING THE INFORMATION CONTAINED IN THIS DOCUMENTS, PLEASE BE SURE TO EVALUATE ALL INFORMATION AS A TOTAL SYSTEM BEFORE MAKING A FINAL DECISION ON THE APPLICABILITY OF THE INFORMATION AND PRODUCTS. SHANGHAI FUDAN MICROELECTRONICS CO., LTD ASSUMES NO RESPONSIBILITY FOR ANY DAMAGE, LIABILITY OR OTHER LOSS RESULTING FROM THE INFORMATION CONTAINED HEREIN. SHANGHAI FUDAN MICROELECTRONICS CO., LTD PRODUCTS ARE NOT INTENDED FOR USE IN MEDICAL, LIFE SAVING, OR LIFE SUSTAINING APPLICATIONS. THE PRIOR WRITTEN APPROVAL OF SHANGHAI FUDAN MICROELECTRONICS CO., LTD IS NECESSARY TO REPRINT OR REPRODUCE IN WHOLE OR IN PART THESE DOCUMENTS. Future routine revisions will occur when appropriate, without notice. Contact Shanghai Fudan Microelectronics Co., Ltd sales office to obtain the latest specifications and before placing your product order. Please also pay attention to information published by Shanghai Fudan Microelectronics Co., Ltd by various means, including Shanghai Fudan Microelectronics Co., Ltd home page (http://www.fmsh.com/). Please contact Shanghai Fudan Microelectronics Co., Ltd local sales office for the specification regarding the information in this documents or Shanghai Fudan Microelectronics Co., Ltd products. Trademarks Shanghai Fudan Microelectronics Co., Ltd name and logo, the 复旦 logo are trademarks or registered trademarks of Shanghai Fudan Microelectronics Co., Ltd or its subsidiaries in China. Shanghai Fudan Microelectronics Co., Ltd, Printed in the China, All Rights Reserved. FM11RF32 32KBits Contactless IC Card Chip Ver 2.1 2

Content CONTENT... 3 1. FEATURES... 4 2. PRODUCT OVERVIEW... 5 2.1. INTRODUCTION... 5 2.2. BLOCK DIAGRAM... 5 2.3. FUNCTION DESCRIPTION... 6 2.3.1. TRANSACTION SEQUENCE... 6 2.3.2. TRANSACTION SEQUENCE DESCRIPTION... 6 3. COMMANDS... 8 3.1. COMMAND CODE (HEX)... 8 3.2. COMMANDS DEMONSTRATION... 8 4. MEMORY ORGANIZATION AND ACCESS CONDITIONS... 9 5. DATA INTEGRITY... 12 6. SECURITY... 13 REVISION HISTORY... 14 SALES AND SERVICE... 15 FM11RF32 32KBits Contactless IC Card Chip Ver 2.1 3

1. Features Contactless communications RF interface Contactless transmission of data and supply (no battery needed) Operating distance: up to 100mm (depending on antenna geometry) Operating frequency: 13.56MHz Fast communication baud rate: 106Kbit/s Half duplex communication protocol using handshake Compatible: with ISO/IEC 14443-A Encryption algorithm compatible with M1 standard Typical Ticking Transaction: <100ms EEPROM 4096 x 8bit EEPROM High security level data communication Organized in security separated 64 sectors supporting multi-application. High security Mutual three pass authentication Each sector has its own two secret keys for systems using key hierarchies. Assess conditions for each block defined by user Arithmetic capability: increase and decrease. High reliability Endurance: 100,000 cycle Data Retention: 10 Years FM11RF32 32KBits Contactless IC Card Chip Ver 2.1 4

2. Product Overview 2.1. Introduction FM1RF32 is the contactless IC card chip development by Shanghai FM Co., Ltd. The chip has 4K x 8bits EEPROM organization; the maximum communication range between the reader antenna and contactless card is approximately 10cm. Data is exchanged half duplex at a 106-kbit/s rate. The FM11RF32 is a true multi-application smart card with the functionality of a processor card realized with hardware logic, and also has a very high security performance with the encryption and communication circuit, so FM11RF32 can be especially tailored to meet the requirements of a payment card which can be used for ticketing systems in public transport and comparable applications. The Contactless smart card contains three components: FM11RF32 chip antenna and the card base with PVC (or PET) material. No battery is needed. When the chip is positioned in proximity of the coupling device antenna, the high speed RF communication interface allows transmitting data with 106 Kbit/s. 2.2. Block Diagram Figure 2-1 FM11RF32 Block Diagram FM11RF32 32KBits Contactless IC Card Chip Ver 2.1 5

2.3. Function Description 2.3.1. Transaction sequence Answer to request Answer to request Anti-collision loop Anti-collision loop Select card Select card Authentication Authentication Read block Read block Write block Write block Figure 2-2 FM11RF32 Transaction sequence diagram 2.3.2. Transaction sequence description Answer to Request: The communication protocol and the communication baud rate between RWD and card are defined in advance. When a card is in the operating range of a RWD, the RWD will communication with the appropriate protocol, to validate the type of a card. Anti-collision Loop: If there are several cards in the operating range of RWD. They can be distinguished by their unique serial numbers and one can be selected for further transactions. The unselected cards return to the standby mode and wait for a new Answer to Request and Anti-collision loop. Select Card: After a card selection, the card returns the Answer to Select code (SAK). FM11RF32 32KBits Contactless IC Card Chip Ver 2.1 6

3 Pass Authentication: After selection of a card, RWD specifies the sector number and use the corresponding key for the 3 Pass Authentication procedures. Any communication after authentication is performed via stream cipher encryption. (If the next sector is selected, cipher verifying is necessary to the new sector.). Read/Write: After authentication, the following operations may be performed: READ: WRITE: Read one block Write one block DECREMENT: Decrements the contents of one block and stores the result in the data-register INCREMENT: Increments the contents of one block and stores the result in the data-register TRANSFER: Writes the contents of the data-register to one block RESTORE: Halt: Stores the contents of one block in the data-register Pause operation FM11RF32 32KBits Contactless IC Card Chip Ver 2.1 7

3. Commands 3.1. Command code (HEX) Commands Code(HEX) Request std 26 Request all 52 Anti-collision 93 Select Card 93 Authentication.la 60 Authentication.lb 61 Read 30 Write A0 Increment C1 Decrement C0 Restore C2 Transfer B0 Halt 50 Table 3-1 FM11RF32 Command Code (HEX) 3.2. Commands demonstration Answer to Request: Look for card in operating area. Request Std means looking for card which is not set to halt, Request All means looking for all cards which are in operating area. Anti-collision: It means selecting only one card if there is one card or several cards in operating area. Select Card: It means setting up the communication with the selected card after the anti-collision command. Authentication: Before visiting memory, the user must verify if the operation is legal by coherence of cipher in RWD and cipher in card. Read: Read 16 bytes of one block. Write: Write data to one block. Increment: Increment a certain value to numerical block, store the result in register. Decrement: Decrement a certain value to numerical block, store the result in register. Restore: Read contents of numerical block to register. Transfer: Write contents of register to numerical block. Halt: Card is set to halt. FM11RF32 32KBits Contactless IC Card Chip Ver 2.1 8

4. Memory Organization and Access Conditions The FM11RF32 has integrated a 32Kbits EEPROM which is split into 64 sectors with 4 blocks. One block consists of 16 bytes each, the structure of memory is shown below: Sector 0 Sector 1 Sector 2 B0 B1 B2 B3 B0 B1 B2 B3 B0 B1 B2 B3 Manufacture Code Data block Sector trailer Sector 63 B0 B1 B2 B3 Figure 4-1 FM11RF32 Memory Organization The fourth block of any sector contains access KEYA (6 bytes), KEYB (6 bytes) and the access conditions (4 bytes).the other three blocks of the sector serve as common data blocks. The first block of the memory is reserved for manufacturer data like 32 bit serial number. This is a read only block and is also solidified. In many documents it is named block0. There are two kinds of data block application, one is data reserved and direct read/write, the other is denoted special data format, it can be initialization evaluation, increment, decrement and read. The structure of block 3 is shown below. FM11RF32 32KBits Contactless IC Card Chip Ver 2.1 9

Bit No. Byte No. 0 5 6 9 10 15 KEY A Access Conditions KEY B Figure 4-2 FM11RF32 Structure of Block 3 bit 7 bit 6 bit 5 bit4 bit3 bit 2 bit 1 bit 0 C2X3_b C2X2_b C2X1_b C2X0_b C1X3_b C1X2_b C1X1_b C1X0_b C1X3 C1X2 C1X1 C1X0 C3X3_b C3X2_b C3X1_b C3X0_b C3X3 C3X2 C3X1 C3X0 C2X3 C2X2 C2X1 C2X0 BX7 BX6 BX5 BX4 BX3 BX2 BX1 BX0 Note: b stands for inversion e.g.:c2x3_b=inv(c2x3) X stands for sector No.(0~15) Y stands for block No.(0~3) C stands for control bit B stands for reserve bit Access condition for the Block 3 (X=0-15) KEYA KEYA Access Con Access Con KEYB KEYB C1X3 C2X3 C3X3 read Write Read Write read Write 0 0 0 never KEYA B KEYA B Never KEYA B KEYA B 0 1 0 never Never KEYA B Never KEYA B Never 1 0 0 never KEYB KEYA B Never never KEYB 1 1 0 never Never KEYA B Never never Never 0 0 1 Never KEYA B KEYA B KEYA B KEYA B KEYA B 0 1 1 Never KEYB KEYA B KEYB never KEYB 1 0 1 Never Never KEYA B KEYB never Never 1 1 1 Never Never KEYA B Never never Never Note: KEY A B means KEY A or KEY B; never means can t perform the function. FM11RF32 32KBits Contactless IC Card Chip Ver 2.1 10

Access condition for Data Blocks (X=0-15 sectors, y=0-2 block of each sector) C1XY C2XY C3XY Read Write Increment decr, transfer, restore 0 0 0 KEYA B KEYA B KEYA B KEYA B 0 1 0 KEYA B Never Never Never 1 0 0 KEYA B KEYB Never Never 1 1 0 KEYA B KEYB KEYB KEYA B 0 0 1 KEYA B Never Never KEYA B 0 1 1 KEYB KEYB Never Never 1 0 1 KEYB Never Never Never 1 1 1 Never Never Never Never Table 4-1 FM11RF32 Access condition for Data Blocks FM11RF32 32KBits Contactless IC Card Chip Ver 2.1 11

5. Data Integrity Following mechanisms are implemented in the contactless communication link between RWD and card to ensure very reliable data transmission: Anti-collision 16 bit CRC per block parity bits for each byte Bit count checking Bit coding to distinguish between 1, 0, and no information Channel monitoring (Protocol sequence and bit stream analysis) FM11RF32 32KBits Contactless IC Card Chip Ver 2.1 12

6. Security The FM11RF32 Card has high security: 3 Pass Authentication must be through before read/write operation. Each card has different Serial Numbers, Crypto-Data transfer, Key Transfer and Access Key Protection which guarantee the uniqueness of each card. Keys in the cards are read protected but can be altered by who knows the actual key. There are 64 sectors in the card, each sector has own keys (Key A, Key B). Two different keys for each sector support systems using key hierarchies, so FM11RF08SH offers real multi-application functionality. FM11RF32 32KBits Contactless IC Card Chip Ver 2.1 13

Revision History Version Publication date Pages Paragraph or Illustration Revise Description 1.0 May. 2004 4 Initial Release. 2.0 Oct. 2007 15 Updated Format. 2.1 May. 2008 15 Sales and service Updated the address of HK office. FM11RF32 32KBits Contactless IC Card Chip Ver 2.1 14

Sales and Service Shanghai Fudan Microelectronics Co., Ltd. Address: Bldg No. 4, 127 Guotai Rd, Shanghai City China. Postcode: 200433 Tel: (86-21) 6565 5050 Fax: (86-21) 6565 9115 Shanghai Fudan Microelectronics (HK) Co., Ltd. Address: Unit 506, 5/F., East Ocean Centre, 98 Granville Road, Tsimshatsui East, Kowloon, Hong Kong Tel: (852) 2116 3288 2116 3338 Fax: (852) 2116 0882 Beijing Office Address: Room.1208, Bldg C, Zhongguancun Science and Technology Development Edifice, 34 zhongguancun Street (South), Hai Dian District, Beijing City, China. Tel: (86-10) 6212 0682 6213 9558 Fax: (86-10) 6212 0681 Shenzhen Office Address: Room.1301, Century Bldg, Shengtingyuan Hotel, Huaqiang Rd (North), Shenzhen City, China. Tel: (86-755) 8335 1011 8335 0911 Fax: (86-755) 8335 9011 Web Site: http://www.fmsh.com/ FM11RF32 32KBits Contactless IC Card Chip Ver 2.1 15