0% found this document useful (0 votes)
252 views47 pages

Car Access

Uploaded by

Huy Tran
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
252 views47 pages

Car Access

Uploaded by

Huy Tran
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Car Access

PEPS, RKE, AES Immobilizer

1
Atmel Car Access System Solutions

• Atmel® launched the first


dedicated transmitter PLL U2741B
for Remote Keyless Entry (RKE)
applications in 1997
• Atmel is a leading car access
supplier and delivered already
more than 250 Mio ICs in this
application
• Strong relationships to the key
players in the automotive market

2
Car Access – Basic of RKE
Remote Start
 Like RKE but RF is typically 2-way
 Fob sends RF to car to "start engine"

 Car replies with RF to fob "engine running"

 Importand Design Considerations


 Very long range, > 300m, requires high RF link budget
 RF Link budget = f (TX power, RX sensitivity, antenna efficiencies)

 Higher TX power by managing RF "on" time (averaging)


 Higher RX sensitivity with narrower IF bandwidth & lower data rate
 Requires tight frequency control & compensation
(temp/voltage/lot)

3
Car Access – Basic of PEPS
Passive Entry / Passive Start
 From outside the vehicle: Touch car door (PE)
 From inside the vehicle: Press "start" button on dashboard (PS)
 LF from car awakens fob (LF downlink)
 Fob measures field strength vectors & sends info to vehicle
 Fob orientation is arbitrary - must measure x, y, & z axis (3D)
 Fob localized: Allow "Unlock" if outside (confirm if 2-way RF)
 Fob localized: Allow "Start" if inside (confirm if 2-way RF)
 Important system design considerations:
 LF field strength regulation over across voltage/temp/coil variation
 Accurate LF field strength measurement
 High LF field sensitivity outside
detection

trunk

RF
separation

outside rear
outside inside detection
outside
detection detection detection

outside
detection

4
Wide Range Of Car Access Solutions
RKE RKE + Immo PKE + Immo Optional
Single chip key Single chip key Single chip MCU, RF transceiver for
solution, best in class solution, 128 bit AES Immo + 3D LF Wake smart key and 2 way
performance – H/W encryption engine, up – ATA5791 BCM basestation –
ATA5774C up to 12.5dBm output ATA5831
Single chip LF driver +
power, works down to
Immo Basestation –
1.9V – ATA5795C
ATA5291
Best in class receiver, Smart RF receiver with
Best in class receiver,
with minimum external Immo transponder with Flash+MCU –
with minimum external
component, no built in coil, AES ATA5782
component, no
external IF filter, standard – ATA5580
external IF filter,
supports self polling –
supports self polling –
ATA5724C / ATA5781 TPMS Receiver
ATA5724C / ATA5781
support
Immo transponder with
built in coil, AES
standard – ATA5580 Door handle touch

5
Car Access: System Solution
Key Vehicle

RF Door
Combi Key

transmitter sensor

Ultra low
power µC
with 8-/16-bit
immobilizer
RF receiver
MCU
RF
Unidirectional
Passive Entry

RF transceiver
transmitter

Ultra low
power µC
with LF
immobilizer ImmoLF
+ 3D LF basestation
Body
computer
Passive Entry
Bidirectional

RF
transceiver 32-bit MCU

Ultra low
LF antenna
power µC
with LF driver
immobilizer
+ 3D LF

6
Product Availability

Embedded
Car / Fob Function Part Number Availability
AVR
Both Immobilizer protocol stack Software Production

Key fob AES immobilizer transponder ATA5580 Production


AES RKE AVR with immobilizer and
Key fob ATA5795 Production
RF transmitter
AES PEG AVR with immobilizer and
Key fob ATA5791 Production
3D wake-up
Key fob Fractional-N RF transmitter ATA5749C Production

Both Fractional-N RF transceiver AVR® ATA5831 Production

Car Fractional-N RF receiver ATA5781 Production

Car Fixed-frequency RF receiver ATA572x Production

Car 6-channel LF driver ATA5279C Production


4-channel LF driver with Immobilizer
Car ATA5291 Sampling
Basestation

7
Car Access Key Fob Controllers
RKE AVR® ATA5795C (Primatik)
RKE key fobs

Stand-alone transponder ATA5580 (TrAESure)

PEG AVR 3D immobilizer & RF ATA5702 (Primus2+)

PEG+RF/ATA5791(Primus+) PEG AVR+RF ATA5703(Primus2+ROM)

PEG Controllers
ATA5790N(PrimusX) PEG AVR ATA5700 (Primus2)

ATA5790 (Primus) PEG AVR ATA5701 (Primus2ROM)

2010 2011 2012 2013


Part Number Description
ATA5795 RKE AVR® controller with AES-128, 315/433MHz RF transmitter and immobilizer

ATA5580 Stand-alone AES-128 transponder, 8K Flash, 2K EEPROM

ATA5790 PEPS AVR controller with AES-128, 3D LF, immobilizer, 16K Flash, 2K EEPROM

ATA5790N PEPS AVR controller with AES-128, 3D LF (enhanced), immobilizer, 16K Flash, 2K EEPROM

ATA5791 PEPS AVR controller with AES-128, 3D LF (enhanced), immobilizer, 315/433MHz RF transmitter, 16K Flash, 2K EEPROM

ATA5700 PEPS AVR controller with AES-128, 3D LF, 3D immobilizer, 16K/32K Flash, 1K/2K EEPROM

ATA5701 PEPS AVR controller with AES-128, 3D LF, 3D immobilizer, 16K/32K ROM, 1K/2K EEPROM

ATA5702 PEPS AVR controller with AES-128, 3D LF, 3D immobilizer, 315/433/868/915MHz, 16K/32K Flash, 1K/2K EEPROM

ATA5703 PEPS AVR controller with AES-128, 3D LF, 3D immobilizer, 315/433/868/915MHz, 16K/32K ROM, 1K/2K EEPROM

8
Remote Keyless Entry (with Immo)

Vehicle

ATA577xC / Remote Control


ATA5795C ATA5724C AVR
Ultra Low power AVR RF Data
With TX for Smart RF
Keyfob 315/433/
868/915 MHz
Receiver

Immobilizer

ATA5580 Energy / Data Immo


Ultra Low power AVR Data LF
With LF Immobilizer Basestation
Transponder AES Crypto

Two different ICs for Keyfob and Transponder allows a cost


optimized approach on the key side

9
Transmitter with AVR µC: ATA577xC

Remote Keyless Entry: key

Key characteristics
 Highly integrated micro-transmitter based on
AVR® microcontroller VCC

 Highly integrated with low external BOM 68nF

VCC
Limited software design effort required
24 23 22 21 20 19 SW1

XTAL

GND
GND_RF
ENABLE

VS_RF
GND
1
VCC PA0
18 SW2
2
PB0 PA1
17
3

Key features 4
PB1
ATA577x PA2
16
SW3

PB 3 / RESET PA3 / T0
15
 4kbytes Flash, in-system programmable 5
PB2 PA4 / SCK
14
6
Perfect current consumption due to optimized

PA_ENABLE
PA6 / MOSI

PA7 PA5 / MISO
13

ANT2

ANT1

GND
CLK
AVR microcontroller 7 8 9 10 11 12

VCC

 Wake-up interrupt for all I/Os RF Choke

 Small package and low external component count


allows small board design
 Integrated temperature sensor
 10-bit ADC, brown-out detection
Package: QFN24, 5x5mm
 ESD protection: 2kV HBM Samples available: now
 Temperature range - 40°C to +85°C PPAP available: now

10
Single Chip LF + RF with µC: ATA5795C

Remote Keyless Entry: key


Key characteristics
 RKE low-power AVR® with immobilizer and RF TX
 125kHz immobilizer interface compatible to existing
base-station ICs
 315MHz – 433MHz Fractional-N RF TX with 12.5dBm Pout
 Fast AES hardware crypto engine for both RF and LF
 CMMI-certified immobilizer stack

Key features
 AES is basis for open-source immobilizer software library
 Highest security level for encryption (128bit)
 Special memory protection secures immobilizer software
 High power TX allows extended coverage

 Easy software design with existing AVR tool set


 Low-power effective AVR microcontroller
 6kB Flash for customer software available

 Small package and low external component count allows Package: QFN32, 5x5mm
small board design Samples available: now
PPAP available: now
 1.9V to 3.6V supply voltage

11
Passive Entry Go - Unidirectional

Key Vehicle

Remote Control
ATA5724C /
RF Data QProx ATA5781
ATA5791
Touch & RF
Ultra Low power AVR Proximity Receiver
With LF Immobilizer
Immobilizer
Technology
3D LF Receiver
AES Crypto
With Energy / Data Body
Integrated ATA5291
Computer
PLL Based Data
RF Transmitter LF Antenna
Driver 32bits
+ MCU
Immobilizer
PEG Wake Up Basestation

Data

 Single chip PEPS Keyfob solution

12
Passive Entry / Go – Bidirectional RF

Key Vehicle

Remote Control
ATA5831 AVR
RF Data Smart RF
ATA5831 Transceiver
Smart RF Immobilizer
Transceiver

Energy / Data
ATA5291
Data LF Antenna Body
ATA5790N Driver
Ultra Low power AVR + Computer
With LF Immobilizer Immobilizer
3D LF Receiver Basestation 32bits
AES Crypto MCU
PEG Wake Up

Data QProx
Touch &
Proximity
Technology

 Complete PEPS solution with Atmel chipset, including capacitive sensing

13
Microcontroller with Immobilizer, 3D LF and RF
Transmitter: ATA5791
Passive Entry Go: key Battery
VBAT
31 30 29 28 27 26 25 24 23 22 21 20
32 19
Key characteristics
33 18
 Low-power AVR® with immobilizer and 3D LF 34 17
LF- Coil
Z- axis
 125kHz immobilizer interface 35 ATA5791 16
LF- Coil
 3D LF receiver with RSSI: 1.5mVpp worst case 36 15
Y- axis
RF- 37 14
 Current consumption in listening mode ~ 4µA 38 13
Loop antenna LF/T- Coil
 300 to 450MHz RF Transmitter up to 12.5dBm 1 2 3 4 5 6 7 8 9 10 11 12 X- axis
 Fast AES hardware crypto engine
VBAT CBUF

Key features
 AES is basis for open-source immobilizer SW library and
comes along with integrated fast AES encryption engine
 32-bit unique identification number
 Two 128-bit secret keys, one 128-bit transponder key
 Highest security level for encryption (128bit)
 Special memory protection secures immobilizer software
 Highly sensitive 3D LF RSSI measurement allows fast
wake-up
 Tolerance compensation for 3D RSSI measurement
 Easy software design with existing AVR tool set
 Low-power, effective AVR microcontroller • Package: QFN38 5x7mm
 14kB Flash for customer software available • Samples available: Now
 Frac-N RF Transmitter (300MHz – 450MHz) up to 12.5dBm • PPAP available: Now
 1.9V to 4.2V supply voltage

14
ATA5702 – 3rd Gen PEPS KeyFob with 3D
Immobilizer
LF Bidirectional
Engine Link
Control 125 kHz
Module
Emergency/
Immobilizer Immobilizer
Base Station
Cbuf
LF Up Link AFE
125 kHz
X-Axis

3D LF
Module Vbat
Power
Y-Axis Management

PEPS
Antenna
Driver
Z-Axis MCU

Central
Board
Controller Primus2+

UHF UHF
Receiver Transmitter

UHF Down Link


315/433/868/915 MHz
Vehicle Passive Key Fob

15
ATA5702 – One chip PEPS Keyfob
2nd Generation Key Fob uC with AES-128, 3D IMMO & RF TX
RKE + PEPS + IMMO: Key
Key Features
• Monolithic Immobilizer/PEPS solution with AES 128
• Open immobilizer Stack
• LF Interface:
• 3D Transponder and 3D LF wake-up
• Programmable sensitivity: 100uVpp / 250uVpp / 500uVpp
• 4.7uA current consumption at 250uVpp
• Programmable LF bitrates: 1.95k / 3.9k / 7.8kbits/s
• Logarithmic RSSI measurement for better spatial
localization
• RSSI measurement on 3 channels simultaneously <2.4ms
• 3D LF Battery charging capability
• AVR Core:
• 16kB/32kB User Flash, 1/2kB EEPROM, 1kB SRAM
• 32kB System Firmware (RF protocol handling, LF handling)
• RF Transmitter:
• Programmable Frac-N PLL covering 310 – 318MHz, 418-
477MHz, 836-956MHz in 93Hz / 185Hz steps
• Programmable RF Output Power: -12 to 14.5dBm
• Up to 80kBit/s Manchester coded data stream
• Controller Interfaces: Status: In Design
• 19 GPIOs, SPI & I2C interfaces, Debug-wire Engineering samples: Nov 2013
• Supply voltage: 1.9V to 4.2V Final Samples: Jun 2014
• QFN 5x7 – 38 pins PPAP: Sep 2014

16
ATA5700 – Primus2 (No Transmitter)
2nd Generation Key Fob uC with AES-128 & 3D IMMO
PEPS + IMMO: Key
Key Features
Features
• Monolithic Immobilizer/PEPS solution with AES 128
• Open immobilizer Stack
• LF Interface:
• 3D Transponder and 3D LF wake-up
• Programmable sensitivity: 100uVpp / 250uVpp / 500 uVpp
• 4.7uA current consumption at 250uVpp
• Programmable LF bitrates: 1.95k / 3.9k / 7.8kbits/s
• Logarithmic RSSI measurement for better spatial
localization
• RSSI measurement on 3 channels simultaneously <2.4ms
• 3D LF Battery charging capability
• AVR Core:
• 16kB / 32kB User Program Memory, 1/2kB EEPROM, 1kB
SRAM
• 32kB System Firmware (RF protocol handling, LF handling)
• Controller Interfaces:
• 19 GPIOs, SPI & I2C interfaces
• Debug-wire
• Supply voltage: 1.9V to 4.2V
• QFN 5x7 – 38 pins Status: In Design
Engineering samples: Nov 2013
Final Samples: Jun 2014
PPAP: Sep 2014

17
Primus2plus – ATA5700
Competitive Assessment

 3D Immobilizer , no direction base


 Best in class range detection (sensitivity - 100uVpp) vs
battery lifetime (power consumption) with good out of
band blocking
 Allows approach lighting/walk away with acceptable battery lifetime
 Possible range measurement for Convertible cars
 Fastest in/out car detection thanks to direct RSSI
measurement on 3 channels simultaneously
 Best in class RF performance due to the integration of PLL
based Transmitter
 Compatible with almost all Immobilizer Base-station in the
market
 Small package to accomodate small keyfob

18
ATA5702/Primus2+
Application 3D-LF/RF-Transmitter

ATA5702/03

19
ATA5702/Primus2+
Application 3D-LF/RF-Transceiver

ATA5700/01

• LFEVENT: Trigger Signal for fast TRX wake up: < 2ms
• SPI-Builder: Library for easier SPI communication between Primus2
and TRX
• Crystal clock from TRX
20
RF Roadmap
ATA5831 (SigmaX)
RF transceivers
Fractional-N RF transceiver with embedded MCU
AVR® ATA5830N (Sigma)

Full duplex RF TRx


ATA5833 Smart RF transceivers
ATA5823C/24C

ATA5782 (OmegaAVR) RF Rx with [Link]

Smart RF receiver

Fract.-N RF receiver ATA5781


ATA5780N (Omega) (Omega2)

2010 2011 2012 2013


Part Number Frequencies Description
ATA5823C 315MHz Full duplex RF transceiver
ATA5824C 433/868MHz Full duplex RF transceiver
ATA5830N 315/433/868–915MHz RF transceiver AVR® microcontroller – 6KByte user Flash
ATA5831 315/433/868–950MHz RF transceiver AVR microcontroller – 20KByte user Flash
ATA5833 315/433/868–950MHz Fractional-N smart RF transceiver for key fobs
ATA5780N 315/433/868–915MHz Fractional-N smart RF receiver
ATA5781 315/433/868–950MHz 2nd-generation Fractional-N smart receiver
ATA5782 315/433/868–950MHz RF receiver AVR microcontroller – 20KByte user Flash

21
Sigma (TrX) & Omega (Rx) Family Roadmap

ATA5830N

ATA5780N

ATA5831

ATA5781

ATA5782
Flash (KB) 6 20 20

User ROM (KB) 20

RF Transmitter

Independent Services 3 3 5 5 5 5

Enhanced RF switch time

Enhanced sensitivity

Transceiver Receiver

Common Best in class Blocking Package &


24kB ROM RF Library
Features RF Receiver pin compatible

22
Advanced RF TRX: ATA5831
RKE / PEG & TPMS RF Transceiver
Key Characteristics
• UHF Transceiver AVR with Excellent RF Performance
• Pin, package & Software Compatible with ATA578x family (Rx)
• One Device & Crystal Covers All Frequencies
• Integrated RF Switch
• ATA5831@20 KB user Flash, ATA5832@20KB user ROM and ATA5833
@no user ROM(+24 kB ROM firmware lib. For all versions)
• Autonomous operation possible

Key Features
 UHF transceiver with excellent RF performance
 ASK Sensitivity (Manchester) at 433.92MHz:
-109dBm @ 20kBit/s IFBW=366 kHz
-119dBm @ 1kBit/s IFBW=366 kHz
 FSK Sensitivity (Manchester) at 433.92MHz:
-108dBm @ 20kBit/s Δf=±20kHz IFBW=165 kHz
-114dBm @ 5kBit/s Δf=±5kHz IFBW=165 kHz
-123dBm @ 0.75kBit/s Δf=±0.75kHz IFBW=25 kHz
 Best in Class blocking performances
e.g. 64 dBc@IFBW=165kHz) and 48dBc@IFBW=225kHz at Freq. Offset of
1MHz
 High image rejection: e.g. 55dB @ 315/433MHz; 50 dB
@868.3MHz/915MHz without calibration
 Automatic antenna tuning for loop antenna
 Programmable output power: -10 to 14 dBm
Wettable flanks package: QFN32 5x5mm
 5 independent services with 3 channels each Samples Available: Now
 Supply range: 1.9V – 3.6 V; 4.5 - 5.5 V PPAP Available: Now
 Temperature range - 40°C to +105°C

23
Advanced RF RX: ATA5781/82
RKE / PEG & TPMS RF Receiver
Key Characteristics
• UHF Receiver AVR with Excellent RF Performance
• Pin, package & Software Compatible with ATA583x family (TRX)
• One Device & Crystal Covers All Frequencies
• Integrated RF Switch
• ATA5782@20 KB user Flash, and AT5781@no user ROM(+24 kB
ROM firmware lib. For all versions)
• Autonomous operation possible

Key Features
 UHF Receiver with excellent RF performance
 ASK Sensitivity (Manchester) at 433.92MHz:
-109dBm @ 20kBit/s IFBW=366 kHz
-119dBm @ 1kBit/s IFBW=366 kHz
 FSK Sensitivity (Manchester) at 433.92MHz:
-108dBm @ 20kBit/s Δf=±20kHz IFBW=165 kHz
-114dBm @ 5kBit/s Δf=±5kHz IFBW=165 kHz
-123dBm @ 0.75kBit/s Δf=±0.75kHz IFBW=25 kHz
 Best in Class blocking performances
e.g. 64 dBc@IFBW=165kHz) and 48dBc@IFBW=225kHz at Freq.
Offset= 1MHz
 High image rejection: e.g. 55dB @ 315/433MHz; 50 dB
@868.3MHz/915MHz without calibration
Automatic antenna tuning for loop antenna
Package: Wettable flanks QFN32 5x5mm

 5 independent services with 3 channels each


 Supply range: 1.9V – 3.6 V; 4.5 - 5.5 V
Samples Available: Now
 Temperature range - 40°C to +105°C
PPAP Available: Now

24
Competitive Battery Lifetime and Blocking
Behavior
Operating Mode ATA5831 A B ATA5781 C
Receive 433MHz 11mA 22mA 22mA 11mA 12mA
Transmit 433MHz (10dBm) 18mA 25mA 33mA N/A N/A
Off (2.7V, 85C) 0.5uA 5uA 5uA 0.5uA 27uA
Multi-profile wake-up

Operating Mode ATA5831 A B ATA5781 C


Blocking (typical) 62dBc 40dBc 40-50dBc 62dBc tbd
Image rejection (typical) 55dBc 45dBc1 31dBc2 55dBc 40dBc
3

1 ... Requires calibration


2 ... Narrower channel selcted
3 ... 10.7MHz IF filter

25
LF Base-station Roadmap

Immobilizer
base station

ATA5291
LF driver + immobilizer

LF drivers

ATA5279C 6-fold antenna


driver for PEG (Adrima)

2010 2011 2012 2013

26
6-channel LF Antenna Driver: ATA5279C

Passive Entry Go: car side


Key characteristics
 6-channel antenna driver for 125kHz LF coils
 Capability to drive high currents (up to 1A for 3 channels)
 Very low power-down current consumption 46 1 4
48 44 7 8

Provides high performance with easy control


VL VL VL VCC
VS OSCi OSCO

3 2 1
21 VDS1

27 VDS2

 Provides a wake-up and initialized channel to the key fob 42 VDS3

26 A1P ATA5279 C VIF 6

 Output driver stage protected against overload and heat Ant1


30 A2P
MCU
33 A3P IRQ 41

29 A4P
NRES 40
32 A5P

Key features
34 A6P MACT 9

BCNT 10
24 A1N1

Flexible current regulation integrated (20 steps)


25 A1N2
 19 A2N1
20 A2N2 S_CS 38

 Autonomous timing generation to unload microcontroller 14


15
A3N1
A3N2
S_CLK 39

Ant6

RSSI measurement supported


22 A4N1
MOSI 37
 23 A4N2

16 A5N1 MISO 36

Fault protection and reporting


17 A5N2
 12 A6N1
13 A6N2

 Diagnostic mode for antenna check 11


18
VSHF1
VSHF2
CINT 3

Reduced effort for external HOST controller due to:


5 VSHS CINT

 RSH
PGND3 PGND2 PGND1
AGND3
AGND2
AGND1
RGND
47 45 43 35 31 28 2

 SPI interface for communication and programming


 Embedded command set (LF data buffer)
 Low level control
 Cost effective due to low external BOM • Package: QFN48, 7x7mm
 Sinusoidal output signal for improved EMV • Samples available: now
• PPAP available: available

27
ATA5291 – LF Driver with Immo Basestation

LF Bidirectional
Engine Link
Control 125 kHz
Module
Emergency/
Immobilizer Immobilizer
Base Station
Cbuf
LF Up Link AFE
125 kHz
X-Axis

Fortimmo 3D LF
Module Vbat
Power
Y-Axis Management

PEPS
Antenna
Driver
Z-Axis MCU

Central
Board
Controller

UHF UHF
Receiver Transmitter

UHF Down Link


315/433/868/915 MHz
Vehicle Passive Key Fob

28
ATA5291 application

LF antenna
with immobilizer
front position
Fortimmo

four antennas

29
Key Features of LF PEG Products

ATA5279C ATA5291

Transmit Channels (Expandable) 6 (9) 4(8)


Prog.
Current Shaping Sinus
Shaping

Immo Base-Station

Integrated Boost Converter

Polling

30
ATA5291 – Fortimmo
 PEPS Coil Driver & Immobilizer Basestation
D2

PEPS + IMMO: Vehicle


VBATT D1
L1 L2
C3

C1 T1
R2 C5
C6

Key Characteristics
C2 C4
C9 C8
C10

VS AVCC33 DVCC AVCC18 BCG BCS BGND VTG VTX


VCP VDS2 VDS1

Derived from the market leading IC ATA5279C


Fortimmo

• Highly integrated solution (Base-station + LF drivers) PCB wires Antennas


Power Management
• Regulated current for stable RSSI measurement

µC voltage supply
A1P
Ant1

line (VDD)
A2P

• 1 coil mulitplexed for Immo/wakeup function (immo coil can


Ant2

A3P
Ant3
C7
also be separated) VIF

NRES
A4P
Ant4

• Compatible with nearly all transponders in the market


tap point
IRQ

BCNT PEPS- A1N


A2N
MACT

• Full diagnostics coverage provides highest safety level driver,


Switches,
A3N
A4N

GPIO1 SPI VSHF1


R1

IO-ctrl Diagnostic VSHF2


Digital Control VSHS

Key Features MISO / DOUT


MOSI / DIN
A1ED
A2ED
A3ED

µC connection
• Internal LC Oscillator for carrier generation (+/-0.3%)
NCS A4ED
SCLK
A1EN

• Immobilizer sensitivity of 5mVpp at the tap point


A2EN
A3EN
A4EN

• Wide 7-16.5V operating supply for normal operation


• Jump Start from 7V-28V & Immobilizer down to 5V CLKOUT
B1P

OSC
• Fast 2Mbit/s SPI interface B1N
R3
Immobilizer TRX
• 4 integrated LF drivers with programmable peak current up to
R4

1A adjustable in 20 steps RXIN

• Integrated coil multiplexer (4 internal, 4 external) with the


ability to drive any of 2 coils together DGND AGND GND

• Full diagnostic coverage for all channels: Short to GND, VCC


and other coil lines. Open detection.
• Programmable carrier shaping (square wave, progressive Package: QFN48 7x7mm
transitions, sinus) Samples Available: MAY 2013
• Operating temperature:-40°C/125°C PPAP Available: 2Q2014

31
Fortimmo – General Features

• LF carrier frequency from 125 kHz

• Internal LC Oscillator for carrier generation (+/-0.5%)

• Battery power supply voltage from 7V to 16.5V for normal operation, from 7V to
28V for jump start operation and 5V is the minimum required for Immobilizer
operation

• Fast SPI interface (2Mbit/s) for Data Access and Configuration, slave select input,
multiplex SPI-data with transparent data-in data-out pins

• Ability to support antennas with tuning capacitor far or close to the IC while keeping
all diagnostic capabilities.

• Diagnostic functions for electrical and thermal stress conditions

• Output driver stages are protected against electrical and thermal overload

• QFN 7x7-48 with wettable flanks - Operating temperature: -40°C / 125°C

32
FortImmo application with four coils
VBATT D1 D2
L1 L2
C3
Combined antenna
C1 T1
PEPS/Immobilizer
R2 C5
C6
C2 C4
C9 C8
C10

VS AVCC33 DVCC AVCC18 BCG BCS BGND VTG VTX VCP VDS2 VDS1

Fortimmo

PCB wires Antennas


Power Management
µC voltage supply

A1P
Ant1
line (VDD)

A2P
Ant2

A3P
Ant3
C7
VIF A4P
Ant4
NRES
tap point
IRQ

BCNT PEPS- A1N


A2N
MACT
driver, A3N
A4N

GPIO1 SPI Switches, R1


VSHF1
IO-ctrl Diagnostic VSHF2
Digital Control VSHS

A1ED
MISO / DOUT
A2ED
MOSI / DIN A3ED
µC connection

NCS A4ED
SCLK
A1EN
A2EN
A3EN
A4EN

B1P
CLKOUT
OSC
B1N
R3
Immobilizer TRX R4

RXIN

DGND AGND GND

33
FortImmo application with eight coils
VBATT D1 D2
L1 L2
C3
Combined antenna
C1 T1 PEPS/Immobilizer
R2 C5
C6
C2 C4
C9 C8 C10

VS AVCC33 DVCC AVCC18 BCG BCS BGND VTG VTX VCP VDS2 VDS1

Fortimmo

PCB wires Antennas


Power Management
µC voltage supply

A1P
Ant1
line (VDD)

A2P
Ant2
A3P
C7 Ant3
VIF A4P

NRES Ant4
IRQ tap point

BCNT PEPS- A1N


A2N
MACT
driver, A3N
A4N

GPIO1 SPI Switches, R1


VSHF1
IO-ctrl Diagnostic VSHF2
Digital Control VSHS
10K
A1ED
MISO / DOUT
A2ED EAnt1
MOSI / DIN A3ED T3
µC connection

10K
NCS A4ED
SCLK EAnt2
A1EN 10K
T4
A2EN
A3EN EAnt3

A4EN 10K T5

EAnt4

T6
Diagnostics
B1P
CLKOUT
OSC
B1N
R3 Up to four external
Immobilizer TRX R4 switches with
RXIN
complete diagnostics

DGND AGND GND

34
Companion Transponder Solution: ATA5580

Remote Keyless Entry: service key


Key characteristics
TrAESure/
 Stand-alone transponder based on 128bit AES 6x12mm

 Embedded 125kHz antenna


Atmel open-immobilizer protocol incorporated
Ferrite
 Antenna

 125kHz immobilizer interface compatible to existing


base-station ICs ATMegaPA 3,4x3,4mm

 Fast AES hardware crypto engine

PD3

PD4

PC1'

PC4-SCK

PC3-SDIN

PD6

PC2-CLK

PD7

PB4
PD3
PB3 PB5

PB2
XTAL2
PB1
GND
XTAL1

ATmegaPA
Key features
VCC

PD2

PD1
PB0
PD0

Best companion solution to ATA5795 as the same


PB7 VBAT

 PB6

GNDRF

NRES
GND

A4N
TME

PC0
PC1

A4P
microcontroller IC is equipped
 Pre-programmed during production process with Atmel’s
open-source immobilizer protocol
 AES is basis for open-source immobilizer software
library
 Highest security level for encryption (128bit)
 Special memory protection secures immobilizer
software
 Coupling factor of 1.5
Transponder package: 3x6x12mm
 Same immobilizer approach as in other Atmel ICs Samples available: now
 ATR5790N (uni- and bi-directional RF) PPAP available: now
 ATR5795 (uni-directional RF)

35
AES Cipher & Open-source Immobilizer Stack

Atmel open-source
NXP Hitag2 NXP HitagPro
protocol

Application Application Application

Hitag cryptography AES AES

Hitag protocol Hitag protocol Open immobilizer protocol

Physical layer Physical layer Physical layer

Coil antenna Coil antenna Coil antenna

Download the open immobilizer protocol stack here:


[Link]

36
Benefits

• Higher security through peer reviewing of protocol design

• Allows mixing LF ICs from different suppliers

• Allows multi-sourcing of immobilizer devices

• Flexible configuration according to customer requirements

37
Open Immobilizer Stack

Immobilizer / RKE / PEG: car & key Key


ATA5580
Transparent
base station
BCM/ECU
32-bit MCU
ATA5790
Key characteristics ATA5795

Physical layer Physical layer GPIOs


 Complete open immobilizer solution
 CMMI certified Logical layer IOs Logical layer
Immob. Immob.
 Fast, secure and configurable protocol protocol
 AES-128 crypto engine with 3 separate keys AES AES
 Configurable uni- and bi-lateral authentification
 Advanced retry strategy
Key Remote base BCM/ECU
ATA5580 station
Key features ATA5790 ATA5272
32-bit MCU
ATA5795
 Software runs in all Atmel car access AVR® ICs
Physical layer Physical layer LIN/K-LINE/UART
 With Atmel ICs a low coupling factor of <1% can be
Logical layer Logical layer LIN/K-LINE prot.
reached
Immob. Immob. protocol
 Compatible with already existing base-station solutions protocol AES
 Two 128-bit keys stored in protected EEPROM AES LIN/K-LINE prot.

 One 128-bit transport key LIN/K-LINE/UART

 32-bit unique identifier


 Configurable challenge/response length (32 – 128 bit) Hardware
CMMI-certified Reference
software software/doc
 Optional CRC on all communication frames
 With enable CRC advanced retry strategy available
 64-byte configuration stored in EEPROM  CMMI-certified package & doc: now
 LIN/K-line protocol example: now

38
Open Source Immobilizer Stack

The industry’s only fully auditable, immobilizer system!

• Protocol layer definition based on


third-party audit firm specializing in Car Key

Automotive Security, Escrypt GmbH


Antenna Antenna
• Definition reviewed and amended by
Physical Layer Physical layer
Tier1 suppliers and Car Manufacturers

Logical layer Logical layer
Open Source license allows any party
to enhance or review the protocol for Protocol Protocol

the industry’s benefit AES AES

• Allows interoperability of existing


Immobilizer ICs (protocol is
implemented in software) Industry
Standard

• Available upon free registration on Open Source


Immobilizer
Atmel’s website Stack

39
Evaluation Kit: ATAK51003-V1
 Complete Car Access Reference System – IMMO+PEPS+RKE
Key Characteristics
• Contains reference designs for new devices:
• OmegaII ATA5781 Available:
• PrimusX+ (ATA5791) – PrimusX and Atik die in same package Now
• Kit uses Open PEPS Protocol (RF+LF) and Open Immobilizer Protocol (LF)

µC with RF Transmitter
(ATA5774)
RF Receiver
(ATA5782)

Frac-N BCM
RF Transmitter LF (AVR,
1D LF Immobilizer Basestation Switches,
(ATA5795C) (ATA5272) LEDs
replaces
STK600)

Frac-N LF Coil
RF Transmitter Driver
+
3D LF Receiver/ (ATA5279C)
1D Transponder
(ATA5791 )

40
Evaluation Kit: ATAK51003-V1
 Complete Car Access Reference System –
IMMO+PEPS+RKE

ATA5791 ATA5795 ATA5774

Immobilizer ATA5781 ATA5279C


Basestation

41
Door Handle Solution

 Using a ATA6616 (LDO, LIN interface and Tiny167 microcontroller)


 Optimized for space and connectivity

LIN, VBAT

Proximity Sensor Touch


Sensor
QT600
Connector

Prox&Touch
controller ISP
Connector

Proximity detection at 150mm distance

42
Real case setup – Approaching Hand

Tiny44 Demo within Door


Handler

Proximity detection in 150mm distance

43
Innovation Lead By Atmel

• Car manufacturers are locked-in with hacked immobilizer


protocols (HiTag-2)
― Open standard cryptography
― Open communication protocols

• Crowded RF spectrum: passive start or RKE systems jammed by


RF interferers
― Industry leading RF blocking characteristics
― Multi-channeling protocols

• Enabling industry longest battery lifetime on key fob while


expanding functionality
― Automatic scanning of TPMS, RKE, PEG and remote start channels
without microcontroller assistance

44
Atmel’s Solution Benefits For OEM-Tier 1
• Innovation
- TPMS & car access as sub-channels with 1 receiver  ATA5745,
ATA5780N
- Ultra low power consumption for PEPS Key fob

• Performance
- Increase RKE distance (at reduced power budget)  Up to 12.5dBm
outpower for Tx
- Increase passive entry distance  ATA5790N with 1.5mV sensitivity
- Greater robustness against noise (e.g. 3 sub-channel)  ATA5780N

• Open Platform Immobilizer


- Remove proprietary protocols that does not require being tied to N**
supplier, no monopoly
- OEM- Tier 1 fully in control of Immobilizer software source code
• Cost Down
- Next generation PEPS solution with better cost option
- Single chip PEPS keyfob ATA5791
- Complete PEPS, RKE solution, single stop shop (Door handle to PEPS
ECU)

45
Car Access Customer Highlights
 Customer List:
 Continental
 Hella
 BOSCH
 Lear China
 Kostal China
 Magneti Marelli China
 Mitsubishi Automotive Japan
 Mobis Korea
 Denso Japan
 Alps
 Omron

 Key OEM
 BMW
 GM
 Ford
 VW Group
 FIAT
 Chrysler
46

You might also like