![](http://datasheet.mmic.net.cn/370000/SCS152_datasheet_16731843/SCS152_1.png)
1997 Microchip Technology Inc.
Preliminary
DS40150B-page 1
M
SCS152
FEATURES
ISO 7816-3:1989 “Answer to Reset” compatible
for synchronous cards
Industry standard 4406 command set compatible
Extended commands:
- Combined WRITE and
ERASE-WITH-CARRY function
- Cryptographic signature of the EEPROM
contents and challenge
40-bit user programmable area with lock bit
64-bit cryptographic key
64-bit transport code
33352 token units (78888
Internal protection against token counter value
corruption (anti-tearing)
8
)
DESCRIPTION
The SCS152 is a third generation token card integrated
circuit intended for prepaid applications. Typical appli-
cations of the SCS152 include disposable telephone
cards, vending machine cards, low value debit cards,
access control, and authentication.
The SCS152 incorporates several security features,
including an internal signature function and a long
transport code. The SCS152 has two modes – issuer
mode and user mode. During wafer testing, it is placed
in issuer mode for card manufacturing and transporta-
tion to the issuer. In issuer mode, the transport code is
needed to program the device and, thus, is protected
from unauthorized use before personalization by the
issuer.
During personalization, a cryptographic key, unique to
the card, is programmed into EEPROM. This key can
not be read. The system using the card must be able to
determine what key was programmed from examining
the memory map (i.e., not the token counter) containing
the issuer and serial number information.
The signature function computes an 8-bit value based
on a system supplied value (challenge) and the visible
memory map. Because of the nature of the signature
function and the fact that the key is not known outside
the system, it is practically impossible to predict the
value which the signature will compute.
DIE LAYOUT
BLOCK DIAGRAM
A correct signature indicates that the memory contents
have not been altered. It can therefore be used to check
the serial number, or that changes to the token counter
have actually occurred.
Programming the token counter uses a special circuit to
ensure that the programming will either be complete or
will not happen at all, if the external supply is suddenly
removed.* This is called
Fail Safe Programming
and, when used in conjunction with the extended write
and erase command, removes the need for special
‘tear-out’ protection to be performed by the reader.
,
Note:
The fail safe feature only works in the token
counter area.
GND
SDIO
V
DD
SCI
SCK
I/O
SCI
SCK
SDIO
V
DD
GND
ADDRESS
GENERATION
EEPROM
SIGNATURE
CALCULATOR
CONTROLLER
Token Card Chip
K
*Patents applied for.
L
is a registered trademark of Microchip Technology Inc.