ABRIDGED DATA SHEET
219-0019; Rev 0; 7/12
E V A L U A T I O N K I T A V A I L A B L E
DS28E25
1-Wire SHA-256 Secure Authenticator
with 4Kb User EEPROM
General Description
Features
The DS28E25 combines crypto-strong, bidirectional,
secure challenge-and-response authentication func-
tionality with an implementation based on the FIPS
180-3-specified Secure Hash Algorithm (SHA-256). A
4Kb user-programmable EEPROM array provides non-
volatile storage of application data and additional pro-
tected memory holds a read-protected secret for SHA-
256 operations and settings for user memory control.
Each device has its own guaranteed unique 64-bit
ROM identification number (ROM ID) that is factory pro-
grammed into the chip. This unique ROM ID is used as
a fundamental input parameter for cryptographic opera-
tions and also serves as an electronic serial number
within the application. A bidirectional security model
enables two-way authentication between a host system
and slave-embedded DS28E25. Slave-to-host authenti-
cation is used by a host system to securely validate that
an attached or embedded DS28E25 is authentic. Host-
to-slave authentication is used to protect DS28E25 user
memory from being modified by a nonauthentic host. The
SHA-256 message authentication code (MAC), which the
DS28E25 generates, is computed from data in the user
memory, an on-chip secret, a host random challenge,
and the 64-bit ROM ID. The DS28E25 communicates
S Symmetric Key-Based Bidirectional Secure
Authentication Model Based on SHA-256
S Dedicated Hardware-Accelerated SHA Engine for
Generating SHA-256 MACs
S Strong Authentication with a High Bit Count, User-
Programmable Secret, and Input Challenge
S 4096 Bits of User EEPROM Partitioned Into 16
Pages of 256 Bits
S User-Programmable and Irreversible EEPROM
Protection Modes Including Authentication, Write
and Read Protect, and OTP/EPROM Emulation
S Unique, Factory-Programmed 64-Bit Identification
Number
S Single-Contact 1-Wire Interface Communicates
with Host at Up to 76.9kbps
S Operating Range: 3.3V 10%, -40NC to +85NC
S Low-Power 5µA (typ) Standby
S
8kV Human Body Model ESD Protection (typ)
S 2-Pin SFN, 6-Pin TDFN, 6-Lead TSOC Packages
Typical Application Circuit
M
over the single-contact 1-Wire bus at overdrive speed.
The communication follows the 1-Wire protocol with the
ROM ID acting as node address in the case of a multiple-
device 1-Wire network.
V
CC
R
PUP
Applications
IO
Authentication of Network-Attached Appliances
Printer Cartridge ID/Authentication
µC
DS28E25
Reference Design License Management
System Intellectual Property Protection
GND
Sensor/Accessory Authentication and Calibration
Secure Feature Setting for Configurable Systems
Key Generation and Exchange for Cryptographic
Systems
Ordering Information appears at end of data sheet.
1-Wire is a registered trademark of Maxim Integrated Products, Inc.
For related parts and recommended products to use with this part, refer to: www.maxim-ic.com/DS28E25.related
For pricing, delivery, and ordering information, please contact Maxim Direct
at 1-888-629-4642, or visit Maxim’s website at www.maxim-ic.com.
1