ABRIDGED DATA SHEET
EVALUATION KIT AVAILABLE
DS28E35
DeepCover Secure Authenticator with
1-Wire ECDSA and 1Kb User EEPROM
General Description
DeepCover embedded security solutions cloak sensitive
data under multiple layers of advanced physical security
to provide the most secure key storage possible.
Features
●ꢀ ECDSAꢀEngineꢀforꢀPublic-KeyꢀSignatureꢀUsingꢀaꢀ
Defined SEC Domain Parameter Set
®
●ꢀ On-ChipꢀHardwareꢀRandomꢀNumberꢀGenerator
The DeepCover Secure Authenticator (DS28E35) pro-
vides a highly secure solution for a host controller to
authenticate peripherals based on the industry stan-
dard (FIPS 186) public-key based Elliptic Curve Digital
Signature Algorithm (ECDSA). The ECDSA engine com-
putes keys and signatures using a pseudorandom curve
over a prime field according to the “Standards for Efficient
Cryptography (SEC)”. The private and public key can
be computed by the device or installed by the user and
optionally locked. Separate memory space is set aside to
store and lock a public-key certificate as it is needed to
verify authenticity. In addition to ECDSA-related memory,
the device has 1024 bits of user memory that is organized
as four pages of 256 bits. Page protection modes include
write protection, read protection, and one-time-program-
mable (OTP) memory emulation modes. The DS28E35
also features a one-time settable, nonvolatile 17-bit dec-
rement-on-command counter, which can be used to keep
track of the lifetime of the object to which the DS28E35
is attached. Each device has its own guaranteed unique
64-bit ROM identification number (ROM ID) that is fac-
tory programmed into the chip. This unique ROM ID is
used as a fundamental input parameter for cryptographic
operations and also serves as an electronic serial number
within the application. The DS28E35 communicates over
●ꢀ PrivateꢀandꢀPublicꢀKeyꢀCanꢀBeꢀComputedꢀbyꢀ
the Device or Loaded from Outside with Optional
Automatic Locking
●ꢀ SeparateꢀUser-ProgrammableꢀandꢀLockableꢀMemoryꢀ
SpaceꢀtoꢀStoreꢀaꢀPublic-KeyꢀCertificate
●ꢀ 17-BitꢀOne-TimeꢀSettable,ꢀNonvolatileꢀDecrement-
On-Command Counter
●ꢀ SHA-256ꢀEngineꢀtoꢀComputeꢀaꢀHashꢀofꢀEEPROMꢀ
PageꢀDataꢀandꢀHostꢀChallengeꢀforꢀSubsequentꢀ
ECDSA Signing
●ꢀ 1024ꢀBitꢀofꢀUserꢀEEPROMꢀOrganizedꢀasꢀFourꢀPagesꢀ
ofꢀ256ꢀBits
●ꢀ ProgrammableꢀandꢀIrreversibleꢀUserꢀEEPROMꢀ
Protection Modes Including Write Protection, Read
Protection, and OTP/EPROM Emulation for Individual
Memory Pages
●ꢀ UniqueꢀFactory-Programmedꢀ64-BitꢀIdentificationꢀ
Number
●ꢀ Single-Contactꢀ1-WireꢀInterfaceꢀCommunicatesꢀwithꢀ
HostꢀatꢀUpꢀtoꢀ76.9kbps
●ꢀ OperatingꢀRange:ꢀ3.3Vꢀ±10%,ꢀ-40ºCꢀtoꢀ+85ºC
●ꢀ ±8kVꢀHBMꢀESDꢀProtectionꢀ(typ)ꢀforꢀIOꢀPin
●ꢀ 8-PinꢀTDFNꢀandꢀ6-PinꢀTSOCꢀPackages
®
the single-contact 1-Wire bus at overdrive speed. The
communication follows the 1-Wire protocol with the ROM
ID acting as node address in the case of a multi-device
1-Wire network.
Typical Application Circuit
3.3V
Applications
●ꢀ AuthenticationꢀofꢀConsumables
R1
10kΩ
●ꢀ PeripheralꢀAuthentication
●ꢀ MedicalꢀSensors
V
CC
PIOX
PIOY
●ꢀ PrinterꢀCartridgeꢀIdentificationꢀandꢀAuthentication
Q1
R
PUP
DS28E35
IO
BSS84
µC
Ordering Information appears at end of data sheet.
1-WIRE
For related parts and recommended products to use with this part, refer
to www.maximintegrated.com/DS28E35.related.
GND
GND
DeepCover and 1-Wire are registered trademarks of Maxim
Integrated Products, Inc.
219-0028; Rev 4; 4/14