HCS320 HCS320 KEELOQ Code Hopping Encoder FEATURES DESCRIPTION The HCS320 from Microchip Technology Inc. is a code Security hopping encoder designed for secure Remote Keyless Programmable 28-bit serial number Entry (RKE) systems. The HCS320 utilizes the code hopping technology which incorporates high security, a Programmable 64-bit encryption key small package outline, and low cost, to make this Each transmission is unique device a perfect solution for unidirectional remote key- 66-bit transmission code length less entry systems and access control systems. 32-bit hopping code 34-bit fixed code (28-bit serial number, PACKAGE TYPES 4-bit function code, 2-bit status) Encryption keys are read protected PDIP, SOIC 8 S0 VDD 1 Operating LED 7 2 S1 3.5V - 13.0V operation Shift key and three inputs 6 PWM 3 S2 16 functions available VSS SHIFT 4 5 Selectable baud rate Automatic code word completion Battery low signal transmitted to receiver HCS320 BLOCK DIAGRAM Battery low indication on LED Oscillator Non-volatile synchronization data Power latching and Controller RESET circuit switching Other LED LED driver Easy-to-use programming interface On-chip EEPROM On-chip oscillator and timing components EEPROM Encoder Button inputs have internal pull-down resistors Current limiting on LED output PWM Low external component cost 32-bit shift register Typical Applications VSS Button input port The HCS320 is ideal for Remote Keyless Entry (RKE) VDD applications. These applications include: Automotive RKE systems S SHIFT S S 2 Automotive alarm systems 1 0 Automotive immobilizers The HCS320 combines a 32-bit hopping code gener- Gate and garage door openers ated by a nonlinear encryption algorithm, with a 28-bit Identity tokens serial number and six status bits to create a 66-bit Burglar alarm systems transmission stream. The length of the transmission eliminates the threat of code scanning and the code hopping mechanism makes each transmission unique, thus rendering code capture and resend (code grab- bing) schemes useless. 2001 Microchip Technology Inc. DS41097C-page 1HCS320 The crypt key, serial number and configuration data are Learn Learning involves the receiver calculating stored in an EEPROM array which is not accessible via the transmitters appropriate crypt key, decrypting any external connection. The EEPROM data is pro- the received hopping code and storing the serial grammable but read-protected. The data can be veri- number, synchronization counter value and crypt fied only after an automatic erase and programming key in EEPROM. The KEELOQ product family facil- operation. This protects against attempts to gain itates several learning strategies to be imple- access to keys or manipulate synchronization values. mented on the decoder. The following are The HCS320 provides an easy-to-use serial interface examples of what can be done. for programming the necessary keys, system parame- - Simple Learning ters and configuration data. The receiver uses a fixed crypt key, common to all components of all systems by the same manufacturer, to decrypt the received code 1.0 SYSTEM OVERVIEW words encrypted portion. Key Terms - Normal Learning The receiver uses information transmitted The following is a list of key terms used throughout this during normal operation to derive the crypt data sheet. For additional information on KEELOQ and key and decrypt the received code words Code Hopping, refer to Technical Brief 3 (TB003). encrypted portion. RKE - Remote Keyless Entry - Secure Learn Button Status - Indicates what button input(s) The transmitter is activated through a special activated the transmission. Encompasses the 4 button combination to transmit a stored 60-bit button status bits S3, S2, S1 and S0 (Figure 4-2). seed value used to generate the transmitters Code Hopping - A method by which a code, crypt key. The receiver uses this seed value viewed externally to the system, appears to to derive the same crypt key and decrypt the change unpredictably each time it is transmitted. received code words encrypted portion. Code word - A block of data that is repeatedly Manufacturers code A unique and secret 64- transmitted upon button activation (Figure 4-1). bit number used to generate unique encoder crypt Transmission - A data stream consisting of keys. Each encoder is programmed with a crypt repeating code words (Figure 8-2). key that is a function of the manufacturers code. Crypt key - A unique and secret 64-bit number Each decoder is programmed with the manufac- used to encrypt and decrypt data. In a symmetri- turer code itself. cal block cipher such as the KEELOQ algorithm, The HCS320 code hopping encoder is designed specif- the encryption and decryption keys are equal and ically for keyless entry systems primarily vehicles and will therefore be referred to generally as the crypt home garage door openers. The encoder portion of a key. keyless entry system is integrated into a transmitter, Encoder - A device that generates and encodes carried by the user and operated to gain access to a data. vehicle or restricted area. The HCS320 is meant to be Encryption Algorithm - A recipe whereby data is a cost-effective yet secure solution to such systems, scrambled using a crypt key. The data can only be requiring very few external components (Figure 2-1). interpreted by the respective decryption algorithm Most low-end keyless entry transmitters are given a using the same crypt key. fixed identification code that is transmitted every time a Decoder - A device that decodes data received button is pushed. The number of unique identification from an encoder. codes in a low-end system is usually a relatively small Decryption algorithm - A recipe whereby data number. These shortcomings provide an opportunity scrambled by an encryption algorithm can be for a sophisticated thief to create a device that grabs unscrambled using the same crypt key. a transmission and retransmits it later, or a device that quickly scans all possible identification codes until the correct one is found. The HCS320 on the other hand, employs the KEELOQ code hopping technology coupled with a transmission length of 66 bits to virtually eliminate the use of code grabbing or code scanning. The high security level of the HCS320 is based on the patented KEELOQ technol- ogy. A block cipher based on a block length of 32 bits and a key length of 64 bits is used. The algorithm obscures the information in such a way that even if the transmission information (before coding) differs by only one bit from that of the previous transmission, the next DS41097C-page 2 2001 Microchip Technology Inc.