AT88SC0808/1616/3216/6416CRF, AT88RF04C
J.2.1.
M = 001b Security – Dual Access Authentication Mode
When M = 001b Authentication is required for Read or Write access to the User Zone. If Authentication is performed
with the key identified in the POK bits of the Password Register, then Read and Program-Only access is granted to the
User Zone. In this state data may be changed from "1b" to "0b", but never from "0b" to "1b".
If Authentication is performed with the key identified in the AK bits of the Password Register, then full Read/Write
access is granted to the User Zone. A checksum is required for write operations.
J.2.2. M = 011b Security – Authentication for Read / Write
When M = 011b Authentication is required for Read or Write access to the User Zone. If Authentication is performed
with the key identified in the AK bits of the Password Register, then Read/Write access is granted to the User Zone. A
checksum is required for write operations.
J.2.3. M = 101b Security – Authentication for Write
When M = 101b Authentication is required for Write access to the User Zone. If Authentication is performed with the
key identified in the AK bits of the Password Register, then Read/Write access is granted to the User Zone. Read-Only
access does not require Authentication or Encryption Activation. A checksum is required for write operations.
J.3.
Authentication Security Options [88RF]
Authentication Communication Security for a User Zone is enabled by programming the Access Register (AR) and Key
Register (KR) for the zone. The Communication Security Mode (M) bits of the Access Register determine the
Communication Security requirements for the User Zone. The Key Register determines which Key Set(s) are used to
access the User Zone. Configuration of the AR and KR registers is described in Appendix H.
Table 83. Selecting Authentication using the Communication Security Mode bits of the Access Register.
M2
M1
M0
Communication Security Mode
Primary Key (PK) Read-Only Key (ROK)
0
1
0 Authentication for Read / Encryption for Write
Read / Write Access
Read Access
0
1
1 Authentication for Read / Write
Read / Write Access
Read Access
1
0
1 Authentication for Write
Read / Write Access
N/A
1
1
1 No Authentication or Encryption Required
N/A
N/A
Table 83 shows the three 88RF PICC Authentication Security options, plus the default setting. By default M = 111b and
no Authentication or Encryption Activation is required to access the user memory.
J.3.1. M = 010b Security - Authentication for Read / Encryption for Write
When M = 010b Authentication is required for Read access to the User Zone. Encryption Activation is required for Write
Access to the User Zone. If Authentication is performed with the key identified in the ROK bits of the Key Register, then
Read-Only access is granted to the User Zone. If Encryption Activation is performed with the key identified in the PK
bits of the Key Register, then Read/Write access is granted to the User Zone. A checksum is required for write
operations.
The M = 010b mode is a new feature in 88RF PICCs. This mode is not available in 88SC devices.
J.3.2. M = 011b Security - Authentication for Read / Write
When M = 011b Authentication is required for Read or Write access to the User Zone. If Authentication is performed
with the key identified in the PK bits of the Key Register, then Read/Write access is granted to the User Zone. If
Authentication is performed with the key identified in the ROK bits of the Key Register, then Read-Only access is
granted to the User Zone. A checksum is required for write operations.
If the PK and ROK bits of the Key Register select the same Key Set, then the Read-Only function is effectively
disabled. Authenticating 88RF PICCs with the PK key results in behavior identical to 88SC devices. The Read-Only
function is not supported by 88SC devices.
5276C–RFID–3/09
107