Microcontrollers combine safety and security with full-automotive software

This article describes in detail the features of a new MCU series specialized for automotive applications.


By Danny Basler, NXP                                                     Download PDF version of this article


Carmakers are in a race to change, with in-car functions evolving as the market moves from motor vehicles towards mobility platforms. Even relatively static body applications like doors, steering wheels, seats, climate control and lighting systems are getting a makeover.

Figure 1. S32K1 MCU block diagram

 

To help meet these challenges, NXP has introduced the S32K family of automotive microcontrollers (MCUs). The 32-bit ARM Cortex-based MCUs are the latest AEC-Q100 qualified, high-reliability products to address this segment. Leveraging the legacy of more than 60 years of experience and expertise, the S32K family offers new opportunities for end product differentiation in secure, connected vehicle edge nodes. Broad family scalability includes the following. Compatible MCU families with multiple performance, feature and pin-count options for fast, efficient end product platform evolution including a memory range from 128 KB to 2 MB, pin count from 32 to 176 pins, QFN, LQFP, MAPBGA packages, and IP compatibility across families. Next generation processing and peripherals – ARM Cortex-M class cores, CAN FD, robust hardware security, and low power consumption. Comprehensive software solution – automotive-grade Software Development Kit (SDK), S32 Design Studio IDE and third-party ecosystem support.

Figure 2. CAN FD frame

 

The S32K1 series consists of six MCU families spanning from 128 KB to 2 MB of flash memory. Use of area efficient 90nm Thin Film Storage (TFS) process technology allows a high level of on-chip feature integration while keeping MCU cost accessible to body node applications price points. Fast, low voltage transistors and distributed charge structure in the bit cell ensure fast access times and high immunity to leakage. MCUs operate from 2.7 to 5.5 V and feature a range of next-generation and market-proven digital and analog IP suitable for electrically harsh environments at up to 125°C ambient temperature.

Traditional body control MCU performance is being increasingly stretched. Interpreting complex sensor algorithms, managing high bandwidth communication peripherals and implementing advanced security features for stored and transmitted data are now common requirements in even modest ECUs. Performance headroom must also be considered for evolving software requirements such as the AUTOSAR standard, where a 10 to15% overhead is typical. The MCU series meets this need through use of the DSP enabled ARM Cortex-M4 and ultra-low power ARM Cortex-M0+ cores on the K14x and K11x families respectively. Operating frequency ranges from 48 to 112 MHz and is supplemented by a variety of proprietary acceleration technology. Extensive DMA support and crossbar switch technology streamline data throughput through reduced CPU loading, while on-chip I/D cache reduces memory access latencies. MCUs of this family also feature a bit manipulation engine (BME) that reduces code size and execution time by an average of 40% when performing bit-oriented math operations.

With 100 ECUs now common in even mid-size cars, in-vehicle networking and end-of-line programming requirements are considerable and place an increasing demand on classic CAN 2.0 bus bandwidth. Layering security functions on top requires more memory and bus utilization to implement cryptographic functions. The MCUs include up to 3 ISO-compliant CAN FD modules which increase the data rate from 500 kb/s (typical) to 2 Mb/s in normal mode and up to 5 Mb/s in programming mode. A new message frame format expands the data field from 8 to 64 bytes reducing data overhead and increasing protocol efficiency. The MCUs can operate in dedicated CAN FD networks or mixed CAN 2.0/CAN FD ones where nodes are upgraded on a case-by-case basis.

Figure 3. Cryptographic Services Engine compressed (CSEc) module

 

NXP has been at the leading edge of automotive MCU security for many years with several generations of hardware peripherals in powertrain, safety and gateway MCUs. This capability now extends down to body applications with the new Cryptographic Services Engine compressed (CSEc) which has been optimized for smaller memory MCUs. Compliant with the SHE (Secure Hardware Extension) standard, and EVITA-Low (E-safety Vehicle Intrusion Protected Applications) guidelines, the CSEc features a dedicated security co-processor and provides secure key storage, AES-128 encryption and decryption, and secure boot functions.

Using the internal 32-bit CSEc co-processor, firmware and a hardware-assisted AES-128 sub-block, the flash memory module enables encryption, decryption and Cipher-based Message Authentication Code (CMAC) algorithms for secure messaging. Two secure blocks of flash memory are pre-programmed with firmware, a unique identification number (UID) and a secret key (SK) - a random number whose value is never disclosed. The unique identifier (UID) is 120 bits long and programmed during manufacture ensuring no two MCUs contain identical keys. Furthermore, establishing the value of the keys in secure flash would require a huge effort and with each key being unique, even compromised keys would be useless for attacking other systems.

At system boot the CSEc core executes boot code from a dedicated ROM which then loads the firmware from secure flash into RAM and starts executing. This reduces the flash accesses by the CSEc’s core on the crossbar thereby avoiding any impact on MCU system performance. If the secure boot code authentication fails, the application may offer a reduced level of functionality, or set a flag to deny use of the keys stored in secure flash. Use cases for the CSEc module are numerous and include mileage tamper prevention, component authentication and secure telematics.

The MCU family feature a range of low power architectural techniques, operating modes, and autonomous peripherals with low power functionality. At a foundational level the 90nm TFS process technology delivers a significant reduction in dynamic power vs. comparable technologies. Extending this is the option to de-rate the clock frequency during periods when maximum performance is not required. With the MCU clock tree accounting for most of the power consumption (up to 30% in some designs), clock gating is available for many peripherals while a low power boot feature can configure default clock settings to reduce losses during the boot phase. For the most extreme application power profiles, memories and peripherals can also be power-gated when inactive. The MCUs contain 3 active and 4 standby operating modes each accompanied by multiple wake-up sources. In all modes, all memory and register contents are maintained which simplifies software handling especially in AUTOSAR related applications. These are: RUN modes – high speed RUN (HSRUN) mode allows over-drive conditions of up to 112 MHz whereas standard RUN mode limits the CPU clock to a maximum of 80 MHz. VLPR (very low power RUN) is new for automotive use cases and de-rates the core to 4 MHz while using a very low Idd for flash memory access. Here the internal regulator is placed in standby with full peripheral and low voltage detect functionality maintained. WAIT and very low power WAIT (VLPW) modes – similar to their equivalent run modes but the CPU is halted and flash memory and FlexMemory (EEPROM) programming is disabled. With interrupts enabled, the MCU can exit WAIT modes, perform the scheduled task and then quickly return to a low power state. This minimizes average power in applications that frequently toggle between active and reduced power states with savings of 30 to 60% achievable over RUN mode. STOP and VLPS – deep sleep modes where all I/O pins and several peripherals can function as wake-up sources. These have slightly longer wake-up times and are suited for applications where wake-up occurs infrequently. Current consumption at 25°C in VLPS mode starts from as low as 25µA with a recovery time of approximately 5µs.

Several of the analog, communication and timing peripherals can also perform basic timekeeping and monitoring tasks autonomously and in low power states. These include LPUARTs that can asynchronously transmit/receive LIN messages, and ADCs (1 Msps capable) that operate in low power states and activate when a threshold value has been reached. The DMA controller also allows data transfers in STOP/VLPS with the core inactive and minimal clocks enabled.

Figure 4. S32K software development kit

 

A typical body application use case would be fast sensor input measurement with power-up when pre-defined conditions have been met. This would be accomplished using the on-chip 128 kHz IRC (internal RC oscillator) to clock an API to wake the MCU every 10ms and toggle between VLPS and RUN mode. On power-up the MCU would switch to its 48 MHz IRC for fast execution. Conversely, in a slow sensor application the MCU would operate in VLPS using an 8 MHz IRC for reduced 4 MHz execution. When the sensor setting time has completed and data becomes available, the API would then change from VLPS to VLPR resulting in a much lower peak current. Another peripheral worth mentioning is the new FlexIO module. Highly configurable, it can emulate various communication peripherals – UART, I2C, SPI, and I2S – or generate 16-bit timers with support for trigger, reset, enable and disable conditions. Compared with GPIO software emulation schemes, the FlexIO module requires less CPU overhead and can operate in all power and debug modes.

The MCUs are members of the NXP SafeAssure program and target the ASIL B integrity level with higher level compliance possible based on system level redundancies. Devices are designed in accordance with the ISO26262 standard with hardware and system level safety measures and comprehensive safety documentation. Features consist of error correcting code (ECC) on flash and RAM memories, a memory protection unit (MPU) for assigning secure access rights, internal and external watchdogs, a cyclic redundancy check (CRC) block and a structural core self-test library (SCST) for detecting permanent faults in the core. Detailed safety manual and FMEDA documentation is available to support system level certification.

The MCUs are supported by a range of automotive-grade development tools to speed and simplify the software development process. S32 Design Studio (S32 DS) is a free of charge, unlimited code size, Eclipse-based IDE with plug-in support. Using the Processor Expert tool included into S32 Design Studio, developers can configure the peripherals (internal and external) and software functionality using a simple GUI. The tool then generates highly optimized embedded C-code saving a huge amount of manual development effort.

For applications that do not require AUTOSAR support, an automotive-grade software development kit (SDK) is available. The SDK consists of free of charge peripheral drivers, the FreeRTOS operating system and application-specific middleware. MISRA 2012 and SPICE Level 3 compliant, the SDK comes pre-installed within the S32 DS IDE and is also compatible with third party compilers and debuggers including those from third party IAR Systems. The SDK plug-in for Design Studio greatly reduces the development effort, thanks to its GUI, where the developer can configure and drag and drop software functions to use the peripheral drivers.

With robust, high speed timers and analog peripherals, S32K MCUs are well suited to the growing number of in-car electric motor applications – fuel/oil/water pumps, HVAC systems and seats/mirrors. To assist developers a range of design tools are offered: embedded Automotive Math and Motor Control Library (AMMCLIB), Motor Control Toolbox for Matlab model-based design), and the FreeMASTER run-time debug monitor with Motor Control Application Tuner (MCAT) plug-in.


Related


Slimming program for medical operating devices

Operating devices in the medical sector are not only subject to strict controls and requirements. Nowadays design demands are becoming more and more important for developers of medical HMI devices. De...

Establishing a root of trust to secure the IoT

Security is not something that any developer can ignore. It is no longer safe, for the OEM or their customers, to assume that their product or service is immune to cyber attacks. The sheer size of the...

 

Perfect Motion Control For the Networked World

We live in a physical world where everything is connected. Trinamic transforms digital information into physical motion with accessible, flexible, and easy to use toolkits putting the world’s be...


New High-Performance Serial NAND: A Better High-Density Storage Option for Automotive Display

The automotive requirements: speed, reliability and compatibility. Winbond's high-performance serial NAND Flash technology offers both cost and performance advantages over the SPI NOR Flash typica...


President Tung-Yi talks about Winbond

Winbond is a leading specialty memory solution provider with a wide rage of product portfolio. Owned technology and innovation are our assets for our industry and our customers. Winbond we are high qu...


New Memory and Security Technologies for Designers of IoT Devices

Internet of Things (IoT) edge nodes are battery-powered, often portable, and are connected to an internet gateway or access point wirelessly. This means that the most important constraints on new I...


Winbond TrustMe Secure Flash - A Robust and Certifiable Secure Storage Solution

Winbond has introduced the TrustMe secure flash products to address the challenge of combining security with advanced process nodes and remove the barriers for adding secure non-volatile storage to pr...


Ultra-Low-Power DRAM: A “Green” Memory in IoT Devices

Winbond is offering a new way to extend the power savings available from Partial Array Self-Refresh (PASR), which was already specified in the JEDEC standard by implementing a new Deep Self-Refresh (D...


Polytronics Thermal Conductive Board (TCB) at Electronica 2018

This video introduce the basic product structure, advantage, and application of Polytronics thermal conductive board (TCB). Polytronics exhibit wide range of circuit protection products and thermal ma...


Arrow and Analog Devices strategic partnership and collaborative approach to provide solutions for our customers.

Mike Britchfield (VP for EMEA Sales) talks about why Analog Devices have a collaborative approach with Arrow Arrow’s design resources are key, from regional FAEs in the field to online des...


WE MAKE IT YOURS! Garz & Fricke to present the latest HMIs and SBCs at Electronica 2018

Sascha Ulrich, Head of Sales at Garz & Fricke, gives you a quick overview about the latest SBC, HMI and Panel-PC Highlights at electronica 2018. Learn more about the SANTOKA 15.6 Outdoor HMI, the ...


Macronix Innovations at electronica 2018

Macronix exhibited at electronica 2018 to showcase its latest innovations: 3D NAND, ArmorFlash secure memory, Ultra Low Vcc memory, and the NVM solutions with supreme quality mainly focusing on Automo...


ams CEO talks about their sensor solutions that define the mega trends of the future

In this video Alexander Everke, ams’ CEO, talks to Alix Paultre of EETimes about their optical, imaging and audio sensor solutions in fast-growing markets – from smartphones, mobile device...


Intel accelerated IoT Solutions by Arrow

Arrow is showing Intel’s Market Ready Solutions in a Retailer shop with complete eco environment. From sensors via gateways into the cloud, combined with data analytics, the full range of Intel ...


CSTAR - Manufacturers of cable assembly from Taiwan

CSTAR was founded in 2010 in Taipei, Taiwan. Through years of experience, we are experts in automotive products, LCD displays, LCD TVs, POS, computers, projectors, laptops, digital cameras, medical ca...


NXP Announces LPC5500 MCU Series

Check this video to discover the new NXP microcontroller LPC5500, the target application and focus area. Links to more information: LPC5500 Series: World’s First Arm® Cortex® -M...


Molex Meets Solutions at Electronica

These are exciting times in the electronics world as Molex migrates from a pure connectors company to an innovate solutions provider. Solutions often start at the component level, such as the connecto...


Alix Paultre investigates Bulgin's new optical fiber rugged connector range at Electronica 2018

Alix Paultre interviews Bulgin's Engineering Team Leader Christian Taylor to find out more about the company's new range of optical fiber connectors for harsh environments. As the smallest rug...


Cypress MCU and Connectivity are the best choice for real-world IoT solutions.

Cypress’ VP of Applications, Alan Hawse, explains why people should use Cypress for their IoT connectivity and MCU needs. Cypress wireless connectivity and MCU solutions work robustly and sea...


Chant Sincere unveils their latest High Speed/High Frequency connection solutions at Electronica 2018

Chant Sincere has been creating various of product families to provide comprehensive connection solutions to customers. USB Series Fakra Series QSFP Series Metric Connector Series Fibro ...


Addressing the energy challenge of IoT to unleash billions of devices

ON Semiconductor introduces various IoT use cases targeted towards smart homes/buildings, smart cities, industrial automation and medical applications on node-to-cloud platforms featuring ultra-low po...


ITECH, world leading manufacturer of power test instruments, shinned on electronica 2018

ITECH, as the leading power electronic instruments manufacturer, attended this show and brought abundant test solutions, such as automotive electronics, battery test, solar array simulator, and electr...


ITECH new series give users a fantastic user experience

ITECH latest series products have a first look at the electronics 2018, such as IT6000B regenerative power system, IT6000C bi-directional programmable DC power supply, IT6000D high power programmable ...


SOTB™ Process Technology - Energy Harvesting in Embedded Systems is Now a Reality

Exclusive SOTB technology from Renesas breaks the previous trade-off between achieving either low active current or low standby current consumption – previously you could only choose one. With S...


Power Integrations unveils their new motor control solution

In this video friend of the show Andy Smith of Power Integrations talks to Alix Paultre from Aspencore Media about their new BridgeSwitch ICs, which feature high- and low-side advanced FREDFETs (Fast ...


Panasonic talks about their automotive technology demonstrator

In this video Marco from Panasonic walks Alix Paultre of Aspencore Media through their automotive technology demonstrator at electronica 2018. The demonstrator highlights various vehicle subsystems an...