|
If you can't view the Datasheet, Please click here to try to view without PDF Reader . |
|
Datasheet File OCR Text: |
1/55 august 2005 M28W320FST, m28w320fsb, m28w640fsb, m28w640fst 32mbit (2mb x16) and 64mbit (4mb x16) 3v supply, boot block, secure flash memories features summary supply voltage ?v dd = 2.7v to 3.6v core power supply ?v ddq = 1.65v to 3.6v for input/output ?v pp = 12v for fast program (optional) access time: 70ns programming time: ? 10s typical ? double word programming option ? quadruple word programming option common flash interface memory blocks ? parameter blocks (top or bottom location) ? main blocks hardware protection ?v pp pin for write protect of all blocks security features ? 128 bit user-programmable otp segment ? 64 bit unique device identifier ? krypto features: modify protection, read protection, device authentication automatic stand-by mode program and erase suspend 100,000 program/erase cycles per block electronic signature ? manufacturer code: 20h ? device codes: M28W320FST: 880ah, m28w320fsb: 880bh m28w640fst: 8858h, m28w640fsb: 8859h ecopack ? package available figure 1. package bga tbga64 (za) 10 x 13mm
M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 2/55 table of contents features summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1 figure 1. package. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1 summary description. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5 table 1. m28w320fs and m28w640fs memory architecture. . . . . . . . . . . . . . . . . . . . . . . . . . . . 5 figure 2. m28w320fs logic diagram . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6 figure 3. m28w640fs logic diagram . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6 table 2. signal names . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6 figure 4. tbga connections (top view through package) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 figure 5. M28W320FST and m28w320fsb block addresses . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8 figure 6. m28w640fst and m28w640fsb block addresses . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9 figure 7. protection register memory map . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9 signal descriptions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 address inputs. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 data input/output (dq0-dq15). . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 chip enable (e ). . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .10 output enable (g ). . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 write enable (w ). . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1 0 reset (rp ). . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 v dd supply voltage. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 v ddq supply voltage. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 v pp program supply voltage . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .10 v ss ground. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 bus operations. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 read. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 write. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 output disable. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 standby. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 automatic standby. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 reset. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 table 3. bus operations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 hardware protection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12 v pp v pplk . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12 security features . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12 command interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13 read memory array command . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13 read status register command . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1 3 read electronic signature command . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13 3/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb table 4. command codes. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13 read cfi query command . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .13 block erase command . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13 program command . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14 double word program command . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14 quadruple word program command . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14 clear status register command . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14 program/erase suspend command . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14 program/erase resume command . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15 protection register program command . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15 table 5. commands . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16 table 6. read electronic signature . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .16 table 7. read protection register and protection register lock . . . . . . . . . . . . . . . . . . . . . . . . . 17 table 8. program, erase times and program/erase endurance cycles . . . . . . . . . . . . . . . . . . . 18 status register . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19 program/erase controller status (bit 7) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .19 erase suspend status (bit 6) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19 erase status (bit 5) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19 program status (bit 4) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19 v pp status (bit 3). . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19 program suspend status (bit 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19 block protection status (bit 1). . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20 reserved (bit 0). . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20 table 9. status register bits . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20 maximum rating. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21 table 10. absolute maximum ratings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2 1 dc and ac parameters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22 table 11. operating and ac measurement conditions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22 figure 8. ac measurement i/o waveform . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22 figure 9. ac measurement load circuit. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22 table 12. capacitance. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22 table 13. dc characteristics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23 figure 10.read ac waveforms. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24 table 14. read ac characteristics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24 figure 11.write ac waveforms, write enable controlled . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25 table 15. write ac characteristics, write enable controlled . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26 figure 12.write ac waveforms, chip enable controlled . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27 table 16. write ac characteristics, chip enable controlled . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 28 figure 13.power-up and reset ac waveforms . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 29 table 17. power-up and reset ac characteristics. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 29 package mechanical . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 30 figure 14.tbga64 - 10x13 active ball array, 1mm pitch, bottom view package outline . . . . . . . . 30 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 4/55 table 18. tbga64 - 10x13 active ball array, 1mm pitch, package mechanical data . . . . . . . . . . . 30 part numbering . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 31 table 19. ordering information scheme . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 1 table 20. daisy chain ordering scheme . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 32 appendix a.block address tables . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33 table 21. top boot block addresses, M28W320FST . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33 table 22. bottom boot block addresses, m28w320fsb . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34 table 23. top boot block addresses, m28w640fst . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35 table 24. bottom boot block addresses, m28w640fsb . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 37 appendix b.common flash interface (cfi) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 39 table 25. query structure overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .39 table 26. cfi query identification string. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .39 table 27. cfi query system interface information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 40 table 28. device geometry definition . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .41 table 29. primary algorithm-specific extended query table . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 43 table 30. security code area . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 44 appendix c.flowcharts and pseudo codes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 45 figure 15.program flowchart and pseudo code . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 45 figure 16.double word program flowchart and pseudo code . . . . . . . . . . . . . . . . . . . . . . . . . . . 46 figure 17.quadruple word program flowchart and pseudo code. . . . . . . . . . . . . . . . . . . . . . . . . 47 figure 18.program suspend & resume flowchart and pseudo code . . . . . . . . . . . . . . . . . . . . . . 48 figure 19.erase flowchart and pseudo code. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 49 figure 20.erase suspend & resume flowchart and pseudo code . . . . . . . . . . . . . . . . . . . . . . . . 50 figure 21.protection register program flowchart and pseudo code. . . . . . . . . . . . . . . . . . . . . . . 51 appendix d.command interface and program/erase controller state. . . . . . . . 52 table 31. write state machine current/next, sheet 1 of 2. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 52 table 32. write state machine current/next, sheet 2 of 2. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 53 revision history. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 54 table 33. document revision history . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 54 5/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb summary description the m28w320fs and m28w640fs are 32 mbit (2mbit x 16) and 64 mbit (4mbit x 16) secure flash memories. the devices can be erased electrically at block level and programmed in-system on a word-by-word basis using a 2.7v to 3.6v v dd supply for the circuitry and a 1.65v to 3.6v v ddq supply for the input/output pins. an optional 12v v pp power supply is provided to speed up custom- er programming. the m28w320fs and m28w640fs feature 32mbit and 64 mbits respectively and have an asymmetrical block architecture with 4 kword pa- rameter blocks and 32 kword main blocks. the M28W320FST and m28w640fst have the pa- rameter blocks at the top of the memory address space while the m28w320fsb and m28w640fsb locate the parameter blocks start- ing from the bottom. refer to table 1. , figure 5. and figure 6. for a detailed description of the de- vices memory architecture and map. all devices are equipped with hardware and soft- ware block protection features to avoid unwanted program/erase (modify) or read of the flash mem- ory content: hardware protection: ? when v pp v pplk all blocks are protected against program or erase. software protection thanks to krypto security features: ? modify protection: volatile and non- volatile. ? read protection. the krypto security features are described in a dedicated application note. please contact stmi- croelectronics for further details. two registers are available for protection purpose: the protection register the krypto protection register. the protection register is a 192 bit protection register to increase the protection of a system de- sign. the protection register is divided into a 64 bit segment and a 128 bit segment. the 64 bit seg- ment contains a unique device number written by st, while the second one is one-time-programma- ble by the user. the user programmable segment can be permanently protected. figure 7. , shows the protection register memory map. the krypto protection register is used to man- age the modify and read protection modes. it also features a device authentication mechanism. the krypto protection register is described in a dedicated application note. please contact stmi- croelectronics for further details. each block can be erased separately. erase can be suspended in order to perform either read or program in any other block and then resumed. program can be suspended to read data in any other block and then resumed. each block can be programmed and erased over 100,000 cycles. program and erase commands are written to the command interface of the memory. an on-chip program/erase controller takes care of the tim- ings necessary for program and erase operations. the end of a program or erase operation can be detected and any error conditions identified. the command set required to control the memory is consistent with jedec standards. all the devices are offered in a tbga64 (10 x 13mm) package. in order to meet environmental requirements, st offers the m28w320fs and m28w640fs in eco- pack ? packages. ecopack packages are lead-free. the category of second level intercon- nect is marked on the package and on the inner box label, in compliance with jedec standard jesd97. the maximum ratings related to solder- ing conditions are also marked on the inner box la- bel. ecopack is an st trademark. ecopack speci- fications are available at: www.st.com. all devices are supplied with all the bits erased (set to ?1?). table 1. m28w320fs and m28w640fs memory architecture note: 1. erasable block size. device parameter blocks main blocks no. of blocks block size (1) no. of blocks block size m28w320fs 8 4 kwords 63 32 kwords m28w640fs 8 4 kwords 127 32 kwords M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 6/55 figure 2. m28w320fs logic diagram figure 3. m28w640fs logic diagram table 2. signal names ai09925 21 a0-a20 w dq0-dq15 v dd M28W320FST m28w320fsb e v ss 16 g rp v ddq v pp ai09909 22 a0-a21 w dq0-dq15 v dd m28w640fst m28w640fsb e v ss 16 g rp v ddq v pp M28W320FST and m28w320fsb m28w640fst and m28w640fsb signal names a0-a20 a0-a21 address inputs dq0-dq15 data input/output e chip enable g output enable w write enable rp reset v dd core power supply v ddq power supply for input/output v pp optional supply voltage for fast program & erase v ss ground nc not connected internally 7/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb figure 4. tbga connections (top view through package) note: 1. the above figure gives the tbga connections for m28w640fst and m28w640fsb. on M28W320FST and m28w320fsb devic- es, a21 is nc. ai09910b dq6 a0 v ssq v dd dq10 v dd dq7 dq5 v ddq dq2 h dq14 v ss dq13 d a15 a19 e a8 c a16 a20 a10 a14 nc a7 b nc a18 a1 a12 a13 a 8 7 6 5 4 3 2 1 a6 a2 a3 a4 g f e dq0 nc a5 v pp a21 a17 a9 a11 rp dq15 nc dq9 dq8 dq1 dq4 dq3 g dq12 dq11 w v ss nc nc nc nc nc nc nc nc nc nc nc M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 8/55 figure 5. M28W320FST and m28w320fsb block addresses ai09931 4 kwords 1fffff 1ff000 32 kwords 00ffff 008000 32 kwords 007fff 000000 M28W320FST top boot block addresses 4 kwords 1f8fff 1f8000 32 kwords 1f0000 1f7fff total of 8 4 kword blocks total of 63 32 kword blocks 4 kwords 1fffff 1f8000 32 kwords 32 kwords 000fff 000000 m28w320fsb bottom boot block addresses 4 kwords 1f7fff 00ffff 32 kwords 1f0000 008000 total of 63 32 kword blocks total of 8 4 kword blocks 007fff 007000 9/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb figure 6. m28w640fst and m28w640fsb block addresses note: also see appendix a. , tables 23 and 24 for a full listing of the block addresses. figure 7. protection register memory map ai09911 4 kwords 3fffff 3ff000 32 kwords 00ffff 008000 32 kwords 007fff 000000 m28w640fst top boot block addresses 4 kwords 3f8fff 3f8000 32 kwords 3f0000 3f7fff total of 8 4 kword blocks total of 127 32 kword blocks 4 kwords 3fffff 3f8000 32 kwords 32 kwords 000fff 000000 m28w640fsb bottom boot block addresses 4 kwords 3f7fff 00ffff 32 kwords 3f0000 008000 total of 127 32 kword blocks total of 8 4 kword blocks 007fff 007000 ai05520b user programmable otp unique device number protection register lock 1 0 8ch 85h 84h 81h 80h protection register M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 10/55 signal descriptions see figures 2 and 3 , logic diagrams and table 2., signal names , for a brief overview of the sig- nals connected to this device. address inputs. the address inputs select the cells in the memory array to access during bus read operations. address inputs range from a0 to a20 for the m28w320fs. the m28w640fs has an additional a21 address line. during bus write operations they control the commands sent to the command interface of the internal state machine. data input/output (dq0-dq15). the data i/o outputs the data stored at the selected address during a bus read operation or inputs a command or the data to be programmed during a write bus operation. chip enable (e ). the chip enable input acti- vates the memory control logic, input buffers, de- coders and sense amplifiers. when chip enable is at v il and reset is at v ih the device is in active mode. when chip enable is at v ih the memory is deselected, the outputs are high impedance and the power consumption is reduced to the stand-by level. output enable (g ). the output enable controls data outputs during the bus read operation of the memory. write enable (w ). the write enable controls the bus write operation of the memory?s command interface. the data and address inputs are latched on the rising edge of chip enable, e, or write en- able, w , whichever occurs first. reset (rp ). the reset input provides a hard- ware reset of the memory. when reset is at v il , the memory is in reset mode: the outputs are high impedance and the current consumption is mini- mized. after reset all blocks are in the locked state. when reset is at v ih , the device is in normal operation. exiting reset mode the device enters read array mode, but a negative transition of chip enable or a change of the address is required to ensure valid data outputs. v dd supply voltage. v dd provides the power supply to the internal core of the memory device. it is the main power supply for all operations (read, program and erase). v ddq supply voltage. v ddq provides the power supply to the i/o pins and enables all outputs to be powered independently from v dd . v ddq can be tied to v dd or can use a separate supply. v pp program supply voltage. v pp is both a control input and a power supply pin. the two functions are selected by the voltage range ap- plied to the pin. the supply voltage v dd and the program supply voltage v pp can be applied in any order. if v pp is kept in a low voltage range (0v to 3.6v) v pp is seen as a control input. in this case a volt- age lower than v pplk gives an absolute protection against program or erase, while v pp > v pp1 en- ables these functions (see table 13., dc charac- teristics , for the relevant values). v pp is only sampled at the beginning of a program or erase; a change in its value after the operation has started does not have any effect on program or erase. if v pp is set to v pph , it acts as a power supply pin. in this condition v pp must be stable until the pro- gram/erase algorithm is completed (see table 15. and table 16. ). a quadruple word program com- mand will be ignored if v pp is not set to v pph while a double word program can be performed even if v pp is set to v dd. v ss ground. v ss is the reference for all voltage measurements. note: each device in a system should have v dd , v ddq and v pp decoupled with a 0.1f ca- pacitor close to the pin. see figure 9., ac mea- surement load circuit . the pcb track widths should be sufficient to carry the required v pp program and erase currents. 11/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb bus operations there are six standard bus operations that control the device. these are bus read, bus write, out- put disable, standby, automatic standby and re- set. see table 3., bus operations , for a summary. typically glitches of less than 5ns on chip enable or write enable are ignored by the memory and do not affect bus operations. read. read bus operations are used to output the contents of the memory array, the electronic signature, the status register and the common flash interface. both chip enable and output en- able must be at v il in order to perform a read op- eration. the chip enable input should be used to enable the device. output enable should be used to gate data onto the output. the data read de- pends on the previous command written to the memory (see command interface section). see figure 10., read ac waveforms , and table 14., read ac characteristics , for details of when the output becomes valid. read mode is the default state of the device when exiting reset or after power-up. write. bus write operations write commands to the memory or latch input data to be programmed. a write operation is initiated when chip enable and write enable are at v il with output enable at v ih . commands, input data and addresses are latched on the rising edge of write enable or chip enable, whichever occurs first. see figure 11. and figure 12. , write ac wave- forms, and table 15. and table 16. , write ac characteristics, for details of the timing require- ments. output disable. the data outputs are high im- pedance when the output enable is at v ih . standby. standby disables most of the internal circuitry allowing a substantial reduction of the cur- rent consumption. the memory is in stand-by when chip enable is at v ih and the device is in read mode. the power consumption is reduced to the stand-by level and the outputs are set to high impedance, independently from the output enable or write enable inputs. if chip enable switches to v ih during a program or erase operation, the de- vice enters standby mode when finished. automatic standby. automatic standby pro- vides a low power consumption state during read mode. following a read operation, the device en- ters automatic standby after 150ns of bus inactiv- ity even if chip enable is low, v il , and the supply current is reduced to i dd1 . the data inputs/out- puts will still output data if a bus read operation is in progress. reset. during reset mode when output enable is low, v il , the memory is deselected and the out- puts are high impedance. the memory is in reset mode when reset is at v il . the power consump- tion is reduced to the standby level, independently from the chip enable, output enable or write en- able inputs. if reset is pulled to v ss during a pro- gram or erase, this operation is aborted and the memory content is no longer valid. table 3. bus operations note: x = v il or v ih , v pph = 12v 5%. operation e g w rp v pp dq0-dq15 bus read v il v il v ih v ih don't care data output bus write v il v ih v il v ih v dd or v pph data input output disable v il v ih v ih v ih don't care hi-z standby v ih xx v ih don't care hi-z reset xxx v il don't care hi-z M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 12/55 hardware protection all devices feature hardware protection. refer to signal descriptions section for a detailed description of these signals. v pp v pplk . the vpp pin protects all the blocks. refer to signal descriptions section for a detailed description of these signals. security features the m28w320fs and m28w640fs are equipped with krypto security features performing soft- ware protection. they allow any block to be pro- tected from program/erase or read operations: modify protection including volatile block lock/unlock, non-volatile block modify protection, non-volatile password modify protection and irreversible protection. read protection. the krypto features (modify protection mode, read protection mode and device authentication mechanism) are not described in this datasheet. for further details concerning these additional pro- tection modes please contact st sales offices. the devices also feature a 64 bit unique device identifier and a 128 bit user-programmable otp segment (see figure 7., protection register mem- ory map and protection register program com- mand ). 13/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb command interface all bus write operations to the memory are inter- preted by the command interface. commands consist of one or more sequential bus write oper- ations. an internal program/erase controller han- dles all timings and verifies the correct execution of the program and erase commands. the pro- gram/erase controller provides a status register whose output may be read at any time during, to monitor the progress of the operation, or the pro- gram/erase states. see table 4., command codes , for a summary of the commands and see appendix d. , table 31., write state machine current/next, sheet 1 of 2. , for a summary of the command interface. the command interface is reset to read mode when power is first applied, when exiting from re- set or whenever v dd is lower than v lko . com- mand sequences must be followed exactly. any invalid combination of commands will reset the de- vice to read mode. refer to table 5., commands , in conjunction with the text descriptions below. read memory array command the read command returns the memory to its read mode. one bus write cycle is required to is- sue the read memory array command and return the memory to read mode. subsequent read op- erations will r ead the addressed location and out- put the data. when a device reset occurs, the memory defaults to read mode. read status register command the status register indicates when a program or erase operation is complete and the success or failure of the operation itself. issue a read status register command to read the status register?s contents. subsequent bus read operations read the status register at any address, until another command is issued. see table 9., status register bits , for details on the definitions of the bits. the read status register command may be is- sued at any time, even during a program/erase operation. any read attempt during a program/ erase operation will automatically output the con- tent of the status register. read electronic signature command the read electronic signature command reads the manufacturer and device codes, and the pro- tection register. the read electronic signature command consists of one write cycle, a s ubsequent read will output the manufacturer code, the device code and the protection register. see tables 6 , and 7 for the valid address. table 4. command codes read cfi query command the read query command is used to read data from the common flash interface (cfi) memory area, allowing programming equipment or appli- cations to automatically match their interface to the characteristics of the device. one bus write cycle is required to issue the read query com- mand. once the command is issued subsequent bus read operations read from the common flash interface memory area. see appendix b., common flash interface (cfi) , tables 25 , 26 , 27 , 28 , 29 and 30 for details on the infor- mation contained in the common flash interface memory area. block erase command the block erase command can be used to erase a block. it sets all the bits within the selected block to ?1?. all previous data in the block is lost. if the block is protected then the erase operation will abort, the data in the block will not be changed and the status register will output the error. two bus write cycles are required to issue the command. the first bus cycle sets up the erase command. the second latches the block address in the internal state machine and starts the program/ erase controller. hex code command 01h block lock confirm 10h program 20h erase 30h double word program 40h program 50h clear status register 56h quadruple word program 70h read status register 90h read electronic signature 98h read cfi query b0h program/erase suspend c0h protection register program d0h program/erase resume ffh read memory array M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 14/55 if the second bus cycle is not write erase confirm (d0h), status register bits b4 and b5 are set and the command aborts. erase aborts if reset turns to v il . as data integrity cannot be guaranteed when the erase operation is aborted, the block must be erased again. during erase operations the memory will accept the read status register command and the pro- gram/erase suspend command, all other com- mands will be ignored. typical erase times are given in table 8., program, erase times and pro- gram/erase endurance cycles . see appendix c. , figure 19., erase flowchart and pseudo code , for a suggested flowchart for using the erase command. program command the memory array can be programmed word-by- word. two bus write cycles are required to issue the program command. the first bus cycle sets up the program command. the second latches the address and the data to be written and starts the program/erase controller. during program operations the memory will ac- cept the read status register command and the program/erase suspend command. typical pro- gram times are given in table 8., program, erase times and program/erase endurance cycles . programming aborts if reset goes to v il . as data integrity cannot be guaranteed when the program operation is aborted, the block containing the memory location must be erased and repro- grammed. see appendix c. , figure 15., program flow- chart and pseudo code , for the flowchart for using the program command. double word program command this feature is offered to improve the programming throughput, writing a page of two adjacent words in parallel.the two words must differ only for the address a0. three bus write cycles are necessary to issue the double word program command. the first bus cycle sets up the double word program command. the second bus cycle latches the address and the data of the first word to be written. the third bus cycle latches the address and the data of the second word to be written and starts the program/erase controller. read operations output the status register con- tent after the programming has started. program- ming aborts if reset goes to v il . as data integrity cannot be guaranteed when the program opera- tion is aborted, the block containing the memory location must be erased and reprogrammed. see appendix c. , figure 16., double word pro- gram flowchart and pseudo code for the flow- chart for using the double word program command. quadruple word program command this feature is offered to improve the programming throughput, writing a page of four adjacent words in parallel.the four words must differ only for the addresses a0 and a1. a quadruple word program command will be ig- nored if v pp is not set to v pph . five bus write cycles are necessary to issue the quadruple word program command. the first bus cycle sets up the quadruple word program command. the second bus cycle latches the address and the data of the first word to be written. the third bus cycle latches the address and the data of the second word to be written. the fourth bus cycle latches the address and the data of the third word to be written. the fifth bus cycle latc hes the address and the data of the fourth word to be written and starts the program/erase controller. read operations output the status register con- tent after the programming has started. program- ming aborts if reset goes to v il . as data integrity cannot be guaranteed when the program opera- tion is aborted, the block containing the memory location must be erased and reprogrammed. see appendix c. , figure 17., quadruple word program flowchart and pseudo code , for the flowchart for using the quadruple word program command. clear status register command the clear status register command can be used to reset bits 1, 3, 4 and 5 in the status register to ?0?. one bus write cycle is required to issue the clear status register command. the bits in the status register do not automatical- ly return to ?0? when a new program or erase com- mand is issued. the error bits in the status register should be cleared before attempting a new program or erase command. program/erase suspend command the program/erase suspend command is used to pause a program or erase operation. one bus write cycle is required to issue the program/erase command and pause the program/erase control- ler. during program/erase suspend the command in- terface will accept the program/erase resume, 15/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb read array, read status register, read electron- ic signature and read cfi query commands. ad- ditionally, if the suspend operation was erase then the program, double word program, quadruple word program, block lock, or protection program commands will also be accepted. the block being erased may be protected by issuing the block pro- tect, block lock or protection program com- mands. when the program/erase resume command is issued the operation will complete. only the blocks not being erased may be read or programmed correctly. during a program/erase suspend, the device can be placed in a pseudo-standby mode by taking chip enable to v ih . program/erase is aborted if reset turns to v il . see appendix c. , figure 18., program suspend & resume flowchart and pseudo code , and fig- ure 20., erase suspend & resume flowchart and pseudo code , for flowcharts for using the pro- gram/erase suspend command. program/erase resume command the program/erase resume command can be used to restart the program/erase controller after a program/erase suspend operation has paused it. one bus write cycle is required to issue the command. once the command is issued subse- quent bus read operations read the status reg- ister. see appendix c. , figure 18., program suspend & resume flowchart and pseudo code , and fig- ure 20., erase suspend & resume flowchart and pseudo code , for flowcharts for using the pro- gram/erase resume command. protection register program command the protection register program command is used to program the 128 bit user one-time-pro- grammable (otp) segment of the protection reg- ister. the segment is programmed 16 bits at a time. when shipped all bits in the segment are set to ?1?. the user can only program the bits to ?0?. two write cycles are required to issue the protec- tion register program command. the first bus cycle sets up the protection register program command. the second latches the address and the data to be written to the protection register and starts the program/erase controller. read operations output the status register con- tent after the programming has started. the segment can be protected by programming bit 1 of the protection lock register (see figure 7., protection register memory map ). attempting to program a previously protected protection reg- ister will result in a status register error. the pro- tection of the protection register is not reversible. the protection register program cannot be sus- pended. M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 16/55 table 5. commands note: 1. x = don't care, ra=read address, rd=read data, srd=status register data, id=identifier (manufacture and device code), qa=query address, qd=query data, ba=block address, pa=program address, pd=program data, pra=protection register ad- dress, prd=protection register data. 2. the signature addresses are listed in tables 6 and 7 . 3. program addresses 1 and 2 must be consecutive addresses differing only for a0. 4. program addresses 1,2,3 and 4 must be consecutive addresses differing only for a0 and a1. table 6. read electronic signature note: 1. rp = v ih . 2. addresses range from a0 to a20 for the m28w320fs and from a0 to a21 for the m29w640fs. commands cycles bus write operations 1st cycle 2nd cycle 3rd cycle 4th cycle 5th cycle op. add data op. add data op. add data op. add data op. add data read memory array 1+ write x ffh read ra rd read status register 1+ write x 70h read x srd read electronic signature 1+ write x 90h read sa (2) idh read cfi query 1+ write x 98h read qa qd erase 2 write x 20h write ba d0h program 2 write x 40h or 10h write pa pd double word program (3) 3 write x 30h write pa1 pd1 write pa2 pd2 quadruple word program (4) 5 write x 56h write pa1 pd1 write pa2 pd2 write pa3 pd3 write pa4 pd4 clear status register 1 write x 50h program/erase suspend 1write x b0h program/erase resume 1write x d0h protection register program 2write x c0h write pra prd code device e g w a0 a1 a2-a7 a8-a20 a8-a21 (2) dq0-dq7 dq8-dq15 manufacture code v il v il v ih v il v il 0 don't care 20h 00h device code M28W320FST v il v il v ih v ih v il 0 don't care 0ah 88h m28w320fsb v il v il v ih v ih v il 0 don't care 0bh 88h m28w640fst v il v il v ih v ih v il 0 don't care 58h 88h m28w640fsb v il v il v ih v ih v il 0 don't care 59h 88h 17/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb table 7. read protection register and protection register lock note: 1. addresses range from a0 to a20 for the m28w320fs and from a0 to a21 for the m29w640fs. word e g w a0-a7 a8-a21 (1) dq0 dq1 dq2 dq3-dq7 dq8-dq15 lock v il v il v ih 80h don't care 0 otp prot. data 0 00h 00h unique id 0 v il v il v ih 81h don't care id data id data id data id data id data unique id 1 v il v il v ih 82h don't care id data id data id data id data id data unique id 2 v il v il v ih 83h don't care id data id data id data id data id data unique id 3 v il v il v ih 84h don't care id data id data id data id data id data otp 0 v il v il v ih 85h don't care otp data otp data otp data otp data otp data otp 1 v il v il v ih 86h don't care otp data otp data otp data otp data otp data otp 2 v il v il v ih 87h don't care otp data otp data otp data otp data otp data otp 3 v il v il v ih 88h don't care otp data otp data otp data otp data otp data otp 4 v il v il v ih 89h don't care otp data otp data otp data otp data otp data otp 5 v il v il v ih 8ah don't care otp data otp data otp data otp data otp data otp 6 v il v il v ih 8bh don't care otp data otp data otp data otp data otp data otp 7 v il v il v ih 8ch don't care otp data otp data otp data otp data otp data M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 18/55 table 8. program, erase times and program/erase endurance cycles note: 1. typical time to program a main or parameter block using the double word program and the quadruple word program commands respectively. parameter test conditions M28W320FST, M28W320FST m28w640fst, m28w640fsb unit min typ max word program v pp = v dd 10 200 s double word program v pp = 12v 5% 10 200 s quadruple word program v pp = 12v 5% 10 200 s main block program v pp = 12v 5% 0.16/0.08 (1) 5s v pp = v dd 0.32 5 s parameter block program v pp = 12v 5% 0.02/0.01 (1) 4s v pp = v dd 0.04 4 s main block erase v pp = 12v 5% 110s v pp = v dd 110s parameter block erase v pp = 12v 5% 0.4 10 s v pp = v dd 0.4 10 s program/erase cycles (per block) 100,000 cycles data retention 20 years 19/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb status register the status register provides information on the current or previous program or erase operation. the various bits convey information and errors on the operation. to read the status register the read status register command can be issued, re- fer to read status register command section. to output the contents, the status register is latched on the falling edge of the chip enable or output enable signals, and can be read until chip enable or output enable returns to v ih . either chip en- able or output enable must be toggled to update the latched data. bus read operations from any address always read the status register during program and erase operations. the bits in the status register are summarized in table 9., status register bits . refer to table 9. in conjunction with the following text descriptions. program/erase controller status (bit 7). the program/erase controller status bit indicates whether the program/erase controller is active or inactive. when the program/erase controller sta- tus bit is low (set to ?0?), the program/erase con- troller is active; when the bit is high (set to ?1?), the program/erase controller is inactive, and the de- vice is ready to process a new command. the program/erase controller status is low im- mediately after a program/erase suspend com- mand is issued until the program/erase controller pauses. after the program/erase controller paus- es the bit is high. during program, erase, operations the program/ erase controller status bit can be polled to find the end of the operation. other bits in the status reg- ister should not be tested until the program/erase controller completes the operation and the bit is high. after the program/erase controller completes its operation the erase status, program status, v pp status and block lock status bits should be tested for errors. erase suspend status (bit 6). the erase sus- pend status bit indicates that an erase operation has been suspended or is going to be suspended. when the erase suspend status bit is high (set to ?1?), a program/erase suspend command has been issued and the memory is waiting for a pro- gram/erase resume command. the erase suspend status should only be consid- ered valid when the program/erase controller sta- tus bit is high (program/erase controller inactive). bit 7 is set within 30s of the program/erase sus- pend command being issued therefore the memo- ry may still complete the operation rather than entering the suspend mode. when a program/erase resume command is is- sued the erase suspend status bit returns low. erase status (bit 5). the erase status bit can be used to identify if the memory has failed to verify that the block has erased correctly. when the erase status bit is high (set to ?1?), the program/ erase controller has applied the maximum num- ber of pulses to the block and still failed to verify that the block has erased correctly. the erase sta- tus bit should be read once the program/erase controller status bit is high (program/erase con- troller inactive). once set high, the erase status bit can only be re- set low by a clear status register command or a hardware reset. if set high it should be reset be- fore a new program or erase command is issued, otherwise the new command will appear to fail. program status (bit 4). the program status bit is used to identify a program failure. when the program status bit is high (set to ?1?), the pro- gram/erase controller has applied the maximum number of pulses to the by te and still failed to ver- ify that it has programmed correctly. the program status bit should be read once the program/erase controller status bit is high (program/erase con- troller inactive). once set high, the program status bit can only be reset low by a clear status register command or a hardware reset. if set high it should be reset be- fore a new command is issued, otherwise the new command will appear to fail. v pp status (bit 3). the v pp status bit can be used to identify an invalid voltage on the v pp pin during program and erase operations. the v pp pin is only sampled at the beginning of a program or erase operation. indeterminate results can oc- cur if v pp becomes invalid during an operation. when the v pp status bit is low (set to ?0?), the volt- age on the v pp pin was sampled at a valid voltage; when the v pp status bit is high (set to ?1?), the v pp pin has a voltage that is below the v pp lockout voltage, v pplk , the memory is protected and pro- gram and erase operations cannot be performed. once set high, the v pp status bit can only be reset low by a clear status register command or a hardware reset. if set high it should be reset be- fore a new program or erase command is issued, otherwise the new command will appear to fail. program suspend status (bit 2). the program suspend status bit indicates that a program oper- ation has been suspended. when the program suspend status bit is high (set to ?1?), a program/ erase suspend command has been issued and the memory is waiting for a program/erase re- sume command. the program suspend status should only be considered valid when the pro- M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 20/55 gram/erase controller status bit is high (program/ erase controller inactive). bit 2 is set within 5s of the program/erase suspend command being is- sued therefore the memory may still complete the operation rather than entering the suspend mode. when a program/erase resume command is is- sued the program suspend status bit returns low. block protection status (bit 1). the block pro- tection status bit can be used to identify if a pro- gram or erase operation has tried to modify the contents of a locked block. when the block protection status bit is high (set to ?1?), a program or erase operation has been at- tempted on a locked block. once set high, the block protection status bit can only be reset low by a clear status register com- mand or a hardware reset. if set high it should be reset before a new command is issued, otherwise the new command will appear to fail. reserved (bit 0). bit 0 of the status register is reserved. its value must be masked. note: refer to appendix c., flowcharts and pseudo codes , for using the status register. table 9. status register bits note: logic level '1' is high, '0' is low. bit name logic level definition 7 p/e.c. status '1' ready '0' busy 6 erase suspend status '1' suspended '0' in progress or completed 5 erase status '1' erase error '0' erase success 4 program status '1' program error '0' program success 3 v pp status '1' v pp invalid, abort '0' v pp ok 2 program suspend status '1' suspended '0' in progress or completed 1 block protection status '1' program/erase on protected block, abort '0' no operation to protected blocks 0reserved 21/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb maximum rating stressing the device above the rating listed in the absolute maximum ratings table may cause per- manent damage to the device. these are stress ratings only and operation of the device at these or any other conditions above those indicated in the operating sections of this specification is not im- plied. exposure to absolute maximum rating con- ditions for extended periods may affect device reliability. refer also to the stmicroelectronics sure program and other relevant quality docu- ments. table 10. absolute maximum ratings note: 1. depends on range. symbol parameter value unit min max t a ambient operating temperature (1) ? 40 85 c t bias temperature under bias ? 40 125 c t stg storage temperature ? 55 155 c v io input or output voltage ? 0.6 v ddq +0.6 v v dd , v ddq supply voltage ? 0.6 4.1 v v pp program voltage ? 0.6 13 v M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 22/55 dc and ac parameters this section summarizes the operating and mea- surement conditions, and the dc and ac charac- teristics of the device. the parameters in the dc and ac characteristics tables that follow, are de- rived from tests performed under the measure- ment conditions summarized in table 11., operating and ac measurement conditions . designers should check that the operating condi- tions in their circuit match the measurement condi- tions when relying on the quoted parameters. table 11. operating and ac measurement conditions figure 8. ac measurement i/o waveform figure 9. ac measurement load circuit table 12. capacitance note: sampled only, not 100% tested. parameter M28W320FST, M28W320FST, m28w640fst, m28w640fsb 70 85 90 10 units min max min max min max min max v dd supply voltage 2.7 3.6 2.7 3.6 2.7 3.6 2.7 3.6 v v ddq supply voltage (v ddq v dd ) 2.7 3.6 2.7 3.6 2.7 3.6 1.65 3.6 v ambient operating temperature ?40 85 ?40 85 ?40 85 ?40 85 c load capacitance (c l ) 50 50 50 50 pf input rise and fall times 5 5 5 5 ns input pulse voltages 0 to v ddq 0 to v ddq 0 to v ddq 0 to v ddq v input and output timing ref. voltages v ddq /2 v ddq /2 v ddq /2 v ddq /2 v ai00610 v ddq 0v v ddq /2 ai00609c v ddq c l c l includes jig capacitance 25k ? device under test 0.1f v dd 0.1f v ddq 25k ? symbol parameter test condition min max unit c in input capacitance v in = 0v 6pf c out output capacitance v out = 0v 12 pf 23/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb table 13. dc characteristics symbol parameter test condition min typ max unit i li input leakage current 0v v in v ddq 1 a i lo output leakage current 0v v out v ddq 10 a i dd supply current (read) e = v ss , g = v ih , f = 5mhz 918ma i dd1 supply current (stand-by or automatic stand-by) e = v ddq 0.2v, rp = v ddq 0.2v 15 50 a i dd2 supply current (reset) rp = v ss 0.2v 15 50 a i dd3 supply current (program) program in progress v pp = 12v 5% 510ma program in progress v pp = v dd 10 20 ma i dd4 supply current (erase) erase in progress v pp = 12v 5% 520ma erase in progress v pp = v dd 10 20 ma i dd5 supply current (program/erase suspend) e = v ddq 0.2v, erase suspended 15 50 a i pp program current (read or stand-by) v pp > v dd 400 a i pp1 program current (read or stand-by) v pp v dd 15a i pp2 program current (reset) rp = v ss 0.2v 15a i pp3 program current (program) program in progress v pp = 12v 5% 110ma program in progress v pp = v dd 15a i pp4 program current (erase) erase in progress v pp = 12v 5% 310ma erase in progress v pp = v dd 15a v il input low voltage ?0.5 0.4 v v ddq 2.7v ?0.5 0.8 v v ih input high voltage v ddq ?0.4 v ddq +0.4 v v ddq 2.7v 0.7 v ddq v ddq +0.4 v v ol output low voltage i ol = 100a, v dd = v dd min, v ddq = v ddq min 0.1 v v oh output high voltage i oh = ?100a, v dd = v dd min, v ddq = v ddq min v ddq ?0.1 v v pp1 program voltage (program or erase operations) 1.65 3.6 v v pph program voltage (program or erase operations) 11.4 12.6 v v pplk program voltage (program and erase lock-out) 1v v lko v dd supply voltage (program and erase lock-out) 2v M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 24/55 figure 10. read ac waveforms note: 1. addresses range from a0 to a20 for the m28w320fs and from a0 to a21 for the m29w640fs. table 14. read ac characteristics note: 1. sampled only, not 100% tested. 2. g may be delayed by up to t elqv - t glqv after the falling edge of e without increasing t elqv . symbol alt parameter M28W320FST, M28W320FST m28w640fst, m28w640fsb unit 70 70 t avav t rc address valid to next address valid min 70 70 ns t av qv t acc address valid to output valid max 70 70 ns t axqx (1) t oh address transition to output transition min 0 0 ns t ehqx (1) t oh chip enable high to output transition min 0 0 ns t ehqz (1) t hz chip enable high to output hi-z max 20 20 ns t elqv (2) t ce chip enable low to output valid max 70 70 ns t elqx (1) t lz chip enable low to output transition min 0 0 ns t ghqx (1) t oh output enable high to output transition min 0 0 ns t ghqz (1) t df output enable high to output hi-z max 20 20 ns t glqv (2) t oe output enable low to output valid max 20 20 ns t glqx (1) t olz output enable low to output transition min 0 0 ns dq0-dq15 ai09928 valid a0-a20/a21 (1) e taxqx tavav valid tavqv telqv telqx tglqv tglqx addr. valid chip enable outputs enabled data valid standby g tghqx tghqz tehqx tehqz 25/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb figure 11. write ac waveforms, write enable controlled note: 1. addresses range from a0 to a20 for the m28w320fs and from a0 to a21 for the m29w640fs. e g w dq0-dq15 command cmd or data status register v pp valid a0-a20/a21 (1) tavav tqvvpl tavwh twhax program or erase telwl twheh twhdx tdvwh twlwh twhwl tvphwh set-up command confirm command or data input status register read 1st polling telqv ai09929 twhgl twhel M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 26/55 table 15. write ac characteristics, write enable controlled note: 1. sampled only, not 100% tested. 2. applicable if v pp is seen as a logic input (v pp < 3.6v). symbol alt parameter M28W320FST, M28W320FST m28w640fst, m28w640fsb unit 70 70 t avav t wc write cycle time min 70 70 ns t avw h t as address valid to write enable high min 45 45 ns t dvwh t ds data valid to write enable high min 45 45 ns t elwl t cs chip enable low to write enable low min 0 0 ns t elqv chip enable low to output valid min 70 70 ns t qvvpl (1,2) output valid to v pp low min 0 0 ns t vphwh (1) t vps v pp high to write enable high min 200 200 ns t whax t ah write enable high to address transition min 0 0 ns t whdx t dh write enable high to data transition min 0 0 ns t wheh t ch write enable high to chip enable high min 0 0 ns t whel write enable high to chip enable low min 25 25 ns t whgl write enable high to output enable low min 20 20 ns t whwl t wph write enable high to write enable low min 25 25 ns t wlwh t wp write enable low to write enable high min 45 45 ns 27/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb figure 12. write ac waveforms, chip enable controlled note: 1. addresses range from a0 to a20 for the m28w320fs and from a0 to a21 for the m29w640fs. e g dq0-dq15 command cmd or data status register v pp valid a0-a20/a21 tavav tqvvpl taveh tehax program or erase twlel tehwh tehdx tdveh teleh tehel tvpheh power-up and set-up command confirm command or data input status register read 1st polling telqv ai09930 w tehgl M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 28/55 table 16. write ac characteristics, chip enable controlled note: 1. sampled only, not 100% tested. 2. applicable if v pp is seen as a logic input (v pp < 3.6v). symbol alt parameter M28W320FST, M28W320FST m28w640fst, m28w640fsb unit 70 70 t avav t wc write cycle time min 70 70 ns t ave h t as address valid to chip enable high min 45 45 ns t dveh t ds data valid to chip enable high min 45 45 ns t ehax t ah chip enable high to address transition min 0 0 ns t ehdx t dh chip enable high to data transition min 0 0 ns t ehel t cph chip enable high to chip enable low min 25 25 ns t ehgl chip enable high to output enable low min 25 25 ns t ehwh t wh chip enable high to write enable high min 0 0 ns t eleh t cp chip enable low to chip enable high min 45 45 ns t elqv chip enable low to output valid min 70 70 ns t qvvpl (1,2) output valid to v pp low min 0 0 ns t vpheh (1) t vps v pp high to chip enable high min 200 200 ns t wlel t cs write enable low to chip enable low min 0 0 ns 29/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb figure 13. power-up and reset ac waveforms table 17. power-up and reset ac characteristics note: 1. the device reset is possible but not guaranteed if t plph < 100ns. 2. sampled only, not 100% tested. 3. it is important to assert rp in order to allow proper cpu initialization during power up or reset. symbol parameter test condition M28W320FST, M28W320FST, m28w640fst, m28w640fsb unit 70 t phwl t phel t phgl reset high to write enable low, chip enable low, output enable low during program and erase min 50 s others min 30 ns t plph (1,2) reset low to reset high min 100 ns t vdhph (3) supply voltages high to reset high min 50 s ai03537b w, rp tphwl tphel tphgl e, g vdd, vddq tvdhph tphwl tphel tphgl tplph power-up reset M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 30/55 package mechanical figure 14. tbga64 - 10x13 active ball array, 1mm pitch, bottom view package outline note: drawing is not to scale. table 18. tbga64 - 10x13 active ball array, 1mm pitch, package mechanical data symbol millimeters inches typ min max typ min max a 1.200 0.0472 a1 0.300 0.200 0.350 0.0118 0.0079 0.0138 a2 0.800 0.0315 b 0.350 0.500 0.0138 0.0197 d 10.000 9.900 10.100 0.3937 0.3898 0.3976 d1 7.000 ? ? 0.2756 ? ? ddd 0.100 0.0039 e 1.000 ? ? 0.0394 ? ? e 13.000 12.900 13.100 0.5118 0.5079 0.5157 e1 7.000 ? ? 0.2756 ? ? fd 1.500 ? ? 0.0591 ? ? fe 3.000 ? ? 0.1181 ? ? sd 0.500 ? ? 0.0197 ? ? se 0.500 ? ? 0.0197 ? ? e1 e d1 d eb sd se a2 a1 a bga-z23 ddd fd fe ball "a1" 31/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb part numbering table 19. ordering information scheme example: m28w640fst 70 za 6 t device type m28 operating voltage w = v dd = 2.7v to 3.6v; v ddq = 1.65v to 3.6v device function 320fs = 32 mbit (2 mb x16), boot block, secure, 0.13m 640fs = 64 mbit (4 mb x16), boot block, secure, 0.13m array matrix t = top boot b = bottom boot speed 70 = 70ns package za = tbga64:10 x 13mm, 1mm pitch temperature range 1 = 0 to 70 c 6 = ?40 to 85 c option blank = standard packing t = tape & reel packing e = ecopack package, standard packing f = ecopack package, tape & reel 24mm packing M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 32/55 table 20. daisy chain ordering scheme note:devices are shipped from the factory with the memory content bits erased to ?1?. for a list of available options (speed, package, etc.) or for further information on any aspect of this device, please contact the st sales office nearest to you. example: m28w640fs -za t device type m28w640fs m28w320fs daisy chain -za = tbga64: 10 x 13, 1mm pitch option blank = standard packing t = tape & reel packing e = ecopack package, standard packing f = ecopack package, tape & reel 24mm packing 33/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb appendix a. block address tables table 21. top boot block addresses, M28W320FST # size (kword) address range 0 4 1ff000-1fffff 1 4 1fe000-1fefff 2 4 1fd000-1fdfff 3 4 1fc000-1fcfff 4 4 1fb000-1fbfff 5 4 1fa000-1fafff 6 4 1f9000-1f9fff 7 4 1f8000-1f8fff 8 32 1f0000-1f7fff 9 32 1e8000-1effff 10 32 1e0000-1e7fff 11 32 1d8000-1dffff 12 32 1d0000-1d7fff 13 32 1c8000-1cffff 14 32 1c0000-1c7fff 15 32 1b8000-1bffff 16 32 1b0000-1b7fff 17 32 1a8000-1affff 18 32 1a0000-1a7fff 19 32 198000-19ffff 20 32 190000-197fff 21 32 188000-18ffff 22 32 180000-187fff 23 32 178000-17ffff 24 32 170000-177fff 25 32 168000-16ffff 26 32 160000-167fff 27 32 158000-15ffff 28 32 150000-157fff 29 32 148000-14ffff 30 32 140000-147fff 31 32 138000-13ffff 32 32 130000-137fff 33 32 128000-12ffff 34 32 120000-127fff 35 32 118000-11ffff 36 32 110000-117fff 37 32 108000-10ffff 38 32 100000-107fff 39 32 0f8000-0fffff 40 32 0f00000-f7fff 41 32 0e8000-0effff 42 32 0e0000-0e7fff 43 32 0d8000-0dffff 44 32 0d0000-0d7fff 45 32 0c8000-0cffff 46 32 0c0000-0c7fff 47 32 0b8000-0bffff 48 32 0b0000-0b7fff 49 32 0a8000-0affff 50 32 0a0000-0a7fff 51 32 098000-09ffff 52 32 090000-097fff 53 32 088000-08ffff 54 32 080000-087fff 55 32 078000-07ffff 56 32 070000-077fff 57 32 068000-06ffff 58 32 060000-067fff 59 32 058000-05ffff 60 32 050000-057fff 61 32 048000-04ffff 62 32 040000-047fff 63 32 038000-03ffff 64 32 030000-037fff 65 32 028000-02ffff 66 32 020000-027fff 67 32 018000-01ffff 68 32 010000-017fff 69 32 008000-00ffff 70 32 000000-007fff M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 34/55 table 22. bottom boot block addresses, m28w320fsb # size (kword) address range 70 32 1f8000-1fffff 69 32 1f0000-1f7fff 68 32 1e8000-1effff 67 32 1e0000-1e7fff 66 32 1d8000-1dffff 65 32 1d0000-1d7fff 64 32 1c8000-1cffff 63 32 1c0000-1c7fff 62 32 1b8000-1bffff 61 32 1b0000-1b7fff 60 32 1a8000-1affff 59 32 1a0000-1a7fff 58 32 198000-19ffff 57 32 190000-197fff 56 32 188000-18ffff 55 32 180000-187fff 54 32 178000-17ffff 53 32 170000-177fff 52 32 168000-16ffff 51 32 160000-167fff 50 32 158000-15ffff 49 32 150000-157fff 48 32 148000-14ffff 47 32 140000-147fff 46 32 138000-13ffff 45 32 130000-137fff 44 32 128000-12ffff 43 32 120000-127fff 42 32 118000-11ffff 41 32 110000-117fff 40 32 108000-10ffff 39 32 100000-107fff 38 32 0f8000-0fffff 37 32 0f0000-0f7fff 36 32 0e8000-0effff 35 32 0e0000-0e7fff 34 32 0d8000-0dffff 33 32 0d0000-0d7fff 32 32 0c8000-0cffff 31 32 0c0000-0c7fff 30 32 0b8000-0bffff 29 32 0b0000-0b7fff 28 32 0a8000-0affff 27 32 0a0000-0a7fff 26 32 098000-09ffff 25 32 090000-097fff 24 32 088000-08ffff 23 32 080000-087fff 22 32 078000-07ffff 21 32 070000-077fff 20 32 068000-06ffff 19 32 060000-067fff 18 32 058000-05ffff 17 32 050000-057fff 16 32 048000-04ffff 15 32 040000-047fff 14 32 038000-03ffff 13 32 030000-037fff 12 32 028000-02ffff 11 32 020000-027fff 10 32 018000-01ffff 9 32 010000-017fff 8 32 008000-00ffff 7 4 007000-007fff 6 4 006000-006fff 5 4 005000-005fff 4 4 004000-004fff 3 4 003000-003fff 2 4 002000-002fff 1 4 001000-001fff 0 4 000000-000fff 35/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb table 23. top boot block addresses, m28w640fst # size (kword) address range 0 4 3ff000-3fffff 1 4 3fe000-3fefff 2 4 3fd000-3fdfff 3 4 3fc000-3fcfff 4 4 3fb000-3fbfff 5 4 3fa000-3fafff 6 4 3f9000-3f9fff 7 4 3f8000-3f8fff 8 32 3f0000-3f7fff 9 32 3e8000-3effff 10 32 3e0000-3e7fff 11 32 3d8000-3dffff 12 32 3d0000-3d7fff 13 32 3c8000-3cffff 14 32 3c0000-3c7fff 15 32 3b8000-3bffff 16 32 3b0000-3b7fff 17 32 3a8000-3affff 18 32 3a0000-3a7fff 19 32 398000-39ffff 20 32 390000-397fff 21 32 388000-38ffff 22 32 380000-387fff 23 32 378000-37ffff 24 32 370000-377fff 25 32 368000-36ffff 26 32 360000-367fff 27 32 358000-35ffff 28 32 350000-357fff 29 32 348000-34ffff 30 32 340000-347fff 31 32 338000-33ffff 32 32 330000-337fff 33 32 328000-32ffff 34 32 320000-327fff 35 32 318000-31ffff 36 32 310000-317fff 37 32 308000-30ffff 38 32 300000-307fff 39 32 2f8000-2fffff 40 32 2f0000-2f7fff 41 32 2e8000-2effff 42 32 2e0000-2e7fff 43 32 2d8000-2dffff 44 32 2d0000-2d7fff 45 32 2c8000-2cffff 46 32 2c0000-2c7fff 47 32 2b8000-2bffff 48 32 2b0000-2b7fff 49 32 2a8000-2affff 50 32 2a0000-2a7fff 51 32 298000-29ffff 52 32 290000-297fff 53 32 288000-28ffff 54 32 280000-287fff 55 32 278000-27ffff 56 32 270000-277fff 57 32 268000-26ffff 58 32 260000-267fff 59 32 258000-25ffff 60 32 250000-257fff 61 32 248000-24ffff 62 32 240000-247fff 63 32 238000-23ffff 64 32 230000-237fff 65 32 228000-22ffff 66 32 220000-227fff 67 32 218000-21ffff 68 32 210000-217fff 69 32 208000-20ffff 70 32 200000-207fff 71 32 1f8000-1fffff 72 32 1f0000-1f7fff 73 32 1e8000-1effff 74 32 1e0000-1e7fff 75 32 1d8000-1dffff 76 32 1d0000-1d7fff 77 32 1c8000-1cffff 78 32 1c0000-1c7fff 79 32 1b8000-1bffff 80 32 1b0000-1b7fff 81 32 1a8000-1affff 82 32 1a0000-1a7fff 83 32 198000-19ffff 84 32 190000-197fff 85 32 188000-18ffff # size (kword) address range M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 36/55 86 32 180000-187fff 87 32 178000-17ffff 88 32 170000-177fff 89 32 168000-16ffff 90 32 160000-167fff 91 32 158000-15ffff 92 32 150000-157fff 93 32 148000-14ffff 94 32 140000-147fff 95 32 138000-13ffff 96 32 130000-137fff 97 32 128000-12ffff 98 32 120000-127fff 99 32 118000-11ffff 100 32 110000-117fff 101 32 108000-10ffff 102 32 100000-107fff 103 32 0f8000-0fffff 104 32 0f0000-0f7fff 105 32 0e8000-0effff 106 32 0e0000-0e7fff 107 32 0d8000-0dffff 108 32 0d0000-0d7fff 109 32 0c8000-0cffff 110 32 0c0000-0c7fff 111 32 0b8000-0bffff 112 32 0b0000-0b7fff 113 32 0a8000-0affff 114 32 0a0000-0a7fff 115 32 098000-09ffff 116 32 090000-097fff 117 32 088000-08ffff 118 32 080000-087fff 119 32 078000-07ffff 120 32 070000-077fff 121 32 068000-06ffff 122 32 060000-067fff 123 32 058000-05ffff 124 32 050000-057fff 125 32 048000-04ffff 126 32 040000-047fff 127 32 038000-03ffff 128 32 030000-037fff 129 32 028000-02ffff # size (kword) address range 130 32 020000-027fff 131 32 018000-01ffff 132 32 010000-017fff 133 32 008000-00ffff 134 32 000000-007fff # size (kword) address range 37/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb table 24. bottom boot block addresses, m28w640fsb # size (kword) address range 134 32 3f8000-3fffff 133 32 3f0000-3f7fff 132 32 3e8000-3effff 131 32 3e0000-3e7fff 130 32 3d8000-3dffff 129 32 3d0000-3d7fff 128 32 3c8000-3cffff 127 32 3c0000-3c7fff 126 32 3b8000-3bffff 125 32 3b0000-3b7fff 124 32 3a8000-3affff 123 32 3a0000-3a7fff 122 32 398000-39ffff 121 32 390000-397fff 120 32 388000-38ffff 119 32 380000-387fff 118 32 378000-37ffff 117 32 370000-377fff 116 32 368000-36ffff 115 32 360000-367fff 114 32 358000-35ffff 113 32 350000-357fff 112 32 348000-34ffff 111 32 340000-347fff 110 32 338000-33ffff 109 32 330000-337fff 108 32 328000-32ffff 107 32 320000-327fff 106 32 318000-31ffff 105 32 310000-317fff 104 32 308000-30ffff 103 32 300000-307fff 102 32 2f8000-2fffff 101 32 2f0000-2f7fff 100 32 2e8000-2effff 99 32 2e0000-2e7fff 98 32 2d8000-2dffff 97 32 2d0000-2d7fff 96 32 2c8000-2cffff 95 32 2c0000-2c7fff 94 32 2b8000-2bffff 93 32 2b0000-2b7fff 92 32 2a8000-2affff 91 32 2a0000-2a7fff 90 32 298000-29ffff 89 32 290000-297fff 88 32 288000-28ffff 87 32 280000-287fff 86 32 278000-27ffff 85 32 270000-277fff 84 32 268000-26ffff 83 32 260000-267fff 82 32 258000-25ffff 81 32 250000-257fff 80 32 248000-24ffff 79 32 240000-247fff 78 32 238000-23ffff 77 32 230000-237fff 76 32 228000-22ffff 75 32 220000-227fff 74 32 218000-21ffff 73 32 210000-217fff 72 32 208000-20ffff 71 32 200000-207fff 70 32 1f8000-1fffff 69 32 1f0000-1f7fff 68 32 1e8000-1effff 67 32 1e0000-1e7fff 66 32 1d8000-1dffff 65 32 1d0000-1d7fff 64 32 1c8000-1cffff 63 32 1c0000-1c7fff 62 32 1b8000-1bffff 61 32 1b0000-1b7fff 60 32 1a8000-1affff 59 32 1a0000-1a7fff 58 32 198000-19ffff 57 32 190000-197fff 56 32 188000-18ffff 55 32 180000-187fff 54 32 178000-17ffff 53 32 170000-177fff 52 32 168000-16ffff 51 32 160000-167fff 50 32 158000-15ffff 49 32 150000-157fff # size (kword) address range M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 38/55 48 32 148000-14ffff 47 32 140000-147fff 46 32 138000-13ffff 45 32 130000-137fff 44 32 128000-12ffff 43 32 120000-127fff 42 32 118000-11ffff 41 32 110000-117fff 40 32 108000-10ffff 39 32 100000-107fff 38 32 0f8000-0fffff 37 32 0f0000-0f7fff 36 32 0e8000-0effff 35 32 0e0000-0e7fff 34 32 0d8000-0dffff 33 32 0d0000-0d7fff 32 32 0c8000-0cffff 31 32 0c0000-0c7fff 30 32 0b8000-0bffff 29 32 0b0000-0b7fff 28 32 0a8000-0affff 27 32 0a0000-0a7fff 26 32 098000-09ffff 25 32 090000-097fff 24 32 088000-08ffff 23 32 080000-087fff 22 32 078000-07ffff 21 32 070000-077fff 20 32 068000-06ffff 19 32 060000-067fff 18 32 058000-05ffff 17 32 050000-057fff 16 32 048000-04ffff 15 32 040000-047fff 14 32 038000-03ffff 13 32 030000-037fff 12 32 028000-02ffff 11 32 020000-027fff 10 32 018000-01ffff 9 32 010000-017fff 8 32 008000-00ffff 7 4 007000-007fff 6 4 006000-006fff 5 4 005000-005fff # size (kword) address range 4 4 004000-004fff 3 4 003000-003fff 2 4 002000-002fff 1 4 001000-001fff 0 4 000000-000fff # size (kword) address range 39/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb appendix b. common flash interface (cfi) the common flash interface is a jedec ap- proved, standardized data structure that can be read from the flash memory device. it allows a system software to query the device to determine various electrical and timing parameters, density information and functions supported by the mem- ory. the system can interface easily with the de- vice, enabling the software to upgrade itself when necessary. when the cfi query command (rcfi) is issued the device enters cfi query mode and the data structure is read from the memory. tables 25 , 26 , 27 , 28 , 29 and 30 show the addresses used to re- trieve the data. the cfi data structure also contains a security area where a 64 bit unique security number is writ- ten (see table 30., security code area ). this area can be accessed only in read mode by the final user. it is impossible to change the security num- ber after it has been written by st. issue a read command to return to read mode. table 25. query structure overview note: query data are always presented on the lowest order data outputs. table 26. cfi query identification string note: query data are always presented on the lowest order data outputs (dq7-dq0) only. dq8-dq15 are ?0?. offset sub-section name description 00h reserved reserved for algorithm-specific information 10h cfi query identification string command set id and algorithm data offset 1bh system interface information device timing & voltage information 27h device geometry definition flash device layout p primary algorithm-specific extended query table additional information specific to the primary algorithm (optional) a alternate algorithm-specific extended query table additional information specific to the alternate algorithm (optional) offset data description value 00h 0020h manufacturer code st 01h 8858h 8859h 880ah 880bh device code to p bottom 02h-0fh reserved reserved 10h 0051h "q" 11h 0052h query unique ascii string "qry" "r" 12h 0059h "y" 13h 0003h primary algorithm command set and control interface id code 16 bit id code defining a specific algorithm intel compatible 14h 0000h 15h 0035h address for primary algorithm extended query table (see table 28. ) p = 35h 16h 0000h 17h 0000h alternate vendor command set and control interface id code second vendor - specified algorithm supported (0000h means none exists) na 18h 0000h 19h 0000h address for alternate algorithm extended query table (0000h means none exists) na 1ah 0000h M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 40/55 table 27. cfi query system interface information offset data description value 1bh 0027h v dd logic supply minimum program/erase or write voltage bit 7 to 4bcd value in volts bit 3 to 0bcd value in 100 mv 2.7v 1ch 0036h v dd logic supply maximum program/erase or write voltage bit 7 to 4bcd value in volts bit 3 to 0bcd value in 100 mv 3.6v 1dh 00b4h v pp [programming] supply minimum program/erase voltage bit 7 to 4hex value in volts bit 3 to 0bcd value in 100 mv 11.4v 1eh 00c6h v pp [programming] supply maximum program/erase voltage bit 7 to 4hex value in volts bit 3 to 0bcd value in 100 mv 12.6v 1fh 0004h typical time-out per single word program = 2 n s 16s 20h 0004h typical time-out for double/quadruple word program = 2 n s 16s 21h 000ah typical time-out per individual block erase = 2 n ms 1s 22h 0000h typical time-out for full chip erase = 2 n ms na 23h 0005h maximum time-out for word program = 2 n times typical 512s 24h 0005h maximum time-out for double/quadruple word program = 2 n times typical 512s 25h 0003h maximum time-out per individual block erase = 2 n times typical 8s 26h 0000h maximum time-out for chip erase = 2 n times typical na 41/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb table 28. device geometry definition offset word mode data description value M28W320FST m28w320fsb 27h 0016h device size = 2 n in number of bytes 4 mbyte m28w640fst m28w640fsb 0017h 8 mbyte 28h 29h 0001h 0000h flash device interface code description x16 async. 2ah 2bh 0003h 0000h maximum number of bytes in multi-byte program or page = 2 n 8 2ch 0002h number of erase block regions within the device. it specifies the number of regions within the device containing contiguous erase blocks of the same size. 2 M28W320FST 2dh 2eh 003eh 0000h region 1 information number of identical-size erase block = 003eh+1 63 2fh 30h 0000h 0001h region 1 information block size in region 1 = 0100h * 256 byte 64 kbyte 31h 32h 0007h 0000h region 2 information number of identical-size erase block = 0007h+1 8 33h 34h 0020h 0000h region 2 information block size in region 2 = 0020h * 256 byte 8 kbyte m28w320fsb 2dh 2eh 0007h 0000h region 1 information number of identical-size erase block = 0007h+1 8 2fh 30h 0020h 0000h region 1 information block size in region 1 = 0020h * 256 byte 8 kbyte 31h 32h 003eh 0000h region 2 information number of identical-size erase block = 003eh=1 63 33h 34h 0000h 0001h region 2 information block size in region 2 = 0100h * 256 byte 64 kbyte m28w640fst 2dh 2eh 007eh 0000h region 1 information number of identical-size erase block = 007eh+1 127 2fh 30h 0000h 0001h region 1 information block size in region 1 = 0100h * 256 byte 64 kbyte 31h 32h 0007h 0000h region 2 information number of identical-size erase block = 0007h+1 8 33h 34h 0020h 0000h region 2 information block size in region 2 = 0020h * 256 byte 8 kbyte M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 42/55 m28w640fsb 2dh 2eh 0007h 0000h region 1 information number of identical-size erase block = 0007h+1 8 2fh 30h 0020h 0000h region 1 information block size in region 1 = 0020h * 256 byte 8 kbyte 31h 32h 007eh 0000h region 2 information number of identical-size erase block = 007eh=1 127 33h 34h 0000h 0001h region 2 information block size in region 2 = 0100h * 256 byte 64 kbyte offset word mode data description value 43/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb table 29. primary algorithm-specific extended query table offset p = 35h (1) data description value (p+0)h = 35h 0050h primary algorithm extended query table unique ascii string ?pri? "p" (p+1)h = 36h 0052h "r" (p+2)h = 37h 0049h "i" (p+3)h = 38h 0031h major version number, ascii "1" (p+4)h = 39h 0030h minor version number, ascii "0" (p+5)h = 3ah 0066h extended query table contents for primary algorithm. address (p+5)h contains less significant byte. bit 0chip erase supported(1 = yes, 0 = no) bit 1suspend erase supported(1 = yes, 0 = no) bit 2suspend program supported(1 = yes, 0 = no) bit 3legacy lock/unlock supported(1 = yes, 0 = no) bit 4queued erase supported(1 = yes, 0 = no) bit 5instant individual block locking supported(1 = yes, 0 = no) bit 6protection bits supported(1 = yes, 0 = no) bit 7page mode read supported(1 = yes, 0 = no) bit 8synchronous read supported(1 = yes, 0 = no) bit 31 to 9reserved; undefined bits are ?0? no ye s ye s no no ye s ye s no no (p+6)h = 3bh 0000h (p+7)h = 3ch 0000h (p+8)h = 3dh 0000h (p+9)h = 3eh 0001h supported functions after suspend read array, read status register and cfi query are always supported during erase or program operation bit 0program supported after erase suspend (1 = yes, 0 = no) bit 7 to 1reserved; undefined bits are ?0? yes (p+a)h = 3fh 0003h block lock status defines which bits in the block status register section of the query are implemented. address (p+a)h contains less significant byte bit 0block lock status register lock/unlock bit active(1 = yes, 0 = no) bit 15 to 1reserved for future use; undefined bits are ?0? ye s ye s (p+b)h = 40h 0000h (p+c)h = 41h 0030h v dd logic supply optimum program/erase voltage (highest performance) bit 7 to 4hex value in volts bit 3 to 0bcd value in 100 mv 3v (p+d)h = 42h 00c0h v pp supply optimum program/erase voltage bit 7 to 4hex value in volts bit 3 to 0bcd value in 100 mv 12v (p+e)h = 43h 0001h number of protection register fields in jedec id space. "00h," indicates that 256 protection bytes are available 01 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 44/55 note: 1. see table 26. , offset 15 for p pointer definition. table 30. security code area (p+f)h = 44h 0080h protection field 1: protection description this field describes user-available one time programmable (otp) protection register bytes. some are pre-programmed with device unique serial numbers. others are user programmable. bits 0?15 point to the protection register lock byte, the section?s first byte. the following bytes are factory pre-programmed and user-programmable. bit 0 to 7 lock/bytes jedec-plane physical low address bit 8 to 15lock/bytes jedec-plane physical high address bit 16 to 23 "n" such that 2 n = factory pre-programmed bytes bit 24 to 31 "n" such that 2 n = user programmable bytes 80h (p+10)h = 45h 0000h 00h (p+11)h = 46h 0003h 8 bytes M28W320FST, m28w320fsb (p+12) h = 47h 0003h 8 bytes m28w640fst, m28w640fsb 0004h 16 bytes (p+13)h = 48h reserved offset data description 80h 00xx protection register lock 81h xxxx 64 bits: unique device number 82h xxxx 83h xxxx 84h xxxx 85h xxxx 128 bits: user programmable otp 86h xxxx 87h xxxx 88h xxxx 89h xxxx 8ah xxxx 8bh xxxx 8ch xxxx offset p = 35h (1) data description value 45/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb appendix c. flowcharts and pseudo codes figure 15. program flowchart and pseudo code note: 1. status check of b1 (protected block), b3 (v pp invalid) and b4 (program error) can be made after each program operation or after a sequence. 2. if an error is found, the status register must be cleared before further program/erase controller operations. write 40h or 10h ai03538b start write address & data read status register yes no b7 = 1 yes no b3 = 0 no b4 = 0 v pp invalid error (1, 2) program error (1, 2) program_command (addresstoprogram, datatoprogram) {: writetoflash (any_address, 0x40) ; /*or writetoflash (any_address, 0x10) ; */ do { status_register=readflash (any_address) ; /* e or g must be toggled*/ } while (status_register.b7== 0) ; if (status_register.b3==1) /*vpp invalid error */ error_handler ( ) ; yes end yes no b1 = 0 program to protected block error (1, 2) writetoflash (addresstoprogram, datatoprogram) ; /*memory enters read status state after the program command*/ if (status_register.b4==1) /*program error */ error_handler ( ) ; if (status_register.b1==1) /*program to protect block error */ error_handler ( ) ; } M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 46/55 figure 16. double word program flowchart and pseudo code note: 1. status check of b1 (protected block), b3 (v pp invalid) and b4 (program error) can be made after each program operation or after a sequence. 2. if an error is found, the status register must be cleared before further program/erase operations. 3. address 1 and address 2 must be consecutive addresses differing only for bit a0. write 30h ai03539b start write address 1 & data 1 (3) read status register yes no b7 = 1 yes no b3 = 0 no b4 = 0 v pp invalid error (1, 2) program error (1, 2) yes end yes no b1 = 0 program to protected block error (1, 2) write address 2 & data 2 (3) double_word_program_command (addresstoprogram1, datatoprogram1, addresstoprogram2, datatoprogram2) { writetoflash (any_address, 0x30) ; writetoflash (addresstoprogram1, datatoprogram1) ; /*see note (3) */ writetoflash (addresstoprogram2, datatoprogram2) ; /*see note (3) */ /*memory enters read status state after the program command*/ do { status_register=readflash (any_address) ; /* e or g must be toggled*/ } while (status_register.b7== 0) ; if (status_register.b3==1) /*vpp invalid error */ error_handler ( ) ; if (status_register.b4==1) /*program error */ error_handler ( ) ; if (status_register.b1==1) /*program to protect block error */ error_handler ( ) ; } 47/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb figure 17. quadruple word program flowchart and pseudo code note: 1. status check of b1 (protected block), b3 (v pp invalid) and b4 (program error) can be made after each program operation or after a sequence. 2. if an error is found, the status register must be cleared before further program/erase operations. 3. address 1 to address 4 must be consecutive addresses differing only for bits a0 and a1. write 56h ai06233 start write address 1 & data 1 (3) read status register yes no b7 = 1 yes no b3 = 0 no b4 = 0 v pp invalid error (1, 2) program error (1, 2) yes end yes no b1 = 0 program to protected block error (1, 2) write address 2 & data 2 (3) quadruple_word_program_command (addresstoprogram1, datatoprogram1, addresstoprogram2, datatoprogram2, addresstoprogram3, datatoprogram3, addresstoprogram4, datatoprogram4) { writetoflash (any_address, 0x56) ; writetoflash (addresstoprogram1, datatoprogram1) ; /*see note (3) */ writetoflash (addresstoprogram2, datatoprogram2) ; /*see note (3) */ writetoflash (addresstoprogram3, datatoprogram3) ; /*see note (3) */ writetoflash (addresstoprogram4, datatoprogram4) ; /*see note (3) */ /*memory enters read status state after the program command*/ do { status_register=readflash (any_address) ; /* e or g must be toggled*/ } while (status_register.b7== 0) ; if (status_register.b3==1) /*vpp invalid error */ error_handler ( ) ; if (status_register.b4==1) /*program error */ error_handler ( ) ; if (status_register.b1==1) /*program to protect block error */ error_handler ( ) ; } write address 3 & data 3 (3) write address 4 & data 4 (3) M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 48/55 figure 18. program suspend & resume flowchart and pseudo code write 70h ai03540b read status register yes no b7 = 1 yes no b2 = 1 program continues write d0h read data from another address start write b0h program complete write ffh read data program_suspend_command ( ) { writetoflash (any_address, 0xb0) ; writetoflash (any_address, 0x70) ; /* read status register to check if program has already completed */ do { status_register=readflash (any_address) ; /* e or g must be toggled*/ } while (status_register.b7== 0) ; if (status_register.b2==0) /*program completed */ { writetoflash (any_address, 0xff) ; read_data ( ) ; /*read data from another block*/ /*the device returns to read array (as if program/erase suspend was not issued).*/ } else { writetoflash (any_address, 0xff) ; read_data ( ); /*read data from another address*/ writetoflash (any_address, 0xd0) ; /*write 0xd0 to resume program*/ } } write ffh 49/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb figure 19. erase flowchart and pseudo code note: if an error is found, the status register must be cleared before further program/erase operations. write 20h ai03541b start write block address & d0h read status register yes no b7 = 1 yes no b3 = 0 yes b4, b5 = 1 v pp invalid error (1) command sequence error (1) no no b5 = 0 erase error (1) end yes no b1 = 0 erase to protected block error (1) yes erase_command ( blocktoerase ) { writetoflash (any_address, 0x20) ; writetoflash (blocktoerase, 0xd0) ; /* only a12-a20 are significannt */ /* memory enters read status state after the erase command */ } while (status_register.b7== 0) ; do { status_register=readflash (any_address) ; /* e or g must be toggled*/ if (status_register.b3==1) /*vpp invalid error */ error_handler ( ) ; if ( (status_register.b4==1) && (status_register.b5==1) ) /* command sequence error */ error_handler ( ) ; if (status_register.b1==1) /*program to protect block error */ error_handler ( ) ; if ( (status_register.b5==1) ) /* erase error */ error_handler ( ) ; } M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 50/55 figure 20. erase suspend & resume flowchart and pseudo code write 70h ai03542b read status register yes no b7 = 1 yes no b6 = 1 erase continues write d0h read data from another block or program/protection program or block protect/unprotect/lock start write b0h erase complete write ffh read data write ffh erase_suspend_command ( ) { writetoflash (any_address, 0xb0) ; writetoflash (any_address, 0x70) ; /* read status register to check if erase has already completed */ do { status_register=readflash (any_address) ; /* e or g must be toggled*/ } while (status_register.b7== 0) ; if (status_register.b6==0) /*erase completed */ { writetoflash (any_address, 0xff) ; read_data ( ) ; /*read data from another block*/ /*the device returns to read array (as if program/erase suspend was not issued).*/ } else { writetoflash (any_address, 0xff) ; read_program_data ( ); /*read or program data from another address*/ writetoflash (any_address, 0xd0) ; /*write 0xd0 to resume erase*/ } } 51/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb figure 21. protection register program flowchart and pseudo code note: 1. status check of b1 (protected block), b3 (v pp invalid) and b4 (program error) can be made after each program operation or after a sequence. 2. if an error is found, the status register must be cleared before further program/erase controller operations. write c0h ai04381 start write address & data read status register yes no b7 = 1 yes no b3 = 0 no b4 = 0 v pp invalid error (1, 2) program error (1, 2) protection_register_program_command (addresstoprogram, datatoprogram) {: writetoflash (any_address, 0xc0) ; do { status_register=readflash (any_address) ; /* e or g must be toggled*/ } while (status_register.b7== 0) ; if (status_register.b3==1) /*vpp invalid error */ error_handler ( ) ; yes end yes no b1 = 0 program to protected block error (1, 2) writetoflash (addresstoprogram, datatoprogram) ; /*memory enters read status state after the program command*/ if (status_register.b4==1) /*program error */ error_handler ( ) ; if (status_register.b1==1) /*program to protect block error */ error_handler ( ) ; } M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 52/55 appendix d. command interface and program/erase controller state table 31. write state machine current/next, sheet 1 of 2. note: cmd = command, elect.sg. = electronic signature, ers = erase, prog. = program, prot = protection, sus = suspend. current state sr bit 7 data when read command input (and next state) read array (ffh) program setup (10/40h) erase setup (20h) erase confirm (d0h) prog/ers suspend (b0h) prog/ers resume (d0h) read status (70h) clear status (50h) read array ?1? array read array prog.setup ers. setup read array read sts. read array read status ?1? status read array program setup erase setup read array read status read array read elect.sg. ?1? electronic signature read array program setup erase setup read array read status read array read cfi query ?1? cfi read array program setup erase setup read array read status read array prot. prog. setup ?1? status protection register program prot. prog. (continue) ?0? status protection register program continue prot. prog. (complete) ?1? status read array program setup erase setup read array read status read array prog. setup ?1? status program program (continue) ?0? status program (continue) prog. sus read sts program (continue) prog. sus status ?1? status prog. sus read array program suspend to read array program (continue) prog. sus read array program (continue) prog. sus read sts prog. sus read array prog. sus read array ?1? array prog. sus read array program suspend to read array program (continue) prog. sus read array program (continue) prog. sus read sts prog. sus read array prog. sus read elect.sg. ?1? electronic signature prog. sus read array program suspend to read array program (continue) prog. sus read array program (continue) prog. sus read sts prog. sus read array prog. sus read cfi ?1? cfi prog. sus read array program suspend to read array program (continue) prog. sus read array program (continue) prog. sus read sts prog. sus read array program (complete) ?1? status read array program setup erase setup read array read status read array erase setup ?1? status erase command error erase (continue) erase cmderror erase (continue) erase command error erase cmd.error ?1? status read array program setup erase setup read array read status read array erase (continue) ?0? status erase (continue) erase sus read sts erase (continue) erase sus read sts ?1? status erase sus read array program setup erase sus read array erase (continue) erase sus read array erase (continue) erase sus read sts erase sus read array erase sus read array ?1? array erase sus read array program setup erase sus read array erase (continue) erase sus read array erase (continue) erase sus read sts erase sus read array erase sus read elect.sg. ?1? electronic signature erase sus read array program setup erase sus read array erase (continue) erase sus read array erase (continue) erase sus read sts erase sus read array erase sus read cfi ?1? cfi erase sus read array program setup erase sus read array erase (continue) erase sus read array erase (continue) erase sus read sts erase sus read array erase (complete) ?1? status read array program setup erase setup read array read status read array 53/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb table 32. write state machine current/next, sheet 2 of 2. note: cmd = command, elect.sg. = electronic signature, prog. = program, prot = protection. current state command input (and next state) read elect.sg. (90h) read cfi query (98h) prot. prog. setup (c0h) read array read elect.sg. read cfi query prot. prog. setup read status read elect.sg. read cfi query prot. prog. setup read elect.sg. read elect.sg. read cfi query prot. prog. setup read cfi query read elect.sg. read cfi query prot. prog. setup prot. prog. setup protection register program prot. prog. (continue) protection register program (continue) prot. prog. (complete) read elect.sg. read cfi query prot. prog. setup prog. setup program program (continue) program (continue) prog. suspend read status prog. suspend read elect.sg. prog. suspend read cfi query program suspend read array prog. suspend read array prog. suspend read elect.sg. prog. suspend read cfi query program suspend read array prog. suspend read elect.sg. prog. suspend read elect.sg. prog. suspend read cfi query program suspend read array prog. suspend read cfi prog. suspend read elect.sg. prog. suspend read cfi query program suspend read array program (complete) read elect.sg. read cfiquery prot. prog. setup erase setup erase command error erase cmd.error read elect.sg. read cfi query prot. prog. setup erase (continue) erase (continue) erase suspend read ststus erase suspend read elect.sg. erase suspend read cfi query erase suspend read array erase suspend read array erase suspend read elect.sg. erase suspend read cfi query erase suspend read array erase suspend read elect.sg. erase suspend read elect.sg. erase suspend read cfi query erase suspend read array erase suspend read cfi query erase suspend read elect.sg. erase suspend read cfi query erase suspend read array erase (complete) read elect.sg. read cfi query prot. prog. setup M28W320FST, m28w320fsb, m28w640fst, m28w640fsb 54/55 revision history table 33. document revision history date version revision details 13-jul-2004 0.1 first issue. 05-nov-2004 0.2 du (?do not use?) pins changed to nc (?not connected?) in figure 4., tbga connections (top view through package) . 20-jan-2005 0.3 data at address 47h differentiated for m28w320fs and m28w640fs in table 29., primary algorithm-specific extended query table . 15-mar-2005 1.0 datasheet status promoted to preliminary data. 01-aug-2005 2.0 datasheet status promoted to full datasheet. ecopack text updated. 55/55 M28W320FST, m28w320fsb, m28w640fst, m28w640fsb information furnished is believed to be accurate and reliable. however, stmicroelectronics assumes no responsibility for the co nsequences of use of such information nor for any infringement of patents or other rights of third parties which may result from its use. no license is granted by implication or otherwise under any patent or patent rights of stmicroelectronics. specifications mentioned in this publicati on are subject to change without notice. this publication supersedes and replaces all information previously supplied. stmicroelectronics prod ucts are not authorized for use as critical components in life support devices or systems without express written approval of stmicroelectro nics. the st logo is a registered trademark of stmicroelectronics. ecopack is a registered trademark of stmicroelectronics. all other names are the property of their respective owners ? 2005 stmicroelectronics - all rights reserved stmicroelectronics group of companies australia - belgium - brazil - canada - china - czech republic - finland - france - germany - hong kong - india - israel - ital y - japan - malaysia - malta - morocco - singapore - spain - sweden - switzerland - united kingdom - united states of america www.st.com |
Price & Availability of M28W320FST |
|
|
All Rights Reserved © IC-ON-LINE 2003 - 2022 |
[Add Bookmark] [Contact Us] [Link exchange] [Privacy policy] |
Mirror Sites : [www.datasheet.hk]
[www.maxim4u.com] [www.ic-on-line.cn]
[www.ic-on-line.com] [www.ic-on-line.net]
[www.alldatasheet.com.cn]
[www.gdcy.com]
[www.gdcy.net] |