This addendum describes corrections to the
MPC5604B/C Microcontr oller Refer ence Manual, order
number MPC5604BCRM. For convenience, the addenda
items are grouped by revision. Please check our website
at http://www.freescale.com/powerarchitecture for the
latest updates.
The current version available of the MPC5604B/C Microcontroller Reference Manual is Revision 8.1.
Table of Contents
1Addendum List for Revision 8.1 . . . . . . . . . . . . . . 2
Add a note below Table 27-4, “CFlash TestFlash Structure”.
NOTE
Unique Device ID – Memory location. This device now includes a 128-bit Unique
Identification number (UID) which is programmed during device fabrication.
Start – Stop Address Size (Bytes) Content:
•0x00403C10 0x00403C17 8 UID 1
•0x00403C18 0x00403C1F 8 UID 2
2Addendum List for Revision 8
Table 2. MPC5604BCRM Rev 8 Addenda
LocationDescription
Chapter 4, Signal description,
page 60
Chapter 6, Clock Description,
page 113
Chapter 9, Reset Generation
Module (MC_RGM), page
209
In Table 4-3, Functional port pin descriptions, row PH[9], change the pin numbers for
MPC560xB 64 LQFP and MPC560xC 64 LQFP from “—” to 60.
In row PH[10], change the pin numbers for MPC560xB 64 LQFP and MPC560xC 64 LQFP
from “—” to 53.
Add Note: to Section 6.8.4.1, Crystal clock monitor:
Note: Functional FXOSC monitoring can only be guaranteed when the FXOSC frequency is
greater than (FIRC / 2
Add Note: to Section 6.8.4.2, FMPLL clock monitor:
Note: Functional FMPLL monitoring can only be guaranteed when the FMPLL frequency is
greater than (FIRC / 4) + 0.5 MHz.
Replace Section 9.4.7, Boot Mode Capturing, with the following:
The MC_RGM samples P A[9:8] whenev er RESET is asserted until five FIRC (16 MHz internal
RC oscillator) clock cycles before its deassertion edge. The result of the sampling is used at
the beginning of reset PHASE3 for boot mode selection and is retained after RESET has been
deasserted for subsequent boots after reset sequences during which RESET is not asserted.
RCDIV
)+0.5MHz.
Chapter 13, Real Time Clock /
Autonomous Periodic
Interrupt (RTC/API), page
262
Note: In order to ensure that the boot mode is correctly captured, the application needs to
apply the valid boot mode value the entire time that RESET is asserted.
RESET can be asserted as a consequence of the internal reset generation. This will force
re-sampling of the boot mode pins. (See Table 9-12 for details.)
In Table 13-3 (RTCC field descriptions), update Note in RTCC[APIVAL] field description:
Note: API functionality starts only when APIVAL is nonzero. The first API interrupt takes two
more cycles because of synchronization of APIVAL to the RTC cloc k, and APIVAL + 1 cycles
for subsequent occurrences. After that, interrupts are periodic in nature. Because of
synchronization issues, the minimum supported value of APIVAL is 4.
MPC5604BRMAD, Rev. 2
Freescale Semiconductor2
Page 4
Table 2. MPC5604BCRM Rev 8 Addenda
LocationDescription
Chapter 21, LINFlex, p. 412Insert the following section:
21.8.2.1.6Overrun
Once the message buffer is full, the next valid message reception leads to an
overrun and a message is lost. The hardware sets the BOF bit in the LINSR to
signal the overrun condition. Which message is lost depends on the
configuration of the RX message buffer:
•If the buffer lock function is disabled (LINCR1[RBLM] = 0) the last
message stored in the buffer is overwritten by the new incoming
message. In this case the latest message is always available to the
application.
•If the buffer lock function is enabled (LINCR1[RBLM] = 0) the most
recent message is discarded and the previous message is available in the
buffer.
Chapter 22, FlexCAN,
throughout chapter
Chapter 22, FlexCAN, page
429
Chapter 22, FlexCAN, page
461
Chapter 22, FlexCAN, page
462
Chapter 22, FlexCAN, page
463
Chapter 25, Analog-to-Digital
Converter (ADC), page
Chapter 25, Analog-to-Digital
Converter (ADC), page 597
Remove references throughout the chapter to “low-cost MCUs.”
Add this Note in the RTR field description of Table 22-4 (Message Buffer Structure field
description):
Note: Do not configure the last Message Buffer to be the RTR frame.
In Section 22.4.9.4, Protocol timing, update the Note following Figure 22-16 (CAN engine
clocking scheme) to read: “This clock selection feature may not be available in all MCUs. A
particular MCU may not have a PLL, in which case it would have only the oscillator clock, or
it may use only the PLL clock feeding the FlexCAN module. In these cases, the CLK_SRC bit
in the CTRL Register has no effect on the module operation.”
Update the table title of Table 22-20 from “CAN Standard Compliant Bit Time Segment Settings”
to “Bosch CAN 2.0B standard compliant bit time segment settings.”
In Section 22.4.9.4, Protocol timing, update the Note following Table 22-20 to read: “Other
combinations of Time Segment 1 and Time Segment 2 can be valid. It is the user’s
responsibility to ensure the bit time settings are in compliance with the CAN standard. For bit
time calculations, use an IPT (Information Processing Time) of 2, which is the value
implemented in the FlexCAN module.”
In Section 28.3.5.2, Presampling channel enable signals, in Table 28-7, Presampling voltage
selection based on PREVALx fields, in the 01 row, change the “Presampling voltage” field to:
V1 = V
DD_HV_ADC0
In Section 25.3.2, Analog clock generator and conversion timings, remove the paragraph:
The direct clock should basically be used only in low power mode when the device is using
only the 16 MHz fast internal RC oscillator, but the conversion still requires a 16 MHz clock
(an 8 MHz clock is not fast enough). In all other cases, the ADC should use the clock divided
by two internally.
or V
DD_HV_ADC1
.
MPC5604BRMAD, Rev. 2
Freescale Semiconductor 3
Page 5
Table 2. MPC5604BCRM Rev 8 Addenda
LocationDescription
Chapter 25, Analog-to-Digital
Converter (ADC), p. 600
Chapter 25, Analog-to-Digital
Converter (ADC), page 603
Chapter 25, Analog-to-Digital
Converter (ADC), page 610
Chapter 26, Cross Triggering
Unit (CTU), page 633
In Section 25.3.4.2, CTU in trigger mode, replace the sentence:
If another CTU conversion is triggered before the end of the conversion, that request is
discarded.
with:
If another CTU conversion is triggered before the end of the conversion, that request is
discarded. However, if the CTU has triggered a conversion that is still ongoing on a channel,
it will buffer a second request fo r the channel and wait for the end of the first conv ersion before
requesting another conversion. Thus, two conversion requests close together will both be
serviced.
Add Note to Section 25.3.10, Auto-clock-off mode:
Note: The auto-clock-off feature cannot operate when the digital interface runs at the same
rate as the analog interface. This means that when MCR.ADCCLKSEL = 1, the analog clock
will not shut down in IDLE mode.
In Section 25.4.6.2, Main Status Register (MSR), replace the ADCST ATUS field description with
the following:
The value of this parameter depends on ADC status:
000 IDLE — The ADC is powered up but idle.
001 Power-down — The ADC is powered down.
010 Wait state — The ADC is waiting for an external multiplexer . This occurs only when the
DSDR register is nonzero.
011 Reserved
100 Sample — The ADC is sampling the analog signal.
101 Reserved
110 Conversion — The ADC is converting the sampled signal.
111 Reserved
At the end of Section 26.4.1, Event Configuration Registers (CTU_EVTCFGRx) (x = 0...63), add
the following Note:
NOTE
The CTU tracks issued conversion requests to the ADC. When the ADC
is being triggered by the CTU and there is a need to shut down the ADC,
the ADC must be allowed to complete conversions before being shut
down. This ensures that the CTU is notified of completion; if the ADC
is shut down while performing a CTU-triggered conversion, the CTU is
not notified and will not be able to trigger further conversions until the
device is reset.
3Revision History
Table 3 provides a revision history for this reference manual addendum document.
Table 3. Revision History Table
Rev. NumberSubstantive ChangesDate of Release
2.0Add a note below Table 27-4, “CFlash TestFlash Structure”09/2013
1.0Initial release.05/2012
MPC5604BRMAD, Rev. 2
Freescale Semiconductor4
Page 6
How to Reach Us:
Home Page:
www.freescale.com
Web Support:
http://www.freescale.com/support
USA/Europe or Locations Not Listed:
Freescale Semiconductor, Inc.
Technical Information Center, EL516
2100 East Elliot Road
Tempe, Arizona 85284
+1-800-521-6274 or +1-480-768-2130
www.freescale.com/support
Freescale Semiconductor Japan Ltd.
Headquarters
ARCO Tower 15F
1-8-1, Shimo-Meguro, Meguro-ku,
Tokyo 153-0064
Japan
0120 191014 or +81 3 5437 9125
[email protected]
Asia/Pacific:
Freescale Semiconductor China Ltd.
Exchange Building 23F
No. 118 Jianguo Road
Chaoyang District
Beijing 100022
China
+86 10 5879 8000
[email protected]
For Literature Requests Only:
Freescale Semiconductor Literature Distribution Center
1-800-441-2447 or 303-675-2140
Fax: 303-675-2150
[email protected]
Information in this document is provided solely to enable system and
software implementers to use F reescale S emiconductor prod ucts. There ar e
no express or implied copyright licenses granted hereunder to design or
fabricate any integrated circuits or integrated circuits based on the
information in this document.
Freescale Semiconducto r reserves the right to mak e changes without further
notice to any products herein. F reescale Se miconductor m akes no w arranty,
representation or guarantee regarding the suitability of its products for any
particular purpose, nor does Freescale Semiconductor assume any liability
arising out of the application or use of any produ ct or circuit, an d specific ally
disclaims any and all liability, including without limitation consequential or
incidental damages. “Typical” par ameter s that m a y be pro vided in Freescale
Semiconductor data sheets and/or speci fications can and do v ary in differ ent
applications and actual performance may vary over time. All operating
parameters, including “Typicals”, must be validated for each customer
application by customer’s technical experts. Freescale Semiconductor does
not convey any license under its patent rights nor the rights of others.
Freescale Semicondu ctor products are not de signed, intended, or authorized
for use as components in systems intended for surgical implant into the body ,
or other applications intended to support or sustain life, or for any other
application in which the failure of the Freescale Semiconductor product could
create a situation where personal injury or death may occur. Should Buyer
purchase or use Freescal e Semiconductor products f or an y such unintended
or unauthorized application, B uyer sha ll indemnify and hold Freescale
Semiconductor and its officers, employees, subsidiaries, affiliates, and
distributors harmless against all claims, costs, damages, and expenses, and
reasonable attorney fees arising out of, directly or indirectly, any claim of
personal injury or death associated with such unintended or unauthorized
use, even if such claim alleges that Freescale Semiconductor was negligent
regarding the design or manufacture of the part.
This addendum document describes corrections to the
MPC5604B/C Microcontr oller Refer ence Manual, order
number MPC5604BCRM. For convenience, the addenda
items are grouped by revision. Please check our website
at http://www.freescale.com/powerarchitecture for the
latest updates.
The current version available of the MPC5604B/C Microcontroller Reference Manual is Revision 8.
Chapter 21, LINFlex, p. 412Insert the following section:
In Table 4-3, Functional port pin descriptions, row PH[9], change the pin numbers for
MPC560xB 64 LQFP and MPC560xC 64 LQFP from “—” to 60.
In row PH[10], change the pin numbers for MPC560xB 64 LQFP and MPC560xC 64 LQFP
from “—” to 53.
Add Note: to Section 6.8.4.1, Crystal clock monitor:
Note: Functional FXOSC monitoring can only be guaranteed when the FXOSC frequency is
greater than (FIRC / 2
Add Note: to Section 6.8.4.2, FMPLL clock monitor:
Note: Functional FMPLL monitoring can only be guaranteed when the FMPLL frequency is
greater than (FIRC / 4) + 0.5 MHz.
Replaced Section 9.4.7, Boot Mode Capturing, with the following:
The MC_RGM samples P A[9:8] whenev er RESET is asserted until five FIRC (16 MHz internal
RC oscillator) clock cycles before its deassertion edge. The result of the sampling is used at
the beginning of reset PHASE3 for boot mode selection and is retained after RESET has been
deasserted for subsequent boots after reset sequences during which RESET is not asserted.
Note: In order to ensure that the boot mode is correctly captured, the application needs to
apply the valid boot mode value the entire time that RESET is asserted.
RESET can be asserted as a consequence of the internal reset generation. This will force
re-sampling of the boot mode pins. (See Table 9-12 for details.)
In Table 13-3 (RTCC field descriptions), update Note in RTCC[APIVAL] field description:
Note: API functionality starts only when APIVAL is nonzero. The first API interrupt takes two
more cycles because of synchronization of APIVAL to the RTC cloc k, and APIVAL + 1 cycles
for subsequent occurrences. After that, interrupts are periodic in nature. Because of
synchronization issues, the minimum supported value of APIVAL is 4.
RCDIV
)+0.5MHz.
21.8.2.1.6Overrun
Once the message buffer is full, the next valid message reception leads to an
overrun and a message is lost. The hardware sets the BOF bit in the LINSR to
signal the overrun condition. Which message is lost depends on the
configuration of the RX message buffer:
•If the buffer lock function is disabled (LINCR1[RBLM] = 0) the last
message stored in the buffer is overwritten by the new incoming
message. In this case the latest message is always available to the
application.
•If the buffer lock function is enabled (LINCR1[RBLM] = 0) the most
recent message is discarded and the previous message is available in the
buffer.
MPC5604B Reference Manual Errata, Rev. 1
Freescale Semiconductor2
Page 10
Table 1. MPC5604BCRM Rev 8 Addenda
LocationDescription
Addendum List for Revision 8
Chapter 22, FlexCAN,
throughout chapter
Chapter 22, FlexCAN, page
429
Chapter 22, FlexCAN, page
461
Chapter 22, FlexCAN, page
462
Chapter 22, FlexCAN, page
463
Chapter 25, Analog-to-Digital
Converter (ADC), page
Chapter 25, Analog-to-Digital
Converter (ADC), page 597
Remove references throughout the chapter to “low-cost MCUs.”
Added this Note in the RTR field description of Table 22-4 (Message Buffer Structure field
description):
Note: Do not configure the last Message Buffer to be the RTR frame.
In Section 22.4.9.4, Protocol timing, updated the Note following Figure 22-16 (CAN engine
clocking scheme) to read: “This clock selection feature may not be available in all MCUs. A
particular MCU may not have a PLL, in which case it would have only the oscillator clock, or
it may use only the PLL clock feeding the FlexCAN module. In these cases, the CLK_SRC bit
in the CTRL Register has no effect on the module operation.”
Updated the table title of Table 22-20 from “CAN Standard Compliant Bit Time Segment
Settings” to “Bosch CAN 2.0B standard compliant bit time segment settings.”
In Section 22.4.9.4, Protocol timing, updated the Note following Table 22-20 to read: “Other
combinations of Time Segment 1 and Time Segment 2 can be valid. It is the user’s
responsibility to ensure the bit time settings are in compliance with the CAN standard. For bit
time calculations, use an IPT (Information Processing Time) of 2, which is the value
implemented in the FlexCAN module.”
In Section 28.3.5.2, Presampling channel enable signals, in Table 28-7, Presampling voltage
selection based on PREVALx fields, in the 01 row, change the “Presampling voltage” field to:
V1 = V
DD_HV_ADC0
or V
DD_HV_ADC1
.
In Section 25.3.2, Analog clock generator and conversion timings, remove the paragraph:
The direct clock should basically be used only in low power mode when the device is using
only the 16 MHz fast internal RC oscillator, but the conversion still requires a 16 MHz clock
(an 8 MHz clock is not fast enough). In all other cases, the ADC should use the clock divided
by two internally.
Chapter 25, Analog-to-Digital
Converter (ADC), p. 600
In Section 25.3.4.2, CTU in trigger mode, replace the sentence:
If another CTU conversion is triggered before the end of the conversion, that request is
discarded.
with:
If another CTU conversion is triggered before the end of the conversion, that request is
discarded. However, if the CTU has triggered a conversion that is still ongoing on a channel,
it will buffer a second request fo r the channel and wait for the end of the first conv ersion before
requesting another conversion. Thus, two conversion requests close together will both be
serviced.
Chapter 25, Analog-to-Digital
Converter (ADC), page 603
Add Note to Section 25.3.10, Auto-clock-off mode:
Note: The auto-clock-off feature cannot operate when the digital interface runs at the same
rate as the analog interface. This means that when MCR.ADCCLKSEL = 1, the analog clock
will not shut down in IDLE mode.
MPC5604B Reference Manual Errata, Rev. 1
Freescale Semiconductor 3
Page 11
Revision History
LocationDescription
Table 1. MPC5604BCRM Rev 8 Addenda
Chapter 25, Analog-to-Digital
Converter (ADC), page 610
Chapter 26, Cross Triggering
Unit (CTU), page 633
In Section 25.4.6.2, Main Status Register (MSR), replace the ADCSTATUS field description with
the following:
The value of this parameter depends on ADC status:
000 IDLE — The ADC is powered up but idle.
001 Power-down — The ADC is powered down.
010 Wait state — The ADC is waiting for an external multiplexer . This occurs only when the
DSDR register is nonzero.
011 Reserved
100 Sample — The ADC is sampling the analog signal.
101 Reserved
110 Conversion — The ADC is converting the sampled signal.
111 Reserved
At the end of Section 26.4.1, Event Configuration Registers (CTU_EVTCFGRx) (x = 0...63), add
the following Note:
NOTE
The CTU tracks issued conversion requests to the ADC. When the ADC
is being triggered by the CTU and there is a need to shut down the ADC,
the ADC must be allowed to complete conversions before being shut
down. This ensures that the CTU is notified of completion; if the ADC
is shut down while performing a CTU-triggered conversion, the CTU is
not notified and will not be able to trigger further conversions until the
device is reset.
2Revision History
Table 2 provides a revision history for this reference manual addendum document.
12.2 Features .........................................................................................................................................231
12.3 External signal description ............................................................................................................231
12.4 Memory map and register description ...........................................................................................231
13.2 Features .........................................................................................................................................243
13.3 Device-specific information ..........................................................................................................245
13.4 Modes of operation ........................................................................................................................245
14.2 Main features .................................................................................................................................253
15.4 Features .........................................................................................................................................263
15.4.1Instruction unit features ................................................................................................264
15.4.2Integer unit features ......................................................................................................264
15.4.3Load/Store unit features ...............................................................................................265
15.4.4e200z0h system bus features ........................................................................................265
15.4.5Nexus 2+ features .........................................................................................................265
15.5 Core registers and programmer’s model .......................................................................................266
16.2 Features .........................................................................................................................................269
17.4 Features .........................................................................................................................................302
17.5 Modes of operation ........................................................................................................................302
18.2 Features .........................................................................................................................................308
18.3 Modes of operation ........................................................................................................................309
18.4 External signal description ............................................................................................................309
18.5 Memory map and register description ...........................................................................................309
19.3 Features .........................................................................................................................................329
19.4 External signal description ............................................................................................................329
19.4.1Detailed signal descriptions ..........................................................................................330
19.5 Memory map and register description ...........................................................................................331
21.2 Main features .................................................................................................................................377
21.2.1LIN mode features ........................................................................................................377
21.2.2UART mode features ....................................................................................................377
21.2.3Features common to LIN and UART ...........................................................................377
21.3 General description .......................................................................................................................378
21.5.3Low power mode (Sleep) .............................................................................................382
21.6 Test modes .....................................................................................................................................382
21.6.1Loop Back mode ...........................................................................................................382
21.6.2Self Test mode ..............................................................................................................383
21.7 Memory map and registers description .........................................................................................383
23.2 Features .........................................................................................................................................470
23.3 Modes of operation ........................................................................................................................471
26.2 Main features .................................................................................................................................631
27.2 Main features .................................................................................................................................640
29.2 Features .........................................................................................................................................741
30.2 Features .........................................................................................................................................755
30.3 Modes of operation ........................................................................................................................755
30.4 External signal description ............................................................................................................756
30.5 Memory map and register description ...........................................................................................756
31.3 Features .........................................................................................................................................763
31.4 Memory map and register description ...........................................................................................763
32.4 Features .........................................................................................................................................788
32.5 Modes of operation ........................................................................................................................788
33.3 Features .........................................................................................................................................802
33.4 Modes of Operation .......................................................................................................................803
The primary objective of this document is to define the functionality of the MPC5604B microcontroller
for use by software and hardware developers. The MPC5604B is built on Power Architecture® technology
and integrates technologies that are important for today’s automotive vehicle body applications.
The information in this book is subject to change without notice, as described in the disclaimers on the title
page. As with any technical documentation, it is the reader’s responsibility to be sure he or she is using the
most recent version of the documentation.
To locate any published errata or updates for this document, visit the Freescale Web site at
http://www.freescale.com/.
1.2Audience
This manual is intended for system software and hardware developers and applications programmers who
want to develop products with the MPC5604B device. It is assumed that the reader understands operating
systems, microprocessor system design, basic principles of software and hardware, and basic details of the
Power Architecture.
1.3Guide to this reference manual
Table 1-1. Guide to this reference manual
Chapter
#Title
2IntroductionGeneral overview, family description, feature list and
information on how to use the reference manual in
conjunction with other available documents.
3Memory MapMemory map of all peripherals and memory.Memory map
4Signal descriptionPinout diagrams and descriptions of all pads.Signals
5Microcontroller BootBoot
• Boot mechanism • Describes what configuration is required by the
user and what processes are involved when the
microcontroller boots from flash memory or serial
boot modes.
• Describes censorship.
• Boot Assist Module (BAM)Features of BAM code and when it's used.
• System Status and
Configuration Module
(SSCM)
Reports information about current state and
configuration of the microcontroller.
How to configure the pins or ports for input or output
functions including external interrupts and DSI
serialization.
Core platform
modules
Por ts
Page 32
Table 1-1. Guide to this reference manual (continued)
Chapter
#Title
DescriptionFunctional group
20Inter-Integrated Circuit Bus
Controller Module (I2C)
21LIN Controller (LINFlex)
22FlexCAN
23Deserial Serial Peripheral
Interface (DSPI)
24TimersTimer modules
• Technical overviewGives an overview of the available system timer
• System Timer Module
(STM)
• Enhanced Modular IO
Subsystem (eMIOS)
• Periodic Interrupt Timer
(PIT)
25Analog-to-Digital Converter
(ADC)
These chapters describe the configuration and
operation of the various communication modules.
Some of these modules support eDMA requests to fill
/ empty buffer queues to minimize CPU overhead.
modules showing links to other modules as well as
tables detailing the external pins associated with
eMIOS timer channels.
A simple 32-bit free running counter with 4 compare
channels with interrupt on match. It can be read at any
time; this is very useful for measuring execution times.
Highly configurable timer module(s) supporting PWM,
output compare and input capture features. Includes
interrupt and eDMA support.
Set of 32-bit countdown timers that provide periodic
events (which can trigger an interrupt) with automatic
re-load.
Details the configuration and operation of the ADC
modules as well as detailing the channels that are
shared between the 10-bit and 12-bit ADC. The ADC
is tightly linked to the INTC, eDMA, PIT_RTI and CTU.
When used in conjunction with these other modules,
the CPU overhead for an ADC conversion is
significantly reduced.
Communication
modules
ADC system
26Cross Triggering Unit (CTU)The CTU allows an ADC conversion to be
automatically triggered based on an eMIOS event (like
a PWM output going high) or a PIT_RTI event with no
CPU intervention.
27Flash MemoryDetails the code and data flash memory structure
(with ECC), block sizes and the flash memory port
configuration, including wait states, line buffer
configuration and pre-fetch control.
28Static RAM (SRAM)Details the structure of the SRAM (with ECC). There
are no user configurable registers associated with the
SRAM.
Table 1-1. Guide to this reference manual (continued)
Chapter
#Title
DescriptionFunctional group
29Register ProtectionCertain registers in each peripheral can be protected
from further writes using the register protection
mechanism detailed in this section. Registers can
either be configured to be unlocked via a soft lock bit
or locked unit the next reset.
30Software Watchdog Timer
(SWT)
31Error Correction Status Module
(ECSM)
32IEEE 1149.1 Test Access Port
Controller (JTAGC)
33Nexus Development Interface
(NDI)
ARegister MapSummarizes the registers on this microcontrollerRegister summary
BRevision HistorySummarizes the changes between each successive
The SWT offers a selection of configurable modes that
can be used to monitor the operation of the
microcontroller and /or reset the device or trigger an
interrupt if the SWT is not correctly serviced. The SWT
is enabled out of reset.
Provides information about the last reset, general
device information, system fault information and
detailed ECC error information.
Used for boundary scan as well as device debug.Debug
Provides advanced debug features including non
intrusive trace capabilities.
revision of this reference manual
1.4Register description conventions
Integrity
Revision history
information
The register information for MPC5604B is presented in:
•Memory maps containing:
— An offset from the module’s base address
— The name and acronym/abbreviation of each register
— The page number on which each register is described
•Register figures
•Field-description tables
•Associated text
The register figures show the field structure using the conventions in Figure 1-1.
The numbering of register bits and fields on MPC5604B is as follows:
•Register bit numbers, shown at the top of each figure, use the standard Power Architecture bit
ordering (0, 1, 2, ...) where bit 0 is the most significant bit (MSB).
•Multi-bit fields within a register use conventional bit ordering (..., 2, 1, 0) where bit 0 is the least
significant bit (LSB).
1.5References
In addition to this reference manual, the following documents provide additional information on the
operation of the MPC5604B:
•IEEE-ISTO 5001-2003 Standard for a Global Embedded Processor Interface (Nexus)
•IEEE 1149.1-2001 standard - IEEE Standard Test Access Port and Boundary-Scan Architecture
•Power Architecture Book E V1.0
(http://www.freescale.com/files/32bit/doc/user_guide/BOOK_EUM.pdf)
1.6How to use the MPC5604B documents
This section:
•Describes how the MPC5604B documents provide information on the microcontroller
•Makes recommendations on how to use the documents in a system design
1.6.1The MPC5604B document set
The MPC5604B document set comprises:
•This reference manual (provides information on the features of the logical blocks on the device and
how they are integrated with each other)
•The device data sheet (specifies the electrical characteristics of the device)
•The device product brief
The following reference documents (available online at www .freescale.com) are also available to support
the CPU on this device:
The aforementioned documents describe all of the functional and electrical characteristics of the
MPC5604B microcontroller.
Depending on your task, you may need to refer to multiple documents to make design decisions. However,
in general the use of the documents can be divided up as follows:
•Use the reference manual (this document) during software development and when allocating
functions during system design.
•Use the data sheet when designing hardware and optimizing power consumption.
•Use the CPU reference documents when doing detailed software development in assembly
language or debugging complex software interactions.
1.6.2Reference manual content
The content in this document focuses on the functionality of the microcontroller rather than its
performance. Most chapters describe the functionality of a particular on-chip module, such as a CAN
controller or timer. The remaining chapters describe how these modules are integrated into the memory
map, how they are powered and clocked, and the pin-out of the device.
In general, when an individual module is enabled for use all of the detail required to configure and operate
it is contained in the dedicated chapter. In some cases there are multiple implementations of this module,
however, there is only one chapter for each type of module in use. For this reas on, the address of registers
in each module is normally provided as an offset from a base address which can be found in Chapter 3,
Memory Map. The benefit of this approach is that software developed for a particular module can be easily
reused on this device and on other related devices that use the same modules.
The steps to enable a module for use varies but typically these require configuration of the integration
features of the microcontroller . The module will normally have to be powered and enabled at system level,
then a clock may have to be explicitly chosen and finally if required the input and output connections to
the external system must be configured.
The primary integration chapters of the reference manual contain most of the information required to
enable the modules. There are special cases where a chapter may describe module functionality and some
integration features for convenience — for example, the microcontroller input/output (SIUL) module.
Integration and functional content is provided in the manual as shown in Table 1-2.
Table 1-2. Reference manual integration and functional content
ChapterIntegration contentFunctional content
Introduction • The main features on chip
• A summary of the functions provided by
each module
Memory MapHow the memory map is allocated,
including:
• Internal RAM
• Flash memory
• External memory-mapped resources
and the location of the registers used by
the peripherals
Signal DescriptionHow the signals from each of the modules
are combined and brought to a particular
pin on a package
Boot Assist ModuleCPU boot sequence from resetImplementation of the boot options if
Clock DescriptionClocking architecture of the device (which
clock is available for the system and each
peripheral)
Interrupt ControllerInterrupt vector tableOperation of the module
Mode Entry ModuleModule numbering for control and statusOperation of operating modes
System Integration Unit
Lite
How input signals are mapped to individual
modules including external interrupt pins
1
—
—
—
internal flash memory is not used
Description of operation of different clock
sources
Operation of GPIO
Voltage regulators and
power supplies
Wakeup UnitAllocation of inputs to the Wakeup UnitOperation of the wakeup feature
1
To find the address of a register in a particular module take the start address of the module given in the memory
map and add the offset for the register given in the module chapter.
Power distribution to the MCU—
1.7Using the MPC5604B
There are many different approaches to designing a system using the MPC5604B so the guidance in this
section is provided as an example of how the documents can be applied in this task.
Familiarity with the MPC5604B modules can help ensure that its features are being optimally used in a
system design. Therefore, the current chapter is a good starting point. Further information on the detailed
features of a module are provided within the module chapters. These, combined with the current chapter,
should provide a good introduction to the functions available on the MCU.
1.7.1Hardware design
The MPC5604B requires that certain pins are connected to particular power supplies, system functions and
other voltage levels for operation.
The MPC5604B internal logic operates from 1.2 V (nominal) supplies that are normally supplied by the
on-chip voltage regulator from a 5 V or 3.3 V supply. The 3.3–5 V (±10%) supply is also used to supply
the input/output pins on the MCU. Chapter 4, Signal description, describes the power supply pin names,
numbers and their purpose. For more detail on the voltage supply of each pin, see Chapter 11, Voltage
Regulators and Power Supplies. For specifications of the voltage ranges and limits and decoupling of the
power supplies see the MPC5604B data sheet.
Certain pins have dedicated functions that affect the behavior of the MCU after reset. These include pins
to force test or alternate boot conditions and debug features. These are described in Chapter 4, Signal
description, and a hardware designer should take care that these pins are connected to allow correct
operation.
Beyond power supply and pins that have special functions there are also pins that have special system
purposes such as oscillator and reset pins. These are also described in Chapter 4, Signal description. The
reset pin is bidirectional and its function is closely tied to the reset generation module [Chapter 9, Reset
Generation Module (MC_RGM)”]. The crystal oscillator pins are dedicated to this function but the
oscillator is not started automatically after reset. The oscillator module is described in Chapter 6, Clock
Description, along with the internal clock architecture and the other oscillator sources on chip.
1.7.2Input/output pins
The majority of the pins on the MCU are input/output pins which may either operate as general purpose
pins or be connected to a particular on-chip module. The arrangement allows a function to be available on
several pins. The system designer should allocate the function for the pin before connecting to external
hardware. The software should then choose the correct function to match the hardware. The pad
characteristics can vary depending on the functions on the pad. Chapter 4, Signal description, describes
each pad type (for example, S, M, or J). T wo pads may be able to carry the same function but have different
pad types. The electrical specification of the pads is described in the data sheet dependent on the function
enabled and the pad type.
There are three modules that configure the various functions available:
•System Integration Unit Lite (SIUL)
•Wakeup Unit (WKPU)
•32 KHz oscillator (SXOSC)
The SIUL configures the digital pin functions. Each pin has a register (PCR) in the module that allows
selection of the output functions that is connected to the pin. The available settings for the PCR are
described in Section 4.7, Functional ports. Inputs are selected using the PSMI registers; these are described
in Chapter 19, System Integration Unit Lite (SIUL). (PSMI registers connect a module to one of several
pins, whereas the PCR registers connect a pin to one of several modules).
The WKPU provides the ability to cause interrupts and wake the MCU from low power modes and
operates independently from the SIUL.
In addition to digital I/O functions the SXOSC is a "special function" that provides a slow external crystal.
The SXOSC is enabled independently from the digital I/O which means that the digital function on the pin
must be disabled when the SXOSC is active. The ADC functions are enabled using the PCRs.
Certain modules provide system integration functions, and other modules (such as timers) provide specific
functions.
From reset, the modules involved in configuring the system for application software are:
•Boot Assist Module (BAM) — determines the selected boot source
•Reset Generation Module (MC_RGM) — determines the behavior of the MCU when various reset
sources are triggered and reports the source of the reset
•Mode Entry Module (MC_ME) — controls which operating mode the MCU is in and configures
the peripherals and clocks and power supplies for each of the modes
•Power Control Unit (MC_PCU) — determines which power domains are active
•Clock Generation Module (MC_CGM) — chooses the clock source for the system and many
peripherals
After reset, the MCU will automatically select the appropriate reset source and begin to execute code. At
this point the system clock is the 16 MHz FIRC oscillator, the CPU is in supervisor mode and all the
memory is available. Initialization is required before most peripherals may be used and before the SRAM
can be read (since the SRAM is protected by ECC, the syndrome will generally be uninitialized after reset
and reads would fail the check). Accessing disabled features causes error conditions or interrupts.
A typical startup routine would involve initializing the software environment including stacks, heaps,
variable initialization and so on and configuring the MCU for the application.
The MC_ME module enables the modules and other features like clocks. It is therefore an essential part
of the initialization and operation software. In general, the software will configure an MC_ME mode to
make certain peripherals, clocks, and memory active and then switch to that mode.
Chapter 6, Clock Description, includes a graphic of the clock architecture of the MCU. This can be used
to determine how to configure the MC_CGM module. In general software will configure the module to
enable the required clocks and PLLs and route these to the active modules.
After these steps are complete it is possible to configure the input/output pins and the modules for the
application.
1.7.4Other features
The MC_ME module manages low power modes and so it is likely that it will be used to switch into
different configurations (module sets, clocks) depending on the application requirements.
The MCU includes two other features to improve the integrity of the application:
•It is possible to enable a software watchdog (SWT) immediately at reset or afterwards to help
detect code runaway.
•Individual register settings can be protected from unintended writes using the features of the
Register Protection module. The protected registers are shown in Chapter 29, Register Protection.
Other integration functionality is provided by the System Status and Configuration Module (SSCM).
The MPC5604B represents a new generation of 32-bit microcontrollers based on the Power Architecture®.
It belongs to an expanding family of automotive-focused products targeted at addressing the next wave of
body electronics applications within the vehicle.
This document describes the features of the family and options available within the family members, and
highlights important electrical and physical characteristics of the device.
The advanced and cost-efficient host processor core of the family complies with the Power Architecture
embedded category. It operates at speeds of up to 64 MHz and offers high performance processing
optimized for low power consumption. It capitalizes on the available development infrastructure of current
Power Architecture devices and is supported with software drivers, operating systems and configuration
code to assist with users implementations. See Section 2.4, Developer support, for more information.
2.2Features
This section describes the features of the MPC5604B.
2.2.1MPC5604B family comparison
Table 2-1 and Table 2-2 report the memory scaling of Code Flash and SRAM.
Table 2-1. Code Flash memory scaling
Memory sizeStart addressEnd address
256 KB0x000000000x0003FFFF
384 KB0x000000000x0005FFFF
512 KB0x000000000x0007FFFF
Table 2-2. SRAM memory scaling
Memory sizeStart addressEnd address
24 KB0x400000000x40005FFF
28 KB0x400000000x40006FFF
32 KB0x400000000x40007FFF
40 KB0x400000000x40009FFF
48 KB0x400000000x4000BFFF
Table 2-3 provides a summary of the different members of the MPC5604B family. This information is
intended to provide an understanding of the range of functionality offered by this family.
See the eMIOS section of the device reference manual for information on the channel configuration and functions.
4
IC - Input Capture; OC - Output Compare; PWM - Pulse Width Modulation; MC - Modulus counter
5
SCI0, SCI1 and SCI2 are available. SCI3 is not available.
6
CAN0, CAN1 are available. CAN2, CAN3, CAN4 and CAN5 are not available.
7
CAN0, CAN1 and CAN2 are available. CAN3, CAN4 and CAN5 are not available.
8
I/O count based on multiplexing with peripherals
9
208 MAPBGA available only as development package for Nexus2+
LQFP
100
LQFP
144
LQFP64LQFP
100
LQFP64LQFP
100
LQFP
144
LQFP64LQFP
100
LQFP64LQFP
100
LQFP
144
LQFP64LQFP
100
LQFP
208
MAPBG
9
A
Introduction
Page 43
2.2.2Block diagram
3 x
DSPI
FMPLL
Nexus 2+
Nexus
SRAM
SIUL
Reset control
48 KB
External
IMUX
GPIO and
JTAG
pad control
JTAG port
Nexus port
e200z0h
Interrupt requests
64-bit 2 x 3 Crossbar Switch
6 x
FlexCAN
Peripheral bridge
interrupt
request
Interrupt
request
I/O
Clocks
Instructions
Data
Voltage
regulator
NMI
SWT
PIT
STM
NMI
SIUL
. . .
. . .
. . .
. . .
INTC
I2C
. . .
4 x
LINFlex
2 x
eMIOS
36 Ch.
ADC
MPU
CMU
SRAM
Flash
Code Flash
512 KB
Data Flash
64 KB
MC_PCUMC_MEMC_CGMMC_RGM
BAM
CTU
RTC
SSCM
(Master)
(Master)
(Slave)
(Slave)
(Slave)
controller
controller
Legend:
ADCAnalog-to-Digital Converter
BAMBoot Assist Module
FlexCAN Controller Area Network
CMUClock Monitor Unit
CTUCross Triggering Unit
DSPIDeserial Serial Peripheral Interface
eMIOSEnhanced Modular Input Output System
FMPLLFrequency-Modulated Phase-Locked Loop
I
2
CInter-integrated Circuit Bus
IMUXInternal Multiplexer
INTCInterrupt Controller
JTAGJTAG controller
LINFlexSerial Communication Interface (LIN support)
ECSMError Correction Status Module
MC_CGM Clock Generation Module
MC_MEMode Entry Module
MC_PCU Power Control Unit
MC_RGM Reset Generation Module
MPUMemory Protection Unit
NexusNexus Development Interface (NDI) Level
NMINon-Maskable Interrupt
PITPeriodic Interrupt Timer
RTCReal-Time Clock
SIULSystem Integration Unit Lite
SRAMStatic Random-Access Memory
SSCMSystem Status Configuration Module
STMSystem Timer Module
SWTSoftware Watchdog Timer
WKPUWakeup Unit
MPU
ECSM
from peripheral
registers
blocks
WKPU
Interrupt
request with
wakeup
functionality
Figure 2-1 shows a top-level block diagram of the MPC5604B family.
On-chip modules available within the family include the following features:
•Single issue, 32-bit CPU core complex (e200z0)
— Compliant with the Power Architecture™ embedded category
— Includes an instruction set e nhancement allowing variable length encoding (VLE) for code size
footprint reduction. With the optional encoding of mixed 16-bit and 32-bit instructions, it is
possible to achieve significant code size footprint reduction.
•Up to 512 Kbytes on-chip Code Flash supported with the Flash controller
•Up to 64 Kbytes on-chip Data Flash supported with the Flash controller
•Up to 48 Kbytes on-chip SRAM
•Memory protection unit (MPU) with 8 region descriptors and 32-byte region granularity
•Interrupt controller (INTC) capable of handling 148 selectable-priority interrupt sources
•Frequency-modulated phase-locked loop (FMPLL)
•Crossbar switch architecture for concurrent access to peripherals, Flash, or SRAM from multiple
bus masters
•Boot assist module (BAM) supports internal Flash programming via a serial link (FlexCAN or
LINFlex)
•Timer supports input/output channels providing a range of 16-bit input capture, output compare,
and pulse width modulation functions (eMIOS)
•10-bit analog-to-digital converter (ADC)
•Up to 3 serial peripheral interface (DSPI) modules
•Up to 4 serial communication interface (LINFlex) modules
— LINFlex 1, 2 and 3: Master capable
— LINFlex 0: Master capable and slave capable
•Up to 6 enhanced full CAN (FlexCAN) modules with 64 configurable message buffers
•1 inter-integrated circuit (I2C) module
•Up to 123 configurable general purpose pins supporting input and output operations (package
dependent)
•Real time counter (RTC) with clock source from FIRC or SIRC supporting autonomous wake-up
with 1-ms resolution with max timeout of 2 seconds
— Support for RTC with clock source from SXOSC, supporting wake-up with 1-sec resolution
and max timeout of 1 hour
•6 periodic interrupt timers (PIT) with 32-bit counter resolution
•1 system module timer (STM)
•Nexus development interface (NDI) per IEEE-ISTO 5001-2003 Class Two Plus
•Device/board boundary scan testing supported with per Joint Test Action Group (JTAG) of IEEE
(IEEE 1149.1)
•On-chip voltage regulator (VREG) for regulation of input supply for all internal levels
MPC5604B family members are offered in the following package types:
•64-pin LQFP, 10mm x 10mm outline
•100-pin LQFP, 0.5mm pitch, 14mm x 14mm outline
•144-pin LQFP, 0.5mm pitch, 20mm x 20mm outline
•208 MAPBGA, 1mm ball pitch, 17mm x 17mm outline development package
2.4Developer support
The MPC5604B MCU tools and third-party developers are similar to those used for the Freescale
MPC5500 product family , offering a widespread, established network of tool and software vendors. It also
features a high-performance Nexus debug interface.
The following development support is available:
•Automotive evaluation boards (EVB) featuring CAN, LIN interfaces, and more
•Compilers
•Debuggers
•JTAG and Nexus interfaces
The following software support is available:
•OSEK solutions will be available from multiple third parties
The following sections provide signal descriptions and related information about the functionality and
configuration.
4.2Package pinouts
The LQFP pinouts and the BGA ballmap are provided in the following figures.
For more information on pin multiplexing on this device, see Table 4-1 through Table 4-4.
Note: 208 MAPBGA available only as development package for Nexus 2+.
NC
= Not connected
Figure 4-5. 208 MAPBGA configuration
4.3Pad configuration during reset phases
All pads have a fixed configuration under reset.
During the power-up phase, all pads are forced to tristate.
After power-up phase, all pads are forced to tristate with the following exceptions:
•PA[9] (FAB) is pull-down. Without external strong pull-up the device starts fetching from flash.
•PA[8] (ABS[0]) is pull-up.
•RESET pad is driven low. This is pull-up only after PHASE2 reset completion.
•JTAG pads (TCK, TMS and TDI) are pull-up whilst TDO remains tristate.
•Precise ADC pads (PB[7:4] and PD[11:0]) are left tristate (no output buffer available).
capacitor must be connected between
these pins and the nearest V
VSS_LV1.2V decoupling pins. Decoupling
capacitor must be connected between
these pins and the nearest V
VDD_BVInternal regulator supply voltage122024K3
VSS_HV_ADCReference ground and analog ground for
the ADC
VDD_HV_ADCReference voltage and analog supply for
the ADC
1
Pin numbers apply to both the MPC560xB and MPC560xC packages.
2
208 MAPBGA available only as development package for Nexus2+
3
A decoupling capacitor must be placed between each of the three VDD_LV/VSS_LV supply pairs to ensure stable
voltage (see the recommended operating conditions in the device datasheet for details).
SS_LV
DD_LV
pin.
pin.
11, 23, 5719, 32, 8523, 46, 124D8, K4, P7
3
10, 24, 5818, 33, 8622, 47, 125C8, J2, N7
3
335173R15
345274P14
18, 20, 49,
99, 122
C2, D9, E16,
G13, H3, N9,
R5
G7, G8, G9,
G10, H1, H7,
H8, H9, H10,
J7, J8, J9,
J10, K7, K8,
K9, K10
4.5Pad types
In the device the following types of pads are available for system pins and functional port pins:
S = Slow
M = Medium1
1. See the I/O pad electrical characteristics in the device datasheet for details.
2. All medium and fast pads are in slow configuration by default at reset and can be configured as fast or medium (see PCR.SRC
in Section 19.5.3.8, “Pad Configuration Registers (PCR0–PCR122)).
Table 4-3. Functional port pin descriptions (continued)
1
2
Port pin
PH[6]PCR[118] AF0
PH[7]PCR[119] AF0
PH[8]PCR[120] AF0
9
PH[9]
9
PH[10]
1
Alternate functions are chosen by setting the values of the PCR.PA bitfields inside the SIUL module.
PCR
AF1
AF2
AF3
AF1
AF2
AF3
AF1
AF2
AF3
PCR[121] AF0
AF1
AF2
AF3
PCR[122] AF0
AF1
AF2
AF3
Function
Alternate function
GPIO[118]
E1UC[8]
—
MA[2]
GPIO[119]
E1UC[9]
CS3_2
MA[1]
GPIO[120]
E1UC[10]
CS2_2
MA[0]
GPIO[121]
—
TCK
—
GPIO[122]
—
TMS
—
Peripheral
SIUL
eMIOS_1
—
ADC
SIUL
eMIOS_1
DSPI_2
ADC
SIUL
eMIOS_1
DSPI_2
ADC
SIUL
—
JTAGC
—
SIUL
—
JTAGC
—
Pad type
I/O direction
RESET configuration
I/O
MTristate———136 D5
I/O
—
O
I/O
MTristate———137 C5
I/O
O
O
I/O
MTristate———138 A5
I/O
O
O
I/O
SInput, weak
—
pull-up
I
—
I/O
SInput, weak
—
pull-up
I
—
Pin number
100 LQFP
144 LQFP
MPC560xB 64 LQFP
MPC560xC 64 LQFP
——88127B8
——81120B9
PCR.PA = 00 AF0; PCR.PA = 01 AF1; PCR.PA = 10 AF2; PCR.PA = 11 AF3. This is intended to select
the output functions; to use one of the input functions, the PCR.IBE bit must be written to ‘1’, regardless of the
values selected in the PCR.PA bitfields. For this reason, the value corresponding to an input only function is
reported as “—”.
2
Multiple inputs are routed to all respective modules internally. The input of some modules must be configured by
setting the values of the PSMIO.PADSELx bitfields inside the SIUL module.
3
208 MAPBGA available only as development package for Nexus2+
4
All WKUP pins also support external interrupt capability. See wakeup unit chapter for further details.
5
NMI has higher priority than alternate function. When NMI is selected, the PCR.AF field is ignored.
6
“Not applicable” because these functions are available only while the device is booting. Refer to BAM chapter of the
reference manual for details.
7
Value of PCR.IBE bit must be 0
8
Be aware that this pad is used on the MPC5607B 100-pin and 144-pin to provide VDD_HV_ADC and
VSS_HV_ADC1. Therefore, you should be careful in ensuring compatibility between MPC5604B and MPC5607B.
9
Out of reset all the functional pins except PC[0:1] and PH[9:10] are available to the user as GPIO.
PC[0:1] are available as JTAG pins (TDI and TDO respectively).
PH[9:10] are available as JTAG pins (TCK and TMS respectively).
If the user configures these JTAG pins in GPIO mode the device is no longer compliant with IEEE 1149.1-2001.
The TDO pad has been moved into the STANDBY domain in order to allow low-power debug handshaking in
STANDBY mode. However, no pull-resistor is active on the TDO pad while in STANDBY mode. At this time the pad
is configured as an input. When no debugger is connected the TDO pad is floating causing additional current
consumption. To avoid the extra consumption TDO must be connected. An external pull-up resistor in the range of
47–100 k should be added between the TDO pin and VDD. Only in case the TDO pin is used as application pin
and a pull-up cannot be used then a pull-down resistor with the same value should be used between TDO pin and
GND instead.
11
Available only on MPC560xC versions and MPC5604B 208 MAPBGA devices
12
Not available on MPC5602B devices
13
Not available in 100 LQFP package
14
Available only on MPC5604B 208 MAPBGA devices
15
Not available on MPC5603B 144-pin devices
4.8Nexus 2+ pins
In the 208 MAPBGA package, eight additional debug pins are available (see Table 4-4).
Table 4-4. Nexus 2+ pin descriptions
Pin number
Debug pinFunction
I/O
direction
Pad type
Function
after reset
100
LQFP
144
LQFP
208 MAP
1
BGA
MCKOMessage clock outOF———T4
MDO0Message data out 0OM———H15
MDO1Message data out 1OM———H16
MDO2Message data out 2OM———H14
MDO3Message data out 3OM———H13
EVTIEvent inIMPull-up——K1
EVTOEvent outOM———L4
MSEOMessage start/end outOM———G16
1
208 MAPBGA available only as development package for Nexus2+
This chapter explains the process of booting the microcontroller . The following entities are involved in the
boot process:
•Boot Assist Module (BAM)
•System Status and Configuration Module (SSCM)
•Flash memory boot sectors (see Chapter 27, Flash Memory)
•Memory Management Unit (MMU)
5.1Boot mechanism
This section describes the configuration required by the user, and the steps performed by the
microcontroller, in order to achieve a successful boot from flash memory or serial download modes.
There are 2 external pins on the microcontroller that are latched during reset and used to determine whether
the microcontroller will boot from flash memory or attempt a serial download via FlexCAN or LINFlex
(RS232):
•FAB (Force Alternate Boot mode) on pin PA[9]
•ABS (Alternate Boot Select) on pin PA[8]
Table 5-1 describes the configuration options.
Table 5-1. Boot mode selection
ModeFAB pin (PA[9])ABS pin (PA[8])
Flash memory boot (default mode)0X
Serial boot (LINFlex)10
Serial boot (FlexCAN)11
The microcontroller has a weak pull-down on PA[9] and a weak pull-up on PA[8]. This means that if
nothing external is connected to these pins, the microcontroller will enter flash memory boot mode by
default. In order to change the boot behavior, you should use external pullup or pulldown resistors on
PA[9] and PA[8]. If there is any external circuitry connected to either pin, you must ensure that this does
not interfere with the expected value applied to the pin at reset. Otherwise, the microcontroller may boot
into an unexpected mode after reset.
The SSCM preforms a lot of the automated boot activity including reading the latched value of the FAB
(PA[9]) pin to determine whether to boot from flash memory or serial boot mode. This is illustrated in
In order to sucessfully boot from flash memory , you must program two 32-bit fields into one of 5 possible
boot blocks as detailed below. The entities to program are:
•16-bit Reset Configuration Half Word (RCHW), which contains:
— A BOOT_ID field that must be correctly set to 0x5A in order to "validate" the boot sector
•32-bit reset vector (this is the start address of the user code)
The location and structure of the boot sectors in flash memory are shown in Figure 5-2.
32-bit reset vector (points to start address of application code)
0x8
Application code (from offset 0x8 and onward)
Figure 5-2. Boot sector structure
The RCHW fields are described in Table 5-2.
Table 5-2. RCHW field descriptions
FieldDescription
BOOT_IDBoot identifier.
If BOOT_ID = 0x5A, the boot sector is considered valid and bootable.
The SSCM performs a sequential search of each boot sector (starting at sector 0) for a valid BOOT_ID
within the RCHW. If a valid BOOT_ID is found, the SSCM reads the boot vector address. If a valid
BOOT_ID is not found, the SSCM starts the process of putting the microcontroller into static mode.
Finally , the SSCM sets the e200z0h core instruction pointer to the reset v ector address and starts the core
running.
5.1.1.1Static mode
If no valid BOOT_ID within the RCHW was found, the SSCM sets the CPU core instruction pointer to the
BAM address and the core starts to execute the code to enter static mode as follows:
•The core executes the "wait" instruction which halts the core.
Some applications require an alternate boot sector so that the main boot code can be erased and
reprogrammed in the field. When an alternate boot is needed, you can create two bootable sectors:
•The valid boot sector located at the lowest address is the main boot sector.
•The valid boot sector located at the next available address is the alternate boot sector.
This scheme ensures that there is always one active boot sector even if the main boot sector is erased.
5.1.2Serial boot mode
Serial boot provides a mechanism to download and then execute code into the microcontroller SRAM.
Code may be downloaded using either FlexCAN or LINFlex (RS232). After the SSCM has detected that
serial boot mode has been requested, execution is transferred to the BAM which handles all of the serial
boot mode tasks. See Section 5.2, Boot Assist Module (BAM), for more details.
5.1.3Censorship
Censorship can be enabled to protect the contents of the flash memory from being read or modified. In
order to achieve this, the censorship mechanism controls access to the:
•JTAG / Nexus debug interface
•Serial boot mode (which could otherwise be used to download and execute code to query or modify
the flash memory)
T o re-gain access to the flash memory via JT AG or serial boot, a 64-bit password must be correctly entered.
CAUTION
When censorship has been enabled, the only way to regain access is with the
password. If this is forgotten or not correctly configured, then there is no
way back into the device.
There are two 64-bit values stored in the shadow flash which control the censorship (see Table 27-6 for a
full description):
•Nonvolatile Private Censorship Password registers, NVPWD0 and NVPWD1
•Nonvolatile System Censorship Control registers, NVSCC0 and NVSCC1
5.1.3.1Censorship password registers (NVPWD0 and NVPWD1)
The two private password registers combine to form a 64-bit password that should be programmed to a
value known only by you. After factory test these registers are programmed as shown below:
•NVPWD0 = 0xFEED_FACE
•NVPWD1 = 0xCAFE_BEEF
This means that even if censorship was inadvertently enabled by writing to the censorship control registers,
there is an opportunity to get back into the microcontroller using the default private password of
0xFEED_FACE_CAFE_BEEF.
When configuring the private password, each half word (16-bit) must contain at least one "1" and one "0".
Some examples of legal and illegal passwords are shown in Table 5-3:
Table 5-3. Examples of legal and illegal passwords
In uncensored devices it is possible to download code via LINFlex or FlexCAN (Serial Boot Mode) into
internal SRAM even if the 64-bit private password stored in the flash and provided during the boot
sequence is a password that does not conform to the password rules.
5.1.3.2Nonvolatile System Censorship Control registers (NVSCC0 and
NVSCC1)
These registers are used together to define the censorship configuration. After factory test these registers
are programmed as shown below which disables censorship:
•NVSCC0 = 0x55AA_55AA
•NVSCC1 = 0x55AA_55AA
Each 32-bit register is split into an upper and lower 16-bit field. The upper 16 bits (the SC field) are used
to control serial boot mode censorship. The lower 16 bits (the CW field) are used to control flash memory
boot censorship.
If the contents of the shadow flash memory are erased and the NVSCC0,1
registers are not re-programmed to a valid value, the microcontroller will be
permanently censored with no way for you to regain access. A
microcontroller in this state cannot be debugged or re-flashed.
5.1.3.3Censorship configuration
The steps to configuring censorship are:
1. Define a valid 64-bit password that conforms to the password rules.
2. Using the table and flow charts below, decide what level of censorship you require and configure
the NVSCC0,1 values.
3. Re-program the shadow flash memory and NVPWD0,1 and NVSCC0,1 registers with your new
values. A POR is required before these will take effect.
CAUTION
If
(NVSCC0 and NVSCC1 do not match)
or
(Either NVSCC0 or NVSCC1 is not set to 0x55AA)
then the microcontroller will be permanently censored with no way to get
back in.
Table 5-4 shows all the possible modes of censorship. The red shaded areas are to be avoided as these show
the configuration for a device that is permanently locked out. If you wish to enable censorship with a
private password there is only one valid configuration — to modify the CW field in both NVSCC0,1
registers so they match but do not equal 0x55AA. This will allow you to enter the private password in both
serial and flash boot modes.
Table 5-4. Censorship configuration and truth table
Boot configurationSerial
state
0 (flash
memory
boot)
1 (serial
boot)
Control options
Uncensored0xXXXX AND
Private flash
memory password
and censored
Censored with no
password access
(lockout)
Private flash
memory password
and uncensored
Private flash
memory password
and censored
censorship
control word
(NVSCCn[SC]
)
NVSCC0 ==
NVSCC1
0x55AA AND
NVSCC0 ==
NVSCC1
!0x55AA!0X55AAEnabledDisabledN/A
NVSCC0 != NVSCC1
0x55AA AND
NVSCC0 == NVSCC1
0x55AA AND
NVSCC0 ==
NVSCC1
Censorship
control word
(NVSCCn[CW])
0x55AA AND
NVSCC0 ==
NVSCC1
!0x55AA AND
NVSCC0 ==
NVSCC1
OR
!0x55AA AND
NVSCC0 ==
NVSCC1
Internal
flash
memory
state
EnabledEnabled
EnabledEnabled
EnabledEnabledNVPWD0,1
EnabledDisabledNVPWD1,0
Nexus
state
with
password
Serial
password
(BAM reads
flash
memory
reads flash
memory
1
(SSCM
1
)
)
JTAG
passwordFAB pin
N/A
NVPWD1,0
(SSCM
reads flash
memory
1
)
Public password
and uncensored
Public password
and censored
(lockout)
1
When the SSCM reads the passwords from flash memory, the NVPWD0 and NVPWD1 password order is swapped, so
you have to submit the 64-bit password as {NVPWD1, NVPWD0}.
!0x55AA AND
NVSCC0 !=
NVSCC1
OR NVSCC0 != NVSCC1
= Microcontroller permanently locked out
= Not applicable
0X55AA AND
NVSCC0 !=
NVSCC1
!0x55AADisabledDisabledPublic
EnabledEnabledPublic
(0xFEED_F
ACE_CAFE
_BEEF)
(0xFEED_F
ACE_CAFE
_BEEF)
The flow charts in Figure 5-4 and Figure 5-5 provide a way to quickly check what will happen with
different configurations of the NVSCC0,1 registers as well as detailing the correct way to enter the serial
password. In the password examples, assume the 64-bit password has been programmed into the shadow
flash memory in the order {NVPWD0, NWPWD1} and has a value of 0x01234567_89ABCDEF.
Enter password as
{NVPWD1, NVPWD0}
example –
0x89ABCDEF_01234567
Enter password as
{NVPWD0, NVPWD1}
example –
0x01234567_89ABCDEF
Figure 5-5. Censorship control in serial boot mode
5.2Boot Assist Module (BAM)
The BAM consits of a block of ROM at address 0xFFFF_C000 containing VLE firmware. The BAM
provides 2 main functions:
•Manages the serial download (FlexCAN or LINFlex protocols supported) including support for a
serial password if censorship is enabled
•Places the microcontroller into static mode if flash memory boot mode is selected and a valid
BOOT_ID is not located in one of the boot sectors by the SSCM
The initial (reset) device configuration is saved including the mode and clock configuration. This means
No
Restore default
configuration
configuration
Save default
BAM Entry
0xFFFF_C000
Boot mode valid?
Download new
code and save in
SRAM
Restore default
configuration
Execute new
code
STATIC mode
Ye s
Check boot
mode at
SSCM_STATUS[BMODE]
that the serial download software running in the BAM can make changes to the modes and clocking and
then restore these to the default values before running the newly downloaded application code from the
SRAM.
The SSCM_STATUS[BMODE] field indicates which boot mode is to be executed (see Table 5-5). This
field is only updated during reset.
There are 2 conditions where the boot mode is not considered valid and the BAM pushes the
microcontroller into static mode after restoring the default configuration:
•BMODE = 011 (flash memory boot mode). This means that the SSCM has been unable to find a
valid BOOT_ID in the boot sectors so has called the BAM
•BMODE = reserved
In static mode a wait instruction is executed to halt the core.
For the FlexCAN and LINFlex serial boot modes, the respective area of BAM code is executed to
Table 5-5. SSCM_STATUS[BMODE] values as used by BAM
BMODE valueCorresponding boot mode
000Reserved
001FlexCAN_0 serial boot loader
010LINFlex_0 (RS232 /UART) serial boot loader
011Flash memory boot mode
100–111Reserved
After the code has been downloaded to SRAM, the BAM code restores the initial device configuration and
then transfers execution to the start address of the downloaded code.
5.2.1.1BAM resources
The BAM uses/initializes the following MCU resources:
•MC_ME and MC_CGM to initialize mode and clock sources
•FlexCAN_0, LINFlex _0 and the respective I/O pins when performing serial boot mode
•SSCM and shadow flash memory (NVPWD0,1 and NVSCC0,1) during password check
•SSCM to check the boot mode (see Table 5-5)
•4–16 MHz fast external crystal oscillator
The system clock is selected directly from the 4–16 MHz fast external crystal oscillator . Thus, the external
oscillator frequency defines the baud rates used for serial download (see Table 5-6).
Table 5-6. Serial boot mode – baud rates
FXOSC frequency
(MHz)
f
FXOSC
89600200K
1214400300K
1619200400K
LINFlex baud rate
(baud)
f
/833f
FXOSC
CAN bit rate
(bit/s)
/40
FXOSC
5.2.1.2Download and execute the new code
From a high level perspective, the download protocol follows these steps:
1. Send the 64-bit password.
2. Send the start address, size of code to be downloaded (in bytes) and the VLE bit1.
3. Download the code.
Each step must be completed before the next step starts. After the download is complete (the specified
number of bytes is downloaded), the code executes from the start address.
1. Since the device supports only VLE code and not Book E code, this flag is used only for backward compatibility.
The communication is done in half duplex manner, whereby the transmission from the host is followed by
the microcontroller transmission mirroring the transmission back to the host:
•Host sends data to the microcontroller and waits for a response.
•MCU echoes to host the data received.
•Host verifies if echo is correct:
— If data is correct, the host can continue to send data.
— If data is not correct, the host stops transmission and the microcontroller enters static mode.
All multi-byte data structures are sent with MSB first.
A more detailed description of these steps follows.
5.2.1.3Censorship mode detection and serial password validation
Before the serial download can commence, the BAM code must determine which censorship mode the
microcontroller is in and which password to use. It does this by reading the PUB and SEC fields in the
SSCM Status Register (see Section 5.3.4.1, System Status Register (SSCM_STATUS)) as shown in
Table 5-7.
Table 5-7. BAM censorship mode detection
SSCM_STATUS register fields
ModePassword comparison
PUBSEC
10Uncensored, public password0xFEED_FACE_CAFE_BEEF
00Uncensored, private passwordNVPWD0,1 from flash memory via BAM
01Censored, private passwordNVPWD1,0 from flash memory via SSCM
When censorship is enabled, the flash memory cannot be read by application code running in the BAM or
in the SRAM. This means that the private password in the shadow flash memory cannot be read by the
BAM code. In this case the SSCM is used to obtain the private password from the flash memory of the
censored device. When the SSCM reads the private password it inverts the order of {NVPWD0,
NWPWD1} so the password entered over the serial download needs to be {NVPWD1, NVPWD0}.
The first thing to be downloaded is the 64-bit password. If the password does not match the stored
password, then the BAM code pushes the microcontroller into static mode.
The way the password is compared with either the public or private password (depending on mode) varies
depending on whether censorship is enabled as described in the following subsections.
5.2.1.3.1Censorship disabled (private or public passwords):
1. If the public password is used, the BAM code does a direct comparison between the serial password
and 0xFEED_FACE_CAFE_BEEF.
2. If the private password is used, the BAM code does a direct comparison between the serial
password and the private password in flash memory, {NVPWD0, NVPWD1}.
3. If the password does not match, the BAM code immediately terminates the download and pushes
the microcontroller into static mode.
1. Since the flash is secured, the SSCM is required to read the private password.
2. The BAM code writes the serial password to the SSCM_PWCMPH and SSCM_PWCMPL
registers.
3. The BAM code then continues with the serial download (start address, data size and data) until all
the data has been copied to the SRAM.
4. In the meantime the SSCM has compared the private password in flash with the serial download
password the BAM code wrote into SSCM_PWCMPH and SSCM_PWCMPL.
5. If the SSCM obtains a match in the passwords, the censorship is temporarily disabled (until the
next reset).
6. The SSCM updates the status of the security (SEC) bit to reflect whether the passwords matched
(SEC = 0) or not (SEC = 1)
7. Finally, the BAM code reads SEC. If SEC = 0, execution is transferred to the code in the SRAM.
If SEC = 1, the BAM code forces the microcontroller into static mode.
Figure 5-8. BAM serial boot mode flow for censorship enabled and private password
With LINFlex, any receive error will result in static mode. With FlexCAN, the host will re-transmit data
if there has been no acknowledgment from the microcontroller . However there could be a situation where
the receiver configuration has an error which would result in static mode entry.
In a censored device booting with serial boot mode, it is possible to read the
content of the four 32-bit flash memory locations that make up the boot
sector. For example, if the RCHW is stored at address 0x0000_0000, the
reads at address 0x0000_0000, 0x0000_0004, 0x0000_0008 and
0x0000_000C will return a correct value. No other flash memory locations
can be read.
5.2.1.4Download start address, VLE bit and code size
The next 8 bytes received by the microcontroller contain a 32-bit Start Address, the VLE mode bit and a
31-bit code Length as shown in Figure 5-9.
START_ADDRESS[31:16]
START_ADDRESS[15:0]
VLECODE_LENGTH[30:16]
CODE_LENGTH[15:0]
Figure 5-9. Start address, VLE bit and download size in bytes
The VLE bit (Variable Length Instruction) is used to indicate whether the code to be downloaded is Book
VLE or Book III-E. This device family supports only VLE = 1; the bit is used for backward compatibility .
The Start Address defines where the received data will be stored and where the MCU will branch after the
download is finished. The start address is 32-bit word aligned and the 2 least significant bits are ignored
by the BAM code.
NOTE
The start address is configurable, but most not lie within the 0x4000_0000
to 0x4000_00FF address range.
The Length defines how many data bytes have to be loaded.
5.2.1.5Download data
Each byte of data received is stored in the microcontroller’s SRAM, starting from the address specified in
the previous protocol step.
The address increments until the number of bytes of data received matches the number of bytes specified
by the code length.
Since the SRAM is protected by 32-bit wide Error Correction Code (ECC), the BAM code always writes
bytes into SRAM grouped into 32-bit words. If the last byte received does not fall onto a 32-bit boundary ,
the BAM code fills any additional bytes with 0x0.
Since the ECC on the SRAM has not been initialized (except for the bytes of data that have just been
D1D2D3D4D5D6D7D0
Byte field
Start
bit
Stop
bit
downloaded), an additional dummy word of 0x0000_0000 is written at the end of the downloaded data
block to avoid any ECC errors during core prefetch.
5.2.1.6Execute code
The BAM code waits for the last data byte to be received. If the operating mode is censored with a private
password, then the BAM reads the SSCM status register to determine whether the serial password matched
the private password. If there was a password match then the BAM code restores the initial configuration
and transfers execution to the downloaded code start address in SRAM. If the passwords did not match,
the BAM code forces a static mode entry.
NOTE
The watchdog is disabled at the start of BAM code execution. In the case of
an unexpected issue during BAM code execution, the microcontroller may
be stalled and an external reset required to recover the microcontroller.
5.2.2LINFlex (RS232) boot
5.2.2.1Configuration
Boot according to the LINFlex boot mode download protocol (see Section 5.2.2.2, Protocol) is performed
by the LINFlex_0 module in UART (RS232) mode. Pins used are:
•LIN0TX mapped on PB[2]
•LIN0RX mapped on PB[3]
Boot from LINFlex uses the system clock driven by the 4–16 MHz external crystal oscillator (FXOSC).
The LINFlex controller is configured to operate at a baud rate = system clock frequency/833, using an 8-bit
data frame without parity bit and 1 stop bit.
Figure 5-10. LINFlex bit timing in UART mode
5.2.2.2Protocol
Table 5-8 summarizes the protocol and BAM action during this boot mode.
232-bit store address32-bit store addressLoad address is stored for future use.
3VLE bit + 31-bit
number of bytes
(MSB first)
48 bits of raw binary
data
5NoneNoneBranch to downloaded code
BAM response
message
64-bit passwordPassword checked for validity and compared against
stored password.
VLE bit + 31-bit
number of bytes
(MSB first)
8 bits of raw binary
data
Size of download are stored for future use.
Verify if VLE bit is set to 1
8-bit data are packed into a 32-bit word. This word is
saved into SRAM starting from the “Load address”.
“Load address” increments until the number of data
received and stored matches the size as specified in the
previous step.
Action
5.2.3FlexCAN boot
5.2.3.1Configuration
Boot according to the FlexCAN boot mode download protocol (see Section 5.2.3.2, Protocol) is performed
by the FlexCAN_0 module. Pins used are:
•CAN0TX mapped on PB[0]
•CAN0RX mapped on PB[1]
NOTE
When the serial download via FlexCAN is selected and the device is part of
a CAN network, the serial download may stop unexpectedly if there is any
other traffic on the network. To avoid this situation, ensure that no other
CAN device on the network is active during the serial download process.
Boot from FlexCAN uses the system clock driven by the 4–16 MHz fast external crystal oscillator.
The FlexCAN controller is configured to operate at a baud rate = system clock frequency/40 (see Table 5-6
for examples of baud rate).
It uses the standard 11-bit identifier format detailed in FlexCAN 2.0A specification.
FlexCAN controller bit timing is programmed with 10 time quanta, and the sample point is 2 time quanta
Table 5-9 summarizes the protocol and BAM action during this boot mode. All data are transmitted byte
wise.
Table 5-9. FlexCAN boot mode download protocol
Protoco
l
Host sent message
step
1CAN ID 0x011 +
64-bit password
2CAN ID 0x012 +
32-bit store
address + VLE
bit + 31-bit number of
bytes
3CAN ID 0x013 +
8 to 64 bits of raw
binary data
5NoneNoneBranch to downloaded code
BAM response
message
CAN ID 0x001 +
64-bit password
CAN ID 0x002 +
32-bit store
address + VLE
bit + 31-bit number of
bytes
CAN ID 0x003 +
8 to 64 bits of raw
binary data
Password checked for validity and compared against stored
password
Load address is stored for future use.
Size of download are stored for future use.
Verify if VLE bit is set to 1
8-bit data are packed into 32-bit words. These words are
saved into SRAM starting from the “Load address”.
“Load address” increments until the number of data
received and stored matches the size as specified in the
previous step.
The primary purpose of the SSCM is to provide information about the current state and configuration of
the system that may be useful for configuring application software and for debug of the system.
On microcontrollers with a separate STANDBY power domain, the System Status block is part of that
domain.
Figure 5-12. SSCM block diagram
5.3.2Features
The SSCM includes these features:
•System Configuration and Status
— Memory sizes/status
— Microcontroller Mode and Security Status (including censorship and serial boot information)
— Search Code Flash for bootable sector
— Determine boot vector
•Device identification information (MCU ID Registers)
0x08Debug Status Port Register (SSCM_DEBUGPORT)on page 86
0x0AReserved
0x0CPassword Comparison Register High Word (SSCM_PWCMPH)on page 87
0x10Password Comparison Register Low Word (SSCM_PWCMPL)on page 87
All registers are accessible via 8-bit, 16-bit or 32-bit accesses. However, 16-bit accesses must be aligned
to 16-bit boundaries, and 32-bit accesses must be aligned to 32-bit boundaries. As an example, the
SSCM_STA TUS register is accessible by a 16-bit read/write to address ‘Base + 0x0002’, but performing
a 16-bit access to ‘Base + 0x0003’ is illegal.
5.3.4.1System Status Register (SSCM_STATUS)
The System Status register is a read-only register that reflects the current state of the system.
All 32-bit accesses must be aligned to 32-bit addresses (i.e., 0x0, 0x4, 0x8 or 0xC).
Table 5-12. SSCM_STATUS field descriptions
FieldDescription
NXENNexus enabled
PUBPublic Serial Access Status. This bit indicates whether serial boot mode with public password is
allowed.
1 Serial boot mode with public password is allowed
0 Serial boot mode with private flash memory password is allowed
SECSecurity Status. This bit reflects the current security state of the flash memory.
1 The flash memory is secured.
0 The flash memory is not secured.
BMODEDevice Boot Mode
000 Reserved
001 FlexCAN_0 Serial Boot Loader
010 LINFlex_0 Serial Boot Loader
011 Single Chip
100 Reserved
101 Reserved
110 Reserved
111 Reserved
This field is only updated during reset.
This bit identifies whether or not the on-chip code Flash is available in the system memory map. The
Flash may not be accessible due to security limitations, or because there is no Flash in the system.
1 Code Flash is available
0 Code Flash is not available
DTSZData Flash Size
0000 No Data Flash
0011 64 KB
DVLDData Flash Valid
This bit identifies whether or not the on-chip Data Flash is visible in the system memory map. The Flash
may not be accessible due to security limitations, or because there is no Flash in the system.
1 Data Flash is visible
0 Data Flash is not visible
This bit enables bus aborts on any access to a peripheral slot that is not used on the device. This feature
is intended to aid in debugging when developing application code.
1 Illegal accesses to non-existing peripherals produce a Prefetch or Data Abort exception
0 Illegal accesses to non-existing peripherals do not produce a Prefetch or Data Abort exception
RAERegister Bus Abort Enable
This bit enables bus aborts on illegal accesses to off-platform peripherals. Illegal accesses are defined
as reads or writes to reserved addresses within the address space for a particular peripheral. This
feature is intended to aid in debugging when developing application code.
1 Illegal accesses to peripherals produce a Prefetch or Data Abort exception
0 Illegal accesses to peripherals do not produce a Prefetch or Data Abort exception
Transfers to Peripheral Bus resources may be aborted even before they reach the Peripheral Bus (that
is, at the PBRIDGE level). In this case, bits PAE and RAE will have no effect on the abort.
Table 5-16. SSCM_ERROR allowed register accesses
Access type8-bit16-bit32-bit
ReadAllowedAllowedAllowed
WriteAllowedAllowedNot allowed
5.3.4.4Debug Status Port Register (SSCM_DEBUGPORT)
The Debug Status Port register is used to (optionally) provide debug data on a set of pins.
Offset: 0x08Access: Read/write
0123456789101112131415
R0000000000000
W
Reset0000000000000000
Figure 5-16. Debug Status Port Register (SSCM_DEBUGPORT)
Table 5-17. SSCM_DEBUGPORT field descriptions
FieldDescription
DEBUG_MODE Debug Status Port Mode
This field selects the alternate debug functionality for the Debug Status Port.
000 No alternate functionality selected
001 Mode 1 selected
010 Mode 2 selected
011 Mode 3 selected
100 Mode 4 selected
101 Mode 5 selected
110 Mode 6 selected
111 Mode 7 selected
Ta bl e 5 - 1 8 describes the functionality of the Debug Status Port in each mode.
In order to unsecure the device, the password needs to be written as follows: first the upper word to the
SSCM_PWCMPH register, then the lower word to the SSCM_PWCMPL register. The SSCM compares
the 64-bit password entered into the SSCM_PWCMPH / SSCM_PWCMPL registers with the
NVPWM[1,0] private password stored in the shadow flash. If the passwords match then the SSCM
temporarily uncensors the microcontroller .