Project

General

Profile

SIMtrace Hardware » History » Version 23

tsaitgaist, 02/19/2016 10:49 PM
v1.1p added

1 1 laforge
[[PageOutline]]
2 1 laforge
= Osmocom SIMtrace Hardware =
3 1 laforge
4 7 laforge
This page is dedicated to the Hardware for Osmocom [wiki:SIMtrace], which looks like this:
5 7 laforge
6 3 laforge
[[Image(simtrace_10_front.jpg, 33%)]]
7 17 zecke2
[[Image(simtrace_connectors_scaled.png, 39%, align=right)]]
8 1 laforge
9 21 tsaitgaist
STATUS: We have received the second batch of 100 units from the SMT factory, ready for the 28C3 (Version v1.1p)
10 1 laforge
11 9 tsaitgaist
== Connectors ==
12 9 tsaitgaist
13 9 tsaitgaist
14 9 tsaitgaist
 * USB: USB mini-B connector. The main connector. The host software communicates (sniffing,...) through USB with the board. It can also be used to flash the micro-controller (using DFU).
15 9 tsaitgaist
 * serial: 2.5 mm jack serial cable, as used by osmocomBB. port used to debug the device (printf goes there).
16 18 zecke2
 * debug (P3): same as serial, but using the FTDI serial cable. '''It is recommended to cut the voltage wire of the 6pin FTDI connector before plugging the cable into the simtrace.'''
17 9 tsaitgaist
 * jtag (P1): JTAG 20 pin connector to do hardware assisted debugging.
18 9 tsaitgaist
 * BT1: battery connector (4.5-6V DC). normally the USB provides power, but the battery port can be used for autonomous use of SIMtrace. The sniffing can be saved in the flash (U1).
19 9 tsaitgaist
 * FFC_SIM (P3): to connect the flat flexible cable with SIM end for the phone.
20 9 tsaitgaist
 * SIM (P4): put your SIM in there (instead of in the phone)
21 9 tsaitgaist
 * reset (SW1): to reset the board (not erasing the firmware). If your are too lazy to unplug and re-plug the USB.
22 9 tsaitgaist
 * bootloader (SW2): used to start the bootloader so to flash the device using DFU. press when plugging in the USB.
23 19 zecke2
 * test (JP1): short circuit using a jumper to flash using [wiki:SIMtrace/Firmware#EnteringtheSAM-BAmode SAM-BA].
24 9 tsaitgaist
 * erase (JP2): short circuit using a jumper to erase completely erase the firmware.
25 9 tsaitgaist
26 4 laforge
== Schematics, Gerber & Co ==
27 4 laforge
28 1 laforge
The schematics, Gerber files, etc. can be found in the 'hardware' subdirectory of the simtrace.git repository:
29 1 laforge
 * http://cgit.osmocom.org/cgit/simtrace/tree/hardware (web browsing
30 1 laforge
 * git://git.osmocom.org/simtrace (git clone URL)
31 1 laforge
32 2 laforge
We're using Kicad as EDA tool.  Most of the work on the schematics and Gerber files has been done by Kevin Redon,
33 1 laforge
based on the original design by Harald Welte.
34 5 laforge
35 1 laforge
The latest schematics are also available as an attachment to this page.
36 1 laforge
37 15 zecke2
== Interconnections ==
38 15 zecke2
39 15 zecke2
The hardware schematics are very, very simple:
40 15 zecke2
41 15 zecke2
 * Connect SIM-RST with PA7
42 15 zecke2
 * Connect SIM-I/O with PA6(TXD0) and PA1(TIOB0)
43 15 zecke2
 * Connect SIM-CLK with PA2(SCK0) and PA4(TCLK0)
44 15 zecke2
 * Connect SIM-GND with GND
45 15 zecke2
46 15 zecke2
== Mode of operation ==
47 15 zecke2
48 15 zecke2
The USART of the AT91SAM7S is capable of T=0. The documentation only mentions it in clock-master mode, like you
49 15 zecke2
would run it in a smart card reader to actively talk to a smart card. However, by using the USART input clock multiplexer,
50 15 zecke2
you can use an externally-generated CLK like the one from the SIM card socket of the phone.
51 15 zecke2
52 15 zecke2
Unfortunately, the Rx Timeout feature of the USART is not working in T=0 mode, so I had to re-implement Rx timeout (waiting time)
53 15 zecke2
handling by means of the TC (timer/counter) block 0.  Due to technical limitations, we will wait up to one byte (12 etu) more
54 15 zecke2
than we should.
55 15 zecke2
56 15 zecke2
57 14 zecke2
== Revisions ==
58 1 laforge
59 23 tsaitgaist
=== v1.1p (1.1 Production branch) ===
60 23 tsaitgaist
61 23 tsaitgaist
This is a slightly corrected version of the v1.0p.
62 23 tsaitgaist
63 23 tsaitgaist
Changes:
64 23 tsaitgaist
 * a critical capacitor is near the LDO
65 23 tsaitgaist
 * some other capacitors are nearer to the CPU
66 23 tsaitgaist
 * some power traces are wider
67 23 tsaitgaist
 * the SIM C6/VPP contact is also routed through the bus switch (sometimes used for Single Wire Protocol)
68 23 tsaitgaist
 * sysmocom is added in the copper for legal reasons
69 23 tsaitgaist
 * the FTDI Vcc is cut
70 23 tsaitgaist
71 23 tsaitgaist
Downloads:
72 23 tsaitgaist
 * [attachment:simtrace_v11p_schematic.pdf]
73 23 tsaitgaist
 * [attachment:simtrace_v11p_gerber.zip]
74 23 tsaitgaist
75 7 laforge
=== v1.0p (1.0 Production branch) ===
76 7 laforge
77 20 tsaitgaist
78 20 tsaitgaist
[[Image(simtrace_v10p_front_mid.jpg, 33%)]]
79 20 tsaitgaist
80 7 laforge
This is identical to v1.0 on the schematics side, we simply altered the footprints of some components to accommodate
81 7 laforge
whatever the SMT factory had in stock.  Specifically the LED are 0805 instead of 0603, and the shottky diodes are
82 7 laforge
in a slightly awkward looking very large package.
83 7 laforge
84 7 laforge
Downloads:
85 22 tsaitgaist
 * [attachment:simtrace_v10p_schematic.pdf]
86 22 tsaitgaist
 * [attachment:simtrace_v10p_gerber.zip]
87 7 laforge
88 7 laforge
=== v1.0 ===
89 7 laforge
90 20 tsaitgaist
91 20 tsaitgaist
[[Image(simtrace_10_front.jpg, 33%)]]
92 20 tsaitgaist
93 7 laforge
This is the first stable release.  We built some 5 prototypes from this version.
94 7 laforge
95 7 laforge
Downloads:
96 13 zecke2
 * [attachment:simtrace_schem_v10.pdf]
97 13 zecke2
 * [attachment:simtrace_10_gerber.zip]
98 7 laforge
99 7 laforge
=== v0.9 ===
100 7 laforge
101 20 tsaitgaist
102 20 tsaitgaist
[[Image(simtrace_v09_top_mid.jpg, 33%)]]
103 20 tsaitgaist
104 7 laforge
As of June 04, 2011 the components had all arrived and four PCBs were in production.  We assemble the first
105 1 laforge
units around June 14, 2011.
106 1 laforge
107 7 laforge
As of June 21st, we had four re-worked prototypes that are fully functional.
108 1 laforge
109 7 laforge
=== v0.8 ===
110 20 tsaitgaist
111 20 tsaitgaist
112 20 tsaitgaist
[[Image(simtrace_08_front_mid.jpg, 33%)]]
113 1 laforge
114 7 laforge
Never really was an official release.  However, a friend took the unfinished Gerber files and built 5 units.
115 1 laforge
116 7 laforge
Since the Gerber was not finished, we had to do lots and lots of re-work in order to make them work at all.
117 7 laforge
118 1 laforge
== License ==
119 1 laforge
120 1 laforge
Schematics and Gerber files are released under the Creative Commons CC-BY-SA (Share Alike / Attribution) license.
121 1 laforge
122 1 laforge
== Sales ==
123 1 laforge
124 12 zecke2
Sales started at the 2011 CCC Camp and the hardware can be bought through the web-shop of sysmocom GmbH ([http://shop.sysmocom.de/])
125 7 laforge
126 7 laforge
== Credits ==
127 7 laforge
128 8 laforge
 * Harald Welte
129 8 laforge
  * Original project idea, schematic design
130 8 laforge
  * Olimex SAM7-P64 based prototypes
131 8 laforge
  * Firmware and host software
132 8 laforge
 * Kevin Redon
133 8 laforge
  * KiCAD work on schematics, footprints and routing
134 8 laforge
  * Soldering of some prototypes
135 8 laforge
 * [http://sysmocom.de/ sysmocom - systems for mobile communications GmbH]
136 8 laforge
  * funding for hardware prototyping (PCB, components, etc)
137 8 laforge
 * Christian Daniel
138 8 laforge
  * post-production flashing + debugging, design + test of v1.0p rework
Add picture from clipboard (Maximum size: 48.8 MB)