July 1, 2026

The Dallas 1-wire protocol saga -- more experiments with the DS1994

Nearly a week has passed. I got busy rearranging my lab/workshop. The last thing I did was to successfully read out the 8 bytes of ID information in the DS1994. Now I would like to read out the memory, which is the heart of the device.

The device is described as having 4K bits of non-volatile ram. This is 512K bytes. This is divided into 16 "pages", each of which is 32 bytes (256 bits). These are pages 0-15. There is also a page 16 which contains only 30 bytes which are the clock/counter registers.

Memory accesses use a 16 bit "target address". The low 5 bits (TA4:TA0) give the byte access in a page. The next 4 bits (TA8:TA5) must select the page.

The "read memory" command is 0xf0 and takes a start address and can read to the end of memory. Note that "end of memory" includes reading the 30 bytes in page 16 which have the timer values.
Here is what we see:

Data 0: 4c
Data 1: 61
Data 2: 73
Data 3: 65
Data 4: 72
Data 5: 20
Data 6: 42
Data 7: 41
Data 8: 42
Data 9: 32
Data 10: 31
Data 11: 31
Data 12: 30
Data 13: 30
Data 14: 30
Data 15: 36
Data 16: 20
Data 17: 37
Data 18: 38
Data 19: 35
Data 20: 20
Data 21: 35
Data 22: 20
Data 23: 31
Data 24: 31
Data 25: 33
Data 26: 31
Data 27: 20
Data 28: 33
Data 29: 30
Data 30: 20
Data 31: 31
Data 32: 20
Data 33: 09
Data 34: 09
Data 35: 09
Data 36: 09
Data 37: 09
Data 38: 09
Data 39: 09
Data 40: 09
Data 41: 09
Data 42: 09
Data 43: 09
Data 44: 09
Data 45: 09
Data 46: 09
Data 47: 09
Data 48: 09
Data 49: 09
Data 50: 09
Data 51: 09
Data 52: 09
Data 53: 09
Data 54: 09
Data 55: 09
Data 56: 09
Data 57: 09
Data 58: 09
Data 59: 09
Data 60: 09
Data 61: 09
Data 62: 09
Data 63: 09
Data 64: 55
Data 65: 55
....
....
Data 510: 55
Data 511: 55

Data 512: f8
Data 513: 58
Data 514: 43
Data 515: f1
Data 516: 51
Data 517: 43
Data 518: 0a
Data 519: 09
Data 520: 43
Data 521: cc
Data 522: 11
Data 523: 00
Data 524: 62
Data 525: 00
Data 526: 00
Data 527: 00
Data 528: 00
Data 529: 00
Data 530: 00
Data 531: 00
Data 532: 00
Data 533: 00
Data 534: 00
Data 535: 00
Data 536: 00
Data 537: 00
Data 538: 00
Data 539: 00
Data 540: 00
Data 541: 00

Data 542: ff
Data 543: ff
Data 544: ff
Data 545: ff
The above reads 4 bytes beyond the "end of memory" and gets all ones (0xff) for those locations, as the data sheet predicts.

Ignoring the 30 bytes of timer registers for now, we see the memory filled with 0x55 values except for the first 64 bytes. Just for the record 0x55 is upper case U in ascii. And interestingly, those bytes look like ascii --

Data 0: 4c   -- L
Data 1: 61   -- a
Data 2: 73   -- s
Data 3: 65   -- e
Data 4: 72   -- r
Data 5: 20   --  space
Data 6: 42   -- B
Data 7: 41   -- A
Data 8: 42   -- B
Data 9: 32   -- 2
Data 10: 31  -- 1
Data 11: 31  -- 1
Data 12: 30  -- 0
Data 13: 30  -- 0
Data 14: 30  -- 0
Data 15: 36  -- 6
Data 16: 20  --  space
Data 17: 37  -- 7
Data 18: 38  -- 8
Data 19: 35  -- 5
Data 20: 20  --  space
Data 21: 35  -- 5
Data 22: 20  --  space
Data 23: 31  -- 1
Data 24: 31  -- 1
Data 25: 33  -- 3
Data 26: 31  -- 1
Data 27: 20  --  space
Data 28: 33  -- 3
Data 29: 30  -- 0
Data 30: 20  --  space
Data 31: 31  -- 1

Data 32: 20 - space
Data 33: 09 - tab
Data 34: 09 - tab
Data 35: 09 - tab
Data 36: 09 - tab
Data 37: 09 - tab
Data 38: 09 - tab
Data 39: 09 - tab
Data 40: 09 - tab
Data 41: 09 - tab
Data 42: 09 - tab
Data 43: 09 - tab
Data 44: 09 - tab
Data 45: 09 - tab
Data 46: 09 - tab
Data 47: 09 - tab
Data 48: 09 - tab
Data 49: 09 - tab
Data 50: 09 - tab
Data 51: 09 - tab
Data 52: 09 - tab
Data 53: 09 - tab
Data 54: 09 - tab
Data 55: 09 - tab
Data 56: 09 - tab
Data 57: 09 - tab
Data 58: 09 - tab
Data 59: 09 - tab
Data 60: 09 - tab
Data 61: 09 - tab
Data 62: 09 - tab
Data 63: 09 - tab
I wrote a bit more code to just let printf() display those first 32 bytes:
String: Laser BAB2110006 785 5 1131 30 1

What about those 30 bytes in the timer section?

Data 512: f8 - status
Data 513: 58 - control
Data 514: 43 - real-time counter
Data 515: f1
Data 516: 51
Data 517: 43
Data 518: 0a
Data 519: 09 - interval time counter
Data 520: 43
Data 521: cc
Data 522: 11
Data 523: 00
Data 524: 62 - cycle counter
Data 525: 00
Data 526: 00
Data 527: 00
Data 528: 00 - real time alarm
Data 529: 00
Data 530: 00
Data 531: 00
Data 532: 00
Data 533: 00 - interval time alarm
Data 534: 00
Data 535: 00
Data 536: 00
Data 537: 00
Data 538: 00 - cycle alarm
Data 539: 00
Data 540: 00
Data 541: 00
And here are the values sometime later. Notice that only the real-time counter values have changed.
Data 512 0x0200: f8 - status
Data 513 0x0201: 58 - control
Data 514 0x0202: c1 - real-time counter
Data 515 0x0203: 6b
Data 516 0x0204: 6e
Data 517 0x0205: 43
Data 518 0x0206: 0a
Data 519 0x0207: 09 - interval time counter
Data 520 0x0208: 43
Data 521 0x0209: cc
Data 522 0x020a: 11
Data 523 0x020b: 00
Data 524 0x020c: 62 - cycle counter
The chip has a 32768 Hz crystal oscillator that clearly runs off the battery. It is divided down to a 256 Hz clock which drives the real-time (and interval) counter. These are 5 byte counters. The low byte counts fractions of a second (with 1/256 second resolution given the clock). The upper 4 bytes count full seconds. The 4 bytes can count 136 years worth of seconds. The time assigned to a zero count can be whatever you want (or in our case, whatever Thermo-scientific decided they wanted to use)

What does the value of 0x58 in the control register indicate?

	DSEL = 0 (no extra delay selected)
	Start = 1 (interval timer is stopped)
	Auto = 0 (interval timer is manual)
	Osc = 1 (oscillator enabled)
	RO = 1 (read only on expiration)
	WPC = 0 (no write protect on cycle counter regs)
	WPI = 0 (no write protect on interval counter regs)
	WPR = 0 (no write protect on real-time counter regs)
What does the value of 0xf8 in the status register indicate?
	top 2 bits are don't care
	CCE = 1 (cycle counter alarm disabled)
	ITE = 1 (interval alarm disabled)
	RTE = 1 (real-time alarm disabled)
	CCF = 0 (CC alarm)
	ITF = 0 (interval alarm)
	RTF = 0 (RT alarm)
So, no alarms are enabled or indicated. This is consistent with the values of 0 in the alarm registers.


Have any comments? Questions? Drop me a line!

Tom's software pages / tom@mmto.org